StackRadar

CVE-2022-30580

Unscored

Advisory

Published 26 Jul 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,126
of 17,787 indexed, latest versions
Container images
1,162
deployed by those charts
Fix available
1 of 1
affected package

Empty Cmd.Path can trigger unintended binary in os/exec on Windows

Carried by container images the latest versions of 1,126 of 17,787 indexed charts deploy, on 1,162 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+71 more1.17.111,162
OSV records
GO-2022-0532
Also known as
BIT-golang-2022-30580

Charts affected

1,126 by stars
ChartLatestAffected imagesRadar Score
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
stdlib@go1.18.1
1.17.11

Open the chart page →

20,987
pgbouncerevilmartians0.2.01 of 2See more

pgbouncer evilmartians 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
quay.io/evl.ms/pgbouncer-exporter:0.4.074f919b78494
stdlib@go1.14.4
1.17.11

Open the chart page →

1,838
exa-csiexa-csi-driver0.2.0-rev21 of 6See more

exa-csi exa-csi-driver 0.2.0-rev2

1 of the 6 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.17.11

Open the chart page →

7,050
faasnetfaasnet0.0.41 of 5See more

faasnet faasnet 0.0.4

1 of the 5 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
simpleidserver/faasprometheus:0.0.425e378d57d78
stdlib@go1.17.1
1.17.11

Open the chart page →

7,665
degafactlyVerified publisher0.11.132 of 3See more

dega factly 0.11.13

2 of the 3 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
factly/dega-api:0.15.166fafc7b0a17
stdlib@go1.16.2
1.17.11
factly/dega-server:0.15.194d21479382e
stdlib@go1.16.2
1.17.11

Open the chart page →

5,747
kavachfactlyVerified publisher0.9.51 of 2See more

kavach factly 0.9.5

1 of the 2 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
factly/kavach-server:0.22.3be85ff1b9bd3
stdlib@go1.16.2
1.17.11

Open the chart page →

3,573
oom-event-generatorfairwinds-incubator0.2.21 of 1See more

oom-event-generator fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
stdlib@go1.13
1.17.11

Open the chart page →

4,645
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
stdlib@go1.16.5
1.17.11

Open the chart page →

13,491
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
stdlib@go1.17.8
1.17.11

Open the chart page →

7,519
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
stdlib@go1.13.5
1.17.11

Open the chart page →

14,688
infrafibonacci-cluster-infraVerified publisher1.0.02 of 4See more

infra fibonacci-cluster-infra 1.0.0

2 of the 4 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
library/postgres:16.4e62fbf9d3e2b
stdlib@go1.18.2
1.17.11
library/redis:7.4.1bb142a9c18ac
stdlib@go1.18.2
1.17.11

Open the chart page →

12,510
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
stdlib@go1.17.5
1.17.11

Open the chart page →

3,311
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-payment-service:1.0c96f759b6ce4
stdlib@go1.13
1.17.11

Open the chart page →

7,691
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:3.6.213e51da56fc54
stdlib@go1.15.1
1.17.11

Open the chart page →

64,192
grafanaflagger1.7.01 of 1See more

grafana flagger 1.7.0

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
grafana/grafana:7.3.46d42886b3ebe
stdlib@go1.15.5
1.17.11

Open the chart page →

3,365
podinfoflagger6.1.41 of 1See more

podinfo flagger 6.1.4

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
stdlib@go1.17.9
1.17.11

Open the chart page →

2,808
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.17.11

Open the chart page →

4,079
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
stdlib@go1.16.3
1.17.11

Open the chart page →

8,046
fluent-operatorfluent-operatorVerified publisher0.1.01 of 2See more

fluent-operator fluent-operator 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
kubesphere/fluent-operator:v1.0.2702df77228c6
stdlib@go1.16.6
1.17.11

Open the chart page →

2,630
flyte-depsflyte1.16.81 of 3See more

flyte-deps flyte 1.16.8

1 of the 3 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
stdlib@go1.15.1
1.17.11

Open the chart page →

2,245
csp-reporterfoomoVerified publisher2.2.01 of 1See more

csp-reporter foomo 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
foomo/csp-reporter:1.3.0e436da524785
stdlib@go1.18
1.17.11

Open the chart page →

1,408
maxscalefour-allportalVerified publisher4.1.162 of 3See more

maxscale four-allportal 4.1.16

2 of the 3 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:10.6.12-debian-11-r1643a70df0e7c6
stdlib@go1.18.2
1.17.11
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
stdlib@go1.17.8
1.17.11

Open the chart page →

6,610
icinga2g0dscookie0.2.01 of 1See more

icinga2 g0dscookie 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
stdlib@go1.18.1
1.17.11

