StackRadar

CVE-2025-22868

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,634
of 17,787 indexed, latest versions
Container images
2,031
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Carried by container images the latest versions of 1,634 of 17,787 indexed charts deploy, on 2,031 images.

Affected packageAffected versionsFixed inImages
golang.org/x/oauth2golangv0.0.0-20170629032740-5432cc9688e6, v0.0.0-20170807180024-9a379c6b3e95, v0.0.0-20180620175406-ef147856a6dd, v0.0.0-20180724155351-3d292e4d0cdc+72 more0.27.02,031
OSV records
GHSA-6v2p-p543-phr9
Also known as
GO-2025-3488

Charts affected

1,634 by stars
ChartLatestAffected imagesRadar Score
nut-exportersi-gitops0.5.01 of 1See more

nut-exporter si-gitops 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/druggeri/nut_exporter:3.3.0276460d141c7
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

811
alertmanagersignoz0.5.21 of 1See more

alertmanager signoz 0.5.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
signoz/alertmanager:0.5.07bc7de2e33c2
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

2,181
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
golang.org/x/oauth2@v0.4.0
0.27.0

Open the chart page →

2,863
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
golang.org/x/oauth2@v0.14.0
0.27.0

Open the chart page →

2,316
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

2,381
olmsikalabs0.3.01 of 2See more

olm sikalabs 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned40d0363f4aa6
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

1,146
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

1,494
keydbsinextraVerified publisher0.31.01 of 1See more

keydb sinextra 0.31.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

2,165
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
golang.org/x/oauth2@v0.11.0
0.27.0

Open the chart page →

2,429
mimirskyloud-helm-chartsVerified publisher5.5.13 of 5See more

mimir skyloud-helm-charts 5.5.1

3 of the 5 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/mimir:r292-5f018727476e456c738
golang.org/x/oauth2@v0.19.0
0.27.0
grafana/rollout-operator:v0.14.03409edfb45c7
golang.org/x/oauth2@v0.17.0
0.27.0
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
golang.org/x/oauth2@v0.12.0
0.27.0

Open the chart page →

10,650
tailscale-operatorskyloud-helm-chartsVerified publisher1.70.31 of 1See more

tailscale-operator skyloud-helm-charts 1.70.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
tailscale/k8s-operator:v1.70.08edd06cf5bac
golang.org/x/oauth2@v0.16.0
0.27.0

Open the chart page →

1,045
skypilot-prometheus-serverskypilotVerified publisher0.11.11 of 3See more

skypilot-prometheus-server skypilot 0.11.1

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.15.0db384bf43222
golang.org/x/oauth2@v0.24.0
0.27.0

Open the chart page →

2,344
config-connector-templaterslamdev0.0.51 of 1See more

config-connector-templater slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
slamdev/config-connector-templater:0.0.3a234541c9fa8
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,110
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
golang.org/x/oauth2@v0.0.0-20201203001011-0b49973bad19
0.27.0

Open the chart page →

9,235
gke-preemptible-notifierslamdev0.0.61 of 1See more

gke-preemptible-notifier slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,860
octavia-ingress-controllerslamdev0.0.71 of 1See more

octavia-ingress-controller slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,761
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
golang.org/x/oauth2@v0.0.0-20181106182150-f42d05182288
0.27.0

Open the chart page →

8,697
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

3,462
cost-analyzersoftonic2.5.53 of 6See more

cost-analyzer softonic 2.5.5

3 of the 6 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
grafana/grafana:11.5.28b37a2f028f1
golang.org/x/oauth2@v0.25.0
0.27.0
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
golang.org/x/oauth2@v0.22.0
0.27.0
quay.io/prometheus/prometheus:v3.2.16927e0919a14
golang.org/x/oauth2@v0.25.0
0.27.0

