StackRadar

CVE-2022-2564

High

Advisory

Published 29 Jul 2022In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.327
98th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

automattic/mongoose vulnerable to Prototype pollution via Schema.path

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
mongoosenpm4.13.14, 5.7.5, 5.12.5, 5.12.6+7 more5.13.15, 6.4.614
OSV records
GHSA-f825-f98c-gj3g
Also known as
BIT-mongoose-2022-2564

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
ackeesudaVerified publisher0.2.11 of 1See more

ackee suda 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
electerious/ackee:3.2.05e7173fa321c
mongoose@6.0.6
6.4.6

Open the chart page →

1,602
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
mongoose@4.13.14
5.13.15

Open the chart page →

25,443
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
mongoose@6.3.4
6.4.6
assistiot/smart-orchestrator_enabler:latest89f37e88c871
mongoose@6.3.4
6.4.6
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
mongoose@6.3.4
6.4.6

Open the chart page →

45,363
backend-charteks-3-tier-app-chart0.1.01 of 1See more

backend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
arfath29/3-tier-app-backend:latestee0750b18406
mongoose@5.12.14
5.13.15

Open the chart page →

1,693
iotagent-ulfiware0.1.21 of 1See more

iotagent-ul fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
fiware/iotagent-ul:1.14.0fe11f55a926d
mongoose@5.7.5
5.13.15

Open the chart page →

3,337
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
governify/registry:v3.4.0d3f37f4f8168
mongoose@5.12.6
5.13.15

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
governify/registry:v3.4.0d3f37f4f8168
mongoose@5.12.6
5.13.15

Open the chart page →

24,319
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
mongoose@5.7.5
5.13.15

Open the chart page →

6,454
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
mongoose@5.12.9
5.13.15

Open the chart page →

12,108
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
mongoose@5.12.9
5.13.15

Open the chart page →

19,226
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
mongoose@6.4.4
6.4.6

Open the chart page →

10,959
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
mongoose@5.13.9
5.13.15

Open the chart page →

9,968
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
mongoose@6.4.3
6.4.6

Open the chart page →

4,017
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-2564.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
mongoose@5.12.5
5.13.15

Open the chart page →

6,881

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
governify/registry:v3.4.0d3f37f4f8168
mongoose@5.12.6
5.13.15
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
mongoose@5.12.9
5.13.15
2
arfath29/3-tier-app-backend:latestee0750b18406
mongoose@5.12.14
5.13.15
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
mongoose@6.3.4
6.4.6
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
mongoose@6.3.4
6.4.6
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
mongoose@6.3.4
6.4.6
1
denisshav/backend:latest4cc8dc5a4499
mongoose@5.12.5
5.13.15
1
electerious/ackee:3.2.05e7173fa321c
mongoose@6.0.6
6.4.6
1
fiware/iotagent-ul:1.14.0fe11f55a926d
mongoose@5.7.5
5.13.15
1
jayfong/yapi:1.10.2163e5d621910
mongoose@5.7.5
5.13.15
1
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
mongoose@6.4.4
6.4.6
1
polonel/trudesk:1.2.60cf6513f6fe3
mongoose@6.4.3
6.4.6
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
mongoose@5.13.9
5.13.15
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
mongoose@4.13.14
5.13.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.