StackRadar

CVE-2025-58190

Unscored

Advisory

Published 5 Feb 2026In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,452
of 17,790 indexed, latest versions
Container images
2,996
deployed by those charts
Fix available
1 of 1
affected package

Infinite parsing loop in golang.org/x/net

Carried by container images the latest versions of 2,452 of 17,790 indexed charts deploy, on 2,996 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+210 more0.45.02,996
OSV records
GO-2026-4441

Charts affected

2,452 by stars
ChartLatestAffected imagesRadar Score
neosyncneosyncVerified publisher0.5.412 of 3See more

neosync neosync 0.5.41

2 of the 3 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
golang.org/x/net@v0.37.0
0.45.0
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
golang.org/x/net@v0.37.0
0.45.0

Open the chart page →

7,056
apineosync-apiVerified publisher0.5.411 of 1See more

api neosync-api 0.5.41

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
golang.org/x/net@v0.37.0
0.45.0

Open the chart page →

2,755
workerneosync-workerVerified publisher0.5.411 of 1See more

worker neosync-worker 0.5.41

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
golang.org/x/net@v0.37.0
0.45.0

Open the chart page →

2,732
netbirdnetbird1.9.03 of 4See more

netbird netbird 1.9.0

3 of the 4 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
netbirdio/management:0.46.0b0adc4ad4ec6
golang.org/x/net@v0.39.0
0.45.0
netbirdio/relay:0.46.0d32f82514a24
golang.org/x/net@v0.39.0
0.45.0
netbirdio/signal:0.46.0e8f392611152
golang.org/x/net@v0.39.0
0.45.0

Open the chart page →

6,367
iamdnetsocVerified publisher0.6.11 of 2See more

iamd netsoc 0.6.1

1 of the 2 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.45.0

Open the chart page →

2,890
shhdnetsocVerified publisher0.1.71 of 1See more

shhd netsoc 0.1.7

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.45.0

Open the chart page →

3,986
webspacednetsocVerified publisher0.2.82 of 2See more

webspaced netsoc 0.2.8

2 of the 2 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.45.0
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
0.45.0

Open the chart page →

5,193
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
openvino/model_server:2025.2.11e7cd1d70cc1
golang.org/x/net@v0.38.0
0.45.0

Open the chart page →

7,413
agent-controlnewrelic0.0.921 of 1See more

agent-control newrelic 0.0.92

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
newrelic/newrelic-agent-control-cli:0.48.01a448492b55a
golang.org/x/net@v0.38.0
0.45.0

Open the chart page →

3,821
agent-control-cdnewrelic1.0.03 of 3See more

agent-control-cd newrelic 1.0.0

3 of the 3 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flux-cli:v2.5.1274a179fd402
golang.org/x/net@v0.35.0
0.45.0
ghcr.io/fluxcd/helm-controller:v1.2.062eaa9c9a929
golang.org/x/net@v0.34.0
0.45.0
ghcr.io/fluxcd/source-controller:v1.5.000cd9316a379
golang.org/x/net@v0.34.0
0.45.0

Open the chart page →

5,036
nginx-examplengrok-ingress-helm0.3.01 of 2See more

nginx-example ngrok-ingress-helm 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
wernight/ngrok:latestd211f29ebcfe
golang.org/x/net@v0.17.0
0.45.0

Open the chart page →

2,960
cert-managernicklasfrahm-cert-managerVerified publisher0.1.24 of 4See more

cert-manager nicklasfrahm-cert-manager 0.1.2

4 of the 4 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.18.2af59e01ad975
golang.org/x/net@v0.38.0
0.45.0
quay.io/jetstack/cert-manager-controller:v1.18.281316365dc0b
golang.org/x/net@v0.38.0
0.45.0
quay.io/jetstack/cert-manager-startupapicheck:v1.18.21075e0974151
golang.org/x/net@v0.38.0
0.45.0
quay.io/jetstack/cert-manager-webhook:v1.18.29431f0d8b510
golang.org/x/net@v0.38.0
0.45.0

Open the chart page →

2,824
ciliumnicklasfrahm-ciliumVerified publisher0.7.45 of 6See more

cilium nicklasfrahm-cilium 0.7.4

5 of the 6 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
golang.org/x/net@v0.41.0
0.45.0
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
golang.org/x/net@v0.41.0
0.45.0
quay.io/cilium/hubble-relay:v1.18.26079308ee15e
golang.org/x/net@v0.42.0
0.45.0
quay.io/cilium/hubble-ui-backend:v0.13.3db1454e45dc3
golang.org/x/net@v0.42.0
0.45.0
quay.io/cilium/operator-generic:v1.18.2cb4e4ffc5789
golang.org/x/net@v0.42.0
0.45.0

