StackRadar

CVE-2025-30204

High

Advisory

Published 21 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
580
of 17,781 indexed, latest versions
Container images
621
deployed by those charts
Fix available
2 of 3
affected packages

jwt-go allows excessive memory allocation during header parsing

Carried by container images the latest versions of 580 of 17,781 indexed charts deploy, on 621 images.

Affected packageAffected versionsFixed inImages
github.com/golang-jwt/jwt/v4golangv4.0.0, v4.1.0, v4.2.0, v4.3.0+5 more4.5.2453
github.com/golang-jwt/jwt/v5golangv5.0.0, v5.1.0, v5.2.0, v5.2.15.2.2184
github.com/golang-jwt/jwtgolangv3.2.1+incompatible, v3.2.2+incompatibleno fix listed127
OSV records
GHSA-mh63-6h87-95cp
Also known as
GO-2025-3553

Charts affected

580 by stars
ChartLatestAffected imagesRadar Score
exporteropenshift1.0.471 of 3See more

exporter openshift 1.0.47

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

13,000
opscruiseopenshift0.35.1001 of 11See more

opscruise openshift 0.35.100

1 of the 11 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

8,201
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

8,599
openvscode-serveropenvscode-server-helmVerified publisher2.7.371 of 2See more

openvscode-server openvscode-server-helm 2.7.37

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
library/docker:23.0.1-dindd9a0fd8bdd15
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

4,237
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

5,554
agentoptimizely-agentVerified publisher1.4.01 of 1See more

agent optimizely-agent 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
optimizely/agent:4.0.09d0096cabd63
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,213
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.02 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

2 of the 40 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
prom/prometheus:v3.0.1565ee8650122
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

71,208
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

6,583
lokiot-container-kit1.0.12 of 5See more

loki ot-container-kit 1.0.1

2 of the 5 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/loki:3.1.0d947e68a84d9
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.0
4.5.2
5.2.2
grafana/promtail:3.0.0d3de3da9431c
github.com/golang-jwt/jwt/v5@v5.2.0
5.2.2

Open the chart page →

4,831
pgaot-container-kit1.0.31 of 6See more

pga ot-container-kit 1.0.3

1 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:11.1.0079600c9517b
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2

Open the chart page →

5,137
vmot-container-kit0.0.31 of 7See more

vm ot-container-kit 0.0.3

1 of the 7 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2

Open the chart page →

5,411
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
github.com/golang-jwt/jwt/v5@v5.2.0
5.2.2

Open the chart page →

1,980
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

3,621
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v5@v5.2.1
no fix listed
5.2.2

Open the chart page →

3,298
eigendap2p-avs0.1.12 of 3See more

eigenda p2p-avs 0.1.1

2 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

2,322
parcaparca4.19.02 of 2See more

parca parca 4.19.0

2 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
ghcr.io/parca-dev/parca-agent:v0.28.06d6794f45f3e
github.com/golang-jwt/jwt/v5@v5.1.0
5.2.2

Open the chart page →

3,350
parcaparca-chart0.1.01 of 1See more

parca parca-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,978
vikunjapascaliskeVerified publisher5.1.01 of 1See more

vikunja pascaliske 5.1.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v5@v5.2.1
no fix listed
5.2.2

Open the chart page →

1,342
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

4,642
loki-stackphntom2.10.22 of 2See more

loki-stack phntom 2.10.2

2 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/loki:2.4.2b3af8ead67d7
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
grafana/promtail:2.4.2626900031c4e
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

5,708
npre-essentialsphntom0.1.606 of 22See more

npre-essentials phntom 0.1.60

6 of the 22 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
grafana/promtail:2.7.0c16c710f7333
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.2
phntom/chartmuseum:v0.15.29242b4df9e65
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.4.1
no fix listed
4.5.2
phntom/oauth2-proxy:v7.3.48ea656a2a895
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.4.2
no fix listed
4.5.2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

