StackRadar

CVE-2022-40304

High

Advisory

Published 23 Nov 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.068
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
253
of 17,781 indexed, latest versions
Container images
246
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 253 of 17,781 indexed charts deploy, on 246 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+15 more2.9.1+dfsg1-3ubuntu4.13+esm4, 2.9.3+dfsg1-1ubuntu0.7+esm4, 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5+1 more140
libxml2apk2.9.10-r6, 2.9.10-r7, 2.9.12-r0, 2.9.12-r1+4 more2.9.14-r2106
OSV records
ALPINE-CVE-2022-40304UBUNTU-CVE-2022-40304
Also known as
USN-5760-1, USN-5760-2

Charts affected

253 by stars
ChartLatestAffected imagesRadar Score
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
libxml2@2.9.12-r0
2.9.14-r2

Open the chart page →

2,643
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libxml2@2.9.14-r0
2.9.14-r2

Open the chart page →

16,083
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
libxml2@2.9.12-r1
2.9.14-r2

Open the chart page →

2,534

Container images carrying it

246 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
longhornio/longhorn-ui:v1.1.165560eabe3ee
libxml2@2.9.10-r6
2.9.14-r2
1
mediagis/nominatim:3.7c15e941485ef
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
1
milesmcc/shynet:v0.12.0e821e31140f7
libxml2@2.9.12-r1
2.9.14-r2
1
monogramm/docker-dolibarr:13.0-alpine5afd99523984
libxml2@2.9.10-r7
2.9.14-r2
1
muluder/prograncontrollermcord:0.1.843b597a93da7
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm4
1
neilpang/acme.sh:3.0.2595809ad43a2
libxml2@2.9.12-r2
2.9.14-r2
1
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm4
1
nginxinc/nginx-unprivileged:1.20-alpine38d9dc79cc1d
libxml2@2.9.14-r0
2.9.14-r2
1
ohif/viewer:latestb4bfecdc7cc6
libxml2@2.9.12-r1
2.9.14-r2
1
omecproject/c3po-hssdb:master-latest28a90cc26716
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.8
1
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.8
1
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.8
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.8
1
omecproject/onos-progran:1.0.05715e5648aa0
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm4
1
omecproject/openmme:master-latest64776cb9edb3
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm4
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm4
1
oomk8s/ubuntu-init:1.0.03adf3d21ad3b
libxml2@2.9.3+dfsg1-1ubuntu0.2
2.9.3+dfsg1-1ubuntu0.7+esm4
1
opendatacube/pipelines:wofs-1.225d810e8504b8
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.8
1
opendatacube/restcube:latest91870111837c
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.8
1
opendatacube/wms:latest1b90cdf68831
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.8
1
openelevation/open-elevation:latest82fb21612e86
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
openemr/openemr:6.1.089eaa6d9a4e3
libxml2@2.9.13-r0
2.9.14-r2
1
openkm/openkm-ce:6.3.113bc465a7461b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.8
1
opsmx11/issuegen:v2.1.05c50ca123d88
libxml2@2.9.1+dfsg1-3ubuntu4.12
2.9.1+dfsg1-3ubuntu4.13+esm4
1
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
libxml2@2.9.10-r6
2.9.14-r2
1
pactfoundation/pact-broker:2.101.0.0a3021fc42834
libxml2@2.9.14-r0
2.9.14-r2
1
phntom/keeweb:1.17.4-kix10c75ed6dd606
libxml2@2.9.10-r6
2.9.14-r2
1
photoprism/photoprism:220629-jammy2954334adbda
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm4
1
pnnlmiscscripts/k8s-node-image:1.16.15-nginx-903b3fed5bdbc
libxml2@2.9.10-r6
2.9.14-r2
1
pnnlmiscscripts/k8s-node-image:1.18.20-nginx-323bfca2cfaaaf
libxml2@2.9.14-r0
2.9.14-r2
1
pnnlmiscscripts/k8s-node-image:1.17.17-nginx-3685debe11edc4
libxml2@2.9.14-r0
2.9.14-r2
1
pnnlmiscscripts/k8s-node-image:1.20.15-nginx-18bbc7a777f9f7
libxml2@2.9.14-r0
2.9.14-r2
1
pnnlmiscscripts/k8s-node-image:1.19.16-nginx-20c5c2b19e53a2
libxml2@2.9.14-r0
2.9.14-r2
1
prefapp/nginx-proxified:latestf4d026fd9a26
libxml2@2.9.14-r1
2.9.14-r2
1
project2team4/react:latest3ff031a08887
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5
1
rancher/local-path-provisioner:v0.0.5e66f32d19eb9
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm4
1
reportportal/service-ui:5.7.20a08784eb901
libxml2@2.9.14-r0
2.9.14-r2
1
resouer/redis-slave:v2e2f198b49ba7
libxml2@2.9.1+dfsg1-3ubuntu4.4
2.9.1+dfsg1-3ubuntu4.13+esm4
1
saiakhil46/pizza-app:main-1ffbdf3dc39ce11e5d0
libxml2@2.9.10-r6
2.9.14-r2
1
scrapinghub/splash:3.4.1a5f89bc84606
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.8
1
seafileltd/seafile-mc:9.0.106693911bcc40
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
seafileltd/seafile-mc:9.0.97ac833196f60
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
shlinkio/shlink:2.7.1c6729db1d3a8
libxml2@2.9.10-r6
2.9.14-r2
1
sismics/docs:v1.10f4b0ef019cf1
libxml2@2.9.4+dfsg1-6.1ubuntu1.2
2.9.4+dfsg1-6.1ubuntu1.8
1
snipe/snipe-it:v6.0.1455fb7636a98c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.