StackRadar

CVE-2022-28948

High

Advisory

Published 20 May 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.040
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
376
of 17,781 indexed, latest versions
Container images
407
deployed by those charts
Fix available
1 of 1
affected package

gopkg.in/yaml.v3 Denial of Service

Carried by container images the latest versions of 376 of 17,781 indexed charts deploy, on 407 images.

Affected packageAffected versionsFixed inImages
gopkg.in/yaml.v3golangv3.0.0, v3.0.0-20190924164351-c8b7dadae555, v3.0.0-20191026110619-0b21df46bc1d, v3.0.0-20191120175047-4206685974f2+9 more3.0.1407
OSV records
GHSA-hp87-p4gw-j4gq
Also known as
GO-2022-0603

Charts affected

376 by stars
ChartLatestAffected imagesRadar Score
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

6,596
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

1,827
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
gopkg.in/yaml.v3@v3.0.0-20191120175047-4206685974f2
3.0.1

Open the chart page →

2,869
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

3,764
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

10,568
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

21,005
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ecadlabs/tezos_exporter:latest4bcbe5d1cdd2
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

5,321
monitoringthl-chartsVerified publisher0.1.14 of 10See more

monitoring thl-charts 0.1.1

4 of the 10 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
grafana/loki:2.5.0f9ef133793af
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
grafana/promtail:2.4.2626900031c4e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
quay.io/prometheus/prometheus:v2.34.0b37103e03399
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

18,908
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
gopkg.in/yaml.v3@v3.0.0-20200603094226-e3079894b1e8
3.0.1

Open the chart page →

8,484
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

6,132
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1

Open the chart page →

4,382
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

13,459
vineyard-operatorvineyardVerified publisher0.24.21 of 2See more

vineyard-operator vineyard 0.24.2

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

4,525
volantmqvolantmq0.1.21 of 1See more

volantmq volantmq 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
gopkg.in/yaml.v3@v3.0.0-20200121175148-a6ecf24a6d71
3.0.1

Open the chart page →

2,550
kong-previewwallarmVerified publisher4.2.31 of 5See more

kong-preview wallarm 4.2.3

1 of the 5 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

2,905
wallarm-ingress-rcwallarmVerified publisher4.8.41 of 2See more

wallarm-ingress-rc wallarm 4.8.4

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

2,635
wavefront-hpa-adapterwavefront0.2.101 of 1See more

wavefront-hpa-adapter wavefront 0.2.10

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

1,685
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

4,086
logging-operatorwenerme3.17.101 of 1See more

logging-operator wenerme 3.17.10

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

1,646
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

6,138
temporalwenerme0.15.13 of 13See more

temporal wenerme 0.15.1

3 of the 13 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
prom/prometheus:v2.16.0e4ca62c0d62f
gopkg.in/yaml.v3@v3.0.0-20191120175047-4206685974f2
3.0.1
temporalio/admin-tools:1.15.135034611d981
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
temporalio/server:1.15.1e26758f5a1bf
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

22,665
ceph-csi-cephfswikimedia0.1.82 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

2 of the 5 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.132 of 6See more

ceph-csi-rbd wikimedia 0.1.13

2 of the 6 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

11,784
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

1,958
rawfile-csiymatrixVerified publisher0.2.12 of 4See more

rawfile-csi ymatrix 0.2.1

2 of the 4 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

7,972
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

3,697

Container images carrying it

407 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hyperledger/fabric-ca:1.5.0f270dfeee91d
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1
1
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
inseefrlab/shelly:cloudshell31f04ca7436b
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
invisibl/gravity-init:v1.0.91a970f84178b
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
invisibl/identity-manager:1.0.01029f4fe20eb
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
iomesh/csi-driver:v2.7.25d3f9bf9240b
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
iomesh/node-disk-manager:1.8.0002c4b92fd34
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
iomesh/node-disk-manager:1.8.0-2292ad270082e
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
iomesh/node-disk-operator:1.8.0-1de4aa40684ad
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
iomesh/node-disk-operator:1.8.0f6c76380db34
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
iotaledger/goshimmer:v0.8.6b02a8f77474f
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
istio/install-cni:1.10.32232f365aed6
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
istio/operator:1.10.3655eefa11c84
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
istio/operator:1.12.06cfce8a071b9
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
istio/pilot:1.10.0294ca55bd1cc
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
istio/pilot:1.10.3e7e110a421c2
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
jkremser/log2rbac:v0.0.5e35cf56ef183
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
gopkg.in/yaml.v3@v3.0.0
3.0.1
1
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1
1
keptn/distributor:0.8.472e17527a4f9
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kfirfer/scripts:0.0.2481e5c4e5d70e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kfserving/kfserving-controller:v0.6.163d79d04c2e3
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
kiosksh/kiosk:0.2.11501725ba2025
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kong/kubernetes-ingress-controller:2.35e66021b64a8
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kserve/kserve-controller:v0.8.0f0692a9ea09f
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubebb/capsule-ce:v0.1.2-20221122a3dba2a95cef
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubebb/cert-manager-controller:v1.8.020509de4b399
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubebb/iam-controller:v0.2.0-202401288ffbfa2d67e9
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubebb/iam-provider:v0.2.0-202401280ba03fcee3a7
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubebb/oidc-server:v0.2.02b5894ef1e2f
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubebb/resource-viewer:v0.2.065bb40b353db
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubedb/kubedb-enterprise:v0.11.05829bcedcb0d
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubedb/operator:v0.24.01a06ff0bda52
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubeedge/edgemesh-server:latesta437cf5ec0ae
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubeflowkatib/katib-controller:v0.12.012a28c8a0b41
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
kubeflowkatib/katib-ui:v0.12.0129f0aaba976
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
kubeflownotebookswg/notebook-controller:v1.9.20f14bd28fdd5
gopkg.in/yaml.v3@v3.0.0
3.0.1
1
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubeflownotebookswg/poddefaults-webhook:v1.6.17d42600e1524
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.