StackRadar

CVE-2022-3171

High

Advisory

Published 4 Oct 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.011
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
211
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
4 of 5
affected packages

protobuf-java has a potential Denial of Service issue

Carried by container images the latest versions of 211 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
protobufdeb2.6.1-1.3, 3.0.0-9, 3.0.0-9.1ubuntu1, 3.0.0-9.1ubuntu1.1+3 moreno fix listed15
protobuf-javamaven2.4.1, 2.5.0, 2.6.0, 2.6.1+39 more3.16.3, 3.19.6, 3.20.3, 3.21.7186
google-protobufgem3.8.03.16.34
protobuf-javalitemaven3.11.4, 3.18.0, 3.19.43.16.3, 3.19.64
protobuf-kotlinmaven3.19.43.19.63
OSV records
UBUNTU-CVE-2022-3171GHSA-h4h5-3hr4-j3g2

Charts affected

211 by stars
ChartLatestAffected imagesRadar Score
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
torrespro/mca-worker:2.0.06d3bd305a1ba
protobuf-java@3.10.0
3.16.3

Open the chart page →

19,187
metabasemetabase-helmVerified publisher2.7.11 of 1See more

metabase metabase-helm 2.7.1

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
metabase/metabase:v0.46.09ebdc664a6b2
protobuf-java@3.17.3
3.19.6

Open the chart page →

2,221
hadoopmiuler1.2.21 of 1See more

hadoop miuler 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
protobuf-java@2.5.0
3.16.3

Open the chart page →

5,772
glowrootnovum-rgi-charts1.0.101 of 2See more

glowroot novum-rgi-charts 1.0.10

1 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
novumrgi/glowroot-central:0.14.0-beta.38c54790675b1
protobuf-java@3.19.4
3.19.6

Open the chart page →

2,308
data-prepperopensearch-project-helm-chartsVerified publisher0.3.11 of 1See more

data-prepper opensearch-project-helm-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
opensearchproject/data-prepper:2.8.057c25fa01d3c
protobuf-java@3.7.1
3.16.3

Open the chart page →

1,692
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.0332c6d416808
protobuf-java@3.14.0
3.16.3

Open the chart page →

31,844
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
zbalogh/reservation-api-server:1.0.97c247e399a1f
protobuf-java@3.11.0
3.16.3

Open the chart page →

6,639
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
rm3l/dev-feed-api:latest9a7f732245a3
protobuf-java@3.19.4
3.19.6

Open the chart page →

9,837
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
protobuf-java@3.9.0
3.16.3

Open the chart page →

10,120
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
protobuf-java@3.16.1
3.16.3

Open the chart page →

6,045
routrroutr0.0.101 of 2See more

routr routr 0.0.10

1 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
fonoster/routr:1.0.0-rc52ca65af17cbc
protobuf-java@3.6.1
3.16.3

Open the chart page →

4,983
seldon-coreseldon0.2.72 of 3See more

seldon-core seldon 0.2.7

2 of the 3 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
seldonio/apife:0.2.7ba81b17f00eb
protobuf-java@3.2.0
3.16.3
seldonio/cluster-manager:0.2.729e362bb1ba2
protobuf-java@3.6.1
3.16.3

Open the chart page →

13,798
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
protobuf-java@3.21.2
3.21.7

Open the chart page →

13,486
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
protobuf-java@3.11.0
3.16.3

Open the chart page →

24,930
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
protobuf-java@3.4.0
3.16.3

Open the chart page →

8,063
snowplowt3n0.0.11 of 1See more

snowplow t3n 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
snowplow/scala-stream-collector-pubsub:2.2.041d318841516
protobuf-java@3.12.2
3.16.3

Open the chart page →

2,269
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
protobuf-java@3.11.0
3.16.3

Open the chart page →

15,970
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
protobuf-java@3.3.0
3.16.3

Open the chart page →

7,835
accountaccount-serviceVerified publisher0.4.21 of 1See more

account account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
vitalii1992/account-service:latest0e694d94551d
protobuf-java@3.19.4
protobuf-kotlin@3.19.4
3.19.6
3.19.6

Open the chart page →

2,168
gatewayaccount-serviceVerified publisher0.4.21 of 1See more

gateway account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
vitalii1992/api-gateway-service:latestaabe6ac39356
protobuf-java@3.19.4
protobuf-kotlin@3.19.4
3.19.6
3.19.6

Open the chart page →

2,853
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
protobuf-java@3.19.2
3.19.6

Open the chart page →

7,713
orderaccount-serviceVerified publisher0.4.21 of 1See more

order account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
vitalii1992/order-service:latest07c4a8833ce4
protobuf-java@3.19.4
protobuf-kotlin@3.19.4
3.19.6
3.19.6

Open the chart page →

2,221
airbyte-cronairbyteVerified publisher0.40.371 of 1See more

airbyte-cron airbyte 0.40.37

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
airbyte/cron:0.40.17caf4f551c546
protobuf-java@3.21.6
3.21.7

Open the chart page →

1,413
akto-protectionakto0.1.01 of 4See more

akto-protection akto 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
aktosecurity/akto-api-protection:localbcd7382c9c1b
protobuf-java@3.21.5
3.21.7

