StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,746
of 17,805 indexed, latest versions
Container images
3,305
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,746 of 17,805 indexed charts deploy, on 3,305 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+201 more0.36.02,515
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+148 more1.23.73,203
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,746 by stars
ChartLatestAffected imagesRadar Score
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
stdlib@go1.18.2
1.23.7

Open the chart page →

3,324
tokenexporterethersphereVerified publisher0.3.01 of 1See more

tokenexporter ethersphere 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
darkobas/tokenexporter:latesta0349a0eedf0
stdlib@go1.19.1
1.23.7

Open the chart page →

2,395
whatsmyipeugen1.3.21 of 1See more

whatsmyip eugen 1.3.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/eugenmayer/whatsmyip:0.0.14b6700cc0e2d
stdlib@go1.22.1
1.23.7

Open the chart page →

474
whoamieugen1.0.31 of 1See more

whoami eugen 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
traefik/whoami:v1.101699d99cb4b9
stdlib@go1.23.5
1.23.7

Open the chart page →

359
domain_exporterevilgn0me0.1.41 of 1See more

domain_exporter evilgn0me 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
caarlos0/domain_exporter:v1.23.0d11dec138900
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.36.0
1.23.7

Open the chart page →

1,278
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.1
0.36.0
1.23.7

Open the chart page →

21,014
pgbouncerevilmartians0.2.01 of 2See more

pgbouncer evilmartians 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/evl.ms/pgbouncer-exporter:0.4.074f919b78494
stdlib@go1.14.4
1.23.7

Open the chart page →

1,839
preview-appsevilmartians0.4.01 of 1See more

preview-apps evilmartians 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.10.0b79e77d421d0
golang.org/x/net@v0.23.0
stdlib@go1.20.14
0.36.0
1.23.7

Open the chart page →

625
exa-csiexa-csi-driver0.2.0-rev26 of 6See more

exa-csi exa-csi-driver 0.2.0-rev2

6 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.23.0
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-attacher:v4.5.19dcd469f02bb
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.10.1f25af73ee708
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-provisioner:v4.0.1bf5a235b67d8
golang.org/x/net@v0.19.0
stdlib@go1.21.5
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
golang.org/x/net@v0.18.0
stdlib@go1.21.5
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.36.0
1.23.7

Open the chart page →

7,092
exchange-hackexchange-hack0.1.01 of 1See more

exchange-hack exchange-hack 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
oranhack7/solidproject:77c6453942223f
stdlib@go1.21.7
1.23.7

Open the chart page →

818
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.02 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

2 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/loki:2.9.66ca6e2cd3b6f
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.36.0
1.23.7
grafana/loki-canary:2.9.6549a40203e97
golang.org/x/net@v0.17.0
stdlib@go1.21.3
0.36.0
1.23.7

Open the chart page →

5,841
faasnetfaasnet0.0.41 of 5See more

faasnet faasnet 0.0.4

1 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
simpleidserver/faasprometheus:0.0.425e378d57d78
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.1
0.36.0
1.23.7

Open the chart page →

7,745
degafactlyVerified publisher0.11.132 of 3See more

dega factly 0.11.13

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
factly/dega-api:0.15.166fafc7b0a17
stdlib@go1.16.2
1.23.7
factly/dega-server:0.15.194d21479382e
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.2
0.36.0
1.23.7

Open the chart page →

5,749
kavachfactlyVerified publisher0.9.51 of 2See more

kavach factly 0.9.5

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
factly/kavach-server:0.22.3be85ff1b9bd3
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.16.2
0.36.0
1.23.7

Open the chart page →

3,574
mandefactlyVerified publisher0.5.161 of 3See more

mande factly 0.5.16

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
factly/mande-server:0.34.1384d384310ef
golang.org/x/net@v0.7.0
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

4,789
basic-demofairwinds-incubator1.0.01 of 1See more

basic-demo fairwinds-incubator 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
stdlib@go1.20.4
1.23.7

Open the chart page →

1,599
oom-event-generatorfairwinds-incubator0.2.21 of 1See more

oom-event-generator fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.13
0.36.0
1.23.7

Open the chart page →

4,667
skopeo-syncfairwinds-incubator0.3.11 of 1See more

skopeo-sync fairwinds-incubator 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/skopeo/stable:v1.134853591bd1d2
golang.org/x/net@v0.11.0
stdlib@go1.21.0
0.36.0
1.23.7

Open the chart page →

1,743
stackdriver-metrics-adapterfairwinds-incubator0.3.01 of 1See more

stackdriver-metrics-adapter fairwinds-incubator 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
gcr.io/gke-release/custom-metrics-stackdriver-adapter:v0.13.1-gke.06937c0a9b203
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.19.3
0.36.0
1.23.7

Open the chart page →

1,766
fake-network-operatorfake-network-operatorVerified publisher0.1.01 of 1See more

fake-network-operator fake-network-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/muhmmadayan/fake-network-operator:0.1.03806b1fd4a4b
golang.org/x/net@v0.28.0
0.36.0

Open the chart page →

502
quickstartfeatureformVerified publisher0.1.11 of 3See more

quickstart featureform 0.1.1

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
featureformcom/quickstart-loader:latest82396f8fb5e8
stdlib@go1.21.11
1.23.7

Open the chart page →

3,643
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
golang.org/x/net@v0.0.0-20220621193019-9d032be2e588
stdlib@go1.16.5
0.36.0
1.23.7

