StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,686
of 17,803 indexed, latest versions
Container images
3,262
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,686 of 17,803 indexed charts deploy, on 3,262 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+201 more0.36.02,483
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+147 more1.23.73,163
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,686 by stars
ChartLatestAffected imagesRadar Score
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
stdlib@go1.17.8
1.23.7

Open the chart page →

7,715
vm-console-proxyvm-console-proxyVerified publisher0.2.01 of 1See more

vm-console-proxy vm-console-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/kubevirt/vm-console-proxy:v0.8.08d6b4b6e99bd
golang.org/x/net@v0.34.0
stdlib@go1.22.4
0.36.0
1.23.7

Open the chart page →

645
go-devvoid-xmh1.0.11 of 1See more

go-dev void-xmh 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
voidxmh/golang:1.19-alpine-dev423c6195fab2
stdlib@go1.19
1.23.7

Open the chart page →

1,154
volantmqvolantmq0.1.21 of 1See more

volantmq volantmq 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
stdlib@go1.13.6
1.23.7

Open the chart page →

2,550
vpa-managervpa-managerVerified publisher0.4.91 of 1See more

vpa-manager vpa-manager 0.4.9

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/jcluppnow/vpa-manager:0.6.4e459d2fba277
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.36.0
1.23.7

Open the chart page →

491
cert-manager-webhook-vultrvultrVerified publisher1.0.01 of 1See more

cert-manager-webhook-vultr vultr 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.36.0
1.23.7

Open the chart page →

2,507
vultr-csivultrVerified publisher2.0.01 of 4See more

vultr-csi vultr 2.0.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
vultr/vultr-csi:v0.3.041d26735d437
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16.8
0.36.0
1.23.7

Open the chart page →

2,353
websitewaldo-visionVerified publisher0.33.01 of 2See more

website waldo-vision 0.33.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
stdlib@go1.20.2
1.23.7

Open the chart page →

3,479
kongwallarmVerified publisher4.6.33 of 7See more

kong wallarm 4.6.3

3 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
wallarm/ingress-python:4.6.0-15cb2ae08b40f
stdlib@go1.18.2
1.23.7
wallarm/ingress-ruby:4.6.0-1aecdb35c4def
stdlib@go1.18.3
1.23.7
wallarm/kong-kubernetes-ingress-controller:2.8b55ff6cecbd5
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.36.0
1.23.7

Open the chart page →

11,451
kong-previewwallarmVerified publisher4.2.32 of 5See more

kong-preview wallarm 4.2.3

2 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.5
0.36.0
1.23.7
wallarm/ingress-ruby:4.2.1-195ea2632326c
stdlib@go1.18.3
1.23.7

Open the chart page →

2,905
wallarm-ingress-rcwallarmVerified publisher4.8.42 of 2See more

wallarm-ingress-rc wallarm 4.8.4

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
wallarm/ingress-controller:4.8.0-1a591b9c91570
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.36.0
1.23.7
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.36.0
1.23.7

Open the chart page →

2,635
wallarm-node-nextwallarmVerified publisher0.5.32 of 2See more

wallarm-node-next wallarm 0.5.3

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
wallarm/node-helpers:5.0.2-1097cadc42336
golang.org/x/net@v0.26.0
stdlib@go1.22.7
0.36.0
1.23.7
wallarm/node-next:0.5.24314f3d2b918
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.36.0
1.23.7

Open the chart page →

2,408
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
wallarm/ebpf-agent:0.11.0-rc0c8920e60c726
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.36.0
1.23.7

Open the chart page →

2,838
consulwarjiang1.3.02 of 2See more

consul warjiang 1.3.0

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7

Open the chart page →

4,073
eth-validatorwateim1.4.51 of 3See more

eth-validator wateim 1.4.5

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
wateim/lighthouse-launch:latest2520149ee574
golang.org/x/net@v0.33.0
0.36.0

