StackRadar

CVE-2022-1941

High

Advisory

Published 22 Sept 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
71
of 17,781 indexed, latest versions
Container images
65
deployed by those charts
Fix available
2 of 2
affected packages

protobuf-cpp and protobuf-python have potential Denial of Service issue

Carried by container images the latest versions of 71 of 17,781 indexed charts deploy, on 65 images.

Affected packageAffected versionsFixed inImages
protobufpypi3.5.1, 3.5.2, 3.6.1, 3.7.0+19 more3.18.3, 3.19.5, 3.20.2, 4.21.659
protobufdeb2.6.1-1.3, 3.0.0-9.1ubuntu1, 3.6.1.3-2ubuntu52.6.1-1.3ubuntu0.1~esm2, 3.0.0-9.1ubuntu1.1, 3.6.1.3-2ubuntu5.26
OSV records
GHSA-8gq9-2x98-w8hfUBUNTU-CVE-2022-1941
Also known as
PYSEC-2026-899, USN-5769-1, USN-5945-1

Charts affected

71 by stars
ChartLatestAffected imagesRadar Score
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
protobuf@3.17.3
3.18.3

Open the chart page →

3,999
mlflowkelvins0.4.01 of 3See more

mlflow kelvins 0.4.0

1 of the 3 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
kelvinsp/mlflow:1.26.1cd33e6db2a59
protobuf@4.21.1
4.21.6

Open the chart page →

4,156
specter-desktopkronkltdVerified publisher0.1.01 of 1See more

specter-desktop kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
lncm/specter-desktop:v0.10.4bca14d04397d
protobuf@3.13.0
3.18.3

Open the chart page →

1,850
online-boutiquekubesphere-testVerified publisher0.1.01 of 11See more

online-boutique kubesphere-test 0.1.0

1 of the 11 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
protobuf@3.13.0
3.18.3

Open the chart page →

26,018
pritunlmglants0.1.01 of 1See more

pritunl mglants 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
goofball222/pritunl:1.30.3070.5943c0743701d4
protobuf@3.19.4
3.19.5

Open the chart page →

1,902
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
protobuf@3.19.1
3.19.5

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
protobuf@3.19.4
3.19.5

Open the chart page →

15,675
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
protobuf@2.6.1-1.3
2.6.1-1.3ubuntu0.1~esm2

Open the chart page →

63,223
comacopencord1.0.03 of 9See more

comac opencord 1.0.0

3 of the 9 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
protobuf@3.7.0
3.18.3
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
protobuf@3.5.2
3.18.3
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
protobuf@3.5.2
3.18.3

Open the chart page →

88,546
comac-platformopencord0.0.172 of 11See more

comac-platform opencord 0.0.17

2 of the 11 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
protobuf@3.7.0
3.18.3
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
protobuf@3.5.2
3.18.3

Open the chart page →

26,211
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
protobuf@2.6.1-1.3
2.6.1-1.3ubuntu0.1~esm2

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
protobuf@2.6.1-1.3
2.6.1-1.3ubuntu0.1~esm2

Open the chart page →

29,124
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
protobuf@3.6.1
3.18.3

Open the chart page →

12,609
sebaopencord1.0.04 of 17See more

seba opencord 1.0.0

4 of the 17 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
voltha/voltha-cli:1.6.0c4e41e92f046
protobuf@3.6.1
3.18.3
voltha/voltha-netconf:1.6.037f80524c207
protobuf@3.6.1
3.18.3
voltha/voltha-ofagent:1.6.09ee8c1f4428c
protobuf@3.6.1
3.18.3
voltha/voltha-voltha:1.6.0ff596b62de59
protobuf@3.6.1
3.18.3

Open the chart page →

93,855
seldon-core-loadtestingseldon0.2.01 of 1See more

seldon-core-loadtesting seldon 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
seldonio/locust-core:0.81d0da98a2d76
protobuf@3.7.1
3.18.3

Open the chart page →

23,007
seldon-deployseldon1.4.01 of 2See more

seldon-deploy seldon 1.4.0

1 of the 2 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
seldonio/seldon-request-logger:1.11.24e985d2006a8
protobuf@3.18.1
3.18.3

Open the chart page →

21,997
gar-exportersoftonic0.1.11 of 1See more

gar-exporter softonic 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
softonic/gar-exporter:0.2.1a64d6c0e0ae5
protobuf@3.13.0
3.18.3

Open the chart page →

2,296
gtmetrix-bqt3n1.0.01 of 1See more

gtmetrix-bq t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
protobuf@3.11.3
3.18.3

Open the chart page →

1,287
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
protobuf@3.20.1
3.20.2

Open the chart page →

17,461
wazuh-manager-filebeatwazuh-manager-filebeat0.1.0-gamma1 of 1See more

wazuh-manager-filebeat wazuh-manager-filebeat 0.1.0-gamma

1 of the 1 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
protobuf@3.17.3
3.18.3

