StackRadar

CVE-2022-28131

Unscored

Advisory

Published 20 Jul 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.023
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,159
of 17,787 indexed, latest versions
Container images
1,218
deployed by those charts
Fix available
1 of 1
affected package

Stack exhaustion from deeply nested XML documents in encoding/xml

Carried by container images the latest versions of 1,159 of 17,787 indexed charts deploy, on 1,218 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+73 more1.17.121,218
OSV records
GO-2022-0521
Also known as
BIT-golang-2022-28131

Charts affected

1,159 by stars
ChartLatestAffected imagesRadar Score
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
stdlib@go1.16.10
1.17.12

Open the chart page →

2,435
operatorrookout0.0.201 of 2See more

operator rookout 0.0.20

1 of the 2 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
rookout/k8s-operator:latest0d083f3ef1a7
stdlib@go1.15.15
1.17.12

Open the chart page →

2,209
routehub-serverroutehub-helm1.0.11 of 3See more

routehub-server routehub-helm 1.0.1

1 of the 3 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
stdlib@go1.16.7
1.17.12

Open the chart page →

6,940
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/redis:7.2.4-alpinec8bb255c3559
stdlib@go1.18.2
1.17.12

Open the chart page →

4,612
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
stdlib@go1.17.8
1.17.12

Open the chart page →

2,300
caddysagikazarmarkVerified publisher0.0.141 of 1See more

caddy sagikazarmark 0.0.14

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/caddy:2.4.5874405536b3e
stdlib@go1.17
1.17.12

Open the chart page →

2,960
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-email-service:v0.1.0-nativecf28472bc460
stdlib@go1.17.11
1.17.12

Open the chart page →

16,159
fmtok8s-email-servicesalaboy0.2.01 of 1See more

fmtok8s-email-service salaboy 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-email-service:v0.2.0-nativeb52d5dbac2ca
stdlib@go1.17.11
1.17.12

Open the chart page →

2,896
hellowsamarthya2.0.01 of 1See more

hellow samarthya 2.0.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
samarthya/spinnaker:v1.0ef06d81036af
stdlib@go1.17.6
1.17.12

Open the chart page →

2,121
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
stdlib@go1.18.2
1.17.12

Open the chart page →

11,314
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
stdlib@go1.18.1
1.17.12

Open the chart page →

4,744
mongodbsb-helm-charts0.4.01 of 1See more

mongodb sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mongo:7.0.140032d2ca20db
stdlib@go1.18.2
1.17.12

Open the chart page →

4,095
mysqlsb-helm-charts0.4.01 of 1See more

mysql sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mysql:8.4.3106d5197fd8e
stdlib@go1.18.2
1.17.12

Open the chart page →

1,096
redissb-helm-charts0.4.01 of 1See more

redis sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/redis:7.4.1-alpinec1e88455c852
stdlib@go1.18.2
1.17.12

Open the chart page →

1,324
ed-traefikscaleway-charts0.2.01 of 1See more

ed-traefik scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/traefik:v1.7.345d47b7bb2546
stdlib@go1.16.12
1.17.12

Open the chart page →

2,133
ed-traefik2scaleway-charts0.2.01 of 1See more

ed-traefik2 scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/traefik:2.5.62f603f8d3abe
stdlib@go1.17.5
1.17.12

Open the chart page →

3,160
scalyr-k8snode-managerscalyr-k8snode-managerVerified publisher0.1.71 of 1See more

scalyr-k8snode-manager scalyr-k8snode-manager 0.1.7

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
stdlib@go1.18.1
1.17.12

Open the chart page →

2,150
cosischichtelVerified publisher0.1.01 of 1See more

cosi schichtel 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/objectstorage-controller:v20221027-v0.1.1-8-g300019fa84b574e8027
stdlib@go1.18.3
1.17.12

Open the chart page →

1,309
satisfactoryschichtelVerified publisher0.3.31 of 1See more

satisfactory schichtel 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.9464d11e36e10
stdlib@go1.18.1
1.17.12

Open the chart page →

3,564
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
stdlib@go1.17
1.17.12

Open the chart page →

5,582
icinga2-masterschmitzis0.2.01 of 6See more

icinga2-master schmitzis 0.2.0

1 of the 6 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
grafana/grafana:8.0.3696823fbc561
stdlib@go1.16.1
1.17.12

Open the chart page →

3,731
version-checkerschmitzis0.2.21 of 1See more

version-checker schmitzis 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
stdlib@go1.15.2
1.17.12

Open the chart page →

3,023
openldapschoolguys-helmcharts0.1.31 of 1See more

openldap schoolguys-helmcharts 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.17.12

