StackRadar

CVE-2022-40674

High

Advisory

Published 14 Sept 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
854
of 17,790 indexed, latest versions
Container images
772
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 854 of 17,790 indexed charts deploy, on 772 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+16 more2.1.0-4ubuntu1.4+esm7, 2.1.0-7ubuntu0.16.04.5+esm6, 2.2.5-3ubuntu0.8, 2.2.6-2+deb10u5+3 more548
expatapk2.2.10-r1, 2.2.10-r2, 2.2.10-r6, 2.4.1-r0+5 more2.2.10-r7, 2.4.9-r0128
expatrpm2.1.0-10.el7_3, 2.1.0-11.el7, 2.1.0-12.el7, 2.1.0-14.el7_9+8 more0:2.1.0-15.el7_9, 0:2.2.5-3.el8_1.2, 0:2.2.5-3.el8_2.3, 0:2.2.5-4.el8_4.4+2 more96
OSV records
ALPINE-CVE-2022-40674RHSA-2022:6831RHSA-2022:6832RHSA-2022:6833RHSA-2022:6834RHSA-2022:6878UBUNTU-CVE-2022-40674DLA-3119-1DSA-5236-1SUSE-SU-2022:3597-1
Also known as
USN-5638-1, USN-5638-2, USN-5638-4

Charts affected

854 by stars
ChartLatestAffected imagesRadar Score
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
expat@2.4.8-r0
2.4.9-r0

Open the chart page →

7,998
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,138
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,636

Container images carrying it

772 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
expat@2.2.10-r1
2.2.10-r7
1
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
ghcr.io/miguelndecarvalho/speedtest-exporter:v3.2.29e36964bce26
expat@2.2.10-r1
2.2.10-r7
1
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
expat@2.2.10-2
2.2.10-2+deb11u4
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
expat@2.2.5-3ubuntu0.7
2.2.5-3ubuntu0.8
1
ghcr.io/privacyengineering/collector-go:main7217f1a4fa28
expat@2.2.6-2+deb10u4
2.2.6-2+deb10u5
1
ghcr.io/privacyengineering/consumer:main73f59c032812
expat@2.2.6-2+deb10u4
2.2.6-2+deb10u5
1
ghcr.io/privacyengineering/hawk-monitor:master13309f068a56
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
expat@2.2.10-2
2.2.10-2+deb11u4
1
ghcr.io/simoncaron/velero-notifications:1.0.0d058963d4de7
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
ghcr.io/skyoo2003/digdag:0.0.1821fd6a6f2cd
expat@2.2.10-r1
2.2.10-r7
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
ghcr.io/wbstack/cradle:2.0.11c7a78c54f77
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
ghcr.io/wbstack/quickstatements:1.3.588423e422ea8
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
ghcr.io/wbstack/widar:1.31702fc9df79f
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
expat@2.4.1-r0
2.4.9-r0
1
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
expat@2.4.7-1
2.4.7-1ubuntu0.1
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.4
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
expat@2.4.8-r0
2.4.9-r0
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.4
1
quay.io/eclipse/che-plugin-registry:nightlya88add0f8c93
expat@2.2.10-r1
2.2.10-r7
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.4
1
quay.io/evl.ms/argocd-exporter:0.0.136ea8f34aa6b
expat@2.4.1-r0
2.4.9-r0
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
expat@2.2.5-3ubuntu0.7
2.2.5-3ubuntu0.8
1
quay.io/fairwinds/yelb-appserver:v0.6.0fae21f06131f
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
quay.io/fairwinds/yelb-ui:v0.1.05ac114e567ed
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
expat@2.2.5-8.el8
0:2.2.5-8.el8_6.3
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
expat@2.2.5-8.el8
0:2.2.5-8.el8_6.3
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
expat@2.2.5-8.el8
0:2.2.5-8.el8_6.3
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
expat@2.4.7-1
2.4.7-1ubuntu0.1
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
expat@2.2.10-r1
2.2.10-r7
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
expat@2.2.5-3.el8
0:2.2.5-3.el8_2.3
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.4
1
quay.io/kiwigrid/k8s-sidecar:1.10.718feb3906286
expat@2.2.10-r1
2.2.10-r7
1
quay.io/kiwigrid/k8s-sidecar:1.15.61f025ae37b7b
expat@2.4.5-r0
2.4.9-r0
1
quay.io/kiwigrid/k8s-sidecar:1.15.1a25886092fa4
expat@2.4.3-r0
2.4.9-r0
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
expat@2.2.5-4.el8_5.3
0:2.2.5-8.el8_6.3
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.