StackRadar

CVE-2022-28131

Unscored

Advisory

Published 20 Jul 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,159
of 17,787 indexed, latest versions
Container images
1,218
deployed by those charts
Fix available
1 of 1
affected package

Stack exhaustion from deeply nested XML documents in encoding/xml

Carried by container images the latest versions of 1,159 of 17,787 indexed charts deploy, on 1,218 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+73 more1.17.121,218
OSV records
GO-2022-0521
Also known as
BIT-golang-2022-28131

Charts affected

1,159 by stars
ChartLatestAffected imagesRadar Score
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
stdlib@go1.16.10
1.17.12

Open the chart page →

2,435
operatorrookout0.0.201 of 2See more

operator rookout 0.0.20

1 of the 2 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
rookout/k8s-operator:latest0d083f3ef1a7
stdlib@go1.15.15
1.17.12

Open the chart page →

2,209
routehub-serverroutehub-helm1.0.11 of 3See more

routehub-server routehub-helm 1.0.1

1 of the 3 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
stdlib@go1.16.7
1.17.12

Open the chart page →

6,940
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.17.12

Open the chart page →

4,612
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
stdlib@go1.17.8
1.17.12

Open the chart page →

2,300
caddysagikazarmarkVerified publisher0.0.141 of 1See more

caddy sagikazarmark 0.0.14

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/caddy:2.4.5874405536b3e
stdlib@go1.17
1.17.12

Open the chart page →

2,960
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-email-service:v0.1.0-nativecf28472bc460
stdlib@go1.17.11
1.17.12

Open the chart page →

16,159
fmtok8s-email-servicesalaboy0.2.01 of 1See more

fmtok8s-email-service salaboy 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-email-service:v0.2.0-nativeb52d5dbac2ca
stdlib@go1.17.11
1.17.12

Open the chart page →

2,896
hellowsamarthya2.0.01 of 1See more

hellow samarthya 2.0.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
samarthya/spinnaker:v1.0ef06d81036af
stdlib@go1.17.6
1.17.12

Open the chart page →

2,121
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
stdlib@go1.18.2
1.17.12

Open the chart page →

11,314
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
stdlib@go1.18.1
1.17.12

Open the chart page →

4,744
mongodbsb-helm-charts0.4.01 of 1See more

mongodb sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mongo:7.0.140032d2ca20db
stdlib@go1.18.2
1.17.12

Open the chart page →

4,095
mysqlsb-helm-charts0.4.01 of 1See more

mysql sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mysql:8.4.3106d5197fd8e
stdlib@go1.18.2
1.17.12

Open the chart page →

1,096
redissb-helm-charts0.4.01 of 1See more

redis sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/redis:7.4.1-alpinec1e88455c852
stdlib@go1.18.2
1.17.12

Open the chart page →

1,324
ed-traefikscaleway-charts0.2.01 of 1See more

ed-traefik scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/traefik:v1.7.345d47b7bb2546
stdlib@go1.16.12
1.17.12

Open the chart page →

2,133
ed-traefik2scaleway-charts0.2.01 of 1See more

ed-traefik2 scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/traefik:2.5.62f603f8d3abe
stdlib@go1.17.5
1.17.12

Open the chart page →

3,160
scalyr-k8snode-managerscalyr-k8snode-managerVerified publisher0.1.71 of 1See more

scalyr-k8snode-manager scalyr-k8snode-manager 0.1.7

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
stdlib@go1.18.1
1.17.12

Open the chart page →

2,150
cosischichtelVerified publisher0.1.01 of 1See more

cosi schichtel 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/objectstorage-controller:v20221027-v0.1.1-8-g300019fa84b574e8027
stdlib@go1.18.3
1.17.12

Open the chart page →

1,309
satisfactoryschichtelVerified publisher0.3.31 of 1See more

satisfactory schichtel 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.9464d11e36e10
stdlib@go1.18.1
1.17.12

Open the chart page →

3,564
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
stdlib@go1.17
1.17.12

Open the chart page →

5,582
icinga2-masterschmitzis0.2.01 of 6See more

icinga2-master schmitzis 0.2.0

1 of the 6 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
grafana/grafana:8.0.3696823fbc561
stdlib@go1.16.1
1.17.12

Open the chart page →

3,731
version-checkerschmitzis0.2.21 of 1See more

version-checker schmitzis 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
stdlib@go1.15.2
1.17.12

Open the chart page →

3,023
openldapschoolguys-helmcharts0.1.31 of 1See more

openldap schoolguys-helmcharts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.17.12

Open the chart page →

3,313
satisfactory-serverschoolguys-helmcharts0.1.81 of 1See more

satisfactory-server schoolguys-helmcharts 0.1.8

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
stdlib@go1.18.1
1.17.12

Open the chart page →

3,466
cernboxsciencebox0.0.41 of 6See more

cernbox sciencebox 0.0.4

1 of the 6 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
cs3org/revad:v1.19.03b57a34a7dfd
stdlib@go1.17.3
1.17.12