Open the chart page →

3,313
satisfactory-serverschoolguys-helmcharts0.1.81 of 1See more

satisfactory-server schoolguys-helmcharts 0.1.8

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
stdlib@go1.18.1
1.17.12

Open the chart page →

3,466
cernboxsciencebox0.0.41 of 6See more

cernbox sciencebox 0.0.4

1 of the 6 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
cs3org/revad:v1.19.03b57a34a7dfd
stdlib@go1.17.3
1.17.12

Open the chart page →

2,330
ldap-instance-configsciencebox0.0.11 of 1See more

ldap-instance-config sciencebox 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.17.12

Open the chart page →

3,313
centralbrainsciencemeshVerified publisher0.0.34 of 5See more

centralbrain sciencemesh 0.0.3

4 of the 5 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
grafana/grafana:7.3.315b977f5207d
stdlib@go1.15.1
1.17.12
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.17.12
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.17.12
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
stdlib@go1.15.3
1.17.12

Open the chart page →

9,754
searchpesearchpe4.1.01 of 2See more

searchpe searchpe 4.1.0

1 of the 2 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/postgres:13.703652c675ae1
stdlib@go1.16.7
1.17.12

Open the chart page →

2,637
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mysql:9.0.192dc86967801
stdlib@go1.18.2
1.17.12

Open the chart page →

5,499
aws-secretssecretsprovider0.1.01 of 1See more

aws-secrets secretsprovider 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Open the chart page →

2,213
cloudflaredsectionmeVerified publisher2022.3.41 of 1See more

cloudflared sectionme 2022.3.4

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
stdlib@go1.17.1
1.17.12

Open the chart page →

2,407
influxdb_exportersectionmeVerified publisher0.0.21 of 1See more

influxdb_exporter sectionme 0.0.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/prometheus/influxdb-exporter:v0.10.03854d8af7bd4
stdlib@go1.18.3
1.17.12

Open the chart page →

922
seldon-core-analyticsseldon1.17.14 of 8See more

seldon-core-analytics seldon 1.17.1

4 of the 8 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.17.12
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.17.12
prom/prometheus:v2.18.15880ec936055
stdlib@go1.14.2
1.17.12
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.17.12

Open the chart page →

10,733
backendsignalen4.24.02 of 4See more

backend signalen 4.24.0

2 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.17.12
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
stdlib@go1.16.7
1.17.12

Open the chart page →

10,972
alertmanagersignoz0.5.21 of 1See more

alertmanager signoz 0.5.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
signoz/alertmanager:0.5.07bc7de2e33c2
stdlib@go1.14
1.17.12

Open the chart page →

2,181
trilliansigstoreVerified publisher0.3.201 of 5See more

trillian sigstore 0.3.20

1 of the 5 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.17.12

Open the chart page →

2,739
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
stdlib@go1.17.6
1.17.12

Open the chart page →

2,381
config-connector-templaterslamdev0.0.51 of 1See more

config-connector-templater slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
slamdev/config-connector-templater:0.0.3a234541c9fa8
stdlib@go1.16.5
1.17.12

Open the chart page →

2,110
flux-notifierslamdev0.0.71 of 1See more

flux-notifier slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
slamdev/flux-notifier:v0.0.8b173d809132d
stdlib@go1.13.11
1.17.12

Open the chart page →

2,015
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
stdlib@go1.17.9
1.17.12

Open the chart page →

9,235
gke-preemptible-notifierslamdev0.0.61 of 1See more

gke-preemptible-notifier slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
stdlib@go1.13.11
1.17.12

Open the chart page →

2,860
octavia-ingress-controllerslamdev0.0.71 of 1See more

octavia-ingress-controller slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
stdlib@go1.15
1.17.12

Open the chart page →

2,761
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
stdlib@go1.13.5
1.17.12

Open the chart page →

8,697
oi-slurm-cluster-chartslurm-cluster-chart0.25.11 of 4See more

oi-slurm-cluster-chart slurm-cluster-chart 0.25.1

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.17.12

Open the chart page →

4,376
slurm-cluster-chartslurm-cluster-chart0.25.01 of 4See more

slurm-cluster-chart slurm-cluster-chart 0.25.0

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.17.12

Open the chart page →

4,376
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
helga09/my_sql_shoes:v1.1.1a03657d97897
stdlib@go1.18.2
1.17.12

Open the chart page →

7,586
csi-gcs-softonic-factorysoftonic0.9.31 of 4See more

csi-gcs-softonic-factory softonic 0.9.3

1 of the 4 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
ofekmeister/csi-gcs:v0.9.030d70fa9211b
stdlib@go1.18.2
1.17.12

Open the chart page →

1,842
hello-world-appsoftonic1.2.21 of 1See more

hello-world-app softonic 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
quay.io/giantswarm/helloworld:0.2.07a07ee730305
stdlib@go1.16.7
1.17.12

Open the chart page →

1,957
pod-defaultersoftonic0.1.31 of 1See more

pod-defaulter softonic 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
softonic/pod-defaulter:0.1.072017aed5902
stdlib@go1.14.9
1.17.12

Open the chart page →

2,561
preemptible-killersoftonic1.2.61 of 1See more

preemptible-killer softonic 1.2.6

1 of the 1 container images this version deploys carry CVE-2022-28131.

