StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,691
of 17,787 indexed, latest versions
Container images
3,269
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,691 of 17,787 indexed charts deploy, on 3,269 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+201 more0.36.02,489
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+147 more1.23.73,167
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,691 by stars
ChartLatestAffected imagesRadar Score
qbittorrentalexmorbo-qbittorrentVerified publisher1.2.11 of 1See more

qbittorrent alexmorbo-qbittorrent 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
golang.org/x/net@v0.17.0
stdlib@go1.20.2
0.36.0
1.23.7

Open the chart page →

882
slskdalexmorbo-slskdVerified publisher0.3.01 of 1See more

slskd alexmorbo-slskd 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
stdlib@go1.22.2
1.23.7

Open the chart page →

1,727
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.14.15
0.36.0
1.23.7

Open the chart page →

2,115
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.36.0
1.23.7

Open the chart page →

557
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.36.0
1.23.7

Open the chart page →

557
ipalpineworks0.1.21 of 1See more

ip alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
golang.org/x/net@v0.34.0
0.36.0

Open the chart page →

534
katalogalpineworks0.1.22 of 5See more

katalog alpineworks 0.1.2

2 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.36.0
1.23.7
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.36.0
1.23.7

Open the chart page →

4,414
katalog-agentalpineworks0.1.21 of 1See more

katalog-agent alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.36.0
1.23.7

Open the chart page →

575
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.36.0
1.23.7
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
stdlib@go1.19.13
0.36.0
1.23.7
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.36.0
1.23.7
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.36.0
1.23.7
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.36.0
1.23.7
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.36.0
1.23.7
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.36.0
1.23.7
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.36.0
1.23.7

Open the chart page →

28,212
sliding-sync-proxyananace-chartsVerified publisher0.2.131 of 2See more

sliding-sync-proxy ananace-charts 0.2.13

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.36.0
1.23.7

Open the chart page →

1,592
anchore-admission-controlleranchore-charts0.8.51 of 2See more

anchore-admission-controller anchore-charts 0.8.5

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
golang.org/x/net@v0.20.0
stdlib@go1.20.14
0.36.0
1.23.7

Open the chart page →

7,559
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.36.0
1.23.7

Open the chart page →

1,326
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
golang.org/x/net@v0.17.0
0.36.0

Open the chart page →

5,838
buildkit-serviceandrcunsVerified publisher1.8.01 of 1See more

buildkit-service andrcuns 1.8.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
moby/buildkit:v0.31.0a095b3d11ce1
golang.org/x/net@v0.35.0
0.36.0

Open the chart page →

1,286
terjangandylibrianVerified publisher0.0.31 of 1See more

terjang andylibrian 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/andylibrian/terjang:latest20a46b199247
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.16.4
0.36.0
1.23.7

Open the chart page →

1,985
chirpstack-packet-multiplexerangelnu3.0.01 of 1See more

chirpstack-packet-multiplexer angelnu 3.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
stdlib@go1.13.15
1.23.7

Open the chart page →

2,239
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
stdlib@go1.18.2
1.23.7

Open the chart page →

42,345
maddyangelnu5.0.01 of 1See more

maddy angelnu 5.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
golang.org/x/net@v0.34.0
0.36.0

Open the chart page →

767
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.36.0
1.23.7

Open the chart page →

2,488
ddosifyanteonVerified publisher1.7.55 of 13See more

ddosify anteon 1.7.5

5 of the 13 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
stdlib@go1.20.8
0.36.0
1.23.7
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
stdlib@go1.18.1
0.36.0
1.23.7
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
stdlib@go1.19.4
0.36.0
1.23.7
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.23.7
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
stdlib@go1.19.11
0.36.0
1.23.7

Open the chart page →

25,720
antmediaantmediaVerified publisher3.1.02 of 4See more

antmedia antmedia 3.1.0

2 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.36.0
1.23.7
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.36.0
1.23.7

Open the chart page →

4,615
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.36.0
1.23.7
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.19.1
0.36.0
1.23.7

Open the chart page →

3,322
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
stdlib@go1.15
0.36.0
1.23.7

Open the chart page →

2,730
glauthanza-labsVerified publisher1.0.11 of 1See more

glauth anza-labs 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/glauth/glauth:v2.5.209c782ca5984
golang.org/x/net@v0.17.0
0.36.0

Open the chart page →

1,285
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/net@v0.25.0
stdlib@go1.23.6
0.36.0
1.23.7

