StackRadar

CVE-2022-28948

High

Advisory

Published 20 May 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.040
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
376
of 17,781 indexed, latest versions
Container images
407
deployed by those charts
Fix available
1 of 1
affected package

gopkg.in/yaml.v3 Denial of Service

Carried by container images the latest versions of 376 of 17,781 indexed charts deploy, on 407 images.

Affected packageAffected versionsFixed inImages
gopkg.in/yaml.v3golangv3.0.0, v3.0.0-20190924164351-c8b7dadae555, v3.0.0-20191026110619-0b21df46bc1d, v3.0.0-20191120175047-4206685974f2+9 more3.0.1407
OSV records
GHSA-hp87-p4gw-j4gq
Also known as
GO-2022-0603

Charts affected

376 by stars
ChartLatestAffected imagesRadar Score
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

6,596
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

1,827
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
gopkg.in/yaml.v3@v3.0.0-20191120175047-4206685974f2
3.0.1

Open the chart page →

2,869
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

3,764
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

10,568
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

21,005
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ecadlabs/tezos_exporter:latest4bcbe5d1cdd2
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

5,321
monitoringthl-chartsVerified publisher0.1.14 of 10See more

monitoring thl-charts 0.1.1

4 of the 10 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
grafana/loki:2.5.0f9ef133793af
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
grafana/promtail:2.4.2626900031c4e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
quay.io/prometheus/prometheus:v2.34.0b37103e03399
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

18,908
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
gopkg.in/yaml.v3@v3.0.0-20200603094226-e3079894b1e8
3.0.1

Open the chart page →

8,484
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

6,132
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1

Open the chart page →

4,382
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

13,459
vineyard-operatorvineyardVerified publisher0.24.21 of 2See more

vineyard-operator vineyard 0.24.2

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

4,525
volantmqvolantmq0.1.21 of 1See more

volantmq volantmq 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
gopkg.in/yaml.v3@v3.0.0-20200121175148-a6ecf24a6d71
3.0.1

Open the chart page →

2,550
kong-previewwallarmVerified publisher4.2.31 of 5See more

kong-preview wallarm 4.2.3

1 of the 5 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

2,905
wallarm-ingress-rcwallarmVerified publisher4.8.41 of 2See more

wallarm-ingress-rc wallarm 4.8.4

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

2,635
wavefront-hpa-adapterwavefront0.2.101 of 1See more

wavefront-hpa-adapter wavefront 0.2.10

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

1,685
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

4,086
logging-operatorwenerme3.17.101 of 1See more

logging-operator wenerme 3.17.10

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

1,646
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

6,138
temporalwenerme0.15.13 of 13See more

temporal wenerme 0.15.1

3 of the 13 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
prom/prometheus:v2.16.0e4ca62c0d62f
gopkg.in/yaml.v3@v3.0.0-20191120175047-4206685974f2
3.0.1
temporalio/admin-tools:1.15.135034611d981
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
temporalio/server:1.15.1e26758f5a1bf
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

22,665
ceph-csi-cephfswikimedia0.1.82 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

2 of the 5 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.132 of 6See more

ceph-csi-rbd wikimedia 0.1.13

2 of the 6 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

11,784
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

1,958
rawfile-csiymatrixVerified publisher0.2.12 of 4See more

rawfile-csi ymatrix 0.2.1

2 of the 4 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

7,972
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

3,697

Container images carrying it

407 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
kubeflownotebookswg/tensorboard-controller:v1.9.26536a9f61193
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubeflownotebookswg/tensorboard-controller:v1.6.182ffdd2da285
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubeflow/training-operator:v1-e1434f6ff847e2b6af0
gopkg.in/yaml.v3@v3.0.0
3.0.1
1
kubernetesui/metrics-scraper:v1.0.876049887f07a
gopkg.in/yaml.v3@v3.0.0
3.0.1
1
kubeshop/testkube-api-server:0.11.160ad97f07a78b
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubesphere/fluent-operator:v1.0.2702df77228c6
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubesphere/pvc-autoresizer:v0.19a18a16c7b87
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kubesphere/storageclass-accessor:v0.1.1eac8f273a9b6
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
kvalitetsit/metadoc-app:maine89e351733ad
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
library/influxdb:2.0.8ba10ac9ba17a
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1
1
library/influxdb:2.3.0-alpined7f5dd5f70e2
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1
1
library/telegraf:1.20.428e98eece020
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
library/telegraf:1.19.0-alpine794079a7f241
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
library/telegraf:1.19-alpineaddb86c0c520
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
library/traefik:2.5.62f603f8d3abe
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
library/traefik:v1.7.345d47b7bb2546
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
library/traefik:2.5.47d0228d19042
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
library/traefik:2.4.8eda951fd29a8
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
linuxserver/cloud9:latest45c5fe102ff3
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
livekit/livekit-recorder:v0.3.13ecf1409c75e0
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
livekit/livekit-server:v1.0.08391fd1b834f
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
loftsh/jspolicy:0.2.225deb9bd2683
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
mattermost/focalboard:0.9.031078df7a3c8
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
mattermost/focalboard:0.6.7f2f987dada52
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
mattermost/mattermost-app-chaosengine:c153e436268954edd67
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
metacontrollerio/metacontroller:v2.1.10336993b88e4
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
minio/operator:v4.1.02adc5be088f5
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
natsio/nats-operator:0.8.31261dae38389
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
netapp/trident-operator:21.10.049cfe552d9c2
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
netrisai/mongodb:4.4.4-debian-10-r095abfb776bb4
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
ntakashi/gitana:1.4.04171ec641120
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
ofekmeister/csi-gcs:v0.9.030d70fa9211b
gopkg.in/yaml.v3@v3.0.0-20220512140231-539c8e751b99
3.0.1
1
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1
1
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
prom/prometheus:v2.18.15880ec936055
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1
1
prom/prometheus:v2.19.2cd134bd4fca0
gopkg.in/yaml.v3@v3.0.0-20200603094226-e3079894b1e8
3.0.1
1
prom/prometheus:v2.16.0e4ca62c0d62f
gopkg.in/yaml.v3@v3.0.0-20191120175047-4206685974f2
3.0.1
1
prom/prometheus:v2.22.2f7ffebdd428b
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
1
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1
rancher/k3s:v1.25.3-k3s1eaa270df79cc
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.