StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,689
of 17,792 indexed, latest versions
Container images
3,266
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,689 of 17,792 indexed charts deploy, on 3,266 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+201 more0.36.02,486
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+147 more1.23.73,166
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,689 by stars
ChartLatestAffected imagesRadar Score
kubedb-ui-serverappscodeVerified publisher2021.12.211 of 1See more

kubedb-ui-server appscode 2021.12.21

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.8
0.36.0
1.23.7

Open the chart page →

2,054
kubeform-provider-awsappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-aws appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
golang.org/x/net@v0.10.0
stdlib@go1.19.1
0.36.0
1.23.7

Open the chart page →

2,803
kubeform-provider-azureappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-azure appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.20.5
0.36.0
1.23.7

Open the chart page →

2,724
kubeform-provider-gcpappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-gcp appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
golang.org/x/net@v0.9.0
stdlib@go1.19.9
0.36.0
1.23.7

Open the chart page →

2,750
kubevirt-infra-csi-driverappscodeVerified publisher0.1.01 of 6See more

kubevirt-infra-csi-driver appscode 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
golang.org/x/net@v0.34.0
stdlib@go1.23.1
0.36.0
1.23.7

Open the chart page →

1,210
kubevirt-tenant-csi-driverappscodeVerified publisher0.1.01 of 4See more

kubevirt-tenant-csi-driver appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
golang.org/x/net@v0.17.0
stdlib@go1.20.5
0.36.0
1.23.7

Open the chart page →

1,298
license-proxyserver-addon-managerappscodeVerified publisher2024.2.251 of 1See more

license-proxyserver-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/license-proxyserver:v0.0.8d6c2532ea386
golang.org/x/net@v0.19.0
stdlib@go1.22.1
0.36.0
1.23.7

Open the chart page →

1,391
managed-serviceaccountappscodeVerified publisher2024.2.251 of 1See more

managed-serviceaccount appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:latest365183f83ac9
golang.org/x/net@v0.19.0
stdlib@go1.22.0
0.36.0
1.23.7

Open the chart page →

2,404
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
golang.org/x/net@v0.5.0
stdlib@go1.19.4
0.36.0
1.23.7

Open the chart page →

4,050
multicluster-controlplaneappscodeVerified publisher2025.4.301 of 1See more

multicluster-controlplane appscode 2025.4.30

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
golang.org/x/net@v0.19.0
stdlib@go1.21.8
0.36.0
1.23.7

Open the chart page →

2,576
platform-linksappscodeVerified publisher2026.9.111 of 1See more

platform-links appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/fileserver:v0.0.2b1857871e06c
golang.org/x/net@v0.26.0
0.36.0

Open the chart page →

778
service-gatewayappscodeVerified publisher2026.9.111 of 3See more

service-gateway appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109fa56a9251de6
stdlib@go1.19
1.23.7

Open the chart page →

2,169
service-presetsappscodeVerified publisher2024.2.111 of 1See more

service-presets appscode 2024.2.11

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/echoserver:v20221109-7ee2f3efa56a9251de6
stdlib@go1.19
1.23.7

Open the chart page →

824
service-providerappscodeVerified publisher2026.9.111 of 2See more

service-provider appscode 2026.9.11

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.36.0
1.23.7

Open the chart page →

2,238
stash-communityappscodeVerified publisher0.42.03 of 4See more

stash-community appscode 0.42.0

3 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.36.0
1.23.7
ghcr.io/appscode/kubectl-nonroot:1.3183d43cc41590
golang.org/x/net@v0.26.0
0.36.0
ghcr.io/stashed/stash:v0.42.03a98245a7667
golang.org/x/net@v0.26.0
stdlib@go1.23.3
0.36.0
1.23.7

Open the chart page →

3,669
statefulsetappscodeVerified publisher0.0.12 of 3See more

statefulset appscode 0.0.1

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.36.0
1.23.7
ghcr.io/appscode/kubectl-nonroot:v1.248ee5bdd68977
stdlib@go1.20.7
1.23.7

