StackRadar

CVE-2025-22872

Medium

Advisory

Published 16 Apr 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,032
of 17,787 indexed, latest versions
Container images
2,510
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/net vulnerable to Cross-site Scripting

Carried by container images the latest versions of 2,032 of 17,787 indexed charts deploy, on 2,510 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+202 more0.38.02,510
OSV records
GHSA-vvgc-356p-c3xw
Also known as
GO-2025-3595

Charts affected

2,032 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.11.11da5c38c6a78
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.38.0

Open the chart page →

6,168
zigbee2mqttzigbee2mqtt2.14.11 of 2See more

zigbee2mqtt zigbee2mqtt 2.14.1

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
mikefarah/yq:4.45.12c100efaca06
golang.org/x/net@v0.33.0
0.38.0

Open the chart page →

1,031
aad-pod-identityaad-pod-identity4.1.182 of 2See more

aad-pod-identity aad-pod-identity 4.1.18

2 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/azure/aad-pod-identity/mic:v1.8.173004b93fcb74
golang.org/x/net@v0.7.0
0.38.0
mcr.microsoft.com/oss/azure/aad-pod-identity/nmi:v1.8.1777788bf38938
golang.org/x/net@v0.7.0
0.38.0

Open the chart page →

2,858
baserowbaserow-chartVerified publisher1.0.562 of 6See more

baserow baserow-chart 1.0.56

2 of the 6 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
golang.org/x/net@v0.26.0
0.38.0
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

17,263
mysql-operatorbitpokeVerified publisher0.6.32 of 2See more

mysql-operator bitpoke 0.6.3

2 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
0.38.0
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
0.38.0

Open the chart page →

3,354
cadvisorcadvisorVerified publisher0.1.151 of 1See more

cadvisor cadvisor 0.1.15

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
golang.org/x/net@v0.8.0
0.38.0

Open the chart page →

1,698
celestia-appcelestia-labsVerified publisher0.5.01 of 3See more

celestia-app celestia-labs 0.5.0

1 of the 3 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-app:v3.7.0-arabica23a9ec9b1879
golang.org/x/net@v0.34.0
0.38.0

Open the chart page →

1,066
cert-manager-webhook-hetznercert-manager-webhook-hetznerVerified publisher0.2.11 of 1See more

cert-manager-webhook-hetzner cert-manager-webhook-hetzner 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.38.0

Open the chart page →

3,080
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
0.38.0
library/traefik:2.5.47d0228d19042
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.38.0

Open the chart page →

52,919
immudbcodenotaryVerified publisher1.9.71 of 1See more

immudb codenotary 1.9.7

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
codenotary/immudb:1.9.77c85d7cc4f22
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

1,247
csi-wekafsplugincsi-wekafsOfficialVerified publisher0.6.2-01 of 6See more

csi-wekafsplugin csi-wekafs 0.6.2-0

1 of the 6 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
0.38.0

Open the chart page →

2,822
daskhubdask2024.1.12 of 9See more

daskhub dask 2024.1.1

2 of the 9 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
library/traefik:2.10.61957e3314f43
golang.org/x/net@v0.17.0
0.38.0
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

14,094
seafiledatamateVerified publisher0.6.04 of 6See more

seafile datamate 0.6.0

4 of the 6 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.1-debian-11-r29cfd2df1294d
golang.org/x/net@v0.21.0
0.38.0
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
golang.org/x/net@v0.26.0
0.38.0
bitnamilegacy/os-shell:11-debian-11-r968643af4facff
golang.org/x/net@v0.19.0
0.38.0
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.38.0

Open the chart page →

27,267
drone-runner-dockerdroneVerified publisher0.7.02 of 3See more

drone-runner-docker drone 0.7.0

2 of the 3 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
drone/drone-runner-docker:1.8.1137e79c5e23c
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.38.0
library/docker:20-dindaf96c680a7e1
golang.org/x/net@v0.4.0
0.38.0

Open the chart page →

5,674
k8s-image-swapperestahnVerified publisher1.11.01 of 2See more

k8s-image-swapper estahn 1.11.0

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
golang.org/x/net@v0.19.0
0.38.0

