StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,614
of 17,787 indexed, latest versions
Container images
1,999
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,614 of 17,787 indexed charts deploy, on 1,999 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.01,999
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,614 by stars
ChartLatestAffected imagesRadar Score
permission-managerkfirfer1.0.71 of 1See more

permission-manager kfirfer 1.0.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,266
kubeflowkubeflow1.6.225 of 45See more

kubeflow kubeflow 1.6.2

25 of the 45 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
istio/proxyv2:1.14.1df69c1a7af7c
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
kubeflow/training-operator:v1-e1434f6ff847e2b6af0
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
kubeflownotebookswg/kfam:v1.6.1f226fb44db57
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
kubeflownotebookswg/poddefaults-webhook:v1.6.17d42600e1524
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
kubeflownotebookswg/tensorboard-controller:v1.6.182ffdd2da285
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/ml-pipeline/viewer-crd-controller:2.0.0-alpha.534403f9f94be
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

96,941
openelbkubesphere-stable0.5.02 of 2See more

openelb kubesphere-stable 0.5.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

4,329
operatorkube-starrocksVerified publisher1.11.71 of 1See more

operator kube-starrocks 1.11.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
starrocks/operator:v1.11.78c20435a7579
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

556
vclustermainVerified publisher0.17.06 of 10See more

vcluster main 0.17.0

6 of the 10 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
golang.org/x/oauth2@v0.5.0
0.27.0
quay.io/kubermatic/operating-system-manager:v1.3.010081473da43
golang.org/x/oauth2@v0.7.0
0.27.0
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

11,552
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
headscale/headscale:0.25.1a7a8ae9616bb
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

7,949
netris-operatornetrisai3.0.21 of 2See more

netris-operator netrisai 3.0.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
netrisai/netris-operator:v4.0.244f60aa0d898
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

1,588
node-local-dnsnode-local-dns2.4.01 of 1See more

node-local-dns node-local-dns 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

2,593
goldpingerokgoloveVerified publisher6.2.01 of 1See more

goldpinger okgolove 6.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bloomberg/goldpinger:3.10.08520120f5598
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

715
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

8,722
capsuleprojectcapsuleOfficialVerified publisher0.14.51 of 2See more

capsule projectcapsule 0.14.5

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,229
prometheus-consul-exporterprometheus-communityVerified publisher1.1.11 of 1See more

prometheus-consul-exporter prometheus-community 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/consul-exporter:v0.13.04e4cfd809e96
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

782
prometheus-json-exporterprometheus-communityOfficialVerified publisher0.20.11 of 1See more

prometheus-json-exporter prometheus-community 0.20.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/json-exporter:v0.7.03a777171d39a
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

725
prometheus-smartctl-exporterprometheus-communityVerified publisher0.17.11 of 1See more

prometheus-smartctl-exporter prometheus-community 0.17.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

1,064
prometheus-statsd-exporterprometheus-communityVerified publisher1.0.01 of 1See more

prometheus-statsd-exporter prometheus-community 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

782
rke2-multusrke2-charts3.7.1-build20210416011 of 2See more

rke2-multus rke2-charts 3.7.1-build2021041601

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,519
popeyeself-hosters-by-nightVerified publisher0.6.11 of 1See more

popeye self-hosters-by-night 0.6.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,196
uffizzi-appuffizzi-app1.3.08 of 14See more

uffizzi-app uffizzi-app 1.3.0

8 of the 14 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
golang.org/x/oauth2@v0.10.0
0.27.0
uffizzi/uffizzi-cluster-operator:v1.4.514e528bbd926
golang.org/x/oauth2@v0.4.0
0.27.0
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/oauth2@v0.12.0
0.27.0
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/oauth2@v0.12.0
0.27.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

19,337
dexwiremindVerified publisher2.15.71 of 2See more

dex wiremind 2.15.7

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

13,562
aperture-controlleraperture2.34.02 of 5See more

aperture-controller aperture 2.34.0

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
fluxninja/aperture-operator:2.34.0356d7aa86632
golang.org/x/oauth2@v0.14.0
0.27.0
quay.io/prometheus/prometheus:v2.33.591100b06e86d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

