StackRadar

CVE-2025-22869

High

Advisory

Published 26 Feb 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.009
58th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,684
of 17,787 indexed, latest versions
Container images
1,948
deployed by those charts
Fix available
8 of 8
affected packages

golang.org/x/crypto Vulnerable to Denial of Service (DoS) via Slow or Incomplete Key Exchange

Carried by container images the latest versions of 1,684 of 17,787 indexed charts deploy, on 1,948 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+137 more0.35.01,948
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-82.module+el8.10.0+22931+799fd8061
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+22931+799fd8061
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+22931+799fd8061
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+22931+799fd8061
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-6.module+el8.10.0+22931+799fd8061
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.5-3.module+el8.10.0+22931+799fd8061
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+22931+799fd8061
OSV records
GHSA-hcg3-q754-cr77RHSA-2025:3210
Also known as
GO-2025-3487, RHSA-2025:3268

Charts affected

1,684 by stars
ChartLatestAffected imagesRadar Score
vcluster-proloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.35.0
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/crypto@v0.5.0
0.35.0

Open the chart page →

5,085
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.102 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

2 of the 4 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/crypto@v0.5.0
0.35.0
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.35.0

Open the chart page →

5,936
vcluster-pro-k0sloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro-k0s loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
golang.org/x/crypto@v0.5.0
0.35.0
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/crypto@v0.5.0
0.35.0

Open the chart page →

5,770
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.104 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

4 of the 4 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
golang.org/x/crypto@v0.5.0
0.35.0
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.35.0
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/crypto@v0.1.0
0.35.0
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/crypto@v0.1.0
0.35.0

Open the chart page →

8,206
virtualclusterloftVerified publisher0.0.281 of 2See more

virtualcluster loft 0.0.28

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0

Open the chart page →

2,986
loggingcomponentloggingcomponent1.0.01 of 3See more

loggingcomponent loggingcomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.35.0

Open the chart page →

7,492
nightingalelogic3579Verified publisher0.3.11 of 6See more

nightingale logic3579 0.3.1

1 of the 6 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/crypto@v0.25.0
0.35.0

Open the chart page →

9,021
logicservicelogicservice1.0.01 of 4See more

logicservice logicservice 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.35.0

Open the chart page →

7,498
login-test-backendlogin-test-backend0.1.01 of 2See more

login-test-backend login-test-backend 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
aboogie/login_test_backend:new9c41a4483ac8
golang.org/x/crypto@v0.26.0
0.35.0

Open the chart page →

5,970
apica-ascentlogiqai2.0.45 of 19See more

apica-ascent logiqai 2.0.4

5 of the 19 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
golang.org/x/crypto@v0.18.0
0.35.0
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.35.0
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.35.0
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/crypto@v0.0.0-20200214034016-1d94cc7ab1c6
0.35.0
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.35.0

Open the chart page →

23,255
logtidelogtideVerified publisher2.1.141 of 4See more

logtide logtide 2.1.14

1 of the 4 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg156343bdc87ca1
golang.org/x/crypto@v0.32.0
0.35.0

Open the chart page →

2,775
chronograflsst-sqre1.3.51 of 1See more

chronograf lsst-sqre 1.3.5

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.35.0

Open the chart page →

2,342
sasquatchlsst-sqre0.1.132 of 6See more

sasquatch lsst-sqre 0.1.13

2 of the 6 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
library/kapacitor:1.6.37232f6388a4d
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.35.0
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.35.0

Open the chart page →

9,332
telegraf-dslsst-sqre1.0.231 of 1See more

telegraf-ds lsst-sqre 1.0.23

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.35.0

Open the chart page →

3,764
kube-benchm9sweeperVerified publisher1.6.01 of 1See more

kube-bench m9sweeper 1.6.0

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.6.176672264accce
golang.org/x/crypto@v0.4.0
0.35.0

