StackRadar

CVE-2022-23852

Critical

Advisory

Published 24 Jan 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.046
91st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
401
of 17,781 indexed, latest versions
Container images
329
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 401 of 17,781 indexed charts deploy, on 329 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+5 more2.1.0-4ubuntu1.4+esm4, 2.1.0-7ubuntu0.16.04.5+esm2, 2.2.5-3ubuntu0.4, 2.2.9-1ubuntu0.2163
expatapk2.2.9-r1, 2.2.10-r0, 2.2.10-r1, 2.2.10-r2+2 more2.2.10-r1, 2.2.10-r3, 2.4.4-r0146
expatrpm2.2.5-4.el80:2.2.5-4.el8_4.320
OSV records
ALPINE-CVE-2022-23852RHSA-2022:4834UBUNTU-CVE-2022-23852
Also known as
USN-5288-1

Charts affected

401 by stars
ChartLatestAffected imagesRadar Score
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-23852.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
expat@2.4.1-r0
2.4.4-r0

Open the chart page →

2,534

Container images carrying it

329 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
expat@2.2.9-1build1
2.2.9-1ubuntu0.2
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
expat@2.2.9-1build1
2.2.9-1ubuntu0.2
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.4
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
expat@2.2.10-r1
2.2.10-r3
1
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.2.29e36964bce26
expat@2.2.10-r1
2.2.10-r3
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
expat@2.2.10-r1
2.2.10-r3
1
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
expat@2.4.1-r0
2.4.4-r0
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
expat@2.2.9-1build1
2.2.9-1ubuntu0.2
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.3
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.3
1
quay.io/eclipse/che-devfile-registry:nightly5d25d47d6e17
expat@2.2.9-r1
2.2.10-r1
1
quay.io/eclipse/che-plugin-registry:nightlya88add0f8c93
expat@2.2.10-r1
2.2.10-r3
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.3
1
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
expat@2.4.1-r0
2.4.4-r0
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
expat@2.2.10-r1
2.2.10-r3
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.3
1
quay.io/kiwigrid/k8s-sidecar:1.10.718feb3906286
expat@2.2.10-r1
2.2.10-r3
1
quay.io/kiwigrid/k8s-sidecar:1.15.1a25886092fa4
expat@2.4.3-r0
2.4.4-r0
1
quay.io/netwarps/blockscoutbecd3e39360a
expat@2.4.1-r0
2.4.4-r0
1
quay.io/opsmxpublic/oes-pre-configure:v29b052fbb046f
expat@2.2.9-r1
2.2.10-r1
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
expat@2.1.0-7ubuntu0.16.04.4
2.1.0-7ubuntu0.16.04.5+esm2
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.3
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
expat@2.4.1-r0
2.4.4-r0
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
expat@2.4.1-r0
2.4.4-r0
1
quay.io/renokico/laravel-helm-demo:octane-0.6.0cad83090c58f
expat@2.2.9-r1
2.2.10-r1
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.3
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
expat@2.2.10-r1
2.2.10-r3
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.3
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
expat@2.2.9-1build1
2.2.9-1ubuntu0.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.