StackRadar

CVE-2022-25845

High

Advisory

Published 11 Jun 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.187
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Unsafe deserialization in com.alibaba:fastjson

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
fastjsonmaven1.2.31_noneautotype, 1.2.43, 1.2.69_noneautotype, 1.2.70+3 more1.2.839
OSV records
GHSA-pv7h-hx5h-mgfj
Also known as
SNYK-JAVA-COMALIBABA-2859222

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
hertzbeathertzbeatOfficialVerified publisher1.8.11 of 4See more

hertzbeat hertzbeat 1.8.1

1 of the 4 container images this version deploys carry CVE-2022-25845.

Container imageDigestPackageFixed in
apache/hertzbeat-collector:1.8.0a2bab1be574c
fastjson@1.2.31_noneautotype
1.2.83

Open the chart page →

14,000
rocketmqgin1.1.02 of 2See more

rocketmq gin 1.1.0

2 of the 2 container images this version deploys carry CVE-2022-25845.

Container imageDigestPackageFixed in
apache/rocketmq:4.9.35ac2a4e0f627
fastjson@1.2.76
1.2.83
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
fastjson@1.2.76
1.2.83

Open the chart page →

9,154
seata-serverheidaodageshiwoVerified publisher1.0.01 of 1See more

seata-server heidaodageshiwo 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-25845.

Container imageDigestPackageFixed in
seataio/seata-server:1.5.1ee1ed55f4144
fastjson@1.2.73
1.2.83

Open the chart page →

5,624
sentinel-dashboardsentinel-dashboardVerified publisher0.1.01 of 1See more

sentinel-dashboard sentinel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25845.

Container imageDigestPackageFixed in
royalwang/sentinel-dashboard:1.8.4df99e2499f91
fastjson@1.2.75
1.2.83

Open the chart page →

4,287
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-25845.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
fastjson@1.2.70
1.2.83

Open the chart page →

12,513
tapm-componentkubebb5.7.11 of 3See more

tapm-component kubebb 5.7.1

1 of the 3 container images this version deploys carry CVE-2022-25845.

Container imageDigestPackageFixed in
refar/apm-api:v5.7.1241373fa2972
fastjson@1.2.75
1.2.83

Open the chart page →

10,264
ladeitladeit0.4.01 of 2See more

ladeit ladeit 0.4.0

1 of the 2 container images this version deploys carry CVE-2022-25845.

Container imageDigestPackageFixed in
ladeit/ladeit:latest962b665ffe82
fastjson@1.2.43
1.2.83

Open the chart page →

26,356
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2022-25845.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
fastjson@1.2.69_noneautotype
1.2.83

Open the chart page →

6,634
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2022-25845.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
fastjson@1.2.70
1.2.83

Open the chart page →

12,513
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-25845.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
fastjson@1.2.70
1.2.83

Open the chart page →

12,513

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
fastjson@1.2.70
1.2.83
3
apache/hertzbeat-collector:1.8.0a2bab1be574c
fastjson@1.2.31_noneautotype
1.2.83
1
apache/rocketmq:4.9.35ac2a4e0f627
fastjson@1.2.76
1.2.83
1
apache/rocketmq-exporter:0.0.2c8fb51195444
fastjson@1.2.69_noneautotype
1.2.83
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
fastjson@1.2.76
1.2.83
1
ladeit/ladeit:latest962b665ffe82
fastjson@1.2.43
1.2.83
1
refar/apm-api:v5.7.1241373fa2972
fastjson@1.2.75
1.2.83
1
royalwang/sentinel-dashboard:1.8.4df99e2499f91
fastjson@1.2.75
1.2.83
1
seataio/seata-server:1.5.1ee1ed55f4144
fastjson@1.2.73
1.2.83
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.