StackRadar

CVE-2022-1941

High

Advisory

Published 22 Sept 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
71
of 17,781 indexed, latest versions
Container images
65
deployed by those charts
Fix available
2 of 2
affected packages

protobuf-cpp and protobuf-python have potential Denial of Service issue

Carried by container images the latest versions of 71 of 17,781 indexed charts deploy, on 65 images.

Affected packageAffected versionsFixed inImages
protobufpypi3.5.1, 3.5.2, 3.6.1, 3.7.0+19 more3.18.3, 3.19.5, 3.20.2, 4.21.659
protobufdeb2.6.1-1.3, 3.0.0-9.1ubuntu1, 3.6.1.3-2ubuntu52.6.1-1.3ubuntu0.1~esm2, 3.0.0-9.1ubuntu1.1, 3.6.1.3-2ubuntu5.26
OSV records
GHSA-8gq9-2x98-w8hfUBUNTU-CVE-2022-1941
Also known as
PYSEC-2026-899, USN-5769-1, USN-5945-1

Charts affected

71 by stars
ChartLatestAffected imagesRadar Score
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
protobuf@3.17.3
3.18.3

Open the chart page →

3,999
mlflowkelvins0.4.01 of 3See more

mlflow kelvins 0.4.0

1 of the 3 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
kelvinsp/mlflow:1.26.1cd33e6db2a59
protobuf@4.21.1
4.21.6

Open the chart page →

4,156
specter-desktopkronkltdVerified publisher0.1.01 of 1See more

specter-desktop kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
lncm/specter-desktop:v0.10.4bca14d04397d
protobuf@3.13.0
3.18.3

Open the chart page →

1,850
online-boutiquekubesphere-testVerified publisher0.1.01 of 11See more

online-boutique kubesphere-test 0.1.0

1 of the 11 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
protobuf@3.13.0
3.18.3

Open the chart page →

26,018
pritunlmglants0.1.01 of 1See more

pritunl mglants 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
goofball222/pritunl:1.30.3070.5943c0743701d4
protobuf@3.19.4
3.19.5

Open the chart page →

1,902
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
protobuf@3.19.1
3.19.5

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
protobuf@3.19.4
3.19.5

Open the chart page →

15,675
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
protobuf@2.6.1-1.3
2.6.1-1.3ubuntu0.1~esm2

Open the chart page →

63,223
comacopencord1.0.03 of 9See more

comac opencord 1.0.0

3 of the 9 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
protobuf@3.7.0
3.18.3
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
protobuf@3.5.2
3.18.3
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
protobuf@3.5.2
3.18.3

Open the chart page →

88,546
comac-platformopencord0.0.172 of 11See more

comac-platform opencord 0.0.17

2 of the 11 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
protobuf@3.7.0
3.18.3
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
protobuf@3.5.2
3.18.3

Open the chart page →

26,211
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
protobuf@2.6.1-1.3
2.6.1-1.3ubuntu0.1~esm2

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
protobuf@2.6.1-1.3
2.6.1-1.3ubuntu0.1~esm2

Open the chart page →

29,124
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
protobuf@3.6.1
3.18.3

Open the chart page →

12,609
sebaopencord1.0.04 of 17See more

seba opencord 1.0.0

4 of the 17 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
voltha/voltha-cli:1.6.0c4e41e92f046
protobuf@3.6.1
3.18.3
voltha/voltha-netconf:1.6.037f80524c207
protobuf@3.6.1
3.18.3
voltha/voltha-ofagent:1.6.09ee8c1f4428c
protobuf@3.6.1
3.18.3
voltha/voltha-voltha:1.6.0ff596b62de59
protobuf@3.6.1
3.18.3

Open the chart page →

93,855
seldon-core-loadtestingseldon0.2.01 of 1See more

seldon-core-loadtesting seldon 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
seldonio/locust-core:0.81d0da98a2d76
protobuf@3.7.1
3.18.3

Open the chart page →

23,007
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
protobuf@3.18.1
3.18.3

Open the chart page →

21,997
gar-exportersoftonic0.1.11 of 1See more

gar-exporter softonic 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
softonic/gar-exporter:0.2.1a64d6c0e0ae5
protobuf@3.13.0
3.18.3

Open the chart page →

2,296
gtmetrix-bqt3n1.0.01 of 1See more

gtmetrix-bq t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
protobuf@3.11.3
3.18.3

Open the chart page →

1,287
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
protobuf@3.20.1
3.20.2

Open the chart page →

17,461
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
protobuf@3.17.3
3.18.3

Open the chart page →

11,119
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
protobuf@3.13.0
3.18.3

Open the chart page →

4,086

Container images carrying it

65 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
tensorflow/tensorflow:1.6.0-devel1e3172090703
protobuf@3.5.1
3.18.3
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
protobuf@2.6.1-1.3
2.6.1-1.3ubuntu0.1~esm2
1
voltha/voltha-cli:1.6.0c4e41e92f046
protobuf@3.6.1
3.18.3
1
voltha/voltha-netconf:1.6.037f80524c207
protobuf@3.6.1
3.18.3
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
protobuf@3.6.1
3.18.3
1
voltha/voltha-tester:1.7.0655c3048a602
protobuf@3.6.1
3.18.3
1
voltha/voltha-voltha:1.6.0ff596b62de59
protobuf@3.6.1
3.18.3
1
xeladock/mysql_dns:latest4baf531453f1
protobuf@3.20.1
3.20.2
1
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
protobuf@3.13.0
3.18.3
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
protobuf@3.19.3
3.19.5
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
protobuf@3.0.0-9.1ubuntu1
3.0.0-9.1ubuntu1.1
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
protobuf@3.6.1.3-2ubuntu5
3.6.1.3-2ubuntu5.2
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
protobuf@3.20.1
3.20.2
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
protobuf@3.6.1.3-2ubuntu5
3.6.1.3-2ubuntu5.2
1
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
protobuf@3.6.1
3.18.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.