StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,692
of 17,790 indexed, latest versions
Container images
3,270
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,692 of 17,790 indexed charts deploy, on 3,270 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+201 more0.36.02,490
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+147 more1.23.73,169
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,692 by stars
ChartLatestAffected imagesRadar Score
k8s-appliershlomibendavidOfficialVerified publisher1.0.11 of 1See more

k8s-applier shlomibendavid 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
shlomibendavid/k8s-applier:0311240529a22ffbe0f04e
golang.org/x/net@v0.19.0
stdlib@go1.21.7
0.36.0
1.23.7

Open the chart page →

1,206
clickhousesignoz24.1.183 of 3See more

clickhouse signoz 24.1.18

3 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.36.0
1.23.7
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.36.0
1.23.7
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.23.7

Open the chart page →

4,698
cosignedsigstoreVerified publisher0.1.232 of 2See more

cosigned sigstore 0.1.23

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
gcr.io/projectsigstore/cosigneddigest-pinned784518ff3ee7
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.9
0.36.0
1.23.7
gcr.io/projectsigstore/policy-webhookdigest-pinned82940e8c3e0d
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.9
0.36.0
1.23.7

Open the chart page →

5,132
scaffoldsigstoreVerified publisher0.6.1152 of 15See more

scaffold sigstore 0.6.115

2 of the 15 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/redisdigest-pinned148bb5411c18
stdlib@go1.18.2
1.23.7
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.23.7

Open the chart page →

7,686
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
golang.org/x/net@v0.27.0
stdlib@go1.22.12
0.36.0
1.23.7

Open the chart page →

4,277
postgresql-singlesinextraVerified publisher1.15.11 of 1See more

postgresql-single sinextra 1.15.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
stdlib@go1.16.15
1.23.7

Open the chart page →

4,937
altinity-clickhouse-operatorslamdev0.1.22 of 2See more

altinity-clickhouse-operator slamdev 0.1.2

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.20.08f0f582d41f0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.36.0
1.23.7
altinity/metrics-exporter:0.20.01a46d104406d
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.36.0
1.23.7

Open the chart page →

6,420
docker-registry-uislamdev0.0.11 of 1See more

docker-registry-ui slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quiq/docker-registry-ui:0.9.491281da47036
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
stdlib@go1.18
0.36.0
1.23.7

Open the chart page →

2,200
external-secrets-operatorslamdev0.0.151 of 1See more

external-secrets-operator slamdev 0.0.15

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
slamdev/external-secrets-operator:0.0.8855f6625dda4
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.36.0
1.23.7

Open the chart page →

2,301
smallest-self-hostsmallest-self-hostVerified publisher0.2.26 of 12See more

smallest-self-host smallest-self-host 0.2.2

6 of the 12 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:11.0.00dc5a246ab16
golang.org/x/net@v0.23.0
stdlib@go1.21.10
0.36.0
1.23.7
quay.io/prometheus-operator/prometheus-operator:v0.74.06b3f6d8b4c0a
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.36.0
1.23.7
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.36.0
1.23.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
stdlib@go1.21.8
0.36.0
1.23.7
registry.k8s.io/nfd/node-feature-discovery:v0.16.619ebca8b3804
golang.org/x/net@v0.25.0
stdlib@go1.22.8
0.36.0
1.23.7
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.36.0
1.23.7

Open the chart page →

7,705
smarter-edgesmarterOfficialVerified publisher0.0.151 of 1See more

smarter-edge smarter 0.0.15

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/smarter-device-manager:v1.20.12228f7f44594a
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.36.0
1.23.7

Open the chart page →

1,151
yopasssoftizyVerified publisher1.0.11 of 2See more

yopass softizy 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
jhaals/yopass:11.4.69516e3b3e88c
stdlib@go1.19.1
1.23.7

Open the chart page →

1,461
artifact-hubsoftonic1.19.05 of 8See more

artifact-hub softonic 1.19.0

5 of the 8 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
aquasec/trivy:0.43.1944a04445179
golang.org/x/net@v0.11.0
stdlib@go1.19.10
0.36.0
1.23.7
artifacthub/db-migrator:v1.19.02a746b289fcd
stdlib@go1.22.4
1.23.7
artifacthub/hub:v1.19.0111918d8c399
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.36.0
1.23.7
artifacthub/scanner:v1.19.0323d026e78c3
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.36.0
1.23.7
artifacthub/tracker:v1.19.06596c8c4d955
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.36.0
1.23.7

