StackRadar

CVE-2022-26520

Medium

Advisory

Published 16 Feb 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.030
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
135
of 17,787 indexed, latest versions
Container images
67
deployed by those charts
Fix available
1 of 1
affected package

pgjdbc Arbitrary File Write Vulnerability

Carried by container images the latest versions of 135 of 17,787 indexed charts deploy, on 67 images.

Affected packageAffected versionsFixed inImages
postgresqlmaven42.1.4, 42.2.1, 42.2.2, 42.2.2.jre7+18 more42.3.367
OSV records
GHSA-673j-qm5f-xpv8
Also known as
BIT-postgresql-jdbc-driver-2022-26520, GHSA-727h-hrw8-jg8q

Charts affected

135 by stars
ChartLatestAffected imagesRadar Score
pagespages-vasanth58141.0.01 of 3See more

pages pages-vasanth5814 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagespages-vjp1.0.01 of 3See more

pages pages-vjp 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagespawan-pages1.0.01 of 3See more

pages pawan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
postgresql@42.2.19
42.3.3

Open the chart page →

6,236
pagespighosh-pages1.0.01 of 3See more

pages pighosh-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagesprasanthi1.0.01 of 3See more

pages prasanthi 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagesranjinigogga1.0.01 of 3See more

pages ranjinigogga 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagesrebecca-pages1.0.01 of 3See more

pages rebecca-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
authentication-serviceredestroyder0.2.21 of 1See more

authentication-service redestroyder 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
redestroyder/authorization-service:0.0.1740364a619fd
postgresql@42.3.1
42.3.3

Open the chart page →

2,583
business-serviceredestroyder0.2.11 of 1See more

business-service redestroyder 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
redestroyder/business-service:0.0.1db03499a0726
postgresql@42.3.1
42.3.3

Open the chart page →

2,600
reportportalreportportal5.7.23 of 8See more

reportportal reportportal 5.7.2

3 of the 8 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
reportportal/service-api:5.7.29df41f8fb320
postgresql@42.2.13
42.3.3
reportportal/service-authorization:5.7.09e73114dbd15
postgresql@42.2.13
42.3.3
reportportal/service-jobs:5.7.2dc166c58485a
postgresql@42.2.18
42.3.3

Open the chart page →

25,739
pagesroccohiggins-pages1.0.01 of 3See more

pages roccohiggins-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagesronan-pages1.0.01 of 3See more

pages ronan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagessamanvithkaranth1.0.01 of 3See more

pages samanvithkaranth 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagessarubits-pages1.0.01 of 3See more

pages sarubits-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagessekharpkube1.0.01 of 3See more

pages sekharpkube 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
postgresql@42.2.8
42.3.3

Open the chart page →

12,512
pagesshrutiujlan-pages1.0.01 of 3See more

pages shrutiujlan-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
hetzner-iroboslamdev0.0.51 of 1See more

hetzner-irobo slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
slamdev/hetzner-irobo:0.0.13ca20c184c55
postgresql@42.2.23
42.3.3

Open the chart page →

3,754
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
postgresql@42.2.16
42.3.3

Open the chart page →

13,653
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
postgresql@42.2.6
42.3.3

Open the chart page →

13,127
pagessrinipages1.0.01 of 3See more

pages srinipages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
postgresql@42.2.1
42.3.3

Open the chart page →

11,842
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagestest43221.0.01 of 3See more

pages test4322 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
postgresql@42.2.8
42.3.3

Open the chart page →

12,512
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
thingsboard/tb-node:3.4.1645f43b688f7
postgresql@42.2.20
42.3.3

Open the chart page →

25,202
pagesthiru-pages1.0.01 of 3See more

pages thiru-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagesthuy-pages1.0.01 of 3See more

pages thuy-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pagesvictor-pages1.0.01 of 3See more

pages victor-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
pageswalter1.0.01 of 3See more

pages walter 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3

Open the chart page →

20,233
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
postgresql@42.2.8
42.3.3

