StackRadar

CVE-2025-30204

High

Advisory

Published 21 Mar 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
580
of 17,781 indexed, latest versions
Container images
621
deployed by those charts
Fix available
2 of 3
affected packages

jwt-go allows excessive memory allocation during header parsing

Carried by container images the latest versions of 580 of 17,781 indexed charts deploy, on 621 images.

Affected packageAffected versionsFixed inImages
github.com/golang-jwt/jwt/v4golangv4.0.0, v4.1.0, v4.2.0, v4.3.0+5 more4.5.2453
github.com/golang-jwt/jwt/v5golangv5.0.0, v5.1.0, v5.2.0, v5.2.15.2.2184
github.com/golang-jwt/jwtgolangv3.2.1+incompatible, v3.2.2+incompatibleno fix listed127
OSV records
GHSA-mh63-6h87-95cp
Also known as
GO-2025-3553

Charts affected

580 by stars
ChartLatestAffected imagesRadar Score
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

3,225
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

3,225
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.101 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

1 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

5,936
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.103 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

3 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

8,202
nightingalelogic3579Verified publisher0.3.12 of 6See more

nightingale logic3579 0.3.1

2 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
flashcatcloud/nightingale:8.5.1421acb36181b
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
quay.io/prometheus/prometheus:v2.54.1f6639335d34a
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

8,938
apica-ascentlogiqai2.0.41 of 19See more

apica-ascent logiqai 2.0.4

1 of the 19 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
logiqai/flash:v3.10.265b996bc7bdc
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
no fix listed
4.5.2
5.2.2

Open the chart page →

23,613
chronograflsst-sqre1.3.51 of 1See more

chronograf lsst-sqre 1.3.5

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

2,342
sasquatchlsst-sqre0.1.132 of 6See more

sasquatch lsst-sqre 0.1.13

2 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
library/kapacitor:1.6.37232f6388a4d
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
quay.io/influxdb/chronograf:1.9.3c2ed16080689
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

9,332
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2

Open the chart page →

9,774
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

24,400
mattermost-push-proxymattermostVerified publisher0.14.31 of 1See more

mattermost-push-proxy mattermost 0.14.3

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
mattermost/mattermost-push-proxy:6.3.045c53061c74e
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

890
mayastormayastorVerified publisher2.12.13 of 31See more

mayastor mayastor 2.12.1

3 of the 31 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/loki:3.4.258a6c186ce78
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2

Open the chart page →

21,064
mediawiki-backupmediawiki-backupVerified publisher0.2.11 of 1See more

mediawiki-backup mediawiki-backup 0.2.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

1,917
cert-manager-setupmesosphere-stable0.2.101 of 5See more

cert-manager-setup mesosphere-stable 0.2.10

1 of the 5 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

7,179
knativemesosphere-stable1.10.81 of 7See more

knative mesosphere-stable 1.10.8

1 of the 7 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

7,479
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

8,902
kube-agent-chartmiddleware-labsVerified publisher0.1.21 of 1See more

kube-agent-chart middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2

Open the chart page →

1,799
mw-kube-agentmiddleware-labsVerified publisher0.1.21 of 1See more

mw-kube-agent middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,594
argocd-extra-app-info-exportermikejohVerified publisher0.1.121 of 1See more

argocd-extra-app-info-exporter mikejoh 0.1.12

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
mikejoh/argocd-extra-app-info-exporter:0.2.05c5a3b734271
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,334
miniomilvus-helm8.0.191 of 1See more

minio milvus-helm 8.0.19

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2024-05-28T17-19-04Z391d1d45fdbe
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,529
minio-operatorminio-operator4.3.71 of 2See more

minio-operator minio-operator 4.3.7

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed

Open the chart page →

6,085
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

10,603
mongodb-secure-backupmongodb-secure-backup1.0.01 of 2See more

mongodb-secure-backup mongodb-secure-backup 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
arconixforge/mongodb-secure-backup:v1.1c08d7c438966
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

1,033
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed

Open the chart page →

10,959
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3fb7667fe037f
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