Open the chart page →

1,981
loadtesterflagger0.39.01 of 1See more

loadtester flagger 0.39.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.28.0
0.38.0

Open the chart page →

1,760
flyteflyte1.16.81 of 11See more

flyte flyte 1.16.8

1 of the 11 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.38.0

Open the chart page →

3,281
lndfold0.3.153 of 4See more

lnd fold 0.3.15

3 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.16.4-beta-c287129953689
golang.org/x/net@v0.8.0
0.38.0
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
0.38.0
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
0.38.0

Open the chart page →

8,835
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.38.0

Open the chart page →

1,738
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.32.08ccae74fc039
golang.org/x/net@v0.30.0
0.38.0

Open the chart page →

13,953
hertzbeathertzbeatOfficialVerified publisher1.8.11 of 4See more

hertzbeat hertzbeat 1.8.1

1 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
victoriametrics/victoria-metrics:v1.95.1f52723a08a44
golang.org/x/net@v0.18.0
0.38.0

Open the chart page →

14,000
permission-managerkfirfer1.0.71 of 1See more

permission-manager kfirfer 1.0.7

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.38.0

Open the chart page →

2,266
kubeflowkubeflow1.6.225 of 45See more

kubeflow kubeflow 1.6.2

25 of the 45 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.38.0
istio/proxyv2:1.14.1df69c1a7af7c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.38.0
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/net@v0.0.0-20211205041911-012df41ee64c
0.38.0
kubeflow/training-operator:v1-e1434f6ff847e2b6af0
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
0.38.0
kubeflownotebookswg/kfam:v1.6.1f226fb44db57
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.38.0
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.38.0
kubeflownotebookswg/poddefaults-webhook:v1.6.17d42600e1524
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.38.0
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.38.0
kubeflownotebookswg/tensorboard-controller:v1.6.182ffdd2da285
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.38.0
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.38.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.38.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.38.0
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.38.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.38.0
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.38.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.38.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.38.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.38.0
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.38.0
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.38.0
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.38.0
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.38.0
gcr.io/ml-pipeline/viewer-crd-controller:2.0.0-alpha.534403f9f94be
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.38.0
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.38.0
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.38.0

Open the chart page →

96,941
openelbkubesphere-stable0.5.02 of 2See more

openelb kubesphere-stable 0.5.0

2 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
0.38.0
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.38.0

Open the chart page →

4,329
operatorkube-starrocksVerified publisher1.11.71 of 1See more

operator kube-starrocks 1.11.7

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
starrocks/operator:v1.11.78c20435a7579
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

556
vclustermainVerified publisher0.17.06 of 10See more

vcluster main 0.17.0

6 of the 10 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
golang.org/x/net@v0.8.0
0.38.0
quay.io/kubermatic/operating-system-manager:v1.3.010081473da43
golang.org/x/net@v0.9.0
0.38.0
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/net@v0.7.0
0.38.0
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.38.0
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.38.0
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.38.0

Open the chart page →

11,552
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
headscale/headscale:0.25.1a7a8ae9616bb
golang.org/x/net@v0.34.0
0.38.0

Open the chart page →

7,949
netris-operatornetrisai3.0.21 of 2See more

netris-operator netrisai 3.0.2

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
netrisai/netris-operator:v4.0.244f60aa0d898
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.38.0

Open the chart page →

1,588
node-local-dnsnode-local-dns2.4.01 of 1See more

node-local-dns node-local-dns 2.4.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

2,593
goldpingerokgoloveVerified publisher6.2.01 of 1See more

goldpinger okgolove 6.2.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
bloomberg/goldpinger:3.10.08520120f5598
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

715
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
gradiant/open5gs-dbctl:0.10.3332031245fce
golang.org/x/net@v0.34.0
0.38.0

