StackRadar

CVE-2022-28948

High

Advisory

Published 20 May 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.040
90th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
376
of 17,781 indexed, latest versions
Container images
407
deployed by those charts
Fix available
1 of 1
affected package

gopkg.in/yaml.v3 Denial of Service

Carried by container images the latest versions of 376 of 17,781 indexed charts deploy, on 407 images.

Affected packageAffected versionsFixed inImages
gopkg.in/yaml.v3golangv3.0.0, v3.0.0-20190924164351-c8b7dadae555, v3.0.0-20191026110619-0b21df46bc1d, v3.0.0-20191120175047-4206685974f2+9 more3.0.1407
OSV records
GHSA-hp87-p4gw-j4gq
Also known as
GO-2022-0603

Charts affected

376 by stars
ChartLatestAffected imagesRadar Score
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

6,596
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

1,827
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
gopkg.in/yaml.v3@v3.0.0-20191120175047-4206685974f2
3.0.1

Open the chart page →

2,869
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

3,764
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

10,568
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

21,005
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ecadlabs/tezos_exporter:latest4bcbe5d1cdd2
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

5,321
monitoringthl-chartsVerified publisher0.1.14 of 10See more

monitoring thl-charts 0.1.1

4 of the 10 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
grafana/loki:2.5.0f9ef133793af
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
grafana/promtail:2.4.2626900031c4e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
quay.io/prometheus/prometheus:v2.34.0b37103e03399
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

18,908
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
prom/prometheus:v2.19.0bfad037f95e5
gopkg.in/yaml.v3@v3.0.0-20200603094226-e3079894b1e8
3.0.1

Open the chart page →

8,484
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

6,132
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
gopkg.in/yaml.v3@v3.0.0-20200313102051-9f266ea9e77c
3.0.1

Open the chart page →

4,382
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

13,459
vineyard-operatorvineyardVerified publisher0.24.21 of 2See more

vineyard-operator vineyard 0.24.2

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

4,525
volantmqvolantmq0.1.21 of 1See more

volantmq volantmq 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
gopkg.in/yaml.v3@v3.0.0-20200121175148-a6ecf24a6d71
3.0.1

Open the chart page →

2,550
kong-previewwallarmVerified publisher4.2.31 of 5See more

kong-preview wallarm 4.2.3

1 of the 5 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

2,905
wallarm-ingress-rcwallarmVerified publisher4.8.41 of 2See more

wallarm-ingress-rc wallarm 4.8.4

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

2,635
wavefront-hpa-adapterwavefront0.2.101 of 1See more

wavefront-hpa-adapter wavefront 0.2.10

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
wavefronthq/wavefront-hpa-adapter:0.9.12af5fef9a4768
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

1,685
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1

Open the chart page →

4,086
logging-operatorwenerme3.17.101 of 1See more

logging-operator wenerme 3.17.10

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

1,646
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

6,138
temporalwenerme0.15.13 of 13See more

temporal wenerme 0.15.1

3 of the 13 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
prom/prometheus:v2.16.0e4ca62c0d62f
gopkg.in/yaml.v3@v3.0.0-20191120175047-4206685974f2
3.0.1
temporalio/admin-tools:1.15.135034611d981
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
temporalio/server:1.15.1e26758f5a1bf
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

22,665
ceph-csi-cephfswikimedia0.1.82 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

2 of the 5 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

10,285
ceph-csi-rbdwikimedia0.1.132 of 6See more

ceph-csi-rbd wikimedia 0.1.13

2 of the 6 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

11,784
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

1,958
rawfile-csiymatrixVerified publisher0.2.12 of 4See more

rawfile-csi ymatrix 0.2.1

2 of the 4 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
matrixdb/rawfile-csi:v0.2.195b2e38e913d
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1

Open the chart page →

7,972
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-28948.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
gopkg.in/yaml.v3@v3.0.0
3.0.1

Open the chart page →

3,697

Container images carrying it

407 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
wurstmeister/kafka:latest2d4bbf9cc83d
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
7
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
6
quay.io/devtron/kubectl:latest2ad610626658
gopkg.in/yaml.v3@v3.0.0-20210107172259-749611fa9fcc
3.0.1
6
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
gopkg.in/yaml.v3@v3.0.0
3.0.1
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
5
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
4
hyperledger/fabric-peer:2.46ff36af21eb1
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
4
hyperledger/fabric-tools:2.4b1194f509085
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
gopkg.in/yaml.v3@v3.0.0
3.0.1
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
4
argoproj/argocd:v1.8.1830e86cacefd
gopkg.in/yaml.v3@v3.0.0-20200121175148-a6ecf24a6d71
3.0.1
3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
3
grafana/grafana:8.2.500568d89c4f8
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
3
grafana/promtail:2.4.2626900031c4e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
3
prom/prometheus:v2.19.0bfad037f95e5
gopkg.in/yaml.v3@v3.0.0-20200603094226-e3079894b1e8
3.0.1
3
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
3
quay.io/devtron/clair:4.3.675fb847ac045
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
3
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
3
1password/scim:v2.3.129d0c6cb67eb
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
bitnamilegacy/mongodb:4.4.14fe2bd7b4036
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
datawire/aes:1.14.48588eafe6862
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
2
governify/dashboard:lateste83a17ba5038
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
grafana/agent-operator:v0.25.1a136c6208aa3
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
grafana/grafana:8.5.042d3e6bc1865
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
grafana/grafana:7.3.5511bc20bfcd1
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
2
grafana/loki:1.5.0922b3f412fdd
gopkg.in/yaml.v3@v3.0.0-20191120175047-4206685974f2
3.0.1
2
grafana/loki:2.5.0f9ef133793af
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
hashicorp/vault:1.8.34db614d40d0e
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
hashicorp/vault-k8s:0.13.1bebb03e8e800
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
iomesh/csi-provisioner:v3.0.0f9508460b273
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
iomesh/node-disk-exporter:1.8.0f03148764f38
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
2
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
library/traefik:v2.57d5a6ae66572
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
2
minio/operator:v4.3.754393e03f3b2
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
prom/blackbox-exporter:v0.18.01ffc3f109eb3
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
2
prom/prometheus:v2.17.242d2395cd719
gopkg.in/yaml.v3@v3.0.0-20200121175148-a6ecf24a6d71
3.0.1
2
prom/prometheus:v2.21.0d43417c260e5
gopkg.in/yaml.v3@v3.0.0-20200615113413-eeeca48fe776
3.0.1
2
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
gopkg.in/yaml.v3@v3.0.0-20210107192922-496545a6307b
3.0.1
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.