StackRadar

CVE-2021-23438

Medium

Advisory

Published 2 Sept 2021In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
5.6
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Type confusion in mpath

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
mpathnpm0.3.0, 0.5.2, 0.6.0, 0.8.30.8.49
OSV records
GHSA-p92x-r36w-9395

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2021-23438.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
mpath@0.3.0
0.8.4

Open the chart page →

25,443
backend-charteks-3-tier-app-chart0.1.01 of 1See more

backend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-23438.

Container imageDigestPackageFixed in
arfath29/3-tier-app-backend:latestee0750b18406
mpath@0.8.3
0.8.4

Open the chart page →

1,693
iotagent-ulfiware0.1.21 of 1See more

iotagent-ul fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-23438.

Container imageDigestPackageFixed in
fiware/iotagent-ul:1.14.0fe11f55a926d
mpath@0.6.0
0.8.4

Open the chart page →

3,337
Governify-Bluejaygovernify0.1.02 of 12See more

Governify-Bluejay governify 0.1.0

2 of the 12 container images this version deploys carry CVE-2021-23438.

Container imageDigestPackageFixed in
governify/director:v1.4.0608c6940bb98
mpath@0.5.2
0.8.4
governify/registry:v3.4.0d3f37f4f8168
mpath@0.5.2
0.8.4

Open the chart page →

22,512
Governify-Falcongovernify0.1.03 of 10See more

Governify-Falcon governify 0.1.0

3 of the 10 container images this version deploys carry CVE-2021-23438.

Container imageDigestPackageFixed in
governify/collector-dynamic:v1.3.06d3d1a5b46a9
mpath@0.5.2
0.8.4
governify/director:v1.4.0608c6940bb98
mpath@0.5.2
0.8.4
governify/registry:v3.4.0d3f37f4f8168
mpath@0.5.2
0.8.4

Open the chart page →

24,319
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-23438.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
mpath@0.6.0
0.8.4

Open the chart page →

6,454
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2021-23438.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
mpath@0.8.3
0.8.4

Open the chart page →

12,108
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2021-23438.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
mpath@0.8.3
0.8.4

Open the chart page →

19,226
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-23438.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
mpath@0.8.3
0.8.4

Open the chart page →

6,881

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
governify/director:v1.4.0608c6940bb98
mpath@0.5.2
0.8.4
2
governify/registry:v3.4.0d3f37f4f8168
mpath@0.5.2
0.8.4
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
mpath@0.8.3
0.8.4
2
arfath29/3-tier-app-backend:latestee0750b18406
mpath@0.8.3
0.8.4
1
denisshav/backend:latest4cc8dc5a4499
mpath@0.8.3
0.8.4
1
fiware/iotagent-ul:1.14.0fe11f55a926d
mpath@0.6.0
0.8.4
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
mpath@0.5.2
0.8.4
1
jayfong/yapi:1.10.2163e5d621910
mpath@0.6.0
0.8.4
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
mpath@0.3.0
0.8.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.