StackRadar

CVE-2022-25878

High

Advisory

Published 28 May 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.023
83rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
17
of 17,781 indexed, latest versions
Container images
17
deployed by those charts
Fix available
1 of 1
affected package

Prototype Pollution in protobufjs

Carried by container images the latest versions of 17 of 17,781 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
protobufjsnpm6.10.2, 6.11.26.10.3, 6.11.317
OSV records
GHSA-g954-5hwp-pp24

Charts affected

17 by stars
ChartLatestAffected imagesRadar Score
kubeflowkubeflow1.6.21 of 45See more

kubeflow kubeflow 1.6.2

1 of the 45 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
protobufjs@6.11.2
6.11.3

Open the chart page →

96,941
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
protobufjs@6.10.2
6.10.3

Open the chart page →

4,455
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
protobufjs@6.11.2
6.11.3

Open the chart page →

27,096
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
protobufjs@6.11.2
6.11.3

Open the chart page →

7,232
kubeflowkromanow94-kubeflow0.5.11 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

1 of the 30 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
protobufjs@6.11.2
6.11.3

Open the chart page →

70,530
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
protobufjs@6.11.2
6.11.3

Open the chart page →

5,410
online-boutiquekubesphere-testVerified publisher0.1.02 of 11See more

online-boutique kubesphere-test 0.1.0

2 of the 11 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
protobufjs@6.10.2
6.10.3
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
protobufjs@6.10.2
6.10.3

Open the chart page →

26,018
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
protobufjs@6.11.2
6.11.3

Open the chart page →

29,588
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
protobufjs@6.11.2
6.11.3
mojaloop/event-sidecar:v11.0.189b8ab71b74b
protobufjs@6.11.2
6.11.3

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
protobufjs@6.11.2
6.11.3
mojaloop/event-sidecar:v11.0.189b8ab71b74b
protobufjs@6.11.2
6.11.3

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
protobufjs@6.11.2
6.11.3
mojaloop/event-sidecar:v11.0.189b8ab71b74b
protobufjs@6.11.2
6.11.3

Open the chart page →

12,108
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
protobufjs@6.11.2
6.11.3
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
protobufjs@6.11.2
6.11.3

Open the chart page →

11,479
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
protobufjs@6.11.2
6.11.3
mojaloop/central-ledger:v13.14.01abc8a7aa71c
protobufjs@6.11.2
6.11.3
mojaloop/event-sidecar:v11.0.189b8ab71b74b
protobufjs@6.11.2
6.11.3
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
protobufjs@6.11.2
6.11.3

Open the chart page →

19,226
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
protobufjs@6.11.2
6.11.3

Open the chart page →

3,881
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
protobufjs@6.11.2
6.11.3

Open the chart page →

3,576
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
protobufjs@6.10.2
6.10.3

Open the chart page →

2,838
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-25878.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
protobufjs@6.10.2
6.10.3

Open the chart page →

22,665

Container images carrying it

17 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
protobufjs@6.11.2
6.11.3
5
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
protobufjs@6.11.2
6.11.3
3
mojaloop/central-ledger:v13.14.01abc8a7aa71c
protobufjs@6.11.2
6.11.3
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
protobufjs@6.11.2
6.11.3
2
arturisimo/server-urjc:v1.0d8dc4430531e
protobufjs@6.11.2
6.11.3
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
protobufjs@6.10.2
6.10.3
1
catalysm/csmm:latestf003b35f54d9
protobufjs@6.11.2
6.11.3
1
hugohg34/server:0.0.2503e5d8960ff
protobufjs@6.11.2
6.11.3
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
protobufjs@6.11.2
6.11.3
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
protobufjs@6.11.2
6.11.3
1
roadiehq/community-backstage-image:latestef355bf5b639
protobufjs@6.11.2
6.11.3
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
protobufjs@6.11.2
6.11.3
1
temporalio/web:1.14.033cfa863d8ce
protobufjs@6.10.2
6.10.3
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
protobufjs@6.11.2
6.11.3
1
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
protobufjs@6.10.2
6.10.3
1
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
protobufjs@6.10.2
6.10.3
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
protobufjs@6.10.2
6.10.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.