StackRadar

CVE-2022-2309

High

Advisory

Published 5 Jul 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
239
of 17,781 indexed, latest versions
Container images
247
deployed by those charts
Fix available
4 of 5
affected packages

lxml NULL Pointer Dereference allows attackers to cause a denial of service

Carried by container images the latest versions of 239 of 17,781 indexed charts deploy, on 247 images.

Affected packageAffected versionsFixed inImages
libxml2apk2.9.10-r6, 2.9.10-r7, 2.9.12-r0, 2.9.12-r1+3 more2.9.14-r199
libxml2deb2.9.10+dfsg-5, 2.9.10+dfsg-5ubuntu0.20.04.1, 2.9.10+dfsg-5ubuntu0.20.04.2, 2.9.10+dfsg-5ubuntu0.20.04.3+4 more2.9.10+dfsg-5ubuntu0.20.04.5, 2.9.13+dfsg-1ubuntu0.2, 2.9.14+dfsg-1.3~deb12u190
lxmlpypi3.2.1, 3.6.4, 4.1.0, 4.2.1+16 more4.9.162
lxmldeb4.8.0-1build1no fix listed1
libxml2rpm2.9.7-lp151.5.3.12.10.1-1.12
OSV records
ALPINE-CVE-2022-2309DEBIAN-CVE-2022-2309GHSA-wrxv-2j5q-m38wUBUNTU-CVE-2022-2309openSUSE-SU-2024:12290-1
Also known as
PYSEC-2022-230, USN-5760-1

Charts affected

239 by stars
ChartLatestAffected imagesRadar Score
tenant-namespacepnnl-miscscripts0.6.231 of 1See more

tenant-namespace pnnl-miscscripts 0.6.23

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

2,578
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

9,167
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
lxml@4.6.5
4.9.1

Open the chart page →

4,616
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

14,537
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
libxml2@2.9.7-lp151.5.3.1
2.10.1-1.1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
libxml2@2.9.7-lp151.5.3.1
2.10.1-1.1

Open the chart page →

11,942
dolibarrraphaelVerified publisher0.0.11 of 1See more

dolibarr raphael 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
monogramm/docker-dolibarr:13.0-alpine5afd99523984
libxml2@2.9.10-r7
2.9.14-r1

Open the chart page →

3,466
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

15,520
laravel-workerrenoki-co1.1.01 of 1See more

laravel-worker renoki-co 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

5,687
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
reportportal/service-ui:5.7.20a08784eb901
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

25,737
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
lxml@4.6.3
4.9.1

Open the chart page →

5,215
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
4.9.1

Open the chart page →

3,978
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

16,620
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
lxml@4.3.2
4.9.1

Open the chart page →

8,694
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

30,687
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gcr.io/kubecost1/frontend:prod-1.82.2ba66607c947c
libxml2@2.9.10-r7
2.9.14-r1

Open the chart page →

16,506
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
lxml@4.5.2
4.9.1

Open the chart page →

3,044
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.20-alpine38d9dc79cc1d
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

13,767
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2

Open the chart page →

12,048
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2

Open the chart page →

12,048
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
lxml@4.9.0
4.9.1

Open the chart page →

18,756
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
lxml@3.2.1
4.9.1

Open the chart page →

4,240
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.2
xeladock/nginx2:latestc259a67b1dff
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.2

Open the chart page →

17,461
krokiteochenglim1.0.13 of 5See more

kroki teochenglim 1.0.1

3 of the 5 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.16.0bd629239a64e
libxml2@2.9.12-r1
2.9.14-r1
yuzutech/kroki-excalidraw:0.16.015c9eef47a62
libxml2@2.9.12-r1
2.9.14-r1
yuzutech/kroki-mermaid:0.16.07acc8fe7caba
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

8,715
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
denisshav/frontend:latestb97cc69fbac6
libxml2@2.9.10-r6
2.9.14-r1

Open the chart page →

6,881
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
lxml@4.8.0-1build1
lxml@4.8.0
no fix listed
4.9.1

Open the chart page →

13,459
vulcanvulcan0.2.21 of 2See more

vulcan vulcan 0.2.2

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
library/postgres:13.3-alpinee98a69a83639
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

1,516
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
libxml2@2.9.12-r2
2.9.14-r1

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

1,523
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

10,001
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

28,605
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
libxml2@2.9.13-r0
2.9.14-r1

Open the chart page →

7,552
longhornwenerme1.2.32 of 2See more

longhorn wenerme 1.2.3

2 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
longhornio/longhorn-ui:v1.2.3148598de4b7d
libxml2@2.9.12-r0
2.9.14-r1

Open the chart page →

15,230
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
4.9.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
4.9.1

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
libxml2@2.9.12-r0
lxml@4.6.4
2.9.14-r1
4.9.1