Open the chart page →

2,739
vcd-lb-gcappscodeVerified publisher2026.6.251 of 1See more

vcd-lb-gc appscode 2026.6.25

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/appscode/vcd-lb-gc:v0.1.0524c4045cd21
golang.org/x/net@v0.23.0
0.36.0

Open the chart page →

178
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
golang.org/x/net@v0.11.0
stdlib@go1.21.1
0.36.0
1.23.7

Open the chart page →

5,685
stardog-userrole-operatorappuio0.4.01 of 1See more

stardog-userrole-operator appuio 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
golang.org/x/net@v0.19.0
stdlib@go1.22.2
0.36.0
1.23.7

Open the chart page →

1,205
appwriteappwrite-helmVerified publisher1.3.23 of 8See more

appwrite appwrite-helm 1.3.2

3 of the 8 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
stdlib@go1.19.7
1.23.7
bitnamilegacy/redis:7.0.10-debian-11-r059293f5206b7
stdlib@go1.19.7
1.23.7
openruntimes/executor:0.11.42228f186dcbb
stdlib@go1.21.10
1.23.7

Open the chart page →

9,843
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.16.4
0.36.0
1.23.7

Open the chart page →

5,211
argocdargo-helm-charts1.0.03 of 3See more

argocd argo-helm-charts 1.0.0

3 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.42.18186d6dd81f4
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.36.0
1.23.7
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.23.7
quay.io/argoproj/argocd:v2.14.115fc69e31c755
golang.org/x/net@v0.34.0
stdlib@go1.22.2
0.36.0
1.23.7

Open the chart page →

7,369
argonix-apiargonix0.2.61 of 4See more

argonix-api argonix 0.2.6

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/argonix-io/argonix-api:1.0.0ba989d05bc51
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7

Open the chart page →

4,970
arlas-aiasarlas-stackVerified publisher28.8.02 of 22See more

arlas-aias arlas-stack 28.8.0

2 of the 22 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
golang.org/x/net@v0.29.0
stdlib@go1.22.11
0.36.0
1.23.7
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
golang.org/x/net@v0.33.0
0.36.0

Open the chart page →

40,651
arma-reforgerarma-reforger0.5.38 of 8See more

arma-reforger arma-reforger 0.5.3

8 of the 8 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.36.0
1.23.7
stakater/reloader:v1.0.15f4b87a8e56d4
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.36.0
1.23.7
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.36.0
1.23.7
quay.io/prometheus-operator/prometheus-config-reloader:v0.63.03f976422884e
stdlib@go1.19.5
1.23.7
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.36.0
1.23.7
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
stdlib@go1.19.3
0.36.0
1.23.7
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.36.0
1.23.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.36.0
1.23.7

Open the chart page →

23,435
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.2
0.36.0
1.23.7

Open the chart page →

1,780
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.17.11
0.36.0
1.23.7
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.10
0.36.0
1.23.7
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.3
0.36.0
1.23.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.36.0
1.23.7

Open the chart page →

8,622
assemblylineassemblylineVerified publisher7.4.202 of 12See more

assemblyline assemblyline 7.4.20

2 of the 12 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.36.0
1.23.7
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
golang.org/x/net@v0.20.0
stdlib@go1.21.5
0.36.0
1.23.7

Open the chart page →

12,667
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/authorization_db:latestc3adbab6a3e7
stdlib@go1.18.2
1.23.7

Open the chart page →

5,537
dltkvassist-iot-data-integrity-verification0.2.04 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

4 of the 9 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.36.0
1.23.7
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

78,035
dltflassist-iot-dlt-based-fl0.2.04 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

4 of the 9 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.17.13
0.36.0
1.23.7
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7
hyperledger/fabric-tools:2.4b1194f509085
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

78,035
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
stdlib@go1.17.10
0.36.0
1.23.7

