StackRadar

CVE-2025-22869

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,686
of 17,790 indexed, latest versions
Container images
1,951
deployed by those charts
Fix available
8 of 8
affected packages

golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key Exchange

Carried by container images the latest versions of 1,686 of 17,790 indexed charts deploy, on 1,951 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+137 more0.35.01,951
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-82.module+el8.10.0+22931+799fd8061
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+22931+799fd8061
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+22931+799fd8061
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+22931+799fd8061
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-6.module+el8.10.0+22931+799fd8061
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.5-3.module+el8.10.0+22931+799fd8061
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+22931+799fd8061
OSV records
GHSA-hcg3-q754-cr77RHSA-2025:3210
Also known as
GO-2025-3487, RHSA-2025:3268

Charts affected

1,686 by stars
ChartLatestAffected imagesRadar Score
csi-qingcloudkubesphere-stable1.4.03 of 6See more

csi-qingcloud kubesphere-stable 1.4.0

3 of the 6 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.35.0
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.35.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/crypto@v0.0.0-20210317152858-513c2a44f670
0.35.0

Open the chart page →

12,444
deepflowkubesphere-stable6.2.6063 of 8See more

deepflow kubesphere-stable 6.2.606

3 of the 8 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
golang.org/x/crypto@v0.1.0
0.35.0
deepflowce/deepflowio-init-grafana:v6.2.6.56b51a0206b04
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.35.0
grafana/grafana:9.5.239c849cebccc
golang.org/x/crypto@v0.4.0
0.35.0

Open the chart page →

18,420
edgemeshkubesphere-stable0.1.02 of 2See more

edgemesh kubesphere-stable 0.1.0

2 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
kubeedge/edgemesh-agent:latest460c6061b608
golang.org/x/crypto@v0.7.0
0.35.0
kubeedge/edgemesh-server:latesta437cf5ec0ae
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.35.0

Open the chart page →

4,108
fpga-operatorkubesphere-stable2.7.42 of 7See more

fpga-operator kubesphere-stable 2.7.4

2 of the 7 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
inaccel/daemon:latest093e1ea90ab8
golang.org/x/crypto@v0.16.0
0.35.0
inaccel/reef:latestc967218739f3
golang.org/x/crypto@v0.17.0
0.35.0

Open the chart page →

5,770
iomeshkubesphere-stable1.1.011 of 25See more

iomesh kubesphere-stable 1.1.0

11 of the 25 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.1.0d86dab5611a7
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.35.0
iomesh/blockdevice-monitor-prober:v0.1.0584dbe19db7e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.35.0
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/crypto@v0.0.0-20210317152858-513c2a44f670
0.35.0
iomesh/deck:v0.1.0a31e26b6ae22
golang.org/x/crypto@v0.16.0
0.35.0
iomesh/deck-plugin-iomesh:v0.1.00b13bf217110
golang.org/x/crypto@v0.16.0
0.35.0
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.35.0
iomesh/node-disk-exporter:1.8.0f03148764f38
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
iomesh/node-disk-manager:1.8.0002c4b92fd34
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
iomesh/node-disk-operator:1.8.0f6c76380db34
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
iomesh/operator:v1.1.060081c9b2f52
golang.org/x/crypto@v0.14.0
0.35.0
iomesh/post-delete-hook:v1.1.0eea5651f3270
golang.org/x/crypto@v0.14.0
0.35.0

Open the chart page →

48,954
IOMeshkubesphere-stable1.2.011 of 25See more

IOMesh kubesphere-stable 1.2.0

11 of the 25 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
iomesh/blockdevice-monitor-prober:v0.2.1026a1d87f6e9
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/crypto@v0.0.0-20210317152858-513c2a44f670
0.35.0
iomesh/deck:v0.2.0282d6c419ed3
golang.org/x/crypto@v0.16.0
0.35.0
iomesh/deck-plugin-iomesh:v0.2.0df149e4ab39f
golang.org/x/crypto@v0.16.0
0.35.0
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.35.0
iomesh/node-disk-exporter:1.8.0f03148764f38
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
iomesh/node-disk-manager:1.8.0-2292ad270082e
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
iomesh/operator:v1.2.0ba4dd6be7e59
golang.org/x/crypto@v0.14.0
0.35.0
iomesh/post-delete-hook:v1.2.0e3b92f838f4b
golang.org/x/crypto@v0.14.0
0.35.0