Open the chart page →

2,330
ldap-instance-configsciencebox0.0.11 of 1See more

ldap-instance-config sciencebox 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.17.12

Open the chart page →

3,313
centralbrainsciencemeshVerified publisher0.0.34 of 5See more

centralbrain sciencemesh 0.0.3

4 of the 5 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
grafana/grafana:7.3.315b977f5207d
stdlib@go1.15.1
1.17.12
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.17.12
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.17.12
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
stdlib@go1.15.3
1.17.12

Open the chart page →

9,754
searchpesearchpe4.1.01 of 2See more

searchpe searchpe 4.1.0

1 of the 2 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/postgres:13.703652c675ae1
stdlib@go1.16.7
1.17.12

Open the chart page →

2,637
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mysql:9.0.192dc86967801
stdlib@go1.18.2
1.17.12

Open the chart page →

5,499
aws-secretssecretsprovider0.1.01 of 1See more

aws-secrets secretsprovider 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Open the chart page →

2,213
cloudflaredsectionmeVerified publisher2022.3.41 of 1See more

cloudflared sectionme 2022.3.4

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
stdlib@go1.17.1
1.17.12

Open the chart page →

2,407
influxdb_exportersectionmeVerified publisher0.0.21 of 1See more

influxdb_exporter sectionme 0.0.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/prometheus/influxdb-exporter:v0.10.03854d8af7bd4
stdlib@go1.18.3
1.17.12

Open the chart page →

922
seldon-core-analyticsseldon1.17.14 of 8See more

seldon-core-analytics seldon 1.17.1

4 of the 8 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.17.12
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.17.12
prom/prometheus:v2.18.15880ec936055
stdlib@go1.14.2
1.17.12
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.17.12

Open the chart page →

10,733
backendsignalen4.24.02 of 4See more

backend signalen 4.24.0

2 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.17.12
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
stdlib@go1.16.7
1.17.12

Open the chart page →

10,972
alertmanagersignoz0.5.21 of 1See more

alertmanager signoz 0.5.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
signoz/alertmanager:0.5.07bc7de2e33c2
stdlib@go1.14
1.17.12

Open the chart page →

2,181
trilliansigstoreVerified publisher0.3.201 of 5See more

trillian sigstore 0.3.20

1 of the 5 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.17.12

Open the chart page →

2,739
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
stdlib@go1.17.6
1.17.12

Open the chart page →

2,381
config-connector-templaterslamdev0.0.51 of 1See more

config-connector-templater slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
slamdev/config-connector-templater:0.0.3a234541c9fa8
stdlib@go1.16.5
1.17.12

Open the chart page →

2,110
flux-notifierslamdev0.0.71 of 1See more

flux-notifier slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
slamdev/flux-notifier:v0.0.8b173d809132d
stdlib@go1.13.11
1.17.12

Open the chart page →

2,015
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
stdlib@go1.17.9
1.17.12

Open the chart page →

9,235
gke-preemptible-notifierslamdev0.0.61 of 1See more

gke-preemptible-notifier slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
stdlib@go1.13.11
1.17.12

Open the chart page →

2,860
octavia-ingress-controllerslamdev0.0.71 of 1See more

octavia-ingress-controller slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
stdlib@go1.15
1.17.12

Open the chart page →

2,761
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
stdlib@go1.13.5
1.17.12

Open the chart page →

8,697
oi-slurm-cluster-chartslurm-cluster-chart0.25.11 of 4See more

oi-slurm-cluster-chart slurm-cluster-chart 0.25.1

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.17.12

Open the chart page →

4,376
slurm-cluster-chartslurm-cluster-chart0.25.01 of 4See more

slurm-cluster-chart slurm-cluster-chart 0.25.0

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.17.12

Open the chart page →

4,376
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
helga09/my_sql_shoes:v1.1.1a03657d97897
stdlib@go1.18.2
1.17.12

Open the chart page →

7,586
csi-gcs-softonic-factorysoftonic0.9.31 of 4See more

csi-gcs-softonic-factory softonic 0.9.3

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ofekmeister/csi-gcs:v0.9.030d70fa9211b
stdlib@go1.18.2
1.17.12

Open the chart page →

1,842
hello-world-appsoftonic1.2.21 of 1See more

hello-world-app softonic 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/giantswarm/helloworld:0.2.07a07ee730305
stdlib@go1.16.7
1.17.12

Open the chart page →

1,957
pod-defaultersoftonic0.1.31 of 1See more

pod-defaulter softonic 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
softonic/pod-defaulter:0.1.072017aed5902
stdlib@go1.14.9
1.17.12

Open the chart page →

2,561
preemptible-killersoftonic1.2.61 of 1See more

preemptible-killer softonic 1.2.6

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
softonic/preemptible-killer:1.2.6-294b87f1fb362
stdlib@go1.14.10
1.17.12

