StackRadar

CVE-2022-24921

Unscored

Advisory

Published 23 May 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.032
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
840
of 17,787 indexed, latest versions
Container images
868
deployed by those charts
Fix available
1 of 1
affected package

Stack exhaustion when compiling deeply nested expressions in regexp

Carried by container images the latest versions of 840 of 17,787 indexed charts deploy, on 868 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+63 more1.16.15868
OSV records
GO-2021-0347
Also known as
BIT-golang-2022-24921

Charts affected

840 by stars
ChartLatestAffected imagesRadar Score
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
stdlib@go1.16.2
1.16.15

Open the chart page →

3,509
passbolt-hachristianhuthVerified publisher6.0.11 of 4See more

passbolt-ha christianhuth 6.0.1

1 of the 4 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.16.15

Open the chart page →

10,873
cloudflow-enterprise-componentscloudflow-helm-charts0.0.0-NIGHTLY011220202 of 9See more

cloudflow-enterprise-components cloudflow-helm-charts 0.0.0-NIGHTLY01122020

2 of the 9 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.16.15
prom/prometheus:v2.21.0d43417c260e5
stdlib@go1.15.2
1.16.15

Open the chart page →

4,256
cnpg-sandboxcloudnative-pgVerified publisher0.6.12 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

2 of the 6 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
grafana/grafana:8.3.5cd7cb4345aa7
stdlib@go1.17.6
1.16.15
quay.io/prometheus-operator/prometheus-operator:v0.54.0be2aef39a2f8
stdlib@go1.17.6
1.16.15

Open the chart page →

7,583
pgbenchcloudnative-pgVerified publisher0.1.01 of 1See more

pgbench cloudnative-pg 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/postgresql:14.5b3b30d04b362
stdlib@go1.16.7
1.16.15

Open the chart page →

2,713
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.16.15

Open the chart page →

1,579
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
stdlib@go1.13.10
1.16.15

Open the chart page →

7,303
sops-operatorcraftypathVerified publisher0.8.01 of 1See more

sops-operator craftypath 0.8.0

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
craftypath/sops-operator:v0.8.0402a0024c732
stdlib@go1.16.5
1.16.15

Open the chart page →

6,473
duplicaticronce0.1.01 of 1See more

duplicati cronce 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
stdlib@go1.14.4
1.16.15

Open the chart page →

3,026
cubefscubefs3.2.05 of 10See more

cubefs cubefs 3.2.0

5 of the 10 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.16.15
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
stdlib@go1.17.3
1.16.15
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
stdlib@go1.17.3
1.16.15
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
stdlib@go1.16.2
1.16.15
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.16.15

Open the chart page →

15,891
extendeddaemonsetdatadogVerified publisher0.3.31 of 1See more

extendeddaemonset datadog 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
datadog/extendeddaemonset:v0.8.0513a4377aed5
stdlib@go1.15.15
1.16.15

Open the chart page →

4,759
datadogdatadog-test2.4.231 of 2See more

datadog datadog-test 2.4.23

1 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
datadog/agent:7.22.08f20e56b5311
stdlib@go1.13.11
1.16.15

Open the chart page →

4,570
gripmockdeliveryheroVerified publisher1.1.31 of 1See more

gripmock deliveryhero 1.1.3

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
tkpd/gripmock:1.10.174441dadcfbd
stdlib@go1.14.6
1.16.15

Open the chart page →

2,793
labelsmanager-controllerdeliveryheroVerified publisher1.0.41 of 1See more

labelsmanager-controller deliveryhero 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
stdlib@go1.13.15
1.16.15

Open the chart page →

2,305
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
stdlib@go1.13.5
1.16.15

Open the chart page →

7,987
kube-bench-metricsdevopstalesVerified publisher0.1.01 of 1See more

kube-bench-metrics devopstales 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
elastisys/kube-bench-metrics:0.1.6509b94f1da55
stdlib@go1.15.7
1.16.15

Open the chart page →

2,111
kubedashdevopstalesOfficialVerified publisher4.0.01 of 8See more

kubedash devopstales 4.0.0

1 of the 8 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.22.48be660470961
stdlib@go1.17.3
1.16.15

Open the chart page →

9,239
permission-managerdevopstalesVerified publisher1.8.01 of 1See more

permission-manager devopstales 1.8.0

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
stdlib@go1.16.8
1.16.15

Open the chart page →

2,266
dnsmasqdevplayer0Verified publisher0.1.51 of 2See more

dnsmasq devplayer0 0.1.5

1 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
stdlib@go1.16.5
1.16.15

Open the chart page →

3,392
whoamidevplayer0Verified publisher0.1.21 of 1See more

whoami devplayer0 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
traefik/whoami:v1.6.12c52bb2c8480
stdlib@go1.15.6
1.16.15

Open the chart page →

1,216
calicodevtron0.1.14 of 4See more

calico devtron 0.1.1

4 of the 4 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
stdlib@go1.15.2
1.16.15
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
stdlib@go1.15.2
1.16.15
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
stdlib@go1.15.2
1.16.15
quay.io/devtron/calico-networking:pod2daemon-flexvol-v3.19.1c1f36b6e18e0
stdlib@go1.15.2
1.16.15

Open the chart page →

10,073
clairdevtron0.1.141 of 2See more

clair devtron 0.1.14

1 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
stdlib@go1.17.6
1.16.15

Open the chart page →

6,237
digispoof-interfacedigispoof-interface1.0.01 of 3See more

digispoof-interface digispoof-interface 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
stdlib@go1.13.10
1.16.15

