StackRadar

CVE-2022-2421

Critical

Advisory

Published 26 Oct 2022In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
39
of 17,781 indexed, latest versions
Container images
36
deployed by those charts
Fix available
1 of 1
affected package

Insufficient validation when decoding a Socket.IO packet

Carried by container images the latest versions of 39 of 17,781 indexed charts deploy, on 36 images.

Affected packageAffected versionsFixed inImages
socket.io-parsernpm2.2.0, 2.2.2, 2.2.6, 2.3.1+9 more3.3.3, 3.4.2, 4.0.5, 4.2.136
OSV records
GHSA-qm95-pgcg-qqfq

Charts affected

39 by stars
ChartLatestAffected imagesRadar Score
uptime-kumaduyet0.1.71 of 1See more

uptime-kuma duyet 0.1.7

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.18.5a84767d7934f
socket.io-parser@4.1.2
4.2.1

Open the chart page →

4,515
audiobookshelfgeek-cookbookVerified publisher1.2.21 of 1See more

audiobookshelf geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
socket.io-parser@4.0.4
4.0.5

Open the chart page →

1,959
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
socket.io-parser@4.0.4
4.0.5

Open the chart page →

22,773
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
socket.io-parser@4.0.4
4.0.5

Open the chart page →

3,476
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
socket.io-parser@3.2.0
3.3.3

Open the chart page →

10,311
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
socket.io-parser@2.2.2
3.3.3

Open the chart page →

5,209
kubeviouskubevious1.2.21 of 7See more

kubevious kubevious 1.2.2

1 of the 7 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
kubevious/guard:1.2.19bf567704de2
socket.io-parser@4.0.4
4.0.5

Open the chart page →

14,204
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
socket.io-parser@3.3.2
3.3.3

Open the chart page →

2,851
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
ghcr.io/data-fair/simple-directory:438a4f32fad82
socket.io-parser@3.3.2
3.3.3

Open the chart page →

38,346
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
socket.io-parser@4.0.4
4.0.5

Open the chart page →

4,405
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
socket.io-parser@4.0.4
4.0.5

Open the chart page →

5,079
restreamerutkuozdemirVerified publisher1.1.01 of 1See more

restreamer utkuozdemir 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
datarhei/restreamer:0.6.4655e12f9eeed
socket.io-parser@3.4.0
3.4.2

Open the chart page →

2,598
scrapoxywiremindVerified publisher0.3.41 of 1See more

scrapoxy wiremind 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
wiremind/scrapoxy:lateste7048929a676
socket.io-parser@3.1.3
3.3.3

Open the chart page →

2,154
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
socket.io-parser@3.2.0
3.3.3

Open the chart page →

3,237
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
socket.io-parser@2.2.2
3.3.3

Open the chart page →

18,277
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
socket.io-parser@2.3.1
3.3.3

Open the chart page →

4,069
maildevcnieg1.1.11 of 1See more

maildev cnieg 1.1.1

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
cnieg/maildev:v1.1.998ee05668915
socket.io-parser@3.3.0
3.3.3

Open the chart page →

2,449
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
socket.io-parser@3.3.2
3.3.3

Open the chart page →

5,488
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
socket.io-parser@2.2.2
3.3.3

Open the chart page →

5,209
backend-servicedev-krishan-dhaka-charts1.0.31 of 1See more

backend-service dev-krishan-dhaka-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
devkrishan001/backend:latestf1c3acadeabe
socket.io-parser@2.2.0
3.3.3

Open the chart page →

1,264
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
socket.io-parser@4.0.4
4.0.5

Open the chart page →

12,222
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
socket.io-parser@3.3.2
3.3.3

Open the chart page →

4,043
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
socket.io-parser@3.4.1
3.4.2

Open the chart page →

4,591
theloungegeek-cookbookVerified publisher3.4.21 of 1See more

thelounge geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
thelounge/thelounge:4.2.0-alpine639978459c3a
socket.io-parser@3.3.0
3.3.3

Open the chart page →

2,689
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
socket.io-parser@3.2.0
3.3.3

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
socket.io-parser@3.2.0
3.3.3

Open the chart page →

2,682
theloungehalkeye4.3.11 of 1See more

thelounge halkeye 4.3.1

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
thelounge/thelounge:4.3.0-alpine0037aa258261
socket.io-parser@4.0.4
4.0.5

Open the chart page →

1,938
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
socket.io-parser@3.2.0
3.3.3
ibmcom/microclimate-portal:latested5505e5c7ec
socket.io-parser@3.2.0
3.3.3

