StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,615
of 17,781 indexed, latest versions
Container images
2,001
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,615 of 17,781 indexed charts deploy, on 2,001 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,001
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,615 by stars
ChartLatestAffected imagesRadar Score
permission-managerkfirfer1.0.71 of 1See more

permission-manager kfirfer 1.0.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,266
kubeflowkubeflow1.6.225 of 45See more

kubeflow kubeflow 1.6.2

25 of the 45 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
istio/proxyv2:1.14.1df69c1a7af7c
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
kubeflow/training-operator:v1-e1434f6ff847e2b6af0
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
kubeflownotebookswg/kfam:v1.6.1f226fb44db57
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
kubeflownotebookswg/poddefaults-webhook:v1.6.17d42600e1524
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
kubeflownotebookswg/tensorboard-controller:v1.6.182ffdd2da285
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/ml-pipeline/viewer-crd-controller:2.0.0-alpha.534403f9f94be
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

96,941
openelbkubesphere-stable0.5.02 of 2See more

openelb kubesphere-stable 0.5.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

4,329
operatorkube-starrocksVerified publisher1.11.71 of 1See more

operator kube-starrocks 1.11.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
starrocks/operator:v1.11.78c20435a7579
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

556
vclustermainVerified publisher0.17.06 of 10See more

vcluster main 0.17.0

6 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/kubermatic/operating-system-manager:v1.3.010081473da43
golang.org/x/oauth2@v0.7.0
0.27.0
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

11,552
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
headscale/headscale:0.25.1a7a8ae9616bb
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

7,949
netris-operatornetrisai3.0.21 of 2See more

netris-operator netrisai 3.0.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
netrisai/netris-operator:v4.0.244f60aa0d898
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

1,588
node-local-dnsnode-local-dns2.4.01 of 1See more

node-local-dns node-local-dns 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

2,593
goldpingerokgoloveVerified publisher6.2.01 of 1See more

goldpinger okgolove 6.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bloomberg/goldpinger:3.10.08520120f5598
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

715
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

8,722
capsuleprojectcapsuleOfficialVerified publisher0.14.51 of 2See more

capsule projectcapsule 0.14.5

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,229
prometheus-consul-exporterprometheus-communityVerified publisher1.1.11 of 1See more

prometheus-consul-exporter prometheus-community 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/consul-exporter:v0.13.04e4cfd809e96
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

782
prometheus-json-exporterprometheus-communityOfficialVerified publisher0.20.11 of 1See more

prometheus-json-exporter prometheus-community 0.20.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/json-exporter:v0.7.03a777171d39a
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

725
prometheus-smartctl-exporterprometheus-communityVerified publisher0.17.11 of 1See more

prometheus-smartctl-exporter prometheus-community 0.17.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

1,064
prometheus-statsd-exporterprometheus-communityVerified publisher1.0.01 of 1See more

prometheus-statsd-exporter prometheus-community 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

782
rke2-multusrke2-charts3.7.1-build20210416011 of 2See more

rke2-multus rke2-charts 3.7.1-build2021041601

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,519
popeyeself-hosters-by-nightVerified publisher0.6.11 of 1See more

popeye self-hosters-by-night 0.6.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,196
uffizzi-appuffizzi-app1.3.08 of 14See more

uffizzi-app uffizzi-app 1.3.0

8 of the 14 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
golang.org/x/oauth2@v0.10.0
0.27.0
uffizzi/uffizzi-cluster-operator:v1.4.514e528bbd926
golang.org/x/oauth2@v0.4.0
0.27.0
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/oauth2@v0.12.0
0.27.0
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/oauth2@v0.12.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

19,337
dexwiremindVerified publisher2.15.71 of 2See more

dex wiremind 2.15.7

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

13,562
aperture-controlleraperture2.34.02 of 5See more

aperture-controller aperture 2.34.0

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
fluxninja/aperture-operator:2.34.0356d7aa86632
golang.org/x/oauth2@v0.14.0
0.27.0
quay.io/prometheus/prometheus:v2.33.591100b06e86d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

4,663
k8upappuio2.0.51 of 1See more

k8up appuio 2.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

3,300
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

9,052
prometheusaveshaVerified publisher19.3.03 of 4See more

prometheus avesha 19.3.0

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/oauth2@v0.3.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

5,484
aws-calicoaws0.3.111 of 1See more

aws-calico aws 0.3.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.20.1379efe0c2541
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,250
snapschedulerbackube-helm-chartsVerified publisher3.5.01 of 2See more

snapscheduler backube-helm-charts 3.5.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,224
yataibentomlVerified publisher1.1.131 of 1See more

yatai bentoml 1.1.13

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
golang.org/x/oauth2@v0.2.0
0.27.0