Open the chart page →

46,639
pulsarkubesphere-stable2.7.132 of 3See more

pulsar kubesphere-stable 2.7.13

2 of the 3 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
prom/prometheus:v2.17.242d2395cd719
golang.org/x/crypto@v0.0.0-20191206172530-e9b2fee46413
0.35.0
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.35.0

Open the chart page →

14,401
csi-neonsankubesphere-testVerified publisher1.3.03 of 6See more

csi-neonsan kubesphere-test 1.3.0

3 of the 6 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
csiplugin/csi-neonsan:v1.2.21fa83d45417f
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.35.0
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.35.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/crypto@v0.0.0-20210317152858-513c2a44f670
0.35.0

Open the chart page →

18,526
csi-qingcloudkubesphere-testVerified publisher1.4.03 of 6See more

csi-qingcloud kubesphere-test 1.4.0

3 of the 6 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.35.0
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.35.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/crypto@v0.0.0-20210317152858-513c2a44f670
0.35.0

Open the chart page →

12,444
openelbkubesphere-testVerified publisher0.2.41 of 2See more

openelb kubesphere-test 0.2.4

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.4.4ed7311a0f9e4
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.35.0

Open the chart page →

4,336
porterkubesphere-testVerified publisher0.2.21 of 2See more

porter kubesphere-test 0.2.2

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
kubesphere/porter:v0.4.38d1ed5ee1d2e
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.35.0

Open the chart page →

2,791
snapshot-controllerkubesphere-testVerified publisher0.2.01 of 1See more

snapshot-controller kubesphere-test 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.35.0

Open the chart page →

2,220
kubestellar-consolekubestellar-consoleVerified publisher0.3.411 of 2See more

kubestellar-console kubestellar-console 0.3.41

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
alpine/k8s:1.32.47e1e7d5b7a96
golang.org/x/crypto@v0.5.0
0.35.0

Open the chart page →

4,456
kubestellar-uikubestellaruiVerified publisher0.1.11 of 4See more

kubestellar-ui kubestellarui 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
mavrick1/kubestellar-b:latest45ca0429a1d4
golang.org/x/crypto@v0.5.0
0.35.0

Open the chart page →

4,773
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.44 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

4 of the 9 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
grafana/alloy:v1.5.101a63f4e032c
golang.org/x/crypto@v0.29.0
0.35.0
ghcr.io/kubiyabot/kubernetes:1.32.0b5ade0d9cc6b
golang.org/x/crypto@v0.31.0
0.35.0
ghcr.io/kubiyabot/kubiya-operator:runner_v26bf945565865
golang.org/x/crypto@v0.26.0
0.35.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/crypto@v0.28.0
0.35.0

Open the chart page →

20,386
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
golang.org/x/crypto@v0.29.0
0.35.0

Open the chart page →

6,913
operatingkusionstackVerified publisher0.5.11 of 1See more

operating kusionstack 0.5.1

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
kusionstack/operating:v0.5.0c28bd96b986b
golang.org/x/crypto@v0.14.0
0.35.0

Open the chart page →

1,881
longhornkvalitetsitVerified publisher1.1.1-01 of 2See more

longhorn kvalitetsit 1.1.1-0

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.35.0

Open the chart page →

16,539
kvkkvkservice0.1.01 of 4See more

kvk kvkservice 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
conduction/kvk-php:dev8f177f9f8a7b
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.35.0