Open the chart page →

2,947
d.vazquezm.2021_helmapphelmVerified publisher1.0.02 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

2 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.23.7
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.23.7

Open the chart page →

19,784
app-mobilityappmo0.1.03 of 5See more

app-mobility appmo 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
stdlib@go1.18.5
0.36.0
1.23.7
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.36.0
1.23.7
velero/velero:v1.8.18d784580931c
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.36.0
1.23.7

Open the chart page →

12,520
app-movies-seriesapp-movies-seriesVerified publisher0.1.01 of 2See more

app-movies-series app-movies-series 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.23.7

Open the chart page →

3,166
auditorappscodeVerified publisher2023.10.11 of 1See more

auditor appscode 2023.10.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
stdlib@go1.19.4
0.36.0
1.23.7

Open the chart page →

1,673
capa-vpc-peering-operatorappscodeVerified publisher2023.12.111 of 1See more

capa-vpc-peering-operator appscode 2023.12.11

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.36.0
1.23.7

Open the chart page →

1,433
capi-ops-managerappscodeVerified publisher2024.8.142 of 2See more

capi-ops-manager appscode 2024.8.14

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
golang.org/x/net@v0.33.0
stdlib@go1.23.2
0.36.0
1.23.7
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.36.0
1.23.7

Open the chart page →

3,416
cluster-proxyappscodeVerified publisher2024.2.251 of 1See more

cluster-proxy appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-proxy:latest27a5c64b7ea8
golang.org/x/net@v0.20.0
stdlib@go1.21.8
0.36.0
1.23.7

Open the chart page →

1,119
cluster-proxy-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-proxy-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-proxy:v0.10.1a7fce69e171c
golang.org/x/net@v0.19.0
stdlib@go1.22.4
0.36.0
1.23.7

Open the chart page →

1,465
docker-machine-operatorappscodeVerified publisher2024.7.91 of 1See more

docker-machine-operator appscode 2024.7.9

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
golang.org/x/net@v0.14.0
stdlib@go1.22.4
0.36.0
1.23.7

Open the chart page →

2,220
falco-ui-serverappscodeVerified publisher2026.1.151 of 2See more

falco-ui-server appscode 2026.1.15

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.36.0
1.23.7

Open the chart page →

2,873
fluxcd-addon-managerappscodeVerified publisher2024.2.251 of 1See more

fluxcd-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/fluxcd-addon:v0.0.23acba3df8827
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.36.0
1.23.7

Open the chart page →

1,304
gateway-converterappscodeVerified publisher2024.8.301 of 1See more

gateway-converter appscode 2024.8.30

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway-converter:v0.0.1b92123805584
golang.org/x/net@v0.27.0
stdlib@go1.23.1
0.36.0
1.23.7

Open the chart page →

1,267
gh-ci-webhookappscodeVerified publisher2026.9.111 of 1See more

gh-ci-webhook appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/gh-ci-webhook:v0.0.2036ce246d884e
golang.org/x/net@v0.33.0
stdlib@go1.24.0
0.36.0
1.23.7

Open the chart page →

1,240
grafanaappscodeVerified publisher2026.9.111 of 1See more

grafana appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana:v2025.2.367d18880448c
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.1
0.36.0
1.23.7

Open the chart page →

2,333
inbox-agentappscodeVerified publisher2026.6.21 of 2See more

inbox-agent appscode 2026.6.2

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.15.0d8cc6ffb9819
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.36.0
1.23.7

Open the chart page →

2,115
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
stdlib@go1.18.2
1.23.7

Open the chart page →

15,707
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
stdlib@go1.18.2
1.23.7

Open the chart page →

17,110
kube-auth-managerappscodeVerified publisher2023.11.141 of 1See more

kube-auth-manager appscode 2023.11.14

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.36.0
1.23.7

Open the chart page →

1,945
kube-auth-proxyappscodeVerified publisher2023.11.141 of 1See more

kube-auth-proxy appscode 2023.11.14

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/net@v0.8.0
stdlib@go1.20.2
0.36.0
1.23.7

Open the chart page →

1,945
kubedb-communityappscodeVerified publisher0.24.21 of 2See more

kubedb-community appscode 0.24.2

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
kubedb/operator:v0.24.01a06ff0bda52
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.6
0.36.0
1.23.7

