StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,634
of 17,787 indexed, latest versions
Container images
2,031
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,634 of 17,787 indexed charts deploy, on 2,031 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,031
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,634 by stars
ChartLatestAffected imagesRadar Score
tekton-operatorkubebb0.64.02 of 2See more

tekton-operator kubebb 0.64.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
golang.org/x/oauth2@v0.2.0
0.27.0
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
golang.org/x/oauth2@v0.2.0
0.27.0

Open the chart page →

2,406
u4a-componentkubebb0.2.106 of 8See more

u4a-component kubebb 0.2.10

6 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubebb/capsule-ce:v0.1.2-20221122a3dba2a95cef
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
kubebb/iam-controller:v0.2.0-202401288ffbfa2d67e9
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
kubebb/iam-provider:v0.2.0-202401280ba03fcee3a7
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
kubebb/oidc-server:v0.2.02b5894ef1e2f
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
kubebb/resource-viewer:v0.2.065bb40b353db
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

13,820
weaviatekubebb16.3.01 of 1See more

weaviate kubebb 16.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
semitechnologies/weaviate:1.19.17a00d226f063
golang.org/x/oauth2@v0.0.0-20220822191816-0ebed06d0094
0.27.0

Open the chart page →

1,869
apecloud-mcpkubeblocksVerified publisher0.1.01 of 1See more

apecloud-mcp kubeblocks 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apecloud/apecloud-mcp:0.1.094041b080510
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

1,107
apelcoud-mcpkubeblocksVerified publisher0.1.01 of 1See more

apelcoud-mcp kubeblocks 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apecloud/apecloud-mcp:0.1.094041b080510
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

1,107
argo-workflowskubeblocksVerified publisher0.40.142 of 2See more

argo-workflows kubeblocks 0.40.14

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/argoproj/argocli:v3.5.591b9825f09a8
golang.org/x/oauth2@v0.13.0
0.27.0
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

2,871
calicokubeblocksVerified publisher3.28.03 of 3See more

calico kubeblocks 3.28.0

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
calico/cni:v3.28.0cef0c907b8f4
golang.org/x/oauth2@v0.16.0
0.27.0
calico/kube-controllers:v3.28.08f04e4772a2b
golang.org/x/oauth2@v0.16.0
0.27.0
calico/node:v3.28.0385bf6391fea
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

3,288
casdoor-helm-chartskubeblocksVerified publisher1.753.01 of 1See more

casdoor-helm-charts kubeblocks 1.753.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
casbin/casdoor:v1.753.0770ad9ec3190
golang.org/x/oauth2@v0.17.0
0.27.0

Open the chart page →

2,299
chaos-meshkubeblocksVerified publisher2.7.24 of 4See more

chaos-mesh kubeblocks 2.7.2

4 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
golang.org/x/oauth2@v0.10.0
0.27.0
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
golang.org/x/oauth2@v0.10.0
0.27.0
ghcr.io/chaos-mesh/chaos-mesh:v2.7.28bc853c7414c
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

13,517
ciliumkubeblocksVerified publisher1.15.12 of 2See more

cilium kubeblocks 1.15.1

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.15.1351d6685dc6f
golang.org/x/oauth2@v0.15.0
0.27.0
quay.io/cilium/operator-generic:v1.15.1819c7281f5a4
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

5,114
dt-platformkubeblocksVerified publisher0.1.21 of 1See more

dt-platform kubeblocks 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apecloud/dt-platform:0.1.1d48bcbd38066
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

879
geminikubeblocksVerified publisher0.13.42 of 8See more

gemini kubeblocks 0.13.4

2 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/oauth2@v0.24.0
0.27.0
victoriametrics/vmalert:v1.95.1a83e5db0897a
golang.org/x/oauth2@v0.14.0
0.27.0

Open the chart page →

3,103
gemini-schedulerkubeblocksVerified publisher0.1.11 of 1See more

gemini-scheduler kubeblocks 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apecloud/gemini-scheduler:0.1.15832d1a9097a
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,412
grafanakubeblocksVerified publisher6.59.41 of 1See more

grafana kubeblocks 6.59.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:10.1.11b9ca4bbc4a2
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

3,561
kubeblocks-csi-driverkubeblocksVerified publisher0.1.31 of 6See more

kubeblocks-csi-driver kubeblocks 0.1.3

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,083
kubetrankubeblocksVerified publisher0.1.01 of 1See more

kubetran kubeblocks 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apecloud/kubetran-platform:latest32bd92c7f7fa
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,207
lokikubeblocksVerified publisher5.39.03 of 5See more

loki kubeblocks 5.39.0

3 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.34.1045c9125634c
golang.org/x/oauth2@v0.7.0
0.27.0
grafana/loki:2.9.26074e01dbe03
golang.org/x/oauth2@v0.10.0
0.27.0
grafana/loki-canary:2.9.24249db29b992
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

