StackRadar

CVE-2018-1107

Medium

Advisory

Published 6 Jan 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
13
deployed by those charts
Fix available
1 of 1
affected package

Regular expression deinal of service (ReDoS) in is-my-json-valid

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 13 images.

Affected packageAffected versionsFixed inImages
is-my-json-validnpm2.12.2, 2.13.1, 2.15.0, 2.16.12.17.213
OSV records
GHSA-4hpf-3wq7-5rpr

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
microcks/microcks-postman-runtime:latestcb72e46a1b3c
is-my-json-valid@2.15.0
2.17.2

Open the chart page →

10,732
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
is-my-json-valid@2.16.1
2.17.2

Open the chart page →

5,209
splice-helmsplice-helm0.1.71 of 13See more

splice-helm splice-helm 0.1.7

1 of the 13 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:3.0.0c36cf3cc1c99
is-my-json-valid@2.15.0
2.17.2

Open the chart page →

1,477
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
is-my-json-valid@2.16.1
2.17.2

Open the chart page →

18,277
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
is-my-json-valid@2.12.2
2.17.2

Open the chart page →

12,779
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
is-my-json-valid@2.12.2
2.17.2

Open the chart page →

27,417
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
is-my-json-valid@2.15.0
2.17.2

Open the chart page →

77,758
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
is-my-json-valid@2.16.1
2.17.2

Open the chart page →

5,209
logentriesfairwinds-incubator0.2.21 of 1See more

logentries fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
logentries/docker-logentries:0.2.1f1f90a236998
is-my-json-valid@2.15.0
2.17.2

Open the chart page →

1,597
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
is-my-json-valid@2.15.0
2.17.2

Open the chart page →

5,941
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
is-my-json-valid@2.15.0
2.17.2

Open the chart page →

4,614
nubladolsst-sqre0.9.231 of 5See more

nublado lsst-sqre 0.9.23

1 of the 5 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
lsstsqre/sciplat-hub:latest5e0ade6bed1c
is-my-json-valid@2.15.0
2.17.2

Open the chart page →

5,786
monocularmonocular1.4.151 of 5See more

monocular monocular 1.4.15

1 of the 5 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
is-my-json-valid@2.15.0
2.17.2

Open the chart page →

7,048
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
is-my-json-valid@2.13.1
2.17.2

Open the chart page →

27,465
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
is-my-json-valid@2.12.2
2.17.2

Open the chart page →

36,215
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2018-1107.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
is-my-json-valid@2.15.0
2.17.2

Open the chart page →

3,638

Container images carrying it

13 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
pantsel/konga:latestc8172b75607d
is-my-json-valid@2.16.1
2.17.2
3
migmartri/prerender:latest486aacfd5aa9
is-my-json-valid@2.15.0
2.17.2
2
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
is-my-json-valid@2.12.2
2.17.2
1
jupyterhub/configurable-http-proxy:3.0.0c36cf3cc1c99
is-my-json-valid@2.15.0
2.17.2
1
linuxserver/cloud9:latest45c5fe102ff3
is-my-json-valid@2.13.1
2.17.2
1
logentries/docker-logentries:0.2.1f1f90a236998
is-my-json-valid@2.15.0
2.17.2
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
is-my-json-valid@2.15.0
2.17.2
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
is-my-json-valid@2.15.0
2.17.2
1
openthread/otbr:latestf307f59f6432
is-my-json-valid@2.12.2
2.17.2
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
is-my-json-valid@2.12.2
2.17.2
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
is-my-json-valid@2.15.0
2.17.2
1
wekanteam/wekan:v4.2268a51f0327df
is-my-json-valid@2.15.0
2.17.2
1
quay.io/wekan/wekan:v5.65cb17600883a3
is-my-json-valid@2.15.0
2.17.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.