StackRadar

CVE-2022-24921

Unscored

Advisory

Published 23 May 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.032
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
840
of 17,790 indexed, latest versions
Container images
868
deployed by those charts
Fix available
1 of 1
affected package

Stack exhaustion when compiling deeply nested expressions in regexp

Carried by container images the latest versions of 840 of 17,790 indexed charts deploy, on 868 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+63 more1.16.15868
OSV records
GO-2021-0347
Also known as
BIT-golang-2022-24921

Charts affected

840 by stars
ChartLatestAffected imagesRadar Score
kovecmacraeVerified publisher0.2.01 of 1See more

kove cmacrae 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
stdlib@go1.17
1.16.15

Open the chart page →

2,089
kove-deprecationscmacraeVerified publisher0.1.21 of 1See more

kove-deprecations cmacrae 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
stdlib@go1.16
1.16.15

Open the chart page →

2,203
lgtmcmacraeVerified publisher0.1.01 of 1See more

lgtm cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
cmacrae/lgtm:0.1.0dec8d490fe40
stdlib@go1.14.1
1.16.15

Open the chart page →

1,909
door-agentcnoVerified publisher3.0.151 of 15See more

door-agent cno 3.0.15

1 of the 15 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
stdlib@go1.14.13
1.16.15

Open the chart page →

19,454
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
stdlib@go1.13.12
1.16.15

Open the chart page →

2,234
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
stdlib@go1.13.10
1.16.15

Open the chart page →

7,581
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
stdlib@go1.13.10
1.16.15

Open the chart page →

12,915
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
stdlib@go1.13.10
1.16.15

Open the chart page →

7,218
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
stdlib@go1.13.10
1.16.15

Open the chart page →

8,417
katibcowboysysopVerified publisher2.4.23 of 4See more

katib cowboysysop 2.4.2

3 of the 4 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
stdlib@go1.17.1
1.16.15
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
stdlib@go1.13.3
1.16.15
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
stdlib@go1.17.1
1.16.15

Open the chart page →

6,563
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
kfserving/kfserving-controller:v0.6.163d79d04c2e3
stdlib@go1.14.14
1.16.15

Open the chart page →

3,837
metacontrollercowboysysopVerified publisher1.2.21 of 1See more

metacontroller cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
metacontrollerio/metacontroller:v2.1.10336993b88e4
stdlib@go1.17.6
1.16.15

Open the chart page →

2,092
mpi-operatorcowboysysopVerified publisher1.2.21 of 1See more

mpi-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
stdlib@go1.15.13
1.16.15

Open the chart page →

2,577
notebook-controllercowboysysopVerified publisher1.1.21 of 1See more

notebook-controller cowboysysop 1.1.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
stdlib@go1.15.15
1.16.15

Open the chart page →

2,582
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
stdlib@go1.13.1
1.16.15

Open the chart page →

5,489
training-operatorcowboysysopVerified publisher1.2.21 of 1See more

training-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
stdlib@go1.14.9
1.16.15

Open the chart page →

2,275
crossplane-controllerscrossplane0.12.01 of 1See more

crossplane-controllers crossplane 0.12.0

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
crossplane/crossplane:v0.12.066666e6963af
stdlib@go1.14.4
1.16.15

Open the chart page →

2,312
oam-kubernetes-runtimecrossplane0.0.3-71.g0f235901 of 2See more

oam-kubernetes-runtime crossplane 0.0.3-71.g0f23590

1 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
stdlib@go1.13.14
1.16.15

Open the chart page →

2,248
oam-kubernetes-runtime-legacycrossplane0.3.1-5.g11e18941 of 1See more

oam-kubernetes-runtime-legacy crossplane 0.3.1-5.g11e1894

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
stdlib@go1.13.15
1.16.15

Open the chart page →

2,231
external-service-operatorcrowdfox0.1.01 of 1See more

external-service-operator crowdfox 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
crowdfox/external-service-operator:v1.1.06fa7e8063d27
stdlib@go1.14.2
1.16.15

Open the chart page →

4,631
electric-mailcryptexlabsVerified publisher0.0.12 of 5See more

electric-mail cryptexlabs 0.0.1

2 of the 5 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
stdlib@go1.16.7
1.16.15
hashicorp/vault-k8s:0.13.1bebb03e8e800
stdlib@go1.16.3
1.16.15

Open the chart page →

5,980
purple-piecryptexlabsVerified publisher0.0.12 of 4See more

purple-pie cryptexlabs 0.0.1

2 of the 4 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
stdlib@go1.16.7
1.16.15
hashicorp/vault-k8s:0.13.1bebb03e8e800
stdlib@go1.16.3
1.16.15

Open the chart page →

5,980
openldapcsic-charts0.1.11 of 2See more

openldap csic-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.16.15

Open the chart page →

5,294
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
stdlib@go1.14.12
1.16.15

Open the chart page →

13,944
irods-csi-drivercyverse0.12.01 of 4See more

irods-csi-driver cyverse 0.12.0

1 of the 4 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
stdlib@go1.17.3
1.16.15

Open the chart page →

5,288
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
stdlib@go1.17.1
1.16.15

Open the chart page →

6,179
speedtest-exporterdamounVerified publisher1.0.61 of 1See more

speedtest-exporter damoun 1.0.6

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
stdlib@go1.16.6
1.16.15

Open the chart page →

1,209
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
stdlib@go1.16
1.16.15

