StackRadar

CVE-2025-30204

High

Advisory

Published 21 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
580
of 17,781 indexed, latest versions
Container images
621
deployed by those charts
Fix available
2 of 3
affected packages

jwt-go allows excessive memory allocation during header parsing

Carried by container images the latest versions of 580 of 17,781 indexed charts deploy, on 621 images.

Affected packageAffected versionsFixed inImages
github.com/golang-jwt/jwt/v4golangv4.0.0, v4.1.0, v4.2.0, v4.3.0+5 more4.5.2453
github.com/golang-jwt/jwt/v5golangv5.0.0, v5.1.0, v5.2.0, v5.2.15.2.2184
github.com/golang-jwt/jwtgolangv3.2.1+incompatible, v3.2.2+incompatibleno fix listed127
OSV records
GHSA-mh63-6h87-95cp
Also known as
GO-2025-3553

Charts affected

580 by stars
ChartLatestAffected imagesRadar Score
vsl-chainrss30.1.04 of 7See more

vsl-chain rss3 0.1.0

4 of the 7 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rss3/op-batcher:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8adae8a5bdd7a6
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-node:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8a45b91380bbe7
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-proposer:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8aa4059dd32c48
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

6,044
vsl-rpcrss30.3.42 of 4See more

vsl-rpc rss3 0.3.4

2 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

4,610
vsl-sequencerrss30.3.42 of 4See more

vsl-sequencer rss3 0.3.4

2 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

4,610
spindlerubxkubeVerified publisher0.1.11 of 2See more

spindle rubxkube 0.1.1

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/qjoly/spindle:v1.16.1-alphaaab0c99d313f
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

1,438
hellowsamarthya2.0.01 of 1See more

hellow samarthya 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
samarthya/spinnaker:v1.0ef06d81036af
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

2,121
harborsb-helm-charts0.3.01 of 2See more

harbor sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.11.1c017dd84ee96
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

1,680
mimirsb-helm-charts0.3.01 of 1See more

mimir sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/mimir:2.15.085f55510e0d3
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

888
opentelemetry-collectorsb-helm-charts0.3.01 of 1See more

opentelemetry-collector sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.0
no fix listed
4.5.2
5.2.2

Open the chart page →

1,721
thanos-compactorsb-helm-charts0.3.01 of 1See more

thanos-compactor sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
thanos-querysb-helm-charts0.3.01 of 1See more

thanos-query sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
thanos-query-frontendsb-helm-charts0.3.01 of 1See more

thanos-query-frontend sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
thanos-receivesb-helm-charts0.3.01 of 1See more

thanos-receive sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
thanos-rulersb-helm-charts0.3.01 of 1See more

thanos-ruler sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
thanos-sidecarsb-helm-charts0.3.01 of 1See more

thanos-sidecar sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
thanos-storesb-helm-charts0.3.01 of 1See more

thanos-store sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

961
crproxyschichtelVerified publisher0.1.41 of 1See more

crproxy schichtel 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/daocloud/crproxy/crproxy:v0.8.0ee1eb3c9c9a1
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,378
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed

Open the chart page →

5,582
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v5@v5.2.1
no fix listed
5.2.2

Open the chart page →

4,070
cernboxsciencebox0.0.41 of 6See more

cernbox sciencebox 0.0.4

1 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
cs3org/revad:v1.19.03b57a34a7dfd
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

2,330
hermitcrabseal-ioVerified publisher0.1.41 of 2See more

hermitcrab seal-io 0.1.4

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

4,881
semaphoresemaphore-light1.0.01 of 1See more

semaphore semaphore-light 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
semaphoreui/semaphore:latest3996804607eb
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2

Open the chart page →

1,674
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.1
no fix listed
4.5.2