Open the chart page →

11,285
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
protobuf-java@3.21.5
3.21.7

Open the chart page →

4,880
mautrix-signalalexanderbadel0.1.11 of 2See more

mautrix-signal alexanderbadel 0.1.1

1 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
signald/signald:0.18.20ffad7ccc2eb
protobuf-javalite@3.19.4
3.19.6

Open the chart page →

2,099
amorphieamorphie0.1.21 of 18See more

amorphie amorphie 0.1.2

1 of the 18 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.3.18fe26efde8e1
protobuf-java@3.7.1
3.16.3

Open the chart page →

28,131
d.vazquezm.2021_helmapphelmVerified publisher1.0.01 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

1 of the 6 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
protobuf-java@3.10.0
3.16.3

Open the chart page →

19,745
inbox-server-distributedappscodeVerified publisher2025.12.251 of 4See more

inbox-server-distributed appscode 2025.12.25

1 of the 4 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
protobuf-java@3.19.2
3.19.6

Open the chart page →

15,573
james-komposeappscodeVerified publisher0.1.01 of 4See more

james-kompose appscode 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.1.04254021a8c71
protobuf-java@3.19.2
3.19.6

Open the chart page →

16,975
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
protobuf-java@2.5.0
3.16.3

Open the chart page →

8,866
automatedconfigurationassist-iot-automated-configuration1.0.01 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

1 of the 5 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
assistiot/automated_configuration:latest23f195a7a26a
protobuf-java@3.7.0
3.16.3

Open the chart page →

14,728
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
protobuf-java@3.19.2
3.19.6

Open the chart page →

13,352
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
protobuf@3.6.1.3-2ubuntu5.2
no fix listed

Open the chart page →

13,913
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
protobuf-java@3.21.5
3.21.7

Open the chart page →

9,412
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
protobuf-java@3.19.4
3.19.6

Open the chart page →

9,722
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
protobuf-java@3.11.0
3.16.3

Open the chart page →

5,806
firehoseblip-firehoseVerified publisher0.0.181 of 11See more

firehose blip-firehose 0.0.18

1 of the 11 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
protobuf-java@3.19.1
3.19.6

Open the chart page →

13,459
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
protobuf@3.0.0-9.1ubuntu1.1
no fix listed

Open the chart page →

12,779
riemanncloudnativeapp0.1.21 of 1See more

riemann cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
raykrueger/riemann:0.2.14c8baf3de57bb
protobuf-java@2.6.1
3.16.3

Open the chart page →

6,497
rundeckcloudnativeapp0.1.01 of 2See more

rundeck cloudnativeapp 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
rundeck/rundeck:3.0.16b13e8059ad72
protobuf-java@3.5.1
3.16.3

Open the chart page →

23,665
spark-history-servercloudnativeapp1.0.01 of 3See more

spark-history-server cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
lightbend/spark-history-server:2.4.00bedf37f428a
protobuf-java@2.5.0
3.16.3

Open the chart page →

14,066
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
protobuf-java@3.6.1
3.16.3

Open the chart page →

22,442
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
protobuf@2.6.1-1.3
protobuf-java@2.5.0
no fix listed
3.16.3

Open the chart page →

77,758
dependency-trackcnieg3.0.81 of 2See more

dependency-track cnieg 3.0.8

1 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
dependencytrack/apiserver:4.6.3485ac0952c02
protobuf-java@3.19.4
3.19.6

Open the chart page →

2,503
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
protobuf-java@3.5.1
3.16.3
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
protobuf-java@2.4.1
3.16.3

Open the chart page →

16,860
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
protobuf-java@3.19.4
3.19.6

Open the chart page →

7,963
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
protobuf-java@3.19.4
3.19.6

Open the chart page →

7,963
cp-helm-chartscp-helm-charts0.6.16 of 8See more

cp-helm-charts cp-helm-charts 0.6.1

6 of the 8 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
protobuf-java@3.11.4
3.16.3
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
protobuf-java@3.11.4
3.16.3
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
protobuf-java@3.11.4
3.16.3
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
protobuf-java@3.11.4
3.16.3
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
protobuf-java@3.11.4
3.16.3
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
protobuf-java@3.11.4
3.16.3

Open the chart page →

58,857
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-3171.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
protobuf-java@2.5.0
3.16.3

Open the chart page →

8,245

Container images carrying it

206 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/star-whale/server:0.6.158368359c8dd0
protobuf-java@3.21.2
3.21.7
1
ghcr.io/streamingfast/substreams-sink-kv:v2.3.026953ec68d5d
protobuf@3.6.1.3-2ubuntu5.2
no fix listed
1
ghcr.io/streamingfast/substreams-sink-noop:v1.4.0d7c43c3135c6
protobuf@3.6.1.3-2ubuntu5.2
no fix listed
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
protobuf-java@3.7.1
3.16.3
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
protobuf-java@3.19.3
protobuf-javalite@3.18.0
3.19.6
3.19.6
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
protobuf-java@3.12.2
3.16.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.