Open the chart page →

9,261
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

8,722
capsuleprojectcapsuleOfficialVerified publisher0.14.51 of 2See more

capsule projectcapsule 0.14.5

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
0.38.0

Open the chart page →

1,229
prometheus-consul-exporterprometheus-communityVerified publisher1.1.11 of 1See more

prometheus-consul-exporter prometheus-community 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
prom/consul-exporter:v0.13.04e4cfd809e96
golang.org/x/net@v0.29.0
0.38.0

Open the chart page →

782
prometheus-json-exporterprometheus-communityOfficialVerified publisher0.20.11 of 1See more

prometheus-json-exporter prometheus-community 0.20.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/json-exporter:v0.7.03a777171d39a
golang.org/x/net@v0.33.0
0.38.0

Open the chart page →

725
prometheus-smartctl-exporterprometheus-communityVerified publisher0.17.11 of 1See more

prometheus-smartctl-exporter prometheus-community 0.17.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/smartctl-exporter:v0.14.0cfe22c36d7d2
golang.org/x/net@v0.35.0
0.38.0

Open the chart page →

1,064
prometheus-statsd-exporterprometheus-communityVerified publisher1.0.01 of 1See more

prometheus-statsd-exporter prometheus-community 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/net@v0.29.0
0.38.0

Open the chart page →

782
rke2-multusrke2-charts3.7.1-build20210416011 of 2See more

rke2-multus rke2-charts 3.7.1-build2021041601

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.38.0

Open the chart page →

4,519
popeyeself-hosters-by-nightVerified publisher0.6.11 of 1See more

popeye self-hosters-by-night 0.6.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
derailed/popeye:v0.22.18e68e22c7663
golang.org/x/net@v0.34.0
0.38.0

Open the chart page →

1,196
uffizzi-appuffizzi-app1.3.08 of 14See more

uffizzi-app uffizzi-app 1.3.0

8 of the 14 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
golang.org/x/net@v0.12.0
0.38.0
uffizzi/uffizzi-cluster-operator:v1.4.514e528bbd926
golang.org/x/net@v0.8.0
0.38.0
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/net@v0.17.0
0.38.0
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/net@v0.17.0
0.38.0
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
golang.org/x/net@v0.17.0
0.38.0
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/net@v0.17.0
0.38.0
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/net@v0.17.0
0.38.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
0.38.0

Open the chart page →

19,337
dexwiremindVerified publisher2.15.71 of 2See more

dex wiremind 2.15.7

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.38.0

Open the chart page →

13,562
pod-gatewayangelnu7.1.11 of 2See more

pod-gateway angelnu 7.1.1

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/angelnu/gateway-admision-controller:v3.12.06f6ab596afd5
golang.org/x/net@v0.30.0
0.38.0

Open the chart page →

1,133
aperture-controlleraperture2.34.02 of 5See more

aperture-controller aperture 2.34.0

2 of the 5 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
fluxninja/aperture-operator:2.34.0356d7aa86632
golang.org/x/net@v0.19.0
0.38.0
quay.io/prometheus/prometheus:v2.33.591100b06e86d
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
0.38.0

Open the chart page →

4,663
k8upappuio2.0.51 of 1See more

k8up appuio 2.0.5

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.38.0

Open the chart page →

3,300
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.38.0

Open the chart page →

9,052
prometheusaveshaVerified publisher19.3.03 of 4See more

prometheus avesha 19.3.0

3 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
0.38.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
0.38.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
0.38.0

Open the chart page →

5,484
aws-calicoaws0.3.111 of 1See more

aws-calico aws 0.3.11

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.20.1379efe0c2541
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.38.0

Open the chart page →

2,250
yataibentomlVerified publisher1.1.131 of 1See more

yatai bentoml 1.1.13

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
golang.org/x/net@v0.7.0
0.38.0

