StackRadar

CVE-2022-2309

High

Advisory

Published 5 Jul 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
239
of 17,781 indexed, latest versions
Container images
247
deployed by those charts
Fix available
4 of 5
affected packages

lxml NULL Pointer Dereference allows attackers to cause a denial of service

Carried by container images the latest versions of 239 of 17,781 indexed charts deploy, on 247 images.

Affected packageAffected versionsFixed inImages
libxml2apk2.9.10-r6, 2.9.10-r7, 2.9.12-r0, 2.9.12-r1+3 more2.9.14-r199
libxml2deb2.9.10+dfsg-5, 2.9.10+dfsg-5ubuntu0.20.04.1, 2.9.10+dfsg-5ubuntu0.20.04.2, 2.9.10+dfsg-5ubuntu0.20.04.3+4 more2.9.10+dfsg-5ubuntu0.20.04.5, 2.9.13+dfsg-1ubuntu0.2, 2.9.14+dfsg-1.3~deb12u190
lxmlpypi3.2.1, 3.6.4, 4.1.0, 4.2.1+16 more4.9.162
lxmldeb4.8.0-1build1no fix listed1
libxml2rpm2.9.7-lp151.5.3.12.10.1-1.12
OSV records
ALPINE-CVE-2022-2309DEBIAN-CVE-2022-2309GHSA-wrxv-2j5q-m38wUBUNTU-CVE-2022-2309openSUSE-SU-2024:12290-1
Also known as
PYSEC-2022-230, USN-5760-1

Charts affected

239 by stars
ChartLatestAffected imagesRadar Score
tenant-namespacepnnl-miscscripts0.6.231 of 1See more

tenant-namespace pnnl-miscscripts 0.6.23

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

2,578
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

9,167
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
lxml@4.6.5
4.9.1

Open the chart page →

4,616
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

14,537
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
libxml2@2.9.7-lp151.5.3.1
2.10.1-1.1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
libxml2@2.9.7-lp151.5.3.1
2.10.1-1.1

Open the chart page →

11,942
dolibarrraphaelVerified publisher0.0.11 of 1See more

dolibarr raphael 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
monogramm/docker-dolibarr:13.0-alpine5afd99523984
libxml2@2.9.10-r7
2.9.14-r1

Open the chart page →

3,466
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

15,520
laravel-workerrenoki-co1.1.01 of 1See more

laravel-worker renoki-co 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

5,687
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
reportportal/service-ui:5.7.20a08784eb901
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

25,737
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
lxml@4.6.3
4.9.1

Open the chart page →

5,215
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
4.9.1

Open the chart page →

3,978
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

16,620
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
lxml@4.3.2
4.9.1

Open the chart page →

8,694
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

30,687
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gcr.io/kubecost1/frontend:prod-1.82.2ba66607c947c
libxml2@2.9.10-r7
2.9.14-r1

Open the chart page →

16,506
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
lxml@4.5.2
4.9.1

Open the chart page →

3,044
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.20-alpine38d9dc79cc1d
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

13,767
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2

Open the chart page →

12,048
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2

Open the chart page →

12,048
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
lxml@4.9.0
4.9.1

Open the chart page →

18,756
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
lxml@3.2.1
4.9.1

Open the chart page →

4,240
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.2
xeladock/nginx2:latestc259a67b1dff
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.2

Open the chart page →

17,461
krokiteochenglim1.0.13 of 5See more

kroki teochenglim 1.0.1

3 of the 5 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.16.0bd629239a64e
libxml2@2.9.12-r1
2.9.14-r1
yuzutech/kroki-excalidraw:0.16.015c9eef47a62
libxml2@2.9.12-r1
2.9.14-r1
yuzutech/kroki-mermaid:0.16.07acc8fe7caba
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

8,715
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
denisshav/frontend:latestb97cc69fbac6
libxml2@2.9.10-r6
2.9.14-r1

Open the chart page →

6,881
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
lxml@4.8.0-1build1
lxml@4.8.0
no fix listed
4.9.1

Open the chart page →

13,459
vulcanvulcan0.2.21 of 2See more

vulcan vulcan 0.2.2

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
library/postgres:13.3-alpinee98a69a83639
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

1,516
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
libxml2@2.9.12-r2
2.9.14-r1

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

1,523
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

10,001
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

28,605
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
libxml2@2.9.13-r0
2.9.14-r1

