CVE-2025-30204
HighAdvisory
Published 21 Mar 2025In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.007
- 52nd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 579
- of 17,787 indexed, latest versions
- Container images
- 620
- deployed by those charts
- Fix available
- 2 of 3
- affected packages
jwt-go allows excessive memory allocation during header parsing
Carried by container images the latest versions of 579 of 17,787 indexed charts deploy, on 620 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v4.0.0, v4.1.0, v4.2.0, v4.3.0+5 more | 4.5.2 | 452 |
| github.com/ | v5.0.0, v5.1.0, v5.2.0, v5.2.1 | 5.2.2 | 184 |
| github.com/ | v3.2.1+incompatible, v3.2.2+incompatible | no fix listed | 127 |
- OSV records
- GHSA-mh63-6h87-95cp
- Also known as
- GO-2025-3553
Charts affected
579 by stars
Container images carrying it
620 by charts deploying them
A fixed version is listed for 2 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| grafana/ | 49e03f80d361 | github.com/ | 5.2.2 | 1 |
| grafana/ | 7476e456c738 | github.com/ | 5.2.2 | 1 |
| grafana/ | 80c1a8eb24dd | github.com/ | 4.5.2 | 1 |
| grafana/ | 85f55510e0d3 | github.com/ | 5.2.2 | 1 |
| grafana/ | 330f990cdad9 | github.com/ | 4.5.2 | 1 |
| grafana/ | 072527b12cdf | github.com/ | 4.5.2 | 1 |
| grafana/ | 63a2e57a5b14 | github.com/ | 4.5.2 | 1 |
| grafana/ | c16c710f7333 | github.com/ | 4.5.2 | 1 |
| grafana/ | d3de3da9431c | github.com/ | 5.2.2 | 1 |
| grafana/ | 319bf32ae06b | github.com/ | 5.2.2 | 1 |
| grafana/ | f55a8a1937ff | github.com/ | 5.2.2 | 1 |
| groundnuty/ | a26d3d3f6e1c | github.com/ | 4.5.2 | 1 |
| hashicorp/ | 712fe02d2f84 | github.com/ | 4.5.2 | 1 |
| hashicorp/ | 4dcb45513699 | github.com/ | 4.5.2 | 1 |
| hashicorp/ | b77efab1a448 | github.com/ | 4.5.2 | 1 |
| hashicorp/ | 0b01ed3924e6 | github.com/ github.com/ | 4.5.2 5.2.2 | 1 |
| hashicorp/ | b2177a8bfe85 | github.com/ | 4.5.2 | 1 |
| hashicorp/ | bbb7f98dc67d | github.com/ github.com/ | 4.5.2 5.2.2 | 1 |
| hashicorp/ | 97d521a27498 | github.com/ | 4.5.2 | 1 |
| headscale/ | a7a8ae9616bb | github.com/ | 5.2.2 | 1 |
| holiman/ | 5cd609761065 | github.com/ | 4.5.2 | 1 |
| huacnlee/ | 560be93229a5 | github.com/ | 4.5.2 | 1 |
| hyperledgerk8s/ | 729b3d128487 | github.com/ | 4.5.2 | 1 |
| hyperledgerk8s/ | ed0b0c56f1ea | github.com/ | 4.5.2 | 1 |
| igrantio/ | 2d2ea6546ffe | github.com/ | 4.5.2 | 1 |
| inseefrlab/ | 31f04ca7436b | github.com/ | 4.5.2 | 1 |
| intel/ | 3426deb77337 | github.com/ github.com/ | no fix listed 4.5.2 | 1 |
| invisibl/ | 1a970f84178b | github.com/ | 4.5.2 | 1 |
| invisibl/ | 1029f4fe20eb | github.com/ | 4.5.2 | 1 |
| iotaledger/ | 01206f1ba89c | github.com/ | no fix listed | 1 |
| iotaledger/ | 12c669cb8748 | github.com/ | no fix listed | 1 |
| ipfs/ | 1511f6d57994 | github.com/ | 4.5.2 | 1 |
| ispras/ | 42aa9fa9f189 | github.com/ github.com/ | no fix listed 5.2.2 | 1 |
| istio/ | 6cfce8a071b9 | github.com/ | 4.5.2 | 1 |
| istio/ | ac0284d75ec9 | github.com/ | 4.5.2 | 1 |
| istio/ | db08d6963975 | github.com/ | 4.5.2 | 1 |
| juicedata/ | 43978fc60798 | github.com/ | no fix listed | 1 |
| junktext/ | a70936c04aed | github.com/ | 4.5.2 | 1 |
| khaliq/ | 49f96888d2ab | github.com/ | no fix listed | 1 |
| komodorio/ | 9678d02c3f2e | github.com/ | no fix listed | 1 |
| kubebb/ | f83cd256229b | github.com/ | 4.5.2 | 1 |
| kubebb/ | 20509de4b399 | github.com/ | 4.5.2 | 1 |
| kubebb/ | 2b9e7f451d6b | github.com/ github.com/ | no fix listed 4.5.2 | 1 |
| kubebb/ | e366c34a9b8d | github.com/ github.com/ | no fix listed 4.5.2 | 1 |
| kubebb/ | 163ebbfc7a82 | github.com/ | 4.5.2 | 1 |
| kubeflowkatib/ | 72f14e03b9e1 | github.com/ | 4.5.2 | 1 |
| kubernetesui/ | 07135c09e9ff | github.com/ | 4.5.2 | 1 |
| kubeshop/ | 8b5bfd57a3ce | github.com/ | 4.5.2 | 1 |
| kubeshop/ | e97dc620d9b4 | github.com/ | 4.5.2 | 1 |
| kubeshop/ | 73d7e3a2db43 | github.com/ github.com/ | no fix listed 4.5.2 | 1 |