StackRadar

CVE-2022-2309

High

Advisory

Published 5 Jul 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
239
of 17,781 indexed, latest versions
Container images
247
deployed by those charts
Fix available
4 of 5
affected packages

lxml NULL Pointer Dereference allows attackers to cause a denial of service

Carried by container images the latest versions of 239 of 17,781 indexed charts deploy, on 247 images.

Affected packageAffected versionsFixed inImages
libxml2apk2.9.10-r6, 2.9.10-r7, 2.9.12-r0, 2.9.12-r1+3 more2.9.14-r199
libxml2deb2.9.10+dfsg-5, 2.9.10+dfsg-5ubuntu0.20.04.1, 2.9.10+dfsg-5ubuntu0.20.04.2, 2.9.10+dfsg-5ubuntu0.20.04.3+4 more2.9.10+dfsg-5ubuntu0.20.04.5, 2.9.13+dfsg-1ubuntu0.2, 2.9.14+dfsg-1.3~deb12u190
lxmlpypi3.2.1, 3.6.4, 4.1.0, 4.2.1+16 more4.9.162
lxmldeb4.8.0-1build1no fix listed1
libxml2rpm2.9.7-lp151.5.3.12.10.1-1.12
OSV records
ALPINE-CVE-2022-2309DEBIAN-CVE-2022-2309GHSA-wrxv-2j5q-m38wUBUNTU-CVE-2022-2309openSUSE-SU-2024:12290-1
Also known as
PYSEC-2022-230, USN-5760-1

Charts affected

239 by stars
ChartLatestAffected imagesRadar Score
tenant-namespacepnnl-miscscripts0.6.231 of 1See more

tenant-namespace pnnl-miscscripts 0.6.23

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

2,578
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

9,167
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
lxml@4.6.5
4.9.1

Open the chart page →

4,616
pyredispyredis-helm0.1.01 of 2See more

pyredis pyredis-helm 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
avinash263/pyredis263:latestaa2b8727f1a6
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

14,537
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
libxml2@2.9.7-lp151.5.3.1
2.10.1-1.1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
libxml2@2.9.7-lp151.5.3.1
2.10.1-1.1

Open the chart page →

11,942
dolibarrraphaelVerified publisher0.0.11 of 1See more

dolibarr raphael 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
monogramm/docker-dolibarr:13.0-alpine5afd99523984
libxml2@2.9.10-r7
2.9.14-r1

Open the chart page →

3,466
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

15,520
laravel-workerrenoki-co1.1.01 of 1See more

laravel-worker renoki-co 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

5,687
reportportalreportportal5.7.21 of 8See more

reportportal reportportal 5.7.2

1 of the 8 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
reportportal/service-ui:5.7.20a08784eb901
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

25,737
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
lxml@4.6.3
4.9.1

Open the chart page →

5,215
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
lxml@3.2.1
4.9.1

Open the chart page →

3,978
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

16,620
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
lxml@4.3.2
4.9.1

Open the chart page →

8,694
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

30,687
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gcr.io/kubecost1/frontend:prod-1.82.2ba66607c947c
libxml2@2.9.10-r7
2.9.14-r1

Open the chart page →

16,506
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
lxml@4.5.2
4.9.1

Open the chart page →

3,044
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.20-alpine38d9dc79cc1d
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

13,767
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2

Open the chart page →

12,048
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2

Open the chart page →

12,048
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
lxml@4.9.0
4.9.1

Open the chart page →

18,756
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
lxml@3.2.1
4.9.1

Open the chart page →

4,240
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.2
xeladock/nginx2:latestc259a67b1dff
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.2

Open the chart page →

17,461
krokiteochenglim1.0.13 of 5See more

kroki teochenglim 1.0.1

3 of the 5 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.16.0bd629239a64e
libxml2@2.9.12-r1
2.9.14-r1
yuzutech/kroki-excalidraw:0.16.015c9eef47a62
libxml2@2.9.12-r1
2.9.14-r1
yuzutech/kroki-mermaid:0.16.07acc8fe7caba
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

8,715
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
denisshav/frontend:latestb97cc69fbac6
libxml2@2.9.10-r6
2.9.14-r1

Open the chart page →

6,881
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
lxml@4.8.0-1build1
lxml@4.8.0
no fix listed
4.9.1

Open the chart page →

13,459
vulcanvulcan0.2.21 of 2See more

vulcan vulcan 0.2.2

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
library/postgres:13.3-alpinee98a69a83639
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

1,516
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
libxml2@2.9.12-r2
2.9.14-r1

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

1,523
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
libxml2@2.9.14+dfsg-1.2
2.9.14+dfsg-1.3~deb12u1

