StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,686
of 17,803 indexed, latest versions
Container images
3,262
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,686 of 17,803 indexed charts deploy, on 3,262 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+201 more0.36.02,483
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+147 more1.23.73,163
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,686 by stars
ChartLatestAffected imagesRadar Score
devtron-enterprisedevtron48.0.015 of 28See more

devtron-enterprise devtron 48.0.0

15 of the 28 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.36.0
1.23.7
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
stdlib@go1.24.0
1.23.7
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.23.7
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.36.0
1.23.7
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.15
0.36.0
1.23.7
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.36.0
1.23.7
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.36.0
1.23.7
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
stdlib@go1.19.2
1.23.7
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.19.2
0.36.0
1.23.7
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.23.7
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.23.7
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.36.0
1.23.7
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
stdlib@go1.16.15
1.23.7
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/net@v0.28.0
stdlib@go1.21.5
0.36.0
1.23.7

Open the chart page →

68,765
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.36.0
1.23.7
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.36.0
1.23.7

Open the chart page →

5,055
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.36.0
1.23.7

Open the chart page →

4,979
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.17.3
0.36.0
1.23.7

Open the chart page →

11,981
discord-alertmanagerdevtron0.10.01 of 1See more

discord-alertmanager devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/discord-alertmanager:ceceb475-65-35203586419ca31
stdlib@go1.18.1
1.23.7

Open the chart page →

951
jcmhproxy-ingressdevtron0.14.61 of 1See more

jcmhproxy-ingress devtron 0.14.6

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.36.0
1.23.7

Open the chart page →

1,379
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.36.0
1.23.7
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16
0.36.0
1.23.7
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.36.0
1.23.7

Open the chart page →

8,659
migration-incluster-cddevtron0.10.01 of 1See more

migration-incluster-cd devtron 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.23.7

Open the chart page →

3,927
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.16.10
0.36.0
1.23.7

Open the chart page →

2,442
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

1,176
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.7
0.36.0
1.23.7

Open the chart page →

1,514
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/net@v0.23.0
stdlib@go1.22.4
0.36.0
1.23.7

Open the chart page →

9,703
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
stdlib@go1.14.12
0.36.0
1.23.7
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.14.9
0.36.0
1.23.7

Open the chart page →

10,484
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.17.13
0.36.0
1.23.7

Open the chart page →

13,033
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/net@v0.8.0
stdlib@go1.19.8
0.36.0
1.23.7

Open the chart page →

1,587
calertdevtron-labs0.0.11 of 1See more

calert devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
stdlib@go1.18
1.23.7

Open the chart page →

4,699
calicodevtron-labs0.1.14 of 4See more

calico devtron-labs 0.1.1

4 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.36.0
1.23.7
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.36.0
1.23.7
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.2
0.36.0
1.23.7
quay.io/devtron/calico-networking:pod2daemon-flexvol-v3.19.1c1f36b6e18e0
stdlib@go1.15.2
1.23.7

Open the chart page →

10,094
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
stdlib@go1.17.6
0.36.0
1.23.7

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.015 of 28See more

devtron-enterprise devtron-labs 48.0.0

15 of the 28 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.36.0
1.23.7
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
stdlib@go1.24.0
1.23.7
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.23.7
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.36.0
1.23.7
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.14.15
0.36.0
1.23.7
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.36.0
1.23.7
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.36.0
1.23.7
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
stdlib@go1.19.2
1.23.7
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
stdlib@go1.19.2
0.36.0
1.23.7
quay.io/devtron/nats-server-config-reloader:0.6.2b5252e783fb2
stdlib@go1.15.14
1.23.7
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.23.7
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.36.0
1.23.7
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
stdlib@go1.16.15
1.23.7
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/net@v0.28.0
stdlib@go1.21.5
0.36.0
1.23.7

Open the chart page →

68,765
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
stdlib@go1.15.7
0.36.0
1.23.7
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
stdlib@go1.20.7
0.36.0
1.23.7

