StackRadar

CVE-2022-32149

High

Advisory

Published 11 Oct 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.015
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
958
of 17,790 indexed, latest versions
Container images
1,095
deployed by those charts
Fix available
1 of 1
affected package

golang.org/x/text/language Denial of service via crafted Accept-Language header

Carried by container images the latest versions of 958 of 17,790 indexed charts deploy, on 1,095 images.

Affected packageAffected versionsFixed inImages
golang.org/x/textgolangv0.3.0, v0.3.1-0.20180807135948-17ff2d5776d2, v0.3.1-0.20181227161524-e6919f6577db, v0.3.2+8 more0.3.81,095
OSV records
GHSA-69ch-w2m2-3vjp
Also known as
GO-2022-1059

Charts affected

958 by stars
ChartLatestAffected imagesRadar Score
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2022-32149.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/text@v0.3.0
0.3.8

Open the chart page →

2,791
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2022-32149.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/text@v0.3.7
0.3.8

Open the chart page →

2,512
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2022-32149.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
golang.org/x/text@v0.3.3
0.3.8

Open the chart page →

2,623
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2022-32149.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/text@v0.3.7
0.3.8

Open the chart page →

1,965
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2022-32149.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/text@v0.3.7
0.3.8
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/text@v0.3.7
0.3.8
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
golang.org/x/text@v0.3.5
0.3.8
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
golang.org/x/text@v0.3.5
0.3.8

Open the chart page →

7,998
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-32149.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/text@v0.3.3
0.3.8

Open the chart page →

3,024
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-32149.

Container imageDigestPackageFixed in
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/text@v0.3.2
0.3.8

Open the chart page →

5,047
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-32149.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
golang.org/x/text@v0.3.7
0.3.8

Open the chart page →

3,697

Container images carrying it

1,095 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/prometheus:v2.33.591100b06e86d
golang.org/x/text@v0.3.7
0.3.8
1
quay.io/prometheus/prometheus:v2.34.0b37103e03399
golang.org/x/text@v0.3.7
0.3.8
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
golang.org/x/text@v0.3.7
0.3.8
1
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
golang.org/x/text@v0.3.6
0.3.8
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
golang.org/x/text@v0.3.7
0.3.8
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
golang.org/x/text@v0.3.4
0.3.8
1
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/text@v0.3.3
0.3.8
1
quay.io/solo-io/certgen:0.0.0-forkb17a8c7d1f32
golang.org/x/text@v0.3.7
0.3.8
1
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
golang.org/x/text@v0.3.7
0.3.8
1
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
golang.org/x/text@v0.3.7
0.3.8
1
quay.io/solo-io/gloo-envoy-wrapper:0.0.0-fork26ae185e835a
golang.org/x/text@v0.3.7
0.3.8
1
quay.io/thanos/thanos:v0.17.1e362f02ed304
golang.org/x/text@v0.3.3
0.3.8
1
quay.io/tigera/operator:v1.20.1379efe0c2541
golang.org/x/text@v0.3.3
0.3.8
1
quay.io/tigera/operator:v1.15.1c6591da87aa8
golang.org/x/text@v0.3.3
0.3.8
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/text@v0.3.2
0.3.8
1
quay.io/uswitch/kiam:v4.0be3a5846922d
golang.org/x/text@v0.3.4
0.3.8
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.11826b984e75d4
golang.org/x/text@v0.3.7
0.3.8
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
golang.org/x/text@v0.3.6
0.3.8
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/text@v0.3.7
0.3.8
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
golang.org/x/text@v0.3.4
0.3.8
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
golang.org/x/text@v0.3.3
0.3.8
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
golang.org/x/text@v0.3.6
0.3.8
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/text@v0.3.4
0.3.8
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/text@v0.3.6
0.3.8
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
golang.org/x/text@v0.3.3
0.3.8
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/text@v0.3.6
0.3.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/text@v0.3.6
0.3.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/text@v0.3.7
0.3.8
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
golang.org/x/text@v0.3.4
0.3.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/text@v0.3.2
0.3.8
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/text@v0.3.6
0.3.8
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/text@v0.3.7
0.3.8
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.