StackRadar

CVE-2025-30204

High

Advisory

Published 21 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
579
of 17,787 indexed, latest versions
Container images
620
deployed by those charts
Fix available
2 of 3
affected packages

jwt-go allows excessive memory allocation during header parsing

Carried by container images the latest versions of 579 of 17,787 indexed charts deploy, on 620 images.

Affected packageAffected versionsFixed inImages
github.com/golang-jwt/jwt/v4golangv4.0.0, v4.1.0, v4.2.0, v4.3.0+5 more4.5.2452
github.com/golang-jwt/jwt/v5golangv5.0.0, v5.1.0, v5.2.0, v5.2.15.2.2184
github.com/golang-jwt/jwtgolangv3.2.1+incompatible, v3.2.2+incompatibleno fix listed127
OSV records
GHSA-mh63-6h87-95cp
Also known as
GO-2025-3553

Charts affected

579 by stars
ChartLatestAffected imagesRadar Score
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
github.com/golang-jwt/jwt/v4@v4.3.0
4.5.2
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
github.com/golang-jwt/jwt/v4@v4.3.0
4.5.2

Open the chart page →

4,722
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

12,949
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,580
devtron-enterprisedevtron48.0.04 of 28See more

devtron-enterprise devtron 48.0.0

4 of the 28 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
quay.io/devtron/kubectl:latest2ad610626658
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

68,240
devtron-in-clustercddevtron0.10.21 of 2See more

devtron-in-clustercd devtron 0.10.2

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

5,039
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

12,949
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,580
devtron-enterprisedevtron-labs48.0.04 of 28See more

devtron-enterprise devtron-labs 48.0.0

4 of the 28 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
quay.io/devtron/kubectl:latest2ad610626658
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

68,240
devtron-in-clustercddevtron-labs0.10.21 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

5,039
devtron-operatordevtron-labs0.23.33 of 11See more

devtron-operator devtron-labs 0.23.3

3 of the 11 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2
quay.io/devtron/kubectl:latest2ad610626658
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

32,902
direktivdirektivVerified publisher0.10.01 of 6See more

direktiv direktiv 0.10.0

1 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-k8s:0.120.01e45d9483faa
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

3,470
dnation-kubernetes-monitoring-stackdnationcloud4.0.25 of 17See more

dnation-kubernetes-monitoring-stack dnationcloud 4.0.2

5 of the 17 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
grafana/loki:3.2.0882e30c20683
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
grafana/loki-canary:3.2.049e03f80d361
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

21,641
corednsdoubanVerified publisher1.39.21 of 1See more

coredns douban 1.39.2

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
coredns/coredns:1.12.040384aa1f5ea
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2

Open the chart page →

1,132
drogue-cloud-examplesdrogue-iotVerified publisher0.7.112 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

2 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.4.2
no fix listed
4.5.2
ghcr.io/ctron/kubectl:1.25e37d61b5277c
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

30,699
drogue-cloud-metricsdrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.4.2
no fix listed
4.5.2

Open the chart page →

13,558
temporaldtrdnk-helm-chartsVerified publisher0.35.04 of 13See more

temporal dtrdnk-helm-charts 0.35.0

4 of the 13 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.4258958fe2ff2
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
temporalio/server:1.22.4c0a44c26397b
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
temporalio/ui:2.16.2af9c9349708f
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

20,205
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

9,244
bordysnixVerified publisher0.0.81 of 1See more

bor dysnix 0.0.8

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
0xpolygon/bor:1.3.7396d3de26d8b
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,365
api-gatewayeclipse-aeriosVerified publisher1.7.01 of 1See more

api-gateway eclipse-aerios 1.7.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
devopsfaith/krakend:2.6.34c678c224f67
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

1,296
iotaeclipse-aeriosVerified publisher1.0.22 of 4See more

iota eclipse-aerios 1.0.2

2 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
iotaledger/hornet:2.001206f1ba89c
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
iotaledger/inx-dashboard:1.012c669cb8748
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

13,391
openfaas2eclipse-aeriosVerified publisher12.0.52 of 6See more

openfaas2 eclipse-aerios 12.0.5

2 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
prom/prometheus:v2.51.24f6c47e39a90
github.com/golang-jwt/jwt/v5@v5.2.0
5.2.2
ghcr.io/openfaasltd/jetstream-queue-worker:0.3.37d96366e208b1
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

6,678
continuum-proxyedgelesssysVerified publisher1.5.11 of 1See more

continuum-proxy edgelesssys 1.5.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/continuum/continuum-proxydigest-pinned24c76f294a80
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

852
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

1,328
kube-ecp-stackemqx-operator2.5.16 of 16See more

kube-ecp-stack emqx-operator 2.5.1

6 of the 16 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
emqx/ecp-emqx-agent-downloader:2.5.1a8431baa7950
github.com/golang-jwt/jwt/v5@v5.2.0
5.2.2
emqx/ecp-main:2.5.1fa876f71e5d6
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
emqxecp/otelcol:2.5.04c31d9bec846
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
library/telegraf:1.27507a3eecf809
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

23,685
eoapi-supporteoapiVerified publisher0.1.73 of 7See more

eoapi-support eoapi 0.1.7

3 of the 7 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:10.3.38640e5038e83
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

8,648
epinio-uiepinioVerified publisher1.7.21 of 1See more

epinio-ui epinio 1.7.2

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

1,684
upgrade-responderepinioVerified publisher0.2.01 of 5See more

upgrade-responder epinio 0.2.0

1 of the 5 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:10.1.50679e877ba20
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

