StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,692
of 17,790 indexed, latest versions
Container images
3,270
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,692 of 17,790 indexed charts deploy, on 3,270 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+201 more0.36.02,490
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+147 more1.23.73,169
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,692 by stars
ChartLatestAffected imagesRadar Score
hellocloudechoVerified publisher0.1.21 of 1See more

hello cloudecho 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.23.7

Open the chart page →

1,817
cloudflare-exportercloudflare-exporter0.2.31 of 1See more

cloudflare-exporter cloudflare-exporter 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/lablabs/cloudflare_exporter:0.0.1670d74ec46602
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.36.0
1.23.7

Open the chart page →

791
ghostcloudpirates-ghostVerified publisher0.20.221 of 3See more

ghost cloudpirates-ghost 0.20.22

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mariadb:12.0.25b6a1eac15b8
stdlib@go1.18.2
1.23.7

Open the chart page →

7,267
cluster-registrycluster-registry-controller0.2.121 of 1See more

cluster-registry cluster-registry-controller 0.2.12

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
golang.org/x/net@v0.7.0
stdlib@go1.18
0.36.0
1.23.7

Open the chart page →

1,707
coder-observabilitycoder-observabilityVerified publisher0.7.312 of 21See more

coder-observability coder-observability 0.7.3

12 of the 21 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.36.0
1.23.7
grafana/loki:3.1.0d947e68a84d9
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.36.0
1.23.7
grafana/loki-canary:3.1.039baf6d67f85
golang.org/x/net@v0.23.0
stdlib@go1.22.2
0.36.0
1.23.7
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.36.0
1.23.7
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.23.7
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.36.0
1.23.7
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.6
0.36.0
1.23.7
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.36.0
1.23.7
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.36.0
1.23.7
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.36.0
1.23.7
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.36.0
1.23.7

Open the chart page →

24,753
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
golang.org/x/net@v0.17.0
stdlib@go1.21.5
0.36.0
1.23.7

Open the chart page →

17,569
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.36.0
1.23.7

Open the chart page →

3,088
cosmocosmo-platformOfficialVerified publisher0.20.05 of 10See more

cosmo cosmo-platform 0.20.0

5 of the 10 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
stdlib@go1.21.10
1.23.7
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.36.0
1.23.7
ghcr.io/wundergraph/cosmo/graphqlmetrics:0.33.0efb69ec3330c
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.36.0
1.23.7
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
golang.org/x/net@v0.26.0
stdlib@go1.23.6
0.36.0
1.23.7
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
stdlib@go1.20.7
1.23.7

Open the chart page →

29,070
dapr-dashboarddapr0.15.01 of 1See more

dapr-dashboard dapr 0.15.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
daprio/dashboard:0.15.04be696707bd1
golang.org/x/net@v0.25.0
stdlib@go1.21.13
0.36.0
1.23.7

Open the chart page →

1,309
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
golang.org/x/net@v0.17.0
stdlib@go1.21.10
0.36.0
1.23.7

Open the chart page →

3,458
kube-benchdeliveryheroVerified publisher0.1.171 of 1See more

kube-bench deliveryhero 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.36.0
1.23.7

Open the chart page →

1,623
listmonkdeliveryheroVerified publisher0.1.121 of 1See more

listmonk deliveryhero 0.1.12

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.36.0
1.23.7

Open the chart page →

2,537
prometheus-locust-exporterdeliveryheroVerified publisher1.2.31 of 1See more

prometheus-locust-exporter deliveryhero 1.2.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.23.7

Open the chart page →

1,276
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.23.7

Open the chart page →

4,200
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.36.0
1.23.7

Open the chart page →

2,271
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7

Open the chart page →

12,049
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7

Open the chart page →

14,552
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7

Open the chart page →

13,881
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.23.7

Open the chart page →

5,305
frp-operatorfrp-operator1.9.01 of 1See more

frp-operator frp-operator 1.9.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/zufardhiyaulhaq/frp-operator:v0.11.0cd25ee354df2
golang.org/x/net@v0.23.0
0.36.0

Open the chart page →

535
ascii-moviegabe565Verified publisher0.16.41 of 1See more

ascii-movie gabe565 0.16.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/gabe565/ascii-movie:1.9.627f85bb98da3
stdlib@go1.24.0
1.23.7

Open the chart page →

987
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.7
0.36.0
1.23.7

Open the chart page →

3,030
error-pagesgeek-cookbookVerified publisher1.2.21 of 1See more

error-pages geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
stdlib@go1.17.6
1.23.7

Open the chart page →

1,110
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.10
0.36.0
1.23.7

Open the chart page →

7,587
multusgeek-cookbookVerified publisher3.5.22 of 3See more

multus geek-cookbook 3.5.2

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/cni-plugins:v0.9.1241592d93640
stdlib@go1.15.8
1.23.7
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

