StackRadar

CVE-2022-21670

Medium

Advisory

Published 12 Jan 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.022
81st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
31
of 17,781 indexed, latest versions
Container images
29
deployed by those charts
Fix available
1 of 1
affected package

Uncontrolled Resource Consumption in markdown-it

Carried by container images the latest versions of 31 of 17,781 indexed charts deploy, on 29 images.

Affected packageAffected versionsFixed inImages
markdown-itnpm8.4.0, 8.4.2, 10.0.0, 11.0.1+3 more12.3.229
OSV records
GHSA-6vfc-qv3f-vr6c

Charts affected

31 by stars
ChartLatestAffected imagesRadar Score
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
markdown-it@11.0.1
12.3.2

Open the chart page →

5,946
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
markdown-it@12.0.6
12.3.2

Open the chart page →

22,773
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
markdown-it@12.2.0
12.3.2

Open the chart page →

7,579
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
markdown-it@8.4.2
12.3.2

Open the chart page →

18,517
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
markdown-it@10.0.0
12.3.2

Open the chart page →

17,896
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
ghcr.io/data-fair/simple-directory:438a4f32fad82
markdown-it@8.4.2
12.3.2

Open the chart page →

38,346
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
markdown-it@12.0.4
12.3.2

Open the chart page →

2,519
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
markdown-it@8.4.2
12.3.2

Open the chart page →

7,801
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
markdown-it@11.0.1
12.3.2

Open the chart page →

3,833
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
markdown-it@8.4.2
12.3.2

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
markdown-it@8.4.2
12.3.2

Open the chart page →

24,319
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
markdown-it@11.0.1
12.3.2
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
markdown-it@11.0.1
12.3.2
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
markdown-it@11.0.1
12.3.2
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
markdown-it@11.0.1
12.3.2

Open the chart page →

89,959
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
markdown-it@11.0.1
12.3.2

Open the chart page →

4,253
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
markdown-it@12.2.0
12.3.2

Open the chart page →

4,944
keyoxide-webittrident-oss0.2.31 of 1See more

keyoxide-web ittrident-oss 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
keyoxide/keyoxide:stable96f27a71269d
markdown-it@8.4.2
12.3.2

Open the chart page →

2,363
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
markdown-it@8.4.0
12.3.2

Open the chart page →

6,454
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
markdown-it@8.4.2
12.3.2

Open the chart page →

7,929
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
markdown-it@10.0.0
12.3.2

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
markdown-it@10.0.0
12.3.2

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
markdown-it@10.0.0
12.3.2

Open the chart page →

12,108
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
markdown-it@10.0.0
12.3.2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
markdown-it@10.0.0
12.3.2
mojaloop/role-assignment-service:v2.1.0def4bf273721
markdown-it@10.0.0
12.3.2

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
markdown-it@10.0.0
12.3.2

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
markdown-it@10.0.0
12.3.2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
markdown-it@10.0.0
12.3.2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
markdown-it@10.0.0
12.3.2

Open the chart page →

19,226
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
markdown-it@10.0.0
12.3.2

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
markdown-it@10.0.0
12.3.2

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
markdown-it@10.0.0
12.3.2

Open the chart page →

2,316
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
markdown-it@10.0.0
12.3.2

Open the chart page →

27,465
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
markdown-it@12.2.0
12.3.2

Open the chart page →

9,968
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
markdown-it@10.0.0
12.3.2

Open the chart page →

6,524
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
markdown-it@12.2.0
12.3.2

Open the chart page →

3,638
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2022-21670.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
markdown-it@11.0.1
12.3.2

Open the chart page →

5,459

Container images carrying it

29 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
markdown-it@10.0.0
12.3.2
3
governify/assets-manager:v1.4.12987672448c7
markdown-it@8.4.2
12.3.2
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
markdown-it@10.0.0
12.3.2
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
markdown-it@10.0.0
12.3.2
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
markdown-it@10.0.0
12.3.2
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
markdown-it@10.0.0
12.3.2
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
markdown-it@10.0.0
12.3.2
2
requarks/wiki:2:latest68f0d1848261
markdown-it@11.0.1
12.3.2
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
markdown-it@8.4.2
12.3.2
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
markdown-it@10.0.0
12.3.2
1
enketo/enketo-express:3.0.4dcad9c2273f6
markdown-it@8.4.2
12.3.2
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
markdown-it@12.2.0
12.3.2
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
markdown-it@12.2.0
12.3.2
1
jayfong/yapi:1.10.2163e5d621910
markdown-it@8.4.0
12.3.2
1
keyoxide/keyoxide:stable96f27a71269d
markdown-it@8.4.2
12.3.2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
markdown-it@12.0.6
12.3.2
1
linuxserver/codimd:latestb801bbcf6386
markdown-it@10.0.0
12.3.2
1
phntom/codimd:2.4.31b9aafbb62e6
markdown-it@10.0.0
12.3.2
1
requarks/wiki:canary-2.5.2438b5865a7386c
markdown-it@11.0.1
12.3.2
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
markdown-it@8.4.2
12.3.2
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
markdown-it@11.0.1
12.3.2
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
markdown-it@11.0.1
12.3.2
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
markdown-it@11.0.1
12.3.2
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
markdown-it@11.0.1
12.3.2
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
markdown-it@8.4.2
12.3.2
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
markdown-it@12.0.4
12.3.2
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
markdown-it@11.0.1
12.3.2
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
markdown-it@12.2.0
12.3.2
1
quay.io/wekan/wekan:v5.65cb17600883a3
markdown-it@12.2.0
12.3.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.