CVE-2022-28948
HighAdvisory
Published 20 May 2022In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.040
- 90th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 376
- of 17,781 indexed, latest versions
- Container images
- 407
- deployed by those charts
- Fix available
- 1 of 1
- affected package
gopkg.in/yaml.v3 Denial of Service
Carried by container images the latest versions of 376 of 17,781 indexed charts deploy, on 407 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| gopkg.in/ | v3.0.0, v3.0.0-20190924164351-c8b7dadae555, v3.0.0-20191026110619-0b21df46bc1d, v3.0.0-20191120175047-4206685974f2+9 more | 3.0.1 | 407 |
- OSV records
- GHSA-hp87-p4gw-j4gq
- Also known as
- GO-2022-0603
Charts affected
376 by stars
Container images carrying it
407 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 78dc63bc5b89 | gopkg.in/ | 3.0.1 | 2 |
| ghcr.io/ | 5e88f2205de1 | gopkg.in/ | 3.0.1 | 2 |
| quay.io/ | e98d13459cdc | gopkg.in/ | 3.0.1 | 2 |
| quay.io/ | d7079e0890da | gopkg.in/ | 3.0.1 | 2 |
| quay.io/ | bb5e052770e5 | gopkg.in/ | 3.0.1 | 2 |
| quay.io/ | 983627001c89 | gopkg.in/ | 3.0.1 | 2 |
| quay.io/ | b899dbd1b901 | gopkg.in/ | 3.0.1 | 2 |
| quay.io/ | df0cd5887887 | gopkg.in/ | 3.0.1 | 2 |
| registry.k8s.io/ | 01d181618f27 | gopkg.in/ | 3.0.1 | 2 |
| registry.k8s.io/ | 8b9c313c05f5 | gopkg.in/ | 3.0.1 | 2 |
| registry.k8s.io/ | 122bfb8c1eda | gopkg.in/ | 3.0.1 | 2 |
| registry.k8s.io/ | 8f7520bd957e | gopkg.in/ | 3.0.1 | 2 |
| registry.k8s.io/ | 9ebbf9f023e7 | gopkg.in/ | 3.0.1 | 2 |
| registry.k8s.io/ | ad16874e2140 | gopkg.in/ | 3.0.1 | 2 |
| alex6021710/ | 6c7a47e470c3 | gopkg.in/ | 3.0.1 | 1 |
| alex6021710/ | 31e533cf7cd3 | gopkg.in/ | 3.0.1 | 1 |
| alex6021710/ | 5837d9b30cc7 | gopkg.in/ | 3.0.1 | 1 |
| alex6021710/ | f73e8d60fd03 | gopkg.in/ | 3.0.1 | 1 |
| alpine/ | 00ac10bcb759 | gopkg.in/ | 3.0.1 | 1 |
| alpine/ | 21b24e6bf801 | gopkg.in/ | 3.0.1 | 1 |
| alpine/ | a41efe02a041 | gopkg.in/ | 3.0.1 | 1 |
| altinity/ | 7a85f522c5bc | gopkg.in/ | 3.0.1 | 1 |
| altinity/ | 8f0f582d41f0 | gopkg.in/ | 3.0.1 | 1 |
| altinity/ | 1a46d104406d | gopkg.in/ | 3.0.1 | 1 |
| andrcuns/ | b4a8eb20581a | gopkg.in/ | 3.0.1 | 1 |
| apache/ | c010ea7d1694 | gopkg.in/ | 3.0.1 | 1 |
| apache/ | 133d35d2c263 | gopkg.in/ | 3.0.1 | 1 |
| apache/ | b4ec8c18d079 | gopkg.in/ | 3.0.1 | 1 |
| apecloud/ | dbca95a15bc1 | gopkg.in/ | 3.0.1 | 1 |
| aquasec/ | 7ea4aa3d2eb6 | gopkg.in/ | 3.0.1 | 1 |
| aquasec/ | be34f709e1ce | gopkg.in/ | 3.0.1 | 1 |
| beopenit/ | 75a48144e682 | gopkg.in/ | 3.0.1 | 1 |
| bicarus/ | b1dab0721e1c | gopkg.in/ | 3.0.1 | 1 |
| bitnamilegacy/ | 3e51da56fc54 | gopkg.in/ | 3.0.1 | 1 |
| bitnamilegacy/ | e3c9d6b4bc92 | gopkg.in/ | 3.0.1 | 1 |
| bitpoke/ | 21284d1df473 | gopkg.in/ | 3.0.1 | 1 |
| bitpoke/ | 7fb3aad37b5f | gopkg.in/ | 3.0.1 | 1 |
| bsgrigorov/ | 45ab095f09c8 | gopkg.in/ | 3.0.1 | 1 |
| chaosnative/ | 62cf6adc355e | gopkg.in/ | 3.0.1 | 1 |
| cloudbees/ | 1d44fb4f799b | gopkg.in/ | 3.0.1 | 1 |
| cloudbees/ | 8f102ef0383a | gopkg.in/ | 3.0.1 | 1 |
| cockroachdb/ | 983312754620 | gopkg.in/ | 3.0.1 | 1 |
| craftypath/ | 402a0024c732 | gopkg.in/ | 3.0.1 | 1 |
| csiplugin/ | 00fcc441ea9f | gopkg.in/ | 3.0.1 | 1 |
| danielfm/ | 12485563b1d0 | gopkg.in/ | 3.0.1 | 1 |
| datadog/ | 513a4377aed5 | gopkg.in/ | 3.0.1 | 1 |
| datappeal/ | e38c085a3567 | gopkg.in/ | 3.0.1 | 1 |
| datawire/ | 07f8fe4f4f8e | gopkg.in/ | 3.0.1 | 1 |
| datawire/ | 2beb65062c8b | gopkg.in/ | 3.0.1 | 1 |
| datawire/ | 9716efbdd24b | gopkg.in/ | 3.0.1 | 1 |