StackRadar

CVE-2022-28131

Unscored

Advisory

Published 20 Jul 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,159
of 17,787 indexed, latest versions
Container images
1,218
deployed by those charts
Fix available
1 of 1
affected package

Stack exhaustion from deeply nested XML documents in encoding/xml

Carried by container images the latest versions of 1,159 of 17,787 indexed charts deploy, on 1,218 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+73 more1.17.121,218
OSV records
GO-2022-0521
Also known as
BIT-golang-2022-28131

Charts affected

1,159 by stars
ChartLatestAffected imagesRadar Score
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
stdlib@go1.16.10
1.17.12

Open the chart page →

2,435
operatorrookout0.0.201 of 2See more

operator rookout 0.0.20

1 of the 2 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
rookout/k8s-operator:latest0d083f3ef1a7
stdlib@go1.15.15
1.17.12

Open the chart page →

2,209
routehub-serverroutehub-helm1.0.11 of 3See more

routehub-server routehub-helm 1.0.1

1 of the 3 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
stdlib@go1.16.7
1.17.12

Open the chart page →

6,940
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.17.12

Open the chart page →

4,612
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
stdlib@go1.17.8
1.17.12

Open the chart page →

2,300
caddysagikazarmarkVerified publisher0.0.141 of 1See more

caddy sagikazarmark 0.0.14

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/caddy:2.4.5874405536b3e
stdlib@go1.17
1.17.12

Open the chart page →

2,960
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-email-service:v0.1.0-nativecf28472bc460
stdlib@go1.17.11
1.17.12

Open the chart page →

16,159
fmtok8s-email-servicesalaboy0.2.01 of 1See more

fmtok8s-email-service salaboy 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-email-service:v0.2.0-nativeb52d5dbac2ca
stdlib@go1.17.11
1.17.12

Open the chart page →

2,896
hellowsamarthya2.0.01 of 1See more

hellow samarthya 2.0.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
samarthya/spinnaker:v1.0ef06d81036af
stdlib@go1.17.6
1.17.12

Open the chart page →

2,121
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
stdlib@go1.18.2
1.17.12

Open the chart page →

11,314
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
stdlib@go1.18.1
1.17.12

Open the chart page →

4,744
mongodbsb-helm-charts0.4.01 of 1See more

mongodb sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mongo:7.0.140032d2ca20db
stdlib@go1.18.2
1.17.12

Open the chart page →

4,095
mysqlsb-helm-charts0.4.01 of 1See more

mysql sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mysql:8.4.3106d5197fd8e
stdlib@go1.18.2
1.17.12

Open the chart page →

1,096
redissb-helm-charts0.4.01 of 1See more

redis sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/redis:7.4.1-alpinec1e88455c852
stdlib@go1.18.2
1.17.12

Open the chart page →

1,324
ed-traefikscaleway-charts0.2.01 of 1See more

ed-traefik scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/traefik:v1.7.345d47b7bb2546
stdlib@go1.16.12
1.17.12

Open the chart page →

2,133
ed-traefik2scaleway-charts0.2.01 of 1See more

ed-traefik2 scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/traefik:2.5.62f603f8d3abe
stdlib@go1.17.5
1.17.12

Open the chart page →

3,160
scalyr-k8snode-managerscalyr-k8snode-managerVerified publisher0.1.71 of 1See more

scalyr-k8snode-manager scalyr-k8snode-manager 0.1.7

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
stdlib@go1.18.1
1.17.12

Open the chart page →

2,150
cosischichtelVerified publisher0.1.01 of 1See more

cosi schichtel 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/objectstorage-controller:v20221027-v0.1.1-8-g300019fa84b574e8027
stdlib@go1.18.3
1.17.12

Open the chart page →

1,309
satisfactoryschichtelVerified publisher0.3.31 of 1See more

satisfactory schichtel 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.9464d11e36e10
stdlib@go1.18.1
1.17.12

Open the chart page →

3,564
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
stdlib@go1.17
1.17.12

Open the chart page →

5,582
icinga2-masterschmitzis0.2.01 of 6See more

icinga2-master schmitzis 0.2.0

1 of the 6 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
grafana/grafana:8.0.3696823fbc561
stdlib@go1.16.1
1.17.12

Open the chart page →

3,731
version-checkerschmitzis0.2.21 of 1See more

version-checker schmitzis 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
stdlib@go1.15.2
1.17.12

Open the chart page →

3,023
openldapschoolguys-helmcharts0.1.31 of 1See more

openldap schoolguys-helmcharts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.17.12

Open the chart page →

3,313
satisfactory-serverschoolguys-helmcharts0.1.81 of 1See more

satisfactory-server schoolguys-helmcharts 0.1.8

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
stdlib@go1.18.1
1.17.12

Open the chart page →

3,466
cernboxsciencebox0.0.41 of 6See more

cernbox sciencebox 0.0.4

1 of the 6 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
cs3org/revad:v1.19.03b57a34a7dfd
stdlib@go1.17.3
1.17.12

