StackRadar

CVE-2022-41716

Unscored

Advisory

Published 1 Nov 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,315
of 17,790 indexed, latest versions
Container images
1,435
deployed by those charts
Fix available
1 of 1
affected package

Unsanitized NUL in environment variables on Windows in syscall and os/exec

Carried by container images the latest versions of 1,315 of 17,790 indexed charts deploy, on 1,435 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+83 more1.18.81,435
OSV records
GO-2022-1095
Also known as
BIT-golang-2022-41716

Charts affected

1,315 by stars
ChartLatestAffected imagesRadar Score
gophishhelmforgeVerified publisher0.1.51 of 1See more

gophish helmforge 0.1.5

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
gophish/gophish:0.12.18a57cd171999
stdlib@go1.15.2
1.18.8

Open the chart page →

2,819
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.18.8

Open the chart page →

11,122
komgahelmforgeVerified publisher1.4.151 of 1See more

komga helmforge 1.4.15

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
stdlib@go1.17.8
1.18.8

Open the chart page →

2,288
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
stdlib@go1.17.13
1.18.8

Open the chart page →

9,771
zookeeperhelmforgeVerified publisher1.0.21 of 1See more

zookeeper helmforge 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5f258365d4882
stdlib@go1.18.1
1.18.8

Open the chart page →

3,145
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
stdlib@go1.18
1.18.8

Open the chart page →

25,190
postgres-backup-localheywood8-helm-chartsVerified publisher0.1.131 of 1See more

postgres-backup-local heywood8-helm-charts 0.1.13

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
stdlib@go1.16
1.18.8

Open the chart page →

2,434
goshimmerhiveroad0.2.141 of 1See more

goshimmer hiveroad 0.2.14

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
iotaledger/goshimmer:v0.8.6b02a8f77474f
stdlib@go1.17.2
1.18.8

Open the chart page →

2,550
cratedb-adapterhmdmph0.1.01 of 1See more

cratedb-adapter hmdmph 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
stdlib@go1.16.3
1.18.8

Open the chart page →

2,920
imageproxyhmphuVerified publisher0.1.11 of 1See more

imageproxy hmphu 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
willnorris/imageproxy:latest21d0c90f4c31
stdlib@go1.16.8
1.18.8

Open the chart page →

2,147
honeydipperhoneydipperVerified publisher0.1.111 of 2See more

honeydipper honeydipper 0.1.11

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
library/redis:5fc5ecd863862
stdlib@go1.16.7
1.18.8

Open the chart page →

1,731
eoloplanthttpd-eoloplant0.1.02 of 7See more

eoloplant httpd-eoloplant 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.18.8
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.18.8

Open the chart page →

32,372
http-headershttp-headers1.2.11 of 1See more

http-headers http-headers 1.2.1

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
quay.io/k8start/http-headers:1.2.0c7a9987f2ac5
stdlib@go1.19.2
1.18.8

Open the chart page →

2,009
prometheushuangchengwu-helm-chart0.1.01 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
stdlib@go1.16.9
1.18.8

Open the chart page →

16,495
skywalking-v1huangchengwu-helm-chart0.1.01 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
stdlib@go1.16.9
1.18.8

Open the chart page →

20,741
tdenginehuangchengwu-helm-chart3.0.21 of 1See more

tdengine huangchengwu-helm-chart 3.0.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
tdengine/tdengine:3.0.2.24140a4021ddb
stdlib@go1.17.6
1.18.8

Open the chart page →

3,755
mocktailhuseyinnurbaki0.2.11 of 1See more

mocktail huseyinnurbaki 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
hhaluk/mocktail:2.0.3350d19360038
stdlib@go1.17.7
1.18.8

Open the chart page →

1,606
vcbackendi4trustVerified publisher0.0.81 of 1See more

vcbackend i4trust 0.0.8

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
wistefan/vcbackend:0.0.13bd436164b51
stdlib@go1.18.3
1.18.8

