StackRadar

CVE-2022-31090

High

Advisory

Published 21 Jun 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.020
79th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
82
of 17,781 indexed, latest versions
Container images
72
deployed by those charts
Fix available
1 of 1
affected package

CURLOPT_HTTPAUTH option not cleared on change of origin

Carried by container images the latest versions of 82 of 17,781 indexed charts deploy, on 72 images.

Affected packageAffected versionsFixed inImages
guzzlehttp/guzzlecomposer5.3.4, 6.3.0, 6.3.3, 6.5.3+7 more6.5.8, 7.4.572
OSV records
GHSA-25mq-v84q-4j7r

Charts affected

82 by stars
ChartLatestAffected imagesRadar Score
cachetdeliveryheroVerified publisher1.3.51 of 2See more

cachet deliveryhero 1.3.5

1 of the 2 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
guzzlehttp/guzzle@6.3.3
6.5.8

Open the chart page →

1,896
laravelrenoki-co1.0.01 of 2See more

laravel renoki-co 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
guzzlehttp/guzzle@7.3.0
7.4.5

Open the chart page →

6,931
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,052
brpservicebrpservice1.1.01 of 4See more

brpservice brpservice 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,830
contactcataloguscontact-catalogus1.0.01 of 3See more

contactcatalogus contact-catalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,303
prometheus-sentry-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-sentry-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ujamii/prometheus-sentry-exporter:0.5.06243197349e1
guzzlehttp/guzzle@6.3.3
6.5.8

Open the chart page →

2,474
digispoof-interfacedigispoof-interface1.0.01 of 3See more

digispoof-interface digispoof-interface 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,779
firefly-iiigeek-cookbookVerified publisher0.3.01 of 1See more

firefly-iii geek-cookbook 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
fireflyiii/core:version-5.6.142f4283bd0cf7
guzzlehttp/guzzle@7.4.1
7.4.5

Open the chart page →

2,076
monicageek-cookbookVerified publisher8.2.01 of 1See more

monica geek-cookbook 8.2.0

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
library/monica:3.7.0-apacheceb1ba4196ab
guzzlehttp/guzzle@7.4.1
7.4.5

Open the chart page →

2,096
shlinkgeek-cookbookVerified publisher5.2.01 of 1See more

shlink geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
shlinkio/shlink:2.7.1c6729db1d3a8
guzzlehttp/guzzle@7.3.0
7.4.5

Open the chart page →

2,056
webtreesgeek-cookbookVerified publisher2.2.01 of 1See more

webtrees geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

3,646
landelijketabellencataloguslandelijketabellencatalogus1.0.01 of 3See more

landelijketabellencatalogus landelijketabellencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,510
librenmsmidokura-communityVerified publisher0.3.21 of 6See more

librenms midokura-community 0.3.2

1 of the 6 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
librenms/librenms:22.4.14f1f3d667cc7
guzzlehttp/guzzle@7.4.1
7.4.5

Open the chart page →

8,967
laravel-octanerenoki-co1.0.01 of 1See more

laravel-octane renoki-co 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:octane-0.6.0cad83090c58f
guzzlehttp/guzzle@7.3.0
7.4.5

Open the chart page →

3,634
repmanrepman-helmchartVerified publisher1.0.121 of 3See more

repman repman-helmchart 1.0.12

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

3,596
user-componentuser-component1.2.01 of 4See more

user-component user-component 1.2.0

1 of the 4 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,303
waardepapierenwaardepapieren1.0.01 of 3See more

waardepapieren waardepapieren 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

8,079
waardepapieren-baliewaardepapieren-balie1.0.01 of 3See more

waardepapieren-balie waardepapieren-balie 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,871
waardepapieren-registerwaardepapieren-register1.1.01 of 4See more

waardepapieren-register waardepapieren-register 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,429
cachetadnoctemVerified publisher0.3.31 of 2See more

cachet adnoctem 0.3.3

1 of the 2 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
guzzlehttp/guzzle@6.3.3
6.5.8

Open the chart page →

1,896
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,447
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,209
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,561
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
conduction/balance-registration-php:devc36094a41369
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

8,408
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,342
drupalcetic0.1.01 of 1See more

drupal cetic 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
library/drupal:8-apache8a1a3ee83899
guzzlehttp/guzzle@6.5.4
6.5.8

