StackRadar

CVE-2022-40674

High

Advisory

Published 14 Sept 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
854
of 17,787 indexed, latest versions
Container images
772
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 854 of 17,787 indexed charts deploy, on 772 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+16 more2.1.0-4ubuntu1.4+esm7, 2.1.0-7ubuntu0.16.04.5+esm6, 2.2.5-3ubuntu0.8, 2.2.6-2+deb10u5+3 more548
expatapk2.2.10-r1, 2.2.10-r2, 2.2.10-r6, 2.4.1-r0+5 more2.2.10-r7, 2.4.9-r0128
expatrpm2.1.0-10.el7_3, 2.1.0-11.el7, 2.1.0-12.el7, 2.1.0-14.el7_9+8 more0:2.1.0-15.el7_9, 0:2.2.5-3.el8_1.2, 0:2.2.5-3.el8_2.3, 0:2.2.5-4.el8_4.4+2 more96
OSV records
ALPINE-CVE-2022-40674RHSA-2022:6831RHSA-2022:6832RHSA-2022:6833RHSA-2022:6834RHSA-2022:6878UBUNTU-CVE-2022-40674DLA-3119-1DSA-5236-1SUSE-SU-2022:3597-1
Also known as
USN-5638-1, USN-5638-2, USN-5638-4

Charts affected

854 by stars
ChartLatestAffected imagesRadar Score
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
expat@2.4.8-r0
2.4.9-r0

Open the chart page →

7,972
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,138
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,636

Container images carrying it

772 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
istio/operator:1.10.3655eefa11c84
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
istio/pilot:1.10.0294ca55bd1cc
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
istio/pilot:1.2.9c09319753454
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
istio/pilot:1.10.3e7e110a421c2
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
istio/proxyv2:1.2.90c78be035e98
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
istio/proxyv2:1.9.687a9db561d2e
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
istio/proxyv2:1.10.088c6c693e67a
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
expat@2.2.10-2
2.2.10-2+deb11u4
1
j4ckhunter/consumer:1.00bb7a429e3e75
expat@2.4.8-r0
2.4.9-r0
1
j4ckhunter/producer:1.006ba447609b12
expat@2.4.8-r0
2.4.9-r0
1
jacobalberty/unifi:v7.1.664a3616625dda
expat@2.2.5-3ubuntu0.7
2.2.5-3ubuntu0.8
1
jacobalberty/unifi:5.10.19c409924e2463
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
jakowenko/double-take:1.6.0b858bac9e32a
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
jakuboskera/guestbook:v0.3.04989afa06e74
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
jakuboskera/todo:v0.2.3714b1adbbc2d
expat@2.4.5-r0
2.4.9-r0
1
jedi132000/nextapp:latestdc2a81e92f23
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
jellyfin/jellyfin:10.8.1ee24f4459a40
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
jertel/elastalert2:2.2.34dcc0ef93efc
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
jfwenisch/alpine-tor:latest9e6c229f953c
expat@2.2.10-r1
2.2.10-r7
1
jmferrer/azure-devops-agent:latest030f68ec6998
expat@2.1.0-7ubuntu0.16.04.5
2.1.0-7ubuntu0.16.04.5+esm6
1
julb/alertmanager-gchat-integration:1.0.5837c4038a0dd
expat@2.2.10-r1
2.2.10-r7
1
julb/http-url-playlist:1.0.2782ef45279d5
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
expat@2.2.6-2+deb10u4
2.2.6-2+deb10u5
1
kelvinsp/mlflow:1.26.1cd33e6db2a59
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
kennethreitz/httpbin:latest599fe5e50731
expat@2.2.5-3
2.2.5-3ubuntu0.8
1
kfserving/models-web-app:v0.6.1f322d6ffdfa3
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
kiwigrid/k8s-sidecar:1.12.089739be9ff38
expat@2.2.10-r1
2.2.10-r7
1
kiwigrid/k8s-sidecar:0.1.20af151f677a63
expat@2.2.6-2
2.2.6-2+deb10u5
1
kobotoolbox/kobocat:2.022.24ab15679454415
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
kserve/models-web-app:v0.8.063ea05e73842
expat@2.2.6-2+deb10u4
2.2.6-2+deb10u5
1
kubebb/hello-world:0.1.0b746824819f3
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
kubedex/helm-controller:v1.0.14f1008c51ef9
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
kubitodev/traefik-ip-whitelist-sync:1.0.2aa24869319bf
expat@2.4.7-r0
2.4.9-r0
1
ladeit/ladeit:latest962b665ffe82
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
ldapaccountmanager/lam:7.295533a96a4c1
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
library/cassandra:3.11.10b095ff3248c6
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
library/drupal:8-apache8a1a3ee83899
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
library/flink:1.11.2-scala_2.121fe4fb22a2a5
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
library/flink:1.14.6-scala_2.122461f02672b3
expat@2.4.7-1
2.4.7-1ubuntu0.1
1
library/kibana:7.17.3e2e2031c15be
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
library/nextcloud:17.0.0-apache96104cb965fc
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
library/nginx:1.23.03536d368b898
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
library/nginx:1.19.68e1095642250
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
library/nginx:1.17.6b2d89d0a2103
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.