StackRadar

CVE-2025-22872

Medium

Advisory

Published 16 Apr 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,048
of 17,803 indexed, latest versions
Container images
2,537
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/net vulnerable to Cross-site Scripting

Carried by container images the latest versions of 2,048 of 17,803 indexed charts deploy, on 2,537 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+203 more0.38.02,537
OSV records
GHSA-vvgc-356p-c3xw
Also known as
GO-2025-3595

Charts affected

2,048 by stars
ChartLatestAffected imagesRadar Score
bootaerokube1.0.12 of 4See more

boot aerokube 1.0.1

2 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/aerokube/boot:1.0.13c269612053f
golang.org/x/net@v0.24.0
0.38.0
quay.io/aerokube/keygen:1.0.1578934444f04
golang.org/x/net@v0.8.0
0.38.0

Open the chart page →

7,935
browser-opsaerokube2.6.71 of 1See more

browser-ops aerokube 2.6.7

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/aerokube/browser-ops:2.6.7807c1bb67086
golang.org/x/net@v0.23.0
0.38.0

Open the chart page →

552
moonaerokube1.1.373 of 3See more

moon aerokube 1.1.37

3 of the 3 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
aerokube/moon:1.9.17da76ca51220d
golang.org/x/net@v0.25.0
0.38.0
aerokube/moon-api:1.9.176b6323e75785
golang.org/x/net@v0.25.0
0.38.0
aerokube/selenoid-ui:1.10.113f3e299509fd
golang.org/x/net@v0.10.0
0.38.0

Open the chart page →

2,472
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.38.0

Open the chart page →

7,218
agentkube-operatoragentkube-operator0.3.01 of 1See more

agentkube-operator agentkube-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
0.38.0

Open the chart page →

1,723
mt-channel-brokerahhhhVerified publisher0.1.03 of 3See more

mt-channel-broker ahhhh 0.1.0

3 of the 3 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/filterdigest-pinnedd675f211a40f
golang.org/x/net@v0.30.0
0.38.0
gcr.io/knative-releases/knative.dev/eventing/cmd/broker/ingressdigest-pinnedec4b544499ba
golang.org/x/net@v0.30.0
0.38.0
gcr.io/knative-releases/knative.dev/eventing/cmd/mtchannel_brokerdigest-pinned395f4ff1bd34
golang.org/x/net@v0.30.0
0.38.0

Open the chart page →

2,628
net-istioahhhhVerified publisher0.1.12 of 2See more

net-istio ahhhh 0.1.1

2 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controllerdigest-pinnede70bc675f977
golang.org/x/net@v0.30.0
0.38.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhookdigest-pinned7d76a6d42d13
golang.org/x/net@v0.30.0
0.38.0

Open the chart page →

1,128
pod-sweeperairbyteVerified publisher1.5.11 of 1See more

pod-sweeper airbyte 1.5.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
airbyte/pod-sweeper:1.5.198d2c39d512e
golang.org/x/net@v0.26.0
0.38.0

Open the chart page →

4,974
airbyteairbyte-v2Verified publisher2.3.02 of 10See more

airbyte airbyte-v2 2.3.0

2 of the 10 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
airbyte/minio:RELEASE.2023-11-20T22-40-07Zfdae972eaf0e
golang.org/x/net@v0.17.0
0.38.0
temporalio/auto-setup:1.27.2b44cbfeb43db
golang.org/x/net@v0.34.0
0.38.0

Open the chart page →

11,785
airports-kafkaairports-kafka0.1.01 of 2See more

airports-kafka airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.38.0

Open the chart page →

4,558
akriakri0.12.551 of 3See more

akri akri 0.12.55

1 of the 3 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.38.0

Open the chart page →

1,545
aktoakto0.2.01 of 7See more

akto akto 0.2.0

1 of the 7 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
0.38.0

Open the chart page →

13,737
akto-hybrid-redactakto1.44.71See more

akto-hybrid-redact akto 1.44.7

1 container image this version deploys carries CVE-2025-22872.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
0.38.0

Open the chart page →

akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
golang.org/x/net@v0.33.0
0.38.0