Open the chart page →

5,055
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.36.0
1.23.7

Open the chart page →

4,979
devtron-operatordevtron-labs0.23.37 of 11See more

devtron-operator devtron-labs 0.23.3

7 of the 11 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.36.0
1.23.7
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
stdlib@go1.20.12
1.23.7
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.36.0
1.23.7
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.36.0
1.23.7
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.36.0
1.23.7
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.23.7
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.36.0
1.23.7

Open the chart page →

33,219
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.17.3
0.36.0
1.23.7

Open the chart page →

11,981
jcmhproxy-ingressdevtron-labs0.14.61 of 1See more

jcmhproxy-ingress devtron-labs 0.14.6

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.36.0
1.23.7

Open the chart page →

1,379
kube-prometheus-stackdevtron-labs19.3.03 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

3 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.17
0.36.0
1.23.7
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16
0.36.0
1.23.7
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.7
0.36.0
1.23.7

Open the chart page →

8,659
migration-incluster-cddevtron-labs0.10.01 of 1See more

migration-incluster-cd devtron-labs 0.10.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
stdlib@go1.18.2
1.23.7

Open the chart page →

3,927
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.16.10
0.36.0
1.23.7

Open the chart page →

2,442
winter-soldierdevtron-labs0.10.61 of 1See more

winter-soldier devtron-labs 0.10.6

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

1,176
zincdevtron-labs0.1.21 of 1See more

zinc devtron-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.7
0.36.0
1.23.7

Open the chart page →

1,514
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.02 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.23.7
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.23.7

Open the chart page →

27,676
dicedbdicedb-chart0.1.01 of 1See more

dicedb dicedb-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prathamkrishna/dicedb:v1a7298180cd24
stdlib@go1.23.2
1.23.7

Open the chart page →

672
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
golang.org/x/net@v0.20.0
stdlib@go1.20.6
0.36.0
1.23.7
langgenius/dify-web:1.0.0d64914ff0d6d
stdlib@go1.22.5
1.23.7

Open the chart page →

19,513
digital-mobiusdigital-mobius0.1.41 of 1See more

digital-mobius digital-mobius 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
qoveryrd/digital-mobius:0.1.4b30a9398a83c
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.5
0.36.0
1.23.7

Open the chart page →

2,288
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
stdlib@go1.20.7
1.23.7

Open the chart page →

4,553
direktivdirektivVerified publisher0.10.04 of 6See more

direktiv direktiv 0.10.0

4 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-k8s:0.120.01e45d9483faa
golang.org/x/net@v0.35.0
stdlib@go1.24.0
0.36.0
1.23.7
victoriametrics/victoria-logs:v1.15.0-victorialogsd7435244eb19
stdlib@go1.24.0
1.23.7
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.36.0
1.23.7
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.0aaafd456bda1
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.36.0
1.23.7

Open the chart page →

3,480
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3a2fc46b52819
stdlib@go1.18.2
1.23.7

Open the chart page →

7,549
graphite-exporterdjjudas21Verified publisher0.1.91 of 1See more

graphite-exporter djjudas21 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/graphite-exporter:v0.16.0e54bca6645ea
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.36.0
1.23.7

Open the chart page →

782
hammonddjjudas21Verified publisher0.3.91 of 1See more

hammond djjudas21 0.3.9

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
stdlib@go1.20.6
0.36.0
1.23.7

Open the chart page →

1,807
ownclouddjjudas21Verified publisher0.3.231 of 3See more

owncloud djjudas21 0.3.23

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.3.2-debian-12-r9320c70dfd914
stdlib@go1.22.4
1.23.7

Open the chart page →

10,199
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
golang.org/x/net@v0.27.0
stdlib@go1.22.5
0.36.0
1.23.7

Open the chart page →

17,129
smokepingdjjudas21Verified publisher0.1.31 of 1See more

smokeping djjudas21 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
linuxserver/smokeping:2.8.2b7f906899cd3
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.22.5
0.36.0
1.23.7