26,840
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2

Open the chart page →

7,062
planectlplanectlVerified publisher0.7.01 of 10See more

planectl planectl 0.7.0

1 of the 10 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2

Open the chart page →

25,934
jiralertprometheus-communityVerified publisher1.9.01 of 1See more

jiralert prometheus-community 1.9.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/jiralert/jiralert-linux-amd64:v1.3.01983aa64761a
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

728
prometheus-optimizerprometheus-optimizer0.2.221 of 1See more

prometheus-optimizer prometheus-optimizer 0.2.22

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
github.com/golang-jwt/jwt/v5@v5.0.0
5.2.2

Open the chart page →

4,416
cdmswebapppyalive-cdmswebappVerified publisher0.1.01 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
sarwansharma/minio:v359d1da9385d1
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.2

Open the chart page →

6,668
loki-stackpyalive-cdmswebappVerified publisher2.6.52 of 4See more

loki-stack pyalive-cdmswebapp 2.6.5

2 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/loki:2.5.0f9ef133793af
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
grafana/promtail:2.4.2626900031c4e
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

6,525
qubivaqubiva0.3.21 of 3See more

qubiva qubiva 0.3.2

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/loki:3.3.28af2de1abbdd
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2

Open the chart page →

4,272
hydraradar-baseVerified publisher0.48.01 of 1See more

hydra radar-base 0.48.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
oryd/hydra:v2.2.02c93beb5e5f2
github.com/golang-jwt/jwt/v5@v5.0.0
5.2.2

Open the chart page →

1,524
kratosradar-baseVerified publisher0.43.11 of 1See more

kratos radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
oryd/kratos:v1.1.08f15006a080d
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2

Open the chart page →

1,776
kubecostradar-baseVerified publisher1.0.03 of 7See more

kubecost radar-base 1.0.0

3 of the 7 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:11.4.0d8ea37798ccc
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
quay.io/prometheus/prometheus:v3.2.05888c188cf09
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

9,355
radar-grafanaradar-baseVerified publisher0.1.41 of 2See more

radar-grafana radar-base 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:11.6.062d2b9d20a19
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2

Open the chart page →

1,667
radar-hydraradar-baseVerified publisher0.3.41 of 2See more

radar-hydra radar-base 0.3.4

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
oryd/hydra:v2.3.0b94007e19a1f
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

2,177
radar-kratosradar-baseVerified publisher0.1.51 of 1See more

radar-kratos radar-base 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
oryd/kratos:v1.3.1fe2428f103a6
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2

Open the chart page →

1,561
rancher-vsphere-cpirke2-charts1.16.1001 of 1See more

rancher-vsphere-cpi rke2-charts 1.16.100

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rancher/mirrored-cloud-provider-vsphere:v1.31.1febfd0517838
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

905
ntfyrm3lVerified publisher0.1.11 of 1See more

ntfy rm3l 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2

Open the chart page →

1,276
olivetinrm3lVerified publisher0.2.01 of 1See more

olivetin rm3l 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/olivetin/olivetin:2025.2.19a89958921526
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

1,370
krr-enforcerrobusta0.3.51 of 2See more

krr-enforcer robusta 0.3.5

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
alpine/k8s:1.30.0bd01dae02676
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.0
4.5.2
5.2.2

Open the chart page →

4,038
imgproxyrock8sVerified publisher0.8.301 of 1See more

imgproxy rock8s 0.8.30

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.15.040f6eb807444
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2

Open the chart page →

2,022
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

12,949
argo-workflowromholdings0.1.61 of 1See more

argo-workflow romholdings 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,580
devtron-enterpriseromholdings48.0.04 of 28See more

devtron-enterprise romholdings 48.0.0

4 of the 28 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
quay.io/devtron/kubectl:latest2ad610626658
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

68,240
devtron-in-clustercdromholdings0.10.21 of 2See more

devtron-in-clustercd romholdings 0.10.2

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

5,039
devtron-operatorromholdings0.23.33 of 11See more

devtron-operator romholdings 0.23.3

3 of the 11 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2
quay.io/devtron/kubectl:latest2ad610626658
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

