StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,634
of 17,787 indexed, latest versions
Container images
2,031
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,634 of 17,787 indexed charts deploy, on 2,031 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,031
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,634 by stars
ChartLatestAffected imagesRadar Score
ilum-apiilumVerified publisher6.7.31 of 1See more

ilum-api ilum 6.7.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ilum/api:6.7.3624fd09528c8
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,177
ilum-jupyterhubilumVerified publisher4.3.11 of 6See more

ilum-jupyterhub ilum 4.3.1

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,836
ilum-otel-collectorilumVerified publisher0.1.01 of 1See more

ilum-otel-collector ilum 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.113.05ac3e0ba2b0b
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,384
kore-boardimprowisedVerified publisher0.5.83 of 4See more

kore-board improwised 0.5.8

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.backend:v0.5.5455f6e7a26fd
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
ghcr.io/kore3lab/kore-board.metrics-scraper:v0.5.547f88b18fb7c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

16,226
fpga-cloudinaccelVerified publisher1.2.23 of 3See more

fpga-cloud inaccel 1.2.2

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
inaccel/cloud-init:latesta5d3d0af05c1
golang.org/x/oauth2@v0.15.0
0.27.0
inaccel/device-selector:latest44b4f274f40b
golang.org/x/oauth2@v0.14.0
0.27.0
inaccel/kubevirt-hack:latestbdfd61803a70
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

3,152
fpga-operatorinaccelVerified publisher2.8.21 of 7See more

fpga-operator inaccel 2.8.2

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
inaccel/reef:latestc967218739f3
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

5,759
infisical-csi-providerinfisical-charts0.2.31 of 1See more

infisical-csi-provider infisical-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
infisical/infisical-csi-provider:v0.0.9e3390e677db6
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

630
chronografinfluxdata1.2.61 of 1See more

chronograf influxdata 1.2.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/chronograf:1.9.496d8a3f65a4f
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0

Open the chart page →

2,198
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

10,542
lakefsinseefrlab0.0.61 of 2See more

lakefs inseefrlab 0.0.6

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
treeverse/lakefs:0.69.0478f37a6cffc
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

2,645
instemmingserviceinstemmingservice1.0.01 of 3See more

instemmingservice instemmingservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,510
consulintelVerified publisher0.8.12 of 2See more

consul intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

5,389
evi-consulintelVerified publisher3.0.32 of 2See more

evi-consul intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

5,389
evi-kesintelVerified publisher3.0.31 of 1See more

evi-kes intel 3.0.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/kes:2023-04-03T16-41-28Zf93c2d9088df
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

1,758
evi-miniointelVerified publisher3.0.31 of 2See more

evi-minio intel 3.0.3

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

7,457
evi-vaultintelVerified publisher3.0.32 of 2See more

evi-vault intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

4,478
intel-gaudi-resource-driverintelVerified publisher0.3.01 of 1See more

intel-gaudi-resource-driver intel 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
intel/intel-gaudi-resource-driver:v0.3.0ac758c14c2de
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

559
intel-qat-resource-driverintelVerified publisher0.1.01 of 1See more

intel-qat-resource-driver intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
intel/intel-qat-resource-driver:v0.1.0ac7616986a2b
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

602
kesintelVerified publisher0.8.31 of 1See more

kes intel 0.8.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/kes:v0.22.255f3aef5803e
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

3,570
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization:3.03426deb77337
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

11,123
tcs-issuerintelVerified publisher0.5.01 of 2See more

tcs-issuer intel 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
intel/trusted-certificate-issuer:0.5.0591a9db4a427
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

5,996
vaultintelVerified publisher0.8.12 of 2See more

vault intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/oauth2@v0.0.0-20220524215830-622c5d57e401
0.27.0
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

4,478
gravity-initinvisiblVerified publisher1.0.91 of 1See more

gravity-init invisibl 1.0.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
invisibl/gravity-init:v1.0.91a970f84178b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,006
identity-managerinvisiblVerified publisher1.0.01 of 1See more

identity-manager invisibl 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
invisibl/identity-manager:1.0.01029f4fe20eb
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

2,162
karpenteriometeVerified publisher0.19.31 of 1See more

karpenter iomete 0.19.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:v0.19.3f0e5ab60b2df
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,548
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

5,570
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

5,570
istio-ratelimit-operatoristio-ratelimit-operator2.16.11 of 1See more

istio-ratelimit-operator istio-ratelimit-operator 2.16.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
zufardhiyaulhaq/istio-ratelimit-operator:v2.15.0692cfc9d6614
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

745
hetzner-dyndnsitsmethemojoVerified publisher1.4.01 of 1See more

hetzner-dyndns itsmethemojo 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/terraform:1.9.7b77efab1a448
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

1,836
rclonejacobcolvinVerified publisher1.0.11 of 1See more

rclone jacobcolvin 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rclone/rclone:1.63.008e1af3c8814
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

2,143
twitch-predictions-recorderjacobcolvinVerified publisher0.1.01 of 1See more

twitch-predictions-recorder jacobcolvin 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

2,669
wireguard-operatorjacobcolvinVerified publisher0.2.01 of 2See more

wireguard-operator jacobcolvin 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/jodevsa/wireguard-operator/manager:v2.0.2839412bdd403b
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

