StackRadar

CVE-2022-27406

High

Advisory

Published 22 Apr 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.033
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
259
of 17,781 indexed, latest versions
Container images
195
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 259 of 17,781 indexed charts deploy, on 195 images.

Affected packageAffected versionsFixed inImages
freetypedeb2.6.1-0.1ubuntu2.3, 2.6.1-0.1ubuntu2.4, 2.8.1-2ubuntu2, 2.8.1-2ubuntu2.1+2 more2.6.1-0.1ubuntu2.5+esm1, 2.8.1-2ubuntu2.2, 2.10.1-2ubuntu0.2, 2.11.1+dfsg-1ubuntu0.1106
freetypeapk2.10.2-r0, 2.10.4-r0, 2.10.4-r1, 2.10.4-r2+3 more2.10.4-r2, 2.10.4-r3, 2.11.1-r289
OSV records
ALPINE-CVE-2022-27406UBUNTU-CVE-2022-27406
Also known as
USN-5453-1, USN-5528-1, USN-7352-2

Charts affected

259 by stars
ChartLatestAffected imagesRadar Score
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-27406.

Container imageDigestPackageFixed in
denisshav/frontend:latestb97cc69fbac6
freetype@2.10.4-r1
2.10.4-r3

Open the chart page →

6,881
pagesvictor-pages1.0.02 of 3See more

pages victor-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2022-27406.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
flyway/flyway:6.4.422d97ceb0c47
freetype@2.8.1-2ubuntu2
2.8.1-2ubuntu2.2

Open the chart page →

20,190
pageswalter1.0.02 of 3See more

pages walter 1.0.0

2 of the 3 container images this version deploys carry CVE-2022-27406.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
flyway/flyway:6.4.422d97ceb0c47
freetype@2.8.1-2ubuntu2
2.8.1-2ubuntu2.2

Open the chart page →

20,190
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-27406.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
freetype@2.11.0-r0
2.11.1-r2

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-27406.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
freetype@2.11.1-r1
2.11.1-r2

Open the chart page →

1,523
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-27406.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-27406.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2

Open the chart page →

28,605
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-27406.

Container imageDigestPackageFixed in
longhornio/longhorn-ui:v1.2.3148598de4b7d
freetype@2.10.4-r1
2.10.4-r3

Open the chart page →

15,230
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2022-27406.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
freetype@2.11.1-r1
2.11.1-r2
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
freetype@2.11.1-r0
2.11.1-r2

Open the chart page →

16,083

Container images carrying it

195 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
xeladock/mysql_dns:latest4baf531453f1
freetype@2.11.1+dfsg-1build1
2.11.1+dfsg-1ubuntu0.1
1
xeladock/nginx2:latestc259a67b1dff
freetype@2.11.1+dfsg-1build1
2.11.1+dfsg-1ubuntu0.1
1
yuzutech/kroki:0.17.0192b7b27c857
freetype@2.11.1-r0
2.11.1-r2
1
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
freetype@2.10.4-r1
2.10.4-r3
1
yuzutech/kroki-bpmn:0.16.0bd629239a64e
freetype@2.10.4-r1
2.10.4-r3
1
yuzutech/kroki-excalidraw:0.16.015c9eef47a62
freetype@2.10.4-r1
2.10.4-r3
1
yuzutech/kroki-mermaid:0.16.07acc8fe7caba
freetype@2.10.4-r1
2.10.4-r3
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
gcr.io/kubecost1/frontend:prod-1.81.096dfb19838b8
freetype@2.10.4-r1
2.10.4-r3
1
gcr.io/kubecost1/frontend:prod-1.82.2ba66607c947c
freetype@2.10.4-r1
2.10.4-r3
1
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
freetype@2.11.1-r0
2.11.1-r2
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
freetype@2.10.4-r1
2.10.4-r3
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
freetype@2.10.4-r1
2.10.4-r3
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/kore3lab/kore-board.frontend:v0.5.584ece8ee5d35
freetype@2.10.4-r1
2.10.4-r3
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
freetype@2.8.1-2ubuntu2.1
2.8.1-2ubuntu2.2
1
ghcr.io/mmontes11/github-explorer:v0.7.0bf2234545584
freetype@2.10.4-r0
2.10.4-r2
1
ghcr.io/mmontes11/iot-front:v3.11.0eb942172cda9
freetype@2.10.4-r0
2.10.4-r2
1
ghcr.io/mmontes11/iot-nginx:v3.11.0dc8c7bb6605e
freetype@2.10.4-r0
2.10.4-r2
1
ghcr.io/netsoc/docs:latest48890a52b327
freetype@2.10.4-r1
2.10.4-r3
1
ghcr.io/netsoc/website:latesta9618107fa50
freetype@2.10.4-r1
2.10.4-r3
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
ghcr.io/saiakhil46/burger-app:latest68b76520c0a9
freetype@2.10.4-r1
2.10.4-r3
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
freetype@2.10.4-r1
2.10.4-r3
1
ghcr.io/tauffer-consulting/domino-frontend:latesta923b86a0903
freetype@2.10.4-r1
2.10.4-r3
1
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
freetype@2.11.0-r0
2.11.1-r2
1
ghcr.io/wbstack/ui:3.94b01f67faadf1
freetype@2.11.1-r1
2.11.1-r2
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
freetype@2.10.1-2ubuntu0.1
2.10.1-2ubuntu0.2
1
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
freetype@2.11.0-r0
2.11.1-r2
1
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
freetype@2.10.4-r1
2.10.4-r3
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
freetype@2.6.1-0.1ubuntu2.3
2.6.1-0.1ubuntu2.5+esm1
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
freetype@2.10.4-r1
2.10.4-r3
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
freetype@2.10.4-r1
2.10.4-r3
1
quay.io/renokico/laravel-helm-demo:octane-0.6.0cad83090c58f
freetype@2.10.4-r0
2.10.4-r2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.