StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,692
of 17,790 indexed, latest versions
Container images
3,270
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,692 of 17,790 indexed charts deploy, on 3,270 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+201 more0.36.02,490
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+147 more1.23.73,169
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,692 by stars
ChartLatestAffected imagesRadar Score
kubedb-ui-serverappscodeVerified publisher2021.12.211 of 1See more

kubedb-ui-server appscode 2021.12.21

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.8
0.36.0
1.23.7

Open the chart page →

2,054
kubeform-provider-awsappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-aws appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
golang.org/x/net@v0.10.0
stdlib@go1.19.1
0.36.0
1.23.7

Open the chart page →

2,803
kubeform-provider-azureappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-azure appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.20.5
0.36.0
1.23.7

Open the chart page →

2,724
kubeform-provider-gcpappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-gcp appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
golang.org/x/net@v0.9.0
stdlib@go1.19.9
0.36.0
1.23.7

Open the chart page →

2,750
kubevirt-infra-csi-driverappscodeVerified publisher0.1.01 of 6See more

kubevirt-infra-csi-driver appscode 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.36.0
1.23.7

Open the chart page →

1,209
kubevirt-tenant-csi-driverappscodeVerified publisher0.1.01 of 4See more

kubevirt-tenant-csi-driver appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
golang.org/x/net@v0.17.0
stdlib@go1.20.5
0.36.0
1.23.7

Open the chart page →

1,297
license-proxyserver-addon-managerappscodeVerified publisher2024.2.251 of 1See more

license-proxyserver-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.0.8d6c2532ea386
golang.org/x/net@v0.19.0
stdlib@go1.22.1
0.36.0
1.23.7

Open the chart page →

1,391
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
golang.org/x/net@v0.19.0
stdlib@go1.22.0
0.36.0
1.23.7

Open the chart page →

2,404
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.36.0
1.23.7

Open the chart page →

4,050
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.36.0
1.23.7

Open the chart page →

2,575
platform-linksappscodeVerified publisher2026.9.111 of 1See more

platform-links appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
golang.org/x/net@v0.26.0
0.36.0

Open the chart page →

778
service-gatewayappscodeVerified publisher2026.9.111 of 3See more

service-gateway appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109fa56a9251de6
stdlib@go1.19
1.23.7

Open the chart page →

2,155
service-presetsappscodeVerified publisher2024.2.111 of 1See more

service-presets appscode 2024.2.11

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.23.7

Open the chart page →

824
service-providerappscodeVerified publisher2026.9.111 of 2See more

service-provider appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.36.0
1.23.7

Open the chart page →

2,238
stash-communityappscodeVerified publisher0.42.03 of 4See more

stash-community appscode 0.42.0

3 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.36.0
1.23.7
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
0.36.0
ghcr.io/stashed/stash:v0.42.03a98245a7667
golang.org/x/net@v0.26.0
stdlib@go1.23.3
0.36.0
1.23.7

Open the chart page →

3,669
statefulsetappscodeVerified publisher0.0.12 of 3See more

statefulset appscode 0.0.1

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.36.0
1.23.7
ghcr.io/appscode/kubectl-nonroot:v1.248ee5bdd68977
stdlib@go1.20.7
1.23.7

Open the chart page →

2,739
vcd-lb-gcappscodeVerified publisher2026.6.251 of 1See more

vcd-lb-gc appscode 2026.6.25

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/vcd-lb-gc:v0.1.0524c4045cd21
golang.org/x/net@v0.23.0
0.36.0

Open the chart page →

178
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
golang.org/x/net@v0.11.0
stdlib@go1.21.1
0.36.0
1.23.7

Open the chart page →

5,680
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
golang.org/x/net@v0.19.0
stdlib@go1.22.2
0.36.0
1.23.7

Open the chart page →

1,205
appwriteappwrite-helmVerified publisher1.3.23 of 8See more

appwrite appwrite-helm 1.3.2

3 of the 8 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.23.7
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.23.7
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.23.7

Open the chart page →

9,855
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.36.0
1.23.7

Open the chart page →

5,211
argocdargo-helm-charts1.0.03 of 3See more

argocd argo-helm-charts 1.0.0

3 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.36.0
1.23.7
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.23.7
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/net@v0.34.0
stdlib@go1.22.2
0.36.0
1.23.7

Open the chart page →

7,359
argonix-apiargonix0.2.31 of 4See more

argonix-api argonix 0.2.3

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0cb5f24732197
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7

Open the chart page →

4,956
arlas-aiasarlas-stackVerified publisher28.8.02 of 22See more

arlas-aias arlas-stack 28.8.0

2 of the 22 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.36.0
1.23.7
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
golang.org/x/net@v0.33.0
0.36.0

