StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,746
of 17,805 indexed, latest versions
Container images
3,305
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,746 of 17,805 indexed charts deploy, on 3,305 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+201 more0.36.02,515
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+148 more1.23.73,203
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,746 by stars
ChartLatestAffected imagesRadar Score
gcp-local-ssd-raiddysnixVerified publisher0.1.71 of 2See more

gcp-local-ssd-raid dysnix 0.1.7

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.23.7

Open the chart page →

2,439
gke-upgrade-notification-handlerdysnixVerified publisher0.1.11 of 1See more

gke-upgrade-notification-handler dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
dysnix/gke-upgrade-notification-handler:latestc166f958f86a
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.7
0.36.0
1.23.7

Open the chart page →

2,097
grafana-dashboardsdysnixVerified publisher0.2.21 of 2See more

grafana-dashboards dysnix 0.2.2

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:7.4.5d322192ed2fa
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.6
0.36.0
1.23.7

Open the chart page →

5,168
heimdalldysnixVerified publisher0.0.11 of 1See more

heimdall dysnix 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
0xpolygon/heimdall:1.0.134ddf259993c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.36.0
1.23.7

Open the chart page →

1,374
local-path-provisionerdysnixVerified publisher0.0.201 of 1See more

local-path-provisioner dysnix 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.16.6
0.36.0
1.23.7

Open the chart page →

2,926
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
stdlib@go1.16.12
1.23.7

Open the chart page →

5,056
servicemonitor-appsdysnixVerified publisher0.1.01 of 1See more

servicemonitor-apps dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ethpandaops/ethereum-metrics-exporter:0.21.0d1780db2e286
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

1,579
eav-componenteav-component1.0.01 of 3See more

eav-component eav-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,266
echoappechoapp0.1.01 of 1See more

echoapp echoapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
hashicorp/http-echo:1.0.0fcb75f691c8b
stdlib@go1.21.1
1.23.7

Open the chart page →

550
aeros-orchestrator-overlayeclipse-aeriosVerified publisher2.0.01 of 2See more

aeros-orchestrator-overlay eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
masipcat/wireguard-go:latest696206e5954d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.20.14
0.36.0
1.23.7

Open the chart page →

1,195
api-gatewayeclipse-aeriosVerified publisher1.7.01 of 1See more

api-gateway eclipse-aerios 1.7.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
devopsfaith/krakend:2.6.34c678c224f67
golang.org/x/net@v0.24.0
stdlib@go1.22.3
0.36.0
1.23.7

Open the chart page →

1,427
federatoreclipse-aeriosVerified publisher1.1.01 of 1See more

federator eclipse-aerios 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
eclipseaerios/federator:1.1.018c7f0d101c0
golang.org/x/net@v0.25.0
stdlib@go1.22.12
0.36.0
1.23.7

Open the chart page →

743
idmeclipse-aeriosVerified publisher2.0.01 of 2See more

idm eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.23.7

Open the chart page →

4,677
iotaeclipse-aeriosVerified publisher1.0.23 of 4See more

iota eclipse-aerios 1.0.2

3 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
eclipseaerios/iota-tangle-peerer:latest99d7ff18d416
golang.org/x/net@v0.30.0
stdlib@go1.22.12
0.36.0
1.23.7
iotaledger/hornet:2.001206f1ba89c
golang.org/x/net@v0.14.0
stdlib@go1.21.10
0.36.0
1.23.7
iotaledger/inx-dashboard:1.012c669cb8748
golang.org/x/net@v0.14.0
stdlib@go1.21.1
0.36.0
1.23.7

Open the chart page →

13,669
llo-apieclipse-aeriosVerified publisher1.0.01 of 1See more

llo-api eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
eclipseaerios/llo-api:1.2.0ab7a04182191
golang.org/x/net@v0.17.0
stdlib@go1.21.13
0.36.0
1.23.7

