StackRadar

CVE-2022-2509

High

Advisory

Published 1 Aug 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.019
78th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
611
of 17,787 indexed, latest versions
Container images
579
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: gnutls security update

Carried by container images the latest versions of 611 of 17,787 indexed charts deploy, on 579 images.

Affected packageAffected versionsFixed inImages
gnutls28deb3.5.17-1ubuntu1, 3.5.18-1ubuntu1, 3.5.18-1ubuntu1.1, 3.5.18-1ubuntu1.2+9 more3.5.18-1ubuntu1.6, 3.6.13-2ubuntu1.7, 3.7.1-5+deb11u2, 3.7.3-4ubuntu1.1469
gnutlsrpm3.6.5-2.el8, 3.6.7-14.4.1, 3.6.7-lp151.2.3.1, 3.6.8-8.el8+7 more0:3.6.16-5.el8_6, 3.6.7-150200.14.19.2, 3.7.7-1.186
gnutlsapk3.7.1-r0, 3.7.6-r03.7.1-r1, 3.7.7-r024
OSV records
ALPINE-CVE-2022-2509RHSA-2022:7105UBUNTU-CVE-2022-2509DSA-5203-1openSUSE-SU-2024:12233-1SUSE-SU-2022:2882-1
Also known as
USN-5550-1

Charts affected

611 by stars
ChartLatestAffected imagesRadar Score
webhookie-allwebhookie0.1.22 of 3See more

webhookie-all webhookie 0.1.2

2 of the 3 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
gnutls@3.6.14-8.el8_3
0:3.6.16-5.el8_6

Open the chart page →

28,605
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
gnutls28@3.7.1-5
3.7.1-5+deb11u2

Open the chart page →

7,552
emissary-ingresswenerme8.12.21 of 2See more

emissary-ingress wenerme 8.12.2

1 of the 2 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
istio/kubectl:1.5.10dbb7726d1bf0
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6

Open the chart page →

10,843
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
longhornio/longhorn-manager:v1.2.3dca34321452c
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7

Open the chart page →

15,230
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
gnutls@3.6.14-7.el8_3
0:3.6.16-5.el8_6

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
gnutls@3.6.16-4.el8
0:3.6.16-5.el8_6

Open the chart page →

6,138
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
gnutls@3.7.1-r0
3.7.1-r1

Open the chart page →

2,555
vaultwardenwitcom-gmbh0.2.01 of 2See more

vaultwarden witcom-gmbh 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2

Open the chart page →

1,585
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
gnutls28@3.7.1-5
3.7.1-5+deb11u2

Open the chart page →

2,021
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
gnutls@3.6.16-4.el8
0:3.6.16-5.el8_6

Open the chart page →

11,577
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2022-2509.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
gnutls28@3.5.18-1ubuntu1.5
3.5.18-1ubuntu1.6
yandex/clickhouse-server:21.3.204eccfffb01d7
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7

Open the chart page →

9,207

Container images carrying it

579 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
taigaio/taiga-back:6.4.29f97323cc150
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
tautulli/tautulli:v2.7.7c4da15f058ea
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
thecampagnards/trafficlight-api:main7dca9d973837
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.7
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
gnutls28@3.7.3-4ubuntu1
3.7.3-4ubuntu1.1
1
torrespro/mca-worker:2.0.06d3bd305a1ba
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
gnutls@3.7.1-r0
3.7.1-r1
1
tvanro/prerender-alpine:6.4.06909015f0328
gnutls@3.7.1-r0
3.7.1-r1
1
ubcctlt/barman:v2.19cbbbbc8ae16b
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
uffizzi/app:latest66e9e3937c60
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
vexorian/dizquetv:1.4.37e2b99844a5c
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6
1
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
gnutls@3.6.16-4.el8
0:3.6.16-5.el8_6
1
vlebediantsev/config-server-another:lateste7f20450d2ae
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2
1
vlebediantsev/file-system-ms-final:latest10393a89b4a8
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2
1
vlebediantsev/logic-ms:latestdf8bf38c535b
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2
1
vlebediantsev/registration-ms-final:latest427af418b75e
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2
1
voltha/voltha-onos:5.1.8e038acb950d3
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6
1
wavefronthq/proxy:9.2d1064d28f6eb
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6
1
wekanteam/wekan:v4.2268a51f0327df
gnutls28@3.6.13-2ubuntu1.2
3.6.13-2ubuntu1.7
1
wener/samba:4.13.39a42bae466d4
gnutls@3.7.1-r0
3.7.1-r1
1
woojoong/wowza:latestec230db19652
gnutls28@3.5.18-1ubuntu1
3.5.18-1ubuntu1.6
1
xeladock/mysql_dns:latest4baf531453f1
gnutls28@3.7.3-4ubuntu1
3.7.3-4ubuntu1.1
1
xeladock/nginx2:latestc259a67b1dff
gnutls28@3.7.3-4ubuntu1
3.7.3-4ubuntu1.1
1
xtrendence/cryptofolio:V.2.2.0e6e6612bb94c
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
xuxueli/xxl-job-admin:2.4.0640093c35fd6
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
yandex/clickhouse-client:21.3863f94a0f607
gnutls28@3.5.18-1ubuntu1.5
3.5.18-1ubuntu1.6
1
yandex/clickhouse-server:latest1cbf75aabe1e
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
yandex/clickhouse-server:21.3.204eccfffb01d7
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
yandex/clickhouse-server:19.17ab1738a64b70
gnutls28@3.5.18-1ubuntu1.3
3.5.18-1ubuntu1.6
1
yandex/clickhouse-server:19.14ccf9c2b5e3f2
gnutls28@3.5.18-1ubuntu1.3
3.5.18-1ubuntu1.6
1
yandex/clickhouse-server:19.16d210dc69321e
gnutls28@3.5.18-1ubuntu1.3
3.5.18-1ubuntu1.6
1
youssef11gaber10/deployment-ui-react:latestba6853e35c60
gnutls28@3.7.1-5
3.7.1-5+deb11u2
1
yuzutech/kroki-bpmn:0.16.0bd629239a64e
gnutls@3.7.1-r0
3.7.1-r1
1
yuzutech/kroki-excalidraw:0.16.015c9eef47a62
gnutls@3.7.1-r0
3.7.1-r1
1
yuzutech/kroki-mermaid:0.16.07acc8fe7caba
gnutls@3.7.1-r0
3.7.1-r1
1
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
gnutls28@3.7.3-4ubuntu1
3.7.3-4ubuntu1.1
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
gnutls28@3.7.3-4ubuntu1
3.7.3-4ubuntu1.1
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
gnutls28@3.7.3-4ubuntu1
3.7.3-4ubuntu1.1
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
gnutls28@3.7.3-4ubuntu1
3.7.3-4ubuntu1.1
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2
1
zzorica/k8s-mgmt-pod:0.5.2640ca4de2922
gnutls28@3.7.1-5+deb11u1
3.7.1-5+deb11u2
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
gnutls28@3.5.18-1ubuntu1.1
3.5.18-1ubuntu1.6
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.7
1
gcr.io/tfx-oss-public/ml_metadata_store_server:1.5.0db8691752b4c
gnutls28@3.5.18-1ubuntu1.5
3.5.18-1ubuntu1.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.