StackRadar

CVE-2022-38900

High

Advisory

Published 28 Nov 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.238
98th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
226
of 17,781 indexed, latest versions
Container images
226
deployed by those charts
Fix available
1 of 1
affected package

decode-uri-component vulnerable to Denial of Service (DoS)

Carried by container images the latest versions of 226 of 17,781 indexed charts deploy, on 226 images.

Affected packageAffected versionsFixed inImages
decode-uri-componentnpm0.2.00.2.1226
OSV records
GHSA-w573-4hg7-7wgq

Charts affected

226 by stars
ChartLatestAffected imagesRadar Score
simple-db-app-chart-with-dependencysimple-db-app0.1.01 of 3See more

simple-db-app-chart-with-dependency simple-db-app 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
htmlprogrammer2001/simple-db-app:1.0a7e0a233a9bc
decode-uri-component@0.2.0
0.2.1

Open the chart page →

1,925
first-appsimple-helm-chart0.1.01 of 1See more

first-app simple-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
leeyoongti/first-app:1.0.021d66cb76352
decode-uri-component@0.2.0
0.2.1

Open the chart page →

2,154
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
decode-uri-component@0.2.0
0.2.1

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
decode-uri-component@0.2.0
0.2.1

Open the chart page →

29,220
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
decode-uri-component@0.2.0
0.2.1

Open the chart page →

2,460
k8soketisoketi1.0.11 of 1See more

k8soketi soketi 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
decode-uri-component@0.2.0
0.2.1

Open the chart page →

2,267
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
decode-uri-component@0.2.0
0.2.1

Open the chart page →

3,228
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
decode-uri-component@0.2.0
0.2.1

Open the chart page →

2,121
alert-mappersomeblackmagic0.2.01 of 1See more

alert-mapper someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
someblackmagic/alert-mapper:v0.1.088351d85c04c
decode-uri-component@0.2.0
0.2.1

Open the chart page →

1,890
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
decode-uri-component@0.2.0
0.2.1

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
decode-uri-component@0.2.0
0.2.1

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
decode-uri-component@0.2.0
0.2.1

Open the chart page →

3,881
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
decode-uri-component@0.2.0
0.2.1

Open the chart page →

4,967
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
decode-uri-component@0.2.0
0.2.1

Open the chart page →

10,902
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
decode-uri-component@0.2.0
0.2.1

Open the chart page →

3,827
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
decode-uri-component@0.2.0
0.2.1

Open the chart page →

4,017
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
decode-uri-component@0.2.0
0.2.1

Open the chart page →

20,270
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
decode-uri-component@0.2.0
0.2.1

Open the chart page →

3,576
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
decode-uri-component@0.2.0
0.2.1

Open the chart page →

6,881
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
decode-uri-component@0.2.0
0.2.1

Open the chart page →

2,838
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
decode-uri-component@0.2.0
0.2.1

Open the chart page →

3,129
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
decode-uri-component@0.2.0
0.2.1

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
decode-uri-component@0.2.0
0.2.1

Open the chart page →

22,665
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
decode-uri-component@0.2.0
0.2.1

Open the chart page →

5,806
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
decode-uri-component@0.2.0
0.2.1

Open the chart page →

1,752
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-38900.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
decode-uri-component@0.2.0
0.2.1

Open the chart page →

1,309

Container images carrying it

226 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
decode-uri-component@0.2.0
0.2.1
5
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
decode-uri-component@0.2.0
0.2.1
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
decode-uri-component@0.2.0
0.2.1
4
oscarsotosanchez/server:v1.06e2e1279126b
decode-uri-component@0.2.0
0.2.1
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
decode-uri-component@0.2.0
0.2.1
4
dgraph/dgraph:v21.12.03b55ea83fffe
decode-uri-component@0.2.0
0.2.1
3
frankescobar/allure-docker-service-ui:7.0.3:latest4ebd8b4ef340
decode-uri-component@0.2.0
0.2.1
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
decode-uri-component@0.2.0
0.2.1
3
pantsel/konga:latestc8172b75607d
decode-uri-component@0.2.0
0.2.1
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
decode-uri-component@0.2.0
0.2.1
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
decode-uri-component@0.2.0
0.2.1
2
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
decode-uri-component@0.2.0
0.2.1
2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
decode-uri-component@0.2.0
0.2.1
2
governify/assets-manager:v1.4.12987672448c7
decode-uri-component@0.2.0
0.2.1
2
governify/director:v1.4.0608c6940bb98
decode-uri-component@0.2.0
0.2.1
2
governify/registry:v3.4.0d3f37f4f8168
decode-uri-component@0.2.0
0.2.1
2
governify/render:v2.2.0daeca1ce28e6
decode-uri-component@0.2.0
0.2.1
2
governify/reporter:v2.2.038595913458f
decode-uri-component@0.2.0
0.2.1
2
gradiant/open5gs-webui:2.7.5fbd10c017541
decode-uri-component@0.2.0
0.2.1
2
htmlprogrammer2001/simple-db-app:1.0a7e0a233a9bc
decode-uri-component@0.2.0
0.2.1
2
istio/examples-bookinfo-ratings-v1:1.15.009b9d6958a13
decode-uri-component@0.2.0
0.2.1
2
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
decode-uri-component@0.2.0
0.2.1
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
decode-uri-component@0.2.0
0.2.1
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
decode-uri-component@0.2.0
0.2.1
2
mesosphere/kommander:6.100.13917e82333a9
decode-uri-component@0.2.0
0.2.1
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
decode-uri-component@0.2.0
0.2.1
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
decode-uri-component@0.2.0
0.2.1
2
moreillon/api-proxy:a3e8b41e9e578c9653b6
decode-uri-component@0.2.0
0.2.1
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
decode-uri-component@0.2.0
0.2.1
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
decode-uri-component@0.2.0
0.2.1
2
statsd/statsd:v0.8.6dab129e74c25
decode-uri-component@0.2.0
0.2.1
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
decode-uri-component@0.2.0
0.2.1
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
decode-uri-component@0.2.0
0.2.1
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
decode-uri-component@0.2.0
0.2.1
2
a5hut0sh/helloworld:1.02ae77620e616
decode-uri-component@0.2.0
0.2.1
1
adrianberger/fluxcd-webui:latest76848c0d2780
decode-uri-component@0.2.0
0.2.1
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
decode-uri-component@0.2.0
0.2.1
1
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
decode-uri-component@0.2.0
0.2.1
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
decode-uri-component@0.2.0
0.2.1
1
arfath29/3-tier-app-frontend:latest384b3e377f47
decode-uri-component@0.2.0
0.2.1
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
decode-uri-component@0.2.0
0.2.1
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
decode-uri-component@0.2.0
0.2.1
1
assistiot/open_api_frontend:1.0.1f11d82defc70
decode-uri-component@0.2.0
0.2.1
1
aureliengasser/http-folder:1.1.111c4318c2571
decode-uri-component@0.2.0
0.2.1
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
decode-uri-component@0.2.0
0.2.1
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
decode-uri-component@0.2.0
0.2.1
1
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
decode-uri-component@0.2.0
0.2.1
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
decode-uri-component@0.2.0
0.2.1
1
catalysm/csmm:latestf003b35f54d9
decode-uri-component@0.2.0
0.2.1
1
chatwoot/chatwoot:v4.15.167ebc751c171
decode-uri-component@0.2.0
0.2.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.