Open the chart page →

4,428
passboltg0dscookie0.5.22 of 2See more

passbolt g0dscookie 0.5.2

2 of the 2 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
library/mariadb:10.79a48ac9f196f
stdlib@go1.16.7
1.17.11
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
stdlib@go1.14.4
1.17.11

Open the chart page →

7,983
podgrabgabe565Verified publisher0.5.21 of 1See more

podgrab gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
stdlib@go1.15.2
1.17.11

Open the chart page →

2,401
alertmanager-discordgeek-cookbookVerified publisher1.3.21 of 1See more

alertmanager-discord geek-cookbook 1.3.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
rogerrum/alertmanager-discord:1.0.3827593369625
stdlib@go1.17.4
1.17.11

Open the chart page →

1,045
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
stdlib@go1.16.7
1.17.11

Open the chart page →

16,178
embygeek-cookbookVerified publisher3.4.21 of 1See more

emby geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
stdlib@go1.15
1.17.11

Open the chart page →

8,584
gatusgeek-cookbookVerified publisher1.1.21 of 1See more

gatus geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
twinproduction/gatus:v3.8.049dc0d9b2e2c
stdlib@go1.18.1
1.17.11

Open the chart page →

1,881
gonicgeek-cookbookVerified publisher6.4.21 of 1See more

gonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
sentriz/gonic:v0.13.1a74012a6adf3
stdlib@go1.16.4
1.17.11

Open the chart page →

3,525
gotifygeek-cookbookVerified publisher1.2.21 of 1See more

gotify geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
gotify/server:2.1.409c79bc1e403
stdlib@go1.16
1.17.11

Open the chart page →

3,131
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
stdlib@go1.15
1.17.11

Open the chart page →

11,042
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
stdlib@go1.16.7
1.17.11

Open the chart page →

14,328
maddygeek-cookbookVerified publisher3.2.01 of 1See more

maddy geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
foxcpp/maddy:v0.5.28fa2bd8f6830
stdlib@go1.17.2
1.17.11

Open the chart page →

2,630
minifluxgeek-cookbookVerified publisher5.2.01 of 2See more

miniflux geek-cookbook 5.2.0

1 of the 2 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
miniflux/miniflux:2.0.36e2fb990dae74
stdlib@go1.17.8
1.17.11

Open the chart page →

2,430
navidromegeek-cookbookVerified publisher6.4.21 of 1See more

navidrome geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
deluan/navidrome:0.43.04e9ae3bff6aa
stdlib@go1.16.4
1.17.11

Open the chart page →

3,597
nullservgeek-cookbookVerified publisher2.4.21 of 1See more

nullserv geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nullserv:v1.3.00792c7e6d814
stdlib@go1.16.5
1.17.11

Open the chart page →

1,118
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
stdlib@go1.15
1.17.11

Open the chart page →

17,758
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
stdlib@go1.16.5
1.17.11

Open the chart page →

3,236
pod-gateway-settergeek-cookbookVerified publisher1.0.01 of 1See more

pod-gateway-setter geek-cookbook 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v2.0.00d6d0df98fe4
stdlib@go1.16.4
1.17.11

Open the chart page →

1,641
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
stdlib@go1.16.8
1.17.11

Open the chart page →

11,855
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
stdlib@go1.15
1.17.11

Open the chart page →

7,806
satisfactorygeek-cookbookVerified publisher1.2.21 of 1See more

satisfactory geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:lateste103700ae6ae
stdlib@go1.18.1
1.17.11

Open the chart page →

3,466
searxgeek-cookbookVerified publisher5.6.23 of 4See more

searx geek-cookbook 5.6.2

3 of the 4 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
dalf/filtron:latestb19cbf5b2f37
stdlib@go1.18.2
1.17.11
dalf/morty:latest248a4849c350
stdlib@go1.18.2
1.17.11
library/caddy:2.2.0-alpine7367adca165f
stdlib@go1.15.2
1.17.11

Open the chart page →

7,470
torrservergeek-cookbookVerified publisher1.2.21 of 1See more

torrserver geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
smailkoz/torrserver:1.0.1117b52d15de8f0
stdlib@go1.17.5
1.17.11

Open the chart page →

3,165
vikunjageek-cookbookVerified publisher6.2.02 of 4See more

vikunja geek-cookbook 6.2.0

2 of the 4 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
library/caddy:2.4.2-alpinefbc51bcf1ab0
stdlib@go1.16.5
1.17.11
vikunja/api:0.17.18cba0520bf8c
stdlib@go1.16.5
1.17.11

Open the chart page →

6,893
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
stdlib@go1.16.8
1.17.11

Open the chart page →

17,996
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
stdlib@go1.17.10
1.17.11

Open the chart page →

4,547
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
postgis/postgis:11-2.5f479f6c3435e
stdlib@go1.16.7
1.17.11

