StackRadar

CVE-2022-24999

High

Advisory

Published 26 Nov 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.151
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
289
of 17,781 indexed, latest versions
Container images
283
deployed by those charts
Fix available
2 of 2
affected packages

qs vulnerable to Prototype Pollution

Carried by container images the latest versions of 289 of 17,781 indexed charts deploy, on 283 images.

Affected packageAffected versionsFixed inImages
qsnpm0.5.6, 0.6.5, 1.2.2, 2.2.4+16 more6.2.4, 6.3.3, 6.4.1, 6.5.3+4 more283
node-qsdeb6.9.1+ds-16.9.1+ds-1ubuntu0.1~esm12
OSV records
GHSA-hrpp-h998-j3ppUBUNTU-CVE-2022-24999
Also known as
USN-7693-1

Charts affected

289 by stars
ChartLatestAffected imagesRadar Score
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
qs@6.5.1
6.5.3

Open the chart page →

7,210
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
qs@6.5.2
6.5.3

Open the chart page →

9,203
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
qs@2.3.3
6.2.4

Open the chart page →

2,938
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
qs@6.7.0
6.7.3

Open the chart page →

4,577
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
microcks/microcks-postman-runtime:latestcb72e46a1b3c
qs@6.4.0
6.4.1

Open the chart page →

10,732
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
qs@6.5.2
6.5.3

Open the chart page →

30,326
lighthouse-cicowboysysopVerified publisher9.0.01 of 1See more

lighthouse-ci cowboysysop 9.0.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
patrickhulce/lhci-server:0.8.174b4b6a3954d
qs@6.5.2
6.5.3

Open the chart page →

2,213
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
qs@6.7.0
6.7.3

Open the chart page →

5,251
carbonetes-analyzercarbonetes-analyzerVerified publisher1.0.61 of 1See more

carbonetes-analyzer carbonetes-analyzer 1.0.6

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
qs@6.5.2
6.5.3

Open the chart page →

1,829
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
qs@6.5.2
6.5.3

Open the chart page →

52,919
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
qs@6.9.4
6.9.7

Open the chart page →

8,213
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
qs@6.10.1
6.10.3

Open the chart page →

5,946
graphql-gatewaygraphql-gatewayVerified publisher0.1.51 of 1See more

graphql-gateway graphql-gateway 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
hansehe/graphql-gateway:1.0.458e09540afbc
qs@6.7.0
6.7.3

Open the chart page →

1,660
kubeflowkubeflow1.6.21 of 45See more

kubeflow kubeflow 1.6.2

1 of the 45 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
qs@6.7.0
6.7.3

Open the chart page →

96,941
taigarc-helm-charts0.1.01 of 7See more

taiga rc-helm-charts 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
taigaio/taiga-events:6.4.00bf2d24a57d9
qs@6.5.2
6.5.3

Open the chart page →

7,255
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
qs@6.7.0
6.7.3

Open the chart page →

8,212
hubotdecayofmind1.0.21 of 3See more

hubot decayofmind 1.0.2

1 of the 3 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
decayofmind/hubot:3.3.21e18e92fe694
qs@6.5.2
6.5.3

Open the chart page →

2,513
nightscoutgabe565Verified publisher0.13.01 of 2See more

nightscout gabe565 0.13.0

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
qs@6.5.2
6.5.3

Open the chart page →

2,521
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
qs@6.5.2
6.5.3

Open the chart page →

22,773
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
qs@6.7.0
6.7.3

Open the chart page →

7,579
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
qs@6.5.2
6.5.3

Open the chart page →

3,476
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
qs@6.7.0
6.7.3

Open the chart page →

10,311
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
qs@6.4.0
6.4.1

Open the chart page →

5,209
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
qs@6.5.2
6.5.3

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
qs@6.5.2
6.5.3

Open the chart page →

18,517
laravelrenoki-co1.0.01 of 2See more

laravel renoki-co 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
qs@6.5.2
6.5.3

Open the chart page →

6,931
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
qs@2.3.3
6.2.4

Open the chart page →

977
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
qs@6.5.2
6.5.3

Open the chart page →

24,488
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
qs@6.5.2
6.5.3

Open the chart page →

2,851
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
qs@6.5.2
6.5.3

Open the chart page →

13,635
bredbandskollen-prometheus-exporteraolde0.2.31 of 1See more

bredbandskollen-prometheus-exporter aolde 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
qs@6.5.2
6.5.3

Open the chart page →

1,972
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
qs@6.9.4
6.9.7

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
qs@6.5.2
6.5.3

Open the chart page →

10,730
dltbrokerassist-iot-distributed-broker0.2.02 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

2 of the 9 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
qs@6.5.1
6.5.3
hyperledger/fabric-couchdb:0.4.15f6c724592abf
qs@6.5.1
6.5.3

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.02 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

2 of the 9 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
qs@6.5.1
6.5.3
hyperledger/fabric-couchdb:0.4.15f6c724592abf
qs@6.5.1
6.5.3

Open the chart page →

77,687
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
qs@6.5.2
6.5.3

Open the chart page →

3,509
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
qs@6.9.4
6.9.7

Open the chart page →

9,971
data-fairdata354-helmVerified publisher1.1.22 of 12See more

data-fair data354-helm 1.1.2

2 of the 12 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
koumoul/capture:17108d47be3b2
qs@6.5.2
6.5.3
koumoul/openapi-viewer:18eeca2e8285b
qs@6.5.1
6.5.3

