StackRadar

CVE-2022-40674

High

Advisory

Published 14 Sept 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
854
of 17,787 indexed, latest versions
Container images
772
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 854 of 17,787 indexed charts deploy, on 772 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+16 more2.1.0-4ubuntu1.4+esm7, 2.1.0-7ubuntu0.16.04.5+esm6, 2.2.5-3ubuntu0.8, 2.2.6-2+deb10u5+3 more548
expatapk2.2.10-r1, 2.2.10-r2, 2.2.10-r6, 2.4.1-r0+5 more2.2.10-r7, 2.4.9-r0128
expatrpm2.1.0-10.el7_3, 2.1.0-11.el7, 2.1.0-12.el7, 2.1.0-14.el7_9+8 more0:2.1.0-15.el7_9, 0:2.2.5-3.el8_1.2, 0:2.2.5-3.el8_2.3, 0:2.2.5-4.el8_4.4+2 more96
OSV records
ALPINE-CVE-2022-40674RHSA-2022:6831RHSA-2022:6832RHSA-2022:6833RHSA-2022:6834RHSA-2022:6878UBUNTU-CVE-2022-40674DLA-3119-1DSA-5236-1SUSE-SU-2022:3597-1
Also known as
USN-5638-1, USN-5638-2, USN-5638-4

Charts affected

854 by stars
ChartLatestAffected imagesRadar Score
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
expat@2.4.8-r0
2.4.9-r0

Open the chart page →

7,972
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,138
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,636

Container images carrying it

772 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
shinobisystems/shinobi:latestc2f5ce2e1067
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
simpleidserver/faaswebsite:0.0.4367218ae760f
expat@2.2.10-2
2.2.10-2+deb11u4
1
sinusbot/docker:1.0.0-beta.14-dc94a7cc7a4f3cc4393
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
sirfragalot/hyperion.ng:2.0.0-alpha.9-x86_6434577843cb7b
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
sismics/docs:v1.10f4b0ef019cf1
expat@2.2.5-3
2.2.5-3ubuntu0.8
1
slagattollas/planner-practica:latestcecd95e31486
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
slagattollas/weatherservice-practica:latest68e7f56393fc
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
smailkoz/torrserver:1.0.1117b52d15de8f0
expat@2.4.3-r0
2.4.9-r0
1
snipe/snipe-it:v6.0.1455fb7636a98c
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
solidnerd/bookstack:21.12762ffd5c51d3
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
someblackmagic/smtp-fake-server:latest0d63ba37a560
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
splunk/splunk-operator:2.0.0c4e0d3146226
expat@2.2.5-8.el8_6.2
0:2.2.5-8.el8_6.3
1
stacksimplify/kube-nginxapp1:1.0.0ead648280067
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
stacksimplify/kube-nginxapp2:1.0.0ce2b15139aca
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
stakater/workshop-operator:v0.0.3897bf456cc97c
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
stakewiselabs/bls-horcrux:v1.0.02afd0c0b34cb
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
stanfordoval/almond-server:latest1a63cdccedaf
expat@2.2.6-2+deb10u4
2.2.6-2+deb10u5
1
stashapp/stash:latest24dbd7607174
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
statcan/ckan:2.93921305425b8
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
subsquid/hydra-indexer:5.0.0-alpha.37a7f8b9bad7ee
expat@2.4.7-r0
2.4.9-r0
1
subsquid/hydra-indexer-status-service:5.0.0-alpha.37a4136013909c
expat@2.4.7-r0
2.4.9-r0
1
svtechnmaa/svtech_csv:v1.0.1b9d7ecf8de24
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
svtechnmaa/svtech_gitlist:v1.0.0d5a1390b5b75
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
svtechnmaa/svtech_http_thruk:v1.0.2e19aba397c1f
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
svtechnmaa/svtech_rundeck_option_provider:v1.1.1674fad30a51f
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
taemon1337/image-api:0.0.1247bc1dc4f07
expat@2.4.5-r0
2.4.9-r0
1
taigaio/taiga-back:6.4.29f97323cc150
expat@2.2.10-2
2.2.10-2+deb11u4
1
taigaio/taiga-protected:6.4.036318831b3e7
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
tautulli/tautulli:v2.7.7c4da15f058ea
expat@2.2.10-2
2.2.10-2+deb11u4
1
temporalio/admin-tools:1.15.135034611d981
expat@2.2.10-r1
2.2.10-r7
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
expat@2.4.7-r0
2.4.9-r0
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
thingsboard/tb-node:3.4.1645f43b688f7
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
thmmniii/fbs-core:v1.27.15438517d9fc2
expat@2.4.7-1
2.4.7-1ubuntu0.1
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
expat@2.4.7-1
2.4.7-1ubuntu0.1
1
timescale/timescaledb-postgis:latest-pg127758704d4a14
expat@2.2.10-r1
2.2.10-r7
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
tomsquest/docker-radicale:3.1.1.04759cc353a1d
expat@2.4.3-r0
2.4.9-r0
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
torrespro/mca-worker:2.0.06d3bd305a1ba
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
tpdock/freeradius:2.2.93da600c95a49
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
trafex/php-nginx:2.4.07282edfca2bf
expat@2.4.3-r0
2.4.9-r0
1
trafex/php-nginx:2.2.0ee0b7c6cce07
expat@2.4.1-r0
2.4.9-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.