Open the chart page →

931
llo-docker-operatoreclipse-aeriosVerified publisher1.0.02 of 2See more

llo-docker-operator eclipse-aerios 1.0.0

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
eclipseaerios/llo-docker-operator:1.1.2d7ec28bfe735
golang.org/x/net@v0.25.0
0.36.0
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/net@v0.7.0
stdlib@go1.19.4
0.36.0
1.23.7

Open the chart page →

2,194
llo-k8seclipse-aeriosVerified publisher1.1.02 of 2See more

llo-k8s eclipse-aerios 1.1.0

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
golang.org/x/net@v0.10.0
stdlib@go1.21.13
0.36.0
1.23.7
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/net@v0.7.0
stdlib@go1.19.4
0.36.0
1.23.7

Open the chart page →

2,166
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
timescale/timescaledb-postgis:latest-pg127758704d4a14
stdlib@go1.14
1.23.7

Open the chart page →

11,485
openfaas2eclipse-aeriosVerified publisher12.0.55 of 6See more

openfaas2 eclipse-aerios 12.0.5

5 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/nats-streaming:0.25.5ced93c701875
stdlib@go1.19.10
1.23.7
prom/prometheus:v2.51.24f6c47e39a90
golang.org/x/net@v0.22.0
stdlib@go1.22.2
0.36.0
1.23.7
ghcr.io/openfaas/faas-netes:0.18.1224431adc8e2d
golang.org/x/net@v0.32.0
stdlib@go1.23.4
0.36.0
1.23.7
ghcr.io/openfaasltd/jetstream-queue-worker:0.3.37d96366e208b1
stdlib@go1.22.1
1.23.7
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
stdlib@go1.21.7
0.36.0
1.23.7

Open the chart page →

6,844
openldap-stack-haeclipse-aeriosVerified publisher4.1.21 of 4See more

openldap-stack-ha eclipse-aerios 4.1.2

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
eclipseaerios/openldap:2.6.30208743f315e
stdlib@go1.18.2
1.23.7

Open the chart page →

7,539
orion-ldeclipse-aeriosVerified publisher1.0.01 of 2See more

orion-ld eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mongo:7.0.12ae1cf99fa7bf
stdlib@go1.21.12
1.23.7

Open the chart page →

9,829
chartecr-toke-renew0.1.51 of 1See more

chart ecr-toke-renew 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.6
0.36.0
1.23.7

Open the chart page →

2,819
continuum-proxyedgelesssysVerified publisher1.5.11 of 1See more

continuum-proxy edgelesssys 1.5.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/continuum/continuum-proxydigest-pinned24c76f294a80
golang.org/x/net@v0.32.0
stdlib@go1.23.3
0.36.0
1.23.7

Open the chart page →

859
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.36.0
1.23.7

Open the chart page →

11,041
grafanaedu5.3.01 of 1See more

grafana edu 5.3.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.36.0
1.23.7

Open the chart page →

3,199
prometheusedu11.6.04 of 6See more

prometheus edu 11.6.0

4 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.5
0.36.0
1.23.7
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.14.4
0.36.0
1.23.7
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.23.7
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.4
0.36.0
1.23.7

Open the chart page →

8,494
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,338
cert-manager-cpanel-dns-webhookegebackVerified publisher1.0.61 of 1See more

cert-manager-cpanel-dns-webhook egeback 1.0.6

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
jamesorlakin/cert-manager-cpanel-dns-webhook:v0.3.03894dc11b236
golang.org/x/net@v0.29.0
stdlib@go1.22.8
0.36.0
1.23.7

Open the chart page →

1,299
home-assistantegebackVerified publisher2.0.351 of 1See more

home-assistant egeback 2.0.35

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.8.256690a89c79a
stdlib@go1.23.3
1.23.7

Open the chart page →

2,201
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
stdlib@go1.20.5
1.23.7

Open the chart page →

30,749
egressgatewayegressgateway0.6.92 of 2See more

egressgateway egressgateway 0.6.9

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
golang.org/x/net@v0.33.0
0.36.0
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
golang.org/x/net@v0.33.0
0.36.0