Open the chart page →

7,170
metrics-servernicklasfrahm-metrics-serverVerified publisher0.1.11 of 1See more

metrics-server nicklasfrahm-metrics-server 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
registry.k8s.io/metrics-server/metrics-server:v0.8.089258156d0e9
golang.org/x/net@v0.40.0
0.45.0

Open the chart page →

785
node-upgrade-channelnimbolus0.1.11 of 1See more

node-upgrade-channel nimbolus 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.45.0

Open the chart page →

2,062
cloudnative-pgnineinfra-charts0.19.11 of 1See more

cloudnative-pg nineinfra-charts 0.19.1

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.21.19f707d91de1c
golang.org/x/net@v0.17.0
0.45.0

Open the chart page →

1,187
doris-operatornineinfra-charts1.3.11 of 1See more

doris-operator nineinfra-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
selectdb/doris.k8s-operator:1.3.1919210765cb8
golang.org/x/net@v0.10.0
0.45.0

Open the chart page →

869
hdfs-operatornineinfra-charts0.7.01 of 1See more

hdfs-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
nineinfra/hdfs-operator:v0.7.0debb1e3410e2
golang.org/x/net@v0.17.0
0.45.0

Open the chart page →

723
kyuubi-operatornineinfra-charts0.7.01 of 1See more

kyuubi-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
nineinfra/kyuubi-operator:v0.7.08d8ed87ef77c
golang.org/x/net@v0.13.0
0.45.0

Open the chart page →

815
metastore-operatornineinfra-charts0.7.01 of 1See more

metastore-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
nineinfra/metastore-operator:v0.7.011259032fb04
golang.org/x/net@v0.13.0
0.45.0

Open the chart page →

815
minio-directpvnineinfra-charts4.0.85 of 5See more

minio-directpv nineinfra-charts 4.0.8

5 of the 5 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
quay.io/minio/csi-node-driver-registrardigest-pinnedc805fdc16676
golang.org/x/net@v0.8.0
0.45.0
quay.io/minio/csi-provisionerdigest-pinned7b5c070ec70d
golang.org/x/net@v0.8.0
0.45.0
quay.io/minio/csi-resizerdigest-pinned819f68a4daf7
golang.org/x/net@v0.8.0
0.45.0
quay.io/minio/directpv:v4.0.84560083eb77d
golang.org/x/net@v0.8.0
0.45.0
quay.io/minio/livenessprobedigest-pinnedf3bc9a84f149
golang.org/x/net@v0.8.0
0.45.0

Open the chart page →

7,035
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
golang.org/x/net@v0.13.0
0.45.0

Open the chart page →

3,418
nineinfranineinfra-charts0.7.01 of 1See more

nineinfra nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
nineinfra/nineinfra:v0.7.0d4aad414eccd
golang.org/x/net@v0.17.0
0.45.0

Open the chart page →

1,120
supersetnineinfra-charts0.11.21 of 4See more

superset nineinfra-charts 0.11.2

1 of the 4 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
0.45.0

Open the chart page →

1,439
zookeeper-operatornineinfra-charts0.7.01 of 1See more

zookeeper-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
nineinfra/zookeeper-operator:v0.7.0af6eb2f37bfc
golang.org/x/net@v0.17.0
0.45.0

Open the chart page →

723
node-debug-dashboardnode-debug-dashboardVerified publisher0.3.21 of 1See more

node-debug-dashboard node-debug-dashboard 0.3.2

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
golang.org/x/net@v0.30.0
0.45.0

Open the chart page →

6,861
cosmoshub-rpcnodeifyVerified publisher1.0.71 of 2See more

cosmoshub-rpc nodeify 1.0.7

1 of the 2 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
golang.org/x/net@v0.40.0
0.45.0

Open the chart page →

2,007
cosmos-nodenodeifyVerified publisher2.6.01 of 2See more

cosmos-node nodeify 2.6.0

1 of the 2 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/cosmos/gaia:v25.1.0f115777d1112
golang.org/x/net@v0.40.0
0.45.0

