StackRadar

CVE-2025-22870

Medium

Advisory

Published 12 Mar 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,666
of 17,781 indexed, latest versions
Container images
3,231
deployed by those charts
Fix available
2 of 3
affected packages

HTTP Proxy bypass using IPv6 Zone IDs in golang.org/x/net

Carried by container images the latest versions of 2,666 of 17,781 indexed charts deploy, on 3,231 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+200 more0.36.02,459
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+147 more1.23.73,131
OSV records
DEBIAN-CVE-2025-22870GHSA-qxp5-gwg8-xv66GO-2025-3503

Charts affected

2,666 by stars
ChartLatestAffected imagesRadar Score
boundaryboundary-chart0.3.121 of 1See more

boundary boundary-chart 0.3.12

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
hashicorp/boundary:0.15.3339b78b61750
golang.org/x/net@v0.21.0
stdlib@go1.21.8
0.36.0
1.23.7

Open the chart page →

1,624
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,830
bucket-backup-restorebucket-backup-restore0.1.01 of 2See more

bucket-backup-restore bucket-backup-restore 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
golang.org/x/net@v0.17.0
stdlib@go1.21.4
0.36.0
1.23.7

Open the chart page →

2,042
agentbuildkite0.6.41 of 1See more

agent buildkite 0.6.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.7
0.36.0
1.23.7

Open the chart page →

2,663
blackbox-exportercamptocamp31.0.01 of 1See more

blackbox-exporter camptocamp3 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.25.0b04a9fef4fa0
golang.org/x/net@v0.24.0
stdlib@go1.22.2
0.36.0
1.23.7

Open the chart page →

906
capsulecapsuleOfficialVerified publisher0.14.51 of 2See more

capsule capsule 0.14.5

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7

Open the chart page →

1,229
capsule-proxycapsule-proxyOfficialVerified publisher0.14.11 of 2See more

capsule-proxy capsule-proxy 0.14.1

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
stdlib@go1.22.5
0.36.0
1.23.7

Open the chart page →

1,222
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.2
0.36.0
1.23.7

Open the chart page →

3,509
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
golang.org/x/net@v0.27.0
stdlib@go1.23.0
0.36.0
1.23.7

Open the chart page →

1,799
finops-stackcert-managerVerified publisher0.0.57 of 12See more

finops-stack cert-manager 0.0.5

7 of the 12 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:11.1.3b23b588cf7cb
golang.org/x/net@v0.26.0
stdlib@go1.22.4
0.36.0
1.23.7
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.36.0
1.23.7
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.36.0
1.23.7
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.36.0
1.23.7
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.36.0
1.23.7
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.36.0
1.23.7
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
golang.org/x/net@v0.22.0
stdlib@go1.21.12
0.36.0
1.23.7

Open the chart page →

12,562
cert-manager-webhook-arvancloudcert-manager-webhook-arvancloudVerified publisher0.1.11 of 1See more

cert-manager-webhook-arvancloud cert-manager-webhook-arvancloud 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/net@v0.9.0
0.36.0

Open the chart page →

1,067
cert-manager-webhook-gandicert-manager-webhook-gandi0.6.01 of 1See more

cert-manager-webhook-gandi cert-manager-webhook-gandi 0.6.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/sintef/cert-manager-webhook-gandi:0.6.06819b34ccac8
golang.org/x/net@v0.26.0
stdlib@go1.22.0
0.36.0
1.23.7

Open the chart page →

1,024
cert-vaultcert-vaultOfficialVerified publisher2.12.01 of 7See more

cert-vault cert-vault 2.12.0

1 of the 7 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
golang.org/x/net@v0.33.0
0.36.0

Open the chart page →

15,863
chatclichatcliVerified publisher1.203.01 of 2See more

chatcli chatcli 1.203.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.31.10e0b2d217d1d2
golang.org/x/net@v0.26.0
0.36.0

