StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,691
of 17,787 indexed, latest versions
Container images
3,269
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,691 of 17,787 indexed charts deploy, on 3,269 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+201 more0.36.02,489
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+147 more1.23.73,167
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,691 by stars
ChartLatestAffected imagesRadar Score
argo-cdargoOfficialVerified publisher10.9.11 of 3See more

argo-cd argo 10.9.1

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
stdlib@go1.24.0
1.23.7

Open the chart page →

2,989
nfs-subdir-external-provisionernfs-subdir-external-provisioner4.0.181 of 1See more

nfs-subdir-external-provisioner nfs-subdir-external-provisioner 4.0.18

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.36.0
1.23.7

Open the chart page →

2,745
jupyterhubjupyterhubOfficialVerified publisher4.4.21 of 7See more

jupyterhub jupyterhub 4.4.2

1 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.30.1474a5cf9cfa9f
golang.org/x/net@v0.23.0
0.36.0

Open the chart page →

7,909
argo-cdargo-cd-oci10.9.11 of 3See more

argo-cd argo-cd-oci 10.9.1

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
stdlib@go1.24.0
1.23.7

Open the chart page →

2,989
mimir-distributedgrafana6.2.02 of 6See more

mimir-distributed grafana 6.2.0

2 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.36.0
1.23.7
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.36.0
1.23.7

Open the chart page →

4,519
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
stdlib@go1.20.5
1.23.7

Open the chart page →

30,167
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
stdlib@go1.21.8
1.23.7

Open the chart page →

11,372
nfs-server-provisionerkvaps1.8.01 of 1See more

nfs-server-provisioner kvaps 1.8.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.36.0
1.23.7

Open the chart page →

2,315
rook-cephrookOfficialVerified publisher1.20.71 of 2See more

rook-ceph rook 1.20.7

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
rook/ceph:v1.20.72f970c425617
stdlib@go1.22.10
1.23.7

Open the chart page →

1,447
aws-node-termination-handleraws0.21.01 of 1See more

aws-node-termination-handler aws 0.21.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.19.0844478ebd5b8
golang.org/x/net@v0.2.0
stdlib@go1.19.5
0.36.0
1.23.7

Open the chart page →

1,445
openebsopenebsOfficialVerified publisher4.6.112 of 35See more

openebs openebs 4.6.1

12 of the 35 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/loki:3.4.258a6c186ce78
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.36.0
1.23.7
library/nats:2.9.17-alpine1a7b320b2942
stdlib@go1.19.9
1.23.7
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
stdlib@go1.19.4
1.23.7
natsio/prometheus-nats-exporter:0.11.031c02aac089a
stdlib@go1.20.3
1.23.7
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.36.0
1.23.7
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-attacher:v4.8.169888dba5815
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.13.0d7138bcc3aa5
golang.org/x/net@v0.32.0
stdlib@go1.23.1
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-provisioner:v5.2.0d5e46da8aff7
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-resizer:v1.13.28ddd178ba5d0
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.0dd788d79cf4c
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.36.0
1.23.7
registry.k8s.io/sig-storage/snapshot-controller:v8.2.09dade8f2f3ab
golang.org/x/net@v0.31.0
stdlib@go1.23.1
0.36.0
1.23.7

Open the chart page →

24,009
prometheus-adapterprometheus-communityOfficialVerified publisher5.3.01 of 1See more

prometheus-adapter prometheus-community 5.3.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.36.0
1.23.7

Open the chart page →

930
open-webuiopen-webui16.5.01 of 4See more

open-webui open-webui 16.5.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine3.2102419de7eddf
stdlib@go1.18.2
1.23.7

Open the chart page →

1,288
actions-runner-controlleractions-runner-controller0.23.72 of 2See more

actions-runner-controller actions-runner-controller 0.23.7

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
summerwind/actions-runner-controller:v0.27.62128f81dbede
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.36.0
1.23.7
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.1
0.36.0
1.23.7

Open the chart page →

2,883
vpafairwinds-stableVerified publisher5.0.11 of 4See more

vpa fairwinds-stable 5.0.1

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.36.0
1.23.7

Open the chart page →

1,233
terraformhashicorpVerified publisher1.1.21 of 1See more

terraform hashicorp 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.18.8
0.36.0
1.23.7

Open the chart page →

2,059
dagsterdagsterVerified publisher1.13.221 of 5See more

dagster dagster 1.13.22

1 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/postgres:14.6f565573d74ae
stdlib@go1.18.2
1.23.7

