StackRadar

CVE-2022-31684

Medium

Advisory

Published 20 Oct 2022In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
19
of 17,781 indexed, latest versions
Container images
24
deployed by those charts
Fix available
1 of 1
affected package

Invalid HTTP requests in Reactor Netty HTTP Server may reveal access tokens

Carried by container images the latest versions of 19 of 17,781 indexed charts deploy, on 24 images.

Affected packageAffected versionsFixed inImages
reactor-netty-httpmaven1.0.11, 1.0.13, 1.0.14, 1.0.15+5 more1.0.2424
OSV records
GHSA-7w4x-4h67-pgmv

Charts affected

19 by stars
ChartLatestAffected imagesRadar Score
pitchforkexpediagroup0.1.41 of 1See more

pitchfork expediagroup 0.1.4

1 of the 1 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
expediagroup/pitchfork:1.314f2cf61e7de9
reactor-netty-http@1.0.11
1.0.24

Open the chart page →

3,309
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
zbalogh/reservation-api-server:1.0.97c247e399a1f
reactor-netty-http@1.0.23
1.0.24

Open the chart page →

6,639
dshackledysnixVerified publisher0.1.11 of 2See more

dshackle dysnix 0.1.1

1 of the 2 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.12ac2a4bc66ab6
reactor-netty-http@1.0.11
1.0.24

Open the chart page →

2,237
dshackleethereum-helm-chartsVerified publisher0.1.91 of 2See more

dshackle ethereum-helm-charts 0.1.9

1 of the 2 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
emeraldpay/dshackle:0.14.0126f0ae0b388
reactor-netty-http@1.0.11
1.0.24

Open the chart page →

2,021
scorpio-brokerfiware0.3.39 of 10See more

scorpio-broker fiware 0.3.3

9 of the 10 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
reactor-netty-http@1.0.13
1.0.24

Open the chart page →

55,600
scorpiobrokerfiware0.1.29 of 10See more

scorpiobroker fiware 0.1.2

9 of the 10 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
reactor-netty-http@1.0.13
1.0.24
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
reactor-netty-http@1.0.13
1.0.24

Open the chart page →

55,600
scorpio-broker-aaiofiware0.4.151 of 1See more

scorpio-broker-aaio fiware 0.4.15

1 of the 1 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
reactor-netty-http@1.0.13
1.0.24

Open the chart page →

5,286
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
apache/skywalking-ui:9.2.0295f1dc87d98
reactor-netty-http@1.0.18
1.0.24

Open the chart page →

16,401
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
hugohg34/toposervice:0.0.2812a03b3f274
reactor-netty-http@1.0.13
1.0.24

Open the chart page →

29,588
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
reactor-netty-http@1.0.20
1.0.24

Open the chart page →

6,852
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
reactor-netty-http@1.0.17
1.0.24

Open the chart page →

11,738
authentication-serviceredestroyder0.2.21 of 1See more

authentication-service redestroyder 0.2.2

1 of the 1 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
redestroyder/authorization-service:0.0.1740364a619fd
reactor-netty-http@1.0.15
1.0.24

Open the chart page →

2,583
business-serviceredestroyder0.2.11 of 1See more

business-service redestroyder 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
redestroyder/business-service:0.0.1db03499a0726
reactor-netty-http@1.0.15
1.0.24

Open the chart page →

2,600
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
reactor-netty-http@1.0.19
1.0.24

Open the chart page →

16,101
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
reactor-netty-http@1.0.19
1.0.24

Open the chart page →

8,033
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
reactor-netty-http@1.0.19
1.0.24

Open the chart page →

8,804
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
reactor-netty-http@1.0.14
1.0.24

Open the chart page →

13,767
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
reactor-netty-http@1.0.15
1.0.24

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2022-31684.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
reactor-netty-http@1.0.15
1.0.24

Open the chart page →

28,605

Container images carrying it

24 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hookiesolutions/webhookie:latest0629694246ba
reactor-netty-http@1.0.15
1.0.24
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
reactor-netty-http@1.0.13
1.0.24
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
reactor-netty-http@1.0.13
1.0.24
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
reactor-netty-http@1.0.13
1.0.24
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
reactor-netty-http@1.0.13
1.0.24
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
reactor-netty-http@1.0.13
1.0.24
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
reactor-netty-http@1.0.13
1.0.24
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
reactor-netty-http@1.0.13
1.0.24
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
reactor-netty-http@1.0.13
1.0.24
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
reactor-netty-http@1.0.13
1.0.24
2
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
reactor-netty-http@1.0.19
1.0.24
2
apache/shenyu-bootstrap:2.5.11bd5756f6273
reactor-netty-http@1.0.19
1.0.24
1
apache/skywalking-ui:9.2.0295f1dc87d98
reactor-netty-http@1.0.18
1.0.24
1
emeraldpay/dshackle:0.14.0126f0ae0b388
reactor-netty-http@1.0.11
1.0.24
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
reactor-netty-http@1.0.11
1.0.24
1
expediagroup/pitchfork:1.314f2cf61e7de9
reactor-netty-http@1.0.11
1.0.24
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
reactor-netty-http@1.0.17
1.0.24
1
hugohg34/toposervice:0.0.2812a03b3f274
reactor-netty-http@1.0.13
1.0.24
1
redestroyder/authorization-service:0.0.1740364a619fd
reactor-netty-http@1.0.15
1.0.24
1
redestroyder/business-service:0.0.1db03499a0726
reactor-netty-http@1.0.15
1.0.24
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
reactor-netty-http@1.0.13
1.0.24
1
trinodb/trino:405ee80ab5eeab2
reactor-netty-http@1.0.14
1.0.24
1
vlebediantsev/logic-ms:latestdf8bf38c535b
reactor-netty-http@1.0.20
1.0.24
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
reactor-netty-http@1.0.23
1.0.24
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.