32,902
controllerrookout0.2.561 of 1See more

controller rookout 0.2.56

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rookout/controller:latest4451a6f6b8ec
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,960
datastorerookout0.1.481 of 1See more

datastore rookout 0.1.48

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rookout/data-on-prem:latest51c0fce64467
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2

Open the chart page →

1,941
rookout-hybridrookout0.3.12 of 2See more

rookout-hybrid rookout 0.3.1

2 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rookout/controller:latest4451a6f6b8ec
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rookout/data-on-prem:latest51c0fce64467
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2

Open the chart page →

3,901
chainrss30.1.284 of 8See more

chain rss3 0.1.28

4 of the 8 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rss3/op-batcher:d2c5ced00901227473fc196fda838191f0cb4e02e8adc09d9c07
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-proposer:d2c5ced00901227473fc196fda838191f0cb4e0296672897ba9e
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

8,528
op-batcherrss30.1.01 of 2See more

op-batcher rss3 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rss3/op-batcher:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8adae8a5bdd7a6
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,251
op-proposerrss30.1.01 of 2See more

op-proposer rss3 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rss3/op-proposer:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8aa4059dd32c48
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,251

Container images carrying it

621 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
grafana/grafana:11.4.0d8ea37798ccc
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
2
grafana/loki:3.1.0d947e68a84d9
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.0
4.5.2
5.2.2
2
grafana/loki:2.5.0f9ef133793af
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
grafana/tempo:2.5.0f0200a9bff6d
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
2
hashicorp/vault:1.15.26b4e5dadf082
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
2
hashicorp/vault:1.12.18de4d5f31b38
github.com/golang-jwt/jwt/v4@v4.3.0
4.5.2
2
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
library/arangodb:3.11.81e75d74954a4
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
2
library/influxdb:2.6.1-alpine44a366dd7724
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed
2
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
2
listmonk/listmonk:v2.1.0d2eac77ddfad
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
2
minio/operator:v4.3.754393e03f3b2
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed
2
openebs/node-disk-operator:2.1.06afe2123c457
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
oryd/kratos:v1.0.0d06fc5845f63
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2
2
oryd/kratos:v1.3.1fe2428f103a6
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2
2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.0
no fix listed
4.5.2
5.2.2
2
otel/opentelemetry-collector-k8s:0.111.032b3c8296dcc
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
2
prom/prometheus:v2.52.05c435642ca4d
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
2
prom/prometheus:v2.37.98176adea328e
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
prom/prometheus:v2.48.1a67e5e402ff5
github.com/golang-jwt/jwt/v5@v5.0.0
5.2.2
2
rancher/kine:v0.11.412889bbcd1e8
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
2
rclone/rclone:1.6874c51b8817e5
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
2
rookout/controller:latest4451a6f6b8ec
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
rookout/data-on-prem:latest51c0fce64467
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
2
rss3/op-batcher:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8adae8a5bdd7a6
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
rss3/op-proposer:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8aa4059dd32c48
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2
2
temporalio/server:1.22.4c0a44c26397b
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
2
temporalio/ui:2.16.2af9c9349708f
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
2
xelalex/dregsy:0.4.3574054e1c417
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed
2
gcr.io/knative-releases/knative.dev/serving/cmd/controller5b93308a392c
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2
2
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
2
ghcr.io/astriaorg/astria-geth:latest4249e403225a
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
ghcr.io/buoyantio/prometheus:v2.55.12659f4c2ebb7
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
2
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
ghcr.io/opencost/opencost:1.121.2de2784434527
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
2
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
2
quay.io/coreos/etcd:v3.5.628cb0630cb85
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.4.2
no fix listed
4.5.2
2
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2
2
quay.io/jetstack/cert-manager-controller:v1.14.364adcb95ce09
github.com/golang-jwt/jwt/v5@v5.0.0
5.2.2
2
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
quay.io/jetstack/cert-manager-controller:v1.15.3eee34b3de2dd
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.