StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,687
of 17,797 indexed, latest versions
Container images
3,263
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,687 of 17,797 indexed charts deploy, on 3,263 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+201 more0.36.02,484
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+147 more1.23.73,164
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,687 by stars
ChartLatestAffected imagesRadar Score
steamcmdthetredevVerified publisher1.0.91 of 1See more

steamcmd thetredev 1.0.9

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/thetredev/steamcmd:srcds-20240309dbb0f042cb31
stdlib@go1.18.2
1.23.7

Open the chart page →

1,075
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.23.7

Open the chart page →

25,447
mc-routerthl-chartsVerified publisher0.1.01 of 1See more

mc-router thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
itzg/mc-router:1.16.1bb552b59fb53
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.18.4
0.36.0
1.23.7

Open the chart page →

1,855
monitoringthl-chartsVerified publisher0.1.18 of 10See more

monitoring thl-charts 0.1.1

8 of the 10 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.17.9
0.36.0
1.23.7
grafana/loki:2.5.0f9ef133793af
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.8
0.36.0
1.23.7
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
stdlib@go1.17.2
0.36.0
1.23.7
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.23.7
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.36.0
1.23.7
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.36.0
1.23.7
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.36.0
1.23.7
quay.io/prometheus/prometheus:v2.34.0b37103e03399
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.8
0.36.0
1.23.7

Open the chart page →

18,940
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
nginx/nginx-ingress:1.11.1eb5b4fd73325
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.11
0.36.0
1.23.7

Open the chart page →

6,889
tiny-api-charttiny-api1.0.01 of 1See more

tiny-api-chart tiny-api 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
stubin87/tiny-api:v1.1.02e5c42e92ec8
stdlib@go1.19.1
1.23.7

Open the chart page →

1,126
grafanatnh5.3.01 of 1See more

grafana tnh 5.3.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.36.0
1.23.7

Open the chart page →

3,198
prometheustnh11.6.04 of 6See more

prometheus tnh 11.6.0

4 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.36.0
1.23.7
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.36.0
1.23.7
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.23.7
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.36.0
1.23.7

Open the chart page →

8,492
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
erenozcan17/go_backend:v4.250b4f23422b6
golang.org/x/net@v0.10.0
0.36.0

Open the chart page →

7,028
traefik-jwt-decodetraefik-jwt-decode0.1.01 of 1See more

traefik-jwt-decode traefik-jwt-decode 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
simonschneider/traefik-jwt-decode:latestd674ac370f80
stdlib@go1.17.13
1.23.7

Open the chart page →

1,310
nfs-servertranhailongVerified publisher0.1.21 of 1See more

nfs-server tranhailong 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
tranhailong/nfs-server:4.2-2-gcsfuse028662749be2
golang.org/x/net@v0.4.0
stdlib@go1.18.4
0.36.0
1.23.7

Open the chart page →

2,331
treenitytreenityVerified publisher0.1.31 of 4See more

treenity treenity 0.1.3

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/nats:2.9.6-alpine3.16f576cdc17cc3
stdlib@go1.19.3
1.23.7

Open the chart page →

3,383
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.36.0
1.23.7

Open the chart page →

2,486
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.36.0
1.23.7
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

4,816
trivy-webhook-elasticsearchtrivy-webhook-elasticsearch0.1.41 of 1See more

trivy-webhook-elasticsearch trivy-webhook-elasticsearch 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/lbi22/trivy-webhook-elasticsearch:v0.1.4b51b824e4f19
stdlib@go1.22.8
1.23.7

Open the chart page →

755
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,519
monitorortrozz0.0.11 of 1See more

monitoror trozz 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
monitoror/monitoror:44b88edcf51ff
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.6
0.36.0
1.23.7

Open the chart page →

3,110
clickhouse-operatortruefoundryVerified publisher0.1.12 of 3See more

clickhouse-operator truefoundry 0.1.1

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.23.34baec90b20cd
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.36.0
1.23.7
altinity/metrics-exporter:0.23.32912a6c15b44
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.36.0
1.23.7

Open the chart page →

1,430
tfy-cloudflaredtruefoundryVerified publisher0.6.01 of 2See more

tfy-cloudflared truefoundry 0.6.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
golang.org/x/net@v0.5.0
stdlib@go1.20
0.36.0
1.23.7

Open the chart page →

2,022
tfy-distributortruefoundryVerified publisher0.0.13 of 4See more

tfy-distributor truefoundry 0.0.1

3 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.23.7
natsio/nats-server-config-reloader:0.14.08c28b75bc416
stdlib@go1.20.5
1.23.7
natsio/prometheus-nats-exporter:0.13.02adf791d9f9f
stdlib@go1.21.3
1.23.7