Open the chart page →

40,580
arma-reforgerarma-reforger0.5.38 of 8See more

arma-reforger arma-reforger 0.5.3

8 of the 8 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.36.0
1.23.7
stakater/reloader:v1.0.15f4b87a8e56d4
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.36.0
1.23.7
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.36.0
1.23.7
quay.io/prometheus-operator/prometheus-config-reloader:v0.63.03f976422884e
stdlib@go1.19.5
1.23.7
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.36.0
1.23.7
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.36.0
1.23.7
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.36.0
1.23.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.36.0
1.23.7

Open the chart page →

23,425
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.36.0
1.23.7

Open the chart page →

1,779
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.11
0.36.0
1.23.7
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.10
0.36.0
1.23.7
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.36.0
1.23.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.36.0
1.23.7

Open the chart page →

8,621
assemblylineassemblylineVerified publisher7.4.192 of 12See more

assemblyline assemblyline 7.4.19

2 of the 12 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.36.0
1.23.7
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.36.0
1.23.7

Open the chart page →

12,666
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.23.7

Open the chart page →

5,537
dltkvassist-iot-data-integrity-verification0.2.04 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

4 of the 9 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.36.0
1.23.7
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

77,883
dltflassist-iot-dlt-based-fl0.2.04 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

4 of the 9 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.36.0
1.23.7
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

77,883
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
stdlib@go1.17.10
0.36.0
1.23.7

Open the chart page →

3,786
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
stdlib@go1.17.10
1.23.7

Open the chart page →

9,411
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
stdlib@go1.17.10
0.36.0
1.23.7

Open the chart page →

4,367
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
stdlib@go1.18.2
1.23.7

Open the chart page →

13,369
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
stdlib@go1.18.2
1.23.7

Open the chart page →

10,127
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.36.0
1.23.7
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18
0.36.0
1.23.7

Open the chart page →

18,357
performanceandusagediagnosisassist-iot-pud1.0.05 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

5 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.17.12
0.36.0
1.23.7
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.23.7
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.36.0
1.23.7
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.3
0.36.0
1.23.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.36.0
1.23.7

Open the chart page →

8,570
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.23.7

Open the chart page →

8,052
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.22.1
1.23.7
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.23.7
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.23.7

Open the chart page →

45,656
astrotrekastria0.0.24 of 4See more

astrotrek astria 0.0.2

4 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
stdlib@go1.19.1
1.23.7
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.36.0
1.23.7
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.36.0
1.23.7
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
stdlib@go1.20.12
1.23.7

Open the chart page →

32,638
evm-faucetastria0.1.51 of 1See more

evm-faucet astria 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
stdlib@go1.17.13
1.23.7

Open the chart page →

1,764
evm-rollupastria4.1.01 of 2See more

evm-rollup astria 4.1.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.36.0
1.23.7

Open the chart page →

4,010
evm-stackastria5.0.31 of 2See more

evm-stack astria 5.0.3

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.36.0
1.23.7

Open the chart page →

4,010
flame-rollupastria0.1.31 of 2See more

flame-rollup astria 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.36.0
1.23.7

Open the chart page →

3,710
graph-nodeastria0.2.21 of 3See more

graph-node astria 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ipfs/kubo:v0.17.0803fac58ba15
golang.org/x/net@v0.1.0
stdlib@go1.19.1
0.36.0
1.23.7

Open the chart page →

5,547
sequencerastria4.0.02 of 3See more

sequencer astria 4.0.0

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
cometbft/cometbft:v0.38.1722c2ac018f40
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.36.0
1.23.7
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.6
0.36.0
1.23.7

Open the chart page →

6,335
sequencer-faucetastria0.9.21 of 1See more

sequencer-faucet astria 0.9.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
golang.org/x/net@v0.28.0
stdlib@go1.22.6
0.36.0
1.23.7

