StackRadar

CVE-2025-47910

Unscored

Advisory

Published 22 Sept 2025In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
59
of 17,781 indexed, latest versions
Container images
55
deployed by those charts
Fix available
1 of 1
affected package

CrossOriginProtection insecure bypass patterns not limited to exact matches in net/http

Carried by container images the latest versions of 59 of 17,781 indexed charts deploy, on 55 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.25.01.25.155
OSV records
GO-2025-3955
Also known as
BIT-golang-2025-47910

Charts affected

59 by stars
ChartLatestAffected imagesRadar Score
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2025-47910.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
stdlib@go1.25.0
1.25.1

Open the chart page →

5,819
ctlogsigstoreVerified publisher0.2.683 of 4See more

ctlog sigstore 0.2.68

3 of the 4 container images this version deploys carry CVE-2025-47910.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/createctconfig:v0.7.313a061734c5be
stdlib@go1.25.0
1.25.1
ghcr.io/sigstore/scaffolding/createtree:v0.7.31e5232e8c9122
stdlib@go1.25.0
1.25.1
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3166664ba563e7
stdlib@go1.25.0
1.25.1

Open the chart page →

2,728
trilliansigstoreVerified publisher0.3.171 of 5See more

trillian sigstore 0.3.17

1 of the 5 container images this version deploys carry CVE-2025-47910.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/createdbdigest-pinned3cee6c78973b
stdlib@go1.25.0
1.25.1

Open the chart page →

2,808
tufsigstoreVerified publisher0.1.321 of 1See more

tuf sigstore 0.1.32

1 of the 1 container images this version deploys carry CVE-2025-47910.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/serverdigest-pinnedae8eb69c7b70
stdlib@go1.25.0
1.25.1

Open the chart page →

761
spire-ha-agentspiffeVerified publisher0.3.21 of 2See more

spire-ha-agent spiffe 0.3.2

1 of the 2 container images this version deploys carry CVE-2025-47910.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spire-ha-agent:0.5.0307cf2d05afe
stdlib@go1.25.0
1.25.1

Open the chart page →

361
volcanovolcano-sh1.15.23 of 3See more

volcano volcano-sh 1.15.2

3 of the 3 container images this version deploys carry CVE-2025-47910.

Container imageDigestPackageFixed in
volcanosh/vc-controller-manager:v1.15.26a6bc2560d51
stdlib@go1.25.0
1.25.1
volcanosh/vc-scheduler:v1.15.2afab36286a17
stdlib@go1.25.0
1.25.1
volcanosh/vc-webhook-manager:v1.15.22fff65aad011
stdlib@go1.25.0
1.25.1

Open the chart page →

1,533
aih-scannerwallarmVerified publisher2.7.111 of 2See more

aih-scanner wallarm 2.7.11

1 of the 2 container images this version deploys carry CVE-2025-47910.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.7.11f1cb26db1f5b
stdlib@go1.25.0
1.25.1

Open the chart page →

3,911
giteawenerme12.7.01 of 4See more

gitea wenerme 12.7.0

1 of the 4 container images this version deploys carry CVE-2025-47910.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
stdlib@go1.25.0
1.25.1

Open the chart page →

8,811
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2025-47910.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
stdlib@go1.25.0
1.25.1
temporalio/server:1.29.1c1e3326b2ce1
stdlib@go1.25.0
1.25.1

Open the chart page →

14,983

Container images carrying it

55 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/sigstore/scaffolding/serverae8eb69c7b70
stdlib@go1.25.0
1.25.1
1
ghcr.io/spiffe/spire-ha-agent:0.5.0307cf2d05afe
stdlib@go1.25.0
1.25.1
1
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
stdlib@go1.25.0
1.25.1
1
quay.io/kiali/kiali:v2.23.07652b1285f50
stdlib@go1.25.0
1.25.1
1
registry.gitlab.com/gitlab-org/ci-cd/gitlab-runner-pod-cleanup:latest4369f3ba1d9a
stdlib@go1.25.0
1.25.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.