Open the chart page →

5,104
prometheus-storage-adapterwavefront0.1.61 of 2See more

prometheus-storage-adapter wavefront 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
wavefronthq/prometheus-storage-adapter:latestded77b38c7c6
golang.org/x/net@v0.17.0
stdlib@go1.18
0.36.0
1.23.7

Open the chart page →

1,285
wavefront-hpa-adapterwavefront0.2.101 of 1See more

wavefront-hpa-adapter wavefront 0.2.10

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
golang.org/x/net@v0.17.0
stdlib@go1.18
0.36.0
1.23.7

Open the chart page →

1,691
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.45a065930682d
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.36.0
1.23.7

Open the chart page →

5,494
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.36.0
1.23.7

Open the chart page →

11,191
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
golang.org/x/net@v0.5.0
stdlib@go1.20.1
0.36.0
1.23.7

Open the chart page →

6,288
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
stdlib@go1.19.12
1.23.7

Open the chart page →

9,405
myweatherhelmwebapp11.3.501 of 8See more

myweatherhelm webapp1 1.3.50

1 of the 8 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.23.7

Open the chart page →

9,291
myweatherhelm-schedulingwebapp11.3.921 of 9See more

myweatherhelm-scheduling webapp1 1.3.92

1 of the 9 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.23.7

Open the chart page →

9,291
azure-janitorwebdevopsVerified publisher1.0.131 of 1See more

azure-janitor webdevops 1.0.13

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
webdevops/azure-janitor:24.9.02446baee7b69
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.36.0
1.23.7

Open the chart page →

802
azure-keyvault-exporterwebdevopsVerified publisher1.0.121 of 1See more

azure-keyvault-exporter webdevops 1.0.12

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
webdevops/azure-keyvault-exporter:24.9.1f333704ecd60
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.36.0
1.23.7

Open the chart page →

801
azure-resourcegraph-exporterwebdevopsVerified publisher1.1.51 of 1See more

azure-resourcegraph-exporter webdevops 1.1.5

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
webdevops/azure-resourcegraph-exporter:24.9.0381136dda026
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.36.0
1.23.7

Open the chart page →

786
azure-scheduledevents-managerwebdevopsVerified publisher1.0.171 of 1See more

azure-scheduledevents-manager webdevops 1.0.17

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
webdevops/azure-scheduledevents-manager:24.9.0-kubernetes7acd46a8a972
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7

Open the chart page →

1,124
kube-pool-managerwebdevopsVerified publisher1.0.161 of 1See more

kube-pool-manager webdevops 1.0.16

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
webdevops/kube-pool-manager:24.9.04fad7e14ad67
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.36.0
1.23.7

Open the chart page →

499
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.23.7

Open the chart page →

28,729
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
stdlib@go1.20.1
1.23.7

Open the chart page →

2,031
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,562
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.36.0
1.23.7

Open the chart page →

4,093
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
golang.org/x/net@v0.0.0-20200222125558-5a598a2470a0
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

4,999
cadencewenerme0.23.02 of 5See more

cadence wenerme 0.23.0

2 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ubercadence/server:0.23.22ac5491d13bb
golang.org/x/net@v0.0.0-20201031054903-ff519b6c9102
stdlib@go1.13.6
0.36.0
1.23.7
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
golang.org/x/net@v0.0.0-20170114055629-f2499483f923
stdlib@go1.15.2
0.36.0
1.23.7

Open the chart page →

10,147
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
datawire/emissary:3.12.21f67a1292d2a
golang.org/x/net@v0.28.0
stdlib@go1.22.4
0.36.0
1.23.7

Open the chart page →

10,879
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
stdlib@go1.16.2
0.36.0
1.23.7

Open the chart page →

3,174
frpcwenerme1.0.11 of 1See more

frpc wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
wener/frpc:v0.37.0cc9fd4da44c0
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.17.3
0.36.0
1.23.7

