StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,615
of 17,781 indexed, latest versions
Container images
2,001
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,615 of 17,781 indexed charts deploy, on 2,001 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,001
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,615 by stars
ChartLatestAffected imagesRadar Score
gateway-helmappscodeVerified publisher0.0.0-latest1 of 2See more

gateway-helm appscode 0.0.0-latest

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,057
scannerappscodeVerified publisher2026.1.151 of 3See more

scanner appscode 2026.1.15

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

5,299
smtprelayappscodeVerified publisher2026.9.111 of 1See more

smtprelay appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

840
stash-enterpriseappscodeVerified publisher0.42.03 of 4See more

stash-enterprise appscode 0.42.0

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/oauth2@v0.21.0
0.27.0
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

3,620
argocd-backup-s3argocd-backup-s3Verified publisher0.9.51 of 1See more

argocd-backup-s3 argocd-backup-s3 0.9.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

5,222
kedaarieotechVerified publisher0.1.02 of 3See more

keda arieotech 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kedacore/keda:2.16.002348a19aeae
golang.org/x/oauth2@v0.23.0
0.27.0
ghcr.io/kedacore/keda-metrics-apiserver:2.16.073a2ebae4413
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,276
cert-exporterarzu3.0.11 of 1See more

cert-exporter arzu 3.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0

Open the chart page →

2,819
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

10,730
cso-proxyav1o-chartsVerified publisher0.1.31 of 1See more

cso-proxy av1o-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

4,292
dex-k8sav1o-chartsVerified publisher0.2.11 of 1See more

dex-k8s av1o-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/oauth2@v0.0.0-20201203001011-0b49973bad19
0.27.0

Open the chart page →

3,391
db-backupballe-petersen0.1.41 of 1See more

db-backup balle-petersen 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,814
chirpstackbeeinventor0.1.102 of 5See more

chirpstack beeinventor 0.1.10

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

7,807
cloudflare-tunnel-operatorbeezlabs0.2.01 of 1See more

cloudflare-tunnel-operator beezlabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

1,595
helm-dashboardbeluga-cloudVerified publisher2.4.01 of 1See more

helm-dashboard beluga-cloud 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

2,898
boundaryboundary-chart0.3.121 of 1See more

boundary boundary-chart 0.3.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,624
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,830
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

2,042
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/oauth2@v0.0.0-20181003184128-c57b0facaced
0.27.0

Open the chart page →

2,663
argocd-source-trackercableship0.0.91 of 1See more

argocd-source-tracker cableship 0.0.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cableship/argocd-source-tracker:0.0.6ff7dd45aa774
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,483
chart-sentinelcableship0.0.121 of 1See more

chart-sentinel cableship 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cableship/chart-sentinel:0.1.0a037f1042b28
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,483
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

906
capsulecapsuleOfficialVerified publisher0.14.51 of 2See more

capsule capsule 0.14.5

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,229
capsule-proxycapsule-proxyOfficialVerified publisher0.14.11 of 2See more

capsule-proxy capsule-proxy 0.14.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,222
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,509
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,799
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
golang.org/x/oauth2@v0.20.0
0.27.0
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/oauth2@v0.19.0
0.27.0
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

12,562
cert-manager-webhook-arvancloudcert-manager-webhook-arvancloudVerified publisher0.1.11 of 1See more

cert-manager-webhook-arvancloud cert-manager-webhook-arvancloud 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,067
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

1,024
cert-vaultcert-vaultOfficialVerified publisher2.12.01 of 7See more

cert-vault cert-vault 2.12.0

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

15,863
chatclichatcliVerified publisher1.203.01 of 2See more

chatcli chatcli 1.203.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,026
access-managerckotzbauerVerified publisher0.14.31 of 1See more

access-manager ckotzbauer 0.14.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/access-managerdigest-pinneddd584fcda0ff
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

643
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,268
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220201 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

1 of the 9 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,256
cnpg-sandboxcloudnative-pgVerified publisher0.6.13 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

7,583
cloudttycloudtty0.8.91 of 2See more

cloudtty cloudtty 0.8.9

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell-operator:v0.8.9e43ad91f0684
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

3,951
cluster-setupcluster-setup1.5.01 of 8See more

cluster-setup cluster-setup 1.5.0

1 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

10,037
istio-allcode4devsVerified publisher1.2.04 of 6See more

istio-all code4devs 1.2.0

4 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/oauth2@v0.23.0
0.27.0
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
golang.org/x/oauth2@v0.19.0
0.27.0
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

