StackRadar

CVE-2022-2400

Medium

Advisory

Published 19 Jul 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

Dompdf before v2.0.0 vulnerable to chroot check bypass

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
dompdf/dompdfcomposerv0.8.6, v1.0.2, v1.1.1, v1.2.12.0.010
OSV records
GHSA-5qj8-6xxj-hp9h

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
monicageek-cookbookVerified publisher8.2.01 of 1See more

monica geek-cookbook 8.2.0

1 of the 1 container images this version deploys carry CVE-2022-2400.

Container imageDigestPackageFixed in
library/monica:3.7.0-apacheceb1ba4196ab
dompdf/dompdf@v1.1.1
2.0.0

Open the chart page →

2,096
waardepapierenwaardepapieren1.0.01 of 3See more

waardepapieren waardepapieren 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-2400.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
dompdf/dompdf@v0.8.6
2.0.0

Open the chart page →

8,079
waardepapieren-baliewaardepapieren-balie1.0.01 of 3See more

waardepapieren-balie waardepapieren-balie 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-2400.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
dompdf/dompdf@v0.8.6
2.0.0

Open the chart page →

7,871
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-2400.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
dompdf/dompdf@v0.8.6
2.0.0

Open the chart page →

12,907
bookstackgeek-cookbookVerified publisher5.2.01 of 1See more

bookstack geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2022-2400.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
dompdf/dompdf@v1.1.1
2.0.0

Open the chart page →

1,269
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2022-2400.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
dompdf/dompdf@v1.1.1
2.0.0

Open the chart page →

8,392
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2022-2400.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
dompdf/dompdf@v0.8.6
2.0.0

Open the chart page →

8,725
shopwarerobjuz2.0.01 of 6See more

shopware robjuz 2.0.0

1 of the 6 container images this version deploys carry CVE-2022-2400.

Container imageDigestPackageFixed in
shyim/shopware:6.4.6.0a951c0e6b836
dompdf/dompdf@v1.0.2
2.0.0

Open the chart page →

2,972
bookstackschmitzis0.1.11 of 1See more

bookstack schmitzis 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-2400.

Container imageDigestPackageFixed in
solidnerd/bookstack:21.12762ffd5c51d3
dompdf/dompdf@v1.1.1
2.0.0

Open the chart page →

2,751
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-2400.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
dompdf/dompdf@v1.2.1
2.0.0

Open the chart page →

7,552

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
conduction/conduction-ui-php:dev2744565516e8
dompdf/dompdf@v0.8.6
2.0.0
1
conduction/pan-php:dev24f03c57568f
dompdf/dompdf@v0.8.6
2.0.0
1
library/monica:3.7.0-apacheceb1ba4196ab
dompdf/dompdf@v1.1.1
2.0.0
1
openemr/openemr:6.1.089eaa6d9a4e3
dompdf/dompdf@v1.1.1
2.0.0
1
shyim/shopware:6.4.6.0a951c0e6b836
dompdf/dompdf@v1.0.2
2.0.0
1
solidnerd/bookstack:21.12762ffd5c51d3
dompdf/dompdf@v1.1.1
2.0.0
1
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
dompdf/dompdf@v0.8.6
2.0.0
1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
dompdf/dompdf@v0.8.6
2.0.0
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
dompdf/dompdf@v1.2.1
2.0.0
1
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
dompdf/dompdf@v1.1.1
2.0.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.