4,915
network-ups-toolsgeek-cookbookVerified publisher6.4.21 of 1See more

network-ups-tools geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
stdlib@go1.15
1.23.7

Open the chart page →

14,004
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
stdlib@go1.18.4
1.23.7

Open the chart page →

9,669
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.17.8
0.36.0
1.23.7

Open the chart page →

10,221
smarter-device-managergeek-cookbookVerified publisher6.5.21 of 1See more

smarter-device-manager geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
stdlib@go1.16.4
0.36.0
1.23.7

Open the chart page →

2,336
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.13
0.36.0
1.23.7

Open the chart page →

3,378
syncthinggeek-cookbookVerified publisher3.5.21 of 1See more

syncthing geek-cookbook 3.5.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
syncthing/syncthing:1.18.2966433161272
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
stdlib@go1.17
0.36.0
1.23.7

Open the chart page →

2,610
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
stdlib@go1.16.7
1.23.7

Open the chart page →

10,671
traefik-forward-authgeek-cookbookVerified publisher2.2.21 of 1See more

traefik-forward-auth geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.36.0
1.23.7

Open the chart page →

2,234
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
stdlib@go1.20.4
1.23.7

Open the chart page →

11,900
nzbhydra2halkeye2.30.11 of 2See more

nzbhydra2 halkeye 2.30.1

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.23.7

Open the chart page →

6,714
unifi-pollerhalkeye0.1.21 of 1See more

unifi-poller halkeye 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
golift/unifi-poller:2.0.0cafac968b540
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.7
0.36.0
1.23.7

Open the chart page →

1,654
monitoring-stackhaukitechVerified publisher0.1.113 of 3See more

monitoring-stack haukitech 0.1.11

3 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.36.0
1.23.7
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
stdlib@go1.22.5
0.36.0
1.23.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.36.0
1.23.7

Open the chart page →

2,164
prometheus-operatorhaukitechVerified publisher0.1.41 of 1See more

prometheus-operator haukitech 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.36.0
1.23.7

Open the chart page →

561
headscaleheadscaleVerified publisher1.0.191 of 3See more

headscale headscale 1.0.19

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
alpine/k8s:1.36.244ef4942e171
stdlib@go1.24.0
1.23.7

Open the chart page →

3,439
health-exporterhealth-exporterVerified publisher0.3.41 of 1See more

health-exporter health-exporter 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.2
0.36.0
1.23.7

Open the chart page →

1,558
home-assistanthome-assistantVerified publisher0.5.101 of 3See more

home-assistant home-assistant 0.5.10

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
stdlib@go1.23.3
1.23.7

Open the chart page →

2,338
frpc-ingressinfinity-server0.4.11 of 1See more

frpc-ingress infinity-server 0.4.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
springhack/frpc_ingress:latest4aceb821da88
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.19.5
0.36.0
1.23.7

Open the chart page →

2,623
coreinstill-aiOfficialVerified publisher0.1.755 of 15See more

core instill-ai 0.1.75

5 of the 15 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.36.0
1.23.7
instill/artifact-backend:b28766ac4a393e601ed
golang.org/x/net@v0.33.0
0.36.0
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
stdlib@go1.18.3
0.36.0
1.23.7
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.23.7
temporalio/admin-tools:1.28cfde8170c92f
golang.org/x/net@v0.35.0
0.36.0

Open the chart page →

31,122
intel-gpu-resource-driverintelVerified publisher0.7.01 of 1See more

intel-gpu-resource-driver intel 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
intel/intel-gpu-resource-driver:v0.7.0e158711e32ce
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.36.0
1.23.7

Open the chart page →

565
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.6
0.36.0
1.23.7

Open the chart page →

2,211
calibre-webk8s-home-lab-repo9.1.11 of 1See more

calibre-web k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
stdlib@go1.17.8
1.23.7

Open the chart page →

4,526
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
stdlib@go1.23.3
1.23.7

Open the chart page →

4,639
wireguardk8s-home-lab-repo1.6.01 of 1See more

wireguard k8s-home-lab-repo 1.6.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/k8s-home-lab/wireguard:v1.0.20210914779858b5e11d
stdlib@go1.18.5
1.23.7

Open the chart page →

7,378
k8s-sftp-gcsk8s-sftp-gcsVerified publisher0.1.41 of 1See more

k8s-sftp-gcs k8s-sftp-gcs 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
danuk/k8s-sftp-gcs:latestdd0e6585c44f
stdlib@go1.18.4
1.23.7

Open the chart page →

1,606
k8statusk8statusOfficialVerified publisher0.17.01 of 1See more

k8status k8status 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/stenic/k8status:0.17.093298e03089e
golang.org/x/net@v0.26.0
0.36.0

