StackRadar

CVE-2022-30633

Unscored

Advisory

Published 20 Jul 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,159
of 17,790 indexed, latest versions
Container images
1,218
deployed by those charts
Fix available
1 of 1
affected package

Stack exhaustion when unmarshaling certain documents in encoding/xml

Carried by container images the latest versions of 1,159 of 17,790 indexed charts deploy, on 1,218 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+73 more1.17.121,218
OSV records
GO-2022-0523
Also known as
BIT-golang-2022-30633

Charts affected

1,159 by stars
ChartLatestAffected imagesRadar Score
haven-complinacy-dashboardjolle-devVerified publisher1.0.01 of 2See more

haven-complinacy-dashboard jolle-dev 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
stdlib@go1.17.2
1.17.12

Open the chart page →

3,842
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
stdlib@go1.18.2
1.17.12

Open the chart page →

16,680
firstchartjuanjmerono0.2.01 of 1See more

firstchart juanjmerono 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
jmalloc/echo-server:0.3.1e4eaee2c7998
stdlib@go1.17
1.17.12

Open the chart page →

1,443
alertmanager-irc-relayjuppi880.0.11 of 1See more

alertmanager-irc-relay juppi88 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
maldridge/alertmanager-irc-relay:v0.4.1391de2b76128
stdlib@go1.16.4
1.17.12

Open the chart page →

1,615
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
stdlib@go1.18.1
1.17.12

Open the chart page →

6,161
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
alpine/k8s:1.22.600ac10bcb759
stdlib@go1.17.6
1.17.12

Open the chart page →

14,872
k8s-pausek8s-pause0.1.41 of 1See more

k8s-pause k8s-pause 0.1.4

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
stdlib@go1.17.8
1.17.12

Open the chart page →

1,846
k8svault-controllerk8svault-controller0.1.21 of 1See more

k8svault-controller k8svault-controller 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
stdlib@go1.16.15
1.17.12

Open the chart page →

1,885
postgresqlkagiso-me0.4.01 of 1See more

postgresql kagiso-me 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
library/postgres:17.4-alpine7062a2109c4b
stdlib@go1.18.2
1.17.12

Open the chart page →

1,488
rediskagiso-me0.1.61 of 1See more

redis kagiso-me 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.17.12

Open the chart page →

1,288
kestra-starterkestraOfficialVerified publisher2.0.21 of 5See more

kestra-starter kestra 2.0.2

1 of the 5 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
library/postgres:17.5aadf2c0696f5
stdlib@go1.18.2
1.17.12

Open the chart page →

5,455
keycloak-operator-legacykeycloak-operator-legacy1.0.01 of 1See more

keycloak-operator-legacy keycloak-operator-legacy 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
stdlib@go1.13.8
1.17.12

Open the chart page →

5,066
csi-driver-nfskeyporttech0.1.41 of 2See more

csi-driver-nfs keyporttech 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
stdlib@go1.14.2
1.17.12

Open the chart page →

3,364
gogskeyporttech0.1.31 of 3See more

gogs keyporttech 0.1.3

1 of the 3 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
gogs/gogs:0.12.30195b095d0b2
stdlib@go1.14.7
1.17.12

Open the chart page →

3,524
helm-mongodb-operatorkeyporttech0.1.01 of 1See more

helm-mongodb-operator keyporttech 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
stdlib@go1.13.15
1.17.12

Open the chart page →

8,819
dex-k8s-authenticatorkfirfer0.0.31 of 1See more

dex-k8s-authenticator kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
stdlib@go1.13.11
1.17.12

Open the chart page →

2,791
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
stdlib@go1.17.1
1.17.12

Open the chart page →

6,447
scriptskfirfer0.1.361 of 1See more

scripts kfirfer 0.1.36

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
kfirfer/scripts:0.0.2481e5c4e5d70e
stdlib@go1.17.10
1.17.12

Open the chart page →

2,320
kiaekiae0.1.62 of 9See more

kiae kiae 0.1.6

2 of the 9 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.17.12
grafana/promtail:2.6.1072527b12cdf
stdlib@go1.17.9
1.17.12

Open the chart page →

19,257
kimai-helmchartkimai2tet0.1.01 of 2See more

kimai-helmchart kimai2tet 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.17.12

