StackRadar

CVE-2022-40304

High

Advisory

Published 23 Nov 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.068
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
253
of 17,781 indexed, latest versions
Container images
246
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 253 of 17,781 indexed charts deploy, on 246 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+15 more2.9.1+dfsg1-3ubuntu4.13+esm4, 2.9.3+dfsg1-1ubuntu0.7+esm4, 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5+1 more140
libxml2apk2.9.10-r6, 2.9.10-r7, 2.9.12-r0, 2.9.12-r1+4 more2.9.14-r2106
OSV records
ALPINE-CVE-2022-40304UBUNTU-CVE-2022-40304
Also known as
USN-5760-1, USN-5760-2

Charts affected

253 by stars
ChartLatestAffected imagesRadar Score
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
libxml2@2.9.12-r0
2.9.14-r2

Open the chart page →

2,643
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libxml2@2.9.14-r0
2.9.14-r2

Open the chart page →

16,083
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
libxml2@2.9.12-r1
2.9.14-r2

Open the chart page →

2,534

Container images carrying it

246 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
ghcr.io/k8s-at-home/plex:v1.28.0.5999-97678ded3ef756c7d784b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/k8s-at-home/pod-gateway:v1.6.1dcb2d814a4f7
libxml2@2.9.14-r0
2.9.14-r2
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/kore3lab/kore-board.frontend:v0.5.584ece8ee5d35
libxml2@2.9.10-r6
2.9.14-r2
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libxml2@2.9.4+dfsg1-6.1ubuntu1.4
2.9.4+dfsg1-6.1ubuntu1.8
1
ghcr.io/netsoc/docs:latest48890a52b327
libxml2@2.9.12-r1
2.9.14-r2
1
ghcr.io/netsoc/website:latesta9618107fa50
libxml2@2.9.13-r0
2.9.14-r2
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
libxml2@2.9.10+dfsg-5ubuntu0.20.04.3
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/saiakhil46/burger-app:latest68b76520c0a9
libxml2@2.9.10-r6
2.9.14-r2
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
1
ghcr.io/tauffer-consulting/domino-frontend:latesta923b86a0903
libxml2@2.9.10-r6
2.9.14-r2
1
ghcr.io/volosoft/eshoponabp/app-web:1.0.0056bb4271626
libxml2@2.9.14-r0
2.9.14-r2
1
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
libxml2@2.9.12-r2
2.9.14-r2
1
ghcr.io/wbstack/ui:3.94b01f67faadf1
libxml2@2.9.14-r0
2.9.14-r2
1
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
libxml2@2.9.12-r1
2.9.14-r2
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
libxml2@2.9.14-r0
2.9.14-r2
1
quay.io/eclipse/che-plugin-registry:nightlya88add0f8c93
libxml2@2.9.10-r6
2.9.14-r2
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
libxml2@2.9.13-r0
2.9.14-r2
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm4
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
libxml2@2.9.12-r1
2.9.14-r2
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
libxml2@2.9.12-r1
2.9.14-r2
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
libxml2@2.9.14-r1
2.9.14-r2
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
libxml2@2.9.14-r0
2.9.14-r2
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
libxml2@2.9.14-r0
2.9.14-r2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.