StackRadar

CVE-2022-25881

High

Advisory

Published 31 Jan 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.016
75th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
353
of 17,787 indexed, latest versions
Container images
351
deployed by those charts
Fix available
1 of 1
affected package

http-cache-semantics vulnerable to Regular Expression Denial of Service

Carried by container images the latest versions of 353 of 17,787 indexed charts deploy, on 351 images.

Affected packageAffected versionsFixed inImages
http-cache-semanticsnpm3.7.3, 3.8.0, 3.8.1, 4.0.3+1 more4.1.1351
OSV records
GHSA-rc47-6667-2j5j

Charts affected

353 by stars
ChartLatestAffected imagesRadar Score
zigbee2mqtthelm-chart-roeiVerified publisher1.19.01 of 1See more

zigbee2mqtt helm-chart-roei 1.19.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

2,173
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

24,174
streamsheetshelm-chartsVerified publisher0.2.35 of 8See more

streamsheets helm-charts 0.2.3

5 of the 8 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
http-cache-semantics@3.8.1
4.1.1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
http-cache-semantics@3.8.1
4.1.1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
http-cache-semantics@3.8.1
4.1.1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
http-cache-semantics@3.8.1
4.1.1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

89,949
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

8,213
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

4,253
http-folderhttp-folder2.0.01 of 1See more

http-folder http-folder 2.0.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
aureliengasser/http-folder:1.1.111c4318c2571
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

1,847
crypto-watchdoghuseyinnurbaki0.1.01 of 1See more

crypto-watchdog huseyinnurbaki 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
hhaluk/crypto-watchdog:0.4.0a6555953d941
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

2,656
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ibmcom/app-nav-init:1.0.1240ff499eb5b
http-cache-semantics@3.8.0
4.1.1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
http-cache-semantics@3.8.0
4.1.1

Open the chart page →

32,911
ibm-business-automation-insights-devibm-charts3.2.02 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

2 of the 6 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
http-cache-semantics@3.8.1
4.1.1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

39,343
ibm-kerify-devibm-charts1.0.01 of 1See more

ibm-kerify-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

8,221
ibm-microclimateibm-charts0.1.03 of 8See more

ibm-microclimate ibm-charts 0.1.0

3 of the 8 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
http-cache-semantics@3.8.0
4.1.1
ibmcom/microclimate-portal:latested5505e5c7ec
http-cache-semantics@3.8.0
4.1.1
ibmcom/microclimate-theia:lateste17bdccc5030
http-cache-semantics@3.8.0
4.1.1

Open the chart page →

57,728
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

4,504
erpnextimprowisedVerified publisher3.3.02 of 3See more

erpnext improwised 3.3.0

2 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
frappe/frappe-socketio:v13.4.12095767a9e82
http-cache-semantics@4.1.0
4.1.1
improwised/erpnext-worker:v13.4.197280b55cbd4
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

6,502
indexer-chartindexer-application0.1.01 of 1See more

indexer-chart indexer-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ibarreche/cloud-indexer-ci:latestb7a08274e69f
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

3,289
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

4,944
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

10,542
interbtc-hydrainterlay0.1.153 of 4See more

interbtc-hydra interlay 0.1.15

3 of the 4 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
http-cache-semantics@4.1.0
4.1.1
subsquid/hydra-indexer:5.0.0-alpha.37a7f8b9bad7ee
http-cache-semantics@3.8.1
4.1.1
subsquid/hydra-indexer-status-service:5.0.0-alpha.37a4136013909c
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

6,831
interlay-firesquidinterlay0.1.113 of 4See more

interlay-firesquid interlay 0.1.11

3 of the 4 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
http-cache-semantics@4.1.0
4.1.1
subsquid/substrate-explorer:firesquid0889a857f192
http-cache-semantics@4.1.0
4.1.1
subsquid/substrate-ingest:firesquidfa549779e9b1
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

4,667
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

7,233
istio-bookinfoistio-bookinfo1.2.21 of 6See more

istio-bookinfo istio-bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.15.009b9d6958a13
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

18,998
keyoxide-webittrident-oss0.2.31 of 1See more

keyoxide-web ittrident-oss 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
keyoxide/keyoxide:stable96f27a71269d
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

2,363
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

3,448
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

6,452
annotation-tooljtektVerified publisher0.1.51 of 2See more

annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

2,315
polygonal-annotation-tooljtektVerified publisher0.1.51 of 2See more

polygonal-annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

2,231
shynetjuniorjpdj0.1.301 of 1See more

shynet juniorjpdj 0.1.30

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

2,581
todo-appjunktext-via-aws1.2.101 of 1See more

todo-app junktext-via-aws 1.2.10

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.34d44adf5a4da2
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

1,579
k10appk10app0.2.13 of 11See more

k10app k10app 0.2.1

3 of the 11 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ghcr.io/k10app/basicuserservice:latest2ee057ad3bef
http-cache-semantics@4.1.0
4.1.1
ghcr.io/k10app/catalog:latest639c980be0f1
http-cache-semantics@4.1.0
4.1.1
ghcr.io/k10app/order:lateste1017d0dbd78
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

10,560
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

3,040
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

4,667
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

9,832
kube-admission-controller-starterk8s-validating-webhook0.2.01 of 2See more

kube-admission-controller-starter k8s-validating-webhook 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/kube-admission-controller-starter:maine9716966f30b
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

2,166
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

16,464
statsdkeyporttech0.1.191 of 1See more

statsd keyporttech 0.1.19

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
statsd/statsd:v0.8.6dab129e74c25
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

4,185
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service-ui:7.0.34ebd8b4ef340
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

12,541
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.11.0d0cd3d868aca
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

5,644
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

3,397
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

4,230
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

5,411
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
kubebb/tamp-portal:v5.6.0fadac6d52470
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

4,665
tapm-componentkubebb5.7.11 of 3See more

tapm-component kubebb 5.7.1

1 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
refar/apm-portal:v5.7.1dcca8e4477a6
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

10,265
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
kubebb/tdsf-portal:v5.7.0258458311bc9
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

6,490
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
kubebb/bff-server:v0.2.0-202312040fbb732379bc
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

13,820
gptchat-api-feishubotkubegemsapp0.1.11 of 3See more

gptchat-api-feishubot kubegemsapp 0.1.1

1 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
kubegems/chatgpt-api:latestf3c492a938ad
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

8,486
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

2,757
online-boutiquekubesphere-testVerified publisher0.1.02 of 11See more

online-boutique kubesphere-test 0.1.0

2 of the 11 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
http-cache-semantics@3.8.1
4.1.1
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

26,019
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

9,384
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

1,927
workload-operatorkubevious0.0.31 of 1See more

workload-operator kubevious 0.0.3

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
kubevious/workload-operator:1.0.20b0f4c507eb6
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

2,008
multitenantkvalitetsitVerified publisher2.2.181 of 1See more

multitenant kvalitetsit 2.2.18

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

1,614

Container images carrying it

351 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
http-cache-semantics@4.1.0
4.1.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.