StackRadar

CVE-2022-28948

High

Advisory

Published 20 May 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.040
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
376
of 17,781 indexed, latest versions
Container images
407
deployed by those charts
Fix available
1 of 1
affected package

gopkg.in/yaml.v3 Denial of Service

Carried by container images the latest versions of 376 of 17,781 indexed charts deploy, on 407 images.

Affected packageAffected versionsFixed inImages
gopkg.in/yaml.v3golangv3.0.0, v3.0.0-20190924164351-c8b7dadae555, v3.0.0-20191026110619-0b21df46bc1d, v3.0.0-20191120175047-4206685974f2+9 more3.0.1407
OSV records
GHSA-hp87-p4gw-j4gq
Also known as
GO-2022-0603

Charts affected

376 by stars
ChartLatestAffected imagesRadar Score
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

6,596
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

1,827
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
gopkg.in/yaml.v3@v3.0.0-20191120175047-4206685974f2
3.0.1

Open the chart page →

2,869
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

3,764
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

10,568
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

21,005
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ecadlabs/tezos_exporter:latest4bcbe5d1cdd2
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

5,321
monitoringthl-chartsVerified publisher0.1.14 of 10See more

monitoring thl-charts 0.1.1

4 of the 10 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
grafana/loki:2.5.0f9ef133793af
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
grafana/promtail:2.4.2626900031c4e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
quay.io/prometheus/prometheus:v2.34.0b37103e03399
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

18,908
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
gopkg.in/yaml.v3@v3.0.0-20200603094226-e3079894b1e8
3.0.1

Open the chart page →

8,484
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

6,132
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1

Open the chart page →

4,382
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

13,459
vineyard-operatorvineyardVerified publisher0.24.21 of 2See more

vineyard-operator vineyard 0.24.2

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

4,525
volantmqvolantmq0.1.21 of 1See more

volantmq volantmq 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
gopkg.in/yaml.v3@v3.0.0-20200121175148-a6ecf24a6d71
3.0.1

Open the chart page →

2,550
kong-previewwallarmVerified publisher4.2.31 of 5See more

kong-preview wallarm 4.2.3

1 of the 5 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

2,905
wallarm-ingress-rcwallarmVerified publisher4.8.41 of 2See more

wallarm-ingress-rc wallarm 4.8.4

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

2,635
wavefront-hpa-adapterwavefront0.2.101 of 1See more

wavefront-hpa-adapter wavefront 0.2.10

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

1,685
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

4,086
logging-operatorwenerme3.17.101 of 1See more

logging-operator wenerme 3.17.10

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

1,646
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

6,138
temporalwenerme0.15.13 of 13See more

temporal wenerme 0.15.1

3 of the 13 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
prom/prometheus:v2.16.0e4ca62c0d62f
gopkg.in/yaml.v3@v3.0.0-20191120175047-4206685974f2
3.0.1
temporalio/admin-tools:1.15.135034611d981
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
temporalio/server:1.15.1e26758f5a1bf
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

22,665
ceph-csi-cephfswikimedia0.1.82 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

2 of the 5 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.132 of 6See more

ceph-csi-rbd wikimedia 0.1.13

2 of the 6 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

11,784
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

1,958
rawfile-csiymatrixVerified publisher0.2.12 of 4See more

rawfile-csi ymatrix 0.2.1

2 of the 4 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

7,972
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

3,697

Container images carrying it

407 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
dollarshaveclub/thermite:0.0.31663cbf25fcfe
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
ecadlabs/tezos_exporter:latest4bcbe5d1cdd2
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
epamedp/admin-console-operator:2.14.090f9921d8d58
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
epamedp/jenkins-operator:2.15.328ef56bc0ca3
gopkg.in/yaml.v3@v3.0.0-20220521103104-8f96da9f5d5e
3.0.1
1
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
epamedp/reconciler:2.12.0d33e938b6d59
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
fluxcd/helm-controller:v0.9.092b891e495d8
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
fluxcd/source-controller:v0.10.031a8c79a6803
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
gitea/gitea:1.13.0d5ab14cd29af
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
gocrane/craned:v0.5.1a1400909118c
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
gocrane/crane-scheduler:0.0.239ba6d11b2079
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
gocrane/crane-scheduler-controller:0.1.23a2d7e60576f9
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
goharbor/chartmuseum-photon:v2.5.36ab3ca28e9e5
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
goharbor/harbor-core:v2.5.386bf3031f4a7
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1
1
grafana/agent:v0.20.0825c09373d27
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
grafana/grafana:7.5.609bb407e26ab
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
grafana/grafana:7.3.315b977f5207d
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
grafana/grafana:8.0.3696823fbc561
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
grafana/grafana:7.3.46d42886b3ebe
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
grafana/grafana:7.2.1733842cca5bd
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
grafana/grafana:8.3.5cd7cb4345aa7
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
grafana/grafana:8.3.4cf81d2c753c8
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
grafana/grafana:7.4.5d322192ed2fa
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
grafana/grafana:8.5.3ecc1b80b8ca2
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
grafana/kubernetes-diff-logger:0.0.598f6d1cd1e25
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
grafana/logcli:main-c90366d-amd643d85bb66e39b
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
grafana/loki:2.0.077e138f81a8e
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
grafana/loki:2.4.2b3af8ead67d7
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
grafana/mimir:2.0.080c1a8eb24dd
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
grafana/promtail:2.0.05fd12edcc694
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
hashicorp/boundary:0.8.1fb70bd9210ff
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
hashicorp/terraform-k8s:1.1.2b19857bab620
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
hashicorp/vault:1.8.4dfc3500beb0e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
hashicorp/vault-k8s:0.14.0aff47b5ba39c
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.