StackRadar

CVE-2022-2879

Unscored

Advisory

Published 6 Oct 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.017
75th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,282
of 17,787 indexed, latest versions
Container images
1,393
deployed by those charts
Fix available
1 of 1
affected package

Unbounded memory consumption when reading headers in archive/tar

Carried by container images the latest versions of 1,282 of 17,787 indexed charts deploy, on 1,393 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+81 more1.18.71,393
OSV records
GO-2022-1037
Also known as
BIT-golang-2022-2879

Charts affected

1,282 by stars
ChartLatestAffected imagesRadar Score
eoloplanthttpd-eoloplant0.1.02 of 7See more

eoloplant httpd-eoloplant 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.18.7
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.18.7

Open the chart page →

32,336
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
stdlib@go1.16.9
1.18.7

Open the chart page →

16,482
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
stdlib@go1.16.9
1.18.7

Open the chart page →

20,727
tdenginehuangchengwu-helm-chart3.0.21 of 1See more

tdengine huangchengwu-helm-chart 3.0.2

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
tdengine/tdengine:3.0.2.24140a4021ddb
stdlib@go1.17.6
1.18.7

Open the chart page →

3,753
mocktailhuseyinnurbaki0.2.11 of 1See more

mocktail huseyinnurbaki 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
hhaluk/mocktail:2.0.3350d19360038
stdlib@go1.17.7
1.18.7

Open the chart page →

1,606
vcbackendi4trustVerified publisher0.0.81 of 1See more

vcbackend i4trust 0.0.8

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
wistefan/vcbackend:0.0.13bd436164b51
stdlib@go1.18.3
1.18.7

Open the chart page →

1,848
stoloniamalryz0.10.01 of 2See more

stolon iamalryz 0.10.0

1 of the 2 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
stdlib@go1.13.8
1.18.7

Open the chart page →

4,045
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
library/mysql:8.0.41bf577825b52a
stdlib@go1.18.2
1.18.7

Open the chart page →

5,770
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.18.7

Open the chart page →

57,728
eoloserverihuertas2021-vmartinp2021-helm0.1.02 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.18.7
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.18.7

Open the chart page →

27,812
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
stdlib@go1.17.3
1.18.7

Open the chart page →

37,844
chronografinfluxdata1.2.61 of 1See more

chronograf influxdata 1.2.6

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
library/chronograf:1.9.496d8a3f65a4f
stdlib@go1.16.4
1.18.7

Open the chart page →

2,198
l2gethinfradao0.0.11 of 1See more

l2geth infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
ethereumoptimism/l2geth:0.5.315577036dc36d
stdlib@go1.18
1.18.7

Open the chart page →

2,659
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
stdlib@go1.15.7
1.18.7

Open the chart page →

10,542
lakefsinseefrlab0.0.61 of 2See more

lakefs inseefrlab 0.0.6

1 of the 2 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
treeverse/lakefs:0.69.0478f37a6cffc
stdlib@go1.17.8
1.18.7

Open the chart page →

2,645
instemmingserviceinstemmingservice1.0.01 of 3See more

instemmingservice instemmingservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
stdlib@go1.13.10
1.18.7

Open the chart page →

7,510
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization:3.03426deb77337
stdlib@go1.17.11
1.18.7

Open the chart page →

11,123
gravity-initinvisiblVerified publisher1.0.91 of 1See more

gravity-init invisibl 1.0.9

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
invisibl/gravity-init:v1.0.91a970f84178b
stdlib@go1.17.12
1.18.7

Open the chart page →

2,006
identity-managerinvisiblVerified publisher1.0.01 of 1See more

identity-manager invisibl 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
invisibl/identity-manager:1.0.01029f4fe20eb
stdlib@go1.17.11
1.18.7

Open the chart page →

2,162
inlets-clientjacobcolvinVerified publisher0.1.21 of 1See more

inlets-client jacobcolvin 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
stdlib@go1.13.15
1.18.7

Open the chart page →

1,753
inlets-serverjacobcolvinVerified publisher0.1.11 of 1See more

inlets-server jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
stdlib@go1.13.15
1.18.7

Open the chart page →

1,753
wakatime-exporterjacobcolvinVerified publisher0.1.11 of 1See more

wakatime-exporter jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
macropower/wakatime-exporter:0.1.0dbb05debb785
stdlib@go1.14.6
1.18.7

Open the chart page →

1,313
koptimizejaconiVerified publisher0.5.41 of 2See more

koptimize jaconi 0.5.4

1 of the 2 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
alpine/k8s:1.27.321b24e6bf801
stdlib@go1.19
1.18.7

Open the chart page →

5,716
javascriptweeklyjavascriptweekly2.1.01 of 1See more

javascriptweekly javascriptweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
zufardhiyaulhaq/javascriptweekly:v2.1.086424bd0b2a4
stdlib@go1.17.13
1.18.7