4,784
istio-control-planecode4devsVerified publisher1.0.02 of 3See more

istio-control-plane code4devs 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/oauth2@v0.23.0
0.27.0
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,360
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

7,303
cosmo-controller-managercosmoVerified publisher0.9.01 of 2See more

cosmo-controller-manager cosmo 0.9.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-controller-manager:v0.9.08c7fa5552028
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,927
cosmo-dashboardcosmoVerified publisher0.9.11 of 1See more

cosmo-dashboard cosmo 0.9.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-dashboard:v0.9.16a1c4a81a924
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,939
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0

Open the chart page →

6,473
revadcs3orgOfficialVerified publisher1.6.11 of 1See more

revad cs3org 1.6.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

1,704
cubefscubefs3.2.05 of 10See more

cubefs cubefs 3.2.0

5 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0

Open the chart page →

15,891
CubeUniversecubeuniverseVerified publisher0.1.01 of 1See more

CubeUniverse cubeuniverse 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,837
cyphernetes-operatorcyphernetes-operatorVerified publisher0.1.01 of 1See more

cyphernetes-operator cyphernetes-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
fatliverfreddy/cyphernetes-operator:lateste79f24ca7371
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

498
aibrixdanchevVerified publisher0.7.02 of 5See more

aibrix danchev 0.7.0

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aibrix/controller-manager:v0.7.076aabbbfda79
golang.org/x/oauth2@v0.21.0
0.27.0
aibrix/gateway-plugins:v0.7.05b93ea4c753a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

5,274
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,759
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

4,568
dbrepodbrepo1.13.34 of 25See more

dbrepo dbrepo 1.13.3

4 of the 25 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
golang.org/x/oauth2@v0.23.0
0.27.0
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
golang.org/x/oauth2@v0.12.0
0.27.0
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
golang.org/x/oauth2@v0.8.0
0.27.0
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

52,635

Container images carrying it

2,001 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
golang.org/x/oauth2@v0.19.0
0.27.0
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
golang.org/x/oauth2@v0.23.0
0.27.0
2
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.409fdfb7ce090
golang.org/x/oauth2@v0.10.0
0.27.0
2
ghcr.io/keptn/certificate-operator:v3.0.0b82064b0e339
golang.org/x/oauth2@v0.21.0
0.27.0
2
ghcr.io/keptn/lifecycle-operator:v2.0.0866ced256a8c
golang.org/x/oauth2@v0.23.0
0.27.0
2
ghcr.io/keptn/metrics-operator:v2.1.0dc48471c7cf8
golang.org/x/oauth2@v0.23.0
0.27.0
2
ghcr.io/konpyutaika/docker-images/nifikop:v1.14.1-release6bb00c592a82
golang.org/x/oauth2@v0.21.0
0.27.0
2
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
golang.org/x/oauth2@v0.12.0
0.27.0
2
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/oauth2@v0.1.0
0.27.0
2
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/oauth2@v0.2.0
0.27.0
2
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0
2
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
2
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/oauth2@v0.24.0
0.27.0
2
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
golang.org/x/oauth2@v0.21.0
0.27.0
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/oauth2@v0.0.0-20220630143837-2104d58473e0
0.27.0
2
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
2
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/oauth2@v0.12.0
0.27.0
2
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/oauth2@v0.15.0
0.27.0
2
quay.io/jetstack/cert-manager-cainjector:v1.15.3e0ce8ae280c8
golang.org/x/oauth2@v0.20.0
0.27.0
2
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/oauth2@v0.15.0
0.27.0
2
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/oauth2@v0.12.0
0.27.0
2
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
golang.org/x/oauth2@v0.20.0
0.27.0
2
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/jetstack/cert-manager-startupapicheck:v1.15.34cbc1b022a23
golang.org/x/oauth2@v0.20.0
0.27.0
2
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/oauth2@v0.15.0
0.27.0
2
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/oauth2@v0.12.0
0.27.0
2
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/oauth2@v0.15.0
0.27.0
2
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
golang.org/x/oauth2@v0.20.0
0.27.0
2
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/oauth2@v0.5.0
0.27.0
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
golang.org/x/oauth2@v0.12.0
0.27.0
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
golang.org/x/oauth2@v0.10.0
0.27.0
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
golang.org/x/oauth2@v0.4.0
0.27.0
2
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
2
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
golang.org/x/oauth2@v0.7.0
0.27.0
2
quay.io/prometheuscommunity/json-exporter:v0.7.03a777171d39a
golang.org/x/oauth2@v0.24.0
0.27.0
2
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/oauth2@v0.10.0
0.27.0
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.