StackRadar

CVE-2022-40674

High

Advisory

Published 14 Sept 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
854
of 17,790 indexed, latest versions
Container images
772
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 854 of 17,790 indexed charts deploy, on 772 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+16 more2.1.0-4ubuntu1.4+esm7, 2.1.0-7ubuntu0.16.04.5+esm6, 2.2.5-3ubuntu0.8, 2.2.6-2+deb10u5+3 more548
expatapk2.2.10-r1, 2.2.10-r2, 2.2.10-r6, 2.4.1-r0+5 more2.2.10-r7, 2.4.9-r0128
expatrpm2.1.0-10.el7_3, 2.1.0-11.el7, 2.1.0-12.el7, 2.1.0-14.el7_9+8 more0:2.1.0-15.el7_9, 0:2.2.5-3.el8_1.2, 0:2.2.5-3.el8_2.3, 0:2.2.5-4.el8_4.4+2 more96
OSV records
ALPINE-CVE-2022-40674RHSA-2022:6831RHSA-2022:6832RHSA-2022:6833RHSA-2022:6834RHSA-2022:6878UBUNTU-CVE-2022-40674DLA-3119-1DSA-5236-1SUSE-SU-2022:3597-1
Also known as
USN-5638-1, USN-5638-2, USN-5638-4

Charts affected

854 by stars
ChartLatestAffected imagesRadar Score
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
expat@2.4.8-r0
2.4.9-r0

Open the chart page →

7,998
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,138
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,636

Container images carrying it

772 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
expat@2.2.5-3.el8
0:2.2.5-3.el8_1.2
1
quay.io/mongodb/farm-intro-backend:0.11a9ce0b8fbd4
expat@2.2.10-2
2.2.10-2+deb11u4
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
quay.io/netwarps/blockscoutbecd3e39360a
expat@2.4.1-r0
2.4.9-r0
1
quay.io/openshift/origin-cli:4.66722d5041b47
expat@2.2.5-3.el8_2.3
0:2.2.5-8.el8_6.3
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
expat@2.2.5-3.el8_2.3
0:2.2.5-8.el8_6.3
1
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
expat@2.4.4-r0
2.4.9-r0
1
quay.io/opsmxpublic/awsgit:v3-js15a6faada3d4
expat@2.4.7-r0
2.4.9-r0
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
expat@2.1.0-7ubuntu0.16.04.4
2.1.0-7ubuntu0.16.04.5+esm6
1
quay.io/opsmxpublic/ubi8-oes-db:v3.0.089ee6493af89
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.4
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
expat@2.4.1-r0
2.4.9-r0
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
expat@2.4.1-r0
2.4.9-r0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.4
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
expat@2.2.10-r1
2.2.10-r7
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.4
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
registry.gitlab.com/open-forms/forms-catalogue:latest4eaf9c911f33
expat@2.2.10-2
2.2.10-2+deb11u4
1
registry.gitlab.com/open-forms/request-registry:latest0886cbbc5f95
expat@2.2.10-2
2.2.10-2+deb11u4
1
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
expat@2.4.8-r0
2.4.9-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.