StackRadar

CVE-2022-37599

High

Advisory

Published 12 Oct 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
60
of 17,781 indexed, latest versions
Container images
58
deployed by those charts
Fix available
1 of 1
affected package

loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)

Carried by container images the latest versions of 60 of 17,781 indexed charts deploy, on 58 images.

Affected packageAffected versionsFixed inImages
loader-utilsnpm1.0.4, 1.1.0, 1.2.3, 1.4.0+2 more1.4.2, 2.0.458
OSV records
GHSA-hhq3-ff78-jv3g

Charts affected

60 by stars
ChartLatestAffected imagesRadar Score
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-37599.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
loader-utils@1.4.0
1.4.2

Open the chart page →

3,143
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-37599.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
loader-utils@1.2.3
1.4.2

Open the chart page →

3,696
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2022-37599.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
loader-utils@1.4.0
1.4.2

Open the chart page →

2,460
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2022-37599.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
loader-utils@2.0.0
2.0.4

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-37599.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
loader-utils@2.0.0
2.0.4

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-37599.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
loader-utils@1.4.0
1.4.2

Open the chart page →

3,881
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-37599.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
loader-utils@1.4.0
1.4.2

Open the chart page →

20,270
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2022-37599.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
loader-utils@1.4.0
1.4.2

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-37599.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
loader-utils@1.4.0
1.4.2

Open the chart page →

22,665
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-37599.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
loader-utils@1.2.3
1.4.2

Open the chart page →

5,806

Container images carrying it

58 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
loader-utils@1.4.0
1.4.2
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
loader-utils@2.0.0
2.0.4
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
loader-utils@2.0.0
2.0.4
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
loader-utils@2.0.0
2.0.4
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
loader-utils@2.0.0
2.0.4
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
loader-utils@1.2.3
1.4.2
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
loader-utils@1.4.0
1.4.2
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
loader-utils@1.1.0
1.4.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.