StackRadar

CVE-2022-36313

High

Advisory

Published 22 Jul 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

file-type vulnerable to Infinite Loop via malformed MKV file

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
file-typenpm14.1.4, 14.7.1, 15.0.1, 16.2.0+4 more16.5.4, 17.1.310
OSV records
GHSA-mhxj-85r3-2x55

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-36313.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
file-type@17.1.1
17.1.3

Open the chart page →

5,251
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-36313.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
file-type@15.0.1
16.5.4

Open the chart page →

5,946
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-36313.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
file-type@16.5.0
16.5.4

Open the chart page →

22,773
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2022-36313.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
file-type@16.3.0
16.5.4

Open the chart page →

24,488
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2022-36313.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
file-type@15.0.1
16.5.4

Open the chart page →

3,833
theloungegeek-cookbookVerified publisher3.4.21 of 1See more

thelounge geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-36313.

Container imageDigestPackageFixed in
thelounge/thelounge:4.2.0-alpine639978459c3a
file-type@14.7.1
16.5.4

Open the chart page →

2,689
theloungehalkeye4.3.11 of 1See more

thelounge halkeye 4.3.1

1 of the 1 container images this version deploys carry CVE-2022-36313.

Container imageDigestPackageFixed in
thelounge/thelounge:4.3.0-alpine0037aa258261
file-type@16.2.0
16.5.4

Open the chart page →

1,938
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2022-36313.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
file-type@15.0.1
16.5.4

Open the chart page →

4,253
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-36313.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
file-type@14.1.4
16.5.4

Open the chart page →

5,215
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2022-36313.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
file-type@17.1.2
17.1.3

Open the chart page →

3,118
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-36313.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
file-type@17.1.2
17.1.3

Open the chart page →

3,118
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2022-36313.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
file-type@15.0.1
16.5.4

Open the chart page →

5,459

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
requarks/wiki:2:latest68f0d1848261
file-type@15.0.1
16.5.4
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
file-type@17.1.2
17.1.3
2
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
file-type@16.3.0
16.5.4
1
gristlabs/grist:0.7.96e71b1914a7e
file-type@14.1.4
16.5.4
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
file-type@16.5.0
16.5.4
1
misskey/misskey:12.110.1e08b7c478093
file-type@17.1.1
17.1.3
1
requarks/wiki:canary-2.5.2438b5865a7386c
file-type@15.0.1
16.5.4
1
thelounge/thelounge:4.3.0-alpine0037aa258261
file-type@16.2.0
16.5.4
1
thelounge/thelounge:4.2.0-alpine639978459c3a
file-type@14.7.1
16.5.4
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
file-type@15.0.1
16.5.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.