StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,765
of 17,813 indexed, latest versions
Container images
3,323
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,765 of 17,813 indexed charts deploy, on 3,323 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+201 more0.36.02,528
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+149 more1.23.73,220
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,765 by stars
ChartLatestAffected imagesRadar Score
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ecadlabs/tezos_exporter:latest4bcbe5d1cdd2
stdlib@go1.16.5
1.23.7

Open the chart page →

5,337
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
pysga1996/redis:latest3af6d0c7db19
stdlib@go1.18.2
1.23.7

Open the chart page →

4,686
local-path-provisionerth-chartsVerified publisher0.0.291 of 1See more

local-path-provisioner th-charts 0.0.29

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.299bebefa0b908
golang.org/x/net@v0.27.0
stdlib@go1.22.5
0.36.0
1.23.7

Open the chart page →

1,301
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.36.0
1.23.7

Open the chart page →

10,131
ping-exporterth-chartsVerified publisher0.1.11 of 1See more

ping-exporter th-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
czerwonk/ping_exporter:v1.1.394f51e1ef1e2
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.36.0
1.23.7

Open the chart page →

1,236
trafficlight-apithecampagnards0.1.11 of 1See more

trafficlight-api thecampagnards 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
thecampagnards/trafficlight-api:main7dca9d973837
stdlib@go1.16.4
1.23.7

Open the chart page →

4,419
steamcmdthetredevVerified publisher1.0.91 of 1See more

steamcmd thetredev 1.0.9

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/thetredev/steamcmd:srcds-20240309dbb0f042cb31
stdlib@go1.18.2
1.23.7

Open the chart page →

1,076
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.23.7

Open the chart page →

25,586
mc-routerthl-chartsVerified publisher0.1.01 of 1See more

mc-router thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
itzg/mc-router:1.16.1bb552b59fb53
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.18.4
0.36.0
1.23.7

Open the chart page →

1,856
monitoringthl-chartsVerified publisher0.1.18 of 10See more

monitoring thl-charts 0.1.1

8 of the 10 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
stdlib@go1.17.9
0.36.0
1.23.7
grafana/loki:2.5.0f9ef133793af
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.8
0.36.0
1.23.7
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
stdlib@go1.17.2
0.36.0
1.23.7
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.23.7
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.36.0
1.23.7
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.36.0
1.23.7
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.36.0
1.23.7
quay.io/prometheus/prometheus:v2.34.0b37103e03399
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.8
0.36.0
1.23.7

Open the chart page →

18,949
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
nginx/nginx-ingress:1.11.1eb5b4fd73325
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.11
0.36.0
1.23.7

Open the chart page →

6,891
tiny-api-charttiny-api1.0.01 of 1See more

tiny-api-chart tiny-api 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
stubin87/tiny-api:v1.1.02e5c42e92ec8
stdlib@go1.19.1
1.23.7

Open the chart page →

1,127
grafanatnh5.3.01 of 1See more

grafana tnh 5.3.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.36.0
1.23.7

Open the chart page →

3,199
prometheustnh11.6.04 of 6See more

prometheus tnh 11.6.0

4 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.36.0
1.23.7
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.36.0
1.23.7
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.23.7
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.36.0
1.23.7

Open the chart page →

8,495
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
erenozcan17/go_backend:v4.250b4f23422b6
golang.org/x/net@v0.10.0
0.36.0

Open the chart page →

7,087
traefik-jwt-decodetraefik-jwt-decode0.1.01 of 1See more

traefik-jwt-decode traefik-jwt-decode 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
simonschneider/traefik-jwt-decode:latestd674ac370f80
stdlib@go1.17.13
1.23.7

Open the chart page →

1,311
nfs-servertranhailongVerified publisher0.1.21 of 1See more

nfs-server tranhailong 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
tranhailong/nfs-server:4.2-2-gcsfuse028662749be2
golang.org/x/net@v0.4.0
stdlib@go1.18.4
0.36.0
1.23.7

Open the chart page →

2,331
treenitytreenityVerified publisher0.1.31 of 4See more

treenity treenity 0.1.3

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/nats:2.9.6-alpine3.16f576cdc17cc3
stdlib@go1.19.3
1.23.7

Open the chart page →

3,416
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
golang.org/x/net@v0.25.0
stdlib@go1.22.3
0.36.0
1.23.7

