StackRadar

CVE-2022-28948

High

Advisory

Published 20 May 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.040
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
376
of 17,781 indexed, latest versions
Container images
407
deployed by those charts
Fix available
1 of 1
affected package

gopkg.in/yaml.v3 Denial of Service

Carried by container images the latest versions of 376 of 17,781 indexed charts deploy, on 407 images.

Affected packageAffected versionsFixed inImages
gopkg.in/yaml.v3golangv3.0.0, v3.0.0-20190924164351-c8b7dadae555, v3.0.0-20191026110619-0b21df46bc1d, v3.0.0-20191120175047-4206685974f2+9 more3.0.1407
OSV records
GHSA-hp87-p4gw-j4gq
Also known as
GO-2022-0603

Charts affected

376 by stars
ChartLatestAffected imagesRadar Score
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

6,596
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

1,827
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
gopkg.in/yaml.v3@v3.0.0-20191120175047-4206685974f2
3.0.1

Open the chart page →

2,869
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

3,764
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

10,568
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

21,005
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ecadlabs/tezos_exporter:latest4bcbe5d1cdd2
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

5,321
monitoringthl-chartsVerified publisher0.1.14 of 10See more

monitoring thl-charts 0.1.1

4 of the 10 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
grafana/loki:2.5.0f9ef133793af
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
grafana/promtail:2.4.2626900031c4e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
quay.io/prometheus/prometheus:v2.34.0b37103e03399
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

18,908
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
gopkg.in/yaml.v3@v3.0.0-20200603094226-e3079894b1e8
3.0.1

Open the chart page →

8,484
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

6,132
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1

Open the chart page →

4,382
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

13,459
vineyard-operatorvineyardVerified publisher0.24.21 of 2See more

vineyard-operator vineyard 0.24.2

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

4,525
volantmqvolantmq0.1.21 of 1See more

volantmq volantmq 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
gopkg.in/yaml.v3@v3.0.0-20200121175148-a6ecf24a6d71
3.0.1

Open the chart page →

2,550
kong-previewwallarmVerified publisher4.2.31 of 5See more

kong-preview wallarm 4.2.3

1 of the 5 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

2,905
wallarm-ingress-rcwallarmVerified publisher4.8.41 of 2See more

wallarm-ingress-rc wallarm 4.8.4

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

2,635
wavefront-hpa-adapterwavefront0.2.101 of 1See more

wavefront-hpa-adapter wavefront 0.2.10

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

1,685
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

4,086
logging-operatorwenerme3.17.101 of 1See more

logging-operator wenerme 3.17.10

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

1,646
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

6,138
temporalwenerme0.15.13 of 13See more

temporal wenerme 0.15.1

3 of the 13 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
prom/prometheus:v2.16.0e4ca62c0d62f
gopkg.in/yaml.v3@v3.0.0-20191120175047-4206685974f2
3.0.1
temporalio/admin-tools:1.15.135034611d981
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
temporalio/server:1.15.1e26758f5a1bf
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

22,665
ceph-csi-cephfswikimedia0.1.82 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

2 of the 5 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.132 of 6See more

ceph-csi-rbd wikimedia 0.1.13

2 of the 6 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

11,784
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

1,958
rawfile-csiymatrixVerified publisher0.2.12 of 4See more

rawfile-csi ymatrix 0.2.1

2 of the 4 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

7,972
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

3,697

Container images carrying it

407 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
2
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
2
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
gopkg.in/yaml.v3@v3.0.0
3.0.1
2
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
gopkg.in/yaml.v3@v3.0.0
3.0.1
2
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
alex6021710/ai-scale-auth:latest6c7a47e470c3
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
alex6021710/ai-scale-doer:latest31e533cf7cd3
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
alex6021710/ai-scale-provider:latest5837d9b30cc7
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
alex6021710/ai-scale-saver:latestf73e8d60fd03
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
alpine/k8s:1.22.600ac10bcb759
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1
1
alpine/k8s:1.27.321b24e6bf801
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
alpine/k8s:1.18.16a41efe02a041
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
gopkg.in/yaml.v3@v3.0.0
3.0.1
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
gopkg.in/yaml.v3@v3.0.0
3.0.1
1
altinity/metrics-exporter:0.20.01a46d104406d
gopkg.in/yaml.v3@v3.0.0
3.0.1
1
andrcuns/smocker:0.18.5b4a8eb20581a
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
apache/apisix-dashboard:2.9.0c010ea7d1694
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
apache/skywalking-oap-server:9.2.0133d35d2c263
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
apecloud/pyroscope:0.37.2dbca95a15bc1
gopkg.in/yaml.v3@v3.0.0
3.0.1
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
aquasec/starboard-operator:0.15.4be34f709e1ce
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
gopkg.in/yaml.v3@v3.0.0-20220521103104-8f96da9f5d5e
3.0.1
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
bitnamilegacy/mongodb:3.6.213e51da56fc54
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
bitnamilegacy/mongodb:4.4.5e3c9d6b4bc92
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
bitpoke/wordpress-operator:v0.12.421284d1df473
gopkg.in/yaml.v3@v3.0.0
3.0.1
1
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
bsgrigorov/helm-operator:latest45ab095f09c8
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
chaosnative/cle-license-module:2.7.062cf6adc355e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
cloudbees/cert-requester:2.3.31d44fb4f799b
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
cloudbees/sidecar-injector:2.3.38f102ef0383a
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
cockroachdb/cockroach-operator:v2.1.0983312754620
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1
1
craftypath/sops-operator:v0.8.0402a0024c732
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
csiplugin/snapshot-controller:v4.0.000fcc441ea9f
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
danielfm/kube-ecr-cleanup-controller:0.1.1012485563b1d0
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
datadog/extendeddaemonset:v0.8.0513a4377aed5
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
datappeal/hive-metastore:lateste38c085a3567
gopkg.in/yaml.v3@v3.0.0-20190924164351-c8b7dadae555
3.0.1
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
datawire/aes:1.13.62beb65062c8b
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
datawire/emissary:2.0.2-ea9716efbdd24b
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.