StackRadar

CVE-2022-40151

High

Advisory

Published 30 Dec 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
41
of 17,781 indexed, latest versions
Container images
58
deployed by those charts
Fix available
1 of 1
affected package

XStream can cause a Denial of Service by injecting deeply nested objects raising a stack overflow

Carried by container images the latest versions of 41 of 17,781 indexed charts deploy, on 58 images.

Affected packageAffected versionsFixed inImages
xstreammaven1.3.1, 1.4.3, 1.4.4, 1.4.7+7 more1.4.2058
OSV records
GHSA-f8cc-g7j8-xxpm

Charts affected

41 by stars
ChartLatestAffected imagesRadar Score
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
microcks/microcks:0.8.0e3a3e0c67b09
xstream@1.3.1
1.4.20

Open the chart page →

10,732
geoserver-cloudcamptocamp20.0.56 of 11See more

geoserver-cloud camptocamp2 0.0.5

6 of the 11 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
xstream@1.4.11.1
1.4.20

Open the chart page →

84,444
geoserverCloudcamptocamp20.0.66 of 11See more

geoserverCloud camptocamp2 0.0.6

6 of the 11 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
xstream@1.4.11.1
1.4.20

Open the chart page →

84,444
distributed-jmetercloudnativeapp1.0.11 of 1See more

distributed-jmeter cloudnativeapp 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
pedrocesarti/jmeter-docker:3.314851f144f57
xstream@1.4.10
1.4.20

Open the chart page →

4,532
spinnakerdwardu-helm-charts2.2.61 of 2See more

spinnaker dwardu-helm-charts 2.2.6

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
xstream@1.4.11.1
1.4.20

Open the chart page →

8,752
seata-serverheidaodageshiwoVerified publisher1.0.01 of 1See more

seata-server heidaodageshiwo 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
seataio/seata-server:1.5.1ee1ed55f4144
xstream@1.4.19
1.4.20

Open the chart page →

5,624
jmeterjmeterVerified publisher1.2.51 of 1See more

jmeter jmeter 1.2.5

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
liukunup/jmeter:5.59c079617a81b
xstream@1.4.19
1.4.20

Open the chart page →

2,067
routrroutr0.0.101 of 2See more

routr routr 0.0.10

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
fonoster/routr:1.0.0-rc52ca65af17cbc
xstream@1.4.9
1.4.20

Open the chart page →

4,983
graylogt3n1.0.01 of 3See more

graylog t3n 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
graylog2/server:2.4.3-38ff28c66e6c1
xstream@1.4.9
1.4.20

Open the chart page →

8,063
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
xstream@1.4.11.1
1.4.20

Open the chart page →

15,970
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
xstream@1.4.19
1.4.20

Open the chart page →

9,722
geoservercamptocamp20.0.36 of 12See more

geoserver camptocamp2 0.0.3

6 of the 12 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC2ca58b74529cd
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-rest:1.0-RC25dc0c93a1710
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-wcs:1.0-RC247ae1bdb4bcc
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-webui:1.0-RC228c3e5a8c5a3
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-wfs:1.0-RC28c70ee06d5ab
xstream@1.4.11.1
1.4.20
geoservercloud/geoserver-cloud-wms:1.0-RC242775ba6a4da
xstream@1.4.11.1
1.4.20

Open the chart page →

88,335
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
xstream@1.4.9
1.4.20

Open the chart page →

9,808
hazelcastcloudnativeapp1.3.11 of 1See more

hazelcast cloudnativeapp 1.3.1

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
hazelcast/hazelcast:3.11.2ca7d5589744f
xstream@1.4.10
1.4.20

Open the chart page →

4,982
hazelcast-jetcloudnativeapp1.1.01 of 1See more

hazelcast-jet cloudnativeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:3.0df495e64ea65
xstream@1.4.10
1.4.20

Open the chart page →

5,326
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
xstream@1.4.11.1
1.4.20

Open the chart page →

12,513
scorpio-brokerfiware0.3.310 of 10See more

scorpio-broker fiware 0.3.3

10 of the 10 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
xstream@1.4.10
1.4.20
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
xstream@1.4.18
1.4.20

Open the chart page →

55,600
scorpiobrokerfiware0.1.210 of 10See more

scorpiobroker fiware 0.1.2

10 of the 10 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
xstream@1.4.10
1.4.20
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
xstream@1.4.18
1.4.20
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
xstream@1.4.18
1.4.20