Open the chart page →

1,400
m9sweeperm9sweeperVerified publisher1.6.02 of 6See more

m9sweeper m9sweeper 1.6.0

2 of the 6 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
kubesec/kubesec:v2.13.0c0f3b0673578
golang.org/x/crypto@v0.6.0
0.35.0
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
golang.org/x/crypto@v0.17.0
0.35.0

Open the chart page →

9,786
magistralamagistrala-devopsVerified publisher0.16.211 of 42See more

magistrala magistrala-devops 0.16.2

11 of the 42 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
jaegertracing/jaeger-collector:1.53.07f1269222903
golang.org/x/crypto@v0.17.0
0.35.0
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
golang.org/x/crypto@v0.17.0
0.35.0
library/nats:2.10.17-alpineb7752304692b
golang.org/x/crypto@v0.24.0
0.35.0
natsio/nats-box:0.14.31cc420186664
golang.org/x/crypto@v0.9.0
0.35.0
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/crypto@v0.31.0
0.35.0
timescale/timescaledb:latest-pg12645fd9e92d76
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.35.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/crypto@v0.31.0
0.35.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/crypto@v0.21.0
0.35.0
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/crypto@v0.31.0
0.35.0
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/crypto@v0.32.0
0.35.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/crypto@v0.28.0
0.35.0

Open the chart page →

24,488
kruisematrixone-operatorVerified publisher1.8.31 of 2See more

kruise matrixone-operator 1.8.3

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
openkruise/kruise-manager:v1.8.30482722b4e56
golang.org/x/crypto@v0.31.0
0.35.0

Open the chart page →

1,767
matrix-sliding-syncmatrix-sliding-sync0.2.31 of 1See more

matrix-sliding-sync matrix-sliding-sync 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
golang.org/x/crypto@v0.14.0
0.35.0

Open the chart page →

1,592
focalboardmattermostVerified publisher0.5.01 of 1See more

focalboard mattermost 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
mattermost/focalboard:0.6.7f2f987dada52
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.35.0

Open the chart page →

4,014
mattermost-calls-offloadermattermostVerified publisher0.2.11 of 1See more

mattermost-calls-offloader mattermost 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
mattermost/calls-offloader:v0.9.0b440b282599e
golang.org/x/crypto@v0.16.0
0.35.0

Open the chart page →

1,414
mattermost-chaos-enginemattermostVerified publisher0.2.01 of 1See more

mattermost-chaos-engine mattermost 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
mattermost/mattermost-app-chaosengine:c153e436268954edd67
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.35.0

Open the chart page →

4,067
mattermost-push-proxymattermostVerified publisher0.14.31 of 1See more

mattermost-push-proxy mattermost 0.14.3

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
mattermost/mattermost-push-proxy:6.3.045c53061c74e
golang.org/x/crypto@v0.22.0
0.35.0

Open the chart page →

890
mayastormayastorVerified publisher2.12.15 of 31See more

mayastor mayastor 2.12.1

5 of the 31 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
grafana/loki:3.4.258a6c186ce78
golang.org/x/crypto@v0.32.0
0.35.0
library/nats:2.9.17-alpine1a7b320b2942
golang.org/x/crypto@v0.8.0
0.35.0
natsio/prometheus-nats-exporter:0.11.031c02aac089a
golang.org/x/crypto@v0.8.0
0.35.0
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
golang.org/x/crypto@v0.27.0
0.35.0
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/crypto@v0.27.0
0.35.0

Open the chart page →

21,178
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.35.0

Open the chart page →

29,712
medewerkercatalogusmedewerkercatalogus1.0.01 of 3See more

medewerkercatalogus medewerkercatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.35.0

Open the chart page →

7,327
cameramedia-streaming-meshVerified publisher0.2.51 of 3See more

camera media-streaming-mesh 0.2.5

1 of the 3 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.35.0

Open the chart page →

18,712
msmmedia-streaming-meshVerified publisher0.1.171 of 6See more

msm media-streaming-mesh 0.1.17

1 of the 6 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
golang.org/x/crypto@v0.24.0
0.35.0

