StackRadar

CVE-2025-22871

Critical

Advisory

Published 8 Apr 2025In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,763
of 17,821 indexed, latest versions
Container images
3,307
deployed by those charts
Fix available
9 of 10
affected packages

Red Hat Security Advisory: skopeo security update

Carried by container images the latest versions of 2,763 of 17,821 indexed charts deploy, on 3,307 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
skopeorpm2:1.11.2-0.1.el9, 2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.11.2-0.1.el9_2.3, 2:1.11.3-0.1.module+el8.8.0+23219+eb2ac2282
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-67.module+el8.8.0+22334+bb93e3981
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.15-4.module+el8.8.0+22334+bb93e3981
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.11-1.module+el8.8.0+22334+bb93e3981
git-lfsrpm2.13.3-3.el8_60:3.4.1-5.el8_101
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-1.module+el8.8.0+22334+bb93e3981
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.8.0+22334+bb93e3981
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.0-3.module+el8.8.0+22334+bb93e3981
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+152 more1.23.83,307
OSV records
DEBIAN-CVE-2025-22871RHSA-2025:9018RHSA-2025:9025RHSA-2025:9060GO-2025-3563
Also known as
BIT-golang-2025-22871, GHSA-g9pc-8g42-g6vq, RHSA-2025:9142, RHSA-2025:9145, RHSA-2025:9199

Charts affected

2,763 by stars
ChartLatestAffected imagesRadar Score
aws-calicoaws0.3.111 of 1See more

aws-calico aws 0.3.11

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.20.1379efe0c2541
stdlib@go1.15.2
1.23.8

Open the chart page →

2,251
yataibentomlVerified publisher1.1.131 of 1See more

yatai bentoml 1.1.13

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
stdlib@go1.20.7
1.23.8

Open the chart page →

1,917
yatai-deploymentbentomlVerified publisher1.1.211 of 2See more

yatai-deployment bentoml 1.1.21

1 of the 2 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
stdlib@go1.19.13
1.23.8

Open the chart page →

1,160
backup-zenbzen0.1.41 of 1See more

backup-zen bzen 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
rezachalak/bzen-mongo:1.0.034f694325191
stdlib@go1.19.12
1.23.8

Open the chart page →

69,141
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
stdlib@go1.21.4
1.23.8

Open the chart page →

1,901
cadvisorcadvisorVerified publisher0.1.151 of 1See more

cadvisor cadvisor 0.1.15

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
stdlib@go1.19.9
1.23.8

Open the chart page →

1,705
cert-managerchoerodon1.8.24 of 4See more

cert-manager choerodon 1.8.2

4 of the 4 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
stdlib@go1.17.11
1.23.8
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
stdlib@go1.17.11
1.23.8
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
stdlib@go1.17.11
1.23.8
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
stdlib@go1.17.11
1.23.8

Open the chart page →

7,801
popeyechristianhuthVerified publisher2.4.31 of 1See more

popeye christianhuth 2.4.3

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
stdlib@go1.23.5
1.23.8

Open the chart page →

1,342
hellocloudechoVerified publisher0.1.21 of 1See more

hello cloudecho 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.23.8

Open the chart page →

1,818
cloudflare-exportercloudflare-exporter0.2.31 of 1See more

cloudflare-exporter cloudflare-exporter 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
ghcr.io/lablabs/cloudflare_exporter:0.0.1670d74ec46602
stdlib@go1.22.3
1.23.8

Open the chart page →

791
ghostcloudpirates-ghostVerified publisher0.20.251 of 3See more

ghost cloudpirates-ghost 0.20.25

1 of the 3 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
library/mariadb:12.0.25b6a1eac15b8
stdlib@go1.18.2
1.23.8

