StackRadar

CVE-2022-39348

Medium

Advisory

Published 26 Oct 2022In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.012
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
18
of 17,781 indexed, latest versions
Container images
22
deployed by those charts
Fix available
1 of 2
affected packages

Twisted vulnerable to NameVirtualHost Host header injection

Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 22 images.

Affected packageAffected versionsFixed inImages
twistedpypi16.6.0, 17.9.0, 18.9.0, 19.7.0+6 more22.10.0rc122
twisteddeb17.9.0-2ubuntu0.1no fix listed2
OSV records
GHSA-vg46-2rrj-3647UBUNTU-CVE-2022-39348
Also known as
PYSEC-2026-1055

Charts affected

18 by stars
ChartLatestAffected imagesRadar Score
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
twisted@20.3.0
22.10.0rc1

Open the chart page →

30,326
paperlessgeek-cookbookVerified publisher9.2.01 of 1See more

paperless geek-cookbook 9.2.0

1 of the 1 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
twisted@22.4.0
22.10.0rc1

Open the chart page →

3,924
vmware-exporterkremers2.3.01 of 1See more

vmware-exporter kremers 2.3.0

1 of the 1 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
pryorda/vmware_exporter:v0.18.479925e63e59f
twisted@22.8.0
22.10.0rc1

Open the chart page →

1,180
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
twisted@17.9.0-2ubuntu0.1
twisted@17.9.0
no fix listed
22.10.0rc1

Open the chart page →

13,541
prometheus-pve-exporterstenicVerified publisher0.1.11 of 1See more

prometheus-pve-exporter stenic 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
prompve/prometheus-pve-exporter:2.0.1ff6749eb03b0
twisted@20.3.0
22.10.0rc1

Open the chart page →

2,469
synapsesudermanjr1.1.51 of 1See more

synapse sudermanjr 1.1.5

1 of the 1 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
twisted@22.1.0
22.10.0rc1

Open the chart page →

3,332
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
twisted@21.2.0
22.10.0rc1

Open the chart page →

22,891
duoauthproxy-radius-simplecaerus0.1.01 of 1See more

duoauthproxy-radius-simple caerus 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
twisted@20.3.0
22.10.0rc1

Open the chart page →

2,974
vmware-exporterdniel0.0.11 of 1See more

vmware-exporter dniel 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
pryorda/vmware_exporter:v0.18.3e0f5ba8b7856
twisted@22.2.0
22.10.0rc1

Open the chart page →

1,351
pritunldysnixVerified publisher0.2.71 of 3See more

pritunl dysnix 0.2.7

1 of the 3 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
dysnix/pritunl:v1.29-r819951e3e7a32
twisted@20.3.0
22.10.0rc1

Open the chart page →

5,055
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
twisted@17.9.0-2ubuntu0.1
twisted@17.9.0
no fix listed
22.10.0rc1

Open the chart page →

13,551
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
twisted@20.3.0
22.10.0rc1

Open the chart page →

9,854
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
twisted@19.7.0
22.10.0rc1

Open the chart page →

27,633
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
twisted@20.3.0
22.10.0rc1

Open the chart page →

18,023
comacopencord1.0.03 of 9See more

comac opencord 1.0.0

3 of the 9 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
twisted@18.9.0
22.10.0rc1
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
twisted@16.6.0
22.10.0rc1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
twisted@16.6.0
22.10.0rc1

Open the chart page →

88,546
comac-platformopencord0.0.172 of 11See more

comac-platform opencord 0.0.17

2 of the 11 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
twisted@18.9.0
22.10.0rc1
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
twisted@16.6.0
22.10.0rc1

Open the chart page →

26,211
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
twisted@17.9.0
22.10.0rc1

Open the chart page →

12,609
sebaopencord1.0.04 of 17See more

seba opencord 1.0.0

4 of the 17 container images this version deploys carry CVE-2022-39348.

Container imageDigestPackageFixed in
voltha/voltha-cli:1.6.0c4e41e92f046
twisted@17.9.0
22.10.0rc1
voltha/voltha-netconf:1.6.037f80524c207
twisted@17.9.0
22.10.0rc1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
twisted@17.9.0
22.10.0rc1
voltha/voltha-voltha:1.6.0ff596b62de59
twisted@17.9.0
22.10.0rc1

Open the chart page →

93,855

Container images carrying it

22 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
omecproject/kubernetes-synchronizer:comac-1.0.07c17a7b1d1ef
twisted@18.9.0
22.10.0rc1
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
twisted@16.6.0
22.10.0rc1
2
anchore/anchore-engine:v0.10.0bde9eedf639d
twisted@20.3.0
22.10.0rc1
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
twisted@20.3.0
22.10.0rc1
1
dysnix/pritunl:v1.29-r819951e3e7a32
twisted@20.3.0
22.10.0rc1
1
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
twisted@20.3.0
22.10.0rc1
1
gethue/hue:4.10.05702b2c37ff9
twisted@21.2.0
22.10.0rc1
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
twisted@20.3.0
22.10.0rc1
1
linuxserver/deluge:18.04.10ac871624394
twisted@17.9.0-2ubuntu0.1
twisted@17.9.0
no fix listed
22.10.0rc1
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
twisted@17.9.0-2ubuntu0.1
twisted@17.9.0
no fix listed
22.10.0rc1
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
twisted@22.1.0
22.10.0rc1
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
twisted@16.6.0
22.10.0rc1
1
prompve/prometheus-pve-exporter:2.0.1ff6749eb03b0
twisted@20.3.0
22.10.0rc1
1
pryorda/vmware_exporter:v0.18.479925e63e59f
twisted@22.8.0
22.10.0rc1
1
pryorda/vmware_exporter:v0.18.3e0f5ba8b7856
twisted@22.2.0
22.10.0rc1
1
scrapinghub/splash:3.4.1a5f89bc84606
twisted@19.7.0
22.10.0rc1
1
voltha/voltha-cli:1.6.0c4e41e92f046
twisted@17.9.0
22.10.0rc1
1
voltha/voltha-netconf:1.6.037f80524c207
twisted@17.9.0
22.10.0rc1
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
twisted@17.9.0
22.10.0rc1
1
voltha/voltha-tester:1.7.0655c3048a602
twisted@17.9.0
22.10.0rc1
1
voltha/voltha-voltha:1.6.0ff596b62de59
twisted@17.9.0
22.10.0rc1
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
twisted@22.4.0
22.10.0rc1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.