Open the chart page →

57,669
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
frappe/frappe-socketio:v13.4.12095767a9e82
socket.io-parser@3.4.1
3.4.2

Open the chart page →

6,501
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
socket.io-parser@3.3.0
3.3.3

Open the chart page →

10,494
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
socket.io-parser@2.3.1
3.3.3

Open the chart page →

6,454
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
socket.io-parser@3.3.2
3.3.3

Open the chart page →

4,667
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
socket.io-parser@3.3.1
3.3.3

Open the chart page →

27,465
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
socket.io-parser@3.4.1
3.4.2

Open the chart page →

3,118
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
socket.io-parser@2.2.6
3.3.3

Open the chart page →

3,827
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
socket.io-parser@4.0.4
4.0.5

Open the chart page →

4,017
vehicle-dashboardtest-vehi-dash0.1.02 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
socket.io-parser@3.3.2
3.3.3
samajh/alprfrontend:latest05ef4fddbb75
socket.io-parser@3.3.2
3.3.3

Open the chart page →

20,270
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
socket.io-parser@3.4.1
3.4.2

Open the chart page →

3,576
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-2421.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
socket.io-parser@3.4.1
3.4.2

Open the chart page →

3,118

Container images carrying it

36 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
pantsel/konga:latestc8172b75607d
socket.io-parser@2.2.2
3.3.3
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
socket.io-parser@3.2.0
3.3.3
3
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
socket.io-parser@3.4.1
3.4.2
2
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
socket.io-parser@4.0.4
4.0.5
1
catalysm/csmm:latestf003b35f54d9
socket.io-parser@3.4.1
3.4.2
1
cnieg/maildev:v1.1.998ee05668915
socket.io-parser@3.3.0
3.3.3
1
datarhei/restreamer:0.6.4655e12f9eeed
socket.io-parser@3.4.0
3.4.2
1
devkrishan001/backend:latestf1c3acadeabe
socket.io-parser@2.2.0
3.3.3
1
frappe/frappe-socketio:v13.4.12095767a9e82
socket.io-parser@3.4.1
3.4.2
1
ianw/quickchart:v1.7.1dc49dd460c37
socket.io-parser@3.3.2
3.3.3
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
socket.io-parser@3.2.0
3.3.3
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
socket.io-parser@3.2.0
3.3.3
1
ibmcom/microclimate-portal:latested5505e5c7ec
socket.io-parser@3.2.0
3.3.3
1
inseefrlab/shelly:cloudshell31f04ca7436b
socket.io-parser@3.3.0
3.3.3
1
jakowenko/double-take:1.6.0b858bac9e32a
socket.io-parser@4.0.4
4.0.5
1
jayfong/yapi:1.10.2163e5d621910
socket.io-parser@2.3.1
3.3.3
1
konradkleine/docker-registry-frontend:v2181aad54ee64
socket.io-parser@2.3.1
3.3.3
1
kubevious/guard:1.2.19bf567704de2
socket.io-parser@4.0.4
4.0.5
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
socket.io-parser@4.0.4
4.0.5
1
linuxserver/codimd:latestb801bbcf6386
socket.io-parser@3.3.1
3.3.3
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
socket.io-parser@4.0.4
4.0.5
1
louislam/uptime-kuma:1.18.5a84767d7934f
socket.io-parser@4.1.2
4.2.1
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
socket.io-parser@3.3.2
3.3.3
1
polonel/trudesk:1.2.60cf6513f6fe3
socket.io-parser@4.0.4
4.0.5
1
samajh/alprbackend:latestea742b4372ad
socket.io-parser@3.3.2
3.3.3
1
samajh/alprfrontend:latest05ef4fddbb75
socket.io-parser@3.3.2
3.3.3
1
shinobisystems/shinobi:dev3ca746937856
socket.io-parser@3.4.1
3.4.2
1
shinobisystems/shinobi:latestc2f5ce2e1067
socket.io-parser@3.3.2
3.3.3
1
thelounge/thelounge:4.3.0-alpine0037aa258261
socket.io-parser@4.0.4
4.0.5
1
thelounge/thelounge:4.2.0-alpine639978459c3a
socket.io-parser@3.3.0
3.3.3
1
wiremind/scrapoxy:lateste7048929a676
socket.io-parser@3.1.3
3.3.3
1
zooz/predator:1.6f491d1f7a865
socket.io-parser@3.3.2
3.3.3
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
socket.io-parser@4.0.4
4.0.5
1
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
socket.io-parser@4.0.4
4.0.5
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
socket.io-parser@3.3.2
3.3.3
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
socket.io-parser@2.2.6
3.3.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.