StackRadar

CVE-2025-47914

Medium

Advisory

Published 19 Nov 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,125
of 17,821 indexed, latest versions
Container images
2,400
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/crypto/ssh/agent vulnerable to panic if message is malformed due to out of bounds read

Carried by container images the latest versions of 2,125 of 17,821 indexed charts deploy, on 2,400 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+147 more0.45.02,400
OSV records
GHSA-f6x5-jh6r-wrfv
Also known as
GO-2025-4135

Charts affected

2,125 by stars
ChartLatestAffected imagesRadar Score
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0

Open the chart page →

10,296
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0

Open the chart page →

3,379
syncthinggeek-cookbookVerified publisher3.5.21 of 1See more

syncthing geek-cookbook 3.5.2

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
syncthing/syncthing:1.18.2966433161272
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.45.0

Open the chart page →

2,612
traefik-forward-authgeek-cookbookVerified publisher2.2.21 of 1See more

traefik-forward-auth geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.45.0

Open the chart page →

2,235
gitvotegitvoteVerified publisher1.5.01 of 6See more

gitvote gitvote 1.5.0

1 of the 6 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/cncf/gitvote/dbmigrator:v1.5.0f1e7efe440da
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.45.0

Open the chart page →

5,614
monitoring-stackhaukitechVerified publisher0.1.112 of 3See more

monitoring-stack haukitech 0.1.11

2 of the 3 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/crypto@v0.21.0
0.45.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/crypto@v0.28.0
0.45.0

Open the chart page →

2,167
home-assistanthome-assistantVerified publisher0.5.101 of 3See more

home-assistant home-assistant 0.5.10

1 of the 3 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.9.0372d991e5888
golang.org/x/crypto@v0.26.0
0.45.0

Open the chart page →

2,361
frpc-ingressinfinity-server0.4.11 of 1See more

frpc-ingress infinity-server 0.4.1

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
springhack/frpc_ingress:latest4aceb821da88
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.45.0

Open the chart page →

2,624
coreinstill-aiOfficialVerified publisher0.1.754 of 15See more

core instill-ai 0.1.75

4 of the 15 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
instill/api-gateway:9bfdc88b53eaa51c523
golang.org/x/crypto@v0.9.0
0.45.0
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0
openfga/openfga:v1.9.25e94966c11df
golang.org/x/crypto@v0.36.0
0.45.0

Open the chart page →

30,858
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.45.0

Open the chart page →

2,212
home-assistantk8s-home-lab-repo16.3.11 of 1See more

home-assistant k8s-home-lab-repo 16.3.1

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/home-operations/home-assistant:2026.3.1067e54e2e107
golang.org/x/crypto@v0.26.0
0.45.0

Open the chart page →

4,696
k8statusk8statusOfficialVerified publisher0.17.01 of 1See more

k8status k8status 0.17.0

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/stenic/k8status:0.17.093298e03089e
golang.org/x/crypto@v0.24.0
0.45.0

Open the chart page →

712
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
neosu/kubebadges:v0.0.5256530d8e5c6
golang.org/x/crypto@v0.14.0
0.45.0

Open the chart page →

1,566
pyroscopekubeblocksVerified publisher0.2.921 of 1See more

pyroscope kubeblocks 0.2.92

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/crypto@v0.1.0
0.45.0

Open the chart page →

1,621
skywalkingkubesphere-testVerified publisher3.1.02 of 4See more

skywalking kubesphere-test 3.1.0

2 of the 4 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/crypto@v0.0.0-20191122220453-ac88ee75c92c
0.45.0
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/crypto@v0.0.0-20191122220453-ac88ee75c92c
0.45.0

Open the chart page →

18,058
kubeviouskubevious1.2.21 of 7See more

kubevious kubevious 1.2.2

1 of the 7 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
kubevious/ui:1.2.16233e84bdd59
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.45.0

Open the chart page →

14,254
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.03 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

3 of the 6 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/crypto@v0.13.0
0.45.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/crypto@v0.13.0
0.45.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/crypto@v0.13.0
0.45.0

Open the chart page →

59,093
prometheus-pingmesh-exporterkubservice-chartsVerified publisher1.1.11 of 1See more

prometheus-pingmesh-exporter kubservice-charts 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
dongjiang1989/pingmesh-agent:latest355fa4be8e97
golang.org/x/crypto@v0.28.0
0.45.0