Open the chart page →

34,879
istiogetindataVerified publisher1.11.12 of 2See more

istio getindata 1.11.1

2 of the 2 container images this version deploys carry CVE-2022-30580.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:1.11.1c552478f8f11
stdlib@go1.16.7
1.17.11
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
stdlib@go1.16.7
1.17.11

Open the chart page →

16,834

Container images carrying it

1,162 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/influxdb:2.3.0-alpined7f5dd5f70e2
stdlib@go1.17.2
1.17.11
1
library/kapacitor:1.6.37232f6388a4d
stdlib@go1.17.2
1.17.11
1
library/mariadb:10.7.307e06f2e7ae9
stdlib@go1.16.7
1.17.11
1
library/mariadb:10.11.21c33370a599c
stdlib@go1.16.7
1.17.11
1
library/mariadb:10.422edfe1c7834
stdlib@go1.18.2
1.17.11
1
library/mariadb:10.8.2-focal490f01279be1
stdlib@go1.16.7
1.17.11
1
library/mariadb:12.0.25b6a1eac15b8
stdlib@go1.18.2
1.17.11
1
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.17.11
1
library/mariadb:10.79a48ac9f196f
stdlib@go1.16.7
1.17.11
1
library/mariadb:10.10.2bfc25a68e113
stdlib@go1.16.7
1.17.11
1
library/mariadb:10.6.15e22328f4d714
stdlib@go1.16.7
1.17.11
1
library/mariadb:10.9.4fbb8456ebdb1
stdlib@go1.16.7
1.17.11
1
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.17.11
1
library/mongo:7.0.140032d2ca20db
stdlib@go1.18.2
1.17.11
1
library/mongo:4.4.1305678ae4e5e1
stdlib@go1.16.7
1.17.11
1
library/mongo:4.4-bionic3d0e6df9fd5b
stdlib@go1.16.3
1.17.11
1
library/mongo:5.0.14-focal50cae5081ab4
stdlib@go1.17.10
1.17.11
1
library/mongo:6.0.12646902910d6a
stdlib@go1.18.2
1.17.11
1
library/mongo:4.2699d652ed674
stdlib@go1.18.2
1.17.11
1
library/mongo:6.0.271a63fc2438e
stdlib@go1.17.10
1.17.11
1
library/mongo:5.0.217c81758cb295
stdlib@go1.18.2
1.17.11
1
library/mongo:7.0.12ae1cf99fa7bf
stdlib@go1.18.2
1.17.11
1
library/mongo:4.4.18d23ec07162ca
stdlib@go1.17.10
1.17.11
1
library/mongo:8.0.11dca8d11fe467
stdlib@go1.18.2
1.17.11
1
library/mysql:8.4.3106d5197fd8e
stdlib@go1.18.2
1.17.11
1
library/mysql:8.0.303c1aab708f6e
stdlib@go1.16.7
1.17.11
1
library/mysql:9.0.192dc86967801
stdlib@go1.18.2
1.17.11
1
library/mysql:8.0.41bf577825b52a
stdlib@go1.18.2
1.17.11
1
library/mysql:8.0.39ccb8f749bb5e
stdlib@go1.18.2
1.17.11
1
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.17.11
1
library/postgres:13.703652c675ae1
stdlib@go1.16.7
1.17.11
1
library/postgres:14.32d1e636f0778
stdlib@go1.16.7
1.17.11
1
library/postgres:17.4304ab8135187
stdlib@go1.18.2
1.17.11
1
library/postgres:16.6557fea37a744
stdlib@go1.18.2
1.17.11
1
library/postgres:16.4-alpine5660c2cbfea5
stdlib@go1.18.2
1.17.11
1
library/postgres:13.11-bullseye5c265bf1fd30
stdlib@go1.18.2
1.17.11
1
library/postgres:17.5-alpine6567bca8d7bc
stdlib@go1.18.2
1.17.11
1
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.17.11
1
library/postgres:12-alpine7c8f48705831
stdlib@go1.18.2
1.17.11
1
library/postgres:17.2-alpine7e5df973a748
stdlib@go1.18.2
1.17.11
1
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.17.11
1
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.17.11
1
library/postgres:13.12ced3ba927f4c
stdlib@go1.18.2
1.17.11
1
library/postgres:14.6f565573d74ae
stdlib@go1.18.2
1.17.11
1
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.17.11
1
library/redis:7.0.4091a7b5de688
stdlib@go1.16.7
1.17.11
1
library/redis:7-bullseye6a5130174e14
stdlib@go1.18.2
1.17.11
1
library/redis:7.2.5-alpine6aaf3f5e6bc8
stdlib@go1.18.2
1.17.11
1
library/redis:6.2.20-alpine77697a75da9f
stdlib@go1.18.2
1.17.11
1
library/redis83edc2b8e9ff
stdlib@go1.18.2
1.17.11
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.