Open the chart page →

2,007
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
golang.org/x/net@v0.41.0
0.45.0

Open the chart page →

6,542
firehose-ethereumnodeifyVerified publisher1.7.11 of 2See more

firehose-ethereum nodeify 1.7.1

1 of the 2 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/go-ethereum:geth-v1.16.9-fh3.08e3cb38953a3
golang.org/x/net@v0.39.0
0.45.0

Open the chart page →

5,652
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.45.0

Open the chart page →

4,723
nodejsweeklynodejsweekly1.1.01 of 1See more

nodejsweekly nodejsweekly 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
0.45.0

Open the chart page →

1,489
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/net@v0.19.0
0.45.0

Open the chart page →

2,966
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
0.45.0
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
0.45.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
0.45.0
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
0.45.0
quay.io/prometheus/pushgateway:v1.6.05111de00e969
golang.org/x/net@v0.10.0
0.45.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
0.45.0

Open the chart page →

7,740
ingress-helm-chartnotesprojectchart0.1.02 of 2See more

ingress-helm-chart notesprojectchart 0.1.0

2 of the 2 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
golang.org/x/net@v0.10.0
0.45.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
0.45.0

Open the chart page →

2,956
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.45.0

Open the chart page →

4,547
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
golang.org/x/net@v0.8.0
0.45.0

Open the chart page →

2,246
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.45.0

Open the chart page →

7,527
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.45.0

Open the chart page →

4,861
nfs-server-provisionernovum-rgi-charts1.1.21 of 1See more

nfs-server-provisioner novum-rgi-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.45.0

Open the chart page →

2,806
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.45.0

Open the chart page →

27,486
cnaos-pvc-populatornutanix-helm-releasesVerified publisher1.1.0-174-prod1 of 2See more

cnaos-pvc-populator nutanix-helm-releases 1.1.0-174-prod

1 of the 2 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.45.0

Open the chart page →

1,838
nai-knative-istio-controllernutanix-helm-releasesVerified publisher1.13.12 of 2See more

nai-knative-istio-controller nutanix-helm-releases 1.13.1

2 of the 2 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.13.1a5b041ba3c9e
golang.org/x/net@v0.20.0
0.45.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.13.1f066376eee17
golang.org/x/net@v0.20.0
0.45.0

Open the chart page →

1,552
nai-knative-servingnutanix-helm-releasesVerified publisher1.13.14 of 4See more

nai-knative-serving nutanix-helm-releases 1.13.1

4 of the 4 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.13.121f8e11a44bf
golang.org/x/net@v0.20.0
0.45.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.13.134796e9f760b
golang.org/x/net@v0.20.0
0.45.0
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.13.153d9aa4d2c7a
golang.org/x/net@v0.20.0
0.45.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.13.1700c69915dc7
golang.org/x/net@v0.20.0
0.45.0

Open the chart page →

3,738
nutanix-flow-cninutanix-helm-releasesVerified publisher1.1.02 of 7See more

nutanix-flow-cni nutanix-helm-releases 1.1.0

2 of the 7 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
0.45.0
ghcr.io/k8snetworkplumbingwg/multus-cni:v4.1.39751856cacc8
golang.org/x/net@v0.23.0
0.45.0

Open the chart page →

4,989
lensoci-ai-incubations0.1.1410 of 16See more

lens oci-ai-incubations 0.1.14

10 of the 16 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
golang.org/x/net@v0.19.0
0.45.0
grafana/grafana:12.1.1a1701c218024
golang.org/x/net@v0.41.0
0.45.0
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/net@v0.17.0
0.45.0
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/net@v0.17.0
0.45.0
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/net@v0.17.0
0.45.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.85.0ebb560bcb6bd
golang.org/x/net@v0.43.0
0.45.0
quay.io/prometheus/prometheus:v3.5.063805ebb8d2b
golang.org/x/net@v0.41.0
0.45.0
quay.io/prometheus/pushgateway:v1.11.103738d278e08
golang.org/x/net@v0.36.0
0.45.0
registry.k8s.io/ingress-nginx/controller:v1.13.21f7eaeb01933
golang.org/x/net@v0.43.0
0.45.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.2050a34002d5b
golang.org/x/net@v0.43.0
0.45.0

Open the chart page →

17,085
cluster-gateway-addon-managerocm-helm-chartsVerified publisher1.4.01 of 1See more

cluster-gateway-addon-manager ocm-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.45.0

