StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,688
of 17,821 indexed, latest versions
Container images
2,068
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,688 of 17,821 indexed charts deploy, on 2,068 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,068
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,688 by stars
ChartLatestAffected imagesRadar Score
logging-stackhelm-charts-alexis-carbillet0.1.05 of 9See more

logging-stack helm-charts-alexis-carbillet 0.1.0

5 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
grafana/grafana:11.1.0079600c9517b
golang.org/x/oauth2@v0.20.0
0.27.0
grafana/loki:2.6.11ee60f980950
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
grafana/loki:2.8.2b1da1d23037e
golang.org/x/oauth2@v0.4.0
0.27.0
grafana/loki-canary:2.6.1ab2a2569307b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

12,700
monitoring-stackhelm-charts-alexis-carbillet0.1.08 of 11See more

monitoring-stack helm-charts-alexis-carbillet 0.1.0

8 of the 11 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/oauth2@v0.23.0
0.27.0
prom/prometheus:v2.48.1a67e5e402ff5
golang.org/x/oauth2@v0.13.0
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.70.0e20576b76ffd
golang.org/x/oauth2@v0.15.0
0.27.0
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/oauth2@v0.8.0
0.27.0
quay.io/prometheus/node-exporter:v1.7.04cb2b9019f17
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/oauth2@v0.8.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

10,702
aws-ebs-csi-driverhelm-charts-nr2.17.44 of 6See more

aws-ebs-csi-driver helm-charts-nr 2.17.4

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/oauth2@v0.1.0
0.27.0
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/oauth2@v0.2.0
0.27.0
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

6,527
cortex-gatewayhelm-charts-nr0.1.91 of 1See more

cortex-gateway helm-charts-nr 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0

Open the chart page →

2,242
dregsyhelm-charts-nr0.1.51 of 1See more

dregsy helm-charts-nr 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/oauth2@v0.0.0-20201109201403-9fd604954f58
0.27.0

Open the chart page →

2,979
k8s-cloudwatch-adapterhelm-charts-nr0.2.21 of 1See more

k8s-cloudwatch-adapter helm-charts-nr 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,476
k8s-event-loggerhelm-charts-nr1.1.91 of 1See more

k8s-event-logger helm-charts-nr 1.1.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
maxrocketinternet/k8s-event-logger:2.111224534789d
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0

Open the chart page →

864
kube-benchhelm-charts-nr0.1.171 of 1See more

kube-bench helm-charts-nr 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,624
labelsmanager-controllerhelm-charts-nr1.0.41 of 1See more

labelsmanager-controller helm-charts-nr 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,306
node-local-dnshelm-charts-nr2.1.41 of 1See more

node-local-dns helm-charts-nr 2.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.1e3dccb1a21d1
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

2,304
node-problem-detectorhelm-charts-nr2.3.171 of 1See more

node-problem-detector helm-charts-nr 2.3.17

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

2,497
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/oauth2@v0.0.0-20181106182150-f42d05182288
0.27.0

Open the chart page →

8,015
answerhelmforgeVerified publisher1.5.21 of 1See more

answer helmforge 1.5.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apache/answer:2.0.2a0d71b0e30a5
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

557
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

25,439
printserverhmediadeVerified publisher1.0.22 of 4See more

printserver hmediade 1.0.2

2 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/oauth2@v0.12.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

11,032
imageproxyhmphuVerified publisher0.1.11 of 1See more

imageproxy hmphu 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0

Open the chart page →

2,148
cert-managerhomeenterpriseinc1.10.13 of 3See more

cert-manager homeenterpriseinc 1.10.1

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.10.164121721c665
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0

Open the chart page →

4,737
hammerspace-csihscsi1.2.83 of 6See more

hammerspace-csi hscsi 1.2.8

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/oauth2@v0.25.0
0.27.0
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

4,520
cac-systemhuangchengwu-helm-chart0.1.07 of 9See more

cac-system huangchengwu-helm-chart 0.1.0

7 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
golang.org/x/oauth2@v0.6.0
0.27.0
quay.io/jetstack/cert-manager-cainjector:v1.12.0e0a5b06b231c
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.12.0ec4306b243d9
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

11,266
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

16,579
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

20,798
tdenginehuangchengwu-helm-chart3.0.21 of 1See more

tdengine huangchengwu-helm-chart 3.0.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tdengine/tdengine:3.0.2.24140a4021ddb
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0

Open the chart page →

3,775
stoloniamalryz0.10.01 of 2See more

stolon iamalryz 0.10.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,053
monitoring-stackict-platformVerified publisher0.4.02 of 13See more

monitoring-stack ict-platform 0.4.0

2 of the 13 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.2c7adcc4db378
golang.org/x/oauth2@v0.23.0
0.27.0
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

