StackRadar

CVE-2025-22872

Medium

Advisory

Published 16 Apr 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,054
of 17,787 indexed, latest versions
Container images
2,543
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/net vulnerable to Cross-site Scripting

Carried by container images the latest versions of 2,054 of 17,787 indexed charts deploy, on 2,543 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+203 more0.38.02,543
OSV records
GHSA-vvgc-356p-c3xw
Also known as
GO-2025-3595

Charts affected

2,054 by stars
ChartLatestAffected imagesRadar Score
ai-agentdevtron0.0.11 of 1See more

ai-agent devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/net@v0.23.0
0.38.0

Open the chart page →

9,152
argocddevtron1.8.12 of 3See more

argocd devtron 1.8.1

2 of the 3 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
0.38.0
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.38.0

Open the chart page →

10,468
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.38.0

Open the chart page →

12,999
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/net@v0.8.0
0.38.0

Open the chart page →

1,580
devtron-enterprisedevtron48.0.09 of 28See more

devtron-enterprise devtron 48.0.0

9 of the 28 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.38.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.38.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
0.38.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.38.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.38.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.38.0
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.38.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.38.0
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/net@v0.28.0
0.38.0

Open the chart page →

66,542
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.38.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
0.38.0

Open the chart page →

5,041
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/net@v0.8.0
0.38.0

Open the chart page →

4,969
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.38.0

Open the chart page →

11,957
jcmhproxy-ingressdevtron0.14.61 of 1See more

jcmhproxy-ingress devtron 0.14.6

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

1,379
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.38.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
0.38.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.38.0

Open the chart page →

8,645
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.38.0

Open the chart page →

2,435
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.38.0

Open the chart page →

1,176
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
0.38.0

Open the chart page →

1,507
ai-agentdevtron-labs0.0.11 of 1See more

ai-agent devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
golang.org/x/net@v0.23.0
0.38.0

Open the chart page →

9,152
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
0.38.0
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.38.0

Open the chart page →

10,468
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.38.0

Open the chart page →

12,999
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/net@v0.8.0
0.38.0

Open the chart page →

1,580
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.38.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.38.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.38.0

Open the chart page →

10,073
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0.38.0

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.09 of 28See more

devtron-enterprise devtron-labs 48.0.0

9 of the 28 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.38.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.38.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
golang.org/x/net@v0.17.0
0.38.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.38.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.38.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.38.0
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.38.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.38.0
quay.io/devtron/silver-surfer:e3b9a2f6-1191-387899640e2dc4316
golang.org/x/net@v0.28.0
0.38.0

Open the chart page →

66,542
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.38.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
0.38.0

Open the chart page →

5,041
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
golang.org/x/net@v0.8.0
0.38.0

Open the chart page →

4,969
devtron-operatordevtron-labs0.23.35 of 11See more

devtron-operator devtron-labs 0.23.3

5 of the 11 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.38.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.38.0
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.38.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.38.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.38.0

Open the chart page →

31,447
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.38.0

Open the chart page →

11,957
jcmhproxy-ingressdevtron-labs0.14.61 of 1See more

jcmhproxy-ingress devtron-labs 0.14.6

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

1,379
kube-prometheus-stackdevtron-labs19.3.03 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

3 of the 6 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.38.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
0.38.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.38.0

Open the chart page →

8,645
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.38.0

Open the chart page →

2,435
winter-soldierdevtron-labs0.10.61 of 1See more

winter-soldier devtron-labs 0.10.6

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.38.0

Open the chart page →

1,176
zincdevtron-labs0.1.21 of 1See more

zinc devtron-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
0.38.0

Open the chart page →

1,507
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
golang.org/x/net@v0.20.0
0.38.0

Open the chart page →

19,063
digital-mobiusdigital-mobius0.1.41 of 1See more

digital-mobius digital-mobius 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
qoveryrd/digital-mobius:0.1.4b30a9398a83c
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.38.0

Open the chart page →

2,287
direktivdirektivVerified publisher0.10.03 of 6See more

direktiv direktiv 0.10.0

3 of the 6 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-k8s:0.120.01e45d9483faa
golang.org/x/net@v0.35.0
0.38.0
registry.k8s.io/ingress-nginx/controller:v1.12.0e6b8de175acd
golang.org/x/net@v0.33.0
0.38.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.0aaafd456bda1
golang.org/x/net@v0.33.0
0.38.0

