StackRadar

CVE-2025-22873

Unscored

Advisory

Published 4 Feb 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.002
16th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,813
of 17,813 indexed, latest versions
Container images
3,377
deployed by those charts
Fix available
1 of 1
affected package

Improper access to parent directory of root in os

Carried by container images the latest versions of 2,813 of 17,813 indexed charts deploy, on 3,377 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+153 more1.23.93,377
OSV records
GO-2026-4403
Also known as
BIT-golang-2025-22873

Charts affected

2,813 by stars
ChartLatestAffected imagesRadar Score
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
stdlib@go1.20.12
1.23.9

Open the chart page →

4,576
ms-hello-webms-hello-test0.1.01 of 1See more

ms-hello-web ms-hello-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
irakli/ms-web-hello:latest966a4bfefe27
stdlib@go1.19.2
1.23.9

Open the chart page →

755
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.23.9

Open the chart page →

6,674
vikunjamt1905027.1.21 of 3See more

vikunja mt190502 7.1.2

1 of the 3 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
stdlib@go1.23.4
1.23.9

Open the chart page →

3,042
multusmultusVerified publisher0.2.02 of 2See more

multus multus 0.2.0

2 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.409fdfb7ce090
stdlib@go1.23.4
1.23.9
ghcr.io/k8snetworkplumbingwg/multus-dynamic-networks-controller:v0.3.72a2bb32c0ea8
stdlib@go1.22.12
1.23.9

Open the chart page →

1,866
devops-demomungari-development-charts1.0.41 of 4See more

devops-demo mungari-development-charts 1.0.4

1 of the 4 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
stdlib@go1.18.4
1.23.9

Open the chart page →

9,041
approuvezmvisonneau0.1.11 of 1See more

approuvez mvisonneau 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
stdlib@go1.15.6
1.23.9

Open the chart page →

1,979
unpollermvisonneau0.1.01 of 1See more

unpoller mvisonneau 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
golift/unifi-poller:v2.9.2585a29a06d05
stdlib@go1.21.0
1.23.9

Open the chart page →

1,190
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
stdlib@go1.18
1.23.9

Open the chart page →

102,088
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
stdlib@go1.18
1.23.9

Open the chart page →

102,088
authmyaVerified publisher22.4.31 of 1See more

auth mya 22.4.3

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
stdlib@go1.13.7
1.23.9

Open the chart page →

2,382
clickhousemyaVerified publisher0.2403.11 of 1See more

clickhouse mya 0.2403.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.2ed9640bfff07
stdlib@go1.19.10
1.23.9

Open the chart page →

3,620
cognativemyaVerified publisher0.2403.33 of 3See more

cognative mya 0.2403.3

3 of the 3 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.2ed9640bfff07
stdlib@go1.19.10
1.23.9
grafana/grafana:10.4.0f9811e4e687f
stdlib@go1.21.8
1.23.9
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
stdlib@go1.21.7
1.23.9

Open the chart page →

7,408
giteamyaVerified publisher23.12.51 of 1See more

gitea mya 23.12.5

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
gitea/gitea:1.21.6ac73e0da341f
stdlib@go1.21.7
1.23.9

Open the chart page →

3,438
redismyaVerified publisher22.4.101 of 2See more

redis mya 22.4.10

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
stdlib@go1.17.7
1.23.9

Open the chart page →

1,051
redis-queuemyaVerified publisher22.4.61 of 2See more

redis-queue mya 22.4.6

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
stdlib@go1.17.7
1.23.9

Open the chart page →

1,051
redis-raftmyaVerified publisher22.5.41 of 2See more

redis-raft mya 22.5.4

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
stdlib@go1.17.7
1.23.9

Open the chart page →

1,051
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
stdlib@go1.17.5
1.23.9

Open the chart page →

3,369
Practica_4_helmmy-heml-appVerified publisher0.1.03 of 7See more

Practica_4_helm my-heml-app 0.1.0

3 of the 7 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
stdlib@go1.18.10
1.23.9
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.23.9
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.23.9

Open the chart page →

27,941
influxdbmy-personal-influxdb20.1.01 of 1See more

influxdb my-personal-influxdb2 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
stdlib@go1.18.2
1.23.9

Open the chart page →

3,923
phonebook-chartmy-phonebook-chart0.1.01 of 3See more

phonebook-chart my-phonebook-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.23.9

Open the chart page →

3,032
mychartmysqlweb0.1.01 of 1See more

mychart mysqlweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
qichenxu4pd/mysqlweb:1.2d758d41d9c6b
stdlib@go1.18.2
1.23.9

Open the chart page →

1,157
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
library/rabbitmq:3-managemente582c0bc7766
stdlib@go1.22.2
1.23.9

Open the chart page →

18,197
fargate-sidecar-injectormziyaboVerified publisher0.1.51 of 1See more

fargate-sidecar-injector mziyabo 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
mziyabo/fargate-eks-sidecar-injector:latest3067dce17983
stdlib@go1.19.13
1.23.9

Open the chart page →

1,394
victoria-metrics-singlenaps0.0.61 of 1See more

victoria-metrics-single naps 0.0.6

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
victoriametrics/victoria-metrics:v1.34.7b50d5c0153f9
stdlib@go1.14.1
1.23.9

Open the chart page →

1,316
traefik-forward-auth-openidnas-helm-chartsVerified publisher1.0.11 of 1See more

traefik-forward-auth-openid nas-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:latestb364aa6a4117
stdlib@go1.13.15
1.23.9

Open the chart page →

2,198
nats-kafkanatsVerified publisher0.15.41 of 1See more

nats-kafka nats 0.15.4

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
natsio/nats-kafka:1.4.2bb241956b0dc
stdlib@go1.20
1.23.9