Open the chart page →

11,478
msm-rtspmedia-streaming-meshVerified publisher0.0.21 of 2See more

msm-rtsp media-streaming-mesh 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.35.0

Open the chart page →

18,712
rtspmedia-streaming-meshVerified publisher0.0.141 of 2See more

rtsp media-streaming-mesh 0.0.14

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.35.0

Open the chart page →

18,712
mediawiki-backupmediawiki-backupVerified publisher0.2.11 of 1See more

mediawiki-backup mediawiki-backup 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.35.0

Open the chart page →

1,919
memo-componentmemo-component1.0.01 of 3See more

memo-component memo-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/memo-component-php:latestef77f4c089a1
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.35.0

Open the chart page →

7,510
dex-k8s-authenticatormesosphere1.4.31 of 1See more

dex-k8s-authenticator mesosphere 1.4.3

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
mesosphere/dex-k8s-authenticator:v1.4.1-d2iqf3d9982cc2fd
golang.org/x/crypto@v0.11.0
0.35.0

Open the chart page →

1,019
flaggermesosphere0.21.01 of 2See more

flagger mesosphere 0.21.0

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
weaveworks/flagger:0.19.0a9c2e9df4227
golang.org/x/crypto@v0.0.0-20181025213731-e84da0312774
0.35.0

Open the chart page →

6,048
gatekeepermesosphere0.6.111 of 2See more

gatekeeper mesosphere 0.6.11

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.35.0

Open the chart page →

3,034
kafka-operatormesosphere0.20.21 of 2See more

kafka-operator mesosphere 0.20.2

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/kafka-operator:v0.20.2e341aefa9a90
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.35.0

Open the chart page →

1,884
kubeaddons-catalogmesosphere0.1.161 of 2See more

kubeaddons-catalog mesosphere 0.1.16

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.35.0

Open the chart page →

12,049
kubefedmesosphere0.5.21 of 1See more

kubefed mesosphere 0.5.2

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
mesosphere/kubefed:proxyurl4fd8889195fe
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.35.0

Open the chart page →

3,144
kube-oidc-proxymesosphere0.3.41 of 1See more

kube-oidc-proxy mesosphere 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.35.0

Open the chart page →

3,144
kudomesosphere0.1.41 of 1See more

kudo mesosphere 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
kudobuilder/controller:v0.9.069072d979708
golang.org/x/crypto@v0.0.0-20190923035154-9ee001bba392
0.35.0

Open the chart page →

5,688
local-path-provisionermesosphere0.0.221 of 1See more

local-path-provisioner mesosphere 0.0.22

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.22e34c88ae0aff
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
0.35.0

Open the chart page →

2,317
nfs-server-provisionermesosphere0.6.11 of 1See more

nfs-server-provisioner mesosphere 0.6.1

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.35.0

Open the chart page →

2,806
prometheus-operatormesosphere12.11.133 of 8See more

prometheus-operator mesosphere 12.11.13

3 of the 8 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.35.0
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.35.0

Open the chart page →

11,690
traefik2mesosphere9.18.01 of 1See more

traefik2 mesosphere 9.18.0

1 of the 1 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
library/traefik:2.4.8eda951fd29a8
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.35.0

Open the chart page →

3,341
azuredisk-csi-drivermesosphere-stable0.8.14 of 6See more

azuredisk-csi-driver mesosphere-stable 0.8.1

4 of the 6 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.35.0
mcr.microsoft.com/oss/kubernetes-csi/csi-provisioner:v1.6.1667b1b1ea1e4
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.35.0
mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.1.07997e0f236bc
golang.org/x/crypto@v0.0.0-20201217014255-9d1352758620
0.35.0