Open the chart page →

3,470
graphite-exporterdjjudas21Verified publisher0.1.91 of 1See more

graphite-exporter djjudas21 0.1.9

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
prom/graphite-exporter:v0.16.0e54bca6645ea
golang.org/x/net@v0.30.0
0.38.0

Open the chart page →

782
hammonddjjudas21Verified publisher0.3.91 of 1See more

hammond djjudas21 0.3.9

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
0.38.0

Open the chart page →

1,806
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
golang.org/x/net@v0.27.0
0.38.0

Open the chart page →

17,053
smokepingdjjudas21Verified publisher0.1.31 of 1See more

smokeping djjudas21 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
linuxserver/smokeping:2.8.2b7f906899cd3
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.38.0

Open the chart page →

2,053
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
golang.org/x/net@v0.19.0
0.38.0

Open the chart page →

4,217
dnation-kubernetes-monitoring-stackdnationcloud4.0.26 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

6 of the 17 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
golang.org/x/net@v0.30.0
0.38.0
grafana/loki:3.2.0882e30c20683
golang.org/x/net@v0.28.0
0.38.0
grafana/loki-canary:3.2.049e03f80d361
golang.org/x/net@v0.28.0
0.38.0
prom/memcached-exporter:v0.15.0bb01ad25e9fc
golang.org/x/net@v0.29.0
0.38.0
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
golang.org/x/net@v0.0.0-20221017152216-f25eb7ecb193
0.38.0
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
golang.org/x/net@v0.1.0
0.38.0

Open the chart page →

21,455
ssl-exporterdnationcloud1.2.11 of 1See more

ssl-exporter dnationcloud 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
golang.org/x/net@v0.0.0-20220708220712-1185a9018129
0.38.0

Open the chart page →

1,632
snmp-exporterdniel0.0.21 of 1See more

snmp-exporter dniel 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
prom/snmp-exporter:v0.20.09d226d7de223
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.38.0

Open the chart page →

2,126
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.38.0

Open the chart page →

8,408
furan2dollarshaveclubVerified publisher0.2.01 of 1See more

furan2 dollarshaveclub 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
dollarshaveclub/furan2:master14a257836529
golang.org/x/net@v0.0.0-20201002202402-0a1ea396d57c
0.38.0

Open the chart page →

3,046
domain-exporterdomain-exporterVerified publisher0.0.81 of 1See more

domain-exporter domain-exporter 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/shift/domain_exporter:v0.1.1347e27690a816
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.38.0

Open the chart page →

1,351
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
golang.org/x/net@v0.36.0
0.38.0

Open the chart page →

3,166
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
codecov/self-hosted-gateway:24.4.1de483faad6e5
golang.org/x/net@v0.21.0
0.38.0

Open the chart page →

24,975
corednsdoubanVerified publisher1.39.21 of 1See more

coredns douban 1.39.2

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
coredns/coredns:1.12.040384aa1f5ea
golang.org/x/net@v0.31.0
0.38.0

Open the chart page →

1,132
gatekeeperdoubanVerified publisher3.17.12 of 3See more

gatekeeper douban 3.17.1

2 of the 3 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.17.1b7b4d7cfdd52
golang.org/x/net@v0.27.0
0.38.0
openpolicyagent/gatekeeper-crds:v3.17.177bc9bf3d163
golang.org/x/net@v0.23.0
0.38.0

Open the chart page →

2,492
goinceptiondoubanVerified publisher0.3.11 of 2See more

goinception douban 0.3.1

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
hanchuanchuan/goinception:latestb3c0dd26fb50
golang.org/x/net@v0.23.0
0.38.0

Open the chart page →

1,201
k8s-crondoubanVerified publisher0.2.01 of 1See more

k8s-cron douban 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
alpine/k8s:1.28.2fc059f056ad0
golang.org/x/net@v0.9.0
0.38.0

Open the chart page →

3,660
overlorddoubanVerified publisher0.2.21 of 1See more

overlord douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
douz/overlord:latestf2bc7fc068c1
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.38.0