Open the chart page →

2,330
ldap-instance-configsciencebox0.0.11 of 1See more

ldap-instance-config sciencebox 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.17.12

Open the chart page →

3,313
centralbrainsciencemeshVerified publisher0.0.34 of 5See more

centralbrain sciencemesh 0.0.3

4 of the 5 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
grafana/grafana:7.3.315b977f5207d
stdlib@go1.15.1
1.17.12
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.17.12
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.17.12
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
stdlib@go1.15.3
1.17.12

Open the chart page →

9,754
searchpesearchpe4.1.01 of 2See more

searchpe searchpe 4.1.0

1 of the 2 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/postgres:13.703652c675ae1
stdlib@go1.16.7
1.17.12

Open the chart page →

2,637
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mysql:9.0.192dc86967801
stdlib@go1.18.2
1.17.12

Open the chart page →

5,499
aws-secretssecretsprovider0.1.01 of 1See more

aws-secrets secretsprovider 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Open the chart page →

2,213
cloudflaredsectionmeVerified publisher2022.3.41 of 1See more

cloudflared sectionme 2022.3.4

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
stdlib@go1.17.1
1.17.12

Open the chart page →

2,407
influxdb_exportersectionmeVerified publisher0.0.21 of 1See more

influxdb_exporter sectionme 0.0.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/prometheus/influxdb-exporter:v0.10.03854d8af7bd4
stdlib@go1.18.3
1.17.12

Open the chart page →

922
seldon-core-analyticsseldon1.17.14 of 8See more

seldon-core-analytics seldon 1.17.1

4 of the 8 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.17.12
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.17.12
prom/prometheus:v2.18.15880ec936055
stdlib@go1.14.2
1.17.12
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.17.12

Open the chart page →

10,733
backendsignalen4.24.02 of 4See more

backend signalen 4.24.0

2 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.17.12
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
stdlib@go1.16.7
1.17.12

Open the chart page →

10,972
alertmanagersignoz0.5.21 of 1See more

alertmanager signoz 0.5.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
signoz/alertmanager:0.5.07bc7de2e33c2
stdlib@go1.14
1.17.12

Open the chart page →

2,181
trilliansigstoreVerified publisher0.3.201 of 5See more

trillian sigstore 0.3.20

1 of the 5 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.17.12

Open the chart page →

2,739
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
stdlib@go1.17.6
1.17.12

Open the chart page →

2,381
config-connector-templaterslamdev0.0.51 of 1See more

config-connector-templater slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
slamdev/config-connector-templater:0.0.3a234541c9fa8
stdlib@go1.16.5
1.17.12

Open the chart page →

2,110
flux-notifierslamdev0.0.71 of 1See more

flux-notifier slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
slamdev/flux-notifier:v0.0.8b173d809132d
stdlib@go1.13.11
1.17.12

Open the chart page →

2,015
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
stdlib@go1.17.9
1.17.12

Open the chart page →

9,235
gke-preemptible-notifierslamdev0.0.61 of 1See more

gke-preemptible-notifier slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
stdlib@go1.13.11
1.17.12

Open the chart page →

2,860
octavia-ingress-controllerslamdev0.0.71 of 1See more

octavia-ingress-controller slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
stdlib@go1.15
1.17.12

Open the chart page →

2,761
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
stdlib@go1.13.5
1.17.12

Open the chart page →

8,697
oi-slurm-cluster-chartslurm-cluster-chart0.25.11 of 4See more

oi-slurm-cluster-chart slurm-cluster-chart 0.25.1

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.17.12

Open the chart page →

4,376
slurm-cluster-chartslurm-cluster-chart0.25.01 of 4See more

slurm-cluster-chart slurm-cluster-chart 0.25.0

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.17.12

Open the chart page →

4,376
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
helga09/my_sql_shoes:v1.1.1a03657d97897
stdlib@go1.18.2
1.17.12

Open the chart page →

7,586
csi-gcs-softonic-factorysoftonic0.9.31 of 4See more

csi-gcs-softonic-factory softonic 0.9.3

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ofekmeister/csi-gcs:v0.9.030d70fa9211b
stdlib@go1.18.2
1.17.12

Open the chart page →

1,842
hello-world-appsoftonic1.2.21 of 1See more

hello-world-app softonic 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/giantswarm/helloworld:0.2.07a07ee730305
stdlib@go1.16.7
1.17.12

Open the chart page →

1,957
pod-defaultersoftonic0.1.31 of 1See more

pod-defaulter softonic 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
softonic/pod-defaulter:0.1.072017aed5902
stdlib@go1.14.9
1.17.12

Open the chart page →

2,561
preemptible-killersoftonic1.2.61 of 1See more

preemptible-killer softonic 1.2.6

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
softonic/preemptible-killer:1.2.6-294b87f1fb362
stdlib@go1.14.10
1.17.12

