ghcr.io/dexidp/dex:v2.45.1
container imageDeployed by 1 of 300 indexed charts (latest versions) at this tag.Counts say nothing about images outside the indexed set.
Radar Score
- Critical
- 0
- High
- 0
- Medium
- 9
- Low
- 124
- On CISA KEV
- 0
- Exploited (EPSS ≥ 0.1)
- 0
133 findings on digest 8499afd690c4 · scanned 2 Sept 2026
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
History
Radar Score of ghcr.io/dexidp/dex:v2.45.1 across its scanned digests, one point per day (the last scan of the day), last 90 days. Hover a point for its date, digest and advisory data.
Findings
showing 50 of 133
Findings for digest 8499afd690c4 as scanned on 2 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 2 Sept 2026. Other architectures may differ.
| Advisory | Package | Fixed in | Contribution | EPSS | Since |
|---|---|---|---|---|---|
| GHSA-5cgq-3rg8-m6cv golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 38/100 | 0.073 (94th pct) | 2 Sept 2026 |
| GHSA-2x32-jm95-2cpx Authentication Bypass in dex | github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang | 2.27.0 | 25/100 | 0.017 (75th pct) | 2 Sept 2026 |
| GHSA-m9hp-7r99-94h5 Critical security issues in XML encoding in github.com/dexidp/dex | github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang | 2.27.0 | 24/100 | 0.017 (75th pct) | 2 Sept 2026 |
| GHSA-p77j-4mvh-x3m3 gRPC-Go has an authorization bypass via missing leading slash in :path | google.golang.org/grpc@v1.77.0golang | 1.79.3 | 23/100 | 0.016 (73th pct) | 2 Sept 2026 |
| GHSA-vh7g-p26c-j2cw Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code | github.com/dexidp/dex@v0.0.0-20260303133905-11d2eeb52b42golang | 2.35.0 | 21/100 | 0.012 (66th pct) | 2 Sept 2026 |
| GHSA-x527-x647-q7gg golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 17/100 | 0.005 (41th pct) | 2 Sept 2026 |
| GHSA-vgwf-h737-ff37 golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 17/100 | 0.006 (47th pct) | 2 Sept 2026 |
| GHSA-f5wc-c3c7-36mc golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 17/100 | 0.006 (46th pct) | 2 Sept 2026 |
| GHSA-rm3j-f69w-wqmq golang.org/x/crypto vulnerable to infinite loop on large channel writes | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 16/100 | 0.005 (42th pct) | 2 Sept 2026 |
| GHSA-89gr-r52h-f8rx golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 15/100 | 0.004 (35th pct) | 2 Sept 2026 |
| GHSA-jppx-rxg9-jmrx golang.org/x/crypto doesn't enforce invoking key constraints | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 15/100 | 0.004 (34th pct) | 2 Sept 2026 |
| GHSA-mh2q-q3fh-2475 OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) | go.opentelemetry.io/otel@v1.39.0golang | 1.41.0 | 14/100 | 0.007 (48th pct) | 2 Sept 2026 |
| GHSA-78h2-9frx-2jm8 Go JOSE Panics in JWE decryption | github.com/go-jose/go-jose/v4@v4.1.3golang | 4.1.4 | 14/100 | 0.007 (48th pct) | 2 Sept 2026 |
| GHSA-q4h4-gmj2-qvw2 golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 13/100 | 0.005 (39th pct) | 2 Sept 2026 |
| GHSA-w879-237q-wc7r golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 13/100 | 0.005 (38th pct) | 2 Sept 2026 |
| GHSA-qw64-3x98-g7q2 go-billy has path traversal vulnerabilities | github.com/go-git/go-billy/v5@v5.7.0golang | 5.9.0 | 12/100 | 0.003 (23th pct) | 2 Sept 2026 |
| GHSA-pjcq-xvwq-hhpj go-ntlmssp NTLM challenges can panic on malformed payloads | github.com/Azure/go-ntlmssp@v0.0.0-20221128193559-754e69321358golang | 0.1.1 | 12/100 | 0.010 (61th pct) | 2 Sept 2026 |
| GHSA-hc8v-wwc9-vgxm go-git: Worktree operations may follow symlinks | github.com/go-git/go-git/v5@v5.16.4golang | 5.19.2 | 11/100 | 0.004 (29th pct) | 2 Sept 2026 |
| GHSA-479m-364c-43vc validateSignature Loop Variable Capture Signature Bypass in goxmldsig | github.com/russellhaering/goxmldsig@v1.5.0golang | 1.6.0 | 11/100 | 0.003 (22th pct) | 2 Sept 2026 |
| GHSA-m3xc-h892-ggx6 go-billy: Lack of depth and cycle detection in symlink resolution may lead to infinite loops and resource exhaustion | github.com/go-git/go-billy/v5@v5.7.0golang | 5.9.0 | 10/100 | 0.004 (32th pct) | 2 Sept 2026 |
| GHSA-qgq7-7hm3-q39j go-git: Malicious reference names may modify files outside the reference storage | github.com/go-git/go-git/v5@v5.16.4golang | 5.19.2 | 10/100 | 0.004 (34th pct) | 2 Sept 2026 |