Open the chart page →

3,459
miniominio-official5.4.02 of 2See more

minio minio-official 5.4.0

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.36.0
1.23.7
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.36.0
1.23.7

Open the chart page →

2,483
openfaasopenfaas15.0.132 of 6See more

openfaas openfaas 15.0.13

2 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/nats-streaming:0.25.60ad6861379c9
stdlib@go1.20.11
1.23.7
ghcr.io/openfaas/queue-worker:0.14.2c18da04d70f6
stdlib@go1.23.4
1.23.7

Open the chart page →

3,544
jaeger-operatorjaegertracingOfficialVerified publisher2.57.01 of 1See more

jaeger-operator jaegertracing 2.57.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
jaegertracing/jaeger-operator:1.61.03f036ec60e61
golang.org/x/net@v0.29.0
stdlib@go1.22.3
0.36.0
1.23.7

Open the chart page →

566
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
stdlib@go1.18.2
1.23.7

Open the chart page →

5,557
vault-secrets-operatorhashicorpVerified publisher1.5.11 of 2See more

vault-secrets-operator hashicorp 1.5.1

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.18.1e6a323504999
golang.org/x/net@v0.28.0
stdlib@go1.23.0
0.36.0
1.23.7

Open the chart page →

1,040
linkerd-vizlinkerd2Verified publisher30.12.111 of 5See more

linkerd-viz linkerd2 30.12.11

1 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/prometheus:v2.48.0b440bc0e8aa5
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.36.0
1.23.7

Open the chart page →

1,367
rocketchatrocketchat-server7.0.22 of 12See more

rocketchat rocketchat-server 7.0.2

2 of the 12 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.36.0
1.23.7
bitnamilegacy/mongodb-exporter:0.39.0-debian-11-r106de7256c7adcd
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.36.0
1.23.7

Open the chart page →

12,283
influxdb2influxdata2.1.21 of 1See more

influxdb2 influxdata 2.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/influxdb:2.7.4-alpinea10d46445d68
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.36.0
1.23.7

Open the chart page →

2,102
solr-operatorapache-solrVerified publisher0.9.12 of 3See more

solr-operator apache-solr 0.9.1

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
apache/solr-operator:v0.9.14db34508137f
golang.org/x/net@v0.33.0
stdlib@go1.22.12
0.36.0
1.23.7
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.36.0
1.23.7

Open the chart page →

2,943
chaos-meshchaos-meshVerified publisher2.8.41 of 4See more

chaos-mesh chaos-mesh 2.8.4

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.36.0

Open the chart page →

6,362
atlantisatlantis6.15.11 of 1See more

atlantis atlantis 6.15.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/runatlantis/atlantis:v0.47.1511231955463
golang.org/x/net@v0.23.0
stdlib@go1.22.1
0.36.0
1.23.7

Open the chart page →

1,892
rabbitmqcloudpirates-rabbitmqVerified publisher0.21.261 of 2See more

rabbitmq cloudpirates-rabbitmq 0.21.26

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.5-management57bddb6fbc34
stdlib@go1.22.2
1.23.7

Open the chart page →

849
grafana-agentgrafana0.44.22 of 2See more

grafana-agent grafana 0.44.2

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/agent:v0.44.23364714a2f64
golang.org/x/net@v0.33.0
stdlib@go1.22.11
0.36.0
1.23.7
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.23.7

Open the chart page →

3,514
vclusterloftVerified publisher0.0.0-ci.31 of 2See more

vcluster loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.1.1-0.20221027164007-c63010009c80
stdlib@go1.19.4
0.36.0
1.23.7

Open the chart page →

2,453
milvusmilvus4.0.314 of 5See more

milvus milvus 4.0.31

4 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.5-r2102aac62827b
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.2
0.36.0
1.23.7
milvusdb/milvus:v2.2.13a3a55e1c1497
golang.org/x/net@v0.10.0
stdlib@go1.18.3
0.36.0
1.23.7
milvusdb/milvus-config-tool:v0.1.12212dfb61401
golang.org/x/net@v0.0.0-20220706163947-c90051bbdb60
stdlib@go1.16.15
0.36.0
1.23.7
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.36.0
1.23.7