Open the chart page →

7,935
csi-gcs-softonic-factorysoftonic0.9.31 of 4See more

csi-gcs-softonic-factory softonic 0.9.3

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ofekmeister/csi-gcs:v0.9.030d70fa9211b
golang.org/x/oauth2@v0.0.0-20220411215720-9780585627b5
0.27.0

Open the chart page →

1,842
harborsoftonic1.13.03 of 8See more

harbor softonic 1.13.0

3 of the 8 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
golang.org/x/oauth2@v0.5.0
0.27.0
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/oauth2@v0.5.0
0.27.0
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/oauth2@v0.7.0
0.27.0

Open the chart page →

7,672
kyvernosoftonic3.5.21 of 7See more

kyverno softonic 3.5.2

1 of the 7 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.32.73c5268158974
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

1,021
pod-defaultersoftonic0.1.31 of 1See more

pod-defaulter softonic 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
softonic/pod-defaulter:0.1.072017aed5902
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,561
policy-reportersoftonic2.18.21 of 1See more

policy-reporter softonic 2.18.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/kyverno/policy-reporter:2.14.1e74c6bf33d1b
golang.org/x/oauth2@v0.6.0
0.27.0

Open the chart page →

1,038
preemptible-killersoftonic1.2.61 of 1See more

preemptible-killer softonic 1.2.6

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
softonic/preemptible-killer:1.2.6-294b87f1fb362
golang.org/x/oauth2@v0.0.0-20170807180024-9a379c6b3e95
0.27.0

Open the chart page →

2,338
rate-limit-operatorsoftonic1.1.01 of 2See more

rate-limit-operator softonic 1.1.0

1 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
softonic/rate-limit-operator:0.1.1910f6de37763
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,219
rclonesoftonic2.1.01 of 1See more

rclone softonic 2.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
rclone/rclone:1.6874c51b8817e5
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,672
redis-operatorsoftonic0.18.01 of 1See more

redis-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/ot-container-kit/redis-operator/redis-operator:v0.18.090bfeb2e0d71
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

551
sealed-secretssoftonic2.6.91 of 1See more

sealed-secrets softonic 2.6.9

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
golang.org/x/oauth2@v0.0.0-20220223155221-ee480838109b
0.27.0

Open the chart page →

1,515
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
golang.org/x/oauth2@v0.8.0
0.27.0

Open the chart page →

2,505
gloo-meshsolo-gloo-mesh1.1.21 of 1See more

gloo-mesh solo-gloo-mesh 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/gloo-mesh/gloo-mesh:1.1.2a4011eae6a0b
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0

Open the chart page →

3,259
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0

Open the chart page →

30,759
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
golang.org/x/oauth2@v0.23.0
0.27.0

Open the chart page →

3,272
spire-identity-exchangespiffeVerified publisher0.2.21 of 3See more

spire-identity-exchange spiffe 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.099b37df34bc4
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

1,429
spinnakerspinnakerVerified publisher2.2.131 of 4See more

spinnaker spinnaker 2.2.13

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
golang.org/x/oauth2@v0.0.0-20190402181905-9f3314589c9a
0.27.0

Open the chart page →

6,836
ocean-admission-controllerspot1.0.31 of 3See more

ocean-admission-controller spot 1.0.3

1 of the 3 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/oauth2@v0.21.0
0.27.0

Open the chart page →

773
ocean-vpaspot1.0.71 of 4See more

ocean-vpa spot 1.0.7

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.136d05b4077fb
golang.org/x/oauth2@v0.18.0
0.27.0

Open the chart page →

1,195
spotinst-ocean-network-clientspot1.0.01 of 1See more

spotinst-ocean-network-client spot 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0

Open the chart page →

6,955
airflowsqream-chartsVerified publisher1.17.01 of 4See more

airflow sqream-charts 1.17.0

1 of the 4 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/prometheus/statsd-exporter:v0.27.29ed70604d941
golang.org/x/oauth2@v0.22.0
0.27.0