Open the chart page →

17,403
tfy-inferentia-operatortruefoundryVerified publisher0.2.83 of 3See more

tfy-inferentia-operator truefoundry 0.2.8

3 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/kubernetes/kube-scheduler:v1.29.14-eks-1-29-lateste7e1db003e6a
golang.org/x/net@v0.24.0
stdlib@go1.22.12
0.36.0
1.23.7
public.ecr.aws/neuron/neuron-device-plugin:2.23.30.075a6d5ce3bd3
golang.org/x/net@v0.23.0
stdlib@go1.20.4
0.36.0
1.23.7
public.ecr.aws/neuron/neuron-scheduler:2.23.30.04cd274463e6b
golang.org/x/net@v0.23.0
stdlib@go1.20.4
0.36.0
1.23.7

Open the chart page →

2,918
tfy-kservetruefoundryVerified publisher0.1.11 of 2See more

tfy-kserve truefoundry 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
kserve/kserve-controller:v0.10.022ff858b57c1
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

1,178
tfy-llm-gateway-infratruefoundryVerified publisher0.2.102 of 3See more

tfy-llm-gateway-infra truefoundry 0.2.10

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.23.774315beb57db
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.36.0
1.23.7
altinity/metrics-exporter:0.23.7a4d7ff0c727e
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.36.0
1.23.7

Open the chart page →

1,206
tfy-lokitruefoundryVerified publisher0.1.62 of 2See more

tfy-loki truefoundry 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/loki:2.9.1035b02acc6765
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7
grafana/promtail:2.9.1063a2e57a5b14
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7

Open the chart page →

2,827
aws-eks-asg-rolling-update-handlertwin1.5.01 of 1See more

aws-eks-asg-rolling-update-handler twin 1.5.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
twinproduction/aws-eks-asg-rolling-update-handler:v1.7.08f38c206972e
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.36.0
1.23.7

Open the chart page →

1,119
lighthousetwin1.0.21 of 1See more

lighthouse twin 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/twin/lighthouse:v0.0.45aeda2ea2ba2
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.36.0
1.23.7

Open the chart page →

544
twitter-apptwitter-helm0.1.124 of 8See more

twitter-app twitter-helm 0.1.12

4 of the 8 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.3
0.36.0
1.23.7
stakkato95/twitter-service-graphql:0.1.13cbe857234f2
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.36.0
1.23.7
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
stdlib@go1.18.3
1.23.7
stakkato95/twitter-service-users:0.1.1456049efee9a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.36.0
1.23.7

Open the chart page →

6,147
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.7.0e90b7ba06d97
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.36.0
1.23.7

Open the chart page →

1,569
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.23.7

Open the chart page →

4,135
tyk-bootstraptyk-helm5.3.03 of 3See more

tyk-bootstrap tyk-helm 5.3.0

3 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.23.7

Open the chart page →

1,374
tyk-control-planetyk-helm5.3.03 of 7See more

tyk-control-plane tyk-helm 5.3.0

3 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.23.7

Open the chart page →

2,992
tyk-stacktyk-helm5.3.03 of 7See more

tyk-stack tyk-helm 5.3.0

3 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.23.7

Open the chart page →

2,936
typhoontyphoonVerified publisher0.2.32 of 2See more

typhoon typhoon 0.2.3

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.36.0
1.23.7
ghcr.io/zeiss/typhoon/typhoon-webhook:0.2.378f9b82050bc
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.36.0
1.23.7

Open the chart page →

1,686
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
golang.org/x/net@v0.23.0
stdlib@go1.22.9
0.36.0
1.23.7

Open the chart page →

8,674
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.36.0
1.23.7

Open the chart page →

4,967
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
stdlib@go1.20.7
1.23.7

Open the chart page →

5,251
phonebook-chartusuladams2Verified publisher0.2.11 of 3See more

phonebook-chart usuladams2 0.2.1

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.23.7

Open the chart page →

3,176
kiamuswitch6.1.21 of 1See more

kiam uswitch 6.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/uswitch/kiam:v4.0be3a5846922d
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.13.8
0.36.0
1.23.7

Open the chart page →

2,972
utho-app-operator-chartutho-operatorVerified publisher0.1.61 of 2See more

utho-app-operator-chart utho-operator 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
utho/utho-app-operator:0.1.46e8a690e8b7a
golang.org/x/net@v0.26.0
stdlib@go1.22.8
0.36.0
1.23.7

