StackRadar

CVE-2022-36087

Medium

Advisory

Published 9 Sept 2022In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.017
75th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
66
of 17,781 indexed, latest versions
Container images
62
deployed by those charts
Fix available
2 of 2
affected packages

OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI

Carried by container images the latest versions of 66 of 17,781 indexed charts deploy, on 62 images.

Affected packageAffected versionsFixed inImages
python-oauthlibdeb3.2.0-13.2.0-1ubuntu0.11
oauthlibpypi3.1.1, 3.2.0, 3.2.13.2.262
OSV records
GHSA-3pgj-pg6c-r5p7UBUNTU-CVE-2022-36087
Also known as
PYSEC-2022-269, USN-5632-1

Charts affected

66 by stars
ChartLatestAffected imagesRadar Score
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
oauthlib@3.1.1
3.2.2

Open the chart page →

6,501
shynetjuniorjpdj0.1.301 of 1See more

shynet juniorjpdj 0.1.30

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.13.1ba54f7797a6b
oauthlib@3.2.1
3.2.2

Open the chart page →

2,581
mlflowkelvins0.4.01 of 3See more

mlflow kelvins 0.4.0

1 of the 3 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
kelvinsp/mlflow:1.26.1cd33e6db2a59
oauthlib@3.2.0
3.2.2

Open the chart page →

4,156
elastalert2kfirfer2.2.51 of 1See more

elastalert2 kfirfer 2.2.5

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
jertel/elastalert2:2.2.34dcc0ef93efc
oauthlib@3.1.1
3.2.2

Open the chart page →

1,598
kube-hunterkfirfer1.0.51 of 1See more

kube-hunter kfirfer 1.0.5

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
aquasec/kube-hunter:0.6.8e64fe49f059f
oauthlib@3.2.0
3.2.2

Open the chart page →

997
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
oauthlib@3.2.0
3.2.2

Open the chart page →

17,779
sasquatchlsst-sqre0.1.131 of 6See more

sasquatch lsst-sqre 0.1.13

1 of the 6 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
oauthlib@3.1.1
3.2.2

Open the chart page →

9,332
kube-hunterm9sweeperVerified publisher1.6.01 of 1See more

kube-hunter m9sweeper 1.6.0

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
aquasec/kube-hunter:0.6.8e64fe49f059f
oauthlib@3.2.0
3.2.2

Open the chart page →

997
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
oauthlib@3.2.1
3.2.2

Open the chart page →

22,084
pod-pvc-mappingpvc-exporter0.1.31 of 1See more

pod-pvc-mapping pvc-exporter 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
dockerid31415926/pod-pvc-mapping:v0.1.3354309669f16
oauthlib@3.1.1
3.2.2

Open the chart page →

1,762
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
oauthlib@3.2.0
3.2.2

Open the chart page →

4,219
kube-prometheus-stackromholdings19.3.01 of 6See more

kube-prometheus-stack romholdings 19.3.0

1 of the 6 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
oauthlib@3.1.1
3.2.2

Open the chart page →

8,645
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
oauthlib@3.2.0
3.2.2

Open the chart page →

7,295
monitoringthl-chartsVerified publisher0.1.11 of 10See more

monitoring thl-charts 0.1.1

1 of the 10 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
oauthlib@3.2.0
3.2.2

Open the chart page →

18,908
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
oauthlib@3.2.0
3.2.2

Open the chart page →

8,607
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-36087.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
oauthlib@3.2.0
3.2.2

