StackRadar

CVE-2022-0235

High

Advisory

Published 21 Jan 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.016
75th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
82
of 17,781 indexed, latest versions
Container images
79
deployed by those charts
Fix available
1 of 1
affected package

node-fetch forwards secure headers to untrusted sites

Carried by container images the latest versions of 82 of 17,781 indexed charts deploy, on 79 images.

Affected packageAffected versionsFixed inImages
node-fetchnpm1.6.3, 1.7.3, 2.3.0, 2.6.0+3 more2.6.779
OSV records
GHSA-r683-j2x4-v87g

Charts affected

82 by stars
ChartLatestAffected imagesRadar Score
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
node-fetch@2.6.1
2.6.7

Open the chart page →

3,397
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
node-fetch@2.6.6
2.6.7

Open the chart page →

4,230
online-boutiquekubesphere-testVerified publisher0.1.02 of 11See more

online-boutique kubesphere-test 0.1.0

2 of the 11 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
node-fetch@2.6.1
2.6.7
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
node-fetch@2.6.1
2.6.7

Open the chart page →

26,018
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
node-fetch@1.7.3
2.6.7

Open the chart page →

7,929
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
node-fetch@2.6.1
2.6.7

Open the chart page →

2,247
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
node-fetch@2.6.0
2.6.7

Open the chart page →

3,651
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
node-fetch@1.7.3
2.6.7

Open the chart page →

5,287
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
node-fetch@2.6.0
2.6.7

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
node-fetch@2.6.0
2.6.7

Open the chart page →

7,027
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
node-fetch@2.6.1
2.6.7

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
node-fetch@2.6.1
2.6.7

Open the chart page →

10,603
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
node-fetch@2.6.1
2.6.7
mojaloop/event-sidecar:v11.0.189b8ab71b74b
node-fetch@2.6.1
2.6.7

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
node-fetch@2.6.1
2.6.7
mojaloop/event-sidecar:v11.0.189b8ab71b74b
node-fetch@2.6.1
2.6.7

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
node-fetch@2.6.1
2.6.7
mojaloop/event-sidecar:v11.0.189b8ab71b74b
node-fetch@2.6.1
2.6.7

Open the chart page →

12,108
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
node-fetch@2.6.1
2.6.7
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
node-fetch@2.6.1
2.6.7

Open the chart page →

11,479
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
node-fetch@2.6.1
2.6.7
mojaloop/central-ledger:v13.14.01abc8a7aa71c
node-fetch@2.6.1
2.6.7
mojaloop/event-sidecar:v11.0.189b8ab71b74b
node-fetch@2.6.1
2.6.7
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
node-fetch@2.6.1
2.6.7

Open the chart page →

19,226
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
node-fetch@2.6.0
2.6.7

Open the chart page →

6,684
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
node-fetch@1.7.3
2.6.7
socialmediamacroscope/smile_server:0.3.31a528c794270
node-fetch@1.7.3
2.6.7

Open the chart page →

109,294
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
node-fetch@2.6.1
2.6.7

Open the chart page →

9,968
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
node-fetch@2.6.0
2.6.7

Open the chart page →

1,986
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
node-fetch@1.7.3
2.6.7

Open the chart page →

6,524
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
node-fetch@2.6.1
2.6.7

Open the chart page →

29,227
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
node-fetch@2.6.1
2.6.7

Open the chart page →

5,215
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
node-fetch@2.3.0
2.6.7

Open the chart page →

3,638
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
node-fetch@2.6.0
2.6.7

Open the chart page →

3,696
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
node-fetch@2.6.5
2.6.7

Open the chart page →

3,228
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
node-fetch@2.6.1
2.6.7

Open the chart page →

3,881
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
node-fetch@2.6.1
2.6.7

Open the chart page →

2,838
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
node-fetch@2.6.5
2.6.7

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
node-fetch@2.6.5
2.6.7

Open the chart page →

28,605
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
node-fetch@2.6.1
2.6.7

Open the chart page →

5,459
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-0235.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
node-fetch@2.6.1
2.6.7

