ghcr.io/dexidp/dex:v2.45.1

container image

Deployed by 1 of 300 indexed charts (latest versions) at this tag.Counts say nothing about images outside the indexed set.

Radar Score

1,104
worst finding Medium
Critical
0
High
0
Medium
9
Low
124
On CISA KEV
0
Exploited (EPSS ≥ 0.1)
0

133 findings on digest 8499afd690c4 · scanned 2 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

History

Radar Score of ghcr.io/dexidp/dex:v2.45.1 across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.

2 Sept 2026 · Radar Score 1,104 · OSV as of 2 Sept 2026 · digest 8499afd690c4
history since 2 Sept 2026

Findings

showing 50 of 133

Findings for digest 8499afd690c4 as scanned on 2 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Sept 2026. Other architectures may differ.

AdvisoryPackageFixed inContributionEPSSSince
GHSA-5cgq-3rg8-m6cv

golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status

golang.org/x/crypto@v0.48.0golang0.52.038/1000.073 (94th pct)2 Sept 2026
GHSA-2x32-jm95-2cpx

Authentication Bypass in dex

github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang2.27.025/1000.017 (75th pct)2 Sept 2026
GHSA-m9hp-7r99-94h5

Critical security issues in XML encoding in github.com/dexidp/dex

github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang2.27.024/1000.017 (75th pct)2 Sept 2026
GHSA-p77j-4mvh-x3m3

gRPC-Go has an authorization bypass via missing leading slash in :path

google.golang.org/grpc@v1.77.0golang1.79.323/1000.016 (73th pct)2 Sept 2026
GHSA-vh7g-p26c-j2cw

Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code

github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang2.35.021/1000.012 (66th pct)2 Sept 2026
GHSA-x527-x647-q7gg

golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement

golang.org/x/crypto@v0.48.0golang0.52.017/1000.005 (41th pct)2 Sept 2026
GHSA-vgwf-h737-ff37

golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses

golang.org/x/crypto@v0.48.0golang0.52.017/1000.006 (47th pct)2 Sept 2026
GHSA-f5wc-c3c7-36mc

golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys

golang.org/x/crypto@v0.48.0golang0.52.017/1000.006 (46th pct)2 Sept 2026
GHSA-rm3j-f69w-wqmq

golang.org/x/crypto vulnerable to infinite loop on large channel writes

golang.org/x/crypto@v0.48.0golang0.52.016/1000.005 (42th pct)2 Sept 2026
GHSA-89gr-r52h-f8rx

golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed

golang.org/x/crypto@v0.48.0golang0.52.015/1000.004 (35th pct)2 Sept 2026
GHSA-jppx-rxg9-jmrx

golang.org/x/crypto doesn't enforce invoking key constraints

golang.org/x/crypto@v0.48.0golang0.52.015/1000.004 (34th pct)2 Sept 2026
GHSA-mh2q-q3fh-2475

OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

go.opentelemetry.io/otel@v1.39.0golang1.41.014/1000.007 (48th pct)2 Sept 2026
GHSA-78h2-9frx-2jm8

Go JOSE Panics in JWE decryption

github.com/go-jose/go-jose/v4@v4.1.3golang4.1.414/1000.007 (48th pct)2 Sept 2026
GHSA-q4h4-gmj2-qvw2

golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic

golang.org/x/crypto@v0.48.0golang0.52.013/1000.005 (39th pct)2 Sept 2026
GHSA-w879-237q-wc7r

golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS

golang.org/x/crypto@v0.48.0golang0.52.013/1000.005 (38th pct)2 Sept 2026
GHSA-qw64-3x98-g7q2

go-billy has path traversal vulnerabilities

github.com/go-git/go-billy/v5@v5.7.0golang5.9.012/1000.003 (23th pct)2 Sept 2026
GHSA-pjcq-xvwq-hhpj

go-ntlmssp NTLM challenges can panic on malformed payloads

github.com/Azure/go-ntlmssp@v0.0.0-20221128193559-754e69321358golang0.1.112/1000.010 (61th pct)2 Sept 2026
GHSA-hc8v-wwc9-vgxm

go-git: Worktree operations may follow symlinks

github.com/go-git/go-git/v5@v5.16.4golang5.19.211/1000.004 (29th pct)2 Sept 2026
GHSA-479m-364c-43vc

validateSignature Loop Variable Capture Signature Bypass in goxmldsig

github.com/russellhaering/goxmldsig@v1.5.0golang1.6.011/1000.003 (22th pct)2 Sept 2026
GHSA-m3xc-h892-ggx6

go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion

github.com/go-git/go-billy/v5@v5.7.0golang5.9.010/1000.004 (32th pct)2 Sept 2026
GHSA-qgq7-7hm3-q39j

go-git: Malicious reference names may modify files outside the reference storage

github.com/go-git/go-git/v5@v5.16.4golang5.19.210/1000.004 (34th pct)2 Sept 2026
GHSA-hfvc-g4fc-pqhx

opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking

go.opentelemetry.io/otel/sdk@v1.39.0golang1.43.010/1000.003 (17th pct)2 Sept 2026
GHSA-q9hv-hpm4-hj6x