Open the chart page →

1,848
stoloniamalryz0.10.01 of 2See more

stolon iamalryz 0.10.0

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
stdlib@go1.13.8
1.18.8

Open the chart page →

4,052
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
library/mysql:8.0.41bf577825b52a
stdlib@go1.18.2
1.18.8

Open the chart page →

5,986
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.18.8

Open the chart page →

57,759
eoloserverihuertas2021-vmartinp2021-helm0.1.02 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
stdlib@go1.16.7
1.18.8
library/mysql:8.0.28fc77d54cacef
stdlib@go1.16.7
1.18.8

Open the chart page →

27,822
ikigaiikigai-chartVerified publisher0.0.91 of 58See more

ikigai ikigai-chart 0.0.9

1 of the 58 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
stdlib@go1.17.3
1.18.8

Open the chart page →

37,874
chronografinfluxdata1.2.61 of 1See more

chronograf influxdata 1.2.6

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
library/chronograf:1.9.496d8a3f65a4f
stdlib@go1.16.4
1.18.8

Open the chart page →

2,204
l2gethinfradao0.0.11 of 1See more

l2geth infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ethereumoptimism/l2geth:0.5.315577036dc36d
stdlib@go1.18
1.18.8

Open the chart page →

2,659
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
stdlib@go1.15.7
1.18.8

Open the chart page →

10,554
lakefsinseefrlab0.0.61 of 2See more

lakefs inseefrlab 0.0.6

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
treeverse/lakefs:0.69.0478f37a6cffc
stdlib@go1.17.8
1.18.8

Open the chart page →

2,652
instemmingserviceinstemmingservice1.0.01 of 3See more

instemmingservice instemmingservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
stdlib@go1.13.10
1.18.8

Open the chart page →

7,519
consulintelVerified publisher0.8.12 of 2See more

consul intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
stdlib@go1.19.2
1.18.8
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
stdlib@go1.19.2
1.18.8

Open the chart page →

5,403
evi-consulintelVerified publisher3.0.32 of 2See more

evi-consul intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
stdlib@go1.19.2
1.18.8
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
stdlib@go1.19.2
1.18.8

Open the chart page →

5,403
evi-vaultintelVerified publisher3.0.31 of 2See more

evi-vault intel 3.0.3

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
stdlib@go1.19.2
1.18.8

Open the chart page →

4,487
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization:3.03426deb77337
stdlib@go1.17.11
1.18.8

Open the chart page →

11,125
vaultintelVerified publisher0.8.11 of 2See more

vault intel 0.8.1

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
stdlib@go1.19.2
1.18.8

Open the chart page →

4,487
gravity-initinvisiblVerified publisher1.0.91 of 1See more

gravity-init invisibl 1.0.9

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
invisibl/gravity-init:v1.0.91a970f84178b
stdlib@go1.17.12
1.18.8

Open the chart page →

2,006
identity-managerinvisiblVerified publisher1.0.01 of 1See more

identity-manager invisibl 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
invisibl/identity-manager:1.0.01029f4fe20eb
stdlib@go1.17.11
1.18.8

Open the chart page →

2,162
identity-manager-demoinvisiblVerified publisher0.1.11 of 1See more

identity-manager-demo invisibl 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
invisibl/identity-manager-demo:v1.0.0cf5400cb935a
stdlib@go1.19.2
1.18.8

Open the chart page →

1,006
inlets-clientjacobcolvinVerified publisher0.1.21 of 1See more

inlets-client jacobcolvin 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
stdlib@go1.13.15
1.18.8

Open the chart page →

1,753
inlets-serverjacobcolvinVerified publisher0.1.11 of 1See more

inlets-server jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
stdlib@go1.13.15
1.18.8

Open the chart page →

1,753
twitch-predictions-recorderjacobcolvinVerified publisher0.1.01 of 1See more

twitch-predictions-recorder jacobcolvin 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
stdlib@go1.19.2
1.18.8

