StackRadar

CVE-2022-36087

Medium

Advisory

Published 9 Sept 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
75th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
66
of 17,781 indexed, latest versions
Container images
62
deployed by those charts
Fix available
2 of 2
affected packages

OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI

Carried by container images the latest versions of 66 of 17,781 indexed charts deploy, on 62 images.

Affected packageAffected versionsFixed inImages
python-oauthlibdeb3.2.0-13.2.0-1ubuntu0.11
oauthlibpypi3.1.1, 3.2.0, 3.2.13.2.262
OSV records
GHSA-3pgj-pg6c-r5p7UBUNTU-CVE-2022-36087
Also known as
PYSEC-2022-269, USN-5632-1

Charts affected

66 by stars
ChartLatestAffected imagesRadar Score
rook-cephrookOfficialVerified publisher1.20.71 of 2See more

rook-ceph rook 1.20.7

1 of the 2 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
rook/ceph:v1.20.72f970c425617
oauthlib@3.1.1
3.2.2

Open the chart page →

1,447
ceph-csi-cephfsceph-csiOfficialVerified publisher3.17.11 of 6See more

ceph-csi-cephfs ceph-csi 3.17.1

1 of the 6 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
oauthlib@3.1.1
3.2.2

Open the chart page →

4,061
ceph-csi-rbdceph-csiOfficialVerified publisher3.17.11 of 6See more

ceph-csi-rbd ceph-csi 3.17.1

1 of the 6 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
oauthlib@3.1.1
3.2.2

Open the chart page →

4,061
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
oauthlib@3.2.0
3.2.2

Open the chart page →

9,145
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
oauthlib@3.2.0
3.2.2

Open the chart page →

7,705
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
oauthlib@3.2.0
3.2.2

Open the chart page →

27,267
kubeflowkubeflow1.6.25 of 45See more

kubeflow kubeflow 1.6.2

5 of the 45 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
kserve/models-web-app:v0.8.063ea05e73842
oauthlib@3.2.0
3.2.2
kubeflownotebookswg/jupyter-web-app:v1.6.1d762690e21c1
oauthlib@3.2.1
3.2.2
kubeflownotebookswg/tensorboards-web-app:v1.6.10876fef1973b
oauthlib@3.2.1
3.2.2
kubeflownotebookswg/volumes-web-app:v1.6.17299fa94db15
oauthlib@3.2.1
3.2.2
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
oauthlib@3.1.1
3.2.2

Open the chart page →

96,941
clustersecretpatrungel0.2.01 of 1See more

clustersecret patrungel 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
flag5/clustersecret:0.0.94ad5748bfcc6
oauthlib@3.1.1
3.2.2

Open the chart page →

1,841
taigarc-helm-charts0.1.01 of 7See more

taiga rc-helm-charts 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
taigaio/taiga-back:6.4.29f97323cc150
oauthlib@3.1.1
3.2.2

Open the chart page →

7,255
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
oauthlib@3.2.0
3.2.2

Open the chart page →

7,579
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
oauthlib@3.2.0
3.2.2
kobotoolbox/kpi:2.022.24dbcacc01bccd4
oauthlib@3.2.0
3.2.2

Open the chart page →

18,517
cnpg-sandboxcloudnative-pgVerified publisher0.6.11 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

1 of the 6 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.15.1a25886092fa4
oauthlib@3.1.1
3.2.2

Open the chart page →

7,583
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
oauthlib@3.2.0
3.2.2

Open the chart page →

10,858
lazylibrariangeek-cookbookVerified publisher7.4.21 of 1See more

lazylibrarian geek-cookbook 7.4.2

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
linuxserver/lazylibrarian:version-1152df82f93d2560e233
oauthlib@3.1.1
3.2.2

Open the chart page →

11,662
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
oauthlib@3.1.1
3.2.2

Open the chart page →

7,801
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
oauthlib@3.1.1
3.2.2

Open the chart page →

10,231
traefik-whitelist-ddnskubitodevVerified publisher1.0.51 of 1See more

traefik-whitelist-ddns kubitodev 1.0.5

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
kubitodev/traefik-ip-whitelist-sync:1.0.2aa24869319bf
oauthlib@3.2.0
3.2.2

Open the chart page →

936
pvc-exporterpvc-exporter0.1.31 of 1See more

pvc-exporter pvc-exporter 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
dockerid31415926/pvc-exporter:v0.1.35a1dd17e0e07
oauthlib@3.1.1
3.2.2

Open the chart page →

1,762
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg16d7db8f1085a3
oauthlib@3.2.0
3.2.2

Open the chart page →

12,930
pgadminarunalakmalVerified publisher0.1.01 of 1See more

pgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
oauthlib@3.2.0
3.2.2

Open the chart page →

2,418
swdpgadminarunalakmalVerified publisher0.1.01 of 1See more

swdpgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
oauthlib@3.2.0
3.2.2

Open the chart page →

2,418
itera-lmaarzu1.34.601 of 6See more

itera-lma arzu 1.34.60

1 of the 6 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.19.26a8671702d6f
oauthlib@3.2.0
3.2.2