Open the chart page →

1,518
cadvisorkrakazyabraVerified publisher1.0.11 of 1See more

cadvisor krakazyabra 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
stdlib@go1.13.15
1.17.12

Open the chart page →

3,185
krakenkraken0.2.01 of 7See more

kraken kraken 0.2.0

1 of the 7 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
library/redis:5.0fc5ecd863862
stdlib@go1.16.7
1.17.12

Open the chart page →

1,731
kron-aapm-sidecarkron-aapm-sidecar1.1.01 of 1See more

kron-aapm-sidecar kron-aapm-sidecar 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
stdlib@go1.17.10
1.17.12

Open the chart page →

2,111
lndkronkltdVerified publisher0.3.93 of 4See more

lnd kronkltd 0.3.9

3 of the 4 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
stdlib@go1.17.1
1.17.12
thesisrobot/loop:v0.11.1-beta89ae07e787ca
stdlib@go1.13.12
1.17.12
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
stdlib@go1.14.12
1.17.12

Open the chart page →

8,471
casdoorkrzwiatrzyk1.0.01 of 1See more

casdoor krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
casbin/casdoor:v1.224.066f836ef778b
stdlib@go1.17.5
1.17.12

Open the chart page →

3,649
nocodbkrzwiatrzyk0.0.11 of 1See more

nocodb krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
nocodb/nocodb:0.100.2b0b91ec2a2dd
stdlib@go1.18.2
1.17.12

Open the chart page →

2,320
pipecdkrzwiatrzyk0.39.01 of 3See more

pipecd krzwiatrzyk 0.39.0

1 of the 3 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
stdlib@go1.14.6
1.17.12

Open the chart page →

3,819
postgresql-backup-to-miniokrzwiatrzyk0.0.11 of 2See more

postgresql-backup-to-minio krzwiatrzyk 0.0.1

1 of the 2 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.17.12

Open the chart page →

2,199
traggokrzwiatrzyk1.0.01 of 1See more

traggo krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
traggo/server:0.2.3f1ced637510e
stdlib@go1.13.1
1.17.12

Open the chart page →

1,885
cluster-componentkubebb0.2.24 of 4See more

cluster-component kubebb 0.2.2

4 of the 4 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
stdlib@go1.17.8
1.17.12
kubebb/cert-manager-controller:v1.8.020509de4b399
stdlib@go1.17.8
1.17.12
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
stdlib@go1.17.8
1.17.12
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
stdlib@go1.18.2
1.17.12

Open the chart page →

8,174
u4a-componentkubebb0.2.102 of 8See more

u4a-component kubebb 0.2.10

2 of the 8 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
stdlib@go1.18
1.17.12
kubebb/oidc-server:v0.2.02b5894ef1e2f
stdlib@go1.17.8
1.17.12

Open the chart page →

13,834
chaos-meshkubeblocksVerified publisher2.7.21 of 4See more

chaos-mesh kubeblocks 2.7.2

1 of the 4 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
stdlib@go1.16.2
1.17.12

Open the chart page →

13,572
geminikubeblocksVerified publisher0.13.41 of 8See more

gemini kubeblocks 0.13.4

1 of the 8 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.17.12

Open the chart page →

3,103
nvidia-gpu-exporterkubeblocksVerified publisher0.3.11 of 1See more

nvidia-gpu-exporter kubeblocks 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
stdlib@go1.17
1.17.12

Open the chart page →

4,502
prometheuskubeblocksVerified publisher15.16.15 of 6See more

prometheus kubeblocks 15.16.1

5 of the 6 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.17.12
prom/pushgateway:v1.4.33496e0f85943
stdlib@go1.18.2
1.17.12
quay.io/prometheus/alertmanager:v0.24.0088464f949de
stdlib@go1.17.8
1.17.12
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
stdlib@go1.17.3
1.17.12
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
stdlib@go1.18.3
1.17.12

Open the chart page →

10,309
victoria-metrics-alertkubeblocksVerified publisher0.8.3-reload1 of 3See more

victoria-metrics-alert kubeblocks 0.8.3-reload

1 of the 3 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.17.12

Open the chart page →

3,715
cephfs-csikubegems1.0.81 of 6See more

cephfs-csi kubegems 1.0.8

1 of the 6 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
stdlib@go1.17.5
1.17.12