5,841
metallbkubeblocksVerified publisher0.14.42 of 3See more

metallb kubeblocks 0.14.4

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.14.4bbef1ee3e7d3
golang.org/x/oauth2@v0.18.0
0.27.0
quay.io/metallb/speaker:v0.14.437611bde45a2
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

2,600
metrics-serverkubeblocksVerified publisher3.12.01 of 1See more

metrics-server kubeblocks 3.12.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.7.01c0419326500
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,131
nvidia-gpu-exporterkubeblocksVerified publisher0.3.11 of 1See more

nvidia-gpu-exporter kubeblocks 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

4,500
openebskubeblocksVerified publisher3.10.03 of 3See more

openebs kubeblocks 3.10.0

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
openebs/provisioner-localpv:3.5.0aea39e49bb97
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

10,568
postgres-operatorkubeblocksVerified publisher1.12.21 of 1See more

postgres-operator kubeblocks 1.12.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.12.2d81cda253f5c
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,554
prometheuskubeblocksVerified publisher15.16.15 of 6See more

prometheus kubeblocks 15.16.1

5 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.33496e0f85943
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
quay.io/prometheus/alertmanager:v0.24.0088464f949de
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
quay.io/prometheus/prometheus:v2.39.14748e26f9369
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

10,302
smartfs-csi-driverkubeblocksVerified publisher0.1.21 of 6See more

smartfs-csi-driver kubeblocks 0.1.2

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

9,249
snapshot-controllerkubeblocksVerified publisher1.7.21 of 1See more

snapshot-controller kubeblocks 1.7.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
golang.org/x/oauth2@v0.1.0
0.27.0

Open the chart page →

1,128
spiderpoolkubeblocksVerified publisher1.2.04 of 4See more

spiderpool kubeblocks 1.2.0

4 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.409fdfb7ce090
golang.org/x/oauth2@v0.10.0
0.27.0
ghcr.io/spidernet-io/spiderpool/spiderpool-agent:v1.2.08bb9411e47e0
golang.org/x/oauth2@v0.24.0
0.27.0
ghcr.io/spidernet-io/spiderpool/spiderpool-controller:v1.2.042304e3ed36e
golang.org/x/oauth2@v0.24.0
0.27.0
ghcr.io/spidernet-io/spiderpool/spiderpool-plugins:19f19457ae7cec86457b0411543a3cf21dd9f95a8edc39be1e22
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

8,457
victoria-metrics-alertkubeblocksVerified publisher0.8.3-reload2 of 3See more

victoria-metrics-alert kubeblocks 0.8.3-reload

2 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
victoriametrics/vmalert:v1.95.1a83e5db0897a
golang.org/x/oauth2@v0.14.0
0.27.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0

Open the chart page →

3,715
kubeclaritykubeclarity2.23.32 of 5See more

kubeclarity kubeclarity 2.23.3

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/openclarity/grype-server:v0.6.079412399f301
golang.org/x/oauth2@v0.8.0
0.27.0
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

5,496
listener-operatorkubedoopVerified publisher0.4.02 of 6See more

listener-operator kubedoop 0.4.0

2 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/oauth2@v0.22.0
0.27.0
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

4,430
secret-operatorkubedoopVerified publisher0.4.02 of 5See more

secret-operator kubedoop 0.4.0

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/oauth2@v0.22.0
0.27.0
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

4,378
cephfs-csikubegems1.0.81 of 6See more

cephfs-csi kubegems 1.0.8

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

4,445
chartmuseumkubegems3.8.01 of 1See more

chartmuseum kubegems 3.8.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

3,518
gatewaykubegems0.3.22 of 2See more

gateway kubegems 0.3.2

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubegems/ingress-nginx-operator:v0.2.0cc67357beeeb
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
kubegems/kube-rbac-proxy:v0.8.0941f557ed1ee
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

3,498
giteakubegems5.0.81 of 2See more

gitea kubegems 5.0.8

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gitea/gitea:1.16.8b0bdf102b485
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

3,400
juicefs-csi-driverkubegems0.19.22 of 6See more

juicefs-csi-driver kubegems 0.19.2

2 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
juicedata/csi-dashboard:v0.23.03e4daf9626d5
golang.org/x/oauth2@v0.7.0
0.27.0
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

4,825
knative-servingkubegems1.0.17 of 8See more

knative-serving kubegems 1.0.1

7 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourierdigest-pinned197fbb71d1f1
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned08315309da4b
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned105bdd14ecaa
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedbac158dfb0c7
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mappingdigest-pinnede384a295069b
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhookdigest-pinned15f1ce7f35b4
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned1282a399cbb9
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