Open the chart page →

7,020
cluster-registrycluster-registry-controller0.2.121 of 1See more

cluster-registry cluster-registry-controller 0.2.12

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
stdlib@go1.18
1.23.8

Open the chart page →

1,708
coder-observabilitycoder-observabilityVerified publisher0.7.312 of 21See more

coder-observability coder-observability 0.7.3

12 of the 21 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
grafana/agent:v0.40.3f6cbec9409be
stdlib@go1.22.1
1.23.8
grafana/loki:3.1.0d947e68a84d9
stdlib@go1.22.2
1.23.8
grafana/loki-canary:3.1.039baf6d67f85
stdlib@go1.22.2
1.23.8
prom/memcached-exporter:v0.14.2d8a61419b841
stdlib@go1.21.5
1.23.8
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.23.8
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
stdlib@go1.18.6
1.23.8
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
stdlib@go1.18.6
1.23.8
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
stdlib@go1.22.3
1.23.8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
stdlib@go1.21.7
1.23.8
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
stdlib@go1.22.3
1.23.8
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
stdlib@go1.22.5
1.23.8
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.23.8

Open the chart page →

24,973
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
stdlib@go1.21.5
1.23.8

Open the chart page →

17,018
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
stdlib@go1.16.6
1.23.8

Open the chart page →

3,089
cosmocosmo-platformOfficialVerified publisher0.20.05 of 10See more

cosmo cosmo-platform 0.20.0

5 of the 10 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.2.4-debian-12-r1670cafc5a71e8
stdlib@go1.21.10
1.23.8
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
stdlib@go1.22.3
1.23.8
ghcr.io/wundergraph/cosmo/graphqlmetrics:0.33.0efb69ec3330c
stdlib@go1.23.6
1.23.8
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
stdlib@go1.23.6
1.23.8
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
stdlib@go1.20.7
1.23.8

Open the chart page →

29,756
dapr-dashboarddapr0.15.01 of 1See more

dapr-dashboard dapr 0.15.0

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
daprio/dashboard:0.15.04be696707bd1
stdlib@go1.21.13
1.23.8

Open the chart page →

1,322
deepflowdeepflow6.2.2015 of 8See more

deepflow deepflow 6.2.201

5 of the 8 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
stdlib@go1.18.3
1.23.8
deepflowce/deepflow-init-grafana:v6.2.27cd16719eb57
stdlib@go1.19.3
1.23.8
deepflowce/deepflow-server:v6.2.21477e7334d13
stdlib@go1.18.10
1.23.8
deepflowce/mysql:8.0.313d7ae561cf60
stdlib@go1.16.7
1.23.8
grafana/grafana:9.3.6e5a9655dabef
stdlib@go1.19.4
1.23.8

Open the chart page →

16,009
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
stdlib@go1.21.10
1.23.8

Open the chart page →

3,482
kube-benchdeliveryheroVerified publisher0.1.171 of 1See more

kube-bench deliveryhero 0.1.17

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
stdlib@go1.21.7
1.23.8

Open the chart page →

1,624
listmonkdeliveryheroVerified publisher0.1.121 of 1See more

listmonk deliveryhero 0.1.12

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
stdlib@go1.17.6
1.23.8

Open the chart page →

2,538
prometheus-locust-exporterdeliveryheroVerified publisher1.2.31 of 1See more

prometheus-locust-exporter deliveryhero 1.2.3

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
containersol/locust_exporter:v0.4.1a914972d19ad
stdlib@go1.15.8
1.23.8

Open the chart page →

1,277
zabbix-kubernetes-discoverydjerfyVerified publisher1.4.201 of 1See more

zabbix-kubernetes-discovery djerfy 1.4.20

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
ghcr.io/djerfy/zabbix-kubernetes-discovery:v1.4.207a50c07e7c69
stdlib@go1.23.1
1.23.8

Open the chart page →

4,239
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
stdlib@go1.13.15
1.23.8

Open the chart page →

2,273
postgres-pgdump-backupeugen0.7.61 of 1See more

postgres-pgdump-backup eugen 0.7.6

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.23.8

Open the chart page →

353
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.23.8

Open the chart page →

12,064
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.23.8

Open the chart page →

14,568
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
stdlib@go1.20.10
1.23.8

Open the chart page →

13,897
keydbfinkinfridomVerified publisher0.48.31 of 1See more

keydb finkinfridom 0.48.3

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.23.8

Open the chart page →

5,325
ascii-moviegabe565Verified publisher0.16.41 of 1See more

ascii-movie gabe565 0.16.4

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
ghcr.io/gabe565/ascii-movie:1.9.627f85bb98da3
stdlib@go1.24.0
1.23.8

