StackRadar

CVE-2025-30204

High

Advisory

Published 21 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
589
of 17,787 indexed, latest versions
Container images
628
deployed by those charts
Fix available
2 of 3
affected packages

jwt-go allows excessive memory allocation during header parsing

Carried by container images the latest versions of 589 of 17,787 indexed charts deploy, on 628 images.

Affected packageAffected versionsFixed inImages
github.com/golang-jwt/jwt/v4golangv4.0.0, v4.1.0, v4.2.0, v4.3.0+5 more4.5.2458
github.com/golang-jwt/jwt/v5golangv5.0.0, v5.1.0, v5.2.0, v5.2.15.2.2184
github.com/golang-jwt/jwtgolangv3.2.1+incompatible, v3.2.2+incompatibleno fix listed131
OSV records
GHSA-mh63-6h87-95cp
Also known as
GO-2025-3553

Charts affected

589 by stars
ChartLatestAffected imagesRadar Score
devtron-enterpriseromholdings48.0.04 of 28See more

devtron-enterprise romholdings 48.0.0

4 of the 28 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
quay.io/devtron/kubectl:latest2ad610626658
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

66,542
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

5,041
devtron-operatorromholdings0.23.33 of 11See more

devtron-operator romholdings 0.23.3

3 of the 11 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2
quay.io/devtron/kubectl:latest2ad610626658
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

31,447
controllerrookout0.2.561 of 1See more

controller rookout 0.2.56

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rookout/controller:latest4451a6f6b8ec
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,960
datastorerookout0.1.481 of 1See more

datastore rookout 0.1.48

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rookout/data-on-prem:latest51c0fce64467
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2

Open the chart page →

1,941
rookout-hybridrookout0.3.12 of 2See more

rookout-hybrid rookout 0.3.1

2 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rookout/controller:latest4451a6f6b8ec
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rookout/data-on-prem:latest51c0fce64467
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2

Open the chart page →

3,901
chainrss30.1.284 of 8See more

chain rss3 0.1.28

4 of the 8 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rss3/op-batcher:d2c5ced00901227473fc196fda838191f0cb4e02e8adc09d9c07
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-proposer:d2c5ced00901227473fc196fda838191f0cb4e0296672897ba9e
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

8,528
op-batcherrss30.1.01 of 2See more

op-batcher rss3 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rss3/op-batcher:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8adae8a5bdd7a6
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,251
op-proposerrss30.1.01 of 2See more

op-proposer rss3 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rss3/op-proposer:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8aa4059dd32c48
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,251
vsl-chainrss30.1.04 of 7See more

vsl-chain rss3 0.1.0

4 of the 7 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rss3/op-batcher:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8adae8a5bdd7a6
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-node:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8a45b91380bbe7
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-proposer:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8aa4059dd32c48
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

6,044
vsl-rpcrss30.3.42 of 4See more

vsl-rpc rss3 0.3.4

2 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

4,611
vsl-sequencerrss30.3.42 of 4See more

vsl-sequencer rss3 0.3.4

2 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

4,611
spindlerubxkubeVerified publisher0.1.11 of 2See more

spindle rubxkube 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/qjoly/spindle:v1.16.1-alphaaab0c99d313f
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

1,439
hellowsamarthya2.0.01 of 1See more

hellow samarthya 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
samarthya/spinnaker:v1.0ef06d81036af
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

2,121
harborsb-helm-charts0.3.01 of 2See more

harbor sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.11.1c017dd84ee96
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

1,680
mimirsb-helm-charts0.3.01 of 1See more

mimir sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/mimir:2.15.085f55510e0d3
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

888
opentelemetry-collectorsb-helm-charts0.3.01 of 1See more

opentelemetry-collector sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.0
no fix listed
4.5.2
5.2.2

Open the chart page →

1,721
thanos-compactorsb-helm-charts0.3.01 of 1See more

thanos-compactor sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
thanos-querysb-helm-charts0.3.01 of 1See more

thanos-query sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
thanos-query-frontendsb-helm-charts0.3.01 of 1See more

thanos-query-frontend sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
thanos-receivesb-helm-charts0.3.01 of 1See more

thanos-receive sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
thanos-rulersb-helm-charts0.3.01 of 1See more

thanos-ruler sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
thanos-sidecarsb-helm-charts0.3.01 of 1See more

thanos-sidecar sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
thanos-storesb-helm-charts0.3.01 of 1See more

thanos-store sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
crproxyschichtelVerified publisher0.1.41 of 1See more

crproxy schichtel 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/daocloud/crproxy/crproxy:v0.8.0ee1eb3c9c9a1
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,378
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed

