StackRadar

CVE-2025-47914

Medium

Advisory

Published 19 Nov 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,054
of 17,790 indexed, latest versions
Container images
2,352
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read

Carried by container images the latest versions of 2,054 of 17,790 indexed charts deploy, on 2,352 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+146 more0.45.02,352
OSV records
GHSA-f6x5-jh6r-wrfv
Also known as
GO-2025-4135

Charts affected

2,054 by stars
ChartLatestAffected imagesRadar Score
rawfile-csiymatrixVerified publisher0.2.12 of 4See more

rawfile-csi ymatrix 0.2.1

2 of the 4 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.45.0
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.45.0

Open the chart page →

7,998
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0

Open the chart page →

3,024
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.45.0
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.45.0

Open the chart page →

5,047
zahori-moonzahoriVerified publisher1.0.11 of 3See more

zahori-moon zahori 1.0.1

1 of the 3 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
quay.io/aerokube/moon-ui:2.0.589990b146824
golang.org/x/crypto@v0.10.0
0.45.0

Open the chart page →

2,907

Container images carrying it

2,352 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.45.0
2
danielqsj/kafka-exporter:v1.9.04150e46b2e96
golang.org/x/crypto@v0.32.0
0.45.0
2
datawire/aes:1.14.48588eafe6862
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.45.0
2
devopsfaith/krakend:latestf8bdaa8a1a43
golang.org/x/crypto@v0.35.0
0.45.0
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.45.0
2
dtzar/helm-kubectl:3.14.455429449408e
golang.org/x/crypto@v0.17.0
0.45.0
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.45.0
2
free5gc/amf:v3.4.31bc96ff5a2a6
golang.org/x/crypto@v0.22.0
0.45.0
2
free5gc/ausf:v3.4.3687ff4daf5da
golang.org/x/crypto@v0.21.0
0.45.0
2
free5gc/chf:v3.4.3e2a4dd98a4ed
golang.org/x/crypto@v0.22.0
0.45.0
2
free5gc/nrf:v3.4.399e46b860efb
golang.org/x/crypto@v0.21.0
0.45.0
2
free5gc/nssf:v3.4.3dfe8c68c04b4
golang.org/x/crypto@v0.21.0
0.45.0
2
free5gc/pcf:v3.4.3f712e8ecd927
golang.org/x/crypto@v0.21.0
0.45.0
2
free5gc/smf:v3.4.360e38baa4b10
golang.org/x/crypto@v0.21.0
0.45.0
2
free5gc/udm:v3.4.32f68df062a50
golang.org/x/crypto@v0.21.0
0.45.0
2
free5gc/udr:v3.4.3c0783bcdcbdc
golang.org/x/crypto@v0.21.0
0.45.0
2
free5gc/upf:v3.4.3b6b362a39fdd
golang.org/x/crypto@v0.21.0
0.45.0
2
free5gc/webui:v3.4.39adeb18492cb
golang.org/x/crypto@v0.21.0
0.45.0
2
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/crypto@v0.0.0-20220331220935-ae2d96664a29
0.45.0
2
governify/dashboard:lateste83a17ba5038
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.45.0
2
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.45.0
2
grafana/alloy:v1.8.17790f6f7fbd8
golang.org/x/crypto@v0.36.0
0.45.0
2
grafana/alloy:v1.12.2f94b1c82957a
golang.org/x/crypto@v0.43.0
0.45.0
2
grafana/grafana:9.2.4057896e23443
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.45.0
2
grafana/grafana:11.1.0079600c9517b
golang.org/x/crypto@v0.24.0
0.45.0
2
grafana/grafana:12.3.12175aaa91c96
golang.org/x/crypto@v0.43.0
0.45.0
2
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/crypto@v0.0.0-20211117183948-ae814b36b871
0.45.0
2
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.45.0
2
grafana/grafana:11.1.4886b56d5534e
golang.org/x/crypto@v0.24.0
0.45.0
2
grafana/grafana:11.4.0d8ea37798ccc
golang.org/x/crypto@v0.27.0
0.45.0
2
grafana/loki:1.5.0922b3f412fdd
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.45.0
2
grafana/loki:3.1.0d947e68a84d9
golang.org/x/crypto@v0.21.0
0.45.0
2
grafana/loki:2.5.0f9ef133793af
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.45.0
2
grafana/promtail:1.5.046e88d390cd6
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.45.0
2
grafana/tempo:2.5.0f0200a9bff6d
golang.org/x/crypto@v0.22.0
0.45.0
2
hashicorp/consul:1.14.2e38576edcdfd
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.45.0
2
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.45.0
2
hashicorp/vault:1.8.34db614d40d0e
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.45.0
2
hashicorp/vault:1.15.26b4e5dadf082
golang.org/x/crypto@v0.14.0
0.45.0
2
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/crypto@v0.0.0-20220817201139-bc19a97f63c8
0.45.0
2
hashicorp/vault-k8s:1.3.15d74a885ae3e
golang.org/x/crypto@v0.14.0
0.45.0
2
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.45.0
2
honestica/kube-iptables-tailer:master-91a393242fb939
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
golang.org/x/crypto@v0.14.0
0.45.0
2
ilum/api:6.7.3624fd09528c8
golang.org/x/crypto@v0.36.0
0.45.0
2
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/crypto@v0.14.0
0.45.0
2
inaccel/daemon:latest093e1ea90ab8
golang.org/x/crypto@v0.16.0
0.45.0
2
inaccel/reef:latestc967218739f3
golang.org/x/crypto@v0.17.0
0.45.0
2
iomesh/csi-provisioner:v3.0.0f9508460b273
golang.org/x/crypto@v0.0.0-20210317152858-513c2a44f670
0.45.0
2
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.45.0
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.