StackRadar

CVE-2022-40674

High

Advisory

Published 14 Sept 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
854
of 17,787 indexed, latest versions
Container images
772
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: expat security update

Carried by container images the latest versions of 854 of 17,787 indexed charts deploy, on 772 images.

Affected packageAffected versionsFixed inImages
expatdeb2.1.0-4ubuntu1, 2.1.0-4ubuntu1.4, 2.1.0-7ubuntu0.16.04.2, 2.1.0-7ubuntu0.16.04.3+16 more2.1.0-4ubuntu1.4+esm7, 2.1.0-7ubuntu0.16.04.5+esm6, 2.2.5-3ubuntu0.8, 2.2.6-2+deb10u5+3 more548
expatapk2.2.10-r1, 2.2.10-r2, 2.2.10-r6, 2.4.1-r0+5 more2.2.10-r7, 2.4.9-r0128
expatrpm2.1.0-10.el7_3, 2.1.0-11.el7, 2.1.0-12.el7, 2.1.0-14.el7_9+8 more0:2.1.0-15.el7_9, 0:2.2.5-3.el8_1.2, 0:2.2.5-3.el8_2.3, 0:2.2.5-4.el8_4.4+2 more96
OSV records
ALPINE-CVE-2022-40674RHSA-2022:6831RHSA-2022:6832RHSA-2022:6833RHSA-2022:6834RHSA-2022:6878UBUNTU-CVE-2022-40674DLA-3119-1DSA-5236-1SUSE-SU-2022:3597-1
Also known as
USN-5638-1, USN-5638-2, USN-5638-4

Charts affected

854 by stars
ChartLatestAffected imagesRadar Score
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
expat@2.4.8-r0
2.4.9-r0

Open the chart page →

7,972
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,138
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

3,118
grafana-matrix-forwarderzloi-space1.0.01 of 2See more

grafana-matrix-forwarder zloi-space 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40674.

Container imageDigestPackageFixed in
matrixdotorg/pantalaimon:v0.10.4ba6a587fa508
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5

Open the chart page →

1,636

Container images carrying it

772 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
monogramm/docker-dolibarr:13.0-alpine5afd99523984
expat@2.2.10-r1
2.2.10-r7
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
expat@2.2.10-2
2.2.10-2+deb11u4
1
mozilla/sentencecollector:2.0.91da6ff5c4895
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
muluder/prograncontrollermcord:0.1.843b597a93da7
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
namshi/smtp:latestaa63b8de68ce
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
netboxcommunity/netbox:v3.2.83d652dca5351
expat@2.4.7-1
2.4.7-1ubuntu0.1
1
nginx/nginx-ingress:1.11.1eb5b4fd73325
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
nmalhotr/webserver:v1.0.03419361fb0dd
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
noojee/unpubd:0.0.52b3148574f68
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
norskel/site-usb:id45fd6798558d
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
novumrgi/glowroot-central:0.14.0-beta.38c54790675b1
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
ntakashi/gitana:1.4.04171ec641120
expat@2.2.10-2
2.2.10-2+deb11u4
1
nyurik/alpine-python3-requests:lateste0553236e3eb
expat@2.4.1-r0
2.4.9-r0
1
octoprint/octoprint:1.4.0106c26efcd8a
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
octoprint/octoprint:1.6.1ea3bffae2470
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
expat@2.4.7-r0
2.4.9-r0
1
omecproject/c3po-hssdb:master-latest28a90cc26716
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
expat@2.2.5-3
2.2.5-3ubuntu0.8
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
omecproject/onos-progran:1.0.05715e5648aa0
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
expat@2.1.0-7ubuntu0.16.04.3
2.1.0-7ubuntu0.16.04.5+esm6
1
onosproject/onos:2.2.144914a8d4b3f
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
opendatacube/pipelines:wofs-1.225d810e8504b8
expat@2.2.5-3
2.2.5-3ubuntu0.8
1
opendatacube/restcube:latest91870111837c
expat@2.2.5-3
2.2.5-3ubuntu0.8
1
opendatacube/wms:latest1b90cdf68831
expat@2.2.5-3
2.2.5-3ubuntu0.8
1
openelevation/open-elevation:latest82fb21612e86
expat@2.2.9-1build1
2.2.9-1ubuntu0.5
1
openemr/openemr:6.1.089eaa6d9a4e3
expat@2.4.7-r0
2.4.9-r0
1
openhab/openhab:3.2.0d0aa4af452c1
expat@2.2.10-2
2.2.10-2+deb11u4
1
openkm/openkm-ce:6.3.113bc465a7461b
expat@2.2.9-1ubuntu0.4
2.2.9-1ubuntu0.5
1
openliberty/open-liberty:javaee8-ubi-min6f9278b8b2cc
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
openliberty/open-liberty:springBoot2-ubi-minc649524bc428
expat@2.1.0-10.el7_3
0:2.1.0-15.el7_9
1
openproject/community:12.0.2734743d11094
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
openwhisk/kafkaprovider:2.1.063dc3d2a0904
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
expat@2.2.5-3ubuntu0.2
2.2.5-3ubuntu0.8
1
openzaak/open-notificaties:1.3.02e65313b9b10
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
opsmx11/issuegen:v2.1.05c50ca123d88
expat@2.1.0-4ubuntu1.4
2.1.0-4ubuntu1.4+esm7
1
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
expat@2.4.1-r0
2.4.9-r0
1
pecan/docs:1.7.2eaa878d57ef2
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
pecan/monitor:1.7.273b2074f3fec
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
pecan/web:1.7.2814d678c5550
expat@2.2.10-2
2.2.10-2+deb11u4
1
phntom/binaryvision-static-wordpress:0.0.385a2dfb83b11
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
phntom/binaryvision-tlo-static:0.0.4e8b9ac93a3dd
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
phntom/codimd:2.4.31b9aafbb62e6
expat@2.2.6-2+deb10u4
2.2.6-2+deb10u5
1
phntom/fireflyiii:version-5.7.5f881ea5fbbf1
expat@2.2.6-2+deb10u4
2.2.6-2+deb10u5
1
phntom/kix-static-website:latest49ce665acb59
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1
phntom/mattermost-defaultbackend:6.4.0c318dc90a4bf
expat@2.2.10-2
2.2.10-2+deb11u4
1
photoprism/photoprism:220629-jammy2954334adbda
expat@2.4.7-1
2.4.7-1ubuntu0.1
1
phpmyadmin/phpmyadmin:5.138437e021deb
expat@2.2.10-2+deb11u3
2.2.10-2+deb11u4
1
plumdog/db-operator:latest0c2fa2db0357
expat@2.2.6-2+deb10u1
2.2.6-2+deb10u5
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.