10,420
kubegems-edgekubegems1.24.101 of 1See more

kubegems-edge kubegems 1.24.10

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

3,381
kubegems-multus-cnikubegems2.4.11 of 2See more

kubegems-multus-cni kubegems 2.4.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.2.16bebbda31416
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

1,373
logging-operatorkubegems3.17.61 of 1See more

logging-operator kubegems 3.17.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/logging-operator:3.17.623c2d4d54a64
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,800
prometheus-adapterkubegems4.14.11 of 1See more

prometheus-adapter kubegems 4.14.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

930
prometheus-blackbox-exporterkubegems7.1.31 of 1See more

prometheus-blackbox-exporter kubegems 7.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.22.0608acee5704a
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,628
volcanokubegems1.12.13 of 3See more

volcano kubegems 1.12.1

3 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
volcanosh/vc-controller-manager:v1.12.13815883c32f6
golang.org/x/oauth2@v0.23.0
0.27.0
volcanosh/vc-scheduler:v1.12.1b24ea8af2d16
golang.org/x/oauth2@v0.23.0
0.27.0
volcanosh/vc-webhook-manager:v1.12.1f8b50088a732
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

5,021
xpai-schedulerkubegems1.12.11 of 2See more

xpai-scheduler kubegems 1.12.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
projecthami/volcano-vgpu-device-plugin:v1.9.40c94118d1d98
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,317
gptchat-api-feishubotkubegemsapp0.1.11 of 3See more

gptchat-api-feishubot kubegemsapp 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
kubegems/chatgpt-api-proxy:latest8905c9dbbb5d
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

8,486
kubeintellectkubeintellectVerified publisher2.5.01 of 2See more

kubeintellect kubeintellect 2.5.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/mskazemi/kubeintellect:2.5.0b5d7681d1b9d
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,858
kubelet-summary-exporterkubelet-summary-exporter1.0.01 of 1See more

kubelet-summary-exporter kubelet-summary-exporter 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/salesforce/kubelet-summary-exporter:sha-c2bf90d377e09d2dd72
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,015
log-socketkube-loggingVerified publisher0.1.21 of 1See more

log-socket kube-logging 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/log-socket:latesta514736d2d4d
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

1,220
kubemacpoolkubemacpoolVerified publisher0.3.01 of 1See more

kubemacpool kubemacpool 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/kubevirt/kubemacpool:v0.45.0eebb65b8a12c
golang.org/x/oauth2@v0.13.0
0.27.0

Open the chart page →

1,624
kube-netlagkube-netlagVerified publisher1.1.01 of 1See more

kube-netlag kube-netlag 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

1,483
apm-serverkube-opsVerified publisher0.1.21 of 1See more

apm-server kube-ops 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
elastic/apm-server:7.17.6c7a1c63257d0
golang.org/x/oauth2@v0.0.0-20211005180243-6b3c2da341f1
0.27.0

Open the chart page →

7,196

Container images carrying it

2,031 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
9
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
8
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/oauth2@v0.24.0
0.27.0
8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0
8
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
7
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/oauth2@v0.23.0
0.27.0
7
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0
6
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
6
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/oauth2@v0.1.0
0.27.0
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
6
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/oauth2@v0.18.0
0.27.0
6
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/oauth2@v0.25.0
0.27.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/oauth2@v0.21.0
0.27.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/oauth2@v0.18.0
0.27.0
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/oauth2@v0.10.0
0.27.0
5
keelhq/keel:latest73714afb4443
golang.org/x/oauth2@v0.24.0
0.27.0
5
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/oauth2@v0.6.0
0.27.0
5
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
5
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/oauth2@v0.23.0
0.27.0
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/oauth2@v0.12.0
0.27.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/oauth2@v0.21.0
0.27.0
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
5
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/oauth2@v0.5.0
0.27.0
5
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
4
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
4
grafana/loki:2.6.11ee60f980950
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
4
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/oauth2@v0.10.0
0.27.0
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/oauth2@v0.8.0
0.27.0
4
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/oauth2@v0.12.0
0.27.0
4
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/oauth2@v0.12.0
0.27.0
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/oauth2@v0.12.0
0.27.0
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/oauth2@v0.12.0
0.27.0
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
4
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/oauth2@v0.18.0
0.27.0
4
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/oauth2@v0.25.0
0.27.0
4
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/oauth2@v0.15.0
0.27.0
4
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/oauth2@v0.24.0
0.27.0
4
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
3
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/oauth2@v0.13.0
0.27.0
3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
3

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.