Open the chart page →

3,286
miniosergiotocaliniVerified publisher1.0.01 of 1See more

minio sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

4,203
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

2,863
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2

Open the chart page →

2,314
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,494
keydbsinextraVerified publisher0.31.01 of 1See more

keydb sinextra 0.31.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed

Open the chart page →

2,165
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

2,429
mimirskyloud-helm-chartsVerified publisher5.5.13 of 5See more

mimir skyloud-helm-charts 5.5.1

3 of the 5 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/mimir:r292-5f018727476e456c738
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

10,651
cost-analyzersoftonic2.5.53 of 6See more

cost-analyzer softonic 2.5.5

3 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:11.5.28b37a2f028f1
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
quay.io/prometheus/prometheus:v3.2.16927e0919a14
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

7,901
harborsoftonic1.13.03 of 8See more

harbor softonic 1.13.0

3 of the 8 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
goharbor/harbor-registryctl:v2.9.0cce272836449
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

7,672
rclonesoftonic2.1.01 of 1See more

rclone softonic 2.1.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
rclone/rclone:1.6874c51b8817e5
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2

Open the chart page →

1,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

2,505
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

30,687
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

2,416
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

66,266
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.2

Open the chart page →

3,073
stakefishstakefish0.1.02 of 8See more

stakefish stakefish 0.1.0

2 of the 8 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
quay.io/prometheus-operator/prometheus-config-reloader:v0.73.2706cde441321
github.com/golang-jwt/jwt/v5@v5.2.0
5.2.2

Open the chart page →

20,223
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

2,938
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

6,779
sn-platform-slimstreamnative1.11.442 of 6See more

sn-platform-slim streamnative 1.11.44

2 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

10,134
orchestratorsubstraVerified publisher8.8.01 of 3See more

orchestrator substra 8.8.0

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

2,991
lingosubstratusVerified publisher0.2.11 of 1See more

lingo substratus 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/substratusai/lingo:v0.2.12c807cd41ed4
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

1,474
surogate-hubsurogate-hubVerified publisher2.1.51 of 1See more

surogate-hub surogate-hub 2.1.5

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v5@v5.2.0
no fix listed
5.2.2

Open the chart page →

3,460
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2

Open the chart page →

10,902
agentssynapse0.1.301 of 9See more

agents synapse 0.1.30

1 of the 9 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2

Open the chart page →

7,244
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2

Open the chart page →

1,815
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2

Open the chart page →

1,704
pingmetektonops0.1.21 of 1See more

pingme tektonops 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
khaliq/pingme:v0.2.749f96888d2ab
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

1,253
temporaltemporal0.28.94 of 13See more

temporal temporal 0.28.9

4 of the 13 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.4.3
no fix listed
4.5.2
temporalio/server:1.22.0ddeebf8bad8f
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
temporalio/ui:2.16.2af9c9349708f
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

21,005

Container images carrying it

621 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2
2
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
2
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
2
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
0xpolygon/bor:1.3.7396d3de26d8b
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
1
alpine/k8s:1.22.600ac10bcb759
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
alpine/k8s:1.31.49c4976d47656
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
alpine/k8s:1.30.0bd01dae02676
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.0
4.5.2
5.2.2
1
alpine/k8s:1.30.2cd560fce90f7
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
alpine/k8s:1.28.13e5c0b053fed7
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
alpine/k8s:1.32.3eec354133193
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
andrcuns/smocker:0.18.5b4a8eb20581a
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
1
apache/camel-k:1.10.43bb13d14f64a
github.com/golang-jwt/jwt/v4@v4.3.0
4.5.2
1
apecloud/pyroscope:0.37.2dbca95a15bc1
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
aquasec/postee:2.12.0-amd640795cba777e7
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
aquasec/trivy:0.43.1944a04445179
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
aquasec/trivy:0.32.0973d0df16189
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
aristidetm/basic-notebook:3.6.5469dbc951224
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v5@v5.2.1
no fix listed
5.2.2
1
b3log/siyuan:v3.1.2595c0d129bc19
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
1
binwiederhier/ntfy:v2.6.283e2e43d9956
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.