StackRadar

CVE-2022-40674

High

Advisory

Published 14 Sept 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
854
of 17,787 indexed, latest versions
Container images
772
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 854 of 17,787 indexed charts deploy, on 772 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+16 more2.1.0-4ubuntu1.4+esm7, 2.1.0-7ubuntu0.16.04.5+esm6, 2.2.5-3ubuntu0.8, 2.2.6-2+deb10u5+3 more548
expatapk2.2.10-r1, 2.2.10-r2, 2.2.10-r6, 2.4.1-r0+5 more2.2.10-r7, 2.4.9-r0128
expatrpm2.1.0-10.el7_3, 2.1.0-11.el7, 2.1.0-12.el7, 2.1.0-14.el7_9+8 more0:2.1.0-15.el7_9, 0:2.2.5-3.el8_1.2, 0:2.2.5-3.el8_2.3, 0:2.2.5-4.el8_4.4+2 more96
OSV records
ALPINE-CVE-2022-40674RHSA-2022:6831RHSA-2022:6832RHSA-2022:6833RHSA-2022:6834RHSA-2022:6878UBUNTU-CVE-2022-40674DLA-3119-1DSA-5236-1SUSE-SU-2022:3597-1
Also known as
USN-5638-1, USN-5638-2, USN-5638-4

Charts affected

854 by stars
ChartLatestAffected imagesRadar Score
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
expat@2.4.8-r0
2.4.9-r0

Open the chart page →

7,972
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,138
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,636

Container images carrying it

772 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bsgrigorov/helm-operator:latest45ab095f09c8
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
cadmusthefounder/lnd:take-the-helm-0.1.0e596c5fbf80f
expat@2.2.6-2+deb10u4
2.2.6-2+deb10u5
1
camptocamp/bucket-cloner:latestacfafc308d88
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
camptocamp/ekorre:0.1.035c91d5fda04
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
cdignam/kodiak:v0.54.05a6a55b39cee
expat@2.2.6-2
2.2.6-2+deb10u5
1
ceticasbl/pg-ldap-sync:latest6c0aa7567145
expat@2.2.6-2
2.2.6-2+deb10u5
1
ceticasbl/tsimulus-saas:0.1.18bc34ce180d0c
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
charmcli/soft-serve:v0.4.039523c1a6ba8
expat@2.4.8-r0
2.4.9-r0
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
expat@2.1.0-4ubuntu1.4
2.1.0-4ubuntu1.4+esm7
1
chetangautamm/repo:sipp.v3e7f7049e1544
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
cheyang/distributed-tf:1.6.046cc34755493
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
chubaofs/cfs-client:3.2.015ff74209ce7
expat@2.2.10-2
2.2.10-2+deb11u4
1
chubaofs/cfs-server:3.2.0205030e045f2
expat@2.2.10-2
2.2.10-2+deb11u4
1
citizenstig/httpbin:latestb81c818ccb86
expat@2.1.0-7ubuntu0.16.04.2
2.1.0-7ubuntu0.16.04.5+esm6
1
ckulka/baikal:0.8.0aedb1f4f3fa0
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
cloudve/janis-terminal:latestaf56e77ca587
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
cloudve/ttyd:latestd79c1c5881c0
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
cockroachdb/cockroach-operator:v2.1.0983312754620
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.4
1
codercom/code-server:3.10.247605610ad8d
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
confluentinc/cp-enterprise-control-center:6.1.0f2975d507a2a
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
confluentinc/cp-enterprise-kafka:6.1.08f1544df1f48
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
confluentinc/cp-kafka:7.1.2.amd643bf359d5e340
expat@2.2.5-8.el8
0:2.2.5-8.el8_6.3
1
confluentinc/cp-kafka-connect:6.1.04bc70a83ca6f
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
confluentinc/cp-kafka-rest:6.1.0b0b7aa26254a
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
confluentinc/cp-ksqldb-server:6.1.0ee403d5b9090
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
confluentinc/cp-schema-registry:6.1.0b651d4b6185a
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
confluentinc/cp-zookeeper:6.1.078c190f4472c
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
craftypath/sops-operator:v0.8.0402a0024c732
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.4
1
crazymax/rrdcached:1.7.2-r4042536a06596
expat@2.4.1-r0
2.4.9-r0
1
cribl/cribl:3.0.2762747cb6796
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
expat@2.1.0-12.el7
0:2.1.0-15.el7_9
1
ctron/hawkbit-operator:0.1.48fdea8f76499
expat@2.2.5-3.el8
0:2.2.5-3.el8_2.3
1
darkobas/ethexporter:latest62e6464491ba
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
darkobas/tokenexporter:latesta0349a0eedf0
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
daskdev/dask-notebook:1.1.0052630f5ca04
expat@2.2.5-3
2.2.5-3ubuntu0.8
1
datadog/operator:0.3.117f08a860090
expat@2.1.0-11.el7
0:2.1.0-15.el7_9
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
expat@2.2.5-4.el8
0:2.2.5-4.el8_4.4
1
davidvmar/urjc-davidvmar-rabbitmq:1.0.0e9ce2608f799
expat@2.4.8-r0
2.4.9-r0
1
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
dchesterton/amcrest2mqtt:1.0.9cc70f2238aa9
expat@2.4.1-r0
2.4.9-r0
1
deconzcommunity/deconz:2.12.066541bbb78952
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
dellcloud/category:distributed02fc234353a9
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
dellcloud/pages:1.04d2eb25b9225
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
expat@2.2.5-8.el8_6.2
0:2.2.5-8.el8_6.3
1
deltaio/delta-sharing-server:0.2.08b75118187c5
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
deluan/navidrome:0.43.04e9ae3bff6aa
expat@2.2.10-r1
2.2.10-r7
1
devopstales/kube-openid-connector:1.042c40a0e9f1b
expat@2.4.7-r0
2.4.9-r0
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
dnationcloud/kubernetes-linter:0.2.1dee6376560f5
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
dockerid31415926/pod-pvc-mapping:v0.1.3354309669f16
expat@2.4.1-r0
2.4.9-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.