StackRadar

CVE-2021-43138

High

Advisory

Published 7 Apr 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.033
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
116
of 17,781 indexed, latest versions
Container images
106
deployed by those charts
Fix available
1 of 1
affected package

Prototype Pollution in async

Carried by container images the latest versions of 116 of 17,781 indexed charts deploy, on 106 images.

Affected packageAffected versionsFixed inImages
asyncnpm2.0.1, 2.3.0, 2.4.0, 2.5.0+8 more2.6.4, 3.2.2106
OSV records
GHSA-fwr7-v2mv-hh25

Charts affected

116 by stars
ChartLatestAffected imagesRadar Score
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
async@3.2.1
3.2.2

Open the chart page →

3,228
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
async@2.6.3
2.6.4

Open the chart page →

2,121
alert-mappersomeblackmagic0.2.01 of 1See more

alert-mapper someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
someblackmagic/alert-mapper:v0.1.088351d85c04c
async@2.6.3
2.6.4

Open the chart page →

1,890
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
async@2.6.3
2.6.4

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
async@2.6.3
2.6.4

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
async@2.6.3
2.6.4

Open the chart page →

3,881
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
async@2.5.0
2.6.4

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
async@2.5.0
2.6.4

Open the chart page →

12,460
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
async@3.1.1
3.2.2

Open the chart page →

3,827
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
async@2.6.3
2.6.4

Open the chart page →

4,017
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
async@2.0.1
2.6.4

Open the chart page →

3,576
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
async@3.2.1
3.2.2

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
async@3.2.1
3.2.2

Open the chart page →

28,605
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
async@2.6.3
2.6.4

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
async@2.6.3
2.6.4

Open the chart page →

22,665
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
async@3.2.0
3.2.2

Open the chart page →

5,806

Container images carrying it

106 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ibmcom/microclimate-portal:latested5505e5c7ec
async@2.6.0
2.6.4
1
jayfong/yapi:1.10.2163e5d621910
async@2.6.3
2.6.4
1
jesec/flood:4.7.03d1d0bec117a
async@2.6.3
2.6.4
1
jesec/flood:4.6.060bd59cfb4eb
async@2.6.3
2.6.4
1
jesec/rtorrent-flood:latestf0c894ec459e
async@2.6.3
2.6.4
1
jupyterhub/configurable-http-proxy:4.2.281bd96729c14
async@3.2.0
3.2.2
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
async@2.6.3
2.6.4
1
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
async@3.2.0
3.2.2
1
lavandadelpatio/frontend:latest501c3f31e0bc
async@2.6.3
2.6.4
1
library/ghost:4.37.0767230c0f263
async@2.6.3
2.6.4
1
linuxserver/codimd:latestb801bbcf6386
async@3.2.0
3.2.2
1
lissy93/dashy:2.0.51991f7be5ed0
async@2.6.3
2.6.4
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
async@2.6.3
2.6.4
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
async@2.5.0
2.6.4
1
minddocdev/hubot:0.1.96c60b11a4fa7
async@2.6.1
2.6.4
1
misskey/misskey:12.110.1e08b7c478093
async@2.6.3
2.6.4
1
mozilla/sentencecollector:2.0.91da6ff5c4895
async@3.2.0
3.2.2
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
async@3.2.0
3.2.2
1
phntom/codimd:2.4.31b9aafbb62e6
async@2.6.3
2.6.4
1
polonel/trudesk:1.2.60cf6513f6fe3
async@2.6.3
2.6.4
1
requarks/wiki:canary-2.5.2438b5865a7386c
async@2.6.3
2.6.4
1
roadiehq/community-backstage-image:latestef355bf5b639
async@2.6.3
2.6.4
1
shinobisystems/shinobi:dev3ca746937856
async@2.6.3
2.6.4
1
shinobisystems/shinobi:latestc2f5ce2e1067
async@3.2.0
3.2.2
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
async@2.6.3
2.6.4
1
socialmediamacroscope/smile_server:0.3.31a528c794270
async@2.3.0
2.6.4
1
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
async@2.6.3
2.6.4
1
someblackmagic/alert-mapper:v0.1.088351d85c04c
async@2.6.3
2.6.4
1
sqlpad/sqlpad:6.7d3d2f430dffd
async@3.2.0
3.2.2
1
taigaio/taiga-events:6.4.00bf2d24a57d9
async@3.2.0
3.2.2
1
temporalio/web:1.14.033cfa863d8ce
async@2.6.3
2.6.4
1
testhubio/testhub-frontend:on-preme86c2db53be8
async@2.6.3
2.6.4
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
async@2.6.3
2.6.4
1
tzahi12345/youtubedl-material:4.23720b856bd2f
async@2.6.3
2.6.4
1
ubercadence/web:v3.29.58564a5b44a6d
async@2.6.3
2.6.4
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
async@2.6.3
2.6.4
1
willwill/kube-slack:v4.1.1d443017aae98
async@2.6.1
2.6.4
1
zazuko/trifid:2.3.7054be137de70
async@2.6.3
2.6.4
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
async@2.6.3
2.6.4
1
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
async@3.2.0
3.2.2
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
async@3.2.0
3.2.2
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
async@2.6.3
2.6.4
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
async@2.6.3
2.6.4
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
async@3.2.0
3.2.2
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
async@2.6.3
2.6.4
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
async@3.2.0
3.2.2
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
async@2.6.3
2.6.4
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
async@3.2.0
3.2.2
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
async@2.6.3
2.6.4
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
async@2.6.3
2.6.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.