StackRadar

CVE-2022-37620

High

Advisory

Published 31 Oct 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.012
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 17,781 indexed, latest versions
Container images
53
deployed by those charts
Fix available
None
affected package

kangax html-minifier REDoS vulnerability

Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 53 images.

Affected packageAffected versionsFixed inImages
html-minifiernpm1.5.0, 3.5.9, 3.5.20, 3.5.21+1 moreno fix listed53
OSV records
GHSA-pfq8-rq6v-vf5m

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2022-37620.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
html-minifier@4.0.0
no fix listed

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2022-37620.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
html-minifier@4.0.0
no fix listed

Open the chart page →

11,100
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-37620.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
html-minifier@3.5.21
no fix listed

Open the chart page →

3,881
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2022-37620.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
html-minifier@4.0.0
no fix listed

Open the chart page →

5,535
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2022-37620.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
html-minifier@3.5.21
no fix listed

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-37620.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
html-minifier@3.5.21
no fix listed

Open the chart page →

22,665

Container images carrying it

53 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
html-minifier@4.0.0
no fix listed
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
html-minifier@3.5.21
no fix listed
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
html-minifier@3.5.21
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.