StackRadar

CVE-2022-25758

High

Advisory

Published 2 Jul 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.021
80th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
1 of 1
affected package

Regular expression denial of service in scss-tokenizer

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
scss-tokenizernpm0.2.3, 0.3.00.4.312
OSV records
GHSA-7mwh-4pqv-wmr8

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

9,203
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

5,209
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

6,868
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

5,940
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

3,237
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

18,277
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

25,456
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

5,209
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

11,174
testnet-faucetethereum-helm-chartsVerified publisher0.1.31 of 1See more

testnet-faucet ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
parithoshj/testnet-faucet:9859e0dcdca426fea6d
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

3,005
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

32,915
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

3,651
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

5,287
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
scss-tokenizer@0.2.3
0.4.3

Open the chart page →

5,940
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-25758.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
scss-tokenizer@0.3.0
0.4.3

Open the chart page →

4,017

Container images carrying it

12 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
pantsel/konga:latestc8172b75607d
scss-tokenizer@0.2.3
0.4.3
3
chatwoot/chatwoot:v3.1.0d530ab8c1753
scss-tokenizer@0.2.3
0.4.3
2
amundsendev/amundsen-frontend:2.1.169e7915e61c1
scss-tokenizer@0.2.3
0.4.3
1
chatwoot/chatwoot:v4.15.167ebc751c171
scss-tokenizer@0.2.3
0.4.3
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
scss-tokenizer@0.2.3
0.4.3
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
scss-tokenizer@0.2.3
0.4.3
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
scss-tokenizer@0.2.3
0.4.3
1
lavandadelpatio/frontend:latest501c3f31e0bc
scss-tokenizer@0.2.3
0.4.3
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
scss-tokenizer@0.2.3
0.4.3
1
polonel/trudesk:1.2.60cf6513f6fe3
scss-tokenizer@0.3.0
0.4.3
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
scss-tokenizer@0.2.3
0.4.3
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
scss-tokenizer@0.2.3
0.4.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.