Open the chart page →

2,054
spoolmandjjudas21Verified publisher0.1.81 of 1See more

spoolman djjudas21 0.1.8

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.24.042135965c42d
stdlib@go1.19.8
1.23.7

Open the chart page →

1,858
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
golang.org/x/net@v0.19.0
stdlib@go1.19.6
0.36.0
1.23.7

Open the chart page →

4,226
dnation-kubernetes-monitoring-stackdnationcloud4.0.26 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

6 of the 17 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
golang.org/x/net@v0.30.0
stdlib@go1.23.4
0.36.0
1.23.7
grafana/loki:3.2.0882e30c20683
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.36.0
1.23.7
grafana/loki-canary:3.2.049e03f80d361
golang.org/x/net@v0.28.0
stdlib@go1.22.7
0.36.0
1.23.7
prom/memcached-exporter:v0.15.0bb01ad25e9fc
golang.org/x/net@v0.29.0
stdlib@go1.23.3
0.36.0
1.23.7
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
golang.org/x/net@v0.0.0-20221017152216-f25eb7ecb193
stdlib@go1.19.2
0.36.0
1.23.7
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.36.0
1.23.7

Open the chart page →

21,767
ssl-exporterdnationcloud1.2.11 of 1See more

ssl-exporter dnationcloud 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
golang.org/x/net@v0.0.0-20220708220712-1185a9018129
stdlib@go1.18.3
0.36.0
1.23.7

Open the chart page →

1,632
snmp-exporterdniel0.0.21 of 1See more

snmp-exporter dniel 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/snmp-exporter:v0.20.09d226d7de223
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
stdlib@go1.15.8
0.36.0
1.23.7

Open the chart page →

2,126
whoamidniel0.8.11 of 1See more

whoami dniel 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.23.7

Open the chart page →

1,280
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

8,417
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
stdlib@go1.20.12
1.23.7

Open the chart page →

2,865
furan2dollarshaveclubVerified publisher0.2.01 of 1See more

furan2 dollarshaveclub 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
dollarshaveclub/furan2:master14a257836529
golang.org/x/net@v0.0.0-20201002202402-0a1ea396d57c
stdlib@go1.17.2
0.36.0
1.23.7