Open the chart page →

856
karporkusionstackVerified publisher0.7.62 of 3See more

karpor kusionstack 0.7.6

2 of the 3 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
kusionstack/karpor:v0.6.4b707d3bf0abd
golang.org/x/crypto@v0.16.0
0.45.0
quay.io/coreos/etcd:v3.5.11842975891182
golang.org/x/crypto@v0.14.0
0.45.0

Open the chart page →

3,326
loftloftVerified publisher0.0.0-ci.141 of 1See more

loft loft 0.0.0-ci.14

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/crypto@v0.12.0
0.45.0

Open the chart page →

3,694
vcluster-k8sloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-k8s loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.45.0
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/crypto@v0.1.0
0.45.0
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/crypto@v0.1.0
0.45.0

Open the chart page →

5,612
lumigo-operatorlumigo-operatorOfficialVerified publisher69.0.05 of 8See more

lumigo-operator lumigo-operator 69.0.0

5 of the 8 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/opentelemetry-operator/target-allocator:0.124.08936271cf56a
golang.org/x/crypto@v0.36.0
0.45.0
public.ecr.aws/lumigo/lumigo-kubernetes-rbac-proxy:696c2f0585cd6c
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
public.ecr.aws/lumigo/lumigo-kubernetes-telemetry-proxy:691d548e59c2c8
golang.org/x/crypto@v0.40.0
0.45.0
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/crypto@v0.21.0
0.45.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/crypto@v0.28.0
0.45.0

Open the chart page →

7,796
kubecostmesosphere-stable0.37.56 of 9See more

kubecost mesosphere-stable 0.37.5

6 of the 9 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
grafana/grafana:9.4.71a359d92f40e
golang.org/x/crypto@v0.4.0
0.45.0
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
golang.org/x/crypto@v0.15.0
0.45.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.69.17bbe804260f3
golang.org/x/crypto@v0.14.0
0.45.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/crypto@v0.18.0
0.45.0
quay.io/prometheus/prometheus:v2.55.0378f4e037035
golang.org/x/crypto@v0.26.0
0.45.0
quay.io/thanos/thanos:v0.36.1e542959e1b36
golang.org/x/crypto@v0.24.0
0.45.0

Open the chart page →

17,839
rclonemglants2.3.41 of 1See more

rclone mglants 2.3.4

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.45.0

Open the chart page →

2,751
helm-ai-kernelmindburn-labsOfficialVerified publisher0.8.51 of 2See more

helm-ai-kernel mindburn-labs 0.8.5

1 of the 2 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
alpine/helmdigest-pinned105741fa6621
golang.org/x/crypto@v0.25.0
0.45.0

Open the chart page →

2,184
move2kubemove2kube0.3.151 of 1See more

move2kube move2kube 0.3.15

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.45.0

Open the chart page →

3,829
nebraskanebraska3.0.01 of 2See more

nebraska nebraska 3.0.0

1 of the 2 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
golang.org/x/crypto@v0.42.0
0.45.0

Open the chart page →

4,179
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.45.0

Open the chart page →

5,071
mstreamnicholaswildeVerified publisher2.1.21 of 1See more

mstream nicholaswilde 2.1.2

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/mstream:version-v5.2.522c012bcc43c
golang.org/x/crypto@v0.0.0-20201016220609-9e8e0b390897
0.45.0

Open the chart page →

4,379
oesopsmxVerified publisher4.0.323 of 25See more

oes opsmx 4.0.32

3 of the 25 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
0.45.0
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.45.0

Open the chart page →

101,122
ipfs-clusterparadeum-teamVerified publisher0.0.192 of 2See more

ipfs-cluster paradeum-team 0.0.19

2 of the 2 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.13.117259397f587
golang.org/x/crypto@v0.0.0-20220518034528-6f7dac969898
0.45.0
ipfs/ipfs-cluster:1.0.21511f6d57994
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.45.0

Open the chart page →

3,785
permifypermifyVerified publisher0.5.01 of 1See more

permify permify 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/permify/permify:v1.3.5f0c6f7d7daa6
golang.org/x/crypto@v0.24.0
0.45.0

Open the chart page →

1,016
platzioplatz-ioVerified publisher0.6.51 of 2See more

platzio platz-io 0.6.5

1 of the 2 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
platzio/backend:v0.6.5d5e5972f344b
golang.org/x/crypto@v0.39.0
0.45.0

