StackRadar

CVE-2019-18888

High

Advisory

Published 2 Dec 2019In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
13
of 17,781 indexed, latest versions
Container images
6
deployed by those charts
Fix available
1 of 1
affected package

Argument injection in a MimeTypeGuesser in Symfony

Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
symfony/http-foundationcomposerv2.6.13, v2.7.51, v2.8.34, v3.0.9+2 more2.8.52, 3.4.356
OSV records
GHSA-xhh6-956q-4q69

Charts affected

13 by stars
ChartLatestAffected imagesRadar Score
cachetdeliveryheroVerified publisher1.3.51 of 2See more

cachet deliveryhero 1.3.5

1 of the 2 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
symfony/http-foundation@v3.0.9
3.4.35

Open the chart page →

1,896
cachetadnoctemVerified publisher0.3.31 of 2See more

cachet adnoctem 0.3.3

1 of the 2 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
symfony/http-foundation@v3.0.9
3.4.35

Open the chart page →

1,896
satisfyanapsixVerified publisher1.1.31 of 1See more

satisfy anapsix 1.1.3

1 of the 1 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
symfony/http-foundation@v3.4.14
3.4.35

Open the chart page →

1,572
polrchristianhuthVerified publisher4.3.01 of 2See more

polr christianhuth 4.3.0

1 of the 2 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
ajanvier/polr:2.3.091ac61b88c85
symfony/http-foundation@v2.7.51
2.8.52

Open the chart page →

5,904
satisfycloudnativeapp1.0.01 of 1See more

satisfy cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
symfony/http-foundation@v3.4.14
3.4.35

Open the chart page →

1,572
mauticdevtron0.1.31 of 3See more

mautic devtron 0.1.3

1 of the 3 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
symfony/http-foundation@v2.8.34
2.8.52

Open the chart page →

2,939
mauticdevtron-labs0.1.31 of 3See more

mautic devtron-labs 0.1.3

1 of the 3 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
symfony/http-foundation@v2.8.34
2.8.52

Open the chart page →

2,939
cachethelm-charts-nr1.3.51 of 2See more

cachet helm-charts-nr 1.3.5

1 of the 2 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
symfony/http-foundation@v3.0.9
3.4.35

Open the chart page →

1,896
freescoutl4gVerified publisher0.1.01 of 3See more

freescout l4g 0.1.0

1 of the 3 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
symfony/http-foundation@v3.4.18
3.4.35

Open the chart page →

5,332
podcast-helmpodcastwala-helm0.1.01 of 2See more

podcast-helm podcastwala-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
shivani446/podcastwala-php:v1c0d07b7b4c8d
symfony/http-foundation@v2.6.13
2.8.52

Open the chart page →

621
mauticromholdings0.1.31 of 3See more

mautic romholdings 0.1.3

1 of the 3 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
symfony/http-foundation@v2.8.34
2.8.52

Open the chart page →

2,939
cachetsergiotocaliniVerified publisher1.0.01 of 1See more

cachet sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
symfony/http-foundation@v3.0.9
3.4.35

Open the chart page →

1,896
satisfyymrs1.0.21 of 1See more

satisfy ymrs 1.0.2

1 of the 1 container images this version deploys carry CVE-2019-18888.

Container imageDigestPackageFixed in
anapsix/satisfydigest-pinnedfae78e3809e9
symfony/http-foundation@v3.4.14
3.4.35

Open the chart page →

1,572

Container images carrying it

6 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
cachethq/docker:2.3.15a61ff0f67ea7
symfony/http-foundation@v3.0.9
3.4.35
4
anapsix/satisfyfae78e3809e9
symfony/http-foundation@v3.4.14
3.4.35
3
mautic/mautic:2.13-apachea954c5868d76
symfony/http-foundation@v2.8.34
2.8.52
3
ajanvier/polr:2.3.091ac61b88c85
symfony/http-foundation@v2.7.51
2.8.52
1
shivani446/podcastwala-php:v1c0d07b7b4c8d
symfony/http-foundation@v2.6.13
2.8.52
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
symfony/http-foundation@v3.4.18
3.4.35
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.