Open the chart page →

3,359
juicefs-csi-driverwenerme0.33.03 of 5See more

juicefs-csi-driver wenerme 0.33.0

3 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.0cd21e19cd8bb
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
golang.org/x/net@v0.13.0
stdlib@go1.20.5
0.36.0
1.23.7
registry.k8s.io/sig-storage/livenessprobe:v2.12.05baeb4a6d7d5
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.36.0
1.23.7

Open the chart page →

8,944
kubernetes-dashboardwenerme7.14.01 of 5See more

kubernetes-dashboard wenerme 7.14.0

1 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
kubernetesui/dashboard-metrics-scraper:1.2.25154b68252bd
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.36.0
1.23.7

Open the chart page →

3,536
logging-operatorwenerme3.17.101 of 1See more

logging-operator wenerme 3.17.10

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.13
0.36.0
1.23.7

Open the chart page →

1,646
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.1
0.36.0
1.23.7

Open the chart page →

15,310
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.36.0
1.23.7

Open the chart page →

6,922
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.17.5
0.36.0
1.23.7

Open the chart page →

6,145
nats-account-serverwenerme0.8.11 of 1See more

nats-account-server wenerme 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
natsio/nats-account-server:1.0.0a3381560aab6
stdlib@go1.16.6
1.23.7

Open the chart page →

2,634
nfs-subdir-external-provisionerwenerme4.0.181 of 1See more

nfs-subdir-external-provisioner wenerme 4.0.18

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.36.0
1.23.7

Open the chart page →

2,745
openebswenerme3.10.03 of 3See more

openebs wenerme 3.10.0

3 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.36.0
1.23.7
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.36.0
1.23.7
openebs/provisioner-localpv:3.5.0aea39e49bb97
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.36.0
1.23.7

Open the chart page →

10,602
prometheus-statsd-exporterwenerme1.0.01 of 1See more

prometheus-statsd-exporter wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7

Open the chart page →

782
temporalwenerme0.15.16 of 13See more

temporal wenerme 0.15.1

6 of the 13 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.36.0
1.23.7
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.36.0
1.23.7
prom/prometheus:v2.16.0e4ca62c0d62f
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.8
0.36.0
1.23.7
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.23.7
temporalio/admin-tools:1.15.135034611d981
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.36.0
1.23.7
temporalio/server:1.15.1e26758f5a1bf
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.36.0
1.23.7

Open the chart page →

22,707
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
stdlib@go1.14.6
0.36.0
1.23.7

Open the chart page →

3,378
wexa-studiowexa-studio1.2.06 of 15See more

wexa-studio wexa-studio 1.2.0

6 of the 15 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.36.0
1.23.7
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
golang.org/x/net@v0.19.0
stdlib@go1.21.6
0.36.0
1.23.7
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
golang.org/x/net@v0.35.0
0.36.0
temporalio/server:1.29.1c1e3326b2ce1
golang.org/x/net@v0.34.0
0.36.0
temporalio/ui:2.44.00b36e00aad30
golang.org/x/net@v0.34.0
0.36.0
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.36.0
1.23.7

