StackRadar

CVE-2022-40674

High

Advisory

Published 14 Sept 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
854
of 17,787 indexed, latest versions
Container images
772
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 854 of 17,787 indexed charts deploy, on 772 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+16 more2.1.0-4ubuntu1.4+esm7, 2.1.0-7ubuntu0.16.04.5+esm6, 2.2.5-3ubuntu0.8, 2.2.6-2+deb10u5+3 more548
expatapk2.2.10-r1, 2.2.10-r2, 2.2.10-r6, 2.4.1-r0+5 more2.2.10-r7, 2.4.9-r0128
expatrpm2.1.0-10.el7_3, 2.1.0-11.el7, 2.1.0-12.el7, 2.1.0-14.el7_9+8 more0:2.1.0-15.el7_9, 0:2.2.5-3.el8_1.2, 0:2.2.5-3.el8_2.3, 0:2.2.5-4.el8_4.4+2 more96
OSV records
ALPINE-CVE-2022-40674RHSA-2022:6831RHSA-2022:6832RHSA-2022:6833RHSA-2022:6834RHSA-2022:6878UBUNTU-CVE-2022-40674DLA-3119-1DSA-5236-1SUSE-SU-2022:3597-1
Also known as
USN-5638-1, USN-5638-2, USN-5638-4

Charts affected

854 by stars
ChartLatestAffected imagesRadar Score
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
expat@2.4.8-r0
2.4.9-r0

Open the chart page →

7,972
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,138
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,636

Container images carrying it

772 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
guacamole/guacd:1.1.02288530a4d1c
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
guacamole/guacd:1.3.049d43948140f
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
ha33ona/python:test6affdfc644d0
expat@2.2.10-2
2.2.10-2+deb11u4
1
halkeye/self-service-password:latest3c734dde4052
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
haugene/transmission-openvpn:4.0059216cfae4b
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
haveagitgat/tdarr:2.00.181256348872ce
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
hcguersoy/cleanreg:v0.8.063b76fdcfbe1
expat@2.4.3-r0
2.4.9-r0
1
hetznercloud/hcloud-csi-driver:1.6.01475d525f9a4
expat@2.2.10-r1
2.2.10-r7
1
hjacobs/kube-resource-report:21.2.145f93491c434
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
housewrecker/gaps:latestf417dd0a7547
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
hugohg34/toposervice:0.0.2812a03b3f274
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
ibmcom/app-nav-api:1.0.1ce9d2a564273
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ibmcom/app-nav-controller:1.0.1ee4624ba513d
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ibmcom/bai-flink-zookeeper-dev:19.0.258548034cf55
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ibmcom/bai-init-dev:19.0.2b138f1eac0b1
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
expat@2.2.5-3.el8
0:2.2.5-3.el8_2.3
1
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
expat@2.2.5-3.el8
0:2.2.5-3.el8_2.3
1
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
expat@2.2.5-4.el8
0:2.2.5-8.el8_6.3
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
ibmcom/microclimate-theia:lateste17bdccc5030
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
expat@2.2.5-3.el8
0:2.2.5-8.el8_6.3
1
ibmcom/skydive:0.22.0395e60cc6e3d
expat@2.2.5-3
2.2.5-3ubuntu0.8
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ibmcom/websphere-liberty:javaee8-ubi-min28ae40e05980
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
ihatemoney/ihatemoney:5.2.0457fda1feb32
expat@2.4.7-r0
2.4.9-r0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
intel/multimodal-data-visualization:3.03426deb77337
expat@2.4.7-r0
2.4.9-r0
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
iofog/router:2.0.17260cf861479
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
iosifache/wazuh-manager-filebeat:latest85df3f04b5da
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
istio/examples-bookinfo-productpage-v1:1.17.06668bcf42ef0
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
istio/install-cni:1.10.32232f365aed6
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
istio/node-agent-k8s:1.2.9268ab879ea51
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.