Open the chart page →

491
gohttpserverutkuozdemirVerified publisher0.2.01 of 1See more

gohttpserver utkuozdemir 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
codeskyblue/gohttpserver:latestcaa862590e34
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.16.3
0.36.0
1.23.7

Open the chart page →

1,898
transmission-exporterutkuozdemirVerified publisher1.1.01 of 1See more

transmission-exporter utkuozdemir 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
metalmatze/transmission-exporter:0.3.090d6acb6d47d
stdlib@go1.13
1.23.7

Open the chart page →

1,646
openldap-havcnngrVerified publisher1.0.01 of 3See more

openldap-ha vcnngr 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.36.0
1.23.7

Open the chart page →

5,515
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,519
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,537
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,439
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,439
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
stdlib@go1.22.5
1.23.7

Open the chart page →

2,789
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.20.14
0.36.0
1.23.7

Open the chart page →

4,415
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.21.7
0.36.0
1.23.7

Open the chart page →

13,617
kube-monitoring-telegram-botviento-repository1.0.01 of 1See more

kube-monitoring-telegram-bot viento-repository 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.36.0
1.23.7

Open the chart page →

7,906

Container images carrying it

3,263 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.3
0.36.0
1.23.7
2
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.36.0
1.23.7
2
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/net@v0.10.0
stdlib@go1.21.1
0.36.0
1.23.7
2
quay.io/prometheus/pushgateway:v1.11.099392035ae99
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.36.0
1.23.7
2
quay.io/thanos/thanos:v0.39.21d022ef4b8ef
stdlib@go1.24.0
1.23.7
2
quay.io/zncdatadev/sig-storage/csi-provisioner:v5.1.0672e45d6a556
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.36.0
1.23.7
2
quay.io/zncdatadev/sig-storage/livenessprobe:v2.14.033692aed26aa
golang.org/x/net@v0.28.0
stdlib@go1.22.5
0.36.0
1.23.7
2
quay.io/zncdatadev/tools:1.0.0-kubedoop0.0.0-dev382fca2054c9
golang.org/x/net@v0.26.0
stdlib@go1.22.6
0.36.0
1.23.7
2
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.16.15
0.36.0
1.23.7
2
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.36.0
1.23.7
2
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.36.0
1.23.7
2
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.36.0
1.23.7
2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.36.0
1.23.7
2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.5
0.36.0
1.23.7
2
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
golang.org/x/net@v0.23.0
0.36.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.36.0
1.23.7
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
stdlib@go1.19.3
0.36.0
1.23.7
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.36.0
1.23.7
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.15.0db384bf43222
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.36.0
1.23.7
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/csi-attacher:v4.8.0a399393ff5bd
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/livenessprobe:v2.15.02c5f9dc4ea5a
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/livenessprobe:v2.8.0cacee2b5c36d
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
stdlib@go1.18
0.36.0
1.23.7
2
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.36.0
1.23.7
2
0xpolygon/bor:1.3.7396d3de26d8b
golang.org/x/net@v0.26.0
stdlib@go1.22.1
0.36.0
1.23.7
1
0xpolygon/heimdall:1.0.134ddf259993c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.36.0
1.23.7
1
1dev/server:11.9.0cd5b12fe5471
stdlib@go1.22.2
1.23.7
1
1password/connect-api:1.7.26aa94cf713f9
golang.org/x/net@v0.14.0
stdlib@go1.20.6
0.36.0
1.23.7
1
1password/connect-sync:1.7.2fe527ed9d81f
golang.org/x/net@v0.14.0
stdlib@go1.20.6
0.36.0
1.23.7
1
1password/kubernetes-secrets-injector:1.0.25884757f7879
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.36.0
1.23.7
1
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.36.0
1.23.7
1
aboogie/login_test_backend:new9c41a4483ac8
stdlib@go1.22.5
1.23.7
1
absaoss/terraform-controller:v0.0.20ad538a1285a0
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.14.8
0.36.0
1.23.7
1
activepieces/activepieces:0.91.058414dfc94c4
stdlib@go1.23.5
1.23.7
1
adguard/adguardhome:v0.107.513a143e6c071c
golang.org/x/net@v0.25.0
stdlib@go1.22.4
0.36.0
1.23.7
1
adguard/adguardhome:v0.107.3843ec119419a9
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.36.0
1.23.7
1
adguard/adguardhome:v0.107.7b9974aed13d0
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.9
0.36.0
1.23.7
1
adguard/adguardhome:v0.107.56c64a0b37f7b9
golang.org/x/net@v0.33.0
stdlib@go1.23.5
0.36.0
1.23.7
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.