StackRadar

CVE-2022-36087

Medium

Advisory

Published 9 Sept 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
75th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
66
of 17,781 indexed, latest versions
Container images
62
deployed by those charts
Fix available
2 of 2
affected packages

OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI

Carried by container images the latest versions of 66 of 17,781 indexed charts deploy, on 62 images.

Affected packageAffected versionsFixed inImages
python-oauthlibdeb3.2.0-13.2.0-1ubuntu0.11
oauthlibpypi3.1.1, 3.2.0, 3.2.13.2.262
OSV records
GHSA-3pgj-pg6c-r5p7UBUNTU-CVE-2022-36087
Also known as
PYSEC-2022-269, USN-5632-1

Charts affected

66 by stars
ChartLatestAffected imagesRadar Score
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
oauthlib@3.1.1
3.2.2

Open the chart page →

6,501
shynetjuniorjpdj0.1.301 of 1See more

shynet juniorjpdj 0.1.30

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
oauthlib@3.2.1
3.2.2

Open the chart page →

2,581
mlflowkelvins0.4.01 of 3See more

mlflow kelvins 0.4.0

1 of the 3 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
kelvinsp/mlflow:1.26.1cd33e6db2a59
oauthlib@3.2.0
3.2.2

Open the chart page →

4,156
elastalert2kfirfer2.2.51 of 1See more

elastalert2 kfirfer 2.2.5

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
jertel/elastalert2:2.2.34dcc0ef93efc
oauthlib@3.1.1
3.2.2

Open the chart page →

1,598
kube-hunterkfirfer1.0.51 of 1See more

kube-hunter kfirfer 1.0.5

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
aquasec/kube-hunter:0.6.8e64fe49f059f
oauthlib@3.2.0
3.2.2

Open the chart page →

997
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
oauthlib@3.2.0
3.2.2

Open the chart page →

17,779
sasquatchlsst-sqre0.1.131 of 6See more

sasquatch lsst-sqre 0.1.13

1 of the 6 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
oauthlib@3.1.1
3.2.2

Open the chart page →

9,332
kube-hunterm9sweeperVerified publisher1.6.01 of 1See more

kube-hunter m9sweeper 1.6.0

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
aquasec/kube-hunter:0.6.8e64fe49f059f
oauthlib@3.2.0
3.2.2

Open the chart page →

997
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
oauthlib@3.2.1
3.2.2

Open the chart page →

22,084
pod-pvc-mappingpvc-exporter0.1.31 of 1See more

pod-pvc-mapping pvc-exporter 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
dockerid31415926/pod-pvc-mapping:v0.1.3354309669f16
oauthlib@3.1.1
3.2.2

Open the chart page →

1,762
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
oauthlib@3.2.0
3.2.2

Open the chart page →

4,219
kube-prometheus-stackromholdings19.3.01 of 6See more

kube-prometheus-stack romholdings 19.3.0

1 of the 6 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
oauthlib@3.1.1
3.2.2

Open the chart page →

8,645
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
oauthlib@3.2.0
3.2.2

Open the chart page →

7,295
monitoringthl-chartsVerified publisher0.1.11 of 10See more

monitoring thl-charts 0.1.1

1 of the 10 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
oauthlib@3.2.0
3.2.2

Open the chart page →

18,908
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
oauthlib@3.2.0
3.2.2

Open the chart page →

8,607
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
oauthlib@3.2.0
3.2.2

Open the chart page →

13,459

Container images carrying it

62 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/dgtlmoon/changedetection.io:0.39.4f1ce4c56ccaa
oauthlib@3.1.1
3.2.2
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
oauthlib@3.2.0
3.2.2
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
oauthlib@3.2.0
3.2.2
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
oauthlib@3.1.1
3.2.2
1
ghcr.io/kubeshop/k8s-sidecar:ignore-initial-events7f583a36a764
oauthlib@3.2.1
3.2.2
1
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
oauthlib@3.2.0
3.2.2
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
oauthlib@3.2.0
3.2.2
1
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
oauthlib@3.1.1
3.2.2
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
oauthlib@3.2.0
3.2.2
1
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
oauthlib@3.2.0
3.2.2
1
quay.io/kiwigrid/k8s-sidecar:1.15.1a25886092fa4
oauthlib@3.1.1
3.2.2
1
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
oauthlib@3.2.0
3.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.