840
koptimizejaconiVerified publisher0.5.42 of 2See more

koptimize jaconi 0.5.4

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.27.321b24e6bf801
golang.org/x/oauth2@v0.8.0
0.27.0
ghcr.io/jaconi-io/koptimize:1.2.5aca1bbd609b6
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

5,716
mini-infrajaeki0.1.01 of 4See more

mini-infra jaeki 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,746
janus-shieldjanus-shield1.0.01 of 2See more

janus-shield janus-shield 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon:v1.1.096fac2482898
golang.org/x/oauth2@v0.17.0
0.27.0

Open the chart page →

2,377
javascriptweeklyjavascriptweekly2.1.01 of 1See more

javascriptweekly javascriptweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
zufardhiyaulhaq/javascriptweekly:v2.1.086424bd0b2a4
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

1,237
sql-exporterjdstoneVerified publisher0.2.11 of 1See more

sql-exporter jdstone 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
burningalchemist/sql_exporter:0.16.0b8e4757c7def
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

885
jx-app-athensjenkins-x0.0.181 of 1See more

jx-app-athens jenkins-x 0.0.18

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0

Open the chart page →

4,225
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

4,038
jx-app-flaggerjenkins-x0.0.52 of 2See more

jx-app-flagger jenkins-x 0.0.5

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:6.5.1befcd84da2c1
golang.org/x/oauth2@v0.0.0-20190319182350-c85d3e98c914
0.27.0
weaveworks/flagger:1.0.0-rc.5174307de1b36
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

6,028
knative-servingjenkins-x0.19.124 of 4See more

knative-serving jenkins-x 0.19.12

4 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned1e3db4f2eeed
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinneddb6ceff2aab4
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedb2cd45b8a8a4
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedd27b4495ccc3
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0

Open the chart page →

9,699
ingress-nginxjfrog4.5.22 of 2See more

ingress-nginx jfrog 4.5.2

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
golang.org/x/oauth2@v0.3.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,798
vaultjfrog0.25.02 of 2See more

vault jfrog 0.25.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/vault:1.14.0b2177a8bfe85
golang.org/x/oauth2@v0.8.0
0.27.0
hashicorp/vault-k8s:1.2.14500e988b7ce
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

3,969
haven-complinacy-dashboardjolle-devVerified publisher1.0.01 of 2See more

haven-complinacy-dashboard jolle-dev 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,841
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

16,626
k10appk10app0.2.11 of 11See more

k10app k10app 0.2.1

1 of the 11 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/k10app/businit:latest94c9a3e799c2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

10,560
k8quk8qu1.4.01 of 1See more

k8qu k8qu 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/gijsvandulmen/k8qu:1.4e897b18db13d
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

568
deploydefenderk8s-custom-controllerVerified publisher0.1.31 of 1See more

deploydefender k8s-custom-controller 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,893
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

8,879
maddyk8s-home-lab-repo4.2.11 of 1See more

maddy k8s-home-lab-repo 4.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
foxcpp/maddy:0.8.2eeb5813fc4d1
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

1,052

Container images carrying it

2,031 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/oauth2@v0.0.0-20201203001011-0b49973bad19
0.27.0
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
golang.org/x/oauth2@v0.19.0
0.27.0
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/oauth2@v0.23.0
0.27.0
2
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.409fdfb7ce090
golang.org/x/oauth2@v0.10.0
0.27.0
2
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
golang.org/x/oauth2@v0.21.0
0.27.0
2
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
golang.org/x/oauth2@v0.23.0
0.27.0
2
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
golang.org/x/oauth2@v0.23.0
0.27.0
2
ghcr.io/konpyutaika/docker-images/nifikop:v1.14.1-release6bb00c592a82
golang.org/x/oauth2@v0.21.0
0.27.0
2
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
golang.org/x/oauth2@v0.12.0
0.27.0
2
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/oauth2@v0.1.0
0.27.0
2
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/oauth2@v0.2.0
0.27.0
2
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
2
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/oauth2@v0.24.0
0.27.0
2
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
golang.org/x/oauth2@v0.21.0
0.27.0
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/oauth2@v0.0.0-20220630143837-2104d58473e0
0.27.0
2
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
2
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/oauth2@v0.12.0
0.27.0
2
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/oauth2@v0.15.0
0.27.0
2
quay.io/jetstack/cert-manager-cainjector:v1.15.3e0ce8ae280c8
golang.org/x/oauth2@v0.20.0
0.27.0
2
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/oauth2@v0.15.0
0.27.0
2
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/oauth2@v0.12.0
0.27.0
2
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
golang.org/x/oauth2@v0.20.0
0.27.0
2
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/jetstack/cert-manager-startupapicheck:v1.15.34cbc1b022a23
golang.org/x/oauth2@v0.20.0
0.27.0
2
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/oauth2@v0.15.0
0.27.0
2
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/oauth2@v0.12.0
0.27.0
2
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/oauth2@v0.15.0
0.27.0
2
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
golang.org/x/oauth2@v0.20.0
0.27.0
2
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/oauth2@v0.5.0
0.27.0
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
golang.org/x/oauth2@v0.12.0
0.27.0
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
golang.org/x/oauth2@v0.10.0
0.27.0
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
golang.org/x/oauth2@v0.7.0
0.27.0
2
quay.io/prometheuscommunity/json-exporter:v0.7.03a777171d39a
golang.org/x/oauth2@v0.24.0
0.27.0
2
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.