StackRadar

CVE-2022-40304

High

Advisory

Published 23 Nov 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.068
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
253
of 17,781 indexed, latest versions
Container images
246
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 253 of 17,781 indexed charts deploy, on 246 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+15 more2.9.1+dfsg1-3ubuntu4.13+esm4, 2.9.3+dfsg1-1ubuntu0.7+esm4, 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5+1 more140
libxml2apk2.9.10-r6, 2.9.10-r7, 2.9.12-r0, 2.9.12-r1+4 more2.9.14-r2106
OSV records
ALPINE-CVE-2022-40304UBUNTU-CVE-2022-40304
Also known as
USN-5760-1, USN-5760-2

Charts affected

253 by stars
ChartLatestAffected imagesRadar Score
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
libxml2@2.9.12-r0
2.9.14-r2

Open the chart page →

2,643
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libxml2@2.9.14-r0
2.9.14-r2

Open the chart page →

16,083
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
libxml2@2.9.12-r1
2.9.14-r2

Open the chart page →

2,534

Container images carrying it

246 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
soulou2019/angular-nginx:latesta3970f97c215
libxml2@2.9.12-r2
2.9.14-r2
1
stashapp/stash:latest24dbd7607174
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
statcan/ckan:2.93921305425b8
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
swaggerapi/swagger-ui:v4.12.00d7088d47928
libxml2@2.9.14-r0
2.9.14-r2
1
t3nde/matomo:4.3.1-fpm-alpine329ce194393a
libxml2@2.9.12-r1
2.9.14-r2
1
taemon1337/ingress-dashboard:0.0.10e8f5096c66bb
libxml2@2.9.12-r2
2.9.14-r2
1
taigaio/taiga-front:6.4.24d367b1e1250
libxml2@2.9.10-r6
2.9.14-r2
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm4
1
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libxml2@2.9.14-r0
2.9.14-r2
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
timescale/timescaledb-postgis:latest-pg127758704d4a14
libxml2@2.9.10-r6
2.9.14-r2
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm4
1
trafex/php-nginx:2.4.07282edfca2bf
libxml2@2.9.12-r1
2.9.14-r2
1
trafex/php-nginx:2.2.0ee0b7c6cce07
libxml2@2.9.12-r1
2.9.14-r2
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
libxml2@2.9.10-r6
2.9.14-r2
1
tvanro/prerender-alpine:6.4.06909015f0328
libxml2@2.9.12-r1
2.9.14-r2
1
vectorim/riot-web:v1.7.3384bb5af00b5d
libxml2@2.9.12-r1
2.9.14-r2
1
wavefronthq/proxy:9.2d1064d28f6eb
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.8
1
xeladock/mysql_dns:latest4baf531453f1
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.2
1
xeladock/nginx2:latestc259a67b1dff
libxml2@2.9.13+dfsg-1build1
2.9.13+dfsg-1ubuntu0.2
1
yuzutech/kroki-bpmn:0.16.0bd629239a64e
libxml2@2.9.12-r1
2.9.14-r2
1
yuzutech/kroki-excalidraw:0.16.015c9eef47a62
libxml2@2.9.12-r1
2.9.14-r2
1
yuzutech/kroki-mermaid:0.16.07acc8fe7caba
libxml2@2.9.12-r1
2.9.14-r2
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
libxml2@2.9.10-r6
2.9.14-r2
1
gcr.io/kubecost1/frontend:prod-1.81.096dfb19838b8
libxml2@2.9.10-r6
2.9.14-r2
1
gcr.io/kubecost1/frontend:prod-1.82.2ba66607c947c
libxml2@2.9.10-r7
2.9.14-r2
1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
libxml2@2.9.3+dfsg1-1ubuntu0.7
2.9.3+dfsg1-1ubuntu0.7+esm4
1
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
libxml2@2.9.12-r2
2.9.14-r2
1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
libxml2@2.9.13-r0
2.9.14-r2
1
ghcr.io/conductionnl/commonground-gateway-frontend:dev3b3fbb57cae8
libxml2@2.9.14-r0
2.9.14-r2
1
ghcr.io/conductionnl/contactcatalogus-php:latesteeb625bd660c
libxml2@2.9.13-r0
2.9.14-r2
1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
libxml2@2.9.13-r0
2.9.14-r2
1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
libxml2@2.9.13-r0
2.9.14-r2
1
ghcr.io/conductionnl/medewerkercatalogus-php:latest1ea5412bed26
libxml2@2.9.13-r0
2.9.14-r2
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
libxml2@2.9.13-r0
2.9.14-r2
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
libxml2@2.9.13-r0
2.9.14-r2
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
libxml2@2.9.13-r0
2.9.14-r2
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.8
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
libxml2@2.9.12-r1
2.9.14-r2
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.