Open the chart page →

10,001
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5

Open the chart page →

28,605
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
libxml2@2.9.13-r0
2.9.14-r1

Open the chart page →

7,552
longhornwenerme1.2.32 of 2See more

longhorn wenerme 1.2.3

2 of the 2 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
longhornio/longhorn-ui:v1.2.3148598de4b7d
libxml2@2.9.12-r0
2.9.14-r1

Open the chart page →

15,230
ceph-csi-cephfswikimedia0.1.81 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

1 of the 5 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
4.9.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.131 of 6See more

ceph-csi-rbd wikimedia 0.1.13

1 of the 6 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
lxml@4.2.3
4.9.1

Open the chart page →

11,784
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
libxml2@2.9.12-r0
lxml@4.6.4
2.9.14-r1
4.9.1

Open the chart page →

2,643
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libxml2@2.9.14-r0
2.9.14-r1

Open the chart page →

16,083
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-2309.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
libxml2@2.9.12-r1
2.9.14-r1

Open the chart page →

2,534

Container images carrying it

247 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
stashapp/stash:latest24dbd7607174
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
statcan/ckan:2.93921305425b8
libxml2@2.9.10+dfsg-5
lxml@4.4.2
2.9.10+dfsg-5ubuntu0.20.04.5
4.9.1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
lxml@4.9.0
4.9.1
1
swaggerapi/swagger-ui:v4.12.00d7088d47928
libxml2@2.9.14-r0
2.9.14-r1
1
t3nde/matomo:4.3.1-fpm-alpine329ce194393a
libxml2@2.9.12-r1
2.9.14-r1
1
taemon1337/ingress-dashboard:0.0.10e8f5096c66bb
libxml2@2.9.12-r2
2.9.14-r1
1
taigaio/taiga-back:6.4.29f97323cc150
lxml@4.6.3
4.9.1
1
taigaio/taiga-front:6.4.24d367b1e1250
libxml2@2.9.10-r6
2.9.14-r1
1
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libxml2@2.9.14-r0
2.9.14-r1
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
timescale/timescaledb-postgis:latest-pg127758704d4a14
libxml2@2.9.10-r6
2.9.14-r1
1
trafex/php-nginx:2.4.07282edfca2bf
libxml2@2.9.12-r1
2.9.14-r1
1
trafex/php-nginx:2.2.0ee0b7c6cce07
libxml2@2.9.12-r1
2.9.14-r1
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
libxml2@2.9.10-r6
2.9.14-r1
1
tvanro/prerender-alpine:6.4.06909015f0328
libxml2@2.9.12-r1
2.9.14-r1
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
lxml@4.8.0-1build1
lxml@4.8.0
no fix listed
4.9.1
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
lxml@4.7.1
4.9.1
1
vectorim/riot-web:v1.7.3384bb5af00b5d
libxml2@2.9.12-r1
2.9.14-r1
1
voltha/voltha-cli:1.6.0c4e41e92f046
lxml@3.6.4
4.9.1
1
voltha/voltha-netconf:1.6.037f80524c207
lxml@3.6.4
4.9.1
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
lxml@3.6.4
4.9.1
1
voltha/voltha-tester:1.7.0655c3048a602
lxml@3.6.4
4.9.1
1
voltha/voltha-voltha:1.6.0ff596b62de59
lxml@3.6.4
4.9.1
1
weblate/weblate:3.11.3-182848df56ecd
lxml@4.3.2
4.9.1
1
xeladock/mysql_dns:latest4baf531453f1
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.2
1
xeladock/nginx2:latestc259a67b1dff
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.2
1
yuzutech/kroki-bpmn:0.16.0bd629239a64e
libxml2@2.9.12-r1
2.9.14-r1
1
yuzutech/kroki-excalidraw:0.16.015c9eef47a62
libxml2@2.9.12-r1
2.9.14-r1
1
yuzutech/kroki-mermaid:0.16.07acc8fe7caba
libxml2@2.9.12-r1
2.9.14-r1
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
libxml2@2.9.10-r6
2.9.14-r1
1
gcr.io/kubecost1/frontend:prod-1.81.096dfb19838b8
libxml2@2.9.10-r6
2.9.14-r1
1
gcr.io/kubecost1/frontend:prod-1.82.2ba66607c947c
libxml2@2.9.10-r7
2.9.14-r1
1
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
libxml2@2.9.12-r2
2.9.14-r1
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/conductionnl/commonground-gateway-frontend:dev3b3fbb57cae8
libxml2@2.9.14-r0
2.9.14-r1
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
libxml2@2.9.13-r0
2.9.14-r1
1
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
lxml@4.6.4
4.9.1
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.