StackRadar

CVE-2025-30204

High

Advisory

Published 21 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
580
of 17,781 indexed, latest versions
Container images
621
deployed by those charts
Fix available
2 of 3
affected packages

jwt-go allows excessive memory allocation during header parsing

Carried by container images the latest versions of 580 of 17,781 indexed charts deploy, on 621 images.

Affected packageAffected versionsFixed inImages
github.com/golang-jwt/jwt/v4golangv4.0.0, v4.1.0, v4.2.0, v4.3.0+5 more4.5.2453
github.com/golang-jwt/jwt/v5golangv5.0.0, v5.1.0, v5.2.0, v5.2.15.2.2184
github.com/golang-jwt/jwtgolangv3.2.1+incompatible, v3.2.2+incompatibleno fix listed127
OSV records
GHSA-mh63-6h87-95cp
Also known as
GO-2025-3553

Charts affected

580 by stars
ChartLatestAffected imagesRadar Score
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

10,006
monitoringthl-chartsVerified publisher0.1.14 of 10See more

monitoring thl-charts 0.1.1

4 of the 10 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
github.com/golang-jwt/jwt@v3.2.1+incompatible
github.com/golang-jwt/jwt/v4@v4.2.0
no fix listed
4.5.2
grafana/loki:2.5.0f9ef133793af
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
grafana/promtail:2.4.2626900031c4e
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
quay.io/prometheus/prometheus:v2.34.0b37103e03399
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

18,908
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
erenozcan17/go_backend:v4.250b4f23422b6
github.com/golang-jwt/jwt/v5@v5.0.0
5.2.2

Open the chart page →

6,973
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2

Open the chart page →

2,477
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

4,815
tfy-lokitruefoundryVerified publisher0.1.62 of 2See more

tfy-loki truefoundry 0.1.6

2 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/loki:2.9.1035b02acc6765
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
grafana/promtail:2.9.1063a2e57a5b14
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

2,813
tyk-bootstraptyk-helm5.3.01 of 3See more

tyk-bootstrap tyk-helm 5.3.0

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

1,374
tyk-control-planetyk-helm5.3.01 of 7See more

tyk-control-plane tyk-helm 5.3.0

1 of the 7 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

2,925
tyk-stacktyk-helm5.3.01 of 7See more

tyk-stack tyk-helm 5.3.0

1 of the 7 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
tykio/tyk-k8s-bootstrap-pre-install:v2.2.0205215b815a4
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

2,875
typhoontyphoonVerified publisher0.2.31 of 2See more

typhoon typhoon 0.2.3

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/zeiss/typhoon/controller:0.2.34fdf4edfda45
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2

Open the chart page →

1,672
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

4,960
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed

Open the chart page →

4,382
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed

Open the chart page →

13,459
gateway-control-planewallarmVerified publisher0.2.01 of 2See more

gateway-control-plane wallarm 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
wallarm/gateway-control-plane:0.2.0a321bc974a19
github.com/golang-jwt/jwt/v5@v5.2.0
5.2.2

Open the chart page →

1,455
wallarm-node-nextwallarmVerified publisher0.5.31 of 2See more

wallarm-node-next wallarm 0.5.3

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
wallarm/node-helpers:5.0.2-1097cadc42336
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

2,408
consulwarjiang1.3.01 of 2See more

consul warjiang 1.3.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

4,060
eth-validatorwateim1.4.51 of 3See more

eth-validator wateim 1.4.5

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
wateim/lighthouse-launch:latest2520149ee574
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

4,998
azure-janitorwebdevopsVerified publisher1.0.131 of 1See more

azure-janitor webdevops 1.0.13

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
webdevops/azure-janitor:24.9.02446baee7b69
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

801
azure-keyvault-exporterwebdevopsVerified publisher1.0.121 of 1See more

azure-keyvault-exporter webdevops 1.0.12

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
webdevops/azure-keyvault-exporter:24.9.1f333704ecd60
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

801
azure-resourcegraph-exporterwebdevopsVerified publisher1.1.51 of 1See more

azure-resourcegraph-exporter webdevops 1.1.5

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
webdevops/azure-resourcegraph-exporter:24.9.0381136dda026
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

785
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

969
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.1.0
no fix listed
4.5.2

Open the chart page →

6,138
openebswenerme3.10.01 of 3See more

openebs wenerme 3.10.0

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
openebs/node-disk-operator:2.1.06afe2123c457
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

10,489
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
temporalio/server:1.15.1e26758f5a1bf
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

22,665
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2

Open the chart page →

2,022
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

2,506
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed

Open the chart page →

2,616
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
lishimeng/owl-messager:v0.11.23d00485e64dc
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2

Open the chart page →

3,880
ygdrassil-monitoringygdrassilVerified publisher0.4.02 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

2 of the 10 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

9,381

Container images carrying it

621 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2
2
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
quay.io/prometheus/prometheus:v2.53.0075b1ba2c4eb
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
2
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
2
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
2
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
2
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
2
0xpolygon/bor:1.3.7396d3de26d8b
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
1
alpine/k8s:1.22.600ac10bcb759
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
alpine/k8s:1.31.49c4976d47656
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
alpine/k8s:1.30.0bd01dae02676
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.0
4.5.2
5.2.2
1
alpine/k8s:1.30.2cd560fce90f7
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
alpine/k8s:1.28.13e5c0b053fed7
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
alpine/k8s:1.32.3eec354133193
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
andrcuns/smocker:0.18.5b4a8eb20581a
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
1
apache/camel-k:1.10.43bb13d14f64a
github.com/golang-jwt/jwt/v4@v4.3.0
4.5.2
1
apecloud/pyroscope:0.37.2dbca95a15bc1
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
aquasec/postee:2.12.0-amd640795cba777e7
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
aquasec/trivy:0.43.1944a04445179
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
aquasec/trivy:0.32.0973d0df16189
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
aristidetm/basic-notebook:3.6.5469dbc951224
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v5@v5.2.1
no fix listed
5.2.2
1
b3log/siyuan:v3.1.2595c0d129bc19
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
binwiederhier/ntfy:v2.11.04a7d0f0adc6d
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
1
binwiederhier/ntfy:v2.6.283e2e43d9956
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
bitnamilegacy/minio:2023.12.230b60b6565ab2
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
bitnamilegacy/minio:2024.12.18-debian-12-r0cce234b4381a
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
bitnamilegacy/thanos:0.37.1-debian-12-r05bf82b98c82c
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.