Open the chart page →

1,237
jx-app-athensjenkins-x0.0.181 of 1See more

jx-app-athens jenkins-x 0.0.18

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
gomods/athens:v0.8.1d714c7ff0231
stdlib@go1.13.4
1.18.7

Open the chart page →

4,225
jx-app-flaggerjenkins-x0.0.52 of 2See more

jx-app-flagger jenkins-x 0.0.5

2 of the 2 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
grafana/grafana:6.5.1befcd84da2c1
stdlib@go1.13.1
1.18.7
weaveworks/flagger:1.0.0-rc.5174307de1b36
stdlib@go1.14.2
1.18.7

Open the chart page →

6,028
knative-servingjenkins-x0.19.124 of 4See more

knative-serving jenkins-x 0.19.12

4 of the 4 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned1e3db4f2eeed
stdlib@go1.14.10
1.18.7
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinneddb6ceff2aab4
stdlib@go1.14.10
1.18.7
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedb2cd45b8a8a4
stdlib@go1.14.10
1.18.7
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedd27b4495ccc3
stdlib@go1.14.10
1.18.7

Open the chart page →

9,699
ingress-nginxjfrog4.5.21 of 2See more

ingress-nginx jfrog 4.5.2

1 of the 2 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.18.7

Open the chart page →

3,798
alpine-torjfwenischVerified publisher1.1.01 of 1See more

alpine-tor jfwenisch 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
jfwenisch/alpine-tor:latest9e6c229f953c
stdlib@go1.14.6
1.18.7

Open the chart page →

4,461
kafka-offset-lag-for-prometheusjhidalgo3-githubVerified publisher2.3.01 of 1See more

kafka-offset-lag-for-prometheus jhidalgo3-github 2.3.0

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
stdlib@go1.17.13
1.18.7

Open the chart page →

1,470
missing-container-metricsjimdo-missing-container-metrics0.5.01 of 1See more

missing-container-metrics jimdo-missing-container-metrics 0.5.0

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
stdlib@go1.16.2
1.18.7

Open the chart page →

2,409
haven-complinacy-dashboardjolle-devVerified publisher1.0.01 of 2See more

haven-complinacy-dashboard jolle-dev 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
stdlib@go1.17.2
1.18.7

Open the chart page →

3,841
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
stdlib@go1.18.2
1.18.7

Open the chart page →

16,626
firstchartjuanjmerono0.2.01 of 1See more

firstchart juanjmerono 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
jmalloc/echo-server:0.3.1e4eaee2c7998
stdlib@go1.17
1.18.7

Open the chart page →

1,443
alertmanager-irc-relayjuppi880.0.11 of 1See more

alertmanager-irc-relay juppi88 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
maldridge/alertmanager-irc-relay:v0.4.1391de2b76128
stdlib@go1.16.4
1.18.7

Open the chart page →

1,615
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
stdlib@go1.18.1
1.18.7

Open the chart page →

6,136
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
alpine/k8s:1.22.600ac10bcb759
stdlib@go1.17.6
1.18.7

Open the chart page →

14,833
k8s-pausek8s-pause0.1.41 of 1See more

k8s-pause k8s-pause 0.1.4

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
stdlib@go1.17.8
1.18.7

Open the chart page →

1,846
k8svault-controllerk8svault-controller0.1.21 of 1See more

k8svault-controller k8svault-controller 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
stdlib@go1.16.15
1.18.7

Open the chart page →

1,885
postgresqlkagiso-me0.4.01 of 1See more

postgresql kagiso-me 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.18.7

Open the chart page →

1,488
rediskagiso-me0.1.61 of 1See more

redis kagiso-me 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.18.7

Open the chart page →

1,288
kestra-starterkestraOfficialVerified publisher2.0.11 of 5See more

kestra-starter kestra 2.0.1

1 of the 5 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.18.7

Open the chart page →

5,469
keycloak-operator-legacykeycloak-operator-legacy1.0.01 of 1See more

keycloak-operator-legacy keycloak-operator-legacy 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
stdlib@go1.13.8
1.18.7

Open the chart page →

5,066
csi-driver-nfskeyporttech0.1.41 of 2See more

csi-driver-nfs keyporttech 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
stdlib@go1.14.2
1.18.7

Open the chart page →

3,357
gogskeyporttech0.1.31 of 3See more

gogs keyporttech 0.1.3

1 of the 3 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
gogs/gogs:0.12.30195b095d0b2
stdlib@go1.14.7
1.18.7

Open the chart page →

3,523
helm-mongodb-operatorkeyporttech0.1.01 of 1See more

helm-mongodb-operator keyporttech 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
stdlib@go1.13.15
1.18.7

Open the chart page →

8,816
dex-k8s-authenticatorkfirfer0.0.31 of 1See more

dex-k8s-authenticator kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
stdlib@go1.13.11
1.18.7

Open the chart page →

2,791
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
stdlib@go1.17.1
1.18.7

Open the chart page →

6,446
scriptskfirfer0.1.361 of 1See more

scripts kfirfer 0.1.36

1 of the 1 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
kfirfer/scripts:0.0.2481e5c4e5d70e
stdlib@go1.17.10
1.18.7