Open the chart page →

7,552
longhornwenerme1.2.32 of 2See more

longhorn wenerme 1.2.3

2 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
longhornio/longhorn-ui:v1.2.3148598de4b7d
libxml2@2.9.12-r0
2.9.14-r1

Open the chart page →

15,230
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
4.9.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
4.9.1

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
libxml2@2.9.12-r0
lxml@4.6.4
2.9.14-r1
4.9.1

Open the chart page →

2,643
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

16,083
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

2,534

Container images carrying it

247 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
crazymax/rrdcached:1.7.2-r4042536a06596
libxml2@2.9.12-r1
2.9.14-r1
1
datadog/agent:7.22.08f20e56b5311
lxml@4.5.0
4.9.1
1
denisshav/frontend:latestb97cc69fbac6
libxml2@2.9.10-r6
2.9.14-r1
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
digitalist/nginx:1.21.6eec27ad73eaa
libxml2@2.9.12-r2
2.9.14-r1
1
dniel/forwardauth-spademo:masterd3e38df449a2
libxml2@2.9.12-r1
2.9.14-r1
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
libxml2@2.9.14-r0
2.9.14-r1
1
engrmth/bnkr:2.1.06d8464e6f0e8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
esailors/aws-ecr-http-proxy:1.5.15608ae045fa7
libxml2@2.9.13-r0
2.9.14-r1
1
factly/dega-studio:0.15.1140fbaa6d555
libxml2@2.9.12-r1
2.9.14-r1
1
factly/kavach-web:0.22.30cf361b41798
libxml2@2.9.13-r0
2.9.14-r1
1
factly/vidcheck-studio:0.12.024be158ec7d3
libxml2@2.9.12-r0
2.9.14-r1
1
galaxy/galaxy-init:v18.010267bad550e6
lxml@4.1.0
4.9.1
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
lxml@4.5.2
4.9.1
1
gethue/hue:4.10.05702b2c37ff9
lxml@4.6.3
4.9.1
1
gristlabs/grist:0.7.96e71b1914a7e
lxml@4.6.3
4.9.1
1
gulacedia/web-dvwa-new:v367b467d961ca
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1
1
haugene/transmission-openvpn:4.0059216cfae4b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
haveagitgat/tdarr:2.00.181256348872ce
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
lxml@4.8.0
4.9.1
1
ibarreche/cloud-back-ci:lateste16a469c5791
libxml2@2.9.13-r0
2.9.14-r1
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
lxml@3.2.1
4.9.1
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
lxml@3.2.1
4.9.1
1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
lxml@3.2.1
4.9.1
1
improwised/erpnext-worker:v13.4.197280b55cbd4
lxml@4.6.3
4.9.1
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
jakowenko/double-take:1.6.0b858bac9e32a
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
johnblack77/clustereye:latest-amd64bb53ceb8442e
libxml2@2.9.10-r6
2.9.14-r1
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
kanboard/kanboard:v1.2.200b6d33dbbc16
libxml2@2.9.10-r7
2.9.14-r1
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
lxml@4.5.2
4.9.1
1
klausmeyer/docker-registry-browser:1.4.0bdc4c6b8595b
libxml2@2.9.12-r1
2.9.14-r1
1
kobotoolbox/kobocat:2.022.24ab15679454415
lxml@4.8.0
4.9.1
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
lxml@4.8.0
4.9.1
1
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
libxml2@2.9.14-r0
2.9.14-r1
1
lavandadelpatio/frontend:masterccfc0cd77803
libxml2@2.9.12-r1
2.9.14-r1
1
library/adminer:4.7143ec8cc2f3a
libxml2@2.9.10-r6
2.9.14-r1
1
library/postgres:14.1-alpine578ca5c8452c
libxml2@2.9.12-r2
2.9.14-r1
1
library/postgres:13.6-alpine8522c9920d88
libxml2@2.9.13-r0
2.9.14-r1
1
library/postgres:13.3-alpinee98a69a83639
libxml2@2.9.12-r1
2.9.14-r1
1
librenms/librenms:22.4.14f1f3d667cc7
libxml2@2.9.13-r0
2.9.14-r1
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
lxml@4.6.3
2.9.10+dfsg-5ubuntu0.20.04.5
4.9.1
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
lxml@4.2.2
4.9.1
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
lxml@4.4.2
4.9.1
1
linuxserver/jellyfin:10.7.72427dde159a2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
lxml@4.4.2
4.9.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.