Open the chart page →

1,133
domain-watchgabe565Verified publisher1.1.01 of 1See more

domain-watch gabe565 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
ghcr.io/gabe565/domain-watch:latest34c5a1e351d6
stdlib@go1.24.1
1.23.8

Open the chart page →

936
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
stdlib@go1.17.7
1.23.8

Open the chart page →

3,036
error-pagesgeek-cookbookVerified publisher1.2.21 of 1See more

error-pages geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
stdlib@go1.17.6
1.23.8

Open the chart page →

1,111
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
stdlib@go1.15.10
1.23.8

Open the chart page →

1,746
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
stdlib@go1.17.10
1.23.8

Open the chart page →

7,637
multusgeek-cookbookVerified publisher3.5.22 of 3See more

multus geek-cookbook 3.5.2

2 of the 3 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/cni-plugins:v0.9.1241592d93640
stdlib@go1.15.8
1.23.8
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
stdlib@go1.13.10
1.23.8

Open the chart page →

4,768
plexgeek-cookbookVerified publisher6.4.31 of 1See more

plex geek-cookbook 6.4.3

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
stdlib@go1.18.4
1.23.8

Open the chart page →

9,851
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
stdlib@go1.17.8
1.23.8

Open the chart page →

10,296
smarter-device-managergeek-cookbookVerified publisher6.5.21 of 1See more

smarter-device-manager geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
stdlib@go1.16.4
1.23.8

Open the chart page →

2,338
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
stdlib@go1.14.13
1.23.8

Open the chart page →

3,379
syncthinggeek-cookbookVerified publisher3.5.21 of 1See more

syncthing geek-cookbook 3.5.2

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
syncthing/syncthing:1.18.2966433161272
stdlib@go1.17
1.23.8

Open the chart page →

2,612
tautulligeek-cookbookVerified publisher11.4.21 of 1See more

tautulli geek-cookbook 11.4.2

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
stdlib@go1.16.7
1.23.8

Open the chart page →

10,867
traefik-forward-authgeek-cookbookVerified publisher2.2.21 of 1See more

traefik-forward-auth geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
stdlib@go1.13.12
1.23.8

Open the chart page →

2,235
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
stdlib@go1.20.4
1.23.8

Open the chart page →

11,978
nzbhydra2halkeye2.30.11 of 2See more

nzbhydra2 halkeye 2.30.1

1 of the 2 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
stdlib@go1.14
1.23.8

Open the chart page →

6,711
unifi-pollerhalkeye0.1.21 of 1See more

unifi-poller halkeye 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
golift/unifi-poller:2.0.0cafac968b540
stdlib@go1.13.7
1.23.8

Open the chart page →

1,655
whoamiharrytangVerified publisher0.2.01 of 1See more

whoami harrytang 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
traefik/whoami:v1.11.0200689790a0a
stdlib@go1.24.1
1.23.8

Open the chart page →

353
monitoring-stackhaukitechVerified publisher0.1.113 of 3See more

monitoring-stack haukitech 0.1.11

3 of the 3 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
stdlib@go1.23.1
1.23.8
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.23.8
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
stdlib@go1.23.3
1.23.8

Open the chart page →

2,167
prometheus-operatorhaukitechVerified publisher0.1.41 of 1See more

prometheus-operator haukitech 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.77.1dde69a8b6f4b
stdlib@go1.23.1
1.23.8

Open the chart page →

562
headscaleheadscaleVerified publisher1.0.191 of 3See more

headscale headscale 1.0.19

1 of the 3 container images this version deploys carry CVE-2025-22871.

Container imageDigestPackageFixed in
alpine/k8s:1.36.244ef4942e171
stdlib@go1.24.0
1.23.8

Open the chart page →

3,411

Container images carrying it

3,307 by charts deploying them

A fixed version is listed for 9 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.23.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.23.8
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.23.8
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.23.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.23.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.23.8
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.23.8
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.