StackRadar

CVE-2022-37734

High

Advisory

Published 13 Sept 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

graphql-java vulnerable to Denial of Service via GraphQL query that consumes CPU resources

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
graphql-javamaven8.0, 9.2, 13.0, 15.0+1 more17.410
OSV records
GHSA-v62j-cxhh-fq22

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
skywalkingkubesphere-testVerified publisher3.1.01 of 4See more

skywalking kubesphere-test 3.1.0

1 of the 4 container images this version deploys carry CVE-2022-37734.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.1.0-es7641237e0299b
graphql-java@8.0
17.4

Open the chart page →

18,042
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2022-37734.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
graphql-java@17.3
17.4

Open the chart page →

10,120
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2022-37734.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
graphql-java@17.3
17.4

Open the chart page →

7,963
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2022-37734.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
graphql-java@17.3
17.4

Open the chart page →

7,963
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-37734.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
graphql-java@17.3
17.4

Open the chart page →

16,401
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-37734.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
graphql-java@8.0
17.4

Open the chart page →

20,650
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2022-37734.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
graphql-java@13.0
17.4

Open the chart page →

11,188
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2022-37734.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
graphql-java@9.2
17.4

Open the chart page →

13,605
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2022-37734.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
graphql-java@13.0
17.4

Open the chart page →

14,493
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2022-37734.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
graphql-java@17.3
17.4

Open the chart page →

12,455
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-37734.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
graphql-java@15.0
17.4

Open the chart page →

3,424

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
graphql-java@17.3
17.4
2
apache/skywalking-oap-server:9.2.0133d35d2c263
graphql-java@17.3
17.4
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
graphql-java@8.0
17.4
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
graphql-java@8.0
17.4
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
graphql-java@15.0
17.4
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
graphql-java@17.3
17.4
1
atlassian/confluence-server:7.10.03b9222ab32ef
graphql-java@9.2
17.4
1
jacobalberty/unifi:v7.1.664a3616625dda
graphql-java@13.0
17.4
1
linuxserver/unifi-controller:7.3.83ab105cc50322
graphql-java@13.0
17.4
1
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
graphql-java@17.3
17.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.