StackRadar

CVE-2025-22873

Unscored

Advisory

Published 4 Feb 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
—
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,928
of 17,844 indexed, latest versions
Container images
3,471
deployed by those charts
Fix available
1 of 1
affected package

Improper access to parent directory of root in os

Carried by container images the latest versions of 2,928 of 17,844 indexed charts deploy, on 3,471 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+154 more1.23.93,471
OSV records
GO-2026-4403
Also known as
BIT-golang-2025-22873

Charts affected

2,928 by stars
ChartLatestAffected imagesRadar Score
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
stdlib@go1.19.3
1.23.9

Open the chart page →

5,028
erigoninfradao0.0.51 of 2See more

erigon infradao 0.0.5

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
testinprod/op-erigon:latest0a125bd77a2d
stdlib@go1.22.12
1.23.9

Open the chart page →

3,032
l2gethinfradao0.0.11 of 1See more

l2geth infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ethereumoptimism/l2geth:0.5.315577036dc36d
stdlib@go1.18
1.23.9

Open the chart page →

2,659
registry-container-webhookinnagoVerified publisher2.0.21 of 1See more

registry-container-webhook innago 2.0.2

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/indeedeng/harbor-container-webhook:main45ca15fc294f
stdlib@go1.24.1
1.23.9

Open the chart page →

608
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
stdlib@go1.15.7
1.23.9

Open the chart page →

10,883
lakefsinseefrlab0.0.61 of 2See more

lakefs inseefrlab 0.0.6

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
treeverse/lakefs:0.69.0478f37a6cffc
stdlib@go1.17.8
1.23.9

Open the chart page →

2,668
instemmingserviceinstemmingservice1.0.01 of 3See more

instemmingservice instemmingservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
stdlib@go1.13.10
1.23.9

Open the chart page →

7,555
consulintelVerified publisher0.8.12 of 2See more

consul intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
stdlib@go1.19.2
1.23.9
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
stdlib@go1.19.2
1.23.9

Open the chart page →

5,436
evi-consulintelVerified publisher3.0.32 of 2See more

evi-consul intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
stdlib@go1.19.2
1.23.9
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
stdlib@go1.19.2
1.23.9

Open the chart page →

5,436
evi-miniointelVerified publisher3.0.32 of 2See more

evi-minio intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
stdlib@go1.19.4
1.23.9
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
stdlib@go1.19.4
1.23.9

Open the chart page →

7,713
evi-vaultintelVerified publisher3.0.32 of 2See more

evi-vault intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
stdlib@go1.19.2
1.23.9
hashicorp/vault-k8s:1.1.0844337076b72
stdlib@go1.19.3
1.23.9

Open the chart page →

4,484
intel-gaudi-resource-driverintelVerified publisher0.3.01 of 1See more

intel-gaudi-resource-driver intel 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
intel/intel-gaudi-resource-driver:v0.3.0ac758c14c2de
stdlib@go1.23.4
1.23.9

Open the chart page →

575
intel-qat-resource-driverintelVerified publisher0.1.01 of 1See more

intel-qat-resource-driver intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
intel/intel-qat-resource-driver:v0.1.0ac7616986a2b
stdlib@go1.22.4
1.23.9

Open the chart page →

618
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization:3.03426deb77337
stdlib@go1.17.11
1.23.9

Open the chart page →

82,237
tcs-issuerintelVerified publisher0.5.01 of 2See more

tcs-issuer intel 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
intel/trusted-certificate-issuer:0.5.0591a9db4a427
stdlib@go1.19.3
1.23.9

Open the chart page →

6,179
vaultintelVerified publisher0.8.12 of 2See more

vault intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
stdlib@go1.19.2
1.23.9
hashicorp/vault-k8s:1.1.0844337076b72
stdlib@go1.19.3
1.23.9

Open the chart page →

4,484
gravity-initinvisiblVerified publisher1.0.91 of 1See more

gravity-init invisibl 1.0.9

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
invisibl/gravity-init:v1.0.91a970f84178b
stdlib@go1.17.12
1.23.9