Open the chart page →

32,353
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.36.0
1.23.7

Open the chart page →

10,648
semaphoresemaphoreuiOfficialVerified publisher16.2.21 of 1See more

semaphore semaphoreui 16.2.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.18.3e9260bfa8255
stdlib@go1.23.3
1.23.7

Open the chart page →

2,221
signozsignoz0.141.13 of 5See more

signoz signoz 0.141.1

3 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.36.0
1.23.7
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.36.0
1.23.7
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.23.7

Open the chart page →

7,582
prometheus-kafka-exporterprometheus-communityVerified publisher4.0.01 of 1See more

prometheus-kafka-exporter prometheus-community 4.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.9.04150e46b2e96
golang.org/x/net@v0.34.0
stdlib@go1.24.0
0.36.0
1.23.7

Open the chart page →

716
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
stdlib@go1.19.8
1.23.7

Open the chart page →

4,808
nacosygqygq2Verified publisher2.1.102 of 4See more

nacos ygqygq2 2.1.10

2 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.23.7
ygqygq2/mysql-exec-sql:latest54f30def1558
stdlib@go1.18.2
1.23.7

Open the chart page →

4,984
difydoubanVerified publisher0.10.03 of 6See more

dify douban 0.10.0

3 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
stdlib@go1.21.9
1.23.7
langgenius/dify-sandbox:0.2.124e65e8a351a2
stdlib@go1.23.3
1.23.7
langgenius/dify-web:1.10.1-fix.1c306ac577912
stdlib@go1.23.5
1.23.7

Open the chart page →

19,497
stackgres-operatorstackgres-chartsOfficialVerified publisher1.19.11 of 2See more

stackgres-operator stackgres-charts 1.19.1

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/ongres/kubectl:v1.25.16-build-6.5304dada9e4503
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7

Open the chart page →

2,138
pulsarapache4.7.02 of 10See more

pulsar apache 4.7.0

2 of the 10 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
golang.org/x/net@v0.19.0
stdlib@go1.24.0
0.36.0
1.23.7
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.36.0
1.23.7

Open the chart page →

9,869
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.36.0
1.23.7

Open the chart page →

6,949
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
stdlib@go1.19.9
1.23.7

Open the chart page →

22,115
botkubeinfracloudioVerified publisher1.14.01 of 1See more

botkube infracloudio 1.14.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.14.0c6fe64c7bfcd
golang.org/x/net@v0.23.0
stdlib@go1.21.13
0.36.0
1.23.7

Open the chart page →

1,097
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.36.0
1.23.7

Open the chart page →

4,086
rabbitmqgroundhog2k2.3.81 of 2See more

rabbitmq groundhog2k 2.3.8

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.51773ab33af6a
stdlib@go1.22.2
1.23.7

Open the chart page →

1,040
oktetooktetoOfficialVerified publisher0.0.0-2026-08-172 of 10See more

okteto okteto 0.0.0-2026-08-17

2 of the 10 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/okteto/buildkit:0.0.0-2026-08-1714527ca5d2a9
golang.org/x/net@v0.35.0
0.36.0
ghcr.io/okteto/okteto:3.22.04585017f52f6
stdlib@go1.24.0
1.23.7

Open the chart page →

5,491
prometheus-msteamsprometheus-msteams1.3.61 of 1See more

prometheus-msteams prometheus-msteams 1.3.6

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/prometheusmsteams/prometheus-msteams:v1.5.3a9f4d31ab811
golang.org/x/net@v0.7.0
0.36.0

Open the chart page →

941
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.36.0
1.23.7

Open the chart page →

4,159
headscalegabe565Verified publisher0.16.01 of 2See more

headscale gabe565 0.16.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/juanfont/headscale:v0.25.097febecbe6cb
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.36.0
1.23.7

