StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,634
of 17,787 indexed, latest versions
Container images
2,031
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,634 of 17,787 indexed charts deploy, on 2,031 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,031
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,634 by stars
ChartLatestAffected imagesRadar Score
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

8,645
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,435
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,176
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

9,152
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

10,468
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

12,999
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,580
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

10,073
devtron-enterprisedevtron-labs48.0.09 of 28See more

devtron-enterprise devtron-labs 48.0.0

9 of the 28 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/oauth2@v0.11.0
0.27.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/oauth2@v0.1.0
0.27.0
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/oauth2@v0.0.0-20181203162652-d668ce993890
0.27.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

66,542
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

5,041
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

4,969
devtron-operatordevtron-labs0.23.35 of 11See more

devtron-operator devtron-labs 0.23.3

5 of the 11 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/oauth2@v0.1.0
0.27.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

31,447
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/oauth2@v0.0.0-20210427180440-81ed05c6b58c
0.27.0

Open the chart page →

11,957
jcmhproxy-ingressdevtron-labs0.14.61 of 1See more

jcmhproxy-ingress devtron-labs 0.14.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

1,379
kube-prometheus-stackdevtron-labs19.3.03 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/oauth2@v0.0.0-20210805134026-6f1e6394065a
0.27.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

8,645
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,435
winter-soldierdevtron-labs0.10.61 of 1See more

winter-soldier devtron-labs 0.10.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,176
digital-mobiusdigital-mobius0.1.41 of 1See more

digital-mobius digital-mobius 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
qoveryrd/digital-mobius:0.1.4b30a9398a83c
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,287
direktivdirektivVerified publisher0.10.03 of 6See more

direktiv direktiv 0.10.0

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-k8s:0.120.01e45d9483faa
golang.org/x/oauth2@v0.26.0
0.27.0
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
golang.org/x/oauth2@v0.24.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.0aaafd456bda1
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

3,470
graphite-exporterdjjudas21Verified publisher0.1.91 of 1See more

graphite-exporter djjudas21 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/graphite-exporter:v0.16.0e54bca6645ea
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

782
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

17,053
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

4,217
dnation-kubernetes-monitoring-stackdnationcloud4.0.25 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

5 of the 17 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
golang.org/x/oauth2@v0.23.0
0.27.0
grafana/loki:3.2.0882e30c20683
golang.org/x/oauth2@v0.22.0
0.27.0
grafana/loki-canary:3.2.049e03f80d361
golang.org/x/oauth2@v0.22.0
0.27.0
prom/memcached-exporter:v0.15.0bb01ad25e9fc
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

21,455
ssl-exporterdnationcloud1.2.11 of 1See more

ssl-exporter dnationcloud 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
golang.org/x/oauth2@v0.0.0-20220630143837-2104d58473e0
0.27.0

Open the chart page →

1,632
dnsmasq-k8sdnsmasq-k8s1.4.11 of 1See more

dnsmasq-k8s dnsmasq-k8s 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

3,030
docker-authdocker-auth1.14.01 of 1See more

docker-auth docker-auth 1.14.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.14.098e0307e0d2d
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,506
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

8,408
furan2dollarshaveclubVerified publisher0.2.01 of 1See more

furan2 dollarshaveclub 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dollarshaveclub/furan2:master14a257836529
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,046
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

3,166
corednsdoubanVerified publisher1.39.21 of 1See more

coredns douban 1.39.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
coredns/coredns:1.12.040384aa1f5ea
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,132
gatekeeperdoubanVerified publisher3.17.12 of 3See more

gatekeeper douban 3.17.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.17.1b7b4d7cfdd52
golang.org/x/oauth2@v0.21.0
0.27.0
openpolicyagent/gatekeeper-crds:v3.17.177bc9bf3d163
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

2,492
k8s-crondoubanVerified publisher0.2.01 of 1See more

k8s-cron douban 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.28.2fc059f056ad0
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

3,660
tencentcloud-info-exporterdoubanVerified publisher0.2.21 of 1See more

tencentcloud-info-exporter douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

2,325
drogue-cloud-examplesdrogue-iotVerified publisher0.7.112 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

2 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
ghcr.io/ctron/kubectl:1.25e37d61b5277c
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

30,759
drogue-cloud-metricsdrogue-iotVerified publisher0.7.112 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

2 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/oauth2@v0.0.0-20210323180902-22b0adad7558
0.27.0

Open the chart page →

13,558
piraeusdtrdnk-helm-chartsVerified publisher2.2.01 of 1See more

piraeus dtrdnk-helm-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/piraeusdatastore/piraeus-operator:v2.2.0ec4022c8b0e3
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

1,042
tempo-operatordtrdnk-helm-chartsVerified publisher0.0.31 of 2See more

tempo-operator dtrdnk-helm-charts 0.0.3

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/grafana/tempo-operator/tempo-operator:v0.4.02627be646391
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

893
temporaldtrdnk-helm-chartsVerified publisher0.35.07 of 13See more

temporal dtrdnk-helm-charts 0.35.0

7 of the 13 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
temporalio/admin-tools:1.22.4258958fe2ff2
golang.org/x/oauth2@v0.11.0
0.27.0
temporalio/server:1.22.4c0a44c26397b
golang.org/x/oauth2@v0.4.0
0.27.0
temporalio/ui:2.16.2af9c9349708f
golang.org/x/oauth2@v0.6.0
0.27.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

20,204
duplicacyduplicacy0.1.21 of 2See more

duplicacy duplicacy 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
drumsergio/duplicacy-container:0.1.0dd3ee9703969
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,413
commentoduyet0.2.01 of 2See more

commento duyet 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/oauth2@v0.0.0-20180724155351-3d292e4d0cdc
0.27.0