Open the chart page →

2,906
plecopleco0.24.01 of 1See more

pleco pleco 0.24.0

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
golang.org/x/crypto@v0.37.0
0.45.0

Open the chart page →

1,357
pomeriumpomerium34.0.11 of 1See more

pomerium pomerium 34.0.1

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
pomerium/pomerium:v0.22.19c69b10a2126
golang.org/x/crypto@v0.8.0
0.45.0

Open the chart page →

1,949
prometheus-systemd-exporterprometheus-communityVerified publisher0.5.21 of 1See more

prometheus-systemd-exporter prometheus-community 0.5.2

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
quay.io/prometheuscommunity/systemd-exporter:v0.7.078c03f875dfb
golang.org/x/crypto@v0.31.0
0.45.0

Open the chart page →

726
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.45.0
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.45.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.45.0

Open the chart page →

12,139
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
golang.org/x/crypto@v0.35.0
0.45.0

Open the chart page →

5,537
nfs-server-provisionerraphaelVerified publisher1.3.01 of 1See more

nfs-server-provisioner raphael 1.3.0

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.45.0

Open the chart page →

2,732
wordpress-hardenedriotkit-org2.0.01 of 2See more

wordpress-hardened riotkit-org 2.0.0

1 of the 2 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/waf-proxy:snapshot683656fdace2
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.45.0

Open the chart page →

6,618
rqliterqliteOfficialVerified publisher2.0.01 of 1See more

rqlite rqlite 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
rqlite/rqlite:9.1.37b992a526eee
golang.org/x/crypto@v0.43.0
0.45.0

Open the chart page →

1,320
qbittorrent-vpnrtomik-helm-chartsVerified publisher0.0.21 of 2See more

qbittorrent-vpn rtomik-helm-charts 0.0.2

1 of the 2 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
qmcgaw/gluetun:v3.40.02b42bfa04675
golang.org/x/crypto@v0.29.0
0.45.0

Open the chart page →

1,219
bentoself-hosters-by-nightVerified publisher0.9.11 of 1See more

bento self-hosters-by-night 0.9.1

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
golang.org/x/crypto@v0.36.0
0.45.0

Open the chart page →

1,178
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
golang.org/x/crypto@v0.0.0-20221010152910-d6f0a8c073c2
0.45.0

Open the chart page →

1,696
knative-servingsoftonic3.0.05 of 5See more

knative-serving softonic 3.0.0

5 of the 5 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhookdigest-pinned873b968f02b5
golang.org/x/crypto@v0.0.0-20200323165209-0ec3e9974c59
0.45.0
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinneda5de0fb75046
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.45.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned2ef460356b17
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.45.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinned30ce73388ae5
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.45.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedf16c0e022203
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.45.0

Open the chart page →

12,542
miniosolidchartsVerified publisher0.5.01 of 1See more

minio solidcharts 0.5.0

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/coollabsio/minio:RELEASE.2025-10-15T17-29-55Z69b55a1c1c5d
golang.org/x/crypto@v0.40.0
0.45.0

Open the chart page →

1,187
sn-platformstreamnative1.11.445 of 9See more

sn-platform streamnative 1.11.44

5 of the 9 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/crypto@v0.4.0
0.45.0
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/crypto@v0.0.0-20220208050332-20e1d8d225ab
0.45.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/crypto@v0.1.0
0.45.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.45.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/crypto@v0.7.0
0.45.0

Open the chart page →

72,238
pocketbasetechwolf12Verified publisher0.29.31 of 1See more

pocketbase techwolf12 0.29.3

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/techwolf12/pocketbase:0.29.3106099641679
golang.org/x/crypto@v0.41.0
0.45.0

Open the chart page →

1,465
feedbacksystemthm-mni-iiVerified publisher0.47.14 of 10See more

feedbacksystem thm-mni-ii 0.47.1

4 of the 10 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
golang.org/x/crypto@v0.17.0
0.45.0
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/crypto@v0.12.0
0.45.0
library/docker:20.10.21-dind3153fa63f546
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/crypto@v0.1.0
0.45.0

Open the chart page →

28,867
topaztopaz0.2.51 of 1See more

topaz topaz 0.2.5

1 of the 1 container images this version deploys carry CVE-2025-47914.