4,663
k8upappuio2.0.51 of 1See more

k8up appuio 2.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0

Open the chart page →

3,300
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

9,052
prometheusaveshaVerified publisher19.3.03 of 4See more

prometheus avesha 19.3.0

3 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/oauth2@v0.3.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

5,484
aws-calicoaws0.3.111 of 1See more

aws-calico aws 0.3.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.20.1379efe0c2541
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,250
snapschedulerbackube-helm-chartsVerified publisher3.5.01 of 2See more

snapscheduler backube-helm-charts 3.5.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,224
yataibentomlVerified publisher1.1.131 of 1See more

yatai bentoml 1.1.13

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
golang.org/x/oauth2@v0.2.0
0.27.0

Open the chart page →

1,915
yatai-deploymentbentomlVerified publisher1.1.211 of 2See more

yatai-deployment bentoml 1.1.21

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
golang.org/x/oauth2@v0.0.0-20221014153046-6fdb5e3db783
0.27.0

Open the chart page →

1,160
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,884
cert-managerchoerodon1.8.24 of 4See more

cert-manager choerodon 1.8.2

4 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

7,775
popeyechristianhuthVerified publisher2.4.31 of 1See more

popeye christianhuth 2.4.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,196
cluster-registrycluster-registry-controller0.2.121 of 1See more

cluster-registry cluster-registry-controller 0.2.12

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,707
coder-observabilitycoder-observabilityVerified publisher0.7.310 of 21See more

coder-observability coder-observability 0.7.3

10 of the 21 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/oauth2@v0.16.0
0.27.0
grafana/loki:3.1.0d947e68a84d9
golang.org/x/oauth2@v0.18.0
0.27.0
grafana/loki-canary:3.1.039baf6d67f85
golang.org/x/oauth2@v0.18.0
0.27.0
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/oauth2@v0.12.0
0.27.0
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/oauth2@v0.19.0
0.27.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
golang.org/x/oauth2@v0.21.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

24,700
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,080
dapr-dashboarddapr0.15.01 of 1See more

dapr-dashboard dapr 0.15.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
daprio/dashboard:0.15.04be696707bd1
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

1,301
kube-benchdeliveryheroVerified publisher0.1.171 of 1See more

kube-bench deliveryhero 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

1,623
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,271
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

12,042
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

14,546
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

13,874
frp-operatorfrp-operator1.9.01 of 1See more

frp-operator frp-operator 1.9.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/zufardhiyaulhaq/frp-operator:v0.11.0cd25ee354df2
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

528
multusgeek-cookbookVerified publisher3.5.21 of 3See more

multus geek-cookbook 3.5.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

4,906
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,371
traefik-forward-authgeek-cookbookVerified publisher2.2.21 of 1See more

traefik-forward-auth geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,234
monitoring-stackhaukitechVerified publisher0.1.113 of 3See more

monitoring-stack haukitech 0.1.11

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/oauth2@v0.23.0
0.27.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

2,164
prometheus-operatorhaukitechVerified publisher0.1.41 of 1See more

prometheus-operator haukitech 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

561
health-exporterhealth-exporterVerified publisher0.3.41 of 1See more

health-exporter health-exporter 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

1,558
frpc-ingressinfinity-server0.4.11 of 1See more

frpc-ingress infinity-server 0.4.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
springhack/frpc_ingress:latest4aceb821da88
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,622
coreinstill-aiOfficialVerified publisher0.1.754 of 15See more

core instill-ai 0.1.75

4 of the 15 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
instill/artifact-backend:b28766ac4a393e601ed
golang.org/x/oauth2@v0.14.0
0.27.0
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
temporalio/admin-tools:1.28cfde8170c92f
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

30,816
intel-gpu-resource-driverintelVerified publisher0.7.01 of 1See more

intel-gpu-resource-driver intel 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
intel/intel-gpu-resource-driver:v0.7.0e158711e32ce
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