Open the chart page →

2,504
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

8,408
nextcloudcloudve1.13.01 of 2See more

nextcloud cloudve 1.13.0

1 of the 2 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
library/nextcloud:17.0.0-apache96104cb965fc
guzzlehttp/guzzle@6.3.3
6.5.8

Open the chart page →

3,016
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
guzzlehttp/guzzle@6.5.3
6.5.8

Open the chart page →

7,572
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

12,907
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,209
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

8,408
mauticdevtron0.1.31 of 3See more

mautic devtron 0.1.3

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
guzzlehttp/guzzle@6.3.0
6.5.8

Open the chart page →

2,939
mauticdevtron-labs0.1.31 of 3See more

mautic devtron-labs 0.1.3

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
mautic/mautic:2.13-apachea954c5868d76
guzzlehttp/guzzle@6.3.0
6.5.8

Open the chart page →

2,939
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

8,408
eav-componenteav-component1.0.01 of 3See more

eav-component eav-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,255
education-componenteducation-component1.0.01 of 3See more

education-component education-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,327
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,510
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
guzzlehttp/guzzle@7.4.2
7.4.5

Open the chart page →

20,933
bookstackgeek-cookbookVerified publisher5.2.01 of 1See more

bookstack geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
guzzlehttp/guzzle@7.4.1
7.4.5

Open the chart page →

1,269
grocygeek-cookbookVerified publisher8.5.21 of 1See more

grocy geek-cookbook 8.5.2

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
linuxserver/grocy:version-v3.1.3291296e66c2a
guzzlehttp/guzzle@7.4.0
7.4.5

Open the chart page →

1,043
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

9,077
lycheegeek-cookbookVerified publisher6.4.21 of 1See more

lychee geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
lycheeorg/lychee-laravel:v4.3.0308c0e6231da
guzzlehttp/guzzle@7.3.0
7.4.5

Open the chart page →

601
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
guzzlehttp/guzzle@7.4.1
7.4.5

Open the chart page →

8,392
wallabaggeek-cookbookVerified publisher7.2.01 of 1See more

wallabag geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
wallabag/wallabag:2.4.25e4c26a7fb4a
guzzlehttp/guzzle@5.3.4
6.5.8

Open the chart page →

4,358
xbackbonegeek-cookbookVerified publisher5.4.21 of 1See more

xbackbone geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
pe46dro/xbackbone-docker:3.3.309dfe3aa10f6
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

1,655
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
guzzlehttp/guzzle@6.5.5
6.5.8

Open the chart page →

7,510
cachethelm-charts-nr1.3.51 of 2See more

cachet helm-charts-nr 1.3.5

1 of the 2 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
cachethq/docker:2.3.15a61ff0f67ea7
guzzlehttp/guzzle@6.3.3
6.5.8

Open the chart page →

1,896
prometheus-sentry-exporterhelm-charts-nr0.1.51 of 1See more

prometheus-sentry-exporter helm-charts-nr 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
ujamii/prometheus-sentry-exporter:0.5.06243197349e1
guzzlehttp/guzzle@6.3.3
6.5.8

Open the chart page →

2,474
wallabaghelmforgeVerified publisher1.3.61 of 3See more

wallabag helmforge 1.3.6

1 of the 3 container images this version deploys carry CVE-2022-31090.

Container imageDigestPackageFixed in
wallabag/wallabag:2.6.144a527e027e0d
guzzlehttp/guzzle@5.3.4
6.5.8

Open the chart page →

2,762

Container images carrying it

72 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/review-component-php:latestafe623824b82
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/linuxserver/bookstack:version-v21.12f05447347ff1
guzzlehttp/guzzle@7.4.1
7.4.5
1
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
guzzlehttp/guzzle@6.5.5
6.5.8
1
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
guzzlehttp/guzzle@7.2.0
7.4.5
1
ghcr.io/wbstack/quickstatements:1.3.588423e422ea8
guzzlehttp/guzzle@7.4.0
7.4.5
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
guzzlehttp/guzzle@7.4.2
7.4.5
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
guzzlehttp/guzzle@7.3.0
7.4.5
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
guzzlehttp/guzzle@7.3.0
7.4.5
1
quay.io/renokico/laravel-helm-demo:octane-0.6.0cad83090c58f
guzzlehttp/guzzle@7.3.0
7.4.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.