Open the chart page →

5,462
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
postgresql@42.2.5
42.3.3

Open the chart page →

28,699
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-26520.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
postgresql@42.2.16
42.3.3

Open the chart page →

3,424

Container images carrying it

67 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
flyway/flyway:6.4.422d97ceb0c47
postgresql@42.2.12.jre6
42.3.3
79
apache/shenyu-admin:2.4.2e8b7c4ddd069
postgresql@42.2.8
42.3.3
3
supertokens/supertokens-postgresql:3.1418d34c781347
postgresql@42.2.10
42.3.3
3
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
postgresql@42.2.5
42.3.3
2
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
postgresql@42.2.14
42.3.3
2
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
postgresql@42.2.14
42.3.3
2
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
postgresql@42.2.14
42.3.3
2
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
postgresql@42.2.14
42.3.3
2
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
postgresql@42.2.14
42.3.3
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
postgresql@42.3.1
42.3.3
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
postgresql@42.3.1
42.3.3
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
postgresql@42.3.1
42.3.3
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
postgresql@42.3.1
42.3.3
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
postgresql@42.3.1
42.3.3
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
postgresql@42.3.1
42.3.3
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
postgresql@42.3.1
42.3.3
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
postgresql@42.2.5
42.3.3
2
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
postgresql@42.2.20
42.3.3
1
apache/ranger:2.7.076c176e8a0e4
postgresql@42.2.16.jre7
42.3.3
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
postgresql@42.2.18
42.3.3
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
postgresql@42.2.16
42.3.3
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
postgresql@42.2.20
42.3.3
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
postgresql@42.2.20
42.3.3
1
atlassian/confluence-server:7.10.03b9222ab32ef
postgresql@42.2.16
42.3.3
1
atlassian/jira-software:8.14.037bc46cbec1a
postgresql@42.2.6
42.3.3
1
atlassian/jira-software:9.7.264a75aa4ec4e
postgresql@42.2.27
42.3.3
1
beastob/url-shortener:1.0.299a49885ab33
postgresql@42.2.24.jre7
42.3.3
1
bivas/presto:0.19605545994f806
postgresql@42.1.4
42.3.3
1
chandanteekinavar/findery-market-order-service:1.00cf52bf5ee9a
postgresql@42.2.23
42.3.3
1
eikek0/sharry:1.8.0661ff3ef42cd
postgresql@42.2.20
42.3.3
1
farberg/apache-knox-docker:1.6.14b4a22487394
postgresql@42.2.19
42.3.3
1
folioci/mod-marccat:latest1b57d690d568
postgresql@42.1.4
42.3.3
1
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
postgresql@42.2.18
42.3.3
1
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
postgresql@42.2.14
42.3.3
1
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
postgresql@42.2.14
42.3.3
1
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
postgresql@42.2.14
42.3.3
1
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
postgresql@42.2.14
42.3.3
1
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
postgresql@42.2.14
42.3.3
1
library/sonarqube:6.7.6-community0ae5169e3d0f
postgresql@42.2.1
42.3.3
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
postgresql@42.2.19
42.3.3
1
library/sonarqube:8.9.2-community88cd63154d4b
postgresql@42.2.19
42.3.3
1
library/sonarqube:8.2-communitya246bc64207e
postgresql@42.2.8
42.3.3
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
postgresql@42.2.19
42.3.3
1
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
postgresql@42.2.19
42.3.3
1
metabase/metabase:v0.31.2ffb2dccacefc
postgresql@42.2.2
42.3.3
1
openkm/openkm-ce:6.3.113bc465a7461b
postgresql@42.2.8
42.3.3
1
owasp/dependency-track:3.8.0efc65e702ee1
postgresql@42.2.5
42.3.3
1
redestroyder/authorization-service:0.0.1740364a619fd
postgresql@42.3.1
42.3.3
1
redestroyder/business-service:0.0.1db03499a0726
postgresql@42.3.1
42.3.3
1
remche/shinyproxy:2.6.18bcda8a04d3b
postgresql@42.2.25
42.3.3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.