StackRadar

CVE-2022-40896

Medium

Advisory

Published 19 Jul 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
57
of 17,781 indexed, latest versions
Container images
56
deployed by those charts
Fix available
2 of 2
affected packages

Pygments vulnerable to ReDoS

Carried by container images the latest versions of 57 of 17,781 indexed charts deploy, on 56 images.

Affected packageAffected versionsFixed inImages
pygmentspypi2.2.0, 2.3.1, 2.4.2, 2.7.1+10 more2.15.0, 2.15.156
pygmentsdeb2.2.0+dfsg-1, 2.3.1+dfsg-1ubuntu2.2, 2.11.2+dfsg-2, 2.14.0+dfsg-12.11.2+dfsg-2ubuntu0.113
OSV records
DEBIAN-CVE-2022-40896GHSA-mrwq-x4v8-fh7pUBUNTU-CVE-2022-40896PYSEC-2023-117
Also known as
USN-7128-1

Charts affected

57 by stars
ChartLatestAffected imagesRadar Score
email-managerphntom0.1.221 of 2See more

email-manager phntom 0.1.22

1 of the 2 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
phntom/email-manager:0.1.22d8e2a9f2f085
pygments@2.14.0
2.15.0

Open the chart page →

2,565
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
pygments@2.3.1+dfsg-1ubuntu2.2
pygments@2.3.1
no fix listed
2.15.0

Open the chart page →

30,687
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
pygments@2.13.0
2.15.0

Open the chart page →

1,447
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
pygments@2.12.0
2.15.0

Open the chart page →

18,756
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
pygments@2.10.0
2.15.0

Open the chart page →

5,321
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pygments@2.15.0
2.15.1

Open the chart page →

7,085
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
pygments@2.14.0
2.15.0

Open the chart page →

5,846

Container images carrying it

56 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
pygments@2.12.0
2.15.0
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pygments@2.12.0
2.15.0
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
pygments@2.14.0+dfsg-1
pygments@2.14.0
no fix listed
2.15.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
pygments@2.12.0
2.15.0
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
pygments@2.11.2
2.15.0
1
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
pygments@2.13.0
2.15.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.