Open the chart page →

14,550
gcp-quota-exportersoftonic2.0.21 of 1See more

gcp-quota-exporter softonic 2.0.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
stdlib@go1.13.12
0.36.0
1.23.7

Open the chart page →

2,643
go-ratelimitsoftonic1.0.72 of 3See more

go-ratelimit softonic 1.0.7

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:v1.4.071081616da3e
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14
0.36.0
1.23.7
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.23.7

Open the chart page →

5,105
node-policy-webhooksoftonic0.1.101 of 1See more

node-policy-webhook softonic 0.1.10

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
softonic/node-policy-webhook:0.1.2ab6098c04a53
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.6
0.36.0
1.23.7

Open the chart page →

2,591
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.23.7

Open the chart page →

2,330
rabbitmqsolidchartsVerified publisher0.7.51 of 2See more

rabbitmq solidcharts 0.7.5

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.5-managementffd1b50c522a
stdlib@go1.22.2
1.23.7

Open the chart page →

1,045
gloosolo-gloo-edge0.0.0-fork4 of 5See more

gloo solo-gloo-edge 0.0.0-fork

4 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/solo-io/certgen:0.0.0-forkb17a8c7d1f32
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.1
0.36.0
1.23.7
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.1
0.36.0
1.23.7
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.1
0.36.0
1.23.7
quay.io/solo-io/gloo-envoy-wrapper:0.0.0-fork26ae185e835a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.1
0.36.0
1.23.7

Open the chart page →

9,256
sp-otel-collectorsp-otel-collectorVerified publisher1.1.61 of 1See more

sp-otel-collector sp-otel-collector 1.1.6

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.36.0
1.23.7

Open the chart page →

2,032
sql-operatorsql-operatorOfficialVerified publisher0.11.21 of 1See more

sql-operator sql-operator 0.11.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/stenic/sql-operator:1.13.2f4324baa2aad
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.17.13
0.36.0
1.23.7

Open the chart page →

1,594
gitwebhookproxystakaterVerified publisher0.2.791 of 1See more

gitwebhookproxy stakater 0.2.79

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
stakater/gitwebhookproxy:v0.2.79c1226e5270cd
stdlib@go1.13.1
1.23.7

Open the chart page →

1,503
splunk-operatorstakaterVerified publisher0.0.61 of 2See more

splunk-operator stakater 0.0.6

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
splunk/splunk-operator:2.0.0c4e0d3146226
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.17.12
0.36.0
1.23.7

Open the chart page →

11,459
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ipfs/kubo:v0.24.0e3de33bd746b
golang.org/x/net@v0.17.0
stdlib@go1.19.8
0.36.0
1.23.7

Open the chart page →

4,694
mayastorstartechnicaVerified publisher0.2.03 of 13See more

mayastor startechnica 0.2.0

3 of the 13 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.36.0
1.23.7
registry.k8s.io/sig-storage/livenessprobe:v2.8.0cacee2b5c36d
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
stdlib@go1.18
0.36.0
1.23.7

Open the chart page →

4,367
statpingstatping0.1.141 of 1See more

statping statping 0.1.14

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
stdlib@go1.14.13
0.36.0
1.23.7

Open the chart page →

3,378
stornxstornxVerified publisher1.1.11 of 9See more

stornx stornx 1.1.1

1 of the 9 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
golang.org/x/net@v0.33.0
0.36.0

Open the chart page →

11,735
hlf-k8ssubstraVerified publisher10.2.43 of 7See more

hlf-k8s substra 10.2.4

3 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:1.5.0f270dfeee91d
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
stdlib@go1.15.7
0.36.0
1.23.7
ghcr.io/substra/fabric-peer:0.2.4f681e0343a31
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

12,030
Grafanasurajwarbhe-grafana0.1.01 of 1See more

Grafana surajwarbhe-grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
surajwarbhe/grafana:v185248611e9f1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.36.0
1.23.7

Open the chart page →

2,604
hello-appsysintelligentVerified publisher2.0.11 of 1See more

hello-app sysintelligent 2.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
sysintelligent/hello-app:2.0.177fb30df847d
golang.org/x/net@v0.19.0
stdlib@go1.19.3
0.36.0
1.23.7

Open the chart page →

1,880
terraform-controllerterraform-controller0.0.201 of 1See more

terraform-controller terraform-controller 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
absaoss/terraform-controller:v0.0.20ad538a1285a0
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.14.8
0.36.0
1.23.7