7,329
admin-console-operatorepmdedpVerified publisher2.14.01 of 2See more

admin-console-operator epmdedp 2.14.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
epamedp/admin-console-operator:2.14.090f9921d8d58
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2

Open the chart page →

4,308
jenkins-operatorepmdedpVerified publisher2.15.31 of 3See more

jenkins-operator epmdedp 2.15.3

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.15.328ef56bc0ca3
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2

Open the chart page →

2,116
codebase-operatorepmdedp-devVerified publisher2.12.0-MDTU-DDM-SNAPSHOT.101 of 1See more

codebase-operator epmdedp-dev 2.12.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed

Open the chart page →

2,825
jenkins-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

jenkins-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2

Open the chart page →

2,267
keycloak-operatorepmdedp-devVerified publisher1.11.0-MDTU-DDM-SNAPSHOT.101 of 1See more

keycloak-operator epmdedp-dev 1.11.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2

Open the chart page →

2,234
forkmonethereum-helm-chartsVerified publisher0.1.61 of 1See more

forkmon ethereum-helm-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
holiman/nodemonitor:latest5cd609761065
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

1,694
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.186d6d12a40465
github.com/golang-jwt/jwt/v4@v4.3.0
4.5.2

Open the chart page →

4,756
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.01 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/loki:2.9.66ca6e2cd3b6f
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

5,748
siyuanextrim-helm-chartsVerified publisher0.1.11 of 2See more

siyuan extrim-helm-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
b3log/siyuan:v3.1.2595c0d129bc19
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

1,247
faasnetfaasnet0.0.41 of 5See more

faasnet faasnet 0.0.4

1 of the 5 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
simpleidserver/faasprometheus:0.0.425e378d57d78
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

7,617
mandefactlyVerified publisher0.5.161 of 3See more

mande factly 0.5.16

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
factly/mande-server:0.34.1384d384310ef
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

4,777
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

13,450
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2

Open the chart page →

3,311
grgatefikaworks0.3.41 of 1See more

grgate fikaworks 0.3.4

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,080
dsba-pdpfiware0.1.21 of 2See more

dsba-pdp fiware 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.4.3
no fix listed
4.5.2

Open the chart page →

4,103
endpoint-auth-servicefiware0.1.41 of 4See more

endpoint-auth-service fiware 0.1.4

1 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/fiware/ishare-auth-provider:0.4.3158108f70f95
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2

Open the chart page →

11,835
mission-control-tenantflanksourceVerified publisher1.0.921 of 3See more

mission-control-tenant flanksource 1.0.92

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rancher/k3s:v1.28.2-k3s18c2599ecfca8
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

5,684
flyte-devboxflyte0.1.01 of 13See more

flyte-devbox flyte 0.1.0

1 of the 13 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned5b93308a392c
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2

Open the chart page →

4,628
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

4,602
free5gc-amffree5gc-amfVerified publisher0.1.31 of 1See more

free5gc-amf free5gc-amf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
free5gc/amf:v3.4.31bc96ff5a2a6
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

902
free5gc-ausffree5gc-ausfVerified publisher0.1.31 of 1See more

free5gc-ausf free5gc-ausf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
free5gc/ausf:v3.4.3687ff4daf5da
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed

Open the chart page →

910
free5gc-chffree5gc-chfVerified publisher0.1.31 of 1See more

free5gc-chf free5gc-chf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
free5gc/chf:v3.4.3e2a4dd98a4ed
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

997
free5gc-nrffree5gc-nrfVerified publisher0.1.31 of 1See more

free5gc-nrf free5gc-nrf 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
free5gc/nrf:v3.4.399e46b860efb
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

919

Container images carrying it

620 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/miniflux/miniflux:2.2.5bacc9b78ec61
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
ghcr.io/olivetin/olivetin:2025.2.19a89958921526
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
ghcr.io/openfaasltd/federated-gateway:0.2.39066d7b3e6a1
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
ghcr.io/openfaasltd/gcp-pubsub-connector:0.0.18df071f5b719
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/openfaasltd/jetstream-queue-worker:0.3.37d96366e208b1
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/openfaasltd/sns-connector:0.2.0e9ab76a4ec77
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/parca-dev/parca-agent:v0.28.06d6794f45f3e
github.com/golang-jwt/jwt/v5@v5.1.0
5.2.2
1
ghcr.io/permify/permify:v1.3.5f0c6f7d7daa6
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2
1
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed
1
ghcr.io/qjoly/spindle:v1.16.1-alphaaab0c99d313f
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
1
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.2
1
ghcr.io/runatlantis/atlantis:v0.47.1511231955463
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
github.com/golang-jwt/jwt@v3.2.1+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
1
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
ghcr.io/stashed/stash:v0.42.03a98245a7667
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/stashed/stash-enterprise:v0.42.1759f3850eda9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/stashed/stash-enterprise:v0.32.0e9bde36e34b7
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2
1
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2
1
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2
1
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2
1
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
1
ghcr.io/usememos/memos:0.24.04723d86e6797
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v5@v5.2.1
no fix listed
5.2.2
1
ghcr.io/wundergraph/cosmo/graphqlmetrics:0.33.0efb69ec3330c
github.com/golang-jwt/jwt/v5@v5.2.0
5.2.2
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2
1
mcr.microsoft.com/aks/kaito/gpu-provisioner:0.2.01204a7e948e9
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
mcr.microsoft.com/oss/azure/aad-pod-identity/mic:v1.8.173004b93fcb74
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
mcr.microsoft.com/oss/azure/aad-pod-identity/nmi:v1.8.1777788bf38938
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.