Open the chart page →

2,669
wakatime-exporterjacobcolvinVerified publisher0.1.11 of 1See more

wakatime-exporter jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
macropower/wakatime-exporter:0.1.0dbb05debb785
stdlib@go1.14.6
1.18.8

Open the chart page →

1,313
koptimizejaconiVerified publisher0.5.41 of 2See more

koptimize jaconi 0.5.4

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
alpine/k8s:1.27.321b24e6bf801
stdlib@go1.19
1.18.8

Open the chart page →

5,730
javascriptweeklyjavascriptweekly2.1.01 of 1See more

javascriptweekly javascriptweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
zufardhiyaulhaq/javascriptweekly:v2.1.086424bd0b2a4
stdlib@go1.17.13
1.18.8

Open the chart page →

1,237
jx-app-athensjenkins-x0.0.181 of 1See more

jx-app-athens jenkins-x 0.0.18

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
gomods/athens:v0.8.1d714c7ff0231
stdlib@go1.13.4
1.18.8

Open the chart page →

4,232
jx-app-flaggerjenkins-x0.0.52 of 2See more

jx-app-flagger jenkins-x 0.0.5

2 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
grafana/grafana:6.5.1befcd84da2c1
stdlib@go1.13.1
1.18.8
weaveworks/flagger:1.0.0-rc.5174307de1b36
stdlib@go1.14.2
1.18.8

Open the chart page →

6,035
knative-servingjenkins-x0.19.124 of 4See more

knative-serving jenkins-x 0.19.12

4 of the 4 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned1e3db4f2eeed
stdlib@go1.14.10
1.18.8
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinneddb6ceff2aab4
stdlib@go1.14.10
1.18.8
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedb2cd45b8a8a4
stdlib@go1.14.10
1.18.8
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedd27b4495ccc3
stdlib@go1.14.10
1.18.8

Open the chart page →

9,724
ingress-nginxjfrog4.5.21 of 2See more

ingress-nginx jfrog 4.5.2

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.18.8

Open the chart page →

3,798
alpine-torjfwenischVerified publisher1.1.01 of 1See more

alpine-tor jfwenisch 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
jfwenisch/alpine-tor:latest9e6c229f953c
stdlib@go1.14.6
1.18.8

Open the chart page →

4,461
kafka-offset-lag-for-prometheusjhidalgo3-githubVerified publisher2.3.01 of 1See more

kafka-offset-lag-for-prometheus jhidalgo3-github 2.3.0

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
stdlib@go1.17.13
1.18.8

Open the chart page →

1,470
missing-container-metricsjimdo-missing-container-metrics0.5.01 of 1See more

missing-container-metrics jimdo-missing-container-metrics 0.5.0

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
stdlib@go1.16.2
1.18.8

Open the chart page →

2,418
haven-complinacy-dashboardjolle-devVerified publisher1.0.01 of 2See more

haven-complinacy-dashboard jolle-dev 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
stdlib@go1.17.2
1.18.8

Open the chart page →

3,842

Container images carrying it

1,435 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.18.8
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.18.8
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
stdlib@go1.14.2
1.18.8
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.18.8
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
stdlib@go1.16.14
1.18.8
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
stdlib@go1.15.15
1.18.8
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
stdlib@go1.18.3
1.18.8
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
stdlib@go1.18.2
1.18.8
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
stdlib@go1.18.2
1.18.8
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
stdlib@go1.18.2
1.18.8
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
stdlib@go1.18.2
1.18.8
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
stdlib@go1.19
1.18.8
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
stdlib@go1.19
1.18.8
1
registry.k8s.io/kube-scheduler:v1.23.143e149d206076
stdlib@go1.17.13
1.18.8
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
stdlib@go1.18
1.18.8
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
stdlib@go1.18
1.18.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.18.8
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
stdlib@go1.18
1.18.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
stdlib@go1.18
1.18.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.18.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.18.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.18.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.18.8
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.18.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.18.8
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.18.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.18.8
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.