StackRadar

CVE-2022-22950

Medium

Advisory

Published 3 Apr 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.361
98th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
205
of 17,781 indexed, latest versions
Container images
153
deployed by those charts
Fix available
1 of 1
affected package

Allocation of Resources Without Limits or Throttling in Spring Framework

Carried by container images the latest versions of 205 of 17,781 indexed charts deploy, on 153 images.

Affected packageAffected versionsFixed inImages
spring-expressionmaven3.2.18.RELEASE, 4.1.1.RELEASE, 4.2.1.RELEASE, 4.3.1.RELEASE+47 more5.2.20.RELEASE, 5.3.17153
OSV records
GHSA-558x-2xjg-6232

Charts affected

205 by stars
ChartLatestAffected imagesRadar Score
webapp-db-javawebapp-db-java-repo0.1.01 of 2See more

webapp-db-java webapp-db-java-repo 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-22950.

Container imageDigestPackageFixed in
arturisimo/webapp-db-java:v2c95524e90b57
spring-expression@5.3.15
5.3.17

Open the chart page →

2,566
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-22950.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-expression@5.3.15
5.3.17

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-22950.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-expression@5.3.15
5.3.17

Open the chart page →

28,605
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-22950.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
spring-expression@5.2.5.RELEASE
5.2.20.RELEASE

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-22950.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
spring-expression@5.1.2.RELEASE
5.2.20.RELEASE

Open the chart page →

6,213

Container images carrying it

153 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
microcks/microcks:0.8.0e3a3e0c67b09
spring-expression@4.3.20.RELEASE
5.2.20.RELEASE
1
molynx/planner:v1441c9f52f092
spring-expression@5.3.13
5.3.17
1
nacos/nacos-server:1.4.1fe6e5688cdf3
spring-expression@5.1.18.RELEASE
5.2.20.RELEASE
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
spring-expression@4.3.6.RELEASE
5.2.20.RELEASE
1
opencord/ves-agent:1.0.04187e2a8c918
spring-expression@5.0.6.RELEASE
5.2.20.RELEASE
1
openkm/openkm-ce:6.3.113bc465a7461b
spring-expression@3.2.18.RELEASE
5.2.20.RELEASE
1
openzipkin/zipkin:2.21.060c3970df479
spring-expression@5.2.5.RELEASE
5.2.20.RELEASE
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
spring-expression@5.2.0.RELEASE
5.2.20.RELEASE
1
opsmx11/issuegen:v2.1.05c50ca123d88
spring-expression@5.1.10.RELEASE
5.2.20.RELEASE
1
oscarsotosanchez/planner:v1.0730c00a099b8
spring-expression@5.3.1
5.3.17
1
paulczar/spring-helloworld:latestc7140cecd5f7
spring-expression@5.1.5.RELEASE
5.2.20.RELEASE
1
pcarrascoponce/planner:v1.0981fc482442c
spring-expression@5.3.13
5.3.17
1
platform9community/admin-server:latestde3fa9b70df1
spring-expression@5.2.7.RELEASE
5.2.20.RELEASE
1
platform9community/api-gateway:latest40a4970de568
spring-expression@5.2.7.RELEASE
5.2.20.RELEASE
1
platform9community/customers-service:latest2089811e5cc6
spring-expression@5.2.7.RELEASE
5.2.20.RELEASE
1
platform9community/vets-service:latestd1165c94dfb3
spring-expression@5.2.7.RELEASE
5.2.20.RELEASE
1
platform9community/visits-service:latest8d11b50368c6
spring-expression@5.2.7.RELEASE
5.2.20.RELEASE
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
spring-expression@4.3.1.RELEASE
5.2.20.RELEASE
1
redestroyder/authorization-service:0.0.1740364a619fd
spring-expression@5.3.15
5.3.17
1
redestroyder/business-service:0.0.1db03499a0726
spring-expression@5.3.15
5.3.17
1
refar/apm-api:v5.7.1241373fa2972
spring-expression@5.2.8.RELEASE
5.2.20.RELEASE
1
refar/apm-operator-server:v5.7.1e5490f050f9f
spring-expression@5.2.8.RELEASE
5.2.20.RELEASE
1
reportportal/service-api:5.7.29df41f8fb320
spring-expression@5.2.4.RELEASE
5.2.20.RELEASE
1
reportportal/service-authorization:5.7.09e73114dbd15
spring-expression@5.2.4.RELEASE
5.2.20.RELEASE
1
reportportal/service-jobs:5.7.2dc166c58485a
spring-expression@5.3.4
5.3.17
1
richardchesterwood/k8s-fleetman-api-gateway:release2518f946b9f05
spring-expression@4.3.7.RELEASE
5.2.20.RELEASE
1
richardchesterwood/k8s-fleetman-position-simulator:release20b540a28f5a6
spring-expression@4.3.2.RELEASE
5.2.20.RELEASE
1
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
spring-expression@4.3.2.RELEASE
5.2.20.RELEASE
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
spring-expression@5.3.13
5.3.17
1
robotshop/rs-shipping:latest89753ab48919
spring-expression@5.2.8.RELEASE
5.2.20.RELEASE
1
rundeck/rundeck:3.2.74d64fe56f767
spring-expression@4.3.24.RELEASE
5.2.20.RELEASE
1
rundeck/rundeck:3.0.16b13e8059ad72
spring-expression@4.3.18.RELEASE
5.2.20.RELEASE
1
salaboy/fmtok8s-monolith:v0.1.0f225568e6d03
spring-expression@5.2.8.RELEASE
5.2.20.RELEASE
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
spring-expression@5.3.13
5.3.17
1
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
spring-expression@5.1.8.RELEASE
5.2.20.RELEASE
1
seataio/seata-server:1.5.1ee1ed55f4144
spring-expression@5.3.13
5.3.17
1
seldonio/apife:0.2.7ba81b17f00eb
spring-expression@4.3.20.RELEASE
5.2.20.RELEASE
1
seldonio/apife:0.3.1eea0d3f578ca
spring-expression@4.3.20.RELEASE
5.2.20.RELEASE
1
seldonio/cluster-manager:0.2.729e362bb1ba2
spring-expression@4.3.20.RELEASE
5.2.20.RELEASE
1
slagattollas/planner-practica:latestcecd95e31486
spring-expression@5.3.1
5.3.17
1
slagattollas/toposervice-practica:latestdc63973dae0d
spring-expression@5.3.1
5.3.17
1
slamdev/hetzner-irobo:0.0.13ca20c184c55
spring-expression@5.3.10
5.3.17
1
someblackmagic/smtp-fake-server:latest0d63ba37a560
spring-expression@5.3.2
5.3.17
1
stanislovesid/oracle-host-app:14fe1ed26e194
spring-expression@5.3.12
5.3.17
1
torrespro/mca-worker:2.0.06d3bd305a1ba
spring-expression@5.2.1.RELEASE
5.2.20.RELEASE
1
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
spring-expression@5.3.9
5.3.17
1
xetusoss/archiva:v2.2.588f25242b9ee
spring-expression@4.2.1.RELEASE
5.2.20.RELEASE
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
spring-expression@5.2.3.RELEASE
5.2.20.RELEASE
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
spring-expression@5.2.7.RELEASE
5.2.20.RELEASE
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
spring-expression@5.2.6.RELEASE
5.2.20.RELEASE
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.