Open the chart page →

3,538
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
golang.org/x/net@v0.7.0
stdlib@go1.20.6
0.36.0
1.23.7

Open the chart page →

9,119
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
golang.org/x/net@v0.7.0
stdlib@go1.20.6
0.36.0
1.23.7

Open the chart page →

9,119
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.5-debian-11-r66fe59ed5d79f
golang.org/x/net@v0.19.0
stdlib@go1.20.12
0.36.0
1.23.7

Open the chart page →

13,017
goalerttokens-studioVerified publisher0.0.51 of 2See more

goalert tokens-studio 0.0.5

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
goalert/goalert:v0.32.008d57388b0cb
golang.org/x/net@v0.20.0
stdlib@go1.22.1
0.36.0
1.23.7

Open the chart page →

1,476
tor-snowflake-proxytor-snowflake-proxyVerified publisher1.2.01 of 1See more

tor-snowflake-proxy tor-snowflake-proxy 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
thetorproject/snowflake-proxy:v2.11.01ddc5069d354
golang.org/x/net@v0.35.0
0.36.0

Open the chart page →

740
spa-reloadertoucanVerified publisher0.1.01 of 1See more

spa-reloader toucan 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
toucansoftware/spa-reloader:latestc187b1fba501
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.36.0
1.23.7

Open the chart page →

2,245
traefik-hubtraefikOfficialVerified publisher4.2.01 of 1See more

traefik-hub traefik 4.2.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
golang.org/x/net@v0.17.0
stdlib@go1.21.8
0.36.0
1.23.7

Open the chart page →

3,171
atlantistrozz3.12.111 of 1See more

atlantis trozz 3.12.11

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
runatlantis/atlantis:v0.16.145fbaf7e207c
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.14.7
0.36.0
1.23.7

Open the chart page →

5,286
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
golang.org/x/net@v0.26.0
stdlib@go1.22.8
0.36.0
1.23.7

Open the chart page →

4,075
boundaryundergridVerified publisher0.1.02 of 3See more

boundary undergrid 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v1.684edcf796267
stdlib@go1.18.1
1.23.7
hashicorp/boundary:0.8.1fb70bd9210ff
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.10
0.36.0
1.23.7

Open the chart page →

4,965
upbot-operatorupbot-operator0.0.201 of 2See more

upbot-operator upbot-operator 0.0.20

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
alpine/k8s:1.28.13e5c0b053fed7
golang.org/x/net@v0.12.0
stdlib@go1.22.5
0.36.0
1.23.7

Open the chart page →

4,477
user-componentuser-component1.2.01 of 4See more

user-component user-component 1.2.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,313
phonebook-chartusuladamsVerified publisher0.1.51 of 3See more

phonebook-chart usuladams 0.1.5

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.23.7

Open the chart page →

3,176
v2ray-proxyv2ray-proxy0.2.41 of 1See more

v2ray-proxy v2ray-proxy 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
pinclr/v2ray-proxy:latestf37f250b7091
golang.org/x/net@v0.7.0
stdlib@go1.20.2
0.36.0
1.23.7

Open the chart page →

1,961
vault-gcp-secretsvault-gcp-secrets1.19.51 of 1See more

vault-gcp-secrets vault-gcp-secrets 1.19.5

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7

Open the chart page →

2,299
vearchvearch3.3.42 of 4See more

vearch vearch 3.3.4

2 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.36.0
1.23.7
vearch/vearch:3.3.40768af33f9d9
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.36.0
1.23.7

Open the chart page →

5,022
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.36.0
1.23.7

Open the chart page →

5,259
riveruivirtualrootVerified publisher0.1.31 of 1See more

riverui virtualroot 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/riverqueue/riverui:0.5.32dc54179b25a
golang.org/x/net@v0.23.0
stdlib@go1.23.0
0.36.0
1.23.7

Open the chart page →

1,135
go-egvoid-xmh1.1.13 of 3See more

go-eg void-xmh 1.1.1

3 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
voidxmh/xmh-auther:v193e42a569ca8
stdlib@go1.16.5
1.23.7
voidxmh/xmh-cacher:v11b7397412320
stdlib@go1.16.5
1.23.7
voidxmh/xmh-ui:v12ff3f2146547
stdlib@go1.16.5
1.23.7