9,709
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
arunvelsriram/utils:latest655ad18fd8d6
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

9,256
ikigaiikigai-chartVerified publisher0.0.93 of 58See more

ikigai ikigai-chart 0.0.9

3 of the 58 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kuberay/operator:v1.0.04e6ac8a3a2c4
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
rabbitmqoperator/cluster-operator:2.6.08651dd3cec51
golang.org/x/oauth2@v0.8.0
0.27.0
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

113,437
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,171
ilum-jupyterhubilumVerified publisher4.3.11 of 6See more

ilum-jupyterhub ilum 4.3.1

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,997
ilum-otel-collectorilumVerified publisher0.1.01 of 1See more

ilum-otel-collector ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.113.05ac3e0ba2b0b
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,525
kore-boardimprowisedVerified publisher0.5.83 of 4See more

kore-board improwised 0.5.8

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.backend:v0.5.5455f6e7a26fd
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
ghcr.io/kore3lab/kore-board.metrics-scraper:v0.5.547f88b18fb7c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

16,423
fpga-cloudinaccelVerified publisher1.2.23 of 3See more

fpga-cloud inaccel 1.2.2

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
inaccel/cloud-init:latesta5d3d0af05c1
golang.org/x/oauth2@v0.15.0
0.27.0
inaccel/device-selector:latest44b4f274f40b
golang.org/x/oauth2@v0.14.0
0.27.0
inaccel/kubevirt-hack:latestbdfd61803a70
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

3,167
fpga-operatorinaccelVerified publisher2.8.21 of 7See more

fpga-operator inaccel 2.8.2

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
inaccel/reef:latestc967218739f3
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

5,785
infisical-csi-providerinfisical-charts0.2.31 of 1See more

infisical-csi-provider infisical-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
infisical/infisical-csi-provider:v0.0.9e3390e677db6
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

636
chronografinfluxdata1.2.61 of 1See more

chronograf influxdata 1.2.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/chronograf:1.9.496d8a3f65a4f
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0

Open the chart page →

2,206
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

10,602
lakefsinseefrlab0.0.61 of 2See more

lakefs inseefrlab 0.0.6

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
treeverse/lakefs:0.69.0478f37a6cffc
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

2,654
instemmingserviceinstemmingservice1.0.01 of 3See more

instemmingservice instemmingservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,521
consulintelVerified publisher0.8.12 of 2See more

consul intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

5,431
evi-consulintelVerified publisher3.0.32 of 2See more

evi-consul intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

5,431
evi-miniointelVerified publisher3.0.31 of 2See more

evi-minio intel 3.0.3

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

7,614
evi-vaultintelVerified publisher3.0.32 of 2See more

evi-vault intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

4,488
intel-gaudi-resource-driverintelVerified publisher0.3.01 of 1See more

intel-gaudi-resource-driver intel 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
intel/intel-gaudi-resource-driver:v0.3.0ac758c14c2de
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

566
intel-qat-resource-driverintelVerified publisher0.1.01 of 1See more

intel-qat-resource-driver intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
intel/intel-qat-resource-driver:v0.1.0ac7616986a2b
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

609
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization:3.03426deb77337
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

81,922
tcs-issuerintelVerified publisher0.5.01 of 2See more

tcs-issuer intel 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
intel/trusted-certificate-issuer:0.5.0591a9db4a427
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

6,020
vaultintelVerified publisher0.8.12 of 2See more

vault intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

4,488
gravity-initinvisiblVerified publisher1.0.91 of 1See more

gravity-init invisibl 1.0.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
invisibl/gravity-init:v1.0.91a970f84178b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,008
identity-managerinvisiblVerified publisher1.0.01 of 1See more

identity-manager invisibl 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
invisibl/identity-manager:1.0.01029f4fe20eb
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,163
karpenteriometeVerified publisher0.19.31 of 1See more

karpenter iomete 0.19.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:v0.19.3f0e5ab60b2df
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,556
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

5,600

Container images carrying it

2,068 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
golang.org/x/oauth2@v0.13.0
0.27.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
golang.org/x/oauth2@v0.22.0
0.27.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
golang.org/x/oauth2@v0.20.0
0.27.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/oauth2@v0.24.0
0.27.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/oauth2@v0.13.0
0.27.0
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
golang.org/x/oauth2@v0.25.0
0.27.0
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
golang.org/x/oauth2@v0.24.0
0.27.0
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
golang.org/x/oauth2@v0.1.0
0.27.0
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
golang.org/x/oauth2@v0.10.0
0.27.0
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.