Open the chart page →

1,026
passbolt-hachristianhuthVerified publisher6.0.11 of 4See more

passbolt-ha christianhuth 6.0.1

1 of the 4 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.23.7

Open the chart page →

10,817
challengerchronicleVerified publisher0.1.11 of 1See more

challenger chronicle 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/challenger-go:0.1.2c8d5a3c0e966
stdlib@go1.22.12
1.23.7

Open the chart page →

977
access-managerckotzbauerVerified publisher0.14.31 of 1See more

access-manager ckotzbauer 0.14.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/access-managerdigest-pinneddd584fcda0ff
golang.org/x/net@v0.22.0
stdlib@go1.22.1
0.36.0
1.23.7

Open the chart page →

643
cloudbees-sidecar-injectorcloudbees2.3.32 of 2See more

cloudbees-sidecar-injector cloudbees 2.3.3

2 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
cloudbees/cert-requester:2.3.31d44fb4f799b
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.36.0
1.23.7
cloudbees/sidecar-injector:2.3.38f102ef0383a
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
stdlib@go1.20.1
0.36.0
1.23.7

Open the chart page →

3,268
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.23.7
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/net@v0.0.0-20200822124328-c89045814202
stdlib@go1.15.2
0.36.0
1.23.7

Open the chart page →

4,256
cnpg-sandboxcloudnative-pgVerified publisher0.6.13 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

3 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
stdlib@go1.17.6
0.36.0
1.23.7
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.18.6
0.36.0
1.23.7
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.36.0
1.23.7

Open the chart page →

7,583
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
stdlib@go1.16.7
1.23.7

Open the chart page →

2,713
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.23.7

Open the chart page →

1,579
cloudttycloudtty0.8.91 of 2See more

cloudtty cloudtty 0.8.9

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell-operator:v0.8.9e43ad91f0684
golang.org/x/net@v0.25.0
stdlib@go1.21.11
0.36.0
1.23.7

Open the chart page →

3,951
cluster-setupcluster-setup1.5.02 of 8See more

cluster-setup cluster-setup 1.5.0

2 of the 8 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.23.7
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
golang.org/x/net@v0.33.0
stdlib@go1.22.7
0.36.0
1.23.7

Open the chart page →

10,037
istio-allcode4devsVerified publisher1.2.04 of 6See more

istio-all code4devs 1.2.0

4 of the 6 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
quay.io/kiali/kiali:v1.89.30dcdb1c1e747
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.36.0
1.23.7
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
golang.org/x/net@v0.27.0
stdlib@go1.22.6
0.36.0
1.23.7

Open the chart page →

4,784
istio-control-planecode4devsVerified publisher1.0.02 of 3See more

istio-control-plane code4devs 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
istio/install-cni:1.24.2-distrolessaef4825e110f
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
istio/pilot:1.24.2-distroless137e44e3d1d2
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7

Open the chart page →

2,360
maintenancecodewithemadVerified publisher0.1.61 of 1See more

maintenance codewithemad 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/caddy:2.9-alpineb4e3952384eb
golang.org/x/net@v0.33.0
stdlib@go1.23.4
0.36.0
1.23.7

Open the chart page →

1,469
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.10
0.36.0
1.23.7

Open the chart page →

7,303
cosmo-controller-managercosmoVerified publisher0.9.01 of 2See more

cosmo-controller-manager cosmo 0.9.0

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-controller-manager:v0.9.08c7fa5552028
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.36.0
1.23.7

Open the chart page →

1,927
cosmo-dashboardcosmoVerified publisher0.9.11 of 1See more

cosmo-dashboard cosmo 0.9.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/cosmo-dashboard:v0.9.16a1c4a81a924
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.36.0
1.23.7

Open the chart page →

1,939
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.16.5
0.36.0
1.23.7

Open the chart page →

6,473
duplicaticronce0.1.01 of 1See more

duplicati cronce 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
stdlib@go1.14.4
1.23.7

Open the chart page →

3,026
cryptlex-enterprisecryptlex3.21.251 of 8See more

cryptlex-enterprise cryptlex 3.21.25

1 of the 8 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2025-03-12T18-04-18Z46b3009bf704
golang.org/x/net@v0.35.0
0.36.0