Open the chart page →

5,582
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v5@v5.2.1
no fix listed
5.2.2

Open the chart page →

4,109
cernboxsciencebox0.0.41 of 6See more

cernbox sciencebox 0.0.4

1 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
cs3org/revad:v1.19.03b57a34a7dfd
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

2,330
hermitcrabseal-ioVerified publisher0.1.41 of 2See more

hermitcrab seal-io 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

4,883
semaphoresemaphore-light1.0.01 of 1See more

semaphore semaphore-light 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
semaphoreui/semaphore:latest3996804607eb
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2

Open the chart page →

1,674
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.1
no fix listed
4.5.2

Open the chart page →

3,325
miniosergiotocaliniVerified publisher1.0.01 of 1See more

minio sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

4,203
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

2,863
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2

Open the chart page →

2,316
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,494
keydbsinextraVerified publisher0.31.01 of 1See more

keydb sinextra 0.31.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed

Open the chart page →

2,165
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

2,429
mimirskyloud-helm-chartsVerified publisher5.5.13 of 5See more

mimir skyloud-helm-charts 5.5.1

3 of the 5 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/mimir:r292-5f018727476e456c738
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

10,650
cost-analyzersoftonic2.5.53 of 6See more

cost-analyzer softonic 2.5.5

3 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:11.5.28b37a2f028f1
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
quay.io/prometheus/prometheus:v3.2.16927e0919a14
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

7,935
harborsoftonic1.13.03 of 8See more

harbor softonic 1.13.0

3 of the 8 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
goharbor/harbor-registryctl:v2.9.0cce272836449
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

7,672
rclonesoftonic2.1.01 of 1See more

rclone softonic 2.1.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rclone/rclone:1.6874c51b8817e5
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2

Open the chart page →

1,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

2,505
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

30,759
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

2,415
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

65,130
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.2

Open the chart page →

3,073
stakefishstakefish0.1.02 of 8See more

stakefish stakefish 0.1.0

2 of the 8 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
quay.io/prometheus-operator/prometheus-config-reloader:v0.73.2706cde441321
github.com/golang-jwt/jwt/v5@v5.2.0
5.2.2

Open the chart page →

18,426
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

2,854
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

6,531
sn-platform-slimstreamnative1.11.442 of 6See more

sn-platform-slim streamnative 1.11.44

2 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

10,182

Container images carrying it

628 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2
1
mcr.microsoft.com/aks/kaito/gpu-provisioner:0.2.01204a7e948e9
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
mcr.microsoft.com/oss/azure/aad-pod-identity/mic:v1.8.173004b93fcb74
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
mcr.microsoft.com/oss/azure/aad-pod-identity/nmi:v1.8.1777788bf38938
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
github.com/golang-jwt/jwt/v5@v5.0.0
5.2.2
1
public.ecr.aws/v0r6c2e2/minio:latest08c90bd040bf
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
1
quay.io/argoproj/argocli:v3.5.591b9825f09a8
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
1
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
1
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.2
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.4.1
no fix listed
4.5.2
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
quay.io/coreos/etcd:v3.5.11842975891182
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
quay.io/coreos/etcd:v3.5.16d967d98a12dc
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
quay.io/evryfs/github-actions-runner-operator:v0.11.16b084e0bd082
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.4.3
no fix listed
4.5.2
1
quay.io/fiware/ishare-auth-provider:0.4.3158108f70f95
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.0.0
no fix listed
4.5.2
1
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
quay.io/influxdb/chronograf:1.9.3c2ed16080689
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
quay.io/jetstack/cert-manager-controller:v1.14.59c0527cab629
github.com/golang-jwt/jwt/v5@v5.0.0
5.2.2
1
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
quay.io/jetstack/cert-manager-controller:v1.16.1ae5e14401cde
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
quay.io/jiralert/jiralert-linux-amd64:v1.3.01983aa64761a
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2
1
quay.io/minio/mc:RELEASE.2024-01-11T05-49-32Z026ae522febc
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.2
1
quay.io/minio/mc:RELEASE.2024-04-29T09-56-05Zc574fac67f60
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
quay.io/minio/minio:RELEASE.2023-12-20T01-00-02Z5702ea361420
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
quay.io/minio/minio:RELEASE.2024-01-11T07-46-16Z796f75ea413b
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.