Open the chart page →

3,789
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
stdlib@go1.17.10
1.23.7

Open the chart page →

9,422
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
stdlib@go1.17.10
0.36.0
1.23.7

Open the chart page →

4,369
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
stdlib@go1.18.2
1.23.7

Open the chart page →

13,389
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
stdlib@go1.18.2
1.23.7

Open the chart page →

10,173
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.6
0.36.0
1.23.7
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
stdlib@go1.18
0.36.0
1.23.7

Open the chart page →

18,426
performanceandusagediagnosisassist-iot-pud1.0.05 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

5 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
stdlib@go1.17.12
0.36.0
1.23.7
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.23.7
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.36.0
1.23.7
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
stdlib@go1.18.3
0.36.0
1.23.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.5
0.36.0
1.23.7

Open the chart page →

8,571
resource-provisioningassist-iot-resource-provisioning1.0.01 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

1 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.23.7

Open the chart page →

8,052
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.22.1
1.23.7
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.23.7
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.23.7

Open the chart page →

45,620
astrotrekastria0.0.24 of 4See more

astrotrek astria 0.0.2

4 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
stdlib@go1.19.1
1.23.7
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.36.0
1.23.7
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.36.0
1.23.7
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
stdlib@go1.20.12
1.23.7

Open the chart page →

32,664
evm-faucetastria0.1.51 of 1See more

evm-faucet astria 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
stdlib@go1.17.13
1.23.7

Open the chart page →

1,764
evm-rollupastria4.1.01 of 2See more

evm-rollup astria 4.1.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.36.0
1.23.7

Open the chart page →

4,019
evm-stackastria5.0.31 of 2See more

evm-stack astria 5.0.3

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astria-geth:latest4249e403225a
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.36.0
1.23.7

Open the chart page →

4,019
flame-rollupastria0.1.31 of 2See more

flame-rollup astria 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.36.0
1.23.7

Open the chart page →

3,717
graph-nodeastria0.2.21 of 3See more

graph-node astria 0.2.2

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ipfs/kubo:v0.17.0803fac58ba15
golang.org/x/net@v0.1.0
stdlib@go1.19.1
0.36.0
1.23.7

Open the chart page →

5,572
sequencerastria4.0.02 of 3See more

sequencer astria 4.0.0

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
cometbft/cometbft:v0.38.1722c2ac018f40
golang.org/x/net@v0.34.0
stdlib@go1.22.11
0.36.0
1.23.7
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.6
0.36.0
1.23.7

Open the chart page →

6,344
sequencer-faucetastria0.9.21 of 1See more

sequencer-faucet astria 0.9.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
golang.org/x/net@v0.28.0
stdlib@go1.22.6
0.36.0
1.23.7

