StackRadar

CVE-2022-3064

High

Advisory

Published 29 Aug 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
55
of 17,781 indexed, latest versions
Container images
33
deployed by those charts
Fix available
1 of 1
affected package

yaml package for Go can consume excessive amounts of CPU or memory

Carried by container images the latest versions of 55 of 17,781 indexed charts deploy, on 33 images.

Affected packageAffected versionsFixed inImages
gopkg.in/yaml.v2golangv2.0.0-20170712054546-1be3d31502d6, v2.0.0-20170812160011-eb3733d160e7, v2.0.0-20190319135612-7b8349ac747c, v2.2.1+2 more2.2.433
OSV records
GHSA-6q6q-88xp-6f2r
Also known as
GO-2022-0956

Charts affected

55 by stars
ChartLatestAffected imagesRadar Score
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2022-3064.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
gopkg.in/yaml.v2@v2.2.2
2.2.4

Open the chart page →

8,484
monitorortrozz0.0.11 of 1See more

monitoror trozz 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-3064.

Container imageDigestPackageFixed in
monitoror/monitoror:44b88edcf51ff
gopkg.in/yaml.v2@v2.2.2
2.2.4

Open the chart page →

3,109
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-3064.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.4

Open the chart page →

2,030
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-3064.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
gopkg.in/yaml.v2@v2.2.2
2.2.4

Open the chart page →

22,665
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2022-3064.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/yaml.v2@v2.2.2
2.2.4

Open the chart page →

2,791

Container images carrying it

33 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
prom/alertmanager:v0.20.07e4e9f7a0954
gopkg.in/yaml.v2@v2.2.2
2.2.4
5
prom/prometheus:v2.13.10a8caa2e9f19
gopkg.in/yaml.v2@v2.2.2
2.2.4
5
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/yaml.v2@v2.2.2
2.2.4
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
gopkg.in/yaml.v2@v2.2.2
2.2.4
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
gopkg.in/yaml.v2@v2.2.2
2.2.4
3
cesanta/docker_auth:1.6.04d16885f3d4c
gopkg.in/yaml.v2@v2.2.2
2.2.4
2
crate/crate_adapter:latestb8d89fa5d19b
gopkg.in/yaml.v2@v2.2.3
2.2.4
2
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
gopkg.in/yaml.v2@v2.2.2
2.2.4
2
natsio/nats-box:0.11.09fbf7bf684e4
gopkg.in/yaml.v2@v2.2.2
2.2.4
2
pottava/s3-proxy:2.020a0bcb15f76
gopkg.in/yaml.v2@v2.2.2
2.2.4
2
weblate/weblate:4.2.2-169c160d37a3c
gopkg.in/yaml.v2@v2.2.1
2.2.4
2
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
gopkg.in/yaml.v2@v2.2.2
2.2.4
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.4
2
almir/webhook:2.8.01698346f6077
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.4
1
codercom/code-server:4.11.0-debian1e2cc688008e
gopkg.in/yaml.v2@v2.2.1
2.2.4
1
codercom/code-server:3.10.247605610ad8d
gopkg.in/yaml.v2@v2.2.1
2.2.4
1
drone/drone-runner-docker:1.8.1137e79c5e23c
gopkg.in/yaml.v2@v2.2.2
2.2.4
1
drone/kubernetes-secrets:latest206df2280ecf
gopkg.in/yaml.v2@v2.2.1
2.2.4
1
ianw/quickchart:v1.7.1dc49dd460c37
gopkg.in/yaml.v2@v2.2.2
2.2.4
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
gopkg.in/yaml.v2@v2.2.2
2.2.4
1
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
gopkg.in/yaml.v2@v2.2.2
2.2.4
1
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
gopkg.in/yaml.v2@v2.2.2
2.2.4
1
monitoror/monitoror:44b88edcf51ff
gopkg.in/yaml.v2@v2.2.2
2.2.4
1
oxynozeta/prometheus-cachethq:1.1.131f11669d597
gopkg.in/yaml.v2@v2.2.2
2.2.4
1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
gopkg.in/yaml.v2@v2.0.0-20170712054546-1be3d31502d6
2.2.4
1
softonic/preemptible-killer:1.2.6-294b87f1fb362
gopkg.in/yaml.v2@v2.2.1
2.2.4
1
weaveworks/flagger:0.19.0a9c2e9df4227
gopkg.in/yaml.v2@v2.2.2
2.2.4
1
weblate/weblate:3.11.3-182848df56ecd
gopkg.in/yaml.v2@v2.0.0-20190319135612-7b8349ac747c
2.2.4
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
gopkg.in/yaml.v2@v2.2.2
2.2.4
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
gopkg.in/yaml.v2@v2.2.2
2.2.4
1
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
gopkg.in/yaml.v2@v2.2.2
2.2.4
1
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.4
1
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
gopkg.in/yaml.v2@v2.2.2
2.2.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.