StackRadar

CVE-2022-40304

High

Advisory

Published 23 Nov 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.068
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
253
of 17,781 indexed, latest versions
Container images
246
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 253 of 17,781 indexed charts deploy, on 246 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+15 more2.9.1+dfsg1-3ubuntu4.13+esm4, 2.9.3+dfsg1-1ubuntu0.7+esm4, 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5+1 more140
libxml2apk2.9.10-r6, 2.9.10-r7, 2.9.12-r0, 2.9.12-r1+4 more2.9.14-r2106
OSV records
ALPINE-CVE-2022-40304UBUNTU-CVE-2022-40304
Also known as
USN-5760-1, USN-5760-2

Charts affected

253 by stars
ChartLatestAffected imagesRadar Score
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
libxml2@2.9.12-r0
2.9.14-r2

Open the chart page →

2,643
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libxml2@2.9.14-r0
2.9.14-r2

Open the chart page →

16,083
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
libxml2@2.9.12-r1
2.9.14-r2

Open the chart page →

2,534

Container images carrying it

246 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
denisshav/frontend:latestb97cc69fbac6
libxml2@2.9.10-r6
2.9.14-r2
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
digitalist/nginx:1.21.6eec27ad73eaa
libxml2@2.9.12-r2
2.9.14-r2
1
dniel/forwardauth-spademo:masterd3e38df449a2
libxml2@2.9.12-r1
2.9.14-r2
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
libxml2@2.9.14-r0
2.9.14-r2
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.8
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.8
1
engrmth/bnkr:2.1.06d8464e6f0e8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
esailors/aws-ecr-http-proxy:1.5.15608ae045fa7
libxml2@2.9.13-r0
2.9.14-r2
1
factly/dega-studio:0.15.1140fbaa6d555
libxml2@2.9.12-r1
2.9.14-r2
1
factly/kavach-web:0.22.30cf361b41798
libxml2@2.9.13-r0
2.9.14-r2
1
factly/vidcheck-studio:0.12.024be158ec7d3
libxml2@2.9.12-r0
2.9.14-r2
1
galaxy/galaxy-init:v18.010267bad550e6
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm4
1
galaxy/galaxy-stable:v18.018e577a626dfd
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm4
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.8
1
gethue/hue:4.10.05702b2c37ff9
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.8
1
haugene/transmission-openvpn:4.0059216cfae4b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
haveagitgat/tdarr:2.00.181256348872ce
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm4
1
ibarreche/cloud-back-ci:lateste16a469c5791
libxml2@2.9.13-r0
2.9.14-r2
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm4
1
ibmcom/skydive:0.22.0395e60cc6e3d
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.8
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
jakowenko/double-take:1.6.0b858bac9e32a
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
johnblack77/clustereye:latest-amd64bb53ceb8442e
libxml2@2.9.10-r6
2.9.14-r2
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
kanboard/kanboard:v1.2.200b6d33dbbc16
libxml2@2.9.10-r7
2.9.14-r2
1
kennethreitz/httpbin:latest599fe5e50731
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.8
1
klausmeyer/docker-registry-browser:1.4.0bdc4c6b8595b
libxml2@2.9.12-r1
2.9.14-r2
1
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
libxml2@2.9.14-r0
2.9.14-r2
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.8
1
kubeshop/kusk-gateway-dashboard:v1.2.6ff9b5aa1258d
libxml2@2.9.14-r1
2.9.14-r2
1
lavandadelpatio/frontend:masterccfc0cd77803
libxml2@2.9.12-r1
2.9.14-r2
1
library/adminer:4.7143ec8cc2f3a
libxml2@2.9.10-r6
2.9.14-r2
1
library/postgres:14.1-alpine578ca5c8452c
libxml2@2.9.12-r2
2.9.14-r2
1
library/postgres:13.6-alpine8522c9920d88
libxml2@2.9.13-r0
2.9.14-r2
1
library/postgres:13.3-alpinee98a69a83639
libxml2@2.9.12-r1
2.9.14-r2
1
librenms/librenms:22.4.14f1f3d667cc7
libxml2@2.9.13-r0
2.9.14-r2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.8
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
linuxserver/deluge:18.04.10ac871624394
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.8
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.8
1
linuxserver/jellyfin:10.7.72427dde159a2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
longhornio/longhorn-manager:v1.2.3dca34321452c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.8
1
longhornio/longhorn-ui:v1.2.3148598de4b7d
libxml2@2.9.12-r0
2.9.14-r2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.