Open the chart page →

8,608
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
oauthlib@3.2.0
3.2.2

Open the chart page →

10,061
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
oauthlib@3.2.0
3.2.2

Open the chart page →

32,501
shynetatrox0.1.11 of 1See more

shynet atrox 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.12.0e821e31140f7
oauthlib@3.1.1
3.2.2

Open the chart page →

5,507
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/k8s-sidecar:ignore-initial-events7f583a36a764
oauthlib@3.2.1
3.2.2

Open the chart page →

5,074
pvc-exporterbalihb-pvc-exporterVerified publisher0.2.41 of 2See more

pvc-exporter balihb-pvc-exporter 0.2.4

1 of the 2 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
oauthlib@3.1.1
3.2.2

Open the chart page →

2,765
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
oauthlib@3.2.0
3.2.2

Open the chart page →

20,900
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
oauthlib@3.2.0
3.2.2

Open the chart page →

6,695
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
oauthlib@3.2.0
3.2.2

Open the chart page →

6,921
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
oauthlib@3.1.1
3.2.2

Open the chart page →

12,457
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
oauthlib@3.1.1
3.2.2

Open the chart page →

12,131
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
oauthlib@3.1.1
3.2.2

Open the chart page →

11,592
galaxykubemancloudve2.10.11 of 7See more

galaxykubeman cloudve 2.10.1

1 of the 7 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
oauthlib@3.2.1
3.2.2

Open the chart page →

16,069
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
kfserving/models-web-app:v0.6.1f322d6ffdfa3
oauthlib@3.1.1
3.2.2

Open the chart page →

3,830
kube-openid-connectdevopstalesVerified publisher1.1.01 of 1See more

kube-openid-connect devopstales 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
devopstales/kube-openid-connector:1.042c40a0e9f1b
oauthlib@3.2.0
3.2.2

Open the chart page →

1,333
kube-prometheus-stackdevtron19.3.01 of 6See more

kube-prometheus-stack devtron 19.3.0

1 of the 6 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
oauthlib@3.1.1
3.2.2

Open the chart page →

8,645
kube-prometheus-stackdevtron-labs19.3.01 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

1 of the 6 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
oauthlib@3.1.1
3.2.2

Open the chart page →

8,645
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
oauthlib@3.2.0
3.2.2

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
python-oauthlib@3.2.0-1
oauthlib@3.2.0
3.2.0-1ubuntu0.1
3.2.2

Open the chart page →

30,699
drogue-cloud-metricsdrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.19.26a8671702d6f
oauthlib@3.2.0
3.2.2

Open the chart page →

13,558
rook-cephdtrdnk-helm-chartsVerified publisher0.0.11 of 2See more

rook-ceph dtrdnk-helm-charts 0.0.1

1 of the 2 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
rook/ceph:v1.19.2944a1dd70496
oauthlib@3.1.1
3.2.2

Open the chart page →

1,990
argocd-version-exporterevilmartians0.0.11 of 1See more

argocd-version-exporter evilmartians 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
oauthlib@3.1.1
3.2.2

Open the chart page →

2,401
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
oauthlib@3.1.1
3.2.2

Open the chart page →

1,150
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
oauthlib@3.1.1
3.2.2

Open the chart page →

16,123
changedetection-iogeek-cookbookVerified publisher1.5.21 of 1See more

changedetection-io geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
oauthlib@3.1.1
3.2.2

Open the chart page →

1,950
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
oauthlib@3.2.0
3.2.2

Open the chart page →

12,076
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
oauthlib@3.1.1
3.2.2

Open the chart page →

24,293
ldap-backupgluuVerified publisher1.6.111 of 1See more

ldap-backup gluu 1.6.11

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
gluufederation/opendj:4.3.0_011a1128b28b95
oauthlib@3.1.1
3.2.2

Open the chart page →

3,064
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:1.2.0e4770285aaf7
oauthlib@3.1.1
3.2.2

Open the chart page →

37,671

Container images carrying it

62 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
oauthlib@3.1.1
3.2.2
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
oauthlib@3.2.0
3.2.2
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
oauthlib@3.2.0
3.2.2
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
oauthlib@3.1.1
3.2.2
1
ghcr.io/kubeshop/k8s-sidecar:ignore-initial-events7f583a36a764
oauthlib@3.2.1
3.2.2
1
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
oauthlib@3.2.0
3.2.2
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
oauthlib@3.2.0
3.2.2
1
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
oauthlib@3.1.1
3.2.2
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
oauthlib@3.2.0
3.2.2
1
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
oauthlib@3.2.0
3.2.2
1
quay.io/kiwigrid/k8s-sidecar:1.15.1a25886092fa4
oauthlib@3.1.1
3.2.2
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
oauthlib@3.2.0
3.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.