Open the chart page →

712

Container images carrying it

3,270 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.15.12
0.36.0
1.23.7
1
shlomibendavid/k8s-applier:0311240529a22ffbe0f04e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.36.0
1.23.7
1
shyim/shopware:6.4.6.0a951c0e6b836
stdlib@go1.20.7
1.23.7
1
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.36.0
1.23.7
1
signald/signald:0.18.20ffad7ccc2eb
stdlib@go1.18.1
1.23.7
1
signald/signald:0.23.2edbff058278c
stdlib@go1.18.10
1.23.7
1
signoz/alertmanager:0.5.07bc7de2e33c2
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.14
0.36.0
1.23.7
1
sikalabs/slu:v0.72.07bd267f30247
golang.org/x/net@v0.19.0
stdlib@go1.21.4
0.36.0
1.23.7
1
sikalabs/slu:v0.34.0fdc0c6711add
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.36.0
1.23.7
1
simonschneider/traefik-jwt-decode:latestd674ac370f80
stdlib@go1.17.13
1.23.7
1
simpleidserver/faasprometheus:0.0.425e378d57d78
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.1
0.36.0
1.23.7
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
golang.org/x/net@v0.15.0
stdlib@go1.20.4
0.36.0
1.23.7
1
sky5367/locust-plugins-grafana:latestd51bf68d4b26
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.36.0
1.23.7
1
sky5367/locust-plugins-timescale:latestd3150f201471
stdlib@go1.18.7
1.23.7
1
skylenet/ethereum-genesis-generator:latest210353ce7c89
stdlib@go1.17.13
1.23.7
1
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.2
0.36.0
1.23.7
1
slagattollas/weatherservice-practica:latest68e7f56393fc
stdlib@go1.15.6
1.23.7
1
slamdev/config-connector-templater:0.0.3a234541c9fa8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.36.0
1.23.7
1
slamdev/external-secrets-operator:0.0.8855f6625dda4
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.36.0
1.23.7
1
slamdev/flux-notifier:v0.0.8b173d809132d
stdlib@go1.13.11
1.23.7
1
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
golang.org/x/net@v0.0.0-20200501053045-e0ff5e5a1de5
stdlib@go1.13.11
0.36.0
1.23.7
1
smailkoz/torrserver:1.0.1117b52d15de8f0
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.5
0.36.0
1.23.7
1
softonic/node-policy-webhook:0.1.2ab6098c04a53
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.6
0.36.0
1.23.7
1
softonic/pod-defaulter:0.1.072017aed5902
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.14.9
0.36.0
1.23.7
1
softonic/preemptible-killer:1.2.6-294b87f1fb362
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.14.10
0.36.0
1.23.7
1
softonic/rate-limit-operator:0.1.1910f6de37763
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.36.0
1.23.7
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
stdlib@go1.18.2
0.36.0
1.23.7
1
sophos/nginx-vts-exporter:latestf1073556b29b
stdlib@go1.13.6
1.23.7
1
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.8
0.36.0
1.23.7
1
speckle/alertmanager-discord:latestf6221ff308e9
stdlib@go1.22.4
1.23.7
1
splunk/splunk-operator:2.0.0c4e0d3146226
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.17.12
0.36.0
1.23.7
1
springhack/frpc_ingress:latest4aceb821da88
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.19.5
0.36.0
1.23.7
1
sstarcher/ecr-cleaner:0.1.12d43c390cb19
stdlib@go1.14.2
1.23.7
1
sstarcher/helm-exporter:0.5.011769d01ba35
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.6
0.36.0
1.23.7
1
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.9
0.36.0
1.23.7
1
stakater/gitwebhookproxy:v0.2.79c1226e5270cd
stdlib@go1.13.1
1.23.7
1
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.36.0
1.23.7
1
stakater/konfigurator:v0.1.393409565b1ef5
golang.org/x/net@v0.17.0
stdlib@go1.17.13
0.36.0
1.23.7
1
stakater/reloader:v1.0.15f4b87a8e56d4
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.36.0
1.23.7
1
stakater/tronador:v0.0.137ce9acf2722
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.11
0.36.0
1.23.7
1
stakater/whitelister:v0.0.1639107924063e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.13.1
0.36.0
1.23.7
1
stakater/workshop-operator:v0.0.3897bf456cc97c
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.13
0.36.0
1.23.7
1
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.3
0.36.0
1.23.7
1
stakkato95/twitter-service-graphql:0.1.13cbe857234f2
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.36.0
1.23.7
1
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
stdlib@go1.18.3
1.23.7
1
stakkato95/twitter-service-users:0.1.1456049efee9a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.36.0
1.23.7
1
stashapp/stash:latest24dbd7607174
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.13.15
0.36.0
1.23.7
1
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.18.10
0.36.0
1.23.7
1
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.19.10
0.36.0
1.23.7
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.6
0.36.0
1.23.7
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.