Open the chart page →

1,915
yatai-deploymentbentomlVerified publisher1.1.211 of 2See more

yatai-deployment bentoml 1.1.21

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

1,160
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,884
cert-managerchoerodon1.8.24 of 4See more

cert-manager choerodon 1.8.2

4 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

7,775
popeyechristianhuthVerified publisher2.4.31 of 1See more

popeye christianhuth 2.4.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,196
cluster-registrycluster-registry-controller0.2.121 of 1See more

cluster-registry cluster-registry-controller 0.2.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,707
coder-observabilitycoder-observabilityVerified publisher0.7.310 of 21See more

coder-observability coder-observability 0.7.3

10 of the 21 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/oauth2@v0.16.0
0.27.0
grafana/loki:3.1.0d947e68a84d9
golang.org/x/oauth2@v0.18.0
0.27.0
grafana/loki-canary:3.1.039baf6d67f85
golang.org/x/oauth2@v0.18.0
0.27.0
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/oauth2@v0.19.0
0.27.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
golang.org/x/oauth2@v0.21.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

24,700
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,080
dapr-dashboarddapr0.15.01 of 1See more

dapr-dashboard dapr 0.15.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
daprio/dashboard:0.15.04be696707bd1
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

1,301
kube-benchdeliveryheroVerified publisher0.1.171 of 1See more

kube-bench deliveryhero 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,623
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,271
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

12,042
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

14,546
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

13,874
frp-operatorfrp-operator1.9.01 of 1See more

frp-operator frp-operator 1.9.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/zufardhiyaulhaq/frp-operator:v0.11.0cd25ee354df2
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

528
multusgeek-cookbookVerified publisher3.5.21 of 3See more

multus geek-cookbook 3.5.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,906
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,371
traefik-forward-authgeek-cookbookVerified publisher2.2.21 of 1See more

traefik-forward-auth geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,234
monitoring-stackhaukitechVerified publisher0.1.113 of 3See more

monitoring-stack haukitech 0.1.11

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,164
prometheus-operatorhaukitechVerified publisher0.1.41 of 1See more

prometheus-operator haukitech 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

561
health-exporterhealth-exporterVerified publisher0.3.41 of 1See more

health-exporter health-exporter 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

1,558
frpc-ingressinfinity-server0.4.11 of 1See more

frpc-ingress infinity-server 0.4.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
springhack/frpc_ingress:latest4aceb821da88
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,622
coreinstill-aiOfficialVerified publisher0.1.754 of 15See more

core instill-ai 0.1.75

4 of the 15 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
instill/artifact-backend:b28766ac4a393e601ed
golang.org/x/oauth2@v0.14.0
0.27.0
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
temporalio/admin-tools:1.28cfde8170c92f
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

30,816
intel-gpu-resource-driverintelVerified publisher0.7.01 of 1See more

intel-gpu-resource-driver intel 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
intel/intel-gpu-resource-driver:v0.7.0e158711e32ce
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

559
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,211

Container images carrying it

2,001 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
golang.org/x/oauth2@v0.19.0
0.27.0
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/oauth2@v0.23.0
0.27.0
2
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.409fdfb7ce090
golang.org/x/oauth2@v0.10.0
0.27.0
2
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
golang.org/x/oauth2@v0.21.0
0.27.0
2
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
golang.org/x/oauth2@v0.23.0
0.27.0
2
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
golang.org/x/oauth2@v0.23.0
0.27.0
2
ghcr.io/konpyutaika/docker-images/nifikop:v1.14.1-release6bb00c592a82
golang.org/x/oauth2@v0.21.0
0.27.0
2
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
golang.org/x/oauth2@v0.12.0
0.27.0
2
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/oauth2@v0.1.0
0.27.0
2
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/oauth2@v0.2.0
0.27.0
2
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
2
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/oauth2@v0.24.0
0.27.0
2
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
golang.org/x/oauth2@v0.21.0
0.27.0
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/oauth2@v0.0.0-20220630143837-2104d58473e0
0.27.0
2
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
2
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/oauth2@v0.12.0
0.27.0
2
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/oauth2@v0.15.0
0.27.0
2
quay.io/jetstack/cert-manager-cainjector:v1.15.3e0ce8ae280c8
golang.org/x/oauth2@v0.20.0
0.27.0
2
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/oauth2@v0.15.0
0.27.0
2
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/oauth2@v0.12.0
0.27.0
2
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
golang.org/x/oauth2@v0.20.0
0.27.0
2
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/jetstack/cert-manager-startupapicheck:v1.15.34cbc1b022a23
golang.org/x/oauth2@v0.20.0
0.27.0
2
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/oauth2@v0.15.0
0.27.0
2
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/oauth2@v0.12.0
0.27.0
2
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/oauth2@v0.15.0
0.27.0
2
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
golang.org/x/oauth2@v0.20.0
0.27.0
2
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/oauth2@v0.5.0
0.27.0
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
golang.org/x/oauth2@v0.12.0
0.27.0
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
golang.org/x/oauth2@v0.10.0
0.27.0
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
golang.org/x/oauth2@v0.7.0
0.27.0
2
quay.io/prometheuscommunity/json-exporter:v0.7.03a777171d39a
golang.org/x/oauth2@v0.24.0
0.27.0
2
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/oauth2@v0.10.0
0.27.0
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.