Open the chart page →

2,489
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.36.0
1.23.7
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

4,817
trivy-webhook-elasticsearchtrivy-webhook-elasticsearch0.1.41 of 1See more

trivy-webhook-elasticsearch trivy-webhook-elasticsearch 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/lbi22/trivy-webhook-elasticsearch:v0.1.4b51b824e4f19
stdlib@go1.22.8
1.23.7

Open the chart page →

756
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,521
monitorortrozz0.0.11 of 1See more

monitoror trozz 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
monitoror/monitoror:44b88edcf51ff
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
stdlib@go1.14.6
0.36.0
1.23.7

Open the chart page →

3,111
clickhouse-operatortruefoundryVerified publisher0.1.12 of 3See more

clickhouse-operator truefoundry 0.1.1

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.23.34baec90b20cd
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.36.0
1.23.7
altinity/metrics-exporter:0.23.32912a6c15b44
golang.org/x/net@v0.17.0
stdlib@go1.20.14
0.36.0
1.23.7

Open the chart page →

1,432
tfy-cloudflaredtruefoundryVerified publisher0.6.01 of 2See more

tfy-cloudflared truefoundry 0.6.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
golang.org/x/net@v0.5.0
stdlib@go1.20
0.36.0
1.23.7

Open the chart page →

2,035
tfy-distributortruefoundryVerified publisher0.0.13 of 4See more

tfy-distributor truefoundry 0.0.1

3 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.23.7
natsio/nats-server-config-reloader:0.14.08c28b75bc416
stdlib@go1.20.5
1.23.7
natsio/prometheus-nats-exporter:0.13.02adf791d9f9f
stdlib@go1.21.3
1.23.7

Open the chart page →

17,551
tfy-inferentia-operatortruefoundryVerified publisher0.2.83 of 3See more

tfy-inferentia-operator truefoundry 0.2.8

3 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/kubernetes/kube-scheduler:v1.29.14-eks-1-29-lateste7e1db003e6a
golang.org/x/net@v0.24.0
stdlib@go1.22.12
0.36.0
1.23.7
public.ecr.aws/neuron/neuron-device-plugin:2.23.30.075a6d5ce3bd3
golang.org/x/net@v0.23.0
stdlib@go1.20.4
0.36.0
1.23.7
public.ecr.aws/neuron/neuron-scheduler:2.23.30.04cd274463e6b
golang.org/x/net@v0.23.0
stdlib@go1.20.4
0.36.0
1.23.7

Open the chart page →

2,926
tfy-kservetruefoundryVerified publisher0.1.11 of 2See more

tfy-kserve truefoundry 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
kserve/kserve-controller:v0.10.022ff858b57c1
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

1,178
tfy-llm-gateway-infratruefoundryVerified publisher0.2.102 of 3See more

tfy-llm-gateway-infra truefoundry 0.2.10

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.23.774315beb57db
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.36.0
1.23.7
altinity/metrics-exporter:0.23.7a4d7ff0c727e
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.36.0
1.23.7

Open the chart page →

1,210
tfy-lokitruefoundryVerified publisher0.1.62 of 2See more

tfy-loki truefoundry 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/loki:2.9.1035b02acc6765
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7
grafana/promtail:2.9.1063a2e57a5b14
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7

Open the chart page →

2,829
aws-eks-asg-rolling-update-handlertwin1.5.01 of 1See more

aws-eks-asg-rolling-update-handler twin 1.5.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
twinproduction/aws-eks-asg-rolling-update-handler:v1.7.08f38c206972e
golang.org/x/net@v0.1.0
stdlib@go1.19.3
0.36.0
1.23.7

Open the chart page →

1,119
lighthousetwin1.0.21 of 1See more

lighthouse twin 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/twin/lighthouse:v0.0.45aeda2ea2ba2
golang.org/x/net@v0.23.0
stdlib@go1.22.3
0.36.0
1.23.7

Open the chart page →

544
twitter-apptwitter-helm0.1.124 of 8See more

twitter-app twitter-helm 0.1.12

4 of the 8 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.3
0.36.0
1.23.7
stakkato95/twitter-service-graphql:0.1.13cbe857234f2
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.36.0
1.23.7
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
stdlib@go1.18.3
1.23.7
stakkato95/twitter-service-users:0.1.1456049efee9a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.36.0
1.23.7