Open the chart page →

1,320
phonebook-chartasumankamberoglu0.1.51 of 3See more

phonebook-chart asumankamberoglu 0.1.5

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.23.7

Open the chart page →

3,176
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

9,449

Container images carrying it

3,266 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/appscode/kube-rbac-proxy:v0.18.27de54b6dedc8
golang.org/x/net@v0.31.0
stdlib@go1.23.3
0.36.0
1.23.7
1
ghcr.io/appscode/kube-rbac-proxy:v0.15.0d8cc6ffb9819
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.36.0
1.23.7
1
ghcr.io/appscode/license-proxyserver:v0.0.8d6c2532ea386
golang.org/x/net@v0.19.0
stdlib@go1.22.1
0.36.0
1.23.7
1
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
golang.org/x/net@v0.34.0
stdlib@go1.23.2
0.36.0
1.23.7
1
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
golang.org/x/net@v0.26.0
stdlib@go1.20.2
0.36.0
1.23.7
1
ghcr.io/appscode/vcd-lb-gc:v0.1.0524c4045cd21
golang.org/x/net@v0.23.0
0.36.0
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.36.0
1.23.7
1
ghcr.io/argonix-io/argonix-api:1.0.0ba989d05bc51
golang.org/x/net@v0.23.0
stdlib@go1.22.7
0.36.0
1.23.7
1
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.36.0
1.23.7
1
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.36.0
1.23.7
1
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.36.0
1.23.7
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
stdlib@go1.20.12
1.23.7
1
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.36.0
1.23.7
1
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
stdlib@go1.17.13
1.23.7
1
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
golang.org/x/net@v0.28.0
stdlib@go1.22.6
0.36.0
1.23.7
1
ghcr.io/atrox/alertmanager-discord:v1.0.0ac011a4b6df1
stdlib@go1.20.5
1.23.7
1
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.36.0
1.23.7
1
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
golang.org/x/net@v0.26.0
stdlib@go1.22.1
0.36.0
1.23.7
1
ghcr.io/axonops/axonops-developer-operator:v0.1.0b3d6600c8ba5
golang.org/x/net@v0.25.0
stdlib@go1.22.10
0.36.0
1.23.7
1
ghcr.io/bamaas/gofit:0.0.132b6a174b419
stdlib@go1.22.11
1.23.7
1
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
golang.org/x/net@v0.8.0
stdlib@go1.19.11
0.36.0
1.23.7
1
ghcr.io/banzaicloud/kafka-operator:v0.20.2e341aefa9a90
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.17.6
0.36.0
1.23.7
1
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.13
0.36.0
1.23.7
1
ghcr.io/banzaicloud/logging-operator:3.17.623c2d4d54a64
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.9
0.36.0
1.23.7
1
ghcr.io/banzaicloud/log-socket:latesta514736d2d4d
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.18.6
0.36.0
1.23.7
1
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
golang.org/x/net@v0.0.0-20170114055629-f2499483f923
stdlib@go1.15.2
0.36.0
1.23.7
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
golang.org/x/net@v0.30.0
stdlib@go1.22.10
0.36.0
1.23.7
1
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.36.0
1.23.7
1
ghcr.io/behappy-project/behappy-tencentcloud-exporter:0.1.3a0ba56e1501b
stdlib@go1.21.13
1.23.7
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/net@v0.10.0
stdlib@go1.20.8
0.36.0
1.23.7
1
ghcr.io/benc-uk/kubeview:0.1.31f8e7cd7325a3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.2
0.36.0
1.23.7
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10b6373349a301
stdlib@go1.23.6
1.23.7
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.36.0
1.23.7
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
golang.org/x/net@v0.8.0
stdlib@go1.17.1
0.36.0
1.23.7
1
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.36.0
1.23.7
1
ghcr.io/bojanzelic/cloudflare-zero-trust-operator:0.7.1f4b2dbc19a78
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.36.0
1.23.7
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
stdlib@go1.23.5
1.23.7
1
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
stdlib@go1.21.6
1.23.7
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.36.0
1.23.7
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
stdlib@go1.19.8
1.23.7
1
ghcr.io/buoyantio/prometheus:v3.3.1e2b8aa62b648
golang.org/x/net@v0.35.0
0.36.0
1
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.2
0.36.0
1.23.7
1
ghcr.io/camptocamp/prometheus-puppetdb-sd:0.14.0414c0c99fd06
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.36.0
1.23.7
1
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.36.0
1.23.7
1
ghcr.io/caninehq/canine:latesta058034ca006
golang.org/x/net@v0.26.0
stdlib@go1.22.7
0.36.0
1.23.7
1
ghcr.io/celestiaorg/celestia-app:v3.7.0-arabica23a9ec9b1879
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.36.0
1.23.7
1
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/net@v0.27.0
stdlib@go1.23.0
0.36.0
1.23.7
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
stdlib@go1.22.10
1.23.7
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
golang.org/x/net@v0.17.0
stdlib@go1.16.2
0.36.0
1.23.7
1
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.36.0
1.23.7
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.