Open the chart page →

2,643
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

16,083
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

2,534

Container images carrying it

247 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
longhornio/longhorn-ui:v1.2.3148598de4b7d
libxml2@2.9.12-r0
2.9.14-r1
1
longhornio/longhorn-ui:v1.1.165560eabe3ee
libxml2@2.9.10-r6
2.9.14-r1
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
lxml@4.8.0
4.9.1
1
mcronce/yadms-ftp:latestf820ef2e3c26
lxml@4.4.1
4.9.1
1
mcronce/yadms-web:latestc03c1c7f5aa9
lxml@4.4.1
4.9.1
1
mediagis/nominatim:3.7c15e941485ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
1
microcks/microcks:0.8.0e3a3e0c67b09
lxml@3.2.1
4.9.1
1
milesmcc/shynet:v0.12.0e821e31140f7
libxml2@2.9.12-r1
2.9.14-r1
1
monogramm/docker-dolibarr:13.0-alpine5afd99523984
libxml2@2.9.10-r7
2.9.14-r1
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
lxml@4.4.1
4.9.1
1
nacos/nacos-server:1.4.1fe6e5688cdf3
lxml@3.2.1
4.9.1
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
lxml@4.2.5
4.9.1
1
neilpang/acme.sh:3.0.2595809ad43a2
libxml2@2.9.12-r2
2.9.14-r1
1
nginxinc/nginx-unprivileged:1.20-alpine38d9dc79cc1d
libxml2@2.9.14-r0
2.9.14-r1
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
lxml@4.5.2
4.9.1
1
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
lxml@4.6.5
4.9.1
1
ohif/viewer:latestb4bfecdc7cc6
libxml2@2.9.12-r1
2.9.14-r1
1
omecproject/c3po-hssdb:master-latest28a90cc26716
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
opendatacube/pipelines:wofs-1.225d810e8504b8
lxml@4.2.1
4.9.1
1
opendatacube/restcube:latest91870111837c
lxml@4.2.1
4.9.1
1
opendatacube/wms:latest1b90cdf68831
lxml@4.2.1
4.9.1
1
openelevation/open-elevation:latest82fb21612e86
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
openemr/openemr:6.1.089eaa6d9a4e3
libxml2@2.9.13-r0
2.9.14-r1
1
openkm/openkm-ce:6.3.113bc465a7461b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
lxml@4.6.2
4.9.1
1
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
libxml2@2.9.10-r6
2.9.14-r1
1
pactfoundation/pact-broker:2.101.0.0a3021fc42834
libxml2@2.9.14-r0
2.9.14-r1
1
phntom/keeweb:1.17.4-kix10c75ed6dd606
libxml2@2.9.10-r6
2.9.14-r1
1
photoprism/photoprism:220629-jammy2954334adbda
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
pnnlmiscscripts/k8s-node-image:1.16.15-nginx-903b3fed5bdbc
libxml2@2.9.10-r6
2.9.14-r1
1
pnnlmiscscripts/k8s-node-image:1.18.20-nginx-323bfca2cfaaaf
libxml2@2.9.14-r0
2.9.14-r1
1
pnnlmiscscripts/k8s-node-image:1.17.17-nginx-3685debe11edc4
libxml2@2.9.14-r0
2.9.14-r1
1
pnnlmiscscripts/k8s-node-image:1.20.15-nginx-18bbc7a777f9f7
libxml2@2.9.14-r0
2.9.14-r1
1
pnnlmiscscripts/k8s-node-image:1.19.16-nginx-20c5c2b19e53a2
libxml2@2.9.14-r0
2.9.14-r1
1
project2team4/react:latest3ff031a08887
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
lxml@4.6.5
4.9.1
1
reportportal/service-ui:5.7.20a08784eb901
libxml2@2.9.14-r0
2.9.14-r1
1
rook/ceph:v1.20.72f970c425617
lxml@4.6.5
4.9.1
1
rook/ceph:v1.19.2944a1dd70496
lxml@4.6.5
4.9.1
1
saiakhil46/pizza-app:main-1ffbdf3dc39ce11e5d0
libxml2@2.9.10-r6
2.9.14-r1
1
seafileltd/seafile-mc:9.0.106693911bcc40
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
seafileltd/seafile-mc:9.0.97ac833196f60
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
libxml2@2.9.10+dfsg-5
lxml@4.6.3
2.9.10+dfsg-5ubuntu0.20.04.5
4.9.1
1
searx/searx:1.0.0-211-968b28993dbb3a6d9419
lxml@4.6.3
4.9.1
1
shlinkio/shlink:2.7.1c6729db1d3a8
libxml2@2.9.10-r6
2.9.14-r1
1
snipe/snipe-it:v6.0.1455fb7636a98c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
soulou2019/angular-nginx:latesta3970f97c215
libxml2@2.9.12-r2
2.9.14-r1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.