Open the chart page →

2,550
kubedb-enterpriseappscodeVerified publisher0.11.21 of 2See more

kubedb-enterprise appscode 0.11.2

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
kubedb/kubedb-enterprise:v0.11.05829bcedcb0d
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.3
0.36.0
1.23.7

Open the chart page →

2,575
kubedb-oneappscodeVerified publisher2023.12.289 of 10See more

kubedb-one appscode 2023.12.28

9 of the 10 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.36.0
1.23.7
ghcr.io/kubedb/kubedb-autoscaler:v0.25.0df6b11907d33
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.36.0
1.23.7
ghcr.io/kubedb/kubedb-dashboard:v0.16.07bfe1c07bd9b
golang.org/x/net@v0.17.0
stdlib@go1.20.7
0.36.0
1.23.7
ghcr.io/kubedb/kubedb-ops-manager:v0.27.1ec36422b09af
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.36.0
1.23.7
ghcr.io/kubedb/kubedb-provisioner:v0.40.242574f512837
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.36.0
1.23.7
ghcr.io/kubedb/kubedb-schema-manager:v0.16.09518de37eed5
golang.org/x/net@v0.17.0
stdlib@go1.20.7
0.36.0
1.23.7
ghcr.io/kubedb/kubedb-webhook-server:v0.16.2e24894e32cbc
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.36.0
1.23.7
ghcr.io/stashed/stash-crd-installer:v0.32.0c6f2a844b5dd
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.36.0
1.23.7
ghcr.io/stashed/stash-enterprise:v0.32.0e9bde36e34b7
golang.org/x/net@v0.15.0
stdlib@go1.20.7
0.36.0
1.23.7

Open the chart page →

15,016
kubedb-provider-awsappscodeVerified publisher2026.7.101 of 1See more

kubedb-provider-aws appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-aws:v0.27.049b1c312e342
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.36.0
1.23.7

Open the chart page →

2,527
kubedb-provider-azureappscodeVerified publisher2026.7.101 of 1See more

kubedb-provider-azure appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.3
0.36.0
1.23.7

Open the chart page →

2,705
kubedb-provider-gcpappscodeVerified publisher2026.7.101 of 2See more

kubedb-provider-gcp appscode 2026.7.10

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
golang.org/x/net@v0.23.0
stdlib@go1.19.1
0.36.0
1.23.7

Open the chart page →

3,033

Container images carrying it

3,269 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
golang.org/x/net@v0.28.0
stdlib@go1.23.0
0.36.0
1.23.7
2
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.36.0
1.23.7
2
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.36.0
1.23.7
2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.10
0.36.0
1.23.7
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.36.0
1.23.7
2
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18.1
0.36.0
1.23.7
2
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.36.0
1.23.7
2
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.36.0
1.23.7
2
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.36.0
1.23.7
2
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.2
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-cainjector:v1.14.39395dec77fcf
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-cainjector:v1.15.3e0ce8ae280c8
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-startupapicheck:v1.15.34cbc1b022a23
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-startupapicheck:v1.14.3df8677135139
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-webhook:v1.14.3d8ad5515f44f
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.36.0
1.23.7
2
quay.io/jetstack/cert-manager-webhook:v1.15.3fdcb9ac4963f
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7
2
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.36.0
1.23.7
2
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/net@v0.8.0
stdlib@go1.19.5
0.36.0
1.23.7
2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.36.0
1.23.7
2
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.36.0
1.23.7
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.36.0
1.23.7
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
golang.org/x/net@v0.12.0
stdlib@go1.19.11
0.36.0
1.23.7
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.36.0
1.23.7
2
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.10
0.36.0
1.23.7
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.14
0.36.0
1.23.7
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.12
0.36.0
1.23.7
2
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.36.0
1.23.7
2
quay.io/prometheuscommunity/json-exporter:v0.7.03a777171d39a
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.36.0
1.23.7
2
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.36.0
1.23.7
2
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.3
0.36.0
1.23.7
2
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.36.0
1.23.7
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.36.0
1.23.7
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.79.2193280a33bc1
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.36.0
1.23.7
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.2944b2c67345c
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.36.0
1.23.7
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.77.2c96d4fb1d57f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
2
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.14.12
0.36.0
1.23.7
2
quay.io/prometheus-operator/prometheus-operator:v0.77.2af92db7eac86
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
2
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.36.0
1.23.7
2
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.36.0
1.23.7
2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.36.0
1.23.7
2
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.3
0.36.0
1.23.7
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.