Open the chart page →

11,119
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2022-1941.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
protobuf@3.13.0
3.18.3

Open the chart page →

4,086

Container images carrying it

65 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
cloudve/cloudlaunch-server:latest4a3d7fae90bb
protobuf@3.19.1
3.19.5
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
protobuf@2.6.1-1.3
2.6.1-1.3ubuntu0.1~esm2
3
amancevice/superset:0.35.212a0a9e66550
protobuf@3.11.2
3.18.3
2
datawire/aes:1.14.48588eafe6862
protobuf@3.13.0
3.18.3
2
larribas/mlflow:1.9.105ccb0b46bfb
protobuf@3.12.2
3.18.3
2
lncm/specter-desktop:v1.10.536eaa06f99f4
protobuf@3.17.3
3.18.3
2
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
protobuf@3.7.0
3.18.3
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
protobuf@3.5.2
3.18.3
2
weblate/weblate:4.2.2-169c160d37a3c
protobuf@3.13.0
3.18.3
2
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
protobuf@3.14.0
3.18.3
2
alerta/alerta-web:8.5.04786b9eaa606
protobuf@3.19.1
3.19.5
1
amancevice/superset:0.28.1c8c04bfe3d66
protobuf@3.7.1
3.18.3
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
protobuf@3.19.4
3.19.5
1
apachepulsar/pulsar:2.6.14db6ff0b4045
protobuf@3.13.0
3.18.3
1
apachepulsar/pulsar:2.9.0d056c89b7131
protobuf@3.19.1
3.19.5
1
apachepulsar/pulsar:2.8.2d538416d5afe
protobuf@3.19.1
3.19.5
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
protobuf@3.17.3
3.18.3
1
assistiot/fl_training_collector:latest792715dd3084
protobuf@3.19.0
3.19.5
1
cheyang/distributed-tf:1.6.046cc34755493
protobuf@3.5.1
3.18.3
1
datadog/agent:7.22.08f20e56b5311
protobuf@3.7.0
3.18.3
1
datadog/agent:6aad9994de6a7
protobuf@3.17.3
3.18.3
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
protobuf@3.13.0
3.18.3
1
datawire/aes:1.13.62beb65062c8b
protobuf@3.13.0
3.18.3
1
datawire/emissary:2.0.2-ea9716efbdd24b
protobuf@3.13.0
3.18.3
1
dysnix/pritunl:v1.29-r819951e3e7a32
protobuf@3.13.0
3.18.3
1
esphome/esphome:1.18.03f51ec10e823
protobuf@3.15.8
3.18.3
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
protobuf@3.6.1
3.18.3
1
flagsmith/flagsmith-api:v2.6.0fd58556339a4
protobuf@3.14.0
3.18.3
1
gethue/hue:4.10.05702b2c37ff9
protobuf@3.17.0
3.18.3
1
gluufederation/opendj:4.3.0_011a1128b28b95
protobuf@3.17.3
3.18.3
1
goofball222/pritunl:1.30.3070.5943c0743701d4
protobuf@3.19.4
3.19.5
1
improwised/erpnext-worker:v13.4.197280b55cbd4
protobuf@3.17.3
3.18.3
1
intel/trusted-certificate-issuer:0.5.0591a9db4a427
protobuf@3.6.1.3-2ubuntu5
3.6.1.3-2ubuntu5.2
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
protobuf@3.17.3
3.18.3
1
kelvinsp/mlflow:1.26.1cd33e6db2a59
protobuf@4.21.1
4.21.6
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
protobuf@3.17.3
3.18.3
1
lncm/specter-desktop:v0.10.4bca14d04397d
protobuf@3.13.0
3.18.3
1
mozilla/syncserver:latest016162bf39d8
protobuf@3.17.3
3.18.3
1
netboxcommunity/netbox:v3.2.83d652dca5351
protobuf@4.21.4
4.21.6
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
protobuf@3.5.2
3.18.3
1
redash/redash:10.0.0.b503639392753c0376
protobuf@3.17.3
3.18.3
1
robmarkcole/deepstack-ui:latest410275726459
protobuf@3.17.3
3.18.3
1
robotshop/rs-payment:latest774b52c6180d
protobuf@3.18.0rc2
3.18.3
1
rook/ceph:v1.20.72f970c425617
protobuf@3.14.0
3.18.3
1
rook/ceph:v1.19.2944a1dd70496
protobuf@3.14.0
3.18.3
1
seldonio/locust-core:0.81d0da98a2d76
protobuf@3.7.1
3.18.3
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
protobuf@3.18.1
3.18.3
1
softonic/gar-exporter:0.2.1a64d6c0e0ae5
protobuf@3.13.0
3.18.3
1
t3nde/gtmetrix-bq:0.2.0d2939e9a719b
protobuf@3.11.3
3.18.3
1
tachyongroup/mlflow-deployment-controller:mlflow-controller-0.1.87e79b9000856
protobuf@3.20.0
3.20.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.