Open the chart page →

8,543
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
kubeoperator/webkubectl:v2.4.0be8f0d624640
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.35.0

Open the chart page →

26,377
lambdapinglambdaping1.0.41 of 1See more

lambdaping lambdaping 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
udhos/lambdaping:1.0.46bd2cf2ac732
golang.org/x/crypto@v0.31.0
0.35.0

Open the chart page →

1,337
cachelavaOfficialVerified publisher1.1.11 of 1See more

cache lava 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/lavanet/lava/lavap:v2.5.089028adefcff
golang.org/x/crypto@v0.21.0
0.35.0

Open the chart page →

1,385
metallblectures-k8sinfra0.10.22 of 2See more

metallb lectures-k8sinfra 0.10.2

2 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.10.221164241c045
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
quay.io/metallb/speaker:v0.10.258cb99053bb3
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0

Open the chart page →

5,406
prometheuslectures-k8sinfra15.8.54 of 6See more

prometheus lectures-k8sinfra 15.8.5

4 of the 6 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.35.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.35.0
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.35.0
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
golang.org/x/crypto@v0.0.0-20220511200225-c6db032c6c88
0.35.0

Open the chart page →

9,100
grafanaleechistest5.3.01 of 1See more

grafana leechistest 5.3.0

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/crypto@v0.0.0-20200406173513-056763e48d71
0.35.0

Open the chart page →

3,198
prometheusleechistest11.6.03 of 6See more

prometheus leechistest 11.6.0

3 of the 6 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/crypto@v0.0.0-20190617133340-57b3e21c3d56
0.35.0
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/crypto@v0.0.0-20200422194213-44a606286825
0.35.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.35.0

Open the chart page →

8,491
kube-benchlemontechVerified publisher0.1.01 of 1See more

kube-bench lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.6.9c329d73fea58
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.35.0

Open the chart page →

1,632
trivy-serverlemontechVerified publisher0.1.01 of 1See more

trivy-server lemontech 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
aquasec/trivy:0.32.0973d0df16189
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.35.0

Open the chart page →

4,280
minioleprechaun-charts0.1.61 of 1See more

minio leprechaun-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-01-20T14-49-07Z-cpuv114b7076ca85a
golang.org/x/crypto@v0.32.0
0.35.0

Open the chart page →

1,319
kltlifecycle-toolkitOfficialVerified publisher0.2.62 of 4See more

klt lifecycle-toolkit 0.2.6

2 of the 4 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/keptn/metrics-operator:v0.8.2acf22310e9dd
golang.org/x/crypto@v0.12.0
0.35.0
ghcr.io/keptn/scheduler:v0.8.20f7d277bb2b2
golang.org/x/crypto@v0.12.0
0.35.0

Open the chart page →

4,680
kube-iptables-tailerlifen0.2.31 of 1See more

kube-iptables-tailer lifen 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.35.0

Open the chart page →

4,459
op-scim-bridgelifen1.0.31 of 2See more

op-scim-bridge lifen 1.0.3

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
golang.org/x/crypto@v0.0.0-20220131195533-30dcbda58838
0.35.0

Open the chart page →

2,777
op-scim-bridgelifen-chartsVerified publisher1.0.31 of 2See more

op-scim-bridge lifen-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
1password/scim:v2.3.129d0c6cb67eb
golang.org/x/crypto@v0.0.0-20220131195533-30dcbda58838
0.35.0

Open the chart page →

2,777
lightsteplightstep-microsat2.0.211 of 1See more

lightstep lightstep-microsat 2.0.21

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
lightstep/microsatellite:2024-01-22_17-52-59Zc800e05e1eff
golang.org/x/crypto@v0.18.0
0.35.0

Open the chart page →

1,127
linkerd-preview-vizlinkerd-buoyantVerified publisher25.4.31 of 5See more

linkerd-preview-viz linkerd-buoyant 25.4.3

1 of the 5 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/crypto@v0.26.0
0.35.0

