StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,678
of 17,813 indexed, latest versions
Container images
2,057
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,678 of 17,813 indexed charts deploy, on 2,057 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,057
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,678 by stars
ChartLatestAffected imagesRadar Score
push-to-k8ssupporttools1.1.21 of 1See more

push-to-k8s supporttools 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cube8021/push-to-k8s:v1.1.21be9baf096ff
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

531
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

11,020
ingress-nginxsvtech-public-helm-charts1.0.01 of 1See more

ingress-nginx svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

1,480
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,369
synadia-serversynadiaVerified publisher1.1.101 of 2See more

synadia-server synadia 1.1.10

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,971
agentssynapse0.1.301 of 9See more

agents synapse 0.1.30

1 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

7,288
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

1,826
ccm-hcloudsyself1.0.111 of 1See more

ccm-hcloud syself 1.0.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,713
topolvmsyself1.3.01 of 1See more

topolvm syself 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

3,622
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,877
promtailt3n1.0.01 of 1See more

promtail t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,829
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,493
paperless-ngx-backuptaskmediaVerified publisher1.1.01 of 1See more

paperless-ngx-backup taskmedia 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/taskmedia/kubectl-gpg-ncftp:main0fb2b5584f7c
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

518
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

4,230
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,774
clickhousetemp-charts0.7.12 of 3See more

clickhouse temp-charts 0.7.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

8,708
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0

Open the chart page →

75,347
istio-ingresstemp-charts0.3.31 of 1See more

istio-ingress temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.088c6c693e67a
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0

Open the chart page →

75,293
temporaltemporal0.28.97 of 13See more

temporal temporal 0.28.9

7 of the 13 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
temporalio/admin-tools:1.22.0836af062af30
golang.org/x/oauth2@v0.4.0
0.27.0
temporalio/server:1.22.0ddeebf8bad8f
golang.org/x/oauth2@v0.4.0
0.27.0
temporalio/ui:2.16.2af9c9349708f
golang.org/x/oauth2@v0.6.0
0.27.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

21,062
teredixteredix0.0.21 of 1See more

teredix teredix 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/shaharia-lab/teredix:0.0.2ec727be4417a
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,077
gmctest-opea1.0.01 of 1See more

gmc test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
opea/gmcmanager:1.0514af17c495c
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

517
local-path-provisionerth-chartsVerified publisher0.0.291 of 1See more

local-path-provisioner th-charts 0.0.29

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.299bebefa0b908
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,301
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

10,131
mc-routerthl-chartsVerified publisher0.1.01 of 1See more

mc-router thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
itzg/mc-router:1.16.1bb552b59fb53
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

1,856
monitoringthl-chartsVerified publisher0.1.17 of 10See more

monitoring thl-charts 0.1.1

7 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
grafana/loki:2.5.0f9ef133793af
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
grafana/promtail:2.4.2626900031c4e
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/prometheus:v2.34.0b37103e03399
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

18,949
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
nginx/nginx-ingress:1.11.1eb5b4fd73325
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

6,891
grafanatnh5.3.01 of 1See more

grafana tnh 5.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

3,199
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

8,495
nfs-servertranhailongVerified publisher0.1.21 of 1See more

nfs-server tranhailong 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tranhailong/nfs-server:4.2-2-gcsfuse028662749be2
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

2,331
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

2,489
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

4,817
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,521
monitorortrozz0.0.11 of 1See more

monitoror trozz 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
monitoror/monitoror:44b88edcf51ff
golang.org/x/oauth2@v0.0.0-20181106182150-f42d05182288
0.27.0

Open the chart page →

3,111
clickhouse-operatortruefoundryVerified publisher0.1.12 of 3See more

clickhouse-operator truefoundry 0.1.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.23.34baec90b20cd
golang.org/x/oauth2@v0.8.0
0.27.0
altinity/metrics-exporter:0.23.32912a6c15b44
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,432
tfy-inferentia-operatortruefoundryVerified publisher0.2.83 of 3See more

tfy-inferentia-operator truefoundry 0.2.8

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/kubernetes/kube-scheduler:v1.29.14-eks-1-29-lateste7e1db003e6a
golang.org/x/oauth2@v0.11.0
0.27.0
public.ecr.aws/neuron/neuron-device-plugin:2.23.30.075a6d5ce3bd3
golang.org/x/oauth2@v0.13.0
0.27.0
public.ecr.aws/neuron/neuron-scheduler:2.23.30.04cd274463e6b
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

2,926
tfy-kservetruefoundryVerified publisher0.1.11 of 2See more

tfy-kserve truefoundry 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kserve/kserve-controller:v0.10.022ff858b57c1
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

1,178
tfy-llm-gateway-infratruefoundryVerified publisher0.2.102 of 3See more

tfy-llm-gateway-infra truefoundry 0.2.10

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.23.774315beb57db
golang.org/x/oauth2@v0.12.0
0.27.0
altinity/metrics-exporter:0.23.7a4d7ff0c727e
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