Open the chart page →

6,150
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.7.0e90b7ba06d97
golang.org/x/net@v0.10.0
stdlib@go1.20.4
0.36.0
1.23.7

Open the chart page →

1,570
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.23.7

Open the chart page →

4,147
tyk-bootstraptyk-helm5.3.03 of 3See more

tyk-bootstrap tyk-helm 5.3.0

3 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.23.7

Open the chart page →

1,374
tyk-control-planetyk-helm5.3.03 of 7See more

tyk-control-plane tyk-helm 5.3.0

3 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.23.7

Open the chart page →

3,266
tyk-stacktyk-helm5.3.03 of 7See more

tyk-stack tyk-helm 5.3.0

3 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-post:v2.2.055b4d31c7a01
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
tykio/tyk-k8s-bootstrap-pre-delete:v2.2.01489b58f642b
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
stdlib@go1.22.7
1.23.7

Open the chart page →

3,200
typhoontyphoonVerified publisher0.2.32 of 2See more

typhoon typhoon 0.2.3

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.36.0
1.23.7
ghcr.io/zeiss/typhoon/typhoon-webhook:0.2.378f9b82050bc
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.36.0
1.23.7

Open the chart page →

1,690
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
golang.org/x/net@v0.23.0
stdlib@go1.22.9
0.36.0
1.23.7

Open the chart page →

8,709
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.36.0
1.23.7

Open the chart page →

4,995
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
stdlib@go1.20.7
1.23.7

Open the chart page →

5,293
phonebook-chartusuladams2Verified publisher0.2.11 of 3See more

phonebook-chart usuladams2 0.2.1

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.23.7

Open the chart page →

3,176
kiamuswitch6.1.21 of 1See more

kiam uswitch 6.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/uswitch/kiam:v4.0be3a5846922d
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.13.8
0.36.0
1.23.7

Open the chart page →

2,973
utho-app-operator-chartutho-operatorVerified publisher0.1.61 of 2See more

utho-app-operator-chart utho-operator 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
utho/utho-app-operator:0.1.46e8a690e8b7a
golang.org/x/net@v0.26.0
stdlib@go1.22.8
0.36.0
1.23.7

Open the chart page →

491
gohttpserverutkuozdemirVerified publisher0.2.01 of 1See more

gohttpserver utkuozdemir 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
codeskyblue/gohttpserver:latestcaa862590e34
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.16.3
0.36.0
1.23.7

Open the chart page →

1,899
transmission-exporterutkuozdemirVerified publisher1.1.01 of 1See more

transmission-exporter utkuozdemir 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
metalmatze/transmission-exporter:0.3.090d6acb6d47d
stdlib@go1.13
1.23.7

Open the chart page →

1,647
openldap-havcnngrVerified publisher1.0.01 of 3See more

openldap-ha vcnngr 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
stdlib@go1.15.5
0.36.0
1.23.7

Open the chart page →

5,517
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,521
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,539