Open the chart page →

3,454
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
golang.org/x/crypto@v0.17.0
0.35.0

Open the chart page →

10,780
livekit-recorderlivekit-server0.3.131 of 1See more

livekit-recorder livekit-server 0.3.13

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
livekit/livekit-recorder:v0.3.13ecf1409c75e0
golang.org/x/crypto@v0.0.0-20210314154223-e6e6c4f2bb5b
0.35.0

Open the chart page →

2,135
home-assistantlmatfyVerified publisher0.1.381 of 1See more

home-assistant lmatfy 0.1.38

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2026.75a531753cea9
golang.org/x/crypto@v0.26.0
0.35.0

Open the chart page →

2,450
otlp-gatewayloafoe0.0.21 of 2See more

otlp-gateway loafoe 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
golang.org/x/crypto@v0.25.0
0.35.0

Open the chart page →

2,162
patch-operatorloafoe0.11.31 of 2See more

patch-operator loafoe 0.11.3

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.35.0

Open the chart page →

4,911
solgateloafoe0.0.121 of 1See more

solgate loafoe 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/crypto@v0.12.0
0.35.0

Open the chart page →

2,108
tempo-distributedloafoe1.20.11 of 2See more

tempo-distributed loafoe 1.20.1

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
grafana/tempo:2.6.0f55a8a1937ff
golang.org/x/crypto@v0.25.0
0.35.0

Open the chart page →

2,027
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-auth-go:latest6597b26959d2
golang.org/x/crypto@v0.9.0
0.35.0

Open the chart page →

5,905
ocatiecataloguslocatiecatalogus1.0.01 of 3See more

ocatiecatalogus locatiecatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.35.0

Open the chart page →

7,519
locust-pluginslocust-pluginsVerified publisher0.0.42 of 3See more

locust-plugins locust-plugins 0.0.4

2 of the 3 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
sky5367/locust-plugins-grafana:latestd51bf68d4b26
golang.org/x/crypto@v0.21.0
0.35.0
sky5367/locust-plugins-timescale:latestd3150f201471
golang.org/x/crypto@v0.20.0
0.35.0

Open the chart page →

7,534
central-hostpath-mapperloftVerified publisher0.2.91 of 1See more

central-hostpath-mapper loft 0.2.9

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/central-hostpath-mapper:0.2.9fa6dba122171
golang.org/x/crypto@v0.24.0
0.35.0

Open the chart page →

924
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/crypto@v0.14.0
0.35.0

Open the chart page →

3,234
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/crypto@v0.0.0-20200128174031-69ecbb4d6d5d
0.35.0

Open the chart page →

9,888
kioskloftVerified publisher0.2.111 of 1See more

kiosk loft 0.2.11

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
kiosksh/kiosk:0.2.11501725ba2025
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.35.0

