StackRadar

CVE-2022-39198

Critical

Advisory

Published 19 Oct 2022In the index since 9 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.026
84th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3
of 17,781 indexed, latest versions
Container images
1
deployed by those charts
Fix available
2 of 2
affected packages

Hessian Lite for Apache Dubbo deserialization vulnerability

Carried by container images the latest versions of 3 of 17,781 indexed charts deploy, on 1 image.

Affected packageAffected versionsFixed inImages
dubbomaven2.7.82.7.181
hessian-litemaven3.2.83.2.131
OSV records
GHSA-5qwq-g2hx-r6f7

Charts affected

3 by stars
ChartLatestAffected imagesRadar Score
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-39198.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
dubbo@2.7.8
hessian-lite@3.2.8
2.7.18
3.2.13

Open the chart page →

12,513
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2022-39198.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
dubbo@2.7.8
hessian-lite@3.2.8
2.7.18
3.2.13

Open the chart page →

12,513
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-39198.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
dubbo@2.7.8
hessian-lite@3.2.8
2.7.18
3.2.13

Open the chart page →

12,513

Container images carrying it

1 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
dubbo@2.7.8
hessian-lite@3.2.8
2.7.18
3.2.13
3

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.