Open the chart page →

2,345
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
stdlib@go1.19.8
1.23.7

Open the chart page →

13,761
revadcs3orgOfficialVerified publisher1.6.11 of 1See more

revad cs3org 1.6.1

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.36.0
1.23.7

Open the chart page →

1,704
cubefscubefs3.2.06 of 10See more

cubefs cubefs 3.2.0

6 of the 10 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
stdlib@go1.13.1
0.36.0
1.23.7
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.4
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.3
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
stdlib@go1.16.2
0.36.0
1.23.7
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.2
0.36.0
1.23.7

Open the chart page →

15,891
CubeUniversecubeuniverseVerified publisher0.1.01 of 1See more

CubeUniverse cubeuniverse 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
stdlib@go1.20.3
0.36.0
1.23.7

Open the chart page →

1,837
aibrixdanchevVerified publisher0.7.02 of 5See more

aibrix danchev 0.7.0

2 of the 5 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
aibrix/controller-manager:v0.7.076aabbbfda79
golang.org/x/net@v0.34.0
stdlib@go1.22.12
0.36.0
1.23.7
aibrix/gateway-plugins:v0.7.05b93ea4c753a
golang.org/x/net@v0.34.0
stdlib@go1.22.12
0.36.0
1.23.7

Open the chart page →

5,274
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.23.7

Open the chart page →

38,346
datacube-explorerdatacube-charts0.5.321 of 1See more

datacube-explorer datacube-charts 0.5.32

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
opendatacube/explorer:latest120457ffcd69
stdlib@go1.22.2
1.23.7

Open the chart page →

4,854
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.15
0.36.0
1.23.7

Open the chart page →

4,759
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.13.11
0.36.0
1.23.7

Open the chart page →

4,568
dbrepodbrepo1.13.37 of 25See more

dbrepo dbrepo 1.13.3

7 of the 25 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
golang.org/x/net@v0.29.0
stdlib@go1.23.4
0.36.0
1.23.7
bitnamilegacy/mariadb-galera:11.3.2-debian-12-r9aee9c668098f
stdlib@go1.22.5
1.23.7
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
golang.org/x/net@v0.17.0
stdlib@go1.21.12
0.36.0
1.23.7
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
golang.org/x/net@v0.27.0
stdlib@go1.22.8
0.36.0
1.23.7
bitnamilegacy/os-shell:12-debian-12-r3217444b4b2c96
golang.org/x/net@v0.27.0
stdlib@go1.22.8
0.36.0
1.23.7
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
golang.org/x/net@v0.17.0
stdlib@go1.22.8
0.36.0
1.23.7
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
golang.org/x/net@v0.27.0
stdlib@go1.22.7
0.36.0
1.23.7

Open the chart page →

52,635
dregsydeliveryheroVerified publisher0.1.51 of 1See more

dregsy deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.3
0.36.0
1.23.7

Open the chart page →

2,969
gripmockdeliveryheroVerified publisher1.1.31 of 1See more

gripmock deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
tkpd/gripmock:1.10.174441dadcfbd
stdlib@go1.14.6
1.23.7

Open the chart page →

2,793
labelsmanager-controllerdeliveryheroVerified publisher1.0.41 of 1See more

labelsmanager-controller deliveryhero 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.13.15
0.36.0
1.23.7

Open the chart page →

2,305
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
stdlib@go1.13.5
0.36.0
1.23.7

Open the chart page →

7,984
snapshot-controllerdemocratic-csiVerified publisher0.3.01 of 1See more

snapshot-controller democratic-csi 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
golang.org/x/net@v0.33.0
stdlib@go1.23.6
0.36.0
1.23.7

Open the chart page →

466
kube-bench-metricsdevopstalesVerified publisher0.1.01 of 1See more

kube-bench-metrics devopstales 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
elastisys/kube-bench-metrics:0.1.6509b94f1da55
stdlib@go1.15.7
1.23.7