Open the chart page →

1,915
yatai-deploymentbentomlVerified publisher1.1.211 of 2See more

yatai-deployment bentoml 1.1.21

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

1,160
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

1,884

Container images carrying it

2,510 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
goharbor/harbor-core:v2.11.1c017dd84ee96
golang.org/x/net@v0.24.0
0.38.0
1
goharbor/harbor-jobservice:v2.9.039435daedd0c
golang.org/x/net@v0.10.0
0.38.0
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
0.38.0
1
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
golang.org/x/net@v0.0.0-20211013171255-e13a2654a71e
0.38.0
1
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/net@v0.10.0
0.38.0
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.38.0
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.38.0
1
goharbor/trivy-adapter-photon:v2.14.35c6f7162804c
golang.org/x/net@v0.28.0
0.38.0
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
0.38.0
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/net@v0.12.0
0.38.0
1
golift/unifi-poller:v2.9.5486a63339969
golang.org/x/net@v0.19.0
0.38.0
1
golift/unifi-poller:v2.9.2585a29a06d05
golang.org/x/net@v0.15.0
0.38.0
1
golift/unifi-poller:2.0.0cafac968b540
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.38.0
1
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
0.38.0
1
gomods/athens:v0.11.0efb811df7844
golang.org/x/net@v0.0.0-20200222125558-5a598a2470a0
0.38.0
1
goofball222/pritunl:1.32.3602.807bf26032dfce
golang.org/x/net@v0.7.0
0.38.0
1
gophish/gophish:0.12.18a57cd171999
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.38.0
1
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.38.0
1
gradiant/open5gs-dbctl:0.10.3332031245fce
golang.org/x/net@v0.34.0
0.38.0
1
grafana/agent:v0.44.23364714a2f64
golang.org/x/net@v0.33.0
0.38.0
1
grafana/agent:v0.20.0825c09373d27
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
0.38.0
1
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
0.38.0
1
grafana/agent-operator:v0.34.1045c9125634c
golang.org/x/net@v0.10.0
0.38.0
1
grafana/alloy:v1.5.101a63f4e032c
golang.org/x/net@v0.31.0
0.38.0
1
grafana/alloy:v1.4.306bdcbb51fc2
golang.org/x/net@v0.29.0
0.38.0
1
grafana/alloy:v1.1.1c3dac4e26471
golang.org/x/net@v0.24.0
0.38.0
1
grafana/beyla:1.3.336d07f8d276e
golang.org/x/net@v0.21.0
0.38.0
1
grafana/grafana:6.6.0052147d7e0ec
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.38.0
1
grafana/grafana:10.1.50679e877ba20
golang.org/x/net@v0.12.0
0.38.0
1
grafana/grafana:7.5.609bb407e26ab
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.38.0
1
grafana/grafana:7.3.315b977f5207d
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
0.38.0
1
grafana/grafana:9.4.71a359d92f40e
golang.org/x/net@v0.4.0
0.38.0
1
grafana/grafana:10.1.11b9ca4bbc4a2
golang.org/x/net@v0.12.0
0.38.0
1
grafana/grafana:9.5.239c849cebccc
golang.org/x/net@v0.8.0
0.38.0
1
grafana/grafana:11.2.2-security-01464eac539793
golang.org/x/net@v0.28.0
0.38.0
1
grafana/grafana:11.5.15781759b3d27
golang.org/x/net@v0.34.0
0.38.0
1
grafana/grafana:11.6.062d2b9d20a19
golang.org/x/net@v0.36.0
0.38.0
1
grafana/grafana:8.0.3696823fbc561
golang.org/x/net@v0.0.0-20210521195947-fe42d452be8f
0.38.0
1
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/net@v0.19.0
0.38.0
1
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
0.38.0
1
grafana/grafana:7.2.1733842cca5bd
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
0.38.0
1
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/net@v0.4.0
0.38.0
1
grafana/grafana:10.3.38640e5038e83
golang.org/x/net@v0.19.0
0.38.0
1
grafana/grafana:11.5.28b37a2f028f1
golang.org/x/net@v0.34.0
0.38.0
1
grafana/grafana:9.1.19746858c20e6
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
0.38.0
1
grafana/grafana:9.0.1a738d0744784
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.38.0
1
grafana/grafana:11.1.3b23b588cf7cb
golang.org/x/net@v0.26.0
0.38.0
1
grafana/grafana:6.5.1befcd84da2c1
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.38.0
1
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
0.38.0
1
grafana/grafana:8.3.4cf81d2c753c8
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
0.38.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.