StackRadar

CVE-2021-43138

High

Advisory

Published 7 Apr 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.033
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
116
of 17,781 indexed, latest versions
Container images
106
deployed by those charts
Fix available
1 of 1
affected package

Prototype Pollution in async

Carried by container images the latest versions of 116 of 17,781 indexed charts deploy, on 106 images.

Affected packageAffected versionsFixed inImages
asyncnpm2.0.1, 2.3.0, 2.4.0, 2.5.0+8 more2.6.4, 3.2.2106
OSV records
GHSA-fwr7-v2mv-hh25

Charts affected

116 by stars
ChartLatestAffected imagesRadar Score
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
async@3.2.1
3.2.2

Open the chart page →

3,228
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
async@2.6.3
2.6.4

Open the chart page →

2,121
alert-mappersomeblackmagic0.2.01 of 1See more

alert-mapper someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
someblackmagic/alert-mapper:v0.1.088351d85c04c
async@2.6.3
2.6.4

Open the chart page →

1,890
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
async@2.6.3
2.6.4

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
async@2.6.3
2.6.4

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
async@2.6.3
2.6.4

Open the chart page →

3,881
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
async@2.5.0
2.6.4

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
async@2.5.0
2.6.4

Open the chart page →

12,460
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
async@3.1.1
3.2.2

Open the chart page →

3,827
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
async@2.6.3
2.6.4

Open the chart page →

4,017
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
async@2.0.1
2.6.4

Open the chart page →

3,576
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
async@3.2.1
3.2.2

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
async@3.2.1
3.2.2

Open the chart page →

28,605
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
async@2.6.3
2.6.4

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
async@2.6.3
2.6.4

Open the chart page →

22,665
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-43138.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
async@3.2.0
3.2.2

Open the chart page →

5,806

Container images carrying it

106 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
async@3.2.0
3.2.2
5
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
async@3.2.0
3.2.2
3
pantsel/konga:latestc8172b75607d
async@2.0.1
2.6.4
3
agoldis/sorry-cypress-director:2.5.1110228ecd353b
async@3.2.1
3.2.2
2
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
async@3.2.0
3.2.2
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
async@2.6.3
2.6.4
2
governify/director:v1.4.0608c6940bb98
async@2.6.3
2.6.4
2
governify/registry:v3.4.0d3f37f4f8168
async@2.6.3
2.6.4
2
governify/render:v2.2.0daeca1ce28e6
async@3.2.1
3.2.2
2
governify/reporter:v2.2.038595913458f
async@3.2.1
3.2.2
2
gradiant/open5gs-webui:2.7.5fbd10c017541
async@2.5.0
2.6.4
2
hookiesolutions/webhookie:latest0629694246ba
async@3.2.1
3.2.2
2
jupyterhub/configurable-http-proxy:4.5.08ced0a2f8073
async@3.2.0
3.2.2
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
async@3.2.0
3.2.2
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
async@2.5.0
2.6.4
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
async@2.6.3
2.6.4
2
mesosphere/kommander:6.100.13917e82333a9
async@3.2.0
3.2.2
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
async@3.2.0
3.2.2
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
async@2.6.3
2.6.4
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
async@3.2.0
3.2.2
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
async@2.6.3
2.6.4
2
taigaio/taiga-events:latest92fc0822564f
async@3.2.0
3.2.2
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
async@2.6.3
2.6.4
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
async@2.4.0
2.6.4
1
arfath29/3-tier-app-frontend:latest384b3e377f47
async@2.6.3
2.6.4
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
async@3.2.0
3.2.2
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
async@3.2.0
3.2.2
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
async@3.2.0
3.2.2
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
async@3.2.1
3.2.2
1
catalysm/csmm:latestf003b35f54d9
async@2.0.1
2.6.4
1
chatwoot/chatwoot:v4.15.167ebc751c171
async@2.6.3
2.6.4
1
cnieg/maildev:v1.1.998ee05668915
async@3.1.0
3.2.2
1
conduction/conduction-ui-app:devd591f5e6f2a9
async@2.6.3
2.6.4
1
daskdev/dask-notebook:1.1.0052630f5ca04
async@2.6.1
2.6.4
1
datarhei/restreamer:0.6.4655e12f9eeed
async@3.2.0
3.2.2
1
decayofmind/hubot:3.3.21e18e92fe694
async@2.6.3
2.6.4
1
enketo/enketo-express:3.0.4dcad9c2273f6
async@2.6.3
2.6.4
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
async@2.6.0
2.6.4
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
async@2.6.2
2.6.4
1
ethersphere/bzz-token-service:latest7624f11a72ad
async@2.6.3
2.6.4
1
felddy/foundryvtt:0.8.36c5d90b90349
async@3.2.0
3.2.2
1
fiware/iotagent-ul:1.14.0fe11f55a926d
async@2.6.2
2.6.4
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
async@2.6.0
2.6.4
1
getferdi/ferdi-server:1.3.26e620b85afaa
async@2.6.3
2.6.4
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
async@2.6.3
2.6.4
1
gristlabs/grist:0.7.96e71b1914a7e
async@2.6.3
2.6.4
1
halkeye/hubot:latest9764d2202130
async@2.6.3
2.6.4
1
henrywhitaker3/speedtest-tracker:latest47159a940229
async@2.6.3
2.6.4
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
async@2.6.3
2.6.4
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
async@2.6.1
2.6.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.