Open the chart page →

2,011
identity-managerinvisiblVerified publisher1.0.01 of 1See more

identity-manager invisibl 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
invisibl/identity-manager:1.0.01029f4fe20eb
stdlib@go1.17.11
1.23.9

Open the chart page →

2,159
identity-manager-demoinvisiblVerified publisher0.1.11 of 1See more

identity-manager-demo invisibl 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
invisibl/identity-manager-demo:v1.0.0cf5400cb935a
stdlib@go1.19.2
1.23.9

Open the chart page →

1,007
karpenteriometeVerified publisher0.19.31 of 1See more

karpenter iomete 0.19.3

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:v0.19.3f0e5ab60b2df
stdlib@go1.19.3
1.23.9

Open the chart page →

1,557
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
stdlib@go1.20.4
1.23.9

Open the chart page →

5,724
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
stdlib@go1.20.4
1.23.9

Open the chart page →

5,724
istio-ratelimit-operatoristio-ratelimit-operator2.16.11 of 1See more

istio-ratelimit-operator istio-ratelimit-operator 2.16.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
zufardhiyaulhaq/istio-ratelimit-operator:v2.15.0692cfc9d6614
stdlib@go1.19.13
1.23.9

Open the chart page →

749
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
stdlib@go1.24.2
1.23.9

Open the chart page →

3,970
traefikitscontainedVerified publisher9.18.41 of 1See more

traefik itscontained 9.18.4

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
library/traefik:2.4.8eda951fd29a8
stdlib@go1.16.2
1.23.9

Open the chart page →

3,342
hetzner-dyndnsitsmethemojoVerified publisher1.4.01 of 1See more

hetzner-dyndns itsmethemojo 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
hashicorp/terraform:1.9.7b77efab1a448
stdlib@go1.22.7
1.23.9

Open the chart page →

1,882
adguard-homejacobcolvinVerified publisher0.4.01 of 2See more

adguard-home jacobcolvin 0.4.0

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.3843ec119419a9
stdlib@go1.20.8
1.23.9

Open the chart page →

1,602
inlets-clientjacobcolvinVerified publisher0.1.21 of 1See more

inlets-client jacobcolvin 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
stdlib@go1.13.15
1.23.9

Open the chart page →

1,757
inlets-serverjacobcolvinVerified publisher0.1.11 of 1See more

inlets-server jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
stdlib@go1.13.15
1.23.9

Open the chart page →

1,757
opencloudjacobcolvinVerified publisher0.2.31 of 13See more

opencloud jacobcolvin 0.2.3

1 of the 13 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
opencloudeu/opencloud-rolling:2.1.0f9634bb04905
stdlib@go1.24.2
1.23.9

Open the chart page →

46,049
osrs-ge-exporterjacobcolvinVerified publisher0.4.01 of 1See more

osrs-ge-exporter jacobcolvin 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
macropower/osrs_ge_exporter:v0.3c77ab5ea955c
stdlib@go1.21.0
1.23.9

Open the chart page →

609
rclonejacobcolvinVerified publisher1.0.11 of 1See more

rclone jacobcolvin 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
rclone/rclone:1.63.008e1af3c8814
stdlib@go1.20.5
1.23.9

Open the chart page →

2,129
twitch-predictions-recorderjacobcolvinVerified publisher0.1.01 of 1See more

twitch-predictions-recorder jacobcolvin 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
stdlib@go1.19.2
1.23.9

Open the chart page →

3,160
wakatime-exporterjacobcolvinVerified publisher0.1.11 of 1See more

wakatime-exporter jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
macropower/wakatime-exporter:0.1.0dbb05debb785
stdlib@go1.14.6
1.23.9

Open the chart page →

1,315
wireguard-operatorjacobcolvinVerified publisher0.2.01 of 2See more

wireguard-operator jacobcolvin 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
ghcr.io/jodevsa/wireguard-operator/manager:v2.0.2839412bdd403b
stdlib@go1.22.2
1.23.9