Container images carrying it

3,323 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.36.0
1.23.7
1
vikunja/api:0.17.18cba0520bf8c
golang.org/x/net@v0.0.0-20210505024714-0287a6fb4125
stdlib@go1.16.5
0.36.0
1.23.7
1
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
golang.org/x/net@v0.23.0
stdlib@go1.19.13
0.36.0
1.23.7
1
vmware/kube-fluentd-operator:latestf028c138a5f4
golang.org/x/net@v0.17.0
stdlib@go1.21.7
0.36.0
1.23.7
1
voidxmh/golang:1.19-alpine-dev423c6195fab2
stdlib@go1.19
1.23.7
1
voidxmh/xmh-auther:v193e42a569ca8
stdlib@go1.16.5
1.23.7
1
voidxmh/xmh-cacher:v11b7397412320
stdlib@go1.16.5
1.23.7
1
voidxmh/xmh-ui:v12ff3f2146547
stdlib@go1.16.5
1.23.7
1
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
stdlib@go1.13.6
1.23.7
1
volcanosh/vc-webhook-manager:v1.12.1f8b50088a732
golang.org/x/net@v0.30.0
stdlib@go1.23.3
0.36.0
1.23.7
1
voltha/bbsim:1.16.7d90403d58016
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.13.8
0.36.0
1.23.7
1
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.36.0
1.23.7
1
voltha/bbsim-sadis-server:0.4.0762b272d439e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.3
0.36.0
1.23.7
1
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.16.3
0.36.0
1.23.7
1
vultr/vultr-cloud-controller-manager:v0.3.01806f17d620c
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.7
0.36.0
1.23.7
1
vultr/vultr-csi:v0.3.041d26735d437
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
stdlib@go1.16.8
0.36.0
1.23.7
1
wagnermanganelli164/webserver-hello-world:0.3.0d4ef27a4f180
stdlib@go1.22.5
1.23.7
1
wallarm/ebpf-agent:0.11.0-rc0c8920e60c726
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.36.0
1.23.7
1
wallarm/ingress-controller:5.3.10.1a1fecfdf987e
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.36.0
1.23.7
1
wallarm/ingress-controller:4.8.0-1a591b9c91570
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.36.0
1.23.7
1
wallarm/ingress-python:4.6.0-15cb2ae08b40f
stdlib@go1.18.2
1.23.7
1
wallarm/ingress-ruby:4.2.1-195ea2632326c
stdlib@go1.18.3
1.23.7
1
wallarm/ingress-ruby:4.6.0-1aecdb35c4def
stdlib@go1.18.3
1.23.7
1
wallarm/kong-kubernetes-ingress-controller:2.8b55ff6cecbd5
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.36.0
1.23.7
1
wallarm/node-helpers:5.0.2-1097cadc42336
golang.org/x/net@v0.26.0
stdlib@go1.22.7
0.36.0
1.23.7
1
wallarm/node-next:0.5.24314f3d2b918
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.36.0
1.23.7
1
wateim/lighthouse-launch:latest2520149ee574
golang.org/x/net@v0.33.0
0.36.0
1
wavefronthq/prometheus-storage-adapter:latestded77b38c7c6
golang.org/x/net@v0.17.0
stdlib@go1.18
0.36.0
1.23.7
1
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
golang.org/x/net@v0.17.0
stdlib@go1.18
0.36.0
1.23.7
1
wazuh/wazuh-manager:4.11.11da5c38c6a78
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.36.0
1.23.7
1
wazuh/wazuh-manager:4.4.121994f40e0da
golang.org/x/net@v0.5.0
stdlib@go1.18.9
0.36.0
1.23.7
1
wazuh/wazuh-manager:4.14.45a065930682d
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.36.0
1.23.7
1
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.36.0
1.23.7
1
weaveworks/flagger:1.0.0-rc.5174307de1b36
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.2
0.36.0
1.23.7
1
weaveworks/flagger:0.19.0a9c2e9df4227
golang.org/x/net@v0.0.0-20190206173232-65e2d4e15006
stdlib@go1.13.1
0.36.0
1.23.7
1
weaveworks/flagger-loadtester:0.9.03cdac6928a63
golang.org/x/net@v0.0.0-20190206173232-65e2d4e15006
stdlib@go1.13.1
0.36.0
1.23.7
1
webdevops/azure-janitor:24.9.02446baee7b69
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.36.0
1.23.7
1
webdevops/azure-keyvault-exporter:24.9.1f333704ecd60
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.36.0
1.23.7
1
webdevops/azure-resourcegraph-exporter:24.9.0381136dda026
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.36.0
1.23.7
1
webdevops/azure-scheduledevents-manager:24.9.0-kubernetes7acd46a8a972
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7
1
webdevops/kube-pool-manager:24.9.04fad7e14ad67
golang.org/x/net@v0.29.0
stdlib@go1.23.1
0.36.0
1.23.7
1
weblate/weblate:3.11.3-182848df56ecd
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.36.0
1.23.7
1
wernight/ngrok:latestd211f29ebcfe
golang.org/x/net@v0.17.0
stdlib@go1.21.6
0.36.0
1.23.7
1
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.8
0.36.0
1.23.7
1
wistefan/vcbackend:0.0.13bd436164b51
stdlib@go1.18.3
1.23.7
1
wolveix/satisfactory-server:v1.9.1199be1064b18
stdlib@go1.18.1
1.23.7
1
wolveix/satisfactory-server:v1.9.9464d11e36e10
stdlib@go1.18.1
1.23.7
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
stdlib@go1.20.12
1.23.7
1
wuhan005/forklift:daemon4e6da210e449
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.36.0
1.23.7
1
wuhan005/forklift:controllerbfbe82d59850
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.36.0
1.23.7
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.