Open the chart page →

38,346
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
qs@6.5.2
6.5.3

Open the chart page →

3,925
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
qs@6.7.0
6.7.3

Open the chart page →

2,519
foundryvttgeek-cookbookVerified publisher3.4.21 of 1See more

foundryvtt geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
felddy/foundryvtt:0.8.36c5d90b90349
qs@6.5.2
6.5.3

Open the chart page →

2,042
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
qs@6.9.6
6.9.7

Open the chart page →

4,260
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
qs@6.5.2
6.5.3

Open the chart page →

4,405
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
qs@6.7.0
6.7.3

Open the chart page →

3,444
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
qs@6.5.2
6.5.3

Open the chart page →

7,801
tdarrgeek-cookbookVerified publisher4.6.21 of 2See more

tdarr geek-cookbook 4.6.2

1 of the 2 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.00.101e3f9328327d
qs@6.5.2
6.5.3

Open the chart page →

31,000
uptimerobotgeek-cookbookVerified publisher3.0.41 of 1See more

uptimerobot geek-cookbook 3.0.4

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
qs@6.5.2
6.5.3

Open the chart page →

1,669
youtubedl-materialgeek-cookbookVerified publisher4.4.21 of 1See more

youtubedl-material geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.23720b856bd2f
qs@6.5.2
6.5.3

Open the chart page →

4,410
zigbee2mqttgeek-cookbookVerified publisher9.4.21 of 1See more

zigbee2mqtt geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
qs@6.5.2
6.5.3

Open the chart page →

2,173
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2022-24999.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
qs@6.5.2
6.5.3

Open the chart page →

6,810

Container images carrying it

283 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
halkeye/irslackd:latest7638bfba70b0
qs@6.5.2
6.5.3
1
hansehe/graphql-gateway:1.0.458e09540afbc
qs@6.7.0
6.7.3
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
qs@6.5.2
6.5.3
1
henrywhitaker3/speedtest-tracker:latest47159a940229
qs@6.7.0
6.7.3
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
qs@6.7.0
6.7.3
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
qs@6.7.0
6.7.3
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
qs@6.5.1
6.5.3
1
i4trust/pdc-portal:2.0.03e77858e1219
qs@6.5.2
6.5.3
1
ianw/quickchart:v1.7.1dc49dd460c37
qs@6.5.2
6.5.3
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
qs@6.5.2
6.5.3
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
qs@6.5.2
6.5.3
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
qs@6.5.1
6.5.3
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
qs@6.5.1
6.5.3
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
qs@6.5.1
6.5.3
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
qs@6.5.2
6.5.3
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
qs@6.5.2
6.5.3
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
qs@6.5.1
6.5.3
1
ibmcom/microclimate-portal:latested5505e5c7ec
qs@6.5.1
6.5.3
1
ibmcom/microclimate-theia:lateste17bdccc5030
qs@6.5.1
6.5.3
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
qs@6.5.2
6.5.3
1
improwised/erpnext-worker:v13.4.197280b55cbd4
qs@6.5.2
6.5.3
1
inseefrlab/shelly:cloudshell31f04ca7436b
qs@6.7.0
6.7.3
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
qs@6.5.2
6.5.3
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
qs@6.9.6
6.9.7
1
istio/examples-bookinfo-ratings-v1:1.17.0b6a6b88d3578
qs@6.5.2
6.5.3
1
jakowenko/double-take:1.6.0b858bac9e32a
qs@6.7.0
6.7.3
1
jayfong/yapi:1.10.2163e5d621910
qs@6.4.0
6.4.1
1
jesec/flood:4.7.03d1d0bec117a
qs@6.5.2
6.5.3
1
jesec/flood:4.6.060bd59cfb4eb
qs@6.5.2
6.5.3
1
jesec/rtorrent-flood:latestf0c894ec459e
qs@6.5.2
6.5.3
1
joplin/server:latest3f7b852959aa
qs@6.5.2
6.5.3
1
joplin/server:3.0-beta52af57880c0e
qs@6.5.2
6.5.3
1
joplin/server:2.14.2-betab87564ef34e9
qs@6.5.2
6.5.3
1
junktext/getting-started:1.0.5a70936c04aed
qs@6.7.0
6.7.3
1
junktext/getting-started:1.0.34d44adf5a4da2
qs@6.5.2
6.5.3
1
jupyterhub/configurable-http-proxy:3.0.0c36cf3cc1c99
qs@6.2.1
6.2.4
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
qs@6.5.2
6.5.3
1
konradkleine/docker-registry-frontend:v2181aad54ee64
qs@2.3.3
6.2.4
1
koumoul/capture:17108d47be3b2
qs@6.5.2
6.5.3
1
koumoul/openapi-viewer:18eeca2e8285b
qs@6.5.1
6.5.3
1
kubebb/tamp-portal:v5.6.0fadac6d52470
qs@6.5.2
6.5.3
1
kubebb/tdsf-portal:v5.7.0258458311bc9
qs@6.5.2
6.5.3
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
qs@6.7.0
6.7.3
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
qs@6.5.2
6.5.3
1
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
qs@6.5.2
6.5.3
1
kubevious/parser:1.0.151acf1a1f0b47
qs@6.5.2
6.5.3
1
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
qs@6.5.2
6.5.3
1
langgenius/dify-api:1.0.0066035f93856
qs@6.5.2
6.5.3
1
langgenius/dify-api:0.6.11fca918260dd6
qs@6.5.2
6.5.3
1
lavandadelpatio/frontend:latest501c3f31e0bc
qs@6.5.2
6.5.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.