559
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,211

Container images carrying it

1,999 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
golang.org/x/oauth2@v0.4.0
0.27.0
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
golang.org/x/oauth2@v0.18.0
0.27.0
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/oauth2@v0.0.0-20201208152858-08078c50e5b5
0.27.0
1
aquasec/postee:2.12.0-amd640795cba777e7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
aquasec/starboard-operator:0.15.4be34f709e1ce
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
aquasec/trivy:0.43.1944a04445179
golang.org/x/oauth2@v0.7.0
0.27.0
1
aquasec/trivy:0.32.0973d0df16189
golang.org/x/oauth2@v0.0.0-20220718184931-c8730f7fcb92
0.27.0
1
artifacthub/hub:v1.19.0111918d8c399
golang.org/x/oauth2@v0.21.0
0.27.0
1
artifacthub/scanner:v1.19.0323d026e78c3
golang.org/x/oauth2@v0.16.0
0.27.0
1
artifacthub/tracker:v1.19.06596c8c4d955
golang.org/x/oauth2@v0.21.0
0.27.0
1
arunvelsriram/utils:latest655ad18fd8d6
golang.org/x/oauth2@v0.18.0
0.27.0
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
astarte/astarte-kubernetes-operator:26.5.1e3ff1b3c0c98
golang.org/x/oauth2@v0.23.0
0.27.0
1
beopenit/door-agent:v3.0.5d24c323fe7c3
golang.org/x/oauth2@v0.23.0
0.27.0
1
beopenit/door-cd-operator:v3.0.4d3999cb8d026
golang.org/x/oauth2@v0.13.0
0.27.0
1
beopenit/door-helm:v3.0.1b4d9f9bee224
golang.org/x/oauth2@v0.6.0
0.27.0
1
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
bicarus/wg-access-server:v0.8.206cab48e9334
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
1
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
golang.org/x/oauth2@v0.20.0
0.27.0
1
binwiederhier/ntfy:v2.6.283e2e43d9956
golang.org/x/oauth2@v0.9.0
0.27.0
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
golang.org/x/oauth2@v0.23.0
0.27.0
1
bitnamilegacy/kubectl:1.301249fc292e84
golang.org/x/oauth2@v0.10.0
0.27.0
1
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/oauth2@v0.21.0
0.27.0
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
golang.org/x/oauth2@v0.10.0
0.27.0
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/oauth2@v0.10.0
0.27.0
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
golang.org/x/oauth2@v0.15.0
0.27.0
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
golang.org/x/oauth2@v0.2.0
0.27.0
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
golang.org/x/oauth2@v0.21.0
0.27.0
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/oauth2@v0.15.0
0.27.0
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
golang.org/x/oauth2@v0.21.0
0.27.0
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/oauth2@v0.24.0
0.27.0
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
golang.org/x/oauth2@v0.24.0
0.27.0
1
bitnamilegacy/mongodb-exporter:0.39.0-debian-11-r106de7256c7adcd
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
1
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
golang.org/x/oauth2@v0.12.0
0.27.0
1
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
golang.org/x/oauth2@v0.0.0-20190226205417-e64efc72b421
0.27.0
1
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
golang.org/x/oauth2@v0.24.0
0.27.0
1
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
golang.org/x/oauth2@v0.8.0
0.27.0
1
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
golang.org/x/oauth2@v0.21.0
0.27.0
1
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/oauth2@v0.0.0-20220608161450-d0670ef3b1eb
0.27.0
1
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
golang.org/x/oauth2@v0.23.0
0.27.0
1
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
1
bitpoke/wordpress-operator:v0.12.421284d1df473
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1
bloomberg/goldpinger:3.10.08520120f5598
golang.org/x/oauth2@v0.13.0
0.27.0
1
bonovoo/secrethor:1.1.2bb93b68fcd17
golang.org/x/oauth2@v0.12.0
0.27.0
1
breton/cool:dev41b1bb483aa2
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
1
bsgrigorov/helm-operator:latest45ab095f09c8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.