Open the chart page →

4,004
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,521
ejabberdejabberdVerified publisher0.1.01 of 1See more

ejabberd ejabberd 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
indevlab/ejabberd:24.12-k8s8bc689d093a7
golang.org/x/net@v0.30.0
stdlib@go1.23.6
0.36.0
1.23.7

Open the chart page →

904
mongodb-charteks-3-tier-app-chart0.1.01 of 1See more

mongodb-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.23.7

Open the chart page →

8,069
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
stdlib@go1.19
1.23.7

Open the chart page →

92,584
rabbitmqemberstackVerified publisher1.0.211 of 1See more

rabbitmq emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/rabbitmq:managementffd1b50c522a
stdlib@go1.22.2
1.23.7

Open the chart page →

1,068
Navidromeemmas-chartsVerified publisher0.0.41 of 1See more

Navidrome emmas-charts 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
deluan/navidrome:0.49.311a24da08977
golang.org/x/net@v0.5.0
stdlib@go1.19.5
0.36.0
1.23.7

Open the chart page →

2,838
parrot-mirroremmas-chartsVerified publisher1.0.01 of 1See more

parrot-mirror emmas-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.36.0
1.23.7

Open the chart page →

2,261
cost-reportempathyco0.7.81 of 1See more

cost-report empathyco 0.7.8

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
empathyco/cost-report:0.0.124f1e26eaacbf
stdlib@go1.15.15
1.23.7

Open the chart page →

1,168
deadman-switchempathyco0.0.21 of 1See more

deadman-switch empathyco 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
gcr.io/pingcap-public/deadmansswitch:1.04861d81aa528
stdlib@go1.16.3
1.23.7

Open the chart page →

1,259
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
stdlib@go1.16.9
1.23.7

Open the chart page →

10,670
yace-exporterempathyco0.1.01 of 1See more

yace-exporter empathyco 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/nerdswords/yet-another-cloudwatch-exporter:v0.32.0-alpha71e24278a049
stdlib@go1.17.3
1.23.7

Open the chart page →

1,642
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/net@v0.1.0
stdlib@go1.19.10
0.36.0
1.23.7

Open the chart page →

1,329
kube-ecp-stackemqx-operator2.5.111 of 16See more

kube-ecp-stack emqx-operator 2.5.1

11 of the 16 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
golang.org/x/net@v0.23.0
stdlib@go1.23.3
0.36.0
1.23.7
emqx/ecp-main:2.5.1fa876f71e5d6
golang.org/x/net@v0.30.0
stdlib@go1.22.0
0.36.0
1.23.7
emqxecp/otelcol:2.5.04c31d9bec846
golang.org/x/net@v0.28.0
stdlib@go1.22.12
0.36.0
1.23.7
library/telegraf:1.27507a3eecf809
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.36.0
1.23.7
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
golang.org/x/net@v0.28.0
stdlib@go1.23.2
0.36.0
1.23.7
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
quay.io/prometheus-operator/prometheus-config-reloader:v0.78.1e2dc5623bcdd
golang.org/x/net@v0.30.0
stdlib@go1.23.2
0.36.0
1.23.7
quay.io/prometheus/pushgateway:v1.10.07a4d0696a24e
golang.org/x/net@v0.28.0
stdlib@go1.23.1
0.36.0
1.23.7

Open the chart page →

23,993
cnpg-monitoringenixVerified publisher0.3.01 of 1See more

cnpg-monitoring enix 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7

Open the chart page →

825
kube-packetloss-exporterenixVerified publisher0.2.12 of 2See more

kube-packetloss-exporter enix 0.2.1

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.3164614ef8290f
golang.org/x/net@v0.26.0
stdlib@go1.23.4
0.36.0
1.23.7
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.36.0
1.23.7

Open the chart page →

6,208
monitoring-proxyenixVerified publisher0.3.01 of 2See more

monitoring-proxy enix 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.16.02c8f8c357ff8
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.36.0
1.23.7

