StackRadar

CVE-2022-21681

High

Advisory

Published 14 Jan 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.027
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
21
of 17,781 indexed, latest versions
Container images
22
deployed by those charts
Fix available
1 of 1
affected package

Inefficient Regular Expression Complexity in marked

Carried by container images the latest versions of 21 of 17,781 indexed charts deploy, on 22 images.

Affected packageAffected versionsFixed inImages
markednpm0.3.6, 0.3.19, 0.4.0, 0.6.3+7 more4.0.1022
OSV records
GHSA-5v2h-r2cx-5xgj

Charts affected

21 by stars
ChartLatestAffected imagesRadar Score
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
microcks/microcks-postman-runtime:latestcb72e46a1b3c
marked@0.3.6
4.0.10

Open the chart page →

10,732
bredbandskollen-prometheus-exporteraolde0.2.31 of 1See more

bredbandskollen-prometheus-exporter aolde 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
marked@2.0.3
4.0.10

Open the chart page →

1,972
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
marked@1.2.9
4.0.10

Open the chart page →

2,519
lametric-nightscout-proxyaolde0.1.01 of 1See more

lametric-nightscout-proxy aolde 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
ghcr.io/aolde/lametric-nightscout-proxy:latest7d1951b6baf5
marked@2.1.3
4.0.10

Open the chart page →

1,186
trifidappuio2.0.21 of 1See more

trifid appuio 2.0.2

1 of the 1 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
zazuko/trifid:2.3.7054be137de70
marked@0.3.19
4.0.10

Open the chart page →

2,783
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
marked@0.4.0
4.0.10

Open the chart page →

29,901
cryptpadgeek-cookbookVerified publisher0.4.21 of 1See more

cryptpad geek-cookbook 0.4.2

1 of the 1 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
promasu/cryptpad:v4.14.1-nginx51d1142b9f95
marked@1.1.0
4.0.10

Open the chart page →

974
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
governify/registry:v3.4.0d3f37f4f8168
marked@0.3.19
4.0.10

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
governify/registry:v3.4.0d3f37f4f8168
marked@0.3.19
4.0.10

Open the chart page →

24,319
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
marked@1.1.1
4.0.10
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
marked@1.1.1
4.0.10
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
marked@1.1.1
4.0.10
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
marked@1.1.1
4.0.10

Open the chart page →

89,959
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
marked@0.7.0
4.0.10

Open the chart page →

4,944
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
marked@2.1.3
4.0.10

Open the chart page →

5,287
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
marked@1.1.0
4.0.10

Open the chart page →

6,684
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
marked@0.7.0
4.0.10

Open the chart page →

109,294
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
marked@1.2.7
4.0.10

Open the chart page →

27,465
ferdi-serverobeoneVerified publisher1.0.31 of 2See more

ferdi-server obeone 1.0.3

1 of the 2 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
getferdi/ferdi-server:1.3.26e620b85afaa
marked@1.2.9
4.0.10

Open the chart page →

1,866
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
marked@0.6.3
4.0.10

Open the chart page →

6,524
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
marked@1.2.9
4.0.10

Open the chart page →

29,227
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
marked@2.1.3
4.0.10

Open the chart page →

3,118
workshop-exercisestakaterVerified publisher0.0.2601 of 1See more

workshop-exercise stakater 0.0.260

1 of the 1 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
stakater/workshop-exercise:0.0.26076926b7159d3
marked@1.2.9
4.0.10

Open the chart page →

992
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-21681.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
marked@2.1.3
4.0.10

Open the chart page →

3,118

Container images carrying it

22 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
governify/registry:v3.4.0d3f37f4f8168
marked@0.3.19
4.0.10
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
marked@2.1.3
4.0.10
2
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
marked@2.0.3
4.0.10
1
daskdev/dask-notebook:1.1.0052630f5ca04
marked@0.4.0
4.0.10
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
marked@0.7.0
4.0.10
1
getferdi/ferdi-server:1.3.26e620b85afaa
marked@1.2.9
4.0.10
1
linuxserver/codimd:latestb801bbcf6386
marked@1.2.7
4.0.10
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
marked@0.3.6
4.0.10
1
mozilla/sentencecollector:2.0.91da6ff5c4895
marked@1.1.0
4.0.10
1
phntom/codimd:2.4.31b9aafbb62e6
marked@0.6.3
4.0.10
1
promasu/cryptpad:v4.14.1-nginx51d1142b9f95
marked@1.1.0
4.0.10
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
marked@0.7.0
4.0.10
1
stakater/workshop-exercise:0.0.26076926b7159d3
marked@1.2.9
4.0.10
1
zazuko/trifid:2.3.7054be137de70
marked@0.3.19
4.0.10
1
ghcr.io/aolde/lametric-nightscout-proxy:latest7d1951b6baf5
marked@2.1.3
4.0.10
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
marked@1.1.1
4.0.10
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
marked@1.1.1
4.0.10
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
marked@1.1.1
4.0.10
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
marked@1.1.1
4.0.10
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
marked@1.2.9
4.0.10
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
marked@2.1.3
4.0.10
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
marked@1.2.9
4.0.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.