StackRadar

CVE-2021-46743

Critical

Advisory

Published 30 Mar 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

Firebase PHP-JWT key/algorithm type confusion

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
firebase/php-jwtcomposerv5.2.0, v5.2.1, v5.4.0, v5.5.16.0.010
OSV records
GHSA-8xf4-w7qw-pjjw

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
passboltcnieg1.1.171 of 2See more

passbolt cnieg 1.1.17

1 of the 2 container images this version deploys carry CVE-2021-46743.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
firebase/php-jwt@v5.5.1
6.0.0

Open the chart page →

3,543
passbolt-hachristianhuthVerified publisher6.0.11 of 4See more

passbolt-ha christianhuth 6.0.1

1 of the 4 container images this version deploys carry CVE-2021-46743.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
firebase/php-jwt@v5.5.1
6.0.0

Open the chart page →

10,817
firefly-iiigeek-cookbookVerified publisher0.3.01 of 1See more

firefly-iii geek-cookbook 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-46743.

Container imageDigestPackageFixed in
fireflyiii/core:version-5.6.142f4283bd0cf7
firebase/php-jwt@v5.5.1
6.0.0

Open the chart page →

2,076
monicageek-cookbookVerified publisher8.2.01 of 1See more

monica geek-cookbook 8.2.0

1 of the 1 container images this version deploys carry CVE-2021-46743.

Container imageDigestPackageFixed in
library/monica:3.7.0-apacheceb1ba4196ab
firebase/php-jwt@v5.5.1
6.0.0

Open the chart page →

2,096
openldapcsic-charts0.1.11 of 2See more

openldap csic-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2021-46743.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
firebase/php-jwt@v5.5.1
6.0.0

Open the chart page →

5,293
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2021-46743.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
firebase/php-jwt@v5.2.1
6.0.0

Open the chart page →

20,933
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2021-46743.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
firebase/php-jwt@v5.5.1
6.0.0

Open the chart page →

8,392
xbackbonegeek-cookbookVerified publisher5.4.21 of 1See more

xbackbone geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2021-46743.

Container imageDigestPackageFixed in
pe46dro/xbackbone-docker:3.3.309dfe3aa10f6
firebase/php-jwt@v5.2.0
6.0.0

Open the chart page →

1,655
openldapopenldap0.1.11 of 2See more

openldap openldap 0.1.1

1 of the 2 container images this version deploys carry CVE-2021-46743.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
firebase/php-jwt@v5.5.1
6.0.0

Open the chart page →

5,293
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2021-46743.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
firebase/php-jwt@v5.4.0
6.0.0

Open the chart page →

2,972
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2021-46743.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
firebase/php-jwt@v5.5.1
6.0.0

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2021-46743.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
firebase/php-jwt@v5.2.0
6.0.0

Open the chart page →

2,132

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ldapaccountmanager/lam:8.0.1d46cf25d1dda
firebase/php-jwt@v5.5.1
6.0.0
2
passbolt/passbolt:3.4.0-ce-non-root655547e17263
firebase/php-jwt@v5.5.1
6.0.0
2
fireflyiii/core:version-5.6.142f4283bd0cf7
firebase/php-jwt@v5.5.1
6.0.0
1
library/monica:3.7.0-apacheceb1ba4196ab
firebase/php-jwt@v5.5.1
6.0.0
1
openemr/openemr:6.1.089eaa6d9a4e3
firebase/php-jwt@v5.5.1
6.0.0
1
pe46dro/xbackbone-docker:3.3.309dfe3aa10f6
firebase/php-jwt@v5.2.0
6.0.0
1
shyim/shopware:6.4.6.0a951c0e6b836
firebase/php-jwt@v5.4.0
6.0.0
1
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
firebase/php-jwt@v5.5.1
6.0.0
1
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
firebase/php-jwt@v5.2.0
6.0.0
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
firebase/php-jwt@v5.2.1
6.0.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.