Open the chart page →

6,600
akto-mini-testing-kafkaakto1.42.11 of 5See more

akto-mini-testing-kafka akto 1.42.1

1 of the 5 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
0.38.0

Open the chart page →

6,406
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
0.38.0

Open the chart page →

11,296
akto-testing-db-layerakto1.42.171 of 2See more

akto-testing-db-layer akto 1.42.17

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
0.38.0

Open the chart page →

4,865
kpubberalekcVerified publisher0.0.41 of 1See more

kpubber alekc 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.38.0

Open the chart page →

2,228
qbittorrentalexmorbo-qbittorrentVerified publisher1.2.11 of 1See more

qbittorrent alexmorbo-qbittorrent 1.2.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/squat/generic-device-plugin:36bfc606bba2064de6ede0ff2764cbb52edff70dba6f0b4cf6c8
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

889
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.38.0

Open the chart page →

2,116
flux-suspension-exporteralpineworks0.1.11 of 1See more

flux-suspension-exporter alpineworks 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
0.38.0

Open the chart page →

564
flux-suspensions-exporteralpineworks0.1.01 of 1See more

flux-suspensions-exporter alpineworks 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/flux-suspension-exporter:v1.0.0341f0a6cd2b6
golang.org/x/net@v0.34.0
0.38.0

Open the chart page →

564
ipalpineworks0.1.21 of 1See more

ip alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/ip:v1.0.04e0d4d51f0bc
golang.org/x/net@v0.34.0
0.38.0

Open the chart page →

541
katalogalpineworks0.1.22 of 5See more

katalog alpineworks 0.1.2

2 of the 5 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-backend:v1.0.77e7a26393cd1
golang.org/x/net@v0.29.0
0.38.0
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
golang.org/x/net@v0.29.0
0.38.0

Open the chart page →

4,542
katalog-agentalpineworks0.1.21 of 1See more

katalog-agent alpineworks 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-agent:v1.0.48f50bd568c2b
golang.org/x/net@v0.29.0
0.38.0

Open the chart page →

582
amorphieamorphie0.1.28 of 18See more

amorphie amorphie 0.1.2

8 of the 18 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
burganbank/vault-initializer:v19259c34e4037
golang.org/x/net@v0.23.0
0.38.0
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
0.38.0
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
0.38.0
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
0.38.0
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
0.38.0
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
0.38.0
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/net@v0.17.0
0.38.0
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

28,342
sliding-sync-proxyananace-chartsVerified publisher0.2.131 of 2See more

sliding-sync-proxy ananace-charts 0.2.13

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

1,599
anchore-admission-controlleranchore-charts0.9.01 of 2See more

anchore-admission-controller anchore-charts 0.9.0

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
golang.org/x/net@v0.20.0
0.38.0

Open the chart page →

7,597
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
0.38.0

Open the chart page →

1,326
music-assistant-serverandibraeuVerified publisher2.1.21 of 1See more

music-assistant-server andibraeu 2.1.2

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

5,855
buildkit-serviceandrcunsVerified publisher1.8.01 of 1See more

buildkit-service andrcuns 1.8.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
moby/buildkit:v0.31.0a095b3d11ce1
golang.org/x/net@v0.35.0
0.38.0

Open the chart page →

1,290
terjangandylibrianVerified publisher0.0.31 of 1See more

terjang andylibrian 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/andylibrian/terjang:latest20a46b199247
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.38.0

Open the chart page →

1,985
dnsmadeeasy-webhookangelnu6.0.71 of 1See more

dnsmadeeasy-webhook angelnu 6.0.7

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/angelnu/dnsmadeeasy-webhook:v1.9.0a5ca158b1f02
golang.org/x/net@v0.36.0
0.38.0

Open the chart page →

810
maddyangelnu5.0.01 of 1See more

maddy angelnu 5.0.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/foxcpp/maddy:0.9.5de42151adff6
golang.org/x/net@v0.34.0
0.38.0

Open the chart page →

774
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.38.0

Open the chart page →

2,495
ddosifyanteonVerified publisher1.7.54 of 13See more

ddosify anteon 1.7.5

4 of the 13 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
0.38.0
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
0.38.0
library/influxdb:2.6.1-alpine44a366dd7724
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
0.38.0
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
0.38.0

Open the chart page →

26,070
antmediaantmediaVerified publisher3.1.02 of 4See more

antmedia antmedia 3.1.0

2 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
0.38.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.38.0

Open the chart page →

4,631
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
golang.org/x/net@v0.1.0
0.38.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.38.0

