StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,634
of 17,787 indexed, latest versions
Container images
2,031
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,634 of 17,787 indexed charts deploy, on 2,031 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,031
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,634 by stars
ChartLatestAffected imagesRadar Score
operatorrookout0.0.201 of 2See more

operator rookout 0.0.20

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rookout/k8s-operator:latest0d083f3ef1a7
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,209
rookout-hybridrookout0.3.11 of 2See more

rookout-hybrid rookout 0.3.1

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rookout/controller:latest4451a6f6b8ec
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

3,901
rmfakecloudrubxkubeVerified publisher0.1.11 of 1See more

rmfakecloud rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ddvk/rmfakecloud:latest2f5c45cbf0c5
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

498
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

5,833
orbitalryuunosukeds30.2.01 of 1See more

orbital ryuunosukeds3 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ryuunosukeds3/orbital:latest0879f7261b10
golang.org/x/oauth2@v0.26.0
0.27.0

Open the chart page →

2,556
tusdsagikazarmarkVerified publisher0.1.21 of 1See more

tusd sagikazarmark 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tusproject/tusd:v1.10.01e457b59fd5b
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0

Open the chart page →

1,545
knative-helm-operatorsalaboy1.9.02 of 2See more

knative-helm-operator salaboy 1.9.0

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/operator/cmd/webhookdigest-pinned6c5c90cdf707
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0
gcr.io/knative-releases/knative.dev/serving/cmd/default-domaindigest-pinned5e0429b70299
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

2,339
saml-exportersaml-exporter0.5.01 of 2See more

saml-exporter saml-exporter 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,507
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

11,314
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

4,744
harborsb-helm-charts0.3.01 of 2See more

harbor sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.11.1c017dd84ee96
golang.org/x/oauth2@v0.19.0
0.27.0

Open the chart page →

1,680
mimirsb-helm-charts0.3.01 of 1See more

mimir sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/mimir:2.15.085f55510e0d3
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

888
opentelemetry-collectorsb-helm-charts0.3.01 of 1See more

opentelemetry-collector sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
golang.org/x/oauth2@v0.17.0
0.27.0

Open the chart page →

1,721
pushgatewaysb-helm-charts0.3.01 of 1See more

pushgateway sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,172
thanos-compactorsb-helm-charts0.3.01 of 1See more

thanos-compactor sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

961
thanos-querysb-helm-charts0.3.01 of 1See more

thanos-query sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

961
thanos-query-frontendsb-helm-charts0.3.01 of 1See more

thanos-query-frontend sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

961
thanos-receivesb-helm-charts0.3.01 of 1See more

thanos-receive sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

961
thanos-rulersb-helm-charts0.3.01 of 1See more

thanos-ruler sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

961
thanos-sidecarsb-helm-charts0.3.01 of 1See more

thanos-sidecar sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

961
thanos-storesb-helm-charts0.3.01 of 1See more

thanos-store sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

961
ed-traefikscaleway-charts0.2.01 of 1See more

ed-traefik scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/traefik:v1.7.345d47b7bb2546
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,133
ed-traefik2scaleway-charts0.2.01 of 1See more

ed-traefik2 scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/traefik:2.5.62f603f8d3abe
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0

Open the chart page →

3,160
cert-manager-webhook-cloudnsschichtelVerified publisher1.2.01 of 1See more

cert-manager-webhook-cloudns schichtel 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/pschichtel/cert-manager-webhook-cloudns:1.1.01020638bbe23
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,396
cosischichtelVerified publisher0.1.01 of 1See more

cosi schichtel 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/objectstorage-controller:v20221027-v0.1.1-8-g300019fa84b574e8027
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

1,309
cert-manager-desec-webhookschmitzis0.0.11 of 1See more

cert-manager-desec-webhook schmitzis 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
su541/cert-manager-desec-webhook:latest371ee33f83c1
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

1,770
cert-manager-webhook-bunnyschmitzis0.1.11 of 1See more

cert-manager-webhook-bunny schmitzis 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/schmitzis/cert-manager-webhook-bunny:latest125e31c8e85a
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

1,498
icinga2-masterschmitzis0.2.01 of 6See more

icinga2-master schmitzis 0.2.0

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:8.0.3696823fbc561
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0

Open the chart page →

3,731
version-checkerschmitzis0.2.21 of 1See more

version-checker schmitzis 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

3,023
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

4,109
cernboxsciencebox0.0.41 of 6See more

cernbox sciencebox 0.0.4

1 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/oauth2@v0.0.0-20220309155454-6242fa91716a
0.27.0

Open the chart page →

2,330
centralbrainsciencemeshVerified publisher0.0.32 of 5See more

centralbrain sciencemesh 0.0.3

2 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.3.315b977f5207d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/oauth2@v0.0.0-20200902213428-5d25da1a8d43
0.27.0