Open the chart page →

15,056

Container images carrying it

3,262 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
stdlib@go1.21.10
1.23.7
1
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
stdlib@go1.18.2
1.23.7
1
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
stdlib@go1.21.9
1.23.7
1
bitnamilegacy/redis:7.0.8-debian-11-r0bf01d031ba8c
stdlib@go1.18.2
1.23.7
1
bitnamilegacy/redis:7.2.1-debian-11-r0fa288394f402
stdlib@go1.19.12
1.23.7
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/net@v0.0.0-20220614195744-fb05da6f9022
stdlib@go1.17
0.36.0
1.23.7
1
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
golang.org/x/net@v0.30.0
stdlib@go1.23.4
0.36.0
1.23.7
1
bitnamilegacy/zookeeper:3.7.2-debian-11-r5cbf54314c401
stdlib@go1.21.5
1.23.7
1
bitnamilegacy/zookeeper:3.8.1-debian-11-r6dba59d740e13
stdlib@go1.18.2
1.23.7
1
bitnami/mariadb:11.7.216a7dae804fb
stdlib@go1.22.12
1.23.7
1
bitnami/mongodb:8.0.8b3bd5b6be9a0
golang.org/x/net@v0.33.0
0.36.0
1
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.6
0.36.0
1.23.7
1
bitpoke/stack-default-backend:latestc5eed1ddf692
stdlib@go1.16.6
1.23.7
1
bitpoke/wordpress-operator:v0.12.421284d1df473
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.36.0
1.23.7
1
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.36.0
1.23.7
1
blackducksoftware/bdba-pgupgrader:2026.6.35c97f3a3f8b7
stdlib@go1.18.2
1.23.7
1
blipai/deckard:0.0.28737d5d19a312
golang.org/x/net@v0.10.0
stdlib@go1.18.10
0.36.0
1.23.7
1
bloomberg/goldpinger:3.10.08520120f5598
golang.org/x/net@v0.17.0
stdlib@go1.21.9
0.36.0
1.23.7
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.36.0
1.23.7
1
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.36.0
1.23.7
1
bsgrigorov/helm-operator:latest45ab095f09c8
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
stdlib@go1.15.12
0.36.0
1.23.7
1
btcpayserver/tor:0.4.8.10e9585b68dc6b
stdlib@go1.16.5
1.23.7
1
buddyspencer/gickup:0.10.386b656f19b0c1
golang.org/x/net@v0.21.0
stdlib@go1.22.5
0.36.0
1.23.7
1
buddyspencer/gickup:0.10.309e7dbf923c12
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.36.0
1.23.7
1
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.7
0.36.0
1.23.7
1
bulich/domain-exporter:latest6d0b780f7c7b
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.36.0
1.23.7
1
burganbank/vault-initializer:v19259c34e4037
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.36.0
1.23.7
1
burningalchemist/sql_exporter:0.16.0b8e4757c7def
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.36.0
1.23.7
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.36.0
1.23.7
1
caarlos0/domain_exporter:v1.23.0d11dec138900
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.36.0
1.23.7
1
calico/cni:v3.28.0cef0c907b8f4
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.36.0
1.23.7
1
calico/cni:v3.28.1e486870cfde8
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.36.0
1.23.7
1
calico/kube-controllers:v3.28.08f04e4772a2b
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.36.0
1.23.7
1
calico/kube-controllers:v3.28.1eadb3a25109a
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.36.0
1.23.7
1
calico/node:v3.28.0385bf6391fea
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.36.0
1.23.7
1
calico/node:v3.28.1d8c644a8a3ee
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.36.0
1.23.7
1
camptocamp/bucket-cloner:latestacfafc308d88
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.5
0.36.0
1.23.7
1
captnbp/freebox-exporter:1.0.0-r01600c5a253e0
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.36.0
1.23.7
1
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.15.15
0.36.0
1.23.7
1
casbin/casdoor:v1.224.066f836ef778b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.5
0.36.0
1.23.7
1
casbin/casdoor:v1.753.0770ad9ec3190
golang.org/x/net@v0.21.0
stdlib@go1.20.12
0.36.0
1.23.7
1
castopod/castopod:1.12.101fd37280cbb2
stdlib@go1.21.13
1.23.7
1
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
stdlib@go1.15.3
0.36.0
1.23.7
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.3
0.36.0
1.23.7
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.4
0.36.0
1.23.7
1
cgtysylr/cluster-octopus:1.0.0aec0f8a38a77
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.36.0
1.23.7
1
chaerr/kridge:demo-operator-v0.1.266833deec017
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.36.0
1.23.7
1
chainflag/eth-faucet:latestac642796bcb6
stdlib@go1.17.13
1.23.7
1
chainsafe/lodestar:latest5593f6e97912
stdlib@go1.23.1
1.23.7
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
stdlib@go1.20.12
1.23.7
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.