Open the chart page →

836
koptimizejaconiVerified publisher0.5.42 of 2See more

koptimize jaconi 0.5.4

2 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
alpine/k8s:1.27.321b24e6bf801
stdlib@go1.20.4
1.23.9
ghcr.io/jaconi-io/koptimize:1.2.5aca1bbd609b6
stdlib@go1.20.7
1.23.9

Open the chart page →

5,743
mini-infrajaeki0.1.01 of 4See more

mini-infra jaeki 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.13.101b33357b3595
stdlib@go1.19.5
1.23.9

Open the chart page →

1,749
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
stdlib@go1.19.8
1.23.9

Open the chart page →

11,359
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
stdlib@go1.20.12
1.23.9

Open the chart page →

3,667
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
stdlib@go1.24.0
1.23.9

Open the chart page →

6,276
janus-shieldjanus-shield1.0.01 of 2See more

janus-shield janus-shield 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
quay.io/cilium/tetragon:v1.1.096fac2482898
stdlib@go1.22.2
1.23.9

Open the chart page →

2,520
javascriptweeklyjavascriptweekly2.1.01 of 1See more

javascriptweekly javascriptweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
zufardhiyaulhaq/javascriptweekly:v2.1.086424bd0b2a4
stdlib@go1.17.13
1.23.9

Open the chart page →

1,241
sql-exporterjdstoneVerified publisher0.2.11 of 1See more

sql-exporter jdstone 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
burningalchemist/sql_exporter:0.16.0b8e4757c7def
stdlib@go1.23.2
1.23.9

Open the chart page →

891
jx-app-athensjenkins-x0.0.181 of 1See more

jx-app-athens jenkins-x 0.0.18

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
gomods/athens:v0.8.1d714c7ff0231
stdlib@go1.13.4
1.23.9

Open the chart page →

4,242
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
stdlib@go1.21.11
1.23.9

Open the chart page →

4,225
jx-app-flaggerjenkins-x0.0.52 of 2See more

jx-app-flagger jenkins-x 0.0.5

2 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
grafana/grafana:6.5.1befcd84da2c1
stdlib@go1.13.1
1.23.9
weaveworks/flagger:1.0.0-rc.5174307de1b36
stdlib@go1.14.2
1.23.9

Open the chart page →

6,034
knative-servingjenkins-x0.19.124 of 4See more

knative-serving jenkins-x 0.19.12

4 of the 4 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned1e3db4f2eeed
stdlib@go1.14.10
1.23.9
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinneddb6ceff2aab4
stdlib@go1.14.10
1.23.9
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedb2cd45b8a8a4
stdlib@go1.14.10
1.23.9
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedd27b4495ccc3
stdlib@go1.14.10
1.23.9

Open the chart page →

9,719
ingress-nginxjfrog4.5.22 of 2See more

ingress-nginx jfrog 4.5.2

2 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
stdlib@go1.19.4
1.23.9
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.23.9

Open the chart page →

3,808
vaultjfrog0.25.02 of 2See more

vault jfrog 0.25.0

2 of the 2 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
hashicorp/vault:1.14.0b2177a8bfe85
stdlib@go1.20.5
1.23.9
hashicorp/vault-k8s:1.2.14500e988b7ce
stdlib@go1.20.3
1.23.9

Open the chart page →

3,995
alpine-torjfwenischVerified publisher1.1.01 of 1See more

alpine-tor jfwenisch 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-22873.

Container imageDigestPackageFixed in
jfwenisch/alpine-tor:latest9e6c229f953c
stdlib@go1.14.6
1.23.9

Open the chart page →

4,460

Container images carrying it

3,471 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.23.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
stdlib@go1.18
1.23.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.23.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.23.9
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
stdlib@go1.22.5
1.23.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.23.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.23.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.2.15f4bb469fec5
stdlib@go1.23.6
1.23.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.23.9
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.23.9
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.23.9
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.23.9
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.23.9
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
stdlib@go1.23.4
1.23.9
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
stdlib@go1.23.6
1.23.9
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.23.9
1
registry.k8s.io/sig-storage/snapshot-controller:v8.2.1472fa35a89da
stdlib@go1.23.6
1.23.9
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.23.9
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.23.9
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.23.9
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.23.9
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.