Open the chart page →

14,067
cert-manager-setupmesosphere-stable0.2.103 of 5See more

cert-manager-setup mesosphere-stable 0.2.10

3 of the 5 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/crypto@v0.5.0
0.35.0
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/crypto@v0.5.0
0.35.0
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/crypto@v0.5.0
0.35.0

Open the chart page →

7,179
dexmesosphere-stable2.14.12 of 5See more

dex mesosphere-stable 2.14.1

2 of the 5 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.35.0
mesosphere/dex-controller:v0.16.11b2dd9c0b0fc
golang.org/x/crypto@v0.23.0
0.35.0

Open the chart page →

18,583
gatekeepermesosphere-stable0.6.111 of 2See more

gatekeeper mesosphere-stable 0.6.11

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.35.0

Open the chart page →

3,034
kafka-operatormesosphere-stable0.25.11 of 2See more

kafka-operator mesosphere-stable 0.25.1

1 of the 2 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
golang.org/x/crypto@v0.7.0
0.35.0

Open the chart page →

1,241
knativemesosphere-stable1.10.81 of 7See more

knative mesosphere-stable 1.10.8

1 of the 7 container images this version deploys carry CVE-2025-22869.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
golang.org/x/crypto@v0.1.0
0.35.0

Open the chart page →

7,479

Container images carrying it

1,948 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/crypto@v0.14.0
0.35.0
3
ciscolabs/rtsp-server:latestb59fc10bb821
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.35.0
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.35.0
3
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/crypto@v0.32.0
0.35.0
3
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.35.0
3
grafana/grafana:8.2.500568d89c4f8
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.35.0
3
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/crypto@v0.21.0
0.35.0
3
grafana/grafana:11.3.0a0f881232a6f
golang.org/x/crypto@v0.27.0
0.35.0
3
grafana/loki:3.4.258a6c186ce78
golang.org/x/crypto@v0.32.0
0.35.0
3
grafana/promtail:2.4.2626900031c4e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.35.0
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.35.0
3
kubegems/kubegems:v1.24.10a730bcf9322a
golang.org/x/crypto@v0.17.0
0.35.0
3
library/docker:20.10-dind:20-dindaf96c680a7e1
golang.org/x/crypto@v0.2.0
0.35.0
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/crypto@v0.0.0-20201124201722-c8d3bf9c5392
0.35.0
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.35.0
3
natsio/nats-box:0.19.28031d190c7ee
golang.org/x/crypto@v0.31.0
0.35.0
3
oryd/hydra:v2.2.02c93beb5e5f2
golang.org/x/crypto@v0.17.0
0.35.0
3
prom/alertmanager:v0.28.0d5155cfac40a
golang.org/x/crypto@v0.31.0
0.35.0
3
prom/prometheus:v3.0.1565ee8650122
golang.org/x/crypto@v0.28.0
0.35.0
3
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/crypto@v0.0.0-20200422194213-44a606286825
0.35.0
3
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/crypto@v0.27.0
0.35.0
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
golang.org/x/crypto@v0.16.0
0.35.0
3
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.35.0
3
vikunja/vikunja:0.24.6ed1f3ed467fe
golang.org/x/crypto@v0.27.0
0.35.0
3
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
golang.org/x/crypto@v0.31.0
0.35.0
3
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.35.0
3
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.35.0
3
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/crypto@v0.7.0
0.35.0
3
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/crypto@v0.24.0
0.35.0
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.35.0
3
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.35.0
3
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.35.0
3
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.35.0
3
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.35.0
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.35.0
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/crypto@v0.14.0
0.35.0
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
0.35.0
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/crypto@v0.18.0
0.35.0
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/crypto@v0.7.0
0.35.0
3
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.35.0
3
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.35.0
3
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.35.0
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.35.0
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.35.0
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/crypto@v0.14.0
0.35.0
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/crypto@v0.8.0
0.35.0
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.35.0
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/crypto@v0.8.0
0.35.0
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.35.0
3
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/crypto@v0.23.0
0.35.0
3

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.