Open the chart page →

9,754
sealed-secrets-uisealed-secrets-uiVerified publisher0.0.81 of 1See more

sealed-secrets-ui sealed-secrets-ui 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

4,570
hermitcrabseal-ioVerified publisher0.1.41 of 2See more

hermitcrab seal-io 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

4,883
seaweedfs-operatorseaweedfs-operatorVerified publisher1.5.81 of 3See more

seaweedfs-operator seaweedfs-operator 1.5.8

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

2,092
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
leonardomulticloud/webhook:v1.0.0d119918900e8
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

5,499
secrets-bridgesecrets-bridge0.2.01 of 1See more

secrets-bridge secrets-bridge 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/haydercyber/secrets-bridge:0.2.04709f1bb3039
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

373
aws-secretssecretsprovider0.1.01 of 1See more

aws-secrets secretsprovider 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r1-10-g1942553-2021.06.04.00.07-linux-amd64b32c99e7bc45
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0

Open the chart page →

2,213
secret-syncsecret-syncVerified publisher0.1.111 of 1See more

secret-sync secret-sync 0.1.11

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
csepulvedab/secret-sync:0.5227a6f2b0ff8
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

1,442
cloudflaredsectionmeVerified publisher2022.3.41 of 1See more

cloudflared sectionme 2022.3.4

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,407
seldon-core-analyticsseldon1.17.12 of 8See more

seldon-core-analytics seldon 1.17.1

2 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
prom/prometheus:v2.18.15880ec936055
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

10,733
ansible-semaphoresergiotocaliniVerified publisher1.2.01 of 1See more

ansible-semaphore sergiotocalini 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.9.645b50bc11833f
golang.org/x/oauth2@v0.17.0
0.27.0

Open the chart page →

3,336
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

3,325
miniosergiotocaliniVerified publisher1.0.01 of 1See more

minio sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
golang.org/x/oauth2@v0.10.0
0.27.0

Open the chart page →

4,203
service-binding-operatorservice-binding-operator-helm-chart1.4.11 of 1See more

service-binding-operator service-binding-operator-helm-chart 1.4.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/redhat-developer/servicebinding-operatordigest-pinned16286ac84ddd
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

796
serviceexampleserviceexample0.1.01 of 5See more

serviceexample serviceexample 0.1.0

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
natsio/nats-box:0.13.559cf2e949181
golang.org/x/oauth2@v0.5.0
0.27.0

Open the chart page →

5,449
service-exampleservice-example-10.1.01 of 7See more

service-example service-example-1 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
natsio/nats-box:0.13.3c507bd7e3831
golang.org/x/oauth2@v0.3.0
0.27.0

Open the chart page →

9,074
ccx-monitoringseveralnines0.6.213 of 7See more

ccx-monitoring severalnines 0.6.21

3 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
victoriametrics/vmalert:v1.96.0150cd08fde94
golang.org/x/oauth2@v0.15.0
0.27.0
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/oauth2@v0.8.0
0.27.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

7,709
apache-shardingsphere-operator-chartsshardingsphere0.3.01 of 2See more

apache-shardingsphere-operator-charts shardingsphere 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,698
shopwareshopware-storeVerified publisher2.1.11 of 5See more

shopware shopware-store 2.1.1

1 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

4,890

Container images carrying it

2,031 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
9
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
8
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/oauth2@v0.24.0
0.27.0
8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0
8
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
7
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/oauth2@v0.23.0
0.27.0
7
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0
6
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
6
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/oauth2@v0.1.0
0.27.0
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
6
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/oauth2@v0.18.0
0.27.0
6
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/oauth2@v0.25.0
0.27.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/oauth2@v0.21.0
0.27.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/oauth2@v0.18.0
0.27.0
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/oauth2@v0.10.0
0.27.0
5
keelhq/keel:latest73714afb4443
golang.org/x/oauth2@v0.24.0
0.27.0
5
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/oauth2@v0.6.0
0.27.0
5
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
5
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/oauth2@v0.23.0
0.27.0
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/oauth2@v0.12.0
0.27.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/oauth2@v0.21.0
0.27.0
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
5
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/oauth2@v0.5.0
0.27.0
5
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
4
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
4
grafana/loki:2.6.11ee60f980950
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
4
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/oauth2@v0.10.0
0.27.0
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/oauth2@v0.8.0
0.27.0
4
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/oauth2@v0.12.0
0.27.0
4
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/oauth2@v0.12.0
0.27.0
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/oauth2@v0.12.0
0.27.0
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/oauth2@v0.12.0
0.27.0
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
4
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/oauth2@v0.18.0
0.27.0
4
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/oauth2@v0.25.0
0.27.0
4
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/oauth2@v0.15.0
0.27.0
4
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/oauth2@v0.24.0
0.27.0
4
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
3
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/oauth2@v0.13.0
0.27.0
3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
3

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.