StackRadar

CVE-2022-22950

Medium

Advisory

Published 3 Apr 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.361
98th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
205
of 17,781 indexed, latest versions
Container images
153
deployed by those charts
Fix available
1 of 1
affected package

Allocation of Resources Without Limits or Throttling in Spring Framework

Carried by container images the latest versions of 205 of 17,781 indexed charts deploy, on 153 images.

Affected packageAffected versionsFixed inImages
spring-expressionmaven3.2.18.RELEASE, 4.1.1.RELEASE, 4.2.1.RELEASE, 4.3.1.RELEASE+47 more5.2.20.RELEASE, 5.3.17153
OSV records
GHSA-558x-2xjg-6232

Charts affected

205 by stars
ChartLatestAffected imagesRadar Score
webapp-db-javawebapp-db-java-repo0.1.01 of 2See more

webapp-db-java webapp-db-java-repo 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-22950.

Container imageDigestPackageFixed in
arturisimo/webapp-db-java:v2c95524e90b57
spring-expression@5.3.15
5.3.17

Open the chart page →

2,566
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-22950.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-expression@5.3.15
5.3.17

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-22950.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
spring-expression@5.3.15
5.3.17

Open the chart page →

28,605
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-22950.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
spring-expression@5.2.5.RELEASE
5.2.20.RELEASE

Open the chart page →

5,806
is-pattern-1wso2is-pattern15.11.01 of 2See more

is-pattern-1 wso2is-pattern1 5.11.0

1 of the 2 container images this version deploys carry CVE-2022-22950.

Container imageDigestPackageFixed in
massimolauri/wso2is:5.11.0-centose08abf0ce767
spring-expression@5.1.2.RELEASE
5.2.20.RELEASE

Open the chart page →

6,213

Container images carrying it

153 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
spring-expression@5.1.8.RELEASE
5.2.20.RELEASE
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
spring-expression@5.3.16
5.3.17
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
spring-expression@5.3.7
5.3.17
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.