StackRadar

CVE-2022-37620

High

Advisory

Published 31 Oct 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.012
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 17,781 indexed, latest versions
Container images
53
deployed by those charts
Fix available
None
affected package

kangax html-minifier REDoS vulnerability

Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 53 images.

Affected packageAffected versionsFixed inImages
html-minifiernpm1.5.0, 3.5.9, 3.5.20, 3.5.21+1 moreno fix listed53
OSV records
GHSA-pfq8-rq6v-vf5m

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2022-37620.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
html-minifier@4.0.0
no fix listed

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2022-37620.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
html-minifier@4.0.0
no fix listed

Open the chart page →

11,100
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-37620.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
html-minifier@3.5.21
no fix listed

Open the chart page →

3,881
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2022-37620.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
html-minifier@4.0.0
no fix listed

Open the chart page →

5,535
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2022-37620.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
html-minifier@3.5.21
no fix listed

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-37620.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
html-minifier@3.5.21
no fix listed

Open the chart page →

22,665

Container images carrying it

53 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
html-minifier@4.0.0
no fix listed
3
library/ghost:6.63.0e05bc1169fb2
html-minifier@4.0.0
no fix listed
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
html-minifier@3.5.21
no fix listed
2
0hlov3/semaphore:v1.0.050f874ec096b
html-minifier@3.5.21
no fix listed
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
html-minifier@3.5.21
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
html-minifier@4.0.0
no fix listed
1
daskdev/dask-notebook:1.1.0052630f5ca04
html-minifier@3.5.21
no fix listed
1
diygod/rsshub:2025-11-097a6312cac0d5
html-minifier@4.0.0
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
html-minifier@3.5.20
no fix listed
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
html-minifier@3.5.21
no fix listed
1
henrywhitaker3/speedtest-tracker:latest47159a940229
html-minifier@3.5.21
no fix listed
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
html-minifier@4.0.0
no fix listed
1
ibmcom/microclimate-portal:latested5505e5c7ec
html-minifier@3.5.9
no fix listed
1
jayfong/yapi:1.10.2163e5d621910
html-minifier@3.5.21
no fix listed
1
joplin/server:latest3f7b852959aa
html-minifier@4.0.0
no fix listed
1
joplin/server:3.0-beta52af57880c0e
html-minifier@4.0.0
no fix listed
1
joplin/server:2.14.2-betab87564ef34e9
html-minifier@4.0.0
no fix listed
1
konradkleine/docker-registry-frontend:v2181aad54ee64
html-minifier@1.5.0
no fix listed
1
lavandadelpatio/frontend:latest501c3f31e0bc
html-minifier@3.5.21
no fix listed
1
library/ghost:6.37.01ef2e532ca4d
html-minifier@4.0.0
no fix listed
1
library/ghost:6.25.12654b1e90413
html-minifier@4.0.0
no fix listed
1
library/ghost:6.41.129773d6be407
html-minifier@4.0.0
no fix listed
1
library/ghost:6.39.0-alpine77196da4b0df
html-minifier@4.0.0
no fix listed
1
library/ghost:5.79.083f7bf209844
html-minifier@4.0.0
no fix listed
1
library/ghost:6.62.0a7a268bbfb7f
html-minifier@4.0.0
no fix listed
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
html-minifier@4.0.0
no fix listed
1
linuxserver/codimd:latestb801bbcf6386
html-minifier@4.0.0
no fix listed
1
lissy93/dashy:2.0.51991f7be5ed0
html-minifier@3.5.21
no fix listed
1
misskey/misskey:12.110.1e08b7c478093
html-minifier@3.5.21
no fix listed
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
html-minifier@4.0.0
no fix listed
1
phntom/codimd:2.4.31b9aafbb62e6
html-minifier@4.0.0
no fix listed
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
html-minifier@3.5.21
no fix listed
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
html-minifier@3.5.21
no fix listed
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
html-minifier@4.0.0
no fix listed
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
html-minifier@4.0.0
no fix listed
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
html-minifier@4.0.0
no fix listed
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
html-minifier@4.0.0
no fix listed
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
html-minifier@4.0.0
no fix listed
1
speckle/speckle-server:2.26.379f14a2bf931
html-minifier@4.0.0
no fix listed
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
html-minifier@4.0.0
no fix listed
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
html-minifier@4.0.0
no fix listed
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
html-minifier@4.0.0
no fix listed
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
html-minifier@4.0.0
no fix listed
1
temporalio/web:1.14.033cfa863d8ce
html-minifier@3.5.21
no fix listed
1
testhubio/testhub-frontend:on-preme86c2db53be8
html-minifier@3.5.21
no fix listed
1
ubercadence/web:v3.29.58564a5b44a6d
html-minifier@3.5.21
no fix listed
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
html-minifier@3.5.21
no fix listed
1
ghcr.io/data-fair/metrics:0a8d40779eeae
html-minifier@4.0.0
no fix listed
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
html-minifier@4.0.0
no fix listed
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
html-minifier@3.5.21
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.