Container imageDigestPackageFixed in
ghcr.io/aserto-dev/topaz:0.32.594c708ecf7dc4
golang.org/x/crypto@v0.37.0
0.45.0

Open the chart page →

1,677

Container images carrying it

2,400 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/solo-io/certgen:0.0.0-forkb17a8c7d1f32
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
1
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
1
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
1
quay.io/superq/draytek-exporter:v0.2.03b577bdceaae
golang.org/x/crypto@v0.43.0
0.45.0
1
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/crypto@v0.8.0
0.45.0
1
quay.io/thanos/thanos:v0.40.1aae7b2b030ed
golang.org/x/crypto@v0.39.0
0.45.0
1
quay.io/thanos/thanos:v0.17.1e362f02ed304
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.45.0
1
quay.io/thanos/thanos:v0.36.1e542959e1b36
golang.org/x/crypto@v0.24.0
0.45.0
1
quay.io/tigera/operator:v1.20.1379efe0c2541
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0
1
quay.io/tigera/operator:v1.15.1c6591da87aa8
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.45.0
1
quay.io/uswitch/kiam:v4.0be3a5846922d
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.45.0
1
quay.io/youniqx/heist:v1.1.209c43b3a9d98ae
golang.org/x/crypto@v0.26.0
0.45.0
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.45.0
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
golang.org/x/crypto@v0.13.0
0.45.0
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/crypto@v0.0.0-20180808211826-de0752318171
0.45.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
golang.org/x/crypto@v0.36.0
0.45.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
golang.org/x/crypto@v0.36.0
0.45.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
golang.org/x/crypto@v0.0.0-20190530122614-20be4c3c3ed5
0.45.0
1
registry.gitlab.com/gitlab-org/build/cng/cfssl-self-sign:v19.4.07757679afa1b
golang.org/x/crypto@v0.19.0
0.45.0
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.45.0
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
golang.org/x/crypto@v0.12.0
0.45.0
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.45.0
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
golang.org/x/crypto@v0.39.0
0.45.0
1
registry.gitlab.com/xrow-public/developer-operator/developer-operator-controller:2.1.2301847adfe16
golang.org/x/crypto@v0.39.0
0.45.0
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.33.06ef10d108e0e
golang.org/x/crypto@v0.36.0
0.45.0
1
registry.k8s.io/autoscaling/cluster-autoscaler:v1.34.07b172f42533c
golang.org/x/crypto@v0.36.0
0.45.0
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/crypto@v0.11.0
0.45.0
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.32.0f9f4dfd733ab
golang.org/x/crypto@v0.30.0
0.45.0
1
registry.k8s.io/dns/k8s-dns-node-cache:1.26.78b9a78d101a1
golang.org/x/crypto@v0.43.0
0.45.0
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
1
registry.k8s.io/etcd:3.6.4-0e36c08168342
golang.org/x/crypto@v0.36.0
0.45.0
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
1
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
golang.org/x/crypto@v0.19.0
0.45.0
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
1
registry.k8s.io/kube-scheduler:v1.26.110684e23172d9
golang.org/x/crypto@v0.14.0
0.45.0
1
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
golang.org/x/crypto@v0.16.0
0.45.0
1
registry.k8s.io/kube-scheduler:v1.28.1146cf7475c8da
golang.org/x/crypto@v0.21.0
0.45.0
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.45.0
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.45.0
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.2ec5732e28f15
golang.org/x/crypto@v0.0.0-20221012134737-56aed061732a
0.45.0
1
registry.k8s.io/metrics-server/metrics-server:v0.7.01c0419326500
golang.org/x/crypto@v0.18.0
0.45.0
1
registry.k8s.io/metrics-server/metrics-server:v0.7.1db3800085a09
golang.org/x/crypto@v0.18.0
0.45.0
1
registry.k8s.io/nfd/node-feature-discovery:v0.16.619ebca8b3804
golang.org/x/crypto@v0.23.0
0.45.0
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
golang.org/x/crypto@v0.25.0
0.45.0
1
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/crypto@v0.1.0
0.45.0
1
registry.k8s.io/sig-storage/csi-attacher:v4.10.0be59d0556508
golang.org/x/crypto@v0.38.0
0.45.0
1
registry.k8s.io/sig-storage/csi-resizer:v2.0.04a95d94e57ad
golang.org/x/crypto@v0.37.0
0.45.0
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
golang.org/x/crypto@v0.36.0
0.45.0
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.45.0
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.