CVE-2022-22970
HighAdvisory
Published 13 May 2022In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.020
- 79th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 223
- of 17,781 indexed, latest versions
- Container images
- 169
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Denial of service in Spring Framework
Carried by container images the latest versions of 223 of 17,781 indexed charts deploy, on 169 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| spring-beansmaven | 2.5.6.SEC03, 3.0.7, 3.0.7.RELEASE, 3.2.18.RELEASE+53 more | 5.2.22.RELEASE, 5.3.20 | 169 |
- OSV records
- GHSA-hh26-6xwr-ggv7
Charts affected
223 by stars
Container images carrying it
169 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| seataio/ | ee1ed55f4144 | spring-beans | 5.3.20 | 1 |
| seldonio/ | ba81b17f00eb | spring-beans | 5.2.22.RELEASE | 1 |
| seldonio/ | eea0d3f578ca | spring-beans | 5.2.22.RELEASE | 1 |
| seldonio/ | 29e362bb1ba2 | spring-beans | 5.2.22.RELEASE | 1 |
| slagattollas/ | cecd95e31486 | spring-beans | 5.3.20 | 1 |
| slagattollas/ | dc63973dae0d | spring-beans | 5.3.20 | 1 |
| slamdev/ | 3ca20c184c55 | spring-beans | 5.3.20 | 1 |
| someblackmagic/ | 0d63ba37a560 | spring-beans | 5.3.20 | 1 |
| stanislovesid/ | 4fe1ed26e194 | spring-beans | 5.3.20 | 1 |
| torrespro/ | 6d3bd305a1ba | spring-beans | 5.2.22.RELEASE | 1 |
| vientoprojects/ | eb2a71531741 | spring-beans | 5.3.20 | 1 |
| xetusoss/ | 88f25242b9ee | spring-beans | 5.2.22.RELEASE | 1 |
| zenko/ | 386a1f48ec0e | spring-beans | 5.2.22.RELEASE | 1 |
| gcr.io/ | 0ee5f968d2ab | spring-beans | 5.2.22.RELEASE | 1 |
| ghcr.io/ | ef3670f7e0a8 | spring-beans | 5.2.22.RELEASE | 1 |
| ghcr.io/ | baa4fa9549dc | spring-beans | 5.2.22.RELEASE | 1 |
| ghcr.io/ | 41b45003c6b6 | spring-beans | 5.2.22.RELEASE | 1 |
| public.ecr.aws/ | 8cdcb7e83f9f | spring-beans | 5.3.20 | 1 |
| quay.io/ | 7c3fc28746ef | spring-beans | 5.3.20 | 1 |