Open the chart page →

3,323
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.38.0

Open the chart page →

2,731
glauthanza-labsVerified publisher1.0.11 of 1See more

glauth anza-labs 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/glauth/glauth:v2.5.209c782ca5984
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

1,309
apishiftapishiftVerified publisher0.3.01 of 4See more

apishift apishift 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
golang.org/x/net@v0.25.0
0.38.0

Open the chart page →

2,962
app-mobilityappmo0.1.03 of 5See more

app-mobility appmo 0.1.0

3 of the 5 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
0.38.0
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.38.0
velero/velero:v1.8.18d784580931c
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.38.0

Open the chart page →

12,542
auditorappscodeVerified publisher2023.10.11 of 1See more

auditor appscode 2023.10.1

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
0.38.0

Open the chart page →

1,680
capa-vpc-peering-operatorappscodeVerified publisher2023.12.111 of 1See more

capa-vpc-peering-operator appscode 2023.12.11

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

1,433
capi-ops-managerappscodeVerified publisher2024.8.142 of 2See more

capi-ops-manager appscode 2024.8.14

2 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/appscode/capi-ops-manager:v0.0.57465f35b684c
golang.org/x/net@v0.33.0
0.38.0
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.38.0

Open the chart page →

3,430
cluster-proxyappscodeVerified publisher2024.2.251 of 1See more

cluster-proxy appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-proxy:latest27a5c64b7ea8
golang.org/x/net@v0.20.0
0.38.0

Open the chart page →

1,126
cluster-proxy-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-proxy-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-proxy:v0.10.1a7fce69e171c
golang.org/x/net@v0.19.0
0.38.0

Open the chart page →

1,472
docker-machine-operatorappscodeVerified publisher2024.7.91 of 1See more

docker-machine-operator appscode 2024.7.9

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
golang.org/x/net@v0.14.0
0.38.0

Open the chart page →

2,227
falco-ui-serverappscodeVerified publisher2026.1.151 of 2See more

falco-ui-server appscode 2026.1.15

1 of the 2 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
golang.org/x/net@v0.17.0
0.38.0

Open the chart page →

2,887
fluxcd-addon-managerappscodeVerified publisher2024.2.251 of 1See more

fluxcd-addon-manager appscode 2024.2.25

1 of the 1 container images this version deploys carry CVE-2025-22872.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/fluxcd-addon:v0.0.23acba3df8827
golang.org/x/net@v0.23.0
0.38.0

Open the chart page →

1,311

Container images carrying it

2,537 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
golang.org/x/net@v0.27.0
0.38.0
1
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/net@v0.8.0
0.38.0
1
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
golang.org/x/net@v0.4.0
0.38.0
1
registry.k8s.io/sig-storage/csi-attacher:v4.5.19dcd469f02bb
golang.org/x/net@v0.18.0
0.38.0
1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.38.0
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
golang.org/x/net@v0.0.0-20220802222814-0bcc04d9c69b
0.38.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
golang.org/x/net@v0.17.0
0.38.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
golang.org/x/net@v0.4.0
0.38.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.38.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.0cd21e19cd8bb
golang.org/x/net@v0.13.0
0.38.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.38.0
1
registry.k8s.io/sig-storage/csi-provisioner:v5.0.27b9cdb5830d0
golang.org/x/net@v0.25.0
0.38.0
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
golang.org/x/net@v0.4.0
0.38.0
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.38.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
golang.org/x/net@v0.34.0
0.38.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
golang.org/x/net@v0.4.0
0.38.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.38.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
golang.org/x/net@v0.18.0
0.38.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.38.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
golang.org/x/net@v0.28.0
0.38.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.38.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
golang.org/x/net@v0.28.0
0.38.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
golang.org/x/net@v0.33.0
0.38.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.38.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.38.0
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
0.38.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
golang.org/x/net@v0.4.0
0.38.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.12.05baeb4a6d7d5
golang.org/x/net@v0.18.0
0.38.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
golang.org/x/net@v0.13.0
0.38.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/net@v0.37.0
0.38.0
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
golang.org/x/net@v0.37.0
0.38.0
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.38.0
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
golang.org/x/net@v0.33.0
0.38.0
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.38.0
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
golang.org/x/net@v0.4.0
0.38.0
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
golang.org/x/net@v0.17.0
0.38.0
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.38.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.