| GHSA-hfvc-g4fc-pqhx opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking | go.opentelemetry.io/otel/sdk@v1.39.0golang | 1.43.0 | 10/100 | 0.003 (17th pct) | 2 Sept 2026 |
| GHSA-q9hv-hpm4-hj6x CIRCL has an incorrect calculation in secp384r1 CombinedMult | github.com/cloudflare/circl@v1.6.1golang | 1.6.3 | 10/100 | 0.004 (33th pct) | 2 Sept 2026 |
| ALPINE-CVE-2026-31789 | openssl@3.5.5-r0apk | 3.5.6-r0 | 10/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-63073 | openssl@3.5.5-r0apk | 3.5.8-r0 | 10/100 | — | 2 Sept 2026 |
| GHSA-45gg-vh54-h5m9 golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 10/100 | 0.004 (30th pct) | 2 Sept 2026 |
| GHSA-5cv4-jp36-h3mw Go Net HTML parser is vulnerable to denial of service | golang.org/x/net@v0.50.0golang | 0.55.0 | 10/100 | 0.003 (25th pct) | 2 Sept 2026 |
| GHSA-qpw4-5x99-6vjp golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 9/100 | 0.003 (20th pct) | 2 Sept 2026 |
| ALPINE-CVE-2026-34182 | openssl@3.5.5-r0apk | 3.5.7-r0 | 9/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-75803 | openssl@3.5.5-r0apk | 3.5.8-r0 | 9/100 | — | 2 Sept 2026 |
| GHSA-78mq-xcr3-xm33 golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 9/100 | 0.005 (41th pct) | 2 Sept 2026 |
| ALPINE-CVE-2026-45447 | openssl@3.5.5-r0apk | 3.5.7-r0 | 9/100 | — | 2 Sept 2026 |
| GHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities | google.golang.org/grpc@v1.77.0golang | 1.82.1 | 9/100 | — | 2 Sept 2026 |
| GHSA-vp52-pcj8-j9qc gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | google.golang.org/grpc@v1.77.0golang | 1.83.1 | 9/100 | — | 2 Sept 2026 |
| GHSA-9m57-25v3-79x9 golang.org/x/crypto: Invoking pathological inputs can lead to client panic | golang.org/x/crypto@v0.48.0golang | 0.52.0 | 8/100 | 0.004 (34th pct) | 2 Sept 2026 |
| GHSA-389r-gv7p-r3rp go-git's improper parsing of specially crafted objects may lead to inconsistent interpretation compared to upstream Git | github.com/go-git/go-git/v5@v5.16.4golang | 5.19.0 | 8/100 | 0.002 (5th pct) | 2 Sept 2026 |
| GHSA-9h8m-3fm2-qjrq OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking | go.opentelemetry.io/otel/sdk@v1.39.0golang | 1.40.0 | 8/100 | 0.002 (5th pct) | 2 Sept 2026 |
| ALPINE-CVE-2026-28387 | openssl@3.5.5-r0apk | 3.5.6-r0 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-40200 | musl@1.2.5-r21apk | 1.2.5-r23 | 8/100 | — | 2 Sept 2026 |
| ALPINE-CVE-2026-7383 | openssl@3.5.5-r0apk | 3.5.7-r0 | 8/100 | — | 2 Sept 2026 |
| GO-2026-4981 Crash when handling long CNAME response in net | stdlib@go1.26.0golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GO-2026-4977 Quadratic string concatenation in consumePhrase in net/mail | stdlib@go1.26.0golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 |
| GO-2026-4986 Quadratic string concatentation in consumeComment in net/mail | stdlib@go1.26.0golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | golang.org/x/net@v0.50.0golang | 0.53.0 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | stdlib@go1.26.0golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 |
| GO-2026-4337 Unexpected session resumption in crypto/tls | stdlib@go1.25.6golang | 1.24.13 | 8/100 | 0.008 (52th pct) | 2 Sept 2026 |
| ALPINE-CVE-2026-22184 | zlib@1.3.1-r2apk | 1.3.2-r0 | 8/100 | — | 2 Sept 2026 |
| GHSA-crhj-59gh-8x96 go-git: Crafted repositories may modify main and submodule .git directories | github.com/go-git/go-git/v5@v5.16.4golang | 5.19.1 | 8/100 | 0.003 (22th pct) | 2 Sept 2026 |
| GO-2026-4601 Incorrect parsing of IPv6 host literals in net/url | stdlib@go1.26.0golang | 1.25.8 | 8/100 | 0.007 (51th pct) | 2 Sept 2026 |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | golang.org/x/net@v0.50.0golang | 0.55.0 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 |
Tags and digests
Tags observed in indexed charts’ default renders and the digest each resolved to when last seen. A tag can move; the digest is what was scanned.
| Tag | Digest | Platform | First seen | Last seen | Radar Score |
|---|---|---|---|---|---|
| v2.45.1current | 8499afd690c4 | linux/amd64 | 2 Sept 2026 | 2 Sept 2026 | 1,104 |