Open the chart page →

2,111
kubedashdevopstalesOfficialVerified publisher4.0.01 of 8See more

kubedash devopstales 4.0.0

1 of the 8 container images this version deploys carry CVE-2025-22870.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.22.48be660470961
stdlib@go1.17.3
1.23.7

Open the chart page →

9,205

Container images carrying it

3,231 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/mariadb:11.3.2e101f9db3191
stdlib@go1.18.2
1.23.7
2
library/mysql:8.2.0212fe73edca5
stdlib@go1.18.2
1.23.7
2
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.23.7
2
library/nats:2.9.17-alpine1a7b320b2942
stdlib@go1.19.9
1.23.7
2
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.23.7
2
library/nats:2.10.5-alpine85319e5e541b
stdlib@go1.21.4
1.23.7
2
library/nats:2.8.4-alpine988010f74b61
stdlib@go1.17.10
1.23.7
2
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.23.7
2
library/postgres:16.24aea012537ed
stdlib@go1.18.2
1.23.7
2
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.23.7
2
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.23.7
2
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.23.7
2
library/redis148bb5411c18
stdlib@go1.18.2
1.23.7
2
library/redis:7.2.3a7cee7c8178f
stdlib@go1.18.2
1.23.7
2
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.36.0
1.23.7
2
library/zookeeper:3.9.5f258365d4882
stdlib@go1.18.1
1.23.7
2
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
golang.org/x/net@v0.24.0
stdlib@go1.22.5
0.36.0
1.23.7
2
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.36.0
1.23.7
2
louislam/uptime-kuma:2.5.4917318f9d7be
stdlib@go1.20.5
1.23.7
2
louislam/uptime-kuma:2.3.29aeb4e51d038
stdlib@go1.20.5
1.23.7
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
stdlib@go1.20.5
1.23.7
2
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
stdlib@go1.14
1.23.7
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.2
0.36.0
1.23.7
2
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.15.5
0.36.0
1.23.7
2
minio/operator:v4.3.754393e03f3b2
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
stdlib@go1.17.4
0.36.0
1.23.7
2
natsio/nats-account-server:1.0.0a3381560aab6
stdlib@go1.16.6
1.23.7
2
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.1
0.36.0
1.23.7
2
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
stdlib@go1.19
1.23.7
2
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
stdlib@go1.19.4
1.23.7
2
natsio/prometheus-nats-exporter:0.10.016048afb67a5
stdlib@go1.19
1.23.7
2
natsio/prometheus-nats-exporter:0.11.031c02aac089a
stdlib@go1.20.3
1.23.7
2
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.23.7
2
opendatacube/ows:latest668cbb41473c
stdlib@go1.22.2
1.23.7
2
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.36.0
1.23.7
2
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.3
0.36.0
1.23.7
2
openebs/provisioner-localpv:3.5.0aea39e49bb97
golang.org/x/net@v0.17.0
stdlib@go1.19.13
0.36.0
1.23.7
2
openkruise/kruise-helm-hook:v0.1.0edc7cf9428fd
golang.org/x/net@v0.24.0
stdlib@go1.20.14
0.36.0
1.23.7
2
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.16.2
0.36.0
1.23.7
2
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.36.0
1.23.7
2
oryd/kratos:v1.3.1fe2428f103a6
golang.org/x/net@v0.27.0
stdlib@go1.23.2
0.36.0
1.23.7
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
stdlib@go1.20.5
0.36.0
1.23.7
2
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.36.0
1.23.7
2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
golang.org/x/net@v0.21.0
stdlib@go1.21.7
0.36.0
1.23.7
2
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
golang.org/x/net@v0.29.0
stdlib@go1.23.2
0.36.0
1.23.7
2
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.23.7
2
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.23.7
2
phntom/kochi:1.1.33b82358bd56e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.5
0.36.0
1.23.7
2
place1/wg-access-server:v0.4.62b2f3ea80ed6
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.13.8
0.36.0
1.23.7
2
postgis/postgis:15-3.3a2fc46b52819
stdlib@go1.18.2
1.23.7
2
pottava/s3-proxy:2.020a0bcb15f76
stdlib@go1.13.7
1.23.7
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.