Open the chart page →

3,693

Container images carrying it

2,543 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gogs/gogs:0.12.30195b095d0b2
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
0.38.0
1
gogs/gogs:0.12.1420d53bb7277
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
0.38.0
1
goharbor/chartmuseum-photon:v2.5.36ab3ca28e9e5
golang.org/x/net@v0.0.0-20220121210141-e204ce36a2ba
0.38.0
1
goharbor/harbor-acceld:0.2.13451103a6c8d8
golang.org/x/net@v0.19.0
0.38.0
1
goharbor/harbor-core:v2.9.06412d679fdc3
golang.org/x/net@v0.10.0
0.38.0
1
goharbor/harbor-core:v2.5.386bf3031f4a7
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
0.38.0
1
goharbor/harbor-core:v2.11.1c017dd84ee96
golang.org/x/net@v0.24.0
0.38.0
1
goharbor/harbor-jobservice:v2.9.039435daedd0c
golang.org/x/net@v0.10.0
0.38.0
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
0.38.0
1
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
0.38.0
1
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/net@v0.10.0
0.38.0
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.38.0
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.38.0
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
golang.org/x/net@v0.28.0
0.38.0
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
0.38.0
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/net@v0.12.0
0.38.0
1
golift/unifi-poller:v2.9.5486a63339969
golang.org/x/net@v0.19.0
0.38.0
1
golift/unifi-poller:v2.9.2585a29a06d05
golang.org/x/net@v0.15.0
0.38.0
1
golift/unifi-poller:2.0.0cafac968b540
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.38.0
1
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
0.38.0
1
gomods/athens:v0.11.0efb811df7844
golang.org/x/net@v0.0.0-20200222125558-5a598a2470a0
0.38.0
1
goofball222/pritunl:1.32.3602.807bf26032dfce
golang.org/x/net@v0.7.0
0.38.0
1
gophish/gophish:0.12.18a57cd171999
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.38.0
1
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.38.0
1
gradiant/open5gs-dbctl:0.10.3332031245fce
golang.org/x/net@v0.34.0
0.38.0
1
grafana/agent:v0.44.23364714a2f64
golang.org/x/net@v0.33.0
0.38.0
1
grafana/agent:v0.20.0825c09373d27
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
0.38.0
1
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
0.38.0
1
grafana/agent-operator:v0.34.1045c9125634c
golang.org/x/net@v0.10.0
0.38.0
1
grafana/alloy:v1.5.101a63f4e032c
golang.org/x/net@v0.31.0
0.38.0
1
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/net@v0.29.0
0.38.0
1
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/net@v0.24.0
0.38.0
1
grafana/beyla:1.3.336d07f8d276e
golang.org/x/net@v0.21.0
0.38.0
1
grafana/grafana:6.6.0052147d7e0ec
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.38.0
1
grafana/grafana:10.1.50679e877ba20
golang.org/x/net@v0.12.0
0.38.0
1
grafana/grafana:7.5.609bb407e26ab
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.38.0
1
grafana/grafana:7.3.315b977f5207d
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
0.38.0
1
grafana/grafana:9.4.71a359d92f40e
golang.org/x/net@v0.4.0
0.38.0
1
grafana/grafana:10.1.11b9ca4bbc4a2
golang.org/x/net@v0.12.0
0.38.0
1
grafana/grafana:9.5.239c849cebccc
golang.org/x/net@v0.8.0
0.38.0
1
grafana/grafana:11.2.2-security-01464eac539793
golang.org/x/net@v0.28.0
0.38.0
1
grafana/grafana:11.5.15781759b3d27
golang.org/x/net@v0.34.0
0.38.0
1
grafana/grafana:11.6.062d2b9d20a19
golang.org/x/net@v0.36.0
0.38.0
1
grafana/grafana:8.0.3696823fbc561
golang.org/x/net@v0.0.0-20210521195947-fe42d452be8f
0.38.0
1
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/net@v0.19.0
0.38.0
1
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
0.38.0
1
grafana/grafana:7.2.1733842cca5bd
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
0.38.0
1
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/net@v0.4.0
0.38.0
1
grafana/grafana:10.3.38640e5038e83
golang.org/x/net@v0.19.0
0.38.0
1
grafana/grafana:11.5.28b37a2f028f1
golang.org/x/net@v0.34.0
0.38.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.