Open the chart page →

1,732
nats-operatornatsVerified publisher0.8.31 of 1See more

nats-operator nats 0.8.3

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
natsio/nats-operator:0.8.31261dae38389
stdlib@go1.16.10
1.23.9

Open the chart page →

2,354
account-servernatz-operatorVerified publisher0.9.51 of 1See more

account-server natz-operator 0.9.5

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/zeiss/natz-operator/account-server:0.9.5b380b5f17c3f
stdlib@go1.23.3
1.23.9

Open the chart page →

746
navidromenavidrome0.2.51 of 1See more

navidrome navidrome 0.2.5

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
deluan/navidrome:0.41.1fc4d8b6ad9f9
stdlib@go1.16.2
1.23.9

Open the chart page →

3,318
incorencsaVerified publisher1.38.02 of 29See more

incore ncsa 1.38.0

2 of the 29 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
stdlib@go1.21.10
1.23.9
bitnamilegacy/mongodb:4.4.5e3c9d6b4bc92
stdlib@go1.15.8
1.23.9

Open the chart page →

15,572
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
stdlib@go1.20.5
1.23.9

Open the chart page →

30,707
redisneomanexlabsVerified publisher1.1.01 of 1See more

redis neomanexlabs 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.23.9

Open the chart page →

1,434
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
stdlib@go1.17.9
1.23.9

Open the chart page →

6,995
iamdnetsocVerified publisher0.6.11 of 2See more

iamd netsoc 0.6.1

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
stdlib@go1.16.6
1.23.9

Open the chart page →

2,892
shhdnetsocVerified publisher0.1.71 of 1See more

shhd netsoc 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
stdlib@go1.17
1.23.9

Open the chart page →

3,988
webspacednetsocVerified publisher0.2.82 of 2See more

webspaced netsoc 0.2.8

2 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
stdlib@go1.16.5
1.23.9
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
stdlib@go1.16.8
1.23.9

Open the chart page →

5,195
agent-control-cdnewrelic1.0.03 of 3See more

agent-control-cd newrelic 1.0.0

3 of the 3 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
stdlib@go1.23.6
1.23.9
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
stdlib@go1.23.6
1.23.9
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
stdlib@go1.23.6
1.23.9

Open the chart page →

5,519
nexus-freenexus-freeVerified publisher1.0.31 of 1See more

nexus-free nexus-free 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
quay.io/fossa/postgres:17.2-15af45ac79f38
stdlib@go1.18.2
1.23.9

Open the chart page →

1,123
nginx-examplengrok-ingress-helm0.3.01 of 2See more

nginx-example ngrok-ingress-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
wernight/ngrok:latestd211f29ebcfe
stdlib@go1.21.6
1.23.9

Open the chart page →

3,089
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
stdlib@go1.16.9
1.23.9

Open the chart page →

24,394
doublecommandernicholaswildeVerified publisher1.0.21 of 1See more

doublecommander nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
stdlib@go1.16.9
1.23.9

Open the chart page →

25,572
filezillanicholaswildeVerified publisher1.0.11 of 1See more

filezilla nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/filezilla:version-3.51.0-r15103cdd266ce
stdlib@go1.15.12
1.23.9

Open the chart page →

3,178
golinksnicholaswildeVerified publisher1.0.01 of 1See more

golinks nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/golinks:version-154c5818e67b26324c5
stdlib@go1.16.5
1.23.9

Open the chart page →

1,118
notesnicholaswildeVerified publisher1.0.01 of 1See more

notes nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/notes:version-ee287b9ab9bc16465bc
stdlib@go1.16.5
1.23.9

Open the chart page →

1,482
olivetinnicholaswildeVerified publisher1.0.21 of 1See more

olivetin nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/olivetin:version-2021-07-19e1d5c8a01008
stdlib@go1.16.5
1.23.9

Open the chart page →

1,670
podgrabnicholaswildeVerified publisher0.1.01 of 1See more

podgrab nicholaswilde 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
stdlib@go1.15.2
1.23.9

Open the chart page →

2,402
remminanicholaswildeVerified publisher0.1.41 of 1See more

remmina nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/remmina:version-1.2.0-rcgit.29dfsg-1ubuntu105955792e00f
stdlib@go1.17.11
1.23.9

Open the chart page →

22,445
sqlitebrowsernicholaswildeVerified publisher1.0.11 of 1See more

sqlitebrowser nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/sqlitebrowser:version-3.12.2-02876202105241947ubuntu18.04.1426e79828c4b
stdlib@go1.16.12
1.23.9

Open the chart page →

23,648
staticnicholaswildeVerified publisher1.0.01 of 1See more

static nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/nicholaswilde/static:version-ee8a20cd1d47c730bc4
stdlib@go1.16.5
1.23.9

Open the chart page →

1,155

Container images carrying it

3,377 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
stdlib@go1.19
1.23.9
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.23.9
1
registry.k8s.io/sig-storage/csi-provisioner:v5.0.27b9cdb5830d0
stdlib@go1.22.5
1.23.9
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
stdlib@go1.19
1.23.9
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
stdlib@go1.18
1.23.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.13.12a0b297cc7c4
stdlib@go1.23.1
1.23.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.23.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
stdlib@go1.18
1.23.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.23.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.23.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
stdlib@go1.22.5
1.23.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.23.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.23.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.23.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.23.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.23.9
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.23.9
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.23.9
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.23.9
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.23.9
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.23.9
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.23.9
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.23.9
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.23.9
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.23.9
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.23.9
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.23.9
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.