Container imageDigestPackageFixed in
softonic/preemptible-killer:1.2.6-294b87f1fb362
stdlib@go1.14.10
1.17.12

Open the chart page →

2,338

Container images carrying it

1,218 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
stdlib@go1.18.1
1.17.12
1
cloudecho/hello:0.1.0f76ede067ab9
stdlib@go1.16.6
1.17.12
1
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
stdlib@go1.15.14
1.17.12
1
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
stdlib@go1.15.14
1.17.12
1
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
stdlib@go1.15.2
1.17.12
1
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
stdlib@go1.16.6
1.17.12
1
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
stdlib@go1.15.2
1.17.12
1
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
stdlib@go1.15.2
1.17.12
1
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.17.12
1
cmacrae/d2-prometheus-exporter:v0.1.0fc5fecba436e
stdlib@go1.15
1.17.12
1
cmacrae/lgtm:0.1.0dec8d490fe40
stdlib@go1.14.1
1.17.12
1
cockroachdb/cockroach-operator:v2.1.0983312754620
stdlib@go1.13.14
1.17.12
1
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.17.12
1
codercom/code-server:3.10.247605610ad8d
stdlib@go1.14.4
1.17.12
1
codeskyblue/gohttpserver:latestcaa862590e34
stdlib@go1.16.3
1.17.12
1
conduction/agendaservice-php:latest9cfeeb6c7c20
stdlib@go1.13.10
1.17.12
1
conduction/balance-registration-php:devc36094a41369
stdlib@go1.13.10
1.17.12
1
conduction/betaalservice-php:latestece1ab544c57
stdlib@go1.13.10
1.17.12
1
conduction/cgrc-php:dev25415534d245
stdlib@go1.13.10
1.17.12
1
conduction/checkin-component-php:dev3423845692c1
stdlib@go1.13.10
1.17.12
1
conduction/conduction-ui-php:dev2744565516e8
stdlib@go1.13.10
1.17.12
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
stdlib@go1.13.10
1.17.12
1
conduction/docparser-php:devb6f95c8ead7d
stdlib@go1.13.10
1.17.12
1
conduction/kvk-php:dev8f177f9f8a7b
stdlib@go1.13.10
1.17.12
1
conduction/pan-php:dev24f03c57568f
stdlib@go1.13.10
1.17.12
1
containous/maesh:v1.3.2587162516502
stdlib@go1.14.4
1.17.12
1
coredns/coredns:1.7.073ca82b4ce82
stdlib@go1.14.4
1.17.12
1
craftypath/sops-operator:v0.8.0402a0024c732
stdlib@go1.16.5
1.17.12
1
crossplane/crossplane:v0.12.066666e6963af
stdlib@go1.14.4
1.17.12
1
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
stdlib@go1.13.14
1.17.12
1
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
stdlib@go1.13.15
1.17.12
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
stdlib@go1.14.2
1.17.12
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
stdlib@go1.14.4
1.17.12
1
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
stdlib@go1.15
1.17.12
1
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
stdlib@go1.16.13
1.17.12
1
dabealu/zookeeper-exporter:latest86106fec315f
stdlib@go1.14.15
1.17.12
1
dalf/filtron:latestb19cbf5b2f37
stdlib@go1.18.2
1.17.12
1
dalf/morty:latest248a4849c350
stdlib@go1.18.2
1.17.12
1
dannielkil/book-db:latest433290c5c1db
stdlib@go1.18.2
1.17.12
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
stdlib@go1.16.9
1.17.12
1
datadog/agent:7.22.08f20e56b5311
stdlib@go1.13.11
1.17.12
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
stdlib@go1.15.15
1.17.12
1
datadog/operator:0.3.117f08a860090
stdlib@go1.15.2
1.17.12
1
datappeal/hive-metastore:lateste38c085a3567
stdlib@go1.13.4
1.17.12
1
datappeal/trino-exporter:latest325b91c2b09e
stdlib@go1.16.15
1.17.12
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
stdlib@go1.15
1.17.12
1
datawire/aes:1.13.62beb65062c8b
stdlib@go1.15
1.17.12
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
stdlib@go1.16.5
1.17.12
1
datawire/emissary:2.0.2-ea9716efbdd24b
stdlib@go1.15
1.17.12
1
ddosify/selfhosted_hammer:2.0.0181965edb12e
stdlib@go1.18.1
1.17.12
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.