Open the chart page →

2,320
kiaekiae0.1.63 of 9See more

kiae kiae 0.1.6

3 of the 9 container images this version deploys carry CVE-2022-2879.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.18.7
grafana/promtail:2.6.1072527b12cdf
stdlib@go1.17.9
1.18.7
ghcr.io/dexidp/dex:v2.35.313964b29d63e
stdlib@go1.19.1
1.18.7

Open the chart page →

19,208

Container images carrying it

1,393 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/mariadb:10.10.2bfc25a68e113
stdlib@go1.16.7
1.18.7
1
library/mariadb:10.6.15e22328f4d714
stdlib@go1.16.7
1.18.7
1
library/mariadb:10.9.4fbb8456ebdb1
stdlib@go1.16.7
1.18.7
1
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.18.7
1
library/mongo:7.0.140032d2ca20db
stdlib@go1.18.2
1.18.7
1
library/mongo:4.4.1305678ae4e5e1
stdlib@go1.16.7
1.18.7
1
library/mongo:4.4-bionic3d0e6df9fd5b
stdlib@go1.16.3
1.18.7
1
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.18.7
1
library/mongo:6.0.12646902910d6a
stdlib@go1.18.2
1.18.7
1
library/mongo:4.2699d652ed674
stdlib@go1.18.2
1.18.7
1
library/mongo:6.0.271a63fc2438e
stdlib@go1.17.10
1.18.7
1
library/mongo:5.0.217c81758cb295
stdlib@go1.18.2
1.18.7
1
library/mongo:7.0.12ae1cf99fa7bf
stdlib@go1.18.2
1.18.7
1
library/mongo:4.4.18d23ec07162ca
stdlib@go1.17.10
1.18.7
1
library/mongo:8.0.11dca8d11fe467
stdlib@go1.18.2
1.18.7
1
library/mysql:8.4.3106d5197fd8e
stdlib@go1.18.2
1.18.7
1
library/mysql:8.0.303c1aab708f6e
stdlib@go1.16.7
1.18.7
1
library/mysql:9.0.192dc86967801
stdlib@go1.18.2
1.18.7
1
library/mysql:8.0.41bf577825b52a
stdlib@go1.18.2
1.18.7
1
library/mysql:8.0.39ccb8f749bb5e
stdlib@go1.18.2
1.18.7
1
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.18.7
1
library/postgres:13.703652c675ae1
stdlib@go1.16.7
1.18.7
1
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.18.7
1
library/postgres:17.4304ab8135187
stdlib@go1.18.2
1.18.7
1
library/postgres:16.6557fea37a744
stdlib@go1.18.2
1.18.7
1
library/postgres:16.4-alpine5660c2cbfea5
stdlib@go1.18.2
1.18.7
1
library/postgres:13.11-bullseye5c265bf1fd30
stdlib@go1.18.2
1.18.7
1
library/postgres:17.5-alpine6567bca8d7bc
stdlib@go1.18.2
1.18.7
1
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.18.7
1
library/postgres:12-alpine7c8f48705831
stdlib@go1.18.2
1.18.7
1
library/postgres:17.2-alpine7e5df973a748
stdlib@go1.18.2
1.18.7
1
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.18.7
1
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.18.7
1
library/postgres:13.12ced3ba927f4c
stdlib@go1.18.2
1.18.7
1
library/postgres:14.6f565573d74ae
stdlib@go1.18.2
1.18.7
1
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.18.7
1
library/redis:7.0.4091a7b5de688
stdlib@go1.16.7
1.18.7
1
library/redis:7-bullseye6a5130174e14
stdlib@go1.18.2
1.18.7
1
library/redis:7.2.5-alpine6aaf3f5e6bc8
stdlib@go1.18.2
1.18.7
1
library/redis:6.2.20-alpine77697a75da9f
stdlib@go1.18.2
1.18.7
1
library/redis83edc2b8e9ff
stdlib@go1.18.2
1.18.7
1
library/redis:7.0.1092b8b307ee28
stdlib@go1.18.2
1.18.7
1
library/redis:7.4.1bb142a9c18ac
stdlib@go1.18.2
1.18.7
1
library/redis:7.4.1-alpinec1e88455c852
stdlib@go1.18.2
1.18.7
1
library/redis:7.0-alpinec9d92d840fd0
stdlib@go1.18.2
1.18.7
1
library/telegraf:1.20.428e98eece020
stdlib@go1.17.3
1.18.7
1
library/telegraf:1.19.0-alpine794079a7f241
stdlib@go1.16.5
1.18.7
1
library/telegraf:1.19-alpineaddb86c0c520
stdlib@go1.16.6
1.18.7
1
library/traefik:2.5.62f603f8d3abe
stdlib@go1.17.5
1.18.7
1
library/traefik:v1.7.345d47b7bb2546
stdlib@go1.16.12
1.18.7
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.