StackRadar

CVE-2022-40304

High

Advisory

Published 23 Nov 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.068
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
253
of 17,781 indexed, latest versions
Container images
246
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 253 of 17,781 indexed charts deploy, on 246 images.

Affected packageAffected versionsFixed inImages
libxml2deb2.9.1+dfsg1-3ubuntu4.3, 2.9.1+dfsg1-3ubuntu4.4, 2.9.1+dfsg1-3ubuntu4.12, 2.9.3+dfsg1-1ubuntu0.2+15 more2.9.1+dfsg1-3ubuntu4.13+esm4, 2.9.3+dfsg1-1ubuntu0.7+esm4, 2.9.4+dfsg1-6.1ubuntu1.8, 2.9.10+dfsg-5ubuntu0.20.04.5+1 more140
libxml2apk2.9.10-r6, 2.9.10-r7, 2.9.12-r0, 2.9.12-r1+4 more2.9.14-r2106
OSV records
ALPINE-CVE-2022-40304UBUNTU-CVE-2022-40304
Also known as
USN-5760-1, USN-5760-2

Charts affected

253 by stars
ChartLatestAffected imagesRadar Score
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
libxml2@2.9.12-r0
2.9.14-r2

Open the chart page →

2,643
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libxml2@2.9.14-r0
2.9.14-r2

Open the chart page →

16,083
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-40304.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
libxml2@2.9.12-r1
2.9.14-r2

Open the chart page →

2,534

Container images carrying it

246 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
oomk8s/readiness-check:2.0.2875814cc853d
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm4
11
oomk8s/readiness-check:2.0.07daa08b81954
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm4
6
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm4
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm4
4
ciscolabs/rtsp-client:latesta7b60ec88285
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
3
ciscolabs/rtsp-server:latestb59fc10bb821
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
3
nginxinc/nginx-unprivileged:1.19-alpine084242d8028c
libxml2@2.9.10-r6
2.9.14-r2
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm4
3
dependencytrack/frontend:4.6.124422d762e08
libxml2@2.9.14-r1
2.9.14-r2
2
hookiesolutions/webhookie:latest0629694246ba
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
2
library/nginx:1.19-alpine07ab71a2c8e4
libxml2@2.9.10-r6
2.9.14-r2
2
library/postgres:9.6-alpine8342bcb43446
libxml2@2.9.12-r2
2.9.14-r2
2
lightstep/collector:2021-01-26_23-02-36Z11c5569aaf3b
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm4
2
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
libxml2@2.9.4+dfsg1-6.1ubuntu1
2.9.4+dfsg1-6.1ubuntu1.8
2
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
libxml2@2.9.12-r0
2.9.14-r2
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
libxml2@2.9.3+dfsg1-1ubuntu0.6
2.9.3+dfsg1-1ubuntu0.7+esm4
2
pecan/db:latest9a1cdc3a9ccb
libxml2@2.9.12-r2
2.9.14-r2
2
privatebin/pdo:1.3.500466418121c
libxml2@2.9.13-r0
2.9.14-r2
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
libxml2@2.9.10+dfsg-5ubuntu0.20.04.4
2.9.10+dfsg-5ubuntu0.20.04.5
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
2
wurstmeister/zookeeper:latest7a7fd44a7210
libxml2@2.9.1+dfsg1-3ubuntu4.3
2.9.1+dfsg1-3ubuntu4.13+esm4
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libxml2@2.9.13+dfsg-1ubuntu0.1
2.9.13+dfsg-1ubuntu0.2
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
2
quay.io/iver-wharf/wharf-web:v1.6.2dc5d1ed91c26
libxml2@2.9.13-r0
2.9.14-r2
2
a10networks/acos-prometheus-exporter:latest8dc58d434d71
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.8
1
acockburn/appdaemon:4.0.83a93281d7e94
libxml2@2.9.10-r6
2.9.14-r2
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
ahmedinfraplus/simple-app:STAGINGc50e6e81a637
libxml2@2.9.14-r0
2.9.14-r2
1
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
ajanvier/polr:2.3.091ac61b88c85
libxml2@2.9.10-r6
2.9.14-r2
1
allegroai/clearml-agent-k8s-base:1.24-21772827a01bb5
libxml2@2.9.4+dfsg1-6.1ubuntu1.6
2.9.4+dfsg1-6.1ubuntu1.8
1
alpine/k8s:1.22.600ac10bcb759
libxml2@2.9.13-r0
2.9.14-r2
1
anonaddy/anonaddy:0.12.3957a95565166
libxml2@2.9.14-r0
2.9.14-r2
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
apachepulsar/pulsar:2.9.0d056c89b7131
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
apachepulsar/pulsar:2.8.2d538416d5afe
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
assistiot/fl_orchestrator:ui-latest20338b353aaf
libxml2@2.9.14-r1
2.9.14-r2
1
assistiot/tacticle_dashboard:db-latest02bc92348156
libxml2@2.9.14-r1
2.9.14-r2
1
assistiot/tacticle_dashboard:web-latest25fc9f373524
libxml2@2.9.14-r1
2.9.14-r2
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
blockstack/envsubst:latestd64d7430289a
libxml2@2.9.10-r6
2.9.14-r2
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libxml2@2.9.10+dfsg-5ubuntu0.20.04.1
2.9.10+dfsg-5ubuntu0.20.04.5
1
chaosnative/cle-frontend:2.7.007b82a82a702
libxml2@2.9.13-r0
2.9.14-r2
1
chetangautamm/repo:sipp.v3e7f7049e1544
libxml2@2.9.10+dfsg-5
2.9.10+dfsg-5ubuntu0.20.04.5
1
cheyang/distributed-tf:1.6.046cc34755493
libxml2@2.9.3+dfsg1-1ubuntu0.5
2.9.3+dfsg1-1ubuntu0.7+esm4
1
cloudve/janis-terminal:latestaf56e77ca587
libxml2@2.9.4+dfsg1-6.1ubuntu1.3
2.9.4+dfsg1-6.1ubuntu1.8
1
countly/countly-server:25.05.4e3c238248f99
libxml2@2.9.10+dfsg-5ubuntu0.20.04.2
2.9.10+dfsg-5ubuntu0.20.04.5
1
crazymax/rrdcached:1.7.2-r4042536a06596
libxml2@2.9.12-r1
2.9.14-r2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.