Open the chart page →

4,452
chartmuseumkubegems3.8.01 of 1See more

chartmuseum kubegems 3.8.0

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
stdlib@go1.17.6
1.17.12

Open the chart page →

3,526
gatewaykubegems0.3.21 of 2See more

gateway kubegems 0.3.2

1 of the 2 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
kubegems/kube-rbac-proxy:v0.8.0941f557ed1ee
stdlib@go1.13.15
1.17.12

Open the chart page →

3,505
giteakubegems5.0.81 of 2See more

gitea kubegems 5.0.8

1 of the 2 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
gitea/gitea:1.16.8b0bdf102b485
stdlib@go1.18.2
1.17.12

Open the chart page →

3,400
knative-servingkubegems1.0.17 of 8See more

knative-serving kubegems 1.0.1

7 of the 8 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourierdigest-pinned197fbb71d1f1
stdlib@go1.18.3
1.17.12
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned08315309da4b
stdlib@go1.18.3
1.17.12
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinned105bdd14ecaa
stdlib@go1.18.3
1.17.12
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedbac158dfb0c7
stdlib@go1.18.3
1.17.12
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mappingdigest-pinnede384a295069b
stdlib@go1.18.3
1.17.12
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhookdigest-pinned15f1ce7f35b4
stdlib@go1.18.3
1.17.12
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinned1282a399cbb9
stdlib@go1.18.3
1.17.12

Open the chart page →

10,469
logging-operatorkubegems3.17.61 of 1See more

logging-operator kubegems 3.17.6

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/logging-operator:3.17.623c2d4d54a64
stdlib@go1.17.9
1.17.12

Open the chart page →

1,800
apm-serverkube-opsVerified publisher0.1.21 of 1See more

apm-server kube-ops 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
elastic/apm-server:7.17.6c7a1c63257d0
stdlib@go1.18.2
1.17.12

Open the chart page →

7,208
lokikube-opsVerified publisher1.7.31 of 1See more

loki kube-ops 1.7.3

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
quay.io/kube-ops/loki:2.2.14fbd63194674
stdlib@go1.15.3
1.17.12

Open the chart page →

2,653
promtailkube-opsVerified publisher1.5.11 of 2See more

promtail kube-ops 1.5.1

1 of the 2 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
quay.io/kube-ops/promtail:2.2.134de6387233b
stdlib@go1.15.3
1.17.12

Open the chart page →

4,157
kubernetesweeklykubernetesweekly2.1.01 of 1See more

kubernetesweekly kubernetesweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
zufardhiyaulhaq/kubernetesweekly:v2.1.0a287ada277c6
stdlib@go1.16.15
1.17.12

Open the chart page →

1,489
api-serverkubeshop0.11.161 of 2See more

api-server kubeshop 0.11.16

1 of the 2 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
kubeshop/testkube-api-server:0.11.160ad97f07a78b
stdlib@go1.17.8
1.17.12

Open the chart page →

3,432
apisix-dashboardkubesphereVerified publisher0.3.01 of 1See more

apisix-dashboard kubesphere 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
apache/apisix-dashboard:2.9.0c010ea7d1694
stdlib@go1.14.15
1.17.12

Open the chart page →

2,525
apisix-ingress-controllerkubesphereVerified publisher0.8.01 of 2See more

apisix-ingress-controller kubesphere 0.8.0

1 of the 2 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
apache/apisix-ingress-controller:1.3.0412f92cde0b3
stdlib@go1.13.8
1.17.12

Open the chart page →

2,409
fluentbit-operatorkubesphereVerified publisher0.1.01 of 2See more

fluentbit-operator kubesphere 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-30633.

Container imageDigestPackageFixed in
kubesphere/fluentbit-operator:v0.9.0b87db3c57cb3
stdlib@go1.13.15
1.17.12

Open the chart page →

2,902

Container images carrying it

1,218 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
stdlib@go1.18.3
1.17.12
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
stdlib@go1.18.2
1.17.12
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
stdlib@go1.18.2
1.17.12
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
stdlib@go1.18.2
1.17.12
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
stdlib@go1.18.2
1.17.12
1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
stdlib@go1.18
1.17.12
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
stdlib@go1.18
1.17.12
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.17.12
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
stdlib@go1.18
1.17.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
stdlib@go1.18
1.17.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.17.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.17.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.17.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.17.12
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.17.12
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.17.12
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.17.12
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.17.12
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.