Open the chart page →

55,600
scorpio-broker-aaiofiware0.4.151 of 1See more

scorpio-broker-aaio fiware 0.4.15

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
xstream@1.4.18
1.4.20

Open the chart page →

5,286
my-chartfleet-web-app0.1.01 of 6See more

my-chart fleet-web-app 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
xstream@1.4.19
1.4.20

Open the chart page →

24,296
mod-marccatfolio-org0.1.301 of 1See more

mod-marccat folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
folioci/mod-marccat:latest1b57d690d568
xstream@1.4.7
1.4.20

Open the chart page →

6,988
openhabgeek-cookbookVerified publisher1.5.21 of 1See more

openhab geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
openhab/openhab:3.2.0d0aa4af452c1
xstream@1.4.18
1.4.20

Open the chart page →

2,887
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
xstream@1.4.11.1
1.4.20

Open the chart page →

34,754
hazelcast-jethazelcastVerified publisher1.17.11 of 1See more

hazelcast-jet hazelcast 1.17.1

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
xstream@1.4.11.1
1.4.20

Open the chart page →

6,102
ibm-microclimateibm-charts0.1.03 of 8See more

ibm-microclimate ibm-charts 0.1.0

3 of the 8 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
xstream@1.4.4
1.4.20
ibmcom/microclimate-portal:latested5505e5c7ec
xstream@1.4.10
1.4.20
ibmcom/microclimate-theia:lateste17bdccc5030
xstream@1.4.3
1.4.20

Open the chart page →

57,669
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
xstream@1.4.12
1.4.20

Open the chart page →

12,856
filebot-botluiscajl0.0.111 of 1See more

filebot-bot luiscajl 0.0.11

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
lavandadelpatio/filebot-bot:0.0.1-SNAPSHOTd2cba20aa4d8
xstream@1.4.19
1.4.20

Open the chart page →

3,679
lavandaluiscajl0.0.1341 of 5See more

lavanda luiscajl 0.0.134

1 of the 5 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
lavandadelpatio/filebot:0.0.671f2ccec8c0d
xstream@1.4.11.1
1.4.20

Open the chart page →

18,248
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
xstream@1.4.19
1.4.20

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
xstream@1.4.19
1.4.20

Open the chart page →

5,129
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
xstream@1.4.19
1.4.20

Open the chart page →

4,599
dependency-tracknovum-rgi-charts0.1.81 of 2See more

dependency-track novum-rgi-charts 0.1.8

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
owasp/dependency-track:3.8.0efc65e702ee1
xstream@1.4.11.1
1.4.20

Open the chart page →

3,633
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
woojoong/wowza:latestec230db19652
xstream@1.4.7
1.4.20

Open the chart page →

42,614
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
xstream@1.4.18
1.4.20

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
xstream@1.4.11.1
1.4.20

Open the chart page →

12,513
simple-keycloaksikalabs0.1.01 of 1See more

simple-keycloak sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.18830f76112b6
xstream@1.4.19
1.4.20

Open the chart page →

6,443
sistas-chatbotsistas-chatbot5.0.21 of 6See more

sistas-chatbot sistas-chatbot 5.0.2

1 of the 6 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
jhipster/jhipster-registry:latest7184525acd4d
xstream@1.4.18
1.4.20

Open the chart page →

5,856
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
xstream@1.4.13
1.4.20

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
xstream@1.4.11.1
1.4.20

Open the chart page →

13,079
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
xstream@1.3.1
1.4.20

Open the chart page →

11,841
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2022-40151.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
xstream@1.4.11.1
1.4.20

Open the chart page →

12,513

Container images carrying it

58 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
richardchesterwood/k8s-fleetman-queue:release2f7f8d5951155
xstream@1.4.19
1.4.20
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
xstream@1.4.18
1.4.20
1
seataio/seata-server:1.5.1ee1ed55f4144
xstream@1.4.19
1.4.20
1
wavefronthq/proxy:9.2d1064d28f6eb
xstream@1.4.11.1
1.4.20
1
woojoong/wowza:latestec230db19652
xstream@1.4.7
1.4.20
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
xstream@1.4.11.1
1.4.20
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
xstream@1.4.12
1.4.20
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
xstream@1.4.19
1.4.20
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.