StackRadar

CVE-2022-40896

Medium

Advisory

Published 19 Jul 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
57
of 17,781 indexed, latest versions
Container images
56
deployed by those charts
Fix available
2 of 2
affected packages

Pygments vulnerable to ReDoS

Carried by container images the latest versions of 57 of 17,781 indexed charts deploy, on 56 images.

Affected packageAffected versionsFixed inImages
pygmentspypi2.2.0, 2.3.1, 2.4.2, 2.7.1+10 more2.15.0, 2.15.156
pygmentsdeb2.2.0+dfsg-1, 2.3.1+dfsg-1ubuntu2.2, 2.11.2+dfsg-2, 2.14.0+dfsg-12.11.2+dfsg-2ubuntu0.113
OSV records
DEBIAN-CVE-2022-40896GHSA-mrwq-x4v8-fh7pUBUNTU-CVE-2022-40896PYSEC-2023-117
Also known as
USN-7128-1

Charts affected

57 by stars
ChartLatestAffected imagesRadar Score
email-managerphntom0.1.221 of 2See more

email-manager phntom 0.1.22

1 of the 2 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
phntom/email-manager:0.1.22d8e2a9f2f085
pygments@2.14.0
2.15.0

Open the chart page →

2,565
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
pygments@2.3.1+dfsg-1ubuntu2.2
pygments@2.3.1
no fix listed
2.15.0

Open the chart page →

30,687
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
pygments@2.13.0
2.15.0

Open the chart page →

1,447
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
pygments@2.12.0
2.15.0

Open the chart page →

18,756
tezos-nodetezos-nodeVerified publisher1.0.01 of 4See more

tezos-node tezos-node 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
pygments@2.10.0
2.15.0

Open the chart page →

5,321
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
pygments@2.15.0
2.15.1

Open the chart page →

7,085
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-40896.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
pygments@2.14.0
2.15.0

Open the chart page →

5,846

Container images carrying it

56 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
cs3org/wopiserver:v9.4.202a9e78757b4
pygments@2.14.0
2.15.0
2
acockburn/appdaemon:4.0.83a93281d7e94
pygments@2.8.1
2.15.0
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
pygments@2.3.1+dfsg-1ubuntu2.2
pygments@2.3.1
no fix listed
2.15.0
1
apachepulsar/pulsar:2.6.14db6ff0b4045
pygments@2.3.1
2.15.0
1
apachepulsar/pulsar:2.9.0d056c89b7131
pygments@2.3.1+dfsg-1ubuntu2.2
pygments@2.3.1
no fix listed
2.15.0
1
apachepulsar/pulsar:2.8.2d538416d5afe
pygments@2.3.1+dfsg-1ubuntu2.2
pygments@2.3.1
no fix listed
2.15.0
1
apache/superset:4.0.1ab9467fd712c
pygments@2.15.0
2.15.1
1
blacktop/httpie:latestfc5e68e2f5ab
pygments@2.2.0
2.15.0
1
cdignam/kodiak:v0.54.05a6a55b39cee
pygments@2.10.0
2.15.0
1
cheyang/distributed-tf:1.6.046cc34755493
pygments@2.2.0
2.15.0
1
daskdev/dask-notebook:1.1.0052630f5ca04
pygments@2.3.1
2.15.0
1
deconzcommunity/deconz:2.29.2062de2362641
pygments@2.14.0+dfsg-1
pygments@2.14.0
no fix listed
2.15.0
1
deconzcommunity/deconz:2.12.066541bbb78952
pygments@2.3.1
2.15.0
1
errbotio/errbot:6.1.900ee4e0953ab
pygments@2.11.2
2.15.0
1
evk02/mlflow:2.2.1ef6ff257ef35
pygments@2.14.0
2.15.0
1
fluent/fluent-bit:4.0-debuge76397ef3983
pygments@2.14.0+dfsg-1
pygments@2.14.0
no fix listed
2.15.0
1
flyway/flyway:9.1545b5d7cdc75a
pygments@2.14.0
2.15.0
1
flyway/flyway:9.14.1-alpine80f12c80502b
pygments@2.14.0
2.15.0
1
fossology/fossology:4.2.18bd1f22ba7bb
pygments@2.13.0
2.15.0
1
galaxy/galaxy-init:v18.010267bad550e6
pygments@2.2.0
2.15.0
1
gethue/hue:4.11.011b649636e68
pygments@2.14.0
2.15.0
1
gethue/hue:4.10.05702b2c37ff9
pygments@2.9.0
2.15.0
1
hjacobs/kube-web-view:20.10.0b44a9cf81a2f
pygments@2.7.1
2.15.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
pygments@2.9.0
2.15.0
1
jmferrer/azure-devops-agent:latest030f68ec6998
pygments@2.4.2
2.15.0
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
pygments@2.7.1
2.15.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pygments@2.11.2
2.15.0
1
kyso/kyso-nbdime:latest4aa9d38ee81d
pygments@2.13.0
2.15.0
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
pygments@2.8.1
2.15.0
1
makersquad/harp-proxy:0.8.1a40dd258c527
pygments@2.14.0+dfsg-1
pygments@2.14.0
no fix listed
2.15.0
1
mediagis/nominatim:3.7c15e941485ef
pygments@2.3.1+dfsg-1ubuntu2.2
pygments@2.3.1
no fix listed
2.15.0
1
mediagis/nominatim:4.2d0eae7b51374
pygments@2.11.2+dfsg-2
pygments@2.11.2
2.11.2+dfsg-2ubuntu0.1
2.15.0
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pygments@2.2.0
2.15.0
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pygments@2.2.0
2.15.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
pygments@2.12.0
2.15.0
1
opendatacube/wms:latest1b90cdf68831
pygments@2.2.0+dfsg-1
pygments@2.2.0
no fix listed
2.15.0
1
openzaak/open-notificaties:1.3.02e65313b9b10
pygments@2.4.2
2.15.0
1
oxheadalpha/tezos-k8s-utils:5.3.4d9faed45bf1c
pygments@2.10.0
2.15.0
1
phntom/email-manager:0.1.22d8e2a9f2f085
pygments@2.14.0
2.15.0
1
roadiehq/community-backstage-image:latestef355bf5b639
pygments@2.7.4
2.15.0
1
robmarkcole/deepstack-ui:latest410275726459
pygments@2.10.0
2.15.0
1
searx/searx:1.0.0-211-968b28993dbb3a6d9419
pygments@2.8.0
2.15.0
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
pygments@2.3.1+dfsg-1ubuntu2.2
pygments@2.3.1
no fix listed
2.15.0
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
pygments@2.12.0
2.15.0
1
taigaio/taiga-back:6.4.29f97323cc150
pygments@2.9.0
2.15.0
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
pygments@2.2.0
2.15.0
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
pygments@2.11.2+dfsg-2
pygments@2.11.2
2.11.2+dfsg-2ubuntu0.1
2.15.0
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
pygments@2.11.2+dfsg-2
pygments@2.11.2
2.11.2+dfsg-2ubuntu0.1
2.15.0
1
timescale/timescaledb-ha:pg16d7db8f1085a3
pygments@2.11.2
2.15.0
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
pygments@2.11.2
2.15.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.