Open the chart page →

2,338

Container images carrying it

1,218 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
postgis/postgis:17-3.4-alpine5a1dbedac34e
stdlib@go1.18.2
1.17.12
1
postgis/postgis:11-2.5f479f6c3435e
stdlib@go1.16.7
1.17.12
1
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
stdlib@go1.13.12
1.17.12
1
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
stdlib@go1.16.9
1.17.12
1
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
stdlib@go1.16
1.17.12
1
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
stdlib@go1.16.9
1.17.12
1
prom/influxdb-exporter:v0.9.0f63fd77c05ee
stdlib@go1.17.8
1.17.12
1
prom/memcached-exporter:v0.9.001267317c95d
stdlib@go1.16.2
1.17.12
1
prom/prometheus:v2.18.15880ec936055
stdlib@go1.14.2
1.17.12
1
prom/prometheus:v2.19.2cd134bd4fca0
stdlib@go1.14.4
1.17.12
1
prom/prometheus:v2.16.0e4ca62c0d62f
stdlib@go1.13.8
1.17.12
1
prom/prometheus:v2.22.2f7ffebdd428b
stdlib@go1.15.5
1.17.12
1
prom/pushgateway:v1.4.33496e0f85943
stdlib@go1.18.2
1.17.12
1
prom/snmp-exporter:v0.20.09d226d7de223
stdlib@go1.15.8
1.17.12
1
prom/statsd-exporter:v0.22.48be660470961
stdlib@go1.17.3
1.17.12
1
pysga1996/redis:latest3af6d0c7db19
stdlib@go1.18.2
1.17.12
1
qichenxu4pd/mysqlweb:1.2d758d41d9c6b
stdlib@go1.18.2
1.17.12
1
qonstrukt/php:8.4-v8-apache089af7925aa1
stdlib@go1.14.2
1.17.12
1
qoveryrd/digital-mobius:0.1.4b30a9398a83c
stdlib@go1.15.5
1.17.12
1
quiq/docker-registry-ui:0.9.491281da47036
stdlib@go1.18
1.17.12
1
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
stdlib@go1.17
1.17.12
1
ralexstokes/eth2-fork-mon:latestc0d4bbefd31f
stdlib@go1.16.7
1.17.12
1
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
stdlib@go1.16.6
1.17.12
1
rancher/local-path-provisioner:v0.0.22e34c88ae0aff
stdlib@go1.16.15
1.17.12
1
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
stdlib@go1.16.4
1.17.12
1
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
stdlib@go1.16.4
1.17.12
1
rclone/rclone:1.57.01e6eeabddc01
stdlib@go1.17.2
1.17.12
1
rclone/rclone:1.56.0f2fc45c8bc57
stdlib@go1.16.6
1.17.12
1
redislabs/redisearch:2.4.1433561794c5c8
stdlib@go1.16.7
1.17.12
1
reportportal/migrations:5.7.0da5d8e1395fe
stdlib@go1.13.6
1.17.12
1
reportportal/service-index:5.0.112b27a2d7a87d
stdlib@go1.17.1
1.17.12
1
rezachalak/bzen-mongo:1.0.034f694325191
stdlib@go1.18.2
1.17.12
1
ribbybibby/s3-exporter:v0.5.0998184c51a00
stdlib@go1.15.15
1.17.12
1
rimusz/security-sample-app:0.2.0b9a178ca76ef
stdlib@go1.14.4
1.17.12
1
robjuz/postgresql-nominatim:latest805c7bab76df
stdlib@go1.16.5
1.17.12
1
robotshop/rs-dispatch:latestde81f1d07b02
stdlib@go1.17
1.17.12
1
robotshop/rs-mongodb:latest119b545823cd
stdlib@go1.16.3
1.17.12
1
rogerrum/alertmanager-discord:1.0.3827593369625
stdlib@go1.17.4
1.17.12
1
rookout/k8s-operator:latest0d083f3ef1a7
stdlib@go1.15.15
1.17.12
1
runatlantis/atlantis:v0.16.145fbaf7e207c
stdlib@go1.14.7
1.17.12
1
samarthya/spinnaker:v1.0ef06d81036af
stdlib@go1.17.6
1.17.12
1
sarwansharma/minio:v359d1da9385d1
stdlib@go1.18.3
1.17.12
1
sentriz/gonic:v0.13.1a74012a6adf3
stdlib@go1.16.4
1.17.12
1
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
stdlib@go1.15.12
1.17.12
1
signald/signald:0.18.20ffad7ccc2eb
stdlib@go1.18.1
1.17.12
1
signoz/alertmanager:0.5.07bc7de2e33c2
stdlib@go1.14
1.17.12
1
sikalabs/slu:v0.34.0fdc0c6711add
stdlib@go1.17.6
1.17.12
1
simpleidserver/faasprometheus:0.0.425e378d57d78
stdlib@go1.17.1
1.17.12
1
skylenet/ethereum-testnet-homepage:latest8698903e379f
stdlib@go1.17.2
1.17.12
1
slagattollas/weatherservice-practica:latest68e7f56393fc
stdlib@go1.15.6
1.17.12
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.