Open the chart page →

1,600
cluster-proxyocm-helm-chartsVerified publisher0.12.01 of 1See more

cluster-proxy ocm-helm-charts 0.12.0

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/cluster-proxy:v0.12.035f9c3ad644a
golang.org/x/net@v0.23.0
0.45.0

Open the chart page →

1,191
kueue-addonocm-helm-chartsVerified publisher0.1.41 of 1See more

kueue-addon ocm-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/kueue-addon:v0.1.47f728514fead
golang.org/x/net@v0.38.0
0.45.0

Open the chart page →

1,580
multicluster-meshocm-helm-chartsVerified publisher0.0.21 of 1See more

multicluster-mesh ocm-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2025-58190.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.45.0

Open the chart page →

2,124

Container images carrying it

2,996 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
minio/minio:latest:RELEASE.2025-09-07T16-13-09Z14cea493d9a3
golang.org/x/net@v0.39.0
0.45.0
16
codeurjc/toposervice:v1.0:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
0.45.0
13
jenkins/jenkins:2.568.3-jdk21:2.568.3-lts-jdk21:ltsc1e4c349365f
golang.org/x/net@v0.38.0
0.45.0
13
ghcr.io/appscode/kubectl-nonroot:1.340b26892cec94
golang.org/x/net@v0.38.0
0.45.0
13
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
golang.org/x/net@v0.23.0
0.45.0
9
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.45.0
8
quay.io/minio/minio:RELEASE.2024-12-18T13-15-44Z1dce27c494a1
golang.org/x/net@v0.29.0
0.45.0
8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
0.45.0
8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.45.0
8
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
0.45.0
7
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.45.0
7
ghcr.io/appscode/b3:v2026.9.1176d28575b71c
golang.org/x/net@v0.38.0
0.45.0
7
quay.io/minio/mc:RELEASE.2024-11-21T17-21-54Z993e8c454a7e
golang.org/x/net@v0.29.0
0.45.0
7
quay.io/thanos/thanos:v0.37.24ec6df40fdb9
golang.org/x/net@v0.30.0
0.45.0
7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.15.011f199f6bec4
golang.org/x/net@v0.40.0
0.45.0
7
registry.k8s.io/sig-storage/csi-resizer:v1.14.05e7cbb63fd49
golang.org/x/net@v0.39.0
0.45.0
7
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
0.45.0
6
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
0.45.0
6
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.45.0
6
minio/mc:latest:RELEASE.2025-08-13T08-35-41Za7fe349ef4bd
golang.org/x/net@v0.42.0
0.45.0
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.45.0
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.45.0
6
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.45.0
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.45.0
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.45.0
6
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.45.0
6
quay.io/prometheus/node-exporter:v1.10.2337ff1d356b6
golang.org/x/net@v0.44.0
0.45.0
6
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
0.45.0
6
quay.io/prometheus-operator/prometheus-config-reloader:v0.81.0959d47672fbf
golang.org/x/net@v0.37.0
0.45.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.14.037d841299325
golang.org/x/net@v0.29.0
0.45.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
golang.org/x/net@v0.26.0
0.45.0
6
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
0.45.0
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0:v2.8.1f6717ce72a26
golang.org/x/net@v0.8.0
0.45.0
6
registry.k8s.io/sig-storage/csi-provisioner:v5.3.0bb057f866177
golang.org/x/net@v0.40.0
0.45.0
6
alpine/kubectl:1.34.18413f8890d19
golang.org/x/net@v0.38.0
0.45.0
5
bitnamilegacy/kubectl:1.29.2c74b703deed2
golang.org/x/net@v0.19.0
0.45.0
5
keelhq/keel:latest73714afb4443
golang.org/x/net@v0.33.0
0.45.0
5
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
0.45.0
5
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.45.0
5
prom/memcached-exporter:v0.15.4b6763ecb3c47
golang.org/x/net@v0.44.0
0.45.0
5
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.45.0
5
quay.io/brancz/kube-rbac-proxy:v0.19.19f21034731c7
golang.org/x/net@v0.39.0
0.45.0
5
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
0.45.0
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.45.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
0.45.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
0.45.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.4.4a9f03b34a3cb
golang.org/x/net@v0.28.0
0.45.0
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.45.0
5
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
0.45.0
5
cloudflare/cloudflared:2026.3.06b599ca3e974
golang.org/x/net@v0.40.0
0.45.0
4

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.