Open the chart page →

7,464

Container images carrying it

3,270 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
thecampagnards/trafficlight-api:main7dca9d973837
stdlib@go1.16.4
1.23.7
1
thecodingmachine/workadventure-back:v1.17.764001369dad5
stdlib@go1.20.7
1.23.7
1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
stdlib@go1.17.13
1.23.7
1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
stdlib@go1.19.3
1.23.7
1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
stdlib@go1.20.7
1.23.7
1
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
stdlib@go1.20.7
1.23.7
1
thesisrobot/lnd:v0.16.4-beta-c287129953689
golang.org/x/net@v0.8.0
stdlib@go1.21.0
0.36.0
1.23.7
1
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.1
0.36.0
1.23.7
1
thetorproject/snowflake-proxy:v2.11.01ddc5069d354
golang.org/x/net@v0.35.0
0.36.0
1
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
stdlib@go1.20.12
1.23.7
1
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/net@v0.17.0
stdlib@go1.20.11
0.36.0
1.23.7
1
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.36.0
1.23.7
1
thomseddon/traefik-forward-auth:latestb364aa6a4117
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.15
0.36.0
1.23.7
1
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
stdlib@go1.13.12
0.36.0
1.23.7
1
tile38/tile38:1.33.4afb7e82f9485
golang.org/x/net@v0.23.0
stdlib@go1.23.2
0.36.0
1.23.7
1
timescale/timescaledb:latest-pg12645fd9e92d76
stdlib@go1.18.7
1.23.7
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
stdlib@go1.19.1
1.23.7
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
stdlib@go1.19.1
1.23.7
1
timescale/timescaledb-ha:pg16d7db8f1085a3
golang.org/x/net@v0.26.0
stdlib@go1.23.0
0.36.0
1.23.7
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
golang.org/x/net@v0.33.0
stdlib@go1.21.13
0.36.0
1.23.7
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
stdlib@go1.15.6
1.23.7
1
timescale/timescaledb-postgis:latest-pg127758704d4a14
stdlib@go1.14
1.23.7
1
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
stdlib@go1.13.5
1.23.7
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
golang.org/x/net@v0.21.0
stdlib@go1.22.2
0.36.0
1.23.7
1
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.20.3
0.36.0
1.23.7
1
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
stdlib@go1.13.10
0.36.0
1.23.7
1
tobiasehlert/teslamateapi:1.20.2cf09259ad0ea
stdlib@go1.24.0
1.23.7
1
tobirachel/node-project3:v17d9f37154994
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.5
0.36.0
1.23.7
1
toucansoftware/spa-reloader:latestc187b1fba501
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.15
0.36.0
1.23.7
1
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.19
0.36.0
1.23.7
1
traefik/whoami:v1.10.21474027c3166
golang.org/x/net@v0.25.0
stdlib@go1.22.2
0.36.0
1.23.7
1
traefik/whoami:v1.101699d99cb4b9
stdlib@go1.23.5
1.23.7
1
traefik/whoami:v1.6.12c52bb2c8480
stdlib@go1.15.6
1.23.7
1
traefik/whoami:v1.8.08d0f943abdbf
stdlib@go1.17.7
1.23.7
1
traefik/whoami:v1.6.0d38496bf0900
stdlib@go1.15.2
1.23.7
1
traggo/server:0.2.3f1ced637510e
stdlib@go1.13.1
1.23.7
1
tranhailong/nfs-server:4.2-2-gcsfuse028662749be2
golang.org/x/net@v0.4.0
stdlib@go1.18.4
0.36.0
1.23.7
1
treeverse/lakefs:0.69.0478f37a6cffc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.8
0.36.0
1.23.7
1
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.5
0.36.0
1.23.7
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.3
0.36.0
1.23.7
1
tusproject/tusd:v1.10.01e457b59fd5b
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.2
0.36.0
1.23.7
1
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.36.0
1.23.7
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.21.7
0.36.0
1.23.7
1
twinproduction/aws-eks-asg-rolling-update-handler:v1.7.08f38c206972e
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.36.0
1.23.7
1
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.1
0.36.0
1.23.7
1
ubercadence/server:0.23.22ac5491d13bb
golang.org/x/net@v0.0.0-20201031054903-ff519b6c9102
stdlib@go1.13.6
0.36.0
1.23.7
1
udhos/forward:1.1.312e120d39fdb
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.36.0
1.23.7
1
udhos/lambdaping:1.0.46bd2cf2ac732
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.36.0
1.23.7
1
udhos/miniapi:1.3.28a7042db82ce
stdlib@go1.23.2
1.23.7
1
udhos/prime:1.0.0e432012dd34a
stdlib@go1.20.4
1.23.7
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.