Open the chart page →

2,338

Container images carrying it

1,218 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
slamdev/config-connector-templater:0.0.3a234541c9fa8
stdlib@go1.16.5
1.17.12
1
slamdev/external-secrets-operator:0.0.8855f6625dda4
stdlib@go1.13.15
1.17.12
1
slamdev/flux-notifier:v0.0.8b173d809132d
stdlib@go1.13.11
1.17.12
1
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
stdlib@go1.13.11
1.17.12
1
smailkoz/torrserver:1.0.1117b52d15de8f0
stdlib@go1.17.5
1.17.12
1
softonic/node-policy-webhook:0.1.2ab6098c04a53
stdlib@go1.14.6
1.17.12
1
softonic/pod-defaulter:0.1.072017aed5902
stdlib@go1.14.9
1.17.12
1
softonic/preemptible-killer:1.2.6-294b87f1fb362
stdlib@go1.14.10
1.17.12
1
softonic/rate-limit-operator:0.1.1910f6de37763
stdlib@go1.13.15
1.17.12
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
stdlib@go1.18.2
1.17.12
1
sophos/nginx-vts-exporter:latestf1073556b29b
stdlib@go1.13.6
1.17.12
1
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
stdlib@go1.13.8
1.17.12
1
springhack/frpc_ingress:latest4aceb821da88
stdlib@go1.17.2
1.17.12
1
sstarcher/ecr-cleaner:0.1.12d43c390cb19
stdlib@go1.14.2
1.17.12
1
sstarcher/helm-exporter:0.5.011769d01ba35
stdlib@go1.13.6
1.17.12
1
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
stdlib@go1.13.9
1.17.12
1
stakater/gitwebhookproxy:v0.2.79c1226e5270cd
stdlib@go1.13.1
1.17.12
1
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
stdlib@go1.17.8
1.17.12
1
stakater/tronador:v0.0.137ce9acf2722
stdlib@go1.15.11
1.17.12
1
stakater/whitelister:v0.0.1639107924063e
stdlib@go1.13.1
1.17.12
1
stakater/workshop-operator:v0.0.3897bf456cc97c
stdlib@go1.16.13
1.17.12
1
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
stdlib@go1.18.3
1.17.12
1
stakkato95/twitter-service-graphql:0.1.13cbe857234f2
stdlib@go1.18.3
1.17.12
1
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
stdlib@go1.18.3
1.17.12
1
stakkato95/twitter-service-users:0.1.1456049efee9a
stdlib@go1.18.3
1.17.12
1
stashapp/stash:latest24dbd7607174
stdlib@go1.13.15
1.17.12
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
stdlib@go1.15.6
1.17.12
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
stdlib@go1.13.4
1.17.12
1
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
stdlib@go1.17.11
1.17.12
1
subspacecommunity/subspace:1.5.0e2042b63fb35
stdlib@go1.14.6
1.17.12
1
superorbital/cludod:0.0.2-alphad59732f61d6e
stdlib@go1.17.6
1.17.12
1
surajwarbhe/grafana:v185248611e9f1
stdlib@go1.14.3
1.17.12
1
syncthing/syncthing:1.18.2966433161272
stdlib@go1.17
1.17.12
1
t3nde/tideways:1.7.2777e008f764db
stdlib@go1.16.4
1.17.12
1
tdengine/tdengine:3.0.2.24140a4021ddb
stdlib@go1.17.6
1.17.12
1
temporalio/admin-tools:1.15.135034611d981
stdlib@go1.17.6
1.17.12
1
temporalio/server:1.15.1e26758f5a1bf
stdlib@go1.17.6
1.17.12
1
thanosio/thanos:v0.19.088276fcd1491
stdlib@go1.15.10
1.17.12
1
thanosio/thanos:v0.15.0b12d5c31bf5a
stdlib@go1.14.2
1.17.12
1
thecampagnards/trafficlight-api:main7dca9d973837
stdlib@go1.16.4
1.17.12
1
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
stdlib@go1.17.1
1.17.12
1
thomseddon/traefik-forward-auth:269a2c985d2c5
stdlib@go1.13.12
1.17.12
1
thomseddon/traefik-forward-auth:latestb364aa6a4117
stdlib@go1.13.15
1.17.12
1
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
stdlib@go1.13.12
1.17.12
1
timescale/timescaledb-ha:pg16d7db8f1085a3
stdlib@go1.18.1
1.17.12
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
stdlib@go1.18.1
1.17.12
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
stdlib@go1.15.6
1.17.12
1
timescale/timescaledb-postgis:latest-pg127758704d4a14
stdlib@go1.14
1.17.12
1
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
stdlib@go1.13.5
1.17.12
1
tobiasbp/db-backup:0.0.314bee6e33a26
stdlib@go1.13.10
1.17.12
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.