Open the chart page →

13,459

Container images carrying it

62 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
cloudve/cloudlaunch-server:latest4a3d7fae90bb
oauthlib@3.1.1
3.2.2
3
dpage/pgadmin4:6.12781369df9994
oauthlib@3.2.0
3.2.2
3
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
oauthlib@3.1.1
3.2.2
3
aquasec/kube-hunter:0.6.8e64fe49f059f
oauthlib@3.2.0
3.2.2
2
quay.io/cephcsi/cephcsi:v3.17.10b62db8afc9b
oauthlib@3.1.1
3.2.2
2
quay.io/kiwigrid/k8s-sidecar:1.19.26a8671702d6f
oauthlib@3.2.0
3.2.2
2
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
oauthlib@3.1.1
3.2.2
1
datamate/seafile-professional:11.0.202dd66b722464
oauthlib@3.2.0
3.2.2
1
devopstales/kube-openid-connector:1.042c40a0e9f1b
oauthlib@3.2.0
3.2.2
1
dockerid31415926/pod-pvc-mapping:v0.1.3354309669f16
oauthlib@3.1.1
3.2.2
1
dockerid31415926/pvc-exporter:v0.1.35a1dd17e0e07
oauthlib@3.1.1
3.2.2
1
flag5/clustersecret:0.0.94ad5748bfcc6
oauthlib@3.1.1
3.2.2
1
galaxy/cloudman-server:lateste5c265fe9fcd
oauthlib@3.2.1
3.2.2
1
gluufederation/opendj:4.3.0_011a1128b28b95
oauthlib@3.1.1
3.2.2
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
oauthlib@3.2.0
3.2.2
1
improwised/erpnext-worker:v13.4.197280b55cbd4
oauthlib@3.1.1
3.2.2
1
jertel/elastalert2:2.2.34dcc0ef93efc
oauthlib@3.1.1
3.2.2
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
oauthlib@3.1.1
3.2.2
1
kelvinsp/mlflow:1.26.1cd33e6db2a59
oauthlib@3.2.0
3.2.2
1
kfserving/models-web-app:v0.6.1f322d6ffdfa3
oauthlib@3.1.1
3.2.2
1
kobotoolbox/kobocat:2.022.24ab15679454415
oauthlib@3.2.0
3.2.2
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
oauthlib@3.2.0
3.2.2
1
kserve/models-web-app:v0.8.063ea05e73842
oauthlib@3.2.0
3.2.2
1
kubeflownotebookswg/jupyter-web-app:v1.6.1d762690e21c1
oauthlib@3.2.1
3.2.2
1
kubeflownotebookswg/tensorboards-web-app:v1.6.10876fef1973b
oauthlib@3.2.1
3.2.2
1
kubeflownotebookswg/volumes-web-app:v1.6.17299fa94db15
oauthlib@3.2.1
3.2.2
1
kubitodev/traefik-ip-whitelist-sync:1.0.2aa24869319bf
oauthlib@3.2.0
3.2.2
1
linuxserver/beets:1.5.0e36d16f7341c
oauthlib@3.1.1
3.2.2
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
oauthlib@3.1.1
3.2.2
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
oauthlib@3.1.1
3.2.2
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
oauthlib@3.2.0
3.2.2
1
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
oauthlib@3.1.1
3.2.2
1
milesmcc/shynet:v0.13.1ba54f7797a6b
oauthlib@3.2.1
3.2.2
1
milesmcc/shynet:v0.12.0e821e31140f7
oauthlib@3.1.1
3.2.2
1
netboxcommunity/netbox:v3.2.83d652dca5351
oauthlib@3.2.0
3.2.2
1
rook/ceph:v1.20.72f970c425617
oauthlib@3.1.1
3.2.2
1
rook/ceph:v1.19.2944a1dd70496
oauthlib@3.1.1
3.2.2
1
seafileltd/seafile-mc:9.0.97ac833196f60
oauthlib@3.2.1
3.2.2
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
oauthlib@3.2.0
3.2.2
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
oauthlib@3.1.1
3.2.2
1
taigaio/taiga-back:6.4.29f97323cc150
oauthlib@3.1.1
3.2.2
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
oauthlib@3.2.0
3.2.2
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
oauthlib@3.2.0
3.2.2
1
timescale/timescaledb-ha:pg16d7db8f1085a3
oauthlib@3.2.0
3.2.2
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
oauthlib@3.2.0
3.2.2
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
python-oauthlib@3.2.0-1
oauthlib@3.2.0
3.2.0-1ubuntu0.1
3.2.2
1
trueosiris/vrising:latest9356f98ad561
oauthlib@3.2.0
3.2.2
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
oauthlib@3.2.0
3.2.2
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
oauthlib@3.1.1
3.2.2
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
oauthlib@3.1.1
3.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.