Open the chart page →

3,094
loft-agentloftVerified publisher3.2.41 of 1See more

loft-agent loft 3.2.4

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/crypto@v0.5.0
0.35.0

Open the chart page →

2,453

Container images carrying it

1,951 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
iotaledger/goshimmer:v0.8.6b02a8f77474f
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.35.0
1
iotaledger/hornet:2.001206f1ba89c
golang.org/x/crypto@v0.12.0
0.35.0
1
iotaledger/inx-dashboard:1.012c669cb8748
golang.org/x/crypto@v0.12.0
0.35.0
1
ipfs/go-ipfs:v0.13.117259397f587
golang.org/x/crypto@v0.0.0-20220518034528-6f7dac969898
0.35.0
1
ipfs/ipfs-cluster:1.0.21511f6d57994
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.35.0
1
ipfs/kubo:v0.17.0803fac58ba15
golang.org/x/crypto@v0.1.0
0.35.0
1
ipfs/kubo:v0.24.0e3de33bd746b
golang.org/x/crypto@v0.14.0
0.35.0
1
ipushc/cassandra-web:latestfa3e0c66c289
golang.org/x/crypto@v0.7.0
0.35.0
1
istio/install-cni:1.10.32232f365aed6
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.35.0
1
istio/operator:1.10.3655eefa11c84
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.35.0
1
istio/operator:1.12.06cfce8a071b9
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.35.0
1
istio/operator:1.18.270f9d1fe5fff
golang.org/x/crypto@v0.9.0
0.35.0
1
istio/pilot:1.10.0294ca55bd1cc
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.35.0
1
istio/pilot:1.16.0ac0284d75ec9
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.35.0
1
istio/pilot:1.17.1ce9d87606701
golang.org/x/crypto@v0.5.0
0.35.0
1
istio/pilot:1.15.2db08d6963975
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.35.0
1
istio/pilot:1.10.3e7e110a421c2
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.35.0
1
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.35.0
1
istio/proxyv2:1.10.088c6c693e67a
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.35.0
1
istio/proxyv2:1.14.1df69c1a7af7c
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.35.0
1
itzg/mc-router:1.16.1bb552b59fb53
golang.org/x/crypto@v0.0.0-20210915214749-c084706c2272
0.35.0
1
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.35.0
1
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.35.0
1
jaegertracing/all-in-one:1.2942822be7888b
golang.org/x/crypto@v0.0.0-20210920023735-84f357641f63
0.35.0
1
jaegertracing/all-in-one:1.53.060e65bfffe1f
golang.org/x/crypto@v0.17.0
0.35.0
1
jaegertracing/all-in-one:1.42.07d32a4eddec7
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.35.0
1
jaegertracing/all-in-one:1.22.0ca6b73330616
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.35.0
1
jaegertracing/all-in-one:1.18db45c07f2e1b
golang.org/x/crypto@v0.0.0-20200214034016-1d94cc7ab1c6
0.35.0
1
jaegertracing/all-in-one:1.55f6b5d09073f1
golang.org/x/crypto@v0.19.0
0.35.0
1
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.35.0
1
jaegertracing/jaeger-query:1.41.0b636f0f464bc
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.35.0
1
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
golang.org/x/crypto@v0.27.0
0.35.0
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
golang.org/x/crypto@v0.17.0
0.35.0
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
golang.org/x/crypto@v0.17.0
0.35.0
1
jfwenisch/alpine-tor:latest9e6c229f953c
golang.org/x/crypto@v0.0.0-20190325154230-a5d413f7728c
0.35.0
1
jhaals/yopass:11.17.026873480863b
golang.org/x/crypto@v0.28.0
0.35.0
1
jhaals/yopass:11.15.16bca8d5a4914
golang.org/x/crypto@v0.14.0
0.35.0
1
jhaals/yopass:11.4.69516e3b3e88c
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.35.0
1
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
golang.org/x/crypto@v0.1.0
0.35.0
1
jkremser/log2rbac:v0.0.5e35cf56ef183
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.35.0
1
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/crypto@v0.0.0-20191028145041-f83a4685e152
0.35.0
1
joeelliott/cert-exporter:v2.7.0b4acd14642d0
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.35.0
1
juicedata/csi-dashboard:v0.23.03e4daf9626d5
golang.org/x/crypto@v0.14.0
0.35.0
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
golang.org/x/crypto@v0.6.0
0.35.0
1
juicedata/juicefs-csi-driver:v0.23.0d915e899e322
golang.org/x/crypto@v0.14.0
0.35.0
1
junktext/getting-started:1.0.5a70936c04aed
golang.org/x/crypto@v0.4.0
0.35.0
1
justusbunsi/gitea-sonarqube-bot:v0.4.018dd43b470d9
golang.org/x/crypto@v0.29.0
0.35.0
1
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
1
keelhq/keel:0.19.202ac4ea616c4
golang.org/x/crypto@v0.5.0
0.35.0
1
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/crypto@v0.0.0-20191206172530-e9b2fee46413
0.35.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.