25,933
chirpstack-event-forwardmosquitto-helm-chart0.1.21 of 1See more

chirpstack-event-forward mosquitto-helm-chart 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

1,854
vikunjamt1905027.1.21 of 3See more

vikunja mt190502 7.1.2

1 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
vikunja/vikunja:0.24.6ed1f3ed467fe
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v5@v5.2.1
no fix listed
5.2.2

Open the chart page →

2,968
cognativemyaVerified publisher0.2403.32 of 3See more

cognative mya 0.2403.3

2 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:10.4.0f9811e4e687f
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.0
4.5.2
5.2.2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.0
no fix listed
4.5.2
5.2.2

Open the chart page →

7,309
giteamyaVerified publisher23.12.51 of 1See more

gitea mya 23.12.5

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
gitea/gitea:1.21.6ac73e0da341f
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2

Open the chart page →

3,430
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2

Open the chart page →

3,359
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.2

Open the chart page →

6,982
agent-control-cdnewrelic1.0.02 of 3See more

agent-control-cd newrelic 1.0.0

2 of the 3 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2

Open the chart page →

5,034
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2

Open the chart page →

3,419
nineinfranineinfra-charts0.7.01 of 1See more

nineinfra nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
nineinfra/nineinfra:v0.7.0d4aad414eccd
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed

Open the chart page →

1,120
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

2,966
prometheusnodepulse25.0.02 of 6See more

prometheus nodepulse 25.0.0

2 of the 6 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

7,740
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2

Open the chart page →

2,246
nai-knative-servingnutanix-helm-releasesVerified publisher1.13.11 of 4See more

nai-knative-serving nutanix-helm-releases 1.13.1

1 of the 4 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.13.153d9aa4d2c7a
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

3,738
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

17,070
multicluster-meshocm-helm-chartsVerified publisher0.0.21 of 1See more

multicluster-mesh ocm-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2

Open the chart page →

2,124
one-green-coreone-green-coreVerified publisher0.0.73 of 8See more

one-green-core one-green-core 0.0.7

3 of the 8 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
grafana/grafana:8.5.3ecc1b80b8ca2
github.com/golang-jwt/jwt@v3.2.1+incompatible
github.com/golang-jwt/jwt/v4@v4.2.0
no fix listed
4.5.2
library/influxdb:2.0.8ba10ac9ba17a
github.com/golang-jwt/jwt@v3.2.1+incompatible
no fix listed
library/telegraf:1.20.428e98eece020
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2

Open the chart page →

9,558
federated-gatewayopenfaas0.1.01 of 1See more

federated-gateway openfaas 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/federated-gateway:0.2.39066d7b3e6a1
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

1,240
gcp-pubsub-connectoropenfaas0.0.11 of 1See more

gcp-pubsub-connector openfaas 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/gcp-pubsub-connector:0.0.18df071f5b719
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

1,155
postgres-connectoropenfaas0.1.21 of 1See more

postgres-connector openfaas 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

1,070
probuilderopenfaas0.2.01 of 2See more

probuilder openfaas 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
moby/buildkit:v0.10.0c2aeafaed434
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.2

Open the chart page →

4,751
rabbitmq-connectoropenfaas0.0.41 of 1See more

rabbitmq-connector openfaas 0.0.4

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/rabbitmq-connector:0.1.2349f7dca95ec
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

776
sns-connectoropenfaas0.1.31 of 1See more

sns-connector openfaas 0.1.3

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/sns-connector:0.2.0e9ab76a4ec77
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2

Open the chart page →

849
sqs-connectoropenfaas0.2.71 of 1See more

sqs-connector openfaas 0.2.7

1 of the 1 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
ghcr.io/openfaasltd/sqs-connector:0.3.4d44ed3b3128c
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2

Open the chart page →

766
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2025-30204.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2