Open the chart page →

7,779
dnation-pingdnationcloud0.1.94 of 5See more

dnation-ping dnationcloud 0.1.9

4 of the 5 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
stdlib@go1.15.5
1.16.15
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.16.15
prom/blackbox-exporter:v0.18.01ffc3f109eb3
stdlib@go1.15.2
1.16.15
prom/prometheus:v2.21.0d43417c260e5
stdlib@go1.15.2
1.16.15

Open the chart page →

10,454
thermitedollarshaveclubOfficialVerified publisher0.1.171 of 1See more

thermite dollarshaveclub 0.1.17

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
dollarshaveclub/thermite:0.0.31663cbf25fcfe
stdlib@go1.17.1
1.16.15

Open the chart page →

2,732
archerydoubanVerified publisher0.4.31 of 6See more

archery douban 0.4.3

1 of the 6 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
hhyo/archery:v1.9.11aa41843419e
stdlib@go1.15.6
1.16.15

Open the chart page →

5,854
karmadoubanVerified publisher1.9.21 of 1See more

karma douban 1.9.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/prymitive/karma:v0.85d06892218680
stdlib@go1.16.3
1.16.15

Open the chart page →

2,017
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.16.15

Open the chart page →

31,572
nexus-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

nexus-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
stdlib@go1.17.2
1.16.15

Open the chart page →

2,266
httpbingoestahnVerified publisher0.1.11 of 1See more

httpbingo estahn 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
mccutchen/go-httpbin:v2.2.25994403ef75b
stdlib@go1.16.2
1.16.15

Open the chart page →

1,359
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
stdlib@go1.16.3
1.16.15

Open the chart page →

11,483
vidcheckfactlyVerified publisher0.5.21 of 2See more

vidcheck factly 0.5.2

1 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
factly/vidcheck-server:0.12.087064eb0463c
stdlib@go1.14.2
1.16.15

Open the chart page →

3,617
fission-corefission-chartsVerified publisher1.14.13 of 3See more

fission-core fission-charts 1.14.1

3 of the 3 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
fission/fission-bundle:1.14.13fcfd8a0fa5d
stdlib@go1.15.14
1.16.15
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
stdlib@go1.15.14
1.16.15
fission/reporter:1.14.104c6e06af175
stdlib@go1.15.14
1.16.15

Open the chart page →

7,104
openldapfluktuid0.1.11 of 2See more

openldap fluktuid 0.1.1

1 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.16.15

Open the chart page →

3,313
dexgabibbo974.0.41 of 1See more

dex gabibbo97 4.0.4

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
stdlib@go1.16.2
1.16.15

Open the chart page →

3,391
alertmanager-botgeek-cookbookVerified publisher6.4.21 of 1See more

alertmanager-bot geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
stdlib@go1.13.15
1.16.15

Open the chart page →

3,586
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
stdlib@go1.16.8
1.16.15

Open the chart page →

17,438
filebrowsergeek-cookbookVerified publisher1.4.21 of 1See more

filebrowser geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.18.04fcd47af573c
stdlib@go1.16.9
1.16.15

Open the chart page →

3,474
focalboardgeek-cookbookVerified publisher4.4.21 of 1See more

focalboard geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
mattermost/focalboard:0.9.031078df7a3c8
stdlib@go1.16.5
1.16.15

Open the chart page →

3,631
otel-collectorgeek-cookbookVerified publisher1.2.21 of 1See more

otel-collector geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
stdlib@go1.17.7
1.16.15

Open the chart page →

2,556
owncastgeek-cookbookVerified publisher3.4.21 of 1See more

owncast geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
gabekangas/owncast:0.0.797461aedb580
stdlib@go1.15.2
1.16.15

Open the chart page →

3,167
protonmail-bridgegeek-cookbookVerified publisher5.4.21 of 1See more

protonmail-bridge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
stdlib@go1.15.12
1.16.15

Open the chart page →

8,035
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
stdlib@go1.16.8
1.16.15

Open the chart page →

11,606
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.16.15

Open the chart page →

10,279
sambageek-cookbookVerified publisher6.2.21 of 1See more

samba geek-cookbook 6.2.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
stdlib@go1.17.2
1.16.15

Open the chart page →

2,318
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
stdlib@go1.13.15
1.16.15

Open the chart page →

15,917
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
stdlib@go1.17.5
1.16.15

Open the chart page →

5,079
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.16.15

Open the chart page →

7,698
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
stdlib@go1.15.12
1.16.15

Open the chart page →

6,977
cratedb-adapter-v2hmdmph0.2.11 of 1See more

cratedb-adapter-v2 hmdmph 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
stdlib@go1.16.3
1.16.15

Open the chart page →

2,913

Container images carrying it

868 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/tigera/operator:v1.20.1379efe0c2541
stdlib@go1.15.2
1.16.15
1
quay.io/tigera/operator:v1.15.1c6591da87aa8
stdlib@go1.15.2
1.16.15
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
stdlib@go1.13.15
1.16.15
1
quay.io/uswitch/kiam:v4.0be3a5846922d
stdlib@go1.13.8
1.16.15
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
stdlib@go1.16.4
1.16.15
1
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.16.15
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.16.15
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
stdlib@go1.14.2
1.16.15
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.16.15
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
stdlib@go1.16.14
1.16.15
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
stdlib@go1.15.15
1.16.15
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.16.15
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.16.15
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.16.15
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.16.15
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.16.15
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.16.15
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.16.15
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.