1,210
tfy-lokitruefoundryVerified publisher0.1.62 of 2See more

tfy-loki truefoundry 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/loki:2.9.1035b02acc6765
golang.org/x/oauth2@v0.10.0
0.27.0
grafana/promtail:2.9.1063a2e57a5b14
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

2,829
aws-eks-asg-rolling-update-handlertwin1.5.01 of 1See more

aws-eks-asg-rolling-update-handler twin 1.5.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
twinproduction/aws-eks-asg-rolling-update-handler:v1.7.08f38c206972e
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,119
lighthousetwin1.0.21 of 1See more

lighthouse twin 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/twin/lighthouse:v0.0.45aeda2ea2ba2
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

544
tyk-bootstraptyk-helm5.3.02 of 3See more

tyk-bootstrap tyk-helm 5.3.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/oauth2@v0.10.0
0.27.0
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,374
tyk-control-planetyk-helm5.3.02 of 7See more

tyk-control-plane tyk-helm 5.3.0

2 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/oauth2@v0.10.0
0.27.0
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,266
tyk-stacktyk-helm5.3.02 of 7See more

tyk-stack tyk-helm 5.3.0

2 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/oauth2@v0.10.0
0.27.0
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,200
typhoontyphoonVerified publisher0.2.32 of 2See more

typhoon typhoon 0.2.3

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
golang.org/x/oauth2@v0.26.0
0.27.0
ghcr.io/zeiss/typhoon/typhoon-webhook:0.2.378f9b82050bc
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

1,690
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

8,709
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

4,995
utho-app-operator-chartutho-operatorVerified publisher0.1.61 of 2See more

utho-app-operator-chart utho-operator 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
utho/utho-app-operator:0.1.46e8a690e8b7a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

491
vault-raft-snapshot-agentvault-raft-snapshot-agentVerified publisher0.6.91 of 1See more

vault-raft-snapshot-agent vault-raft-snapshot-agent 0.6.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/argelbargel/vault-raft-snapshot-agent:v0.12.5345174727a2b
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

1,267
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,521
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,539

Container images carrying it

2,057 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
golang.org/x/oauth2@v0.3.0
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
golang.org/x/oauth2@v0.17.0
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
golang.org/x/oauth2@v0.7.0
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
golang.org/x/oauth2@v0.5.0
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.11.3d56f135b6462
golang.org/x/oauth2@v0.23.0
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
golang.org/x/oauth2@v0.18.0
0.27.0
1
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
golang.org/x/oauth2@v0.24.0
0.27.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.044d1d0e9f19c
golang.org/x/oauth2@v0.17.0
0.27.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.0aaafd456bda1
golang.org/x/oauth2@v0.23.0
0.27.0
1
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
golang.org/x/oauth2@v0.10.0
0.27.0
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/kubectl:v1.32.73c5268158974
golang.org/x/oauth2@v0.23.0
0.27.0
1
registry.k8s.io/kubectl:v1.32.08ccae74fc039
golang.org/x/oauth2@v0.23.0
0.27.0
1
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/oauth2@v0.21.0
0.27.0
1
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
golang.org/x/oauth2@v0.7.0
0.27.0
1
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
golang.org/x/oauth2@v0.8.0
0.27.0
1
registry.k8s.io/kube-scheduler:v1.28.1146cf7475c8da
golang.org/x/oauth2@v0.8.0
0.27.0
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/oauth2@v0.3.0
0.27.0
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.2ec5732e28f15
golang.org/x/oauth2@v0.3.0
0.27.0
1
registry.k8s.io/metrics-server/metrics-server:v0.7.01c0419326500
golang.org/x/oauth2@v0.16.0
0.27.0
1
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
golang.org/x/oauth2@v0.16.0
0.27.0
1
registry.k8s.io/nfd/node-feature-discovery:v0.16.619ebca8b3804
golang.org/x/oauth2@v0.17.0
0.27.0
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
golang.org/x/oauth2@v0.22.0
0.27.0
1
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/oauth2@v0.4.0
0.27.0
1
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
golang.org/x/oauth2@v0.2.0
0.27.0
1
registry.k8s.io/sig-storage/csi-attacher:v4.5.19dcd469f02bb
golang.org/x/oauth2@v0.13.0
0.27.0
1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/sig-storage/csi-provisioner:v5.0.27b9cdb5830d0
golang.org/x/oauth2@v0.20.0
0.27.0
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
golang.org/x/oauth2@v0.25.0
0.27.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
golang.org/x/oauth2@v0.13.0
0.27.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
golang.org/x/oauth2@v0.22.0
0.27.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
golang.org/x/oauth2@v0.20.0
0.27.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/oauth2@v0.24.0
0.27.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/oauth2@v0.13.0
0.27.0
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.