StackRadar

CVE-2022-28946

High

Advisory

Published 20 May 2022In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.010
61st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 1
affected package

Out of bounds memory access in github.com/open-policy-agent/opa

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
github.com/open-policy-agent/opagolangv0.0.0-20230321113606-0ffef53acc0a, v0.0.0-20230606071249-947d65b372ee, v0.24.0, v0.25.2+1 more0.40.08
OSV records
GHSA-x7f3-62pm-9p38
Also known as
GO-2022-0587

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2022-28946.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
github.com/open-policy-agent/opa@v0.25.2
0.40.0

Open the chart page →

5,202
kovecmacraeVerified publisher0.2.01 of 1See more

kove cmacrae 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-28946.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
github.com/open-policy-agent/opa@v0.25.2
0.40.0

Open the chart page →

2,089
kove-deprecationscmacraeVerified publisher0.1.21 of 1See more

kove-deprecations cmacrae 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-28946.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
github.com/open-policy-agent/opa@v0.25.2
0.40.0

Open the chart page →

2,203
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2022-28946.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
github.com/open-policy-agent/opa@v0.0.0-20230321113606-0ffef53acc0a
0.40.0

Open the chart page →

7,862
gatekeepermesosphere0.6.111 of 2See more

gatekeeper mesosphere 0.6.11

1 of the 2 container images this version deploys carry CVE-2022-28946.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
github.com/open-policy-agent/opa@v0.24.0
0.40.0

Open the chart page →

3,034
gatekeepermesosphere-stable0.6.111 of 2See more

gatekeeper mesosphere-stable 0.6.11

1 of the 2 container images this version deploys carry CVE-2022-28946.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
github.com/open-policy-agent/opa@v0.24.0
0.40.0

Open the chart page →

3,034
opa-nginxopa-nginx0.0.31 of 2See more

opa-nginx opa-nginx 0.0.3

1 of the 2 container images this version deploys carry CVE-2022-28946.

Container imageDigestPackageFixed in
openpolicyagent/opa:0.53.16a58dea59933
github.com/open-policy-agent/opa@v0.0.0-20230606071249-947d65b372ee
0.40.0

Open the chart page →

2,167
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2022-28946.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/open-policy-agent/opa@v0.25.2
0.40.0

Open the chart page →

29,227
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2022-28946.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
github.com/open-policy-agent/opa@v0.39.0
0.40.0

Open the chart page →

1,827

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
github.com/open-policy-agent/opa@v0.24.0
0.40.0
2
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
github.com/open-policy-agent/opa@v0.25.2
0.40.0
1
aquasec/starboard-operator:0.15.4be34f709e1ce
github.com/open-policy-agent/opa@v0.39.0
0.40.0
1
openpolicyagent/opa:0.53.16a58dea59933
github.com/open-policy-agent/opa@v0.0.0-20230606071249-947d65b372ee
0.40.0
1
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
github.com/open-policy-agent/opa@v0.25.2
0.40.0
1
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
github.com/open-policy-agent/opa@v0.25.2
0.40.0
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
github.com/open-policy-agent/opa@v0.0.0-20230321113606-0ffef53acc0a
0.40.0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/open-policy-agent/opa@v0.25.2
0.40.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.