Open the chart page →

3,246
cloudwatch-agent-prometheusdasmeta0.2.21 of 1See more

cloudwatch-agent-prometheus dasmeta 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
amazon/cloudwatch-agent:1.247350.0b251780e745d1783c93
stdlib@go1.15.15
1.16.15

Open the chart page →

2,985
mongodb-bi-connectordasmeta1.0.31 of 1See more

mongodb-bi-connector dasmeta 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
stdlib@go1.16.9
1.16.15

Open the chart page →

5,841
nfs-provisionerdasmeta1.0.31 of 1See more

nfs-provisioner dasmeta 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
stdlib@go1.13.4
1.16.15

Open the chart page →

2,806
datadog-csi-driverdatadogVerified publisher0.17.01 of 2See more

datadog-csi-driver datadog 0.17.0

1 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.16.15

Open the chart page →

2,055
datadog-operatordatadog-test0.1.21 of 1See more

datadog-operator datadog-test 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
datadog/operator:0.3.117f08a860090
stdlib@go1.15.2
1.16.15

Open the chart page →

3,978
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
stdlib@go1.16.5
1.16.15

Open the chart page →

7,494
eg-edge-stack-crdsdatawire0.0.11 of 2See more

eg-edge-stack-crds datawire 0.0.1

1 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
stdlib@go1.16.9
1.16.15

Open the chart page →

2,404
kube-better-nodedecayofmind0.0.41 of 1See more

kube-better-node decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
stdlib@go1.16.6
1.16.15

Open the chart page →

1,584
aws-s3-proxydeliveryheroVerified publisher0.1.71 of 1See more

aws-s3-proxy deliveryhero 0.1.7

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
pottava/s3-proxy:2.020a0bcb15f76
stdlib@go1.13.7
1.16.15

Open the chart page →

1,323
aws-service-events-exporterdeliveryheroVerified publisher1.0.71 of 1See more

aws-service-events-exporter deliveryhero 1.0.7

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
thomasnyambati/aws-service-events-exporter:1.0.01e18a0944ceb
stdlib@go1.15.6
1.16.15

Open the chart page →

1,299
k8s-cloudwatch-adapterdeliveryheroVerified publisher0.2.21 of 1See more

k8s-cloudwatch-adapter deliveryhero 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
stdlib@go1.14.5
1.16.15

Open the chart page →

2,475
killgravedeliveryheroVerified publisher1.0.21 of 1See more

killgrave deliveryhero 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
friendsofgo/killgrave:0.4.139cfbecca342
stdlib@go1.16.3
1.16.15

Open the chart page →

1,181
prometheus-aws-limits-exporterdeliveryheroVerified publisher0.2.21 of 1See more

prometheus-aws-limits-exporter deliveryhero 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
danielfm/aws-limits-exporter:0.6.07152b84e57cb
stdlib@go1.17.2
1.16.15

Open the chart page →

1,846
prometheus-soti-mobicontrol-exporterdeliveryheroVerified publisher1.0.31 of 1See more

prometheus-soti-mobicontrol-exporter deliveryhero 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
stdlib@go1.14
1.16.15

Open the chart page →

1,644
prometheus-statsd-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-statsd-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.18.0d23aca343b86
stdlib@go1.14.7
1.16.15

Open the chart page →

1,315
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
stdlib@go1.16.7
1.16.15

Open the chart page →

30,156
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
library/mariadb:10.9.4fbb8456ebdb1
stdlib@go1.16.7
1.16.15

Open the chart page →

29,157
wordpressdevops0.12.01 of 4See more

wordpress devops 0.12.0

1 of the 4 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
library/mariadb:10.8.30abf60f81588
stdlib@go1.16.7
1.16.15

Open the chart page →

13,039
pushproxdevopstalesVerified publisher0.1.62 of 2See more

pushprox devopstales 0.1.6

2 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
stdlib@go1.16.4
1.16.15
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
stdlib@go1.16.4
1.16.15

Open the chart page →

3,754
lxd8sdevplayer0Verified publisher0.5.12 of 2See more

lxd8s devplayer0 0.5.1

2 of the 2 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
stdlib@go1.16.5
1.16.15
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
stdlib@go1.17
1.16.15

Open the chart page →

5,431
octolxddevplayer0Verified publisher0.1.11 of 1See more

octolxd devplayer0 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
stdlib@go1.16.6
1.16.15

Open the chart page →

2,525
argocddevtron1.8.12 of 3See more

argocd devtron 1.8.1

2 of the 3 container images this version deploys carry CVE-2022-24921.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
stdlib@go1.14.12
1.16.15
quay.io/dexidp/dex:v2.25.07bcf286807b8
stdlib@go1.14.9
1.16.15

Open the chart page →

10,484

Container images carrying it

868 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/tigera/operator:v1.20.1379efe0c2541
stdlib@go1.15.2
1.16.15
1
quay.io/tigera/operator:v1.15.1c6591da87aa8
stdlib@go1.15.2
1.16.15
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
stdlib@go1.13.15
1.16.15
1
quay.io/uswitch/kiam:v4.0be3a5846922d
stdlib@go1.13.8
1.16.15
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
stdlib@go1.16.4
1.16.15
1
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.16.15
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.16.15
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
stdlib@go1.14.2
1.16.15
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.16.15
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
stdlib@go1.16.14
1.16.15
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
stdlib@go1.15.15
1.16.15
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.16.15
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.16.15
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.16.15
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.16.15
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.16.15
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.16.15
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.16.15
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.