Open the chart page →

5,806

Container images carrying it

79 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
node-fetch@2.6.1
2.6.7
5
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
node-fetch@2.6.1
2.6.7
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
node-fetch@2.6.1
2.6.7
2
gradiant/open5gs-webui:2.7.5fbd10c017541
node-fetch@1.7.3
2.6.7
2
hookiesolutions/webhookie:latest0629694246ba
node-fetch@2.6.5
2.6.7
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
node-fetch@2.6.1
2.6.7
2
mesosphere/kommander:6.100.13917e82333a9
node-fetch@2.6.0
2.6.7
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
node-fetch@2.6.1
2.6.7
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
node-fetch@2.6.1
2.6.7
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
node-fetch@2.6.1
2.6.7
2
requarks/wiki:2:latest68f0d1848261
node-fetch@2.6.1
2.6.7
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
node-fetch@1.7.3
2.6.7
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
node-fetch@1.7.3
2.6.7
1
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
node-fetch@2.6.1
2.6.7
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
node-fetch@2.6.1
2.6.7
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
node-fetch@2.6.1
2.6.7
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
node-fetch@2.6.1
2.6.7
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
node-fetch@2.6.1
2.6.7
1
codercom/code-server:3.10.247605610ad8d
node-fetch@2.6.1
2.6.7
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
node-fetch@1.7.3
2.6.7
1
daskdev/dask-notebook:1.1.0052630f5ca04
node-fetch@2.3.0
2.6.7
1
electerious/ackee:3.2.05e7173fa321c
node-fetch@2.6.1
2.6.7
1
enketo/enketo-express:3.0.4dcad9c2273f6
node-fetch@2.6.1
2.6.7
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
node-fetch@1.7.3
2.6.7
1
ethersphere/bzz-token-service:latest7624f11a72ad
node-fetch@1.7.3
2.6.7
1
felddy/foundryvtt:0.8.36c5d90b90349
node-fetch@2.6.1
2.6.7
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
node-fetch@1.7.3
2.6.7
1
gristlabs/grist:0.7.96e71b1914a7e
node-fetch@2.6.1
2.6.7
1
hansehe/graphql-gateway:1.0.458e09540afbc
node-fetch@2.6.1
2.6.7
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
node-fetch@2.6.1
2.6.7
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
node-fetch@2.6.6
2.6.7
1
i4trust/pdc-portal:2.0.03e77858e1219
node-fetch@2.6.1
2.6.7
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
node-fetch@2.6.1
2.6.7
1
jakowenko/double-take:1.6.0b858bac9e32a
node-fetch@2.6.5
2.6.7
1
jayfong/yapi:1.10.2163e5d621910
node-fetch@1.6.3
2.6.7
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
node-fetch@2.6.6
2.6.7
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
node-fetch@2.6.6
2.6.7
1
lavandadelpatio/frontend:latest501c3f31e0bc
node-fetch@2.6.0
2.6.7
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
node-fetch@2.6.1
2.6.7
1
lsstsqre/squareone:0.4.09ded78e7fe03
node-fetch@2.6.1
2.6.7
1
mozilla/sentencecollector:2.0.91da6ff5c4895
node-fetch@2.6.0
2.6.7
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
node-fetch@2.6.6
2.6.7
1
ondrejsika/parking:latestb1fd497416c8
node-fetch@2.6.0
2.6.7
1
openemr/openemr:6.1.089eaa6d9a4e3
node-fetch@2.6.6
2.6.7
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
node-fetch@2.6.0
2.6.7
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
node-fetch@2.6.1
2.6.7
1
phntom/codimd:2.4.31b9aafbb62e6
node-fetch@1.7.3
2.6.7
1
requarks/wiki:canary-2.5.2438b5865a7386c
node-fetch@2.6.1
2.6.7
1
roadiehq/community-backstage-image:latestef355bf5b639
node-fetch@2.6.1
2.6.7
1
shinobisystems/shinobi:dev3ca746937856
node-fetch@2.6.1
2.6.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.