StackRadar

CVE-2020-28502

Critical

Advisory

Published 4 May 2021In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.046
91st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
2 of 2
affected packages

xmlhttprequest and xmlhttprequest-ssl vulnerable to Arbitrary Code Injection

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
xmlhttprequest-sslnpm1.5.1, 1.5.3, 1.5.51.6.217
xmlhttprequestnpm1.5.01.7.01
OSV records
GHSA-h4j5-c7cj-74xg

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

10,311
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
xmlhttprequest-ssl@1.5.3
1.6.2

Open the chart page →

5,209
restreamerutkuozdemirVerified publisher1.1.01 of 1See more

restreamer utkuozdemir 1.1.0

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
datarhei/restreamer:0.6.4655e12f9eeed
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

2,598
scrapoxywiremindVerified publisher0.3.41 of 1See more

scrapoxy wiremind 0.3.4

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
wiremind/scrapoxy:lateste7048929a676
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

2,154
openhab-cloudandibraeuVerified publisher1.2.61 of 1See more

openhab-cloud andibraeu 1.2.6

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
openhab/openhab-cloud:a8138a329dd2bac8c4b
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

3,437
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

3,237
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
xmlhttprequest-ssl@1.5.3
1.6.2

Open the chart page →

18,277
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
xmlhttprequest-ssl@1.5.3
1.6.2

Open the chart page →

4,069
maildevcnieg1.1.11 of 1See more

maildev cnieg 1.1.1

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
cnieg/maildev:v1.1.998ee05668915
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

2,449
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
xmlhttprequest-ssl@1.5.3
1.6.2

Open the chart page →

5,209
backend-servicedev-krishan-dhaka-charts1.0.31 of 1See more

backend-service dev-krishan-dhaka-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
devkrishan001/backend:latestf1c3acadeabe
xmlhttprequest@1.5.0
1.7.0

Open the chart page →

1,264
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

4,043
theloungegeek-cookbookVerified publisher3.4.21 of 1See more

thelounge geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
thelounge/thelounge:4.2.0-alpine639978459c3a
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

2,689
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

2,682
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
xmlhttprequest-ssl@1.5.5
1.6.2
ibmcom/microclimate-portal:latested5505e5c7ec
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

57,669
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

10,494
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
xmlhttprequest-ssl@1.5.3
1.6.2

Open the chart page →

6,454
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
xmlhttprequest-ssl@1.5.1
1.6.2
linuxserver/codimd:latestb801bbcf6386
xmlhttprequest-ssl@1.5.5
1.6.2

Open the chart page →

27,465
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2020-28502.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
xmlhttprequest-ssl@1.5.1
1.6.2

Open the chart page →

3,827

Container images carrying it

18 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
pantsel/konga:latestc8172b75607d
xmlhttprequest-ssl@1.5.3
1.6.2
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
xmlhttprequest-ssl@1.5.5
1.6.2
3
cnieg/maildev:v1.1.998ee05668915
xmlhttprequest-ssl@1.5.5
1.6.2
1
datarhei/restreamer:0.6.4655e12f9eeed
xmlhttprequest-ssl@1.5.5
1.6.2
1
devkrishan001/backend:latestf1c3acadeabe
xmlhttprequest@1.5.0
1.7.0
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
xmlhttprequest-ssl@1.5.5
1.6.2
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
xmlhttprequest-ssl@1.5.5
1.6.2
1
ibmcom/microclimate-portal:latested5505e5c7ec
xmlhttprequest-ssl@1.5.5
1.6.2
1
inseefrlab/shelly:cloudshell31f04ca7436b
xmlhttprequest-ssl@1.5.5
1.6.2
1
jayfong/yapi:1.10.2163e5d621910
xmlhttprequest-ssl@1.5.3
1.6.2
1
konradkleine/docker-registry-frontend:v2181aad54ee64
xmlhttprequest-ssl@1.5.3
1.6.2
1
linuxserver/cloud9:latest45c5fe102ff3
xmlhttprequest-ssl@1.5.1
1.6.2
1
linuxserver/codimd:latestb801bbcf6386
xmlhttprequest-ssl@1.5.5
1.6.2
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
xmlhttprequest-ssl@1.5.5
1.6.2
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
xmlhttprequest-ssl@1.5.5
1.6.2
1
thelounge/thelounge:4.2.0-alpine639978459c3a
xmlhttprequest-ssl@1.5.5
1.6.2
1
wiremind/scrapoxy:lateste7048929a676
xmlhttprequest-ssl@1.5.5
1.6.2
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
xmlhttprequest-ssl@1.5.1
1.6.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.