CIRCL has an incorrect calculation in secp384r1 CombinedMult

github.com/cloudflare/circl@v1.6.1golang1.6.310/1000.004 (33th pct)2 Sept 2026
ALPINE-CVE-2026-31789openssl@3.5.5-r0apk3.5.6-r010/1002 Sept 2026
ALPINE-CVE-2026-63073openssl@3.5.5-r0apk3.5.8-r010/1002 Sept 2026
GHSA-45gg-vh54-h5m9

golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions

golang.org/x/crypto@v0.48.0golang0.52.010/1000.004 (30th pct)2 Sept 2026
GHSA-5cv4-jp36-h3mw

Go Net HTML parser is vulnerable to denial of service

golang.org/x/net@v0.50.0golang0.55.010/1000.003 (25th pct)2 Sept 2026
GHSA-qpw4-5x99-6vjp

golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS

golang.org/x/crypto@v0.48.0golang0.52.09/1000.003 (20th pct)2 Sept 2026
ALPINE-CVE-2026-34182openssl@3.5.5-r0apk3.5.7-r09/1002 Sept 2026
ALPINE-CVE-2026-75803openssl@3.5.5-r0apk3.5.8-r09/1002 Sept 2026
GHSA-78mq-xcr3-xm33

golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow

golang.org/x/crypto@v0.48.0golang0.52.09/1000.005 (41th pct)2 Sept 2026
ALPINE-CVE-2026-45447openssl@3.5.5-r0apk3.5.7-r09/1002 Sept 2026
GHSA-hrxh-6v49-42gf

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

google.golang.org/grpc@v1.77.0golang1.82.19/1002 Sept 2026
GHSA-vp52-pcj8-j9qc

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

google.golang.org/grpc@v1.77.0golang1.83.19/1002 Sept 2026
GHSA-9m57-25v3-79x9

golang.org/x/crypto: Invoking pathological inputs can lead to client panic

golang.org/x/crypto@v0.48.0golang0.52.08/1000.004 (34th pct)2 Sept 2026
GHSA-389r-gv7p-r3rp

go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git

github.com/go-git/go-git/v5@v5.16.4golang5.19.08/1000.002 (5th pct)2 Sept 2026
GHSA-9h8m-3fm2-qjrq

OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking

go.opentelemetry.io/otel/sdk@v1.39.0golang1.40.08/1000.002 (5th pct)2 Sept 2026
ALPINE-CVE-2026-28387openssl@3.5.5-r0apk3.5.6-r08/1002 Sept 2026
ALPINE-CVE-2026-40200musl@1.2.5-r21apk1.2.5-r238/1002 Sept 2026
ALPINE-CVE-2026-7383openssl@3.5.5-r0apk3.5.7-r08/1002 Sept 2026
GO-2026-4981

Crash when handling long CNAME response in net

stdlib@go1.26.0golang1.25.108/1000.008 (54th pct)2 Sept 2026
GO-2026-4977

Quadratic string concatenation in consumePhrase in net/mail

stdlib@go1.26.0golang1.25.108/1000.008 (54th pct)2 Sept 2026
GO-2026-4986

Quadratic string concatentation in consumeComment in net/mail

stdlib@go1.26.0golang1.25.108/1000.008 (53th pct)2 Sept 2026
GO-2026-4918

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

golang.org/x/net@v0.50.0golang0.53.08/1000.008 (53th pct)2 Sept 2026
GO-2026-4918

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

stdlib@go1.26.0golang1.25.108/1000.008 (53th pct)2 Sept 2026
GO-2026-4337

Unexpected session resumption in crypto/tls

stdlib@go1.25.6golang1.24.138/1000.008 (52th pct)2 Sept 2026
ALPINE-CVE-2026-22184zlib@1.3.1-r2apk1.3.2-r08/1002 Sept 2026
GHSA-crhj-59gh-8x96

go-git: Crafted repositories may modify main and submodule .git directories

github.com/go-git/go-git/v5@v5.16.4golang5.19.18/1000.003 (22th pct)2 Sept 2026
GO-2026-4601

Incorrect parsing of IPv6 host literals in net/url

stdlib@go1.26.0golang1.25.88/1000.007 (51th pct)2 Sept 2026
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

golang.org/x/net@v0.50.0golang0.55.08/1000.007 (50th pct)2 Sept 2026

All 133 findings

Tags and digests

Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.

TagDigestPlatformFirst seenLast seenRadar Score
v2.45.1current8499afd690c4linux/amd642 Sept 20262 Sept 20261,104

Used by

Charts whose default render references this repository, with the workload that carries it.

syft 1.42.1 · scanned 2 Sept 2026 · advisories as of 2 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.