Open the chart page →

1,320
phonebook-chartasumankamberoglu0.1.51 of 3See more

phonebook-chart asumankamberoglu 0.1.5

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.23.7

Open the chart page →

3,176
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

9,429

Container images carrying it

3,270 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
kubedb/kubedb-enterprise:v0.11.05829bcedcb0d
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.3
0.36.0
1.23.7
1
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.8
0.36.0
1.23.7
1
kubedb/operator:v0.24.01a06ff0bda52
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.17.6
0.36.0
1.23.7
1
kubeedge/edgemesh-agent:latest460c6061b608
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.36.0
1.23.7
1
kubeedge/edgemesh-server:latesta437cf5ec0ae
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.11
0.36.0
1.23.7
1
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.1
0.36.0
1.23.7
1
kubeflowkatib/katib-controller:v0.17.072f14e03b9e1
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.36.0
1.23.7
1
kubeflowkatib/katib-db-manager:v0.17.0916a7695b0dd
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.36.0
1.23.7
1
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
golang.org/x/net@v0.0.0-20191021144547-ec77196f6094
stdlib@go1.13.3
0.36.0
1.23.7
1
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.1
0.36.0
1.23.7
1
kubeflowkatib/katib-ui:v0.17.07a41c508deb1
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.36.0
1.23.7
1
kubeflow/model-registry:v0.2.95783f6db428f
golang.org/x/net@v0.28.0
stdlib@go1.21.13
0.36.0
1.23.7
1
kubeflownotebookswg/kfam:v1.9.22060a2ede788
golang.org/x/net@v0.17.0
stdlib@go1.17.13
0.36.0
1.23.7
1
kubeflownotebookswg/kfam:v1.6.1f226fb44db57
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.17.13
0.36.0
1.23.7
1
kubeflownotebookswg/notebook-controller:v1.9.20f14bd28fdd5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.36.0
1.23.7
1
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.36.0
1.23.7
1
kubeflownotebookswg/poddefaults-webhook:v1.6.17d42600e1524
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.13
0.36.0
1.23.7
1
kubeflownotebookswg/poddefaults-webhook:v1.9.2bde88d98ad74
golang.org/x/net@v0.13.0
stdlib@go1.21.13
0.36.0
1.23.7
1
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.36.0
1.23.7
1
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.36.0
1.23.7
1
kubeflownotebookswg/pvcviewer-controller:v1.9.29815e9b1728f
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.36.0
1.23.7
1
kubeflownotebookswg/tensorboard-controller:v1.9.26536a9f61193
golang.org/x/net@v0.17.0
stdlib@go1.17.13
0.36.0
1.23.7
1
kubeflownotebookswg/tensorboard-controller:v1.6.182ffdd2da285
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.36.0
1.23.7
1
kubeflow/training-operator:v1-04f9f13dabb76dbda29
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
1
kubeflow/training-operator:v1-e1434f6ff847e2b6af0
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.11
0.36.0
1.23.7
1
kubegems/alertproxy:v0.4.2eaee03055329
stdlib@go1.18.10
1.23.7
1
kubegems/chatgpt-api:latestf3c492a938ad
stdlib@go1.19.3
1.23.7
1
kubegems/chatgpt-api-feishubot:latest7c93c84b2055
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.36.0
1.23.7
1
kubegems/chatgpt-api-proxy:latest8905c9dbbb5d
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.36.0
1.23.7
1
kubegems/ingress-nginx-operator:v0.2.0cc67357beeeb
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.22.5
0.36.0
1.23.7
1
kubegems/kubectl:latestc3b4be9a54f5
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.20
0.36.0
1.23.7
1
kubegems/kube-rbac-proxy:v0.8.0941f557ed1ee
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.13.15
0.36.0
1.23.7
1
kubegems/mysql:8.0.33-debian-11-r019cb195b9a50
stdlib@go1.19.8
1.23.7
1
kubegems/redis:7.2.5-debian-12-r2870ee3a77add
stdlib@go1.21.11
1.23.7
1
kubemod/kubemod:v0.19.11f8154f7e80c
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.18
0.36.0
1.23.7
1
kubemod/kubemod:v0.13.0cadca39288ad
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.14.7
0.36.0
1.23.7
1
kubemod/kubemod-crt:v1.3.0028347c9fa77
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.18.1
0.36.0
1.23.7
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
golang.org/x/net@v0.0.0-20200519113804-d87ec0cfa476
stdlib@go1.14
0.36.0
1.23.7
1
kuberay/operator:v1.0.04e6ac8a3a2c4
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.36.0
1.23.7
1
kubernetesui/dashboard:v2.6.1290bebc3cd96
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
stdlib@go1.19
0.36.0
1.23.7
1
kubernetesui/dashboard:v2.7.02e500d29e9d5
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.36.0
1.23.7
1
kubernetesui/dashboard-api:1.7.060595892c2cf
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.36.0
1.23.7
1
kubernetesui/dashboard-auth:1.1.307135c09e9ff
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.36.0
1.23.7
1
kubernetesui/dashboard-metrics-scraper:1.2.25154b68252bd
golang.org/x/net@v0.34.0
stdlib@go1.23.4
0.36.0
1.23.7
1
kubernetesui/dashboard-metrics-scraper:1.1.17747d363c9fe
golang.org/x/net@v0.21.0
stdlib@go1.22.1
0.36.0
1.23.7
1
kubernetesui/dashboard-web:1.4.04445b31a2c25
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.36.0
1.23.7
1
kubernetesui/metrics-scraper:v1.0.876049887f07a
golang.org/x/net@v0.0.0-20220524220425-1d687d428aca
stdlib@go1.18.2
0.36.0
1.23.7
1
kubesec/kubesec:latest025a365d9f18
stdlib@go1.23.3
1.23.7
1
kubesec/kubesec:v2.13.0c0f3b0673578
stdlib@go1.19.7
1.23.7
1
kubeshop/kube-webhook-certgen:0.0.7866827c379ae
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.36.0
1.23.7
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.