Open the chart page →

3,055

Container images carrying it

3,262 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/appscode/kube-rbac-proxy:v0.15.0d8cc6ffb9819
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.36.0
1.23.7
1
ghcr.io/appscode/license-proxyserver:v0.0.8d6c2532ea386
golang.org/x/net@v0.19.0
stdlib@go1.22.1
0.36.0
1.23.7
1
ghcr.io/appscode/smtprelay:v0.0.479c9c76a78e6
golang.org/x/net@v0.34.0
stdlib@go1.23.2
0.36.0
1.23.7
1
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
golang.org/x/net@v0.26.0
stdlib@go1.20.2
0.36.0
1.23.7
1
ghcr.io/appscode/vcd-lb-gc:v0.1.0524c4045cd21
golang.org/x/net@v0.23.0
0.36.0
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.36.0
1.23.7
1
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.36.0
1.23.7
1
ghcr.io/astriaorg/astria-indexer:0.1.05cf1e5709820
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.36.0
1.23.7
1
ghcr.io/astriaorg/astria-indexer-api:0.1.03490d9900af1
golang.org/x/net@v0.26.0
stdlib@go1.23.1
0.36.0
1.23.7
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
stdlib@go1.20.12
1.23.7
1
ghcr.io/astriaorg/flame:0.1.0c8af1c5aae40
golang.org/x/net@v0.26.0
stdlib@go1.22.12
0.36.0
1.23.7
1
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
stdlib@go1.17.13
1.23.7
1
ghcr.io/astriaorg/seq-faucet:0.9.0bf3cb9b505b6
golang.org/x/net@v0.28.0
stdlib@go1.22.6
0.36.0
1.23.7
1
ghcr.io/atrox/alertmanager-discord:v1.0.0ac011a4b6df1
stdlib@go1.20.5
1.23.7
1
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
stdlib@go1.19.3
0.36.0
1.23.7
1
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
golang.org/x/net@v0.26.0
stdlib@go1.22.1
0.36.0
1.23.7
1
ghcr.io/axonops/axonops-developer-operator:v0.1.0b3d6600c8ba5
golang.org/x/net@v0.25.0
stdlib@go1.22.10
0.36.0
1.23.7
1
ghcr.io/bamaas/gofit:0.0.132b6a174b419
stdlib@go1.22.11
1.23.7
1
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
golang.org/x/net@v0.8.0
stdlib@go1.19.11
0.36.0
1.23.7
1
ghcr.io/banzaicloud/kafka-operator:v0.20.2e341aefa9a90
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
stdlib@go1.17.6
0.36.0
1.23.7
1
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.13
0.36.0
1.23.7
1
ghcr.io/banzaicloud/logging-operator:3.17.623c2d4d54a64
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.17.9
0.36.0
1.23.7
1
ghcr.io/banzaicloud/log-socket:latesta514736d2d4d
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
stdlib@go1.18.6
0.36.0
1.23.7
1
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
golang.org/x/net@v0.0.0-20170114055629-f2499483f923
stdlib@go1.15.2
0.36.0
1.23.7
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
golang.org/x/net@v0.30.0
stdlib@go1.22.10
0.36.0
1.23.7
1
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.12
0.36.0
1.23.7
1
ghcr.io/behappy-project/behappy-tencentcloud-exporter:0.1.3a0ba56e1501b
stdlib@go1.21.13
1.23.7
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/net@v0.10.0
stdlib@go1.20.8
0.36.0
1.23.7
1
ghcr.io/benc-uk/kubeview:0.1.31f8e7cd7325a3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.2
0.36.0
1.23.7
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10b6373349a301
stdlib@go1.23.6
1.23.7
1
ghcr.io/bitmagnet-io/bitmagnet:v0.10.0cf2c16fac5b5
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.36.0
1.23.7
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
golang.org/x/net@v0.8.0
stdlib@go1.17.1
0.36.0
1.23.7
1
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.36.0
1.23.7
1
ghcr.io/bojanzelic/cloudflare-zero-trust-operator:0.7.1f4b2dbc19a78
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.36.0
1.23.7
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
stdlib@go1.23.5
1.23.7
1
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
stdlib@go1.21.6
1.23.7
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.36.0
1.23.7
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
stdlib@go1.19.8
1.23.7
1
ghcr.io/buoyantio/prometheus:v3.3.1e2b8aa62b648
golang.org/x/net@v0.35.0
0.36.0
1
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.19.2
0.36.0
1.23.7
1
ghcr.io/camptocamp/prometheus-puppetdb-sd:0.14.0414c0c99fd06
golang.org/x/net@v0.34.0
stdlib@go1.23.5
0.36.0
1.23.7
1
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.36.0
1.23.7
1
ghcr.io/caninehq/canine:latesta058034ca006
golang.org/x/net@v0.26.0
stdlib@go1.22.7
0.36.0
1.23.7
1
ghcr.io/celestiaorg/celestia-app:v3.7.0-arabica23a9ec9b1879
golang.org/x/net@v0.34.0
stdlib@go1.23.6
0.36.0
1.23.7
1
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/net@v0.27.0
stdlib@go1.23.0
0.36.0
1.23.7
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
stdlib@go1.22.10
1.23.7
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
golang.org/x/net@v0.17.0
stdlib@go1.16.2
0.36.0
1.23.7
1
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18
0.36.0
1.23.7
1
ghcr.io/chaos-mesh/chaos-daemon:v2.8.0fb609bc264d9
stdlib@go1.16.2
1.23.7
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
golang.org/x/net@v0.17.0
stdlib@go1.20.8
0.36.0
1.23.7
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.