CVE-2022-37620
HighAdvisory
Published 31 Oct 2022In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.012
- 65th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 56
- of 17,781 indexed, latest versions
- Container images
- 53
- deployed by those charts
- Fix available
- None
- affected package
kangax html-minifier REDoS vulnerability
Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 53 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| html-minifiernpm | 1.5.0, 3.5.9, 3.5.20, 3.5.21+1 more | no fix listed | 53 |
- OSV records
- GHSA-pfq8-rq6v-vf5m
Charts affected
56 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| speckle-server-branch-testing5speckleVerified publisher | 2.21.3-branch.testing5.219631-2153bef | 1 of 5See more | 15,635 |
| speckle-server-branch-testing6speckleVerified publisher | 2.25.10-branch.testing6.645-b125c1e | 1 of 4See more | 11,100 |
| fdi-dotstatsuite-dlmstatcan | 0.3.1 | 1 of 1See more | 3,881 |
| joplintobiassackmann | 0.1.7 | 1 of 2See more | 5,535 |
| cadencewenerme | 0.23.0 | 1 of 5See more | 10,127 |
| temporalwenerme | 0.15.1 | 1 of 13See more | 22,665 |
Container images carrying it
53 by charts deploying them
A fixed version is listed for 0 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | dd991bafa85e | html-minifier | no fix listed | 1 |
| quay.io/ | ce6938ff6709 | html-minifier | no fix listed | 1 |
| quay.io/ | 7a4b9fedc724 | html-minifier | no fix listed | 1 |