Open the chart page →

1,843
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
golang.org/x/oauth2@v0.15.0
0.27.0

Open the chart page →

2,415
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
golang.org/x/oauth2@v0.2.0
0.27.0

Open the chart page →

65,130
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

3,096
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

28,165
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/oauth2@v0.0.0-20210413134643-5e61552d6c78
0.27.0

Open the chart page →

2,081
k8scostoptimizerstakaterVerified publisher0.0.51 of 1See more

k8scostoptimizer stakater 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0

Open the chart page →

1,408
konfiguratorstakaterVerified publisher0.1.391 of 1See more

konfigurator stakater 0.1.39

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
stakater/konfigurator:v0.1.393409565b1ef5
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

1,279
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/oauth2@v0.0.0-20191122200657-5d9234df094c
0.27.0

Open the chart page →

2,853
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

2,173
vaultstakaterVerified publisher0.8.42 of 2See more

vault stakater 0.8.4

2 of the 2 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
hashicorp/vault-k8s:0.14.0aff47b5ba39c
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0

Open the chart page →

5,864
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2025-22868.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0

Open the chart page →

2,564

Container images carrying it

2,031 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/oauth2@v0.18.0
0.27.0
9
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
8
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/oauth2@v0.24.0
0.27.0
8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/oauth2@v0.16.0
0.27.0
8
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/oauth2@v0.0.0-20210819190943-2bc19b11175f
0.27.0
7
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/oauth2@v0.23.0
0.27.0
7
clastix/kubectl:v1.3122918a06c253
golang.org/x/oauth2@v0.21.0
0.27.0
6
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/oauth2@v0.0.0-20210628180205-a41e5a781914
0.27.0
6
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/oauth2@v0.1.0
0.27.0
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
6
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/oauth2@v0.18.0
0.27.0
6
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/oauth2@v0.25.0
0.27.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/oauth2@v0.23.0
0.27.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/oauth2@v0.21.0
0.27.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/oauth2@v0.18.0
0.27.0
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/oauth2@v0.10.0
0.27.0
5
keelhq/keel:latest73714afb4443
golang.org/x/oauth2@v0.24.0
0.27.0
5
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/oauth2@v0.6.0
0.27.0
5
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
5
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/oauth2@v0.23.0
0.27.0
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/oauth2@v0.0.0-20210514164344-f6687ab2804c
0.27.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/oauth2@v0.12.0
0.27.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/oauth2@v0.21.0
0.27.0
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
5
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/oauth2@v0.5.0
0.27.0
5
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
4
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/oauth2@v0.0.0-20190604053449-0f29369cfe45
0.27.0
4
grafana/loki:2.6.11ee60f980950
golang.org/x/oauth2@v0.0.0-20211104180415-d3ed0bb246c8
0.27.0
4
ghcr.io/curium-rocks/docker-kubectl:maind04c003d7593
golang.org/x/oauth2@v0.10.0
0.27.0
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/oauth2@v0.8.0
0.27.0
4
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/oauth2@v0.12.0
0.27.0
4
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/oauth2@v0.12.0
0.27.0
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/oauth2@v0.12.0
0.27.0
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/oauth2@v0.12.0
0.27.0
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/oauth2@v0.0.0-20220909003341-f21342109be1
0.27.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/oauth2@v0.0.0-20200107190931-bf48bf16ab8d
0.27.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/oauth2@v0.0.0-20210402161424-2e8d93401602
0.27.0
4
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/oauth2@v0.18.0
0.27.0
4
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/oauth2@v0.25.0
0.27.0
4
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/oauth2@v0.15.0
0.27.0
4
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/oauth2@v0.24.0
0.27.0
4
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/oauth2@v0.0.0-20191202225959-858c2ad4c8b6
0.27.0
3
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/oauth2@v0.13.0
0.27.0
3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
golang.org/x/oauth2@v0.0.0-20210313182246-cd4f82c27b84
0.27.0
3

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.