StackRadar

CVE-2022-25881

High

Advisory

Published 31 Jan 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.016
75th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
353
of 17,787 indexed, latest versions
Container images
351
deployed by those charts
Fix available
1 of 1
affected package

http-cache-semantics vulnerable to Regular Expression Denial of Service

Carried by container images the latest versions of 353 of 17,787 indexed charts deploy, on 351 images.

Affected packageAffected versionsFixed inImages
http-cache-semanticsnpm3.7.3, 3.8.0, 3.8.1, 4.0.3+1 more4.1.1351
OSV records
GHSA-rc47-6667-2j5j

Charts affected

353 by stars
ChartLatestAffected imagesRadar Score
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

2,685
stremiolbenicio-communityVerified publisher0.1.11 of 2See more

stremio lbenicio-community 0.1.1

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
stremio/server:latest3dc145603def
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

2,601
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-ui-react:latestba6853e35c60
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

5,905
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
devspacecloud/ui:0.3.3deef55ff29a7
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

9,880
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

17,836
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

2,248
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

3,651
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

5,288
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

29,712
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

68,330
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

7,027
middleware-odigosmiddleware-labsVerified publisher0.2.411 of 6See more

middleware-odigos middleware-labs 0.2.41

1 of the 6 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-ui:middleware-test-0.0.787120a4561a9
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

8,370
middleware-visionmiddleware-labsVerified publisher0.2.651 of 6See more

middleware-vision middleware-labs 0.2.65

1 of the 6 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-ui:middleware-test-0.0.853772b7b42c7
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

8,361
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service-ui:7.0.34ebd8b4ef340
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

12,862
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

42,983
iotmmontesVerified publisher0.3.24 of 7See more

iot mmontes 0.3.2

4 of the 7 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
http-cache-semantics@3.8.1
4.1.1
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
http-cache-semantics@3.8.1
4.1.1
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
http-cache-semantics@3.8.1
4.1.1
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

10,608
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
http-cache-semantics@3.8.1
4.1.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

11,734
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
http-cache-semantics@3.8.1
4.1.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

11,734
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
http-cache-semantics@3.8.1
4.1.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

12,147
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

14,811
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
http-cache-semantics@3.8.1
4.1.1
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

11,518
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
http-cache-semantics@3.8.1
4.1.1
mojaloop/central-ledger:v13.14.01abc8a7aa71c
http-cache-semantics@3.8.1
4.1.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
http-cache-semantics@3.8.1
4.1.1
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

19,265
reporting-hub-bop-api-svcmojaloop4.1.31 of 1See more

reporting-hub-bop-api-svc mojaloop 4.1.3

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

1,661
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

6,438
monopolymonopolypackage0.1.01 of 1See more

monopoly monopolypackage 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
gonzague/monopoly:latest70465995deea
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

1,130
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

8,556
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

10,998
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

6,684
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

4,908
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

6,646
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

3,128
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

12,861
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

12,861
myhelmappmyhelm-app1.1.01 of 1See more

myhelmapp myhelm-app 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
patdada/bella-docker:v1.0.075127147a624
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

1,625
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

3,270
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
http-cache-semantics@3.8.1
4.1.1
socialmediamacroscope/smile_server:0.3.31a528c794270
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

109,485
node-appnode-app-charts0.1.01 of 1See more

node-app node-app-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
eameti/node-app:latestf36642affa86
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

1,444
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

27,486
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
http-cache-semantics@3.8.0
4.1.1

Open the chart page →

88,616
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
http-cache-semantics@3.8.0
4.1.1

Open the chart page →

38,889
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

9,968
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
openwhisk/alarmprovider:2.2.0b695a6ceb406
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

36,230
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

1,986
myappp4-helm0.1.02 of 6See more

myapp p4-helm 0.1.0

2 of the 6 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
http-cache-semantics@3.8.1
4.1.1
fjvela/urjc-fjvela-server:1.0.53c840aebce22
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

19,725
blockscoutparadeum-teamVerified publisher0.1.51 of 1See more

blockscout paradeum-team 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
quay.io/netwarps/blockscoutdigest-pinnedbecd3e39360a
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

3,448
walletconnect-relayparadeum-teamVerified publisher0.1.21 of 1See more

walletconnect-relay paradeum-team 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
quay.io/netwarps/walletconnect-relay:v2.1.3-rc.15d90b9c193e0
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

1,243
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

6,524
practica-helmpractica-helm0.1.02 of 7See more

practica-helm practica-helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
http-cache-semantics@3.8.1
4.1.1
slagattollas/weatherservice-practica:latest68e7f56393fc
http-cache-semantics@3.8.1
4.1.1

Open the chart page →

28,495
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2022-25881.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
http-cache-semantics@4.1.0
4.1.1

Open the chart page →

2,969

Container images carrying it

351 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
http-cache-semantics@4.1.0
4.1.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.