Open the chart page →

2,679
kubernetes-database-scalerdvdlevanonVerified publisher0.1.21 of 1See more

kubernetes-database-scaler dvdlevanon 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dvdlevanon/kubernetes-database-scaler:v0.0.361e79c1643fe4
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

1,022
ai-scale-authdysnixVerified publisher0.1.12 of 3See more

ai-scale-auth dysnix 0.1.1

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alex6021710/ai-scale-auth:latest6c7a47e470c3
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
alex6021710/ai-scale-migrator:latest744b8a924f35
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

6,141
ai-scale-doerdysnixVerified publisher0.1.01 of 1See more

ai-scale-doer dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alex6021710/ai-scale-doer:latest31e533cf7cd3
golang.org/x/oauth2@v0.0.0-20210810183815-faf39c7919d5
0.27.0

Open the chart page →

2,801
ai-scale-providerdysnixVerified publisher0.1.01 of 1See more

ai-scale-provider dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alex6021710/ai-scale-provider:latest5837d9b30cc7
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

2,179
ai-scale-saverdysnixVerified publisher0.1.01 of 1See more

ai-scale-saver dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alex6021710/ai-scale-saver:latestf73e8d60fd03
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

2,136
bordysnixVerified publisher0.0.81 of 1See more

bor dysnix 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
0xpolygon/bor:1.3.7396d3de26d8b
golang.org/x/oauth2@v0.20.0
0.27.0

Open the chart page →

1,365
gcp-local-ssd-raiddysnixVerified publisher0.1.71 of 2See more

gcp-local-ssd-raid dysnix 0.1.7

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

2,399
gke-upgrade-notification-handlerdysnixVerified publisher0.1.11 of 1See more

gke-upgrade-notification-handler dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
dysnix/gke-upgrade-notification-handler:latestc166f958f86a
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

2,090
grafana-dashboardsdysnixVerified publisher0.2.21 of 2See more

grafana-dashboards dysnix 0.2.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.4.5d322192ed2fa
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0

Open the chart page →

5,161
heimdalldysnixVerified publisher0.0.11 of 1See more

heimdall dysnix 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
0xpolygon/heimdall:1.0.134ddf259993c
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

1,366

Container images carrying it

2,031 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
golang.org/x/oauth2@v0.8.0
0.27.0
1
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
apecloud/kubetran-platform:latest32bd92c7f7fa
golang.org/x/oauth2@v0.6.0
0.27.0
1
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
golang.org/x/oauth2@v0.4.0
0.27.0
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
golang.org/x/oauth2@v0.18.0
0.27.0
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
1
aquasec/postee:2.12.0-amd640795cba777e7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
aquasec/starboard-operator:0.15.4be34f709e1ce
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
aquasec/trivy:0.43.1944a04445179
golang.org/x/oauth2@v0.7.0
0.27.0
1
aquasec/trivy:0.32.0973d0df16189
golang.org/x/oauth2@v0.0.0-20220718184931-c8730f7fcb92
0.27.0
1
artifacthub/hub:v1.19.0111918d8c399
golang.org/x/oauth2@v0.21.0
0.27.0
1
artifacthub/scanner:v1.19.0323d026e78c3
golang.org/x/oauth2@v0.16.0
0.27.0
1
artifacthub/tracker:v1.19.06596c8c4d955
golang.org/x/oauth2@v0.21.0
0.27.0
1
arunvelsriram/utils:latest655ad18fd8d6
golang.org/x/oauth2@v0.18.0
0.27.0
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
astarte/astarte-kubernetes-operator:26.5.1e3ff1b3c0c98
golang.org/x/oauth2@v0.23.0
0.27.0
1
beopenit/door-agent:v3.0.5d24c323fe7c3
golang.org/x/oauth2@v0.23.0
0.27.0
1
beopenit/door-cd-operator:v3.0.4d3999cb8d026
golang.org/x/oauth2@v0.13.0
0.27.0
1
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/oauth2@v0.6.0
0.27.0
1
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
bicarus/wg-access-server:v0.8.206cab48e9334
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
golang.org/x/oauth2@v0.20.0
0.27.0
1
binwiederhier/ntfy:v2.6.283e2e43d9956
golang.org/x/oauth2@v0.9.0
0.27.0
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
golang.org/x/oauth2@v0.23.0
0.27.0
1
bitnamilegacy/kubectl:1.301249fc292e84
golang.org/x/oauth2@v0.10.0
0.27.0
1
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/oauth2@v0.21.0
0.27.0
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
golang.org/x/oauth2@v0.10.0
0.27.0
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/oauth2@v0.10.0
0.27.0
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
golang.org/x/oauth2@v0.15.0
0.27.0
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
golang.org/x/oauth2@v0.2.0
0.27.0
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
golang.org/x/oauth2@v0.21.0
0.27.0
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/oauth2@v0.15.0
0.27.0
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
golang.org/x/oauth2@v0.21.0
0.27.0
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/oauth2@v0.24.0
0.27.0
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
golang.org/x/oauth2@v0.24.0
0.27.0
1
bitnamilegacy/mongodb-exporter:0.39.0-debian-11-r106de7256c7adcd
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
golang.org/x/oauth2@v0.12.0
0.27.0
1
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0
1
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
golang.org/x/oauth2@v0.24.0
0.27.0
1
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
golang.org/x/oauth2@v0.8.0
0.27.0
1
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
golang.org/x/oauth2@v0.21.0
0.27.0
1
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
1
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
golang.org/x/oauth2@v0.23.0
0.27.0
1
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
bitpoke/wordpress-operator:v0.12.421284d1df473
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.