Open the chart page →

1,985

Container images carrying it

3,269 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
gocrane/crane-scheduler-controller:0.1.23a2d7e60576f9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.2
0.36.0
1.23.7
1
gogs/gogs:0.12.30195b095d0b2
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.14.7
0.36.0
1.23.7
1
gogs/gogs:0.12.1420d53bb7277
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
stdlib@go1.14.7
0.36.0
1.23.7
1
goharbor/chartmuseum-photon:v2.5.36ab3ca28e9e5
golang.org/x/net@v0.0.0-20220121210141-e204ce36a2ba
stdlib@go1.17.7
0.36.0
1.23.7
1
goharbor/harbor-acceld:0.2.13451103a6c8d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.36.0
1.23.7
1
goharbor/harbor-core:v2.9.06412d679fdc3
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.36.0
1.23.7
1
goharbor/harbor-core:v2.5.386bf3031f4a7
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.7
0.36.0
1.23.7
1
goharbor/harbor-core:v2.11.1c017dd84ee96
golang.org/x/net@v0.24.0
stdlib@go1.22.6
0.36.0
1.23.7
1
goharbor/harbor-jobservice:v2.9.039435daedd0c
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.36.0
1.23.7
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.7
0.36.0
1.23.7
1
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
stdlib@go1.17.7
0.36.0
1.23.7
1
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.36.0
1.23.7
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.36.0
1.23.7
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.15
0.36.0
1.23.7
1
goharbor/registry-photon:v2.11.15645d459af2b
stdlib@go1.22.6
1.23.7
1
goharbor/registry-photon:v2.9.08a26e8cb7862
stdlib@go1.20.7
1.23.7
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
golang.org/x/net@v0.28.0
0.36.0
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
stdlib@go1.18.3
0.36.0
1.23.7
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.36.0
1.23.7
1
golift/unifi-poller:v2.9.5486a63339969
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.36.0
1.23.7
1
golift/unifi-poller:v2.9.2585a29a06d05
golang.org/x/net@v0.15.0
stdlib@go1.21.0
0.36.0
1.23.7
1
golift/unifi-poller:2.0.0cafac968b540
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.7
0.36.0
1.23.7
1
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.13.4
0.36.0
1.23.7
1
gomods/athens:v0.11.0efb811df7844
golang.org/x/net@v0.0.0-20200222125558-5a598a2470a0
stdlib@go1.13.10
0.36.0
1.23.7
1
goofball222/pritunl:1.32.3602.807bf26032dfce
golang.org/x/net@v0.7.0
stdlib@go1.18.7
0.36.0
1.23.7
1
gophish/gophish:0.12.18a57cd171999
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.15.2
0.36.0
1.23.7
1
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16
0.36.0
1.23.7
1
gotson/komga:1.22.0ba892ab3e082
stdlib@go1.17.8
1.23.7
1
gradiant/open5gs-dbctl:0.10.3332031245fce
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.36.0
1.23.7
1
grafana/agent:v0.44.23364714a2f64
golang.org/x/net@v0.33.0
stdlib@go1.22.11
0.36.0
1.23.7
1
grafana/agent:v0.20.0825c09373d27
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16
0.36.0
1.23.7
1
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.36.0
1.23.7
1
grafana/agent-operator:v0.34.1045c9125634c
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.36.0
1.23.7
1
grafana/alloy:v1.5.101a63f4e032c
golang.org/x/net@v0.31.0
stdlib@go1.22.7
0.36.0
1.23.7
1
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/net@v0.29.0
stdlib@go1.22.7
0.36.0
1.23.7
1
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.36.0
1.23.7
1
grafana/beyla:1.3.336d07f8d276e
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.36.0
1.23.7
1
grafana/grafana:6.6.0052147d7e0ec
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.36.0
1.23.7
1
grafana/grafana:10.1.50679e877ba20
golang.org/x/net@v0.12.0
stdlib@go1.20.10
0.36.0
1.23.7
1
grafana/grafana:7.5.609bb407e26ab
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.1
0.36.0
1.23.7
1
grafana/grafana:7.3.315b977f5207d
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.1
0.36.0
1.23.7
1
grafana/grafana:9.4.71a359d92f40e
golang.org/x/net@v0.4.0
stdlib@go1.20.1
0.36.0
1.23.7
1
grafana/grafana:10.1.11b9ca4bbc4a2
golang.org/x/net@v0.12.0
stdlib@go1.20.8
0.36.0
1.23.7
1
grafana/grafana:9.5.239c849cebccc
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.36.0
1.23.7
1
grafana/grafana:11.2.2-security-01464eac539793
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.36.0
1.23.7
1
grafana/grafana:11.5.15781759b3d27
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.36.0
1.23.7
1
grafana/grafana:8.0.3696823fbc561
golang.org/x/net@v0.0.0-20210521195947-fe42d452be8f
stdlib@go1.16.1
0.36.0
1.23.7
1
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/net@v0.19.0
stdlib@go1.21.3
0.36.0
1.23.7
1
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.5
0.36.0
1.23.7
1
grafana/grafana:7.2.1733842cca5bd
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.1
0.36.0
1.23.7
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.