StackRadar

CVE-2022-2053

High

Advisory

Published 6 Aug 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.010
61st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Undertow vulnerable to Dos via Large AJP request

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
undertow-coremaven1.3.15.Final, 1.4.0.Final, 2.2.4.Final, 2.2.5.Final+5 more2.2.19.Final9
OSV records
GHSA-95rf-557x-44g5

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2022-2053.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
undertow-core@2.2.14.Final
2.2.19.Final

Open the chart page →

7,713
kafdroplsst-sqre0.1.31 of 1See more

kafdrop lsst-sqre 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-2053.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
undertow-core@2.2.16.Final
2.2.19.Final

Open the chart page →

7,901
activemq-artemisactivemq-artemis-helm0.3.61 of 1See more

activemq-artemis activemq-artemis-helm 0.3.6

1 of the 1 container images this version deploys carry CVE-2022-2053.

Container imageDigestPackageFixed in
vromero/activemq-artemis:2.16.0408d6a46b153
undertow-core@1.3.15.Final
2.2.19.Final

Open the chart page →

4,419
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2022-2053.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
undertow-core@2.2.8.Final
2.2.19.Final

Open the chart page →

3,958
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2022-2053.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
undertow-core@2.2.14.Final
2.2.19.Final

Open the chart page →

7,713
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-2053.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
undertow-core@2.2.17.Final
2.2.19.Final

Open the chart page →

13,352
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2022-2053.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
undertow-core@2.2.16.Final
2.2.19.Final

Open the chart page →

13,459
dinsrokronkltdVerified publisher0.1.71 of 2See more

dinsro kronkltd 0.1.7

1 of the 2 container images this version deploys carry CVE-2022-2053.

Container imageDigestPackageFixed in
duck1123/dinsro:latest9568c5961d5d
undertow-core@2.2.4.Final
2.2.19.Final

Open the chart page →

1,628
ma1sdnetsocVerified publisher0.2.11 of 1See more

ma1sd netsoc 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-2053.

Container imageDigestPackageFixed in
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
undertow-core@2.2.7.Final
2.2.19.Final

Open the chart page →

3,582
digdagskyoo20030.5.21 of 4See more

digdag skyoo2003 0.5.2

1 of the 4 container images this version deploys carry CVE-2022-2053.

Container imageDigestPackageFixed in
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
undertow-core@1.4.0.Final
2.2.19.Final

Open the chart page →

6,949
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-2053.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
undertow-core@2.2.5.Final
2.2.19.Final

Open the chart page →

28,605

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
undertow-core@2.2.16.Final
2.2.19.Final
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
undertow-core@2.2.14.Final
2.2.19.Final
2
assistiot/identity-manager_kc:latest0df4b4fa899a
undertow-core@2.2.17.Final
2.2.19.Final
1
duck1123/dinsro:latest9568c5961d5d
undertow-core@2.2.4.Final
2.2.19.Final
1
ma1uta/ma1sd:2.5.0ee2a56d8b8ca
undertow-core@2.2.7.Final
2.2.19.Final
1
remche/shinyproxy:2.6.18bcda8a04d3b
undertow-core@2.2.8.Final
2.2.19.Final
1
vromero/activemq-artemis:2.16.0408d6a46b153
undertow-core@1.3.15.Final
2.2.19.Final
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
undertow-core@1.4.0.Final
2.2.19.Final
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
undertow-core@2.2.5.Final
2.2.19.Final
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.