Open the chart page →

7,459

Container images carrying it

621 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
oryd/kratos:v1.1.08f15006a080d
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.0.0
4.5.2
5.2.2
1
otel/opentelemetry-collector:0.100.09e36620d6c2c
github.com/golang-jwt/jwt/v5@v5.2.0
5.2.2
1
otel/opentelemetry-collector:0.59.0ee9da0b08d83
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
otel/opentelemetry-collector-contrib:0.114.037fa87091cfa
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
otel/opentelemetry-collector-contrib:0.113.05ac3e0ba2b0b
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
1
otel/opentelemetry-collector-contrib:0.108.0923eb1cfae32
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.1
no fix listed
4.5.2
5.2.2
1
otel/opentelemetry-collector-contrib:0.89.0995f17004231
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
1
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
1
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.2.0
no fix listed
4.5.2
1
otel/opentelemetry-collector-k8s:0.120.01e45d9483faa
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
owncloud/ocis:7.1.388e7c854517d
github.com/golang-jwt/jwt/v4@v4.5.1
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
owncloud/server:10.15.051d9b74fc2a8
github.com/golang-jwt/jwt/v5@v5.2.1
5.2.2
1
phntom/chartmuseum:v0.16.053883b65d9b7
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.4.1
no fix listed
4.5.2
1
phntom/chartmuseum:v0.15.29242b4df9e65
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.4.1
no fix listed
4.5.2
1
phntom/external-dns-host-network:0.0.123adadbac8443
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
github.com/golang-jwt/jwt/v5@v5.0.0
5.2.2
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
prom/prometheus:v2.51.24f6c47e39a90
github.com/golang-jwt/jwt/v5@v5.2.0
5.2.2
1
prom/prometheus:v2.48.0b440bc0e8aa5
github.com/golang-jwt/jwt/v5@v5.0.0
5.2.2
1
quiq/docker-registry-ui:0.9.491281da47036
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
1
rancher/k3s:v1.28.2-k3s18c2599ecfca8
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
rancher/kubectl:v1.25.085a0d1148784
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
rancher/mirrored-cloud-provider-vsphere:v1.31.1febfd0517838
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
rclone/rclone:1.63.008e1af3c8814
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
rss3/op-batcher:d2c5ced00901227473fc196fda838191f0cb4e02e8adc09d9c07
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
rss3/op-node:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8a45b91380bbe7
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
rss3/op-proposer:d2c5ced00901227473fc196fda838191f0cb4e0296672897ba9e
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
samarthya/spinnaker:v1.0ef06d81036af
github.com/golang-jwt/jwt@v3.2.2+incompatible
no fix listed
1
sarwansharma/minio:v359d1da9385d1
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.2
1
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.2
1
semaphoreui/semaphore:latest:v2.19.123996804607eb
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2
1
semaphoreui/semaphore:v2.19.1498ad9bc7a2a0
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2
1
semaphoreui/semaphore:v2.18.3e9260bfa8255
github.com/golang-jwt/jwt/v4@v4.5.1
4.5.2
1
semitechnologies/weaviate:1.19.17a00d226f063
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
sikalabs/slu:v0.72.07bd267f30247
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
1
simpleidserver/faasprometheus:0.0.425e378d57d78
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
sky5367/locust-plugins-grafana:latestd51bf68d4b26
github.com/golang-jwt/jwt/v4@v4.5.0
github.com/golang-jwt/jwt/v5@v5.2.0
4.5.2
5.2.2
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.2
1
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
github.com/golang-jwt/jwt/v4@v4.3.0
4.5.2
1
summerwind/actions-runner-controller:v0.27.62128f81dbede
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.2
1
supabase/gotrue:v2.91.07174d551d720
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.4.3
no fix listed
4.5.2
1
supabase/gotrue:v2.163.0ba4ddc594b0b
github.com/golang-jwt/jwt/v4@v4.4.3
github.com/golang-jwt/jwt/v5@v5.2.1
4.5.2
5.2.2
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.2
1
tailwarden/komiser:3.1.103f68c8ae7993
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.2
1
temporalio/admin-tools:1.22.4258958fe2ff2
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.0
no fix listed
4.5.2
1
temporalio/admin-tools:1.26.237e2e33dbd7b
github.com/golang-jwt/jwt@v3.2.2+incompatible
github.com/golang-jwt/jwt/v4@v4.5.1
no fix listed
4.5.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.