Open the chart page →

13,540
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
golang.org/x/net@v0.20.0
stdlib@go1.21.6
0.36.0
1.23.7

Open the chart page →

6,234
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.8
0.36.0
1.23.7

Open the chart page →

7,544
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.5
0.36.0
1.23.7

Open the chart page →

14,728
infrafibonacci-cluster-infraVerified publisher1.0.02 of 4See more

infra fibonacci-cluster-infra 1.0.0

2 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.23.7
library/redis:7.4.1bb142a9c18ac
stdlib@go1.18.2
1.23.7

Open the chart page →

12,660
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.5
0.36.0
1.23.7

Open the chart page →

3,321
grgatefikaworks0.3.41 of 1See more

grgate fikaworks 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
stdlib@go1.20.2
1.23.7

Open the chart page →

1,080
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-payment-service:1.0c96f759b6ce4
golang.org/x/net@v0.25.0
stdlib@go1.19.13
0.36.0
1.23.7

Open the chart page →

7,850
first-matefirst-mateVerified publisher1.0.51 of 1See more

first-mate first-mate 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
chriswells0/first-mate:1.0.5f3918ec8471c
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.36.0
1.23.7

Open the chart page →

1,722
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:3.6.213e51da56fc54
stdlib@go1.15.1
1.23.7

Open the chart page →

112,968
dsba-pdpfiware0.1.22 of 2See more

dsba-pdp fiware 0.1.2

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
golang.org/x/net@v0.1.0
stdlib@go1.18.10
0.36.0
1.23.7
quay.io/wi_stefan/dsba-db-migrations:0.0.125b986cd14a08
stdlib@go1.18.9
1.23.7

Open the chart page →

4,105
endpoint-auth-servicefiware0.1.43 of 4See more

endpoint-auth-service fiware 0.1.4

3 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.3
0.36.0
1.23.7
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.18.5
0.36.0
1.23.7
quay.io/fiware/ishare-auth-provider:0.4.3158108f70f95
stdlib@go1.18.5
1.23.7

Open the chart page →

11,840
grafanaflagger1.7.01 of 1See more

grafana flagger 1.7.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
stdlib@go1.15.5
0.36.0
1.23.7

Open the chart page →

3,373
podinfoflagger6.1.41 of 1See more

podinfo flagger 6.1.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
stdlib@go1.17.9
0.36.0
1.23.7

Open the chart page →

2,816
apm-hubflanksourceVerified publisher0.0.471 of 2See more

apm-hub flanksource 0.0.47

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
golang.org/x/net@v0.10.0
stdlib@go1.20.7
0.36.0
1.23.7

Open the chart page →

6,210
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
stdlib@go1.19.9
1.23.7

Open the chart page →

5,544
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
stdlib@go1.20.7
1.23.7

Open the chart page →

4,707
flanksource-uiflanksourceVerified publisher1.4.3191 of 1See more

flanksource-ui flanksource 1.4.319

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.319953948a194c9
stdlib@go1.23.5
1.23.7

Open the chart page →

2,610
mission-controlflanksourceVerified publisher0.1.3382 of 8See more

mission-control flanksource 0.1.338

2 of the 8 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
stdlib@go1.19.8
1.23.7
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
stdlib@go1.23.5
1.23.7

Open the chart page →

9,013
mission-control-tenantflanksourceVerified publisher1.0.923 of 3See more

mission-control-tenant flanksource 1.0.92

3 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
golang.org/x/net@v0.7.0
stdlib@go1.17.13
0.36.0
1.23.7
rancher/k3s:v1.28.2-k3s18c2599ecfca8
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.36.0
1.23.7
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.36.0
1.23.7

Open the chart page →

5,725
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.23.7

Open the chart page →

4,119
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.23.7

Open the chart page →

8,069
fluent-operatorfluent-operatorVerified publisher0.1.01 of 2See more

fluent-operator fluent-operator 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
kubesphere/fluent-operator:v1.0.2702df77228c6
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.6
0.36.0
1.23.7

Open the chart page →

2,631
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
louislam/uptime-kuma:13d632903e6af
stdlib@go1.20.5
1.23.7

Open the chart page →

3,528
flyte-depsflyte1.16.81 of 3See more

flyte-deps flyte 1.16.8

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.1
0.36.0
1.23.7

Open the chart page →

2,246
csp-reporterfoomoVerified publisher2.2.01 of 1See more

csp-reporter foomo 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
foomo/csp-reporter:1.3.0e436da524785
stdlib@go1.18
1.23.7

Open the chart page →

1,409
forkliftforklift0.1.42 of 2See more

forklift forklift 0.1.4

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
wuhan005/forklift:daemon4e6da210e449
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.36.0
1.23.7
wuhan005/forklift:controllerbfbe82d59850
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.36.0
1.23.7

Open the chart page →

1,816
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/net@v0.4.0
stdlib@go1.18.10
0.36.0
1.23.7

Open the chart page →

4,681
forwardforward1.3.11 of 1See more

forward forward 1.3.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
udhos/forward:1.1.312e120d39fdb
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.36.0
1.23.7

Open the chart page →

2,215

Container images carrying it

3,305 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.36.0
1.23.7
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.36.0
1.23.7
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
golang.org/x/net@v0.4.0
stdlib@go1.19
0.36.0
1.23.7
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
golang.org/x/net@v0.17.0
stdlib@go1.20.5
0.36.0
1.23.7
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.3
0.36.0
1.23.7
1

syft 1.42.1 · advisories as of 19 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.