Open the chart page →

4,001
eoapi-supporteoapiVerified publisher0.1.76 of 7See more

eoapi-support eoapi 0.1.7

6 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:10.3.38640e5038e83
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.36.0
1.23.7
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
stdlib@go1.20.6
0.36.0
1.23.7
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.36.0
1.23.7
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
stdlib@go1.21.0
0.36.0
1.23.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.36.0
1.23.7
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/net@v0.8.0
stdlib@go1.20.4
0.36.0
1.23.7

Open the chart page →

8,696
backendeoc-chartsVerified publisher0.1.01 of 1See more

backend eoc-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
hashicorp/http-echo:latestfcb75f691c8b
stdlib@go1.21.1
1.23.7

Open the chart page →

550
mariadbeoc-chartsVerified publisher0.3.141 of 1See more

mariadb eoc-charts 0.3.14

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mariadb:10.6.15e22328f4d714
stdlib@go1.16.7
1.23.7

Open the chart page →

5,173

Container images carrying it

3,305 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
golang.org/x/net@v0.11.0
stdlib@go1.19.12
0.36.0
1.23.7
1
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.18
0.36.0
1.23.7
1
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
golang.org/x/net@v0.4.0
stdlib@go1.19.4
0.36.0
1.23.7
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
stdlib@go1.23.6
1.23.7
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.17.5
0.36.0
1.23.7
1
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.6
0.36.0
1.23.7
1
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.36.0
1.23.7
1
quay.io/influxdb/chronograf:1.9.3c2ed16080689
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.16.4
0.36.0
1.23.7
1
quay.io/influxdb/telegraf-operator:v1.3.11eec10ef37cc3
golang.org/x/net@v0.17.0
stdlib@go1.18.10
0.36.0
1.23.7
1
quay.io/jcluppnow/vpa-manager:0.6.4e459d2fba277
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.36.0
1.23.7
1
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.6
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-cainjector:v1.16.13c49185718cf
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-cainjector:v1.14.54ffda7facb4d
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-cainjector:v1.12.0e0a5b06b231c
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-controller:v1.14.59c0527cab629
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
golang.org/x/net@v0.17.0
stdlib@go1.20.10
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-startupapicheck:v1.14.50f5b104bdd1b
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-startupapicheck:v1.16.1b4a5e42f6dbf
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-webhook:v1.10.164121721c665
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
stdlib@go1.19.3
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-webhook:v1.16.16edf44244b2a
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.11
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-webhook:v1.12.0ec4306b243d9
golang.org/x/net@v0.9.0
stdlib@go1.20.4
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-webhook:v1.14.5ef419261a209
golang.org/x/net@v0.24.0
stdlib@go1.21.9
0.36.0
1.23.7
1
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.36.0
1.23.7
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.14.1
0.36.0
1.23.7
1
quay.io/jiralert/jiralert-linux-amd64:v1.3.01983aa64761a
stdlib@go1.19.6
1.23.7
1
quay.io/jupyterhub/k8s-image-awaiter:3.3.7ada70832a345
stdlib@go1.18.10
1.23.7
1
quay.io/jupyterhub/k8s-image-awaiter:3.2.1f65b644ed6db
stdlib@go1.18.10
1.23.7
1
quay.io/k8start/http-headers:1.2.0c7a9987f2ac5
stdlib@go1.19.2
1.23.7
1
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.36.0
1.23.7
1
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.36.0
1.23.7
1
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.13.8
0.36.0
1.23.7
1
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.36.0
1.23.7
1
quay.io/kiali/kiali-operator:v2.32.096c5264d54ab
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.36.0
1.23.7
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.19
0.36.0
1.23.7
1
quay.io/kube-ops/loki:2.2.14fbd63194674
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.3
0.36.0
1.23.7
1
quay.io/kube-ops/promtail:2.2.134de6387233b
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.3
0.36.0
1.23.7
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
golang.org/x/net@v0.19.0
stdlib@go1.20.6
0.36.0
1.23.7
1
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.36.0
1.23.7
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.