StackRadar

CVE-2022-41716

Unscored

Advisory

Published 1 Nov 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.008
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,315
of 17,787 indexed, latest versions
Container images
1,435
deployed by those charts
Fix available
1 of 1
affected package

Unsanitized NUL in environment variables on Windows in syscall and os/exec

Carried by container images the latest versions of 1,315 of 17,787 indexed charts deploy, on 1,435 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+83 more1.18.81,435
OSV records
GO-2022-1095
Also known as
BIT-golang-2022-41716

Charts affected

1,315 by stars
ChartLatestAffected imagesRadar Score
gboxgboxVerified publisher1.0.51 of 2See more

gbox gbox 1.0.5

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
gboxproxy/gbox:v1.0.63a9f4a711d5c
stdlib@go1.17.9
1.18.8

Open the chart page →

2,521
adguard-homegeek-cookbookVerified publisher5.5.21 of 2See more

adguard-home geek-cookbook 5.5.2

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.7b9974aed13d0
stdlib@go1.17.9
1.18.8

Open the chart page →

1,742
alertmanager-botgeek-cookbookVerified publisher6.4.21 of 1See more

alertmanager-bot geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
stdlib@go1.13.15
1.18.8

Open the chart page →

3,586
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
stdlib@go1.16.8
1.18.8

Open the chart page →

17,438
filebrowsergeek-cookbookVerified publisher1.4.21 of 1See more

filebrowser geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.18.04fcd47af573c
stdlib@go1.16.9
1.18.8

Open the chart page →

3,474
focalboardgeek-cookbookVerified publisher4.4.21 of 1See more

focalboard geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
mattermost/focalboard:0.9.031078df7a3c8
stdlib@go1.16.5
1.18.8

Open the chart page →

3,631
influxdb-exportergeek-cookbookVerified publisher1.2.21 of 1See more

influxdb-exporter geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
prom/influxdb-exporter:v0.9.0f63fd77c05ee
stdlib@go1.17.8
1.18.8

Open the chart page →

1,051
otel-collectorgeek-cookbookVerified publisher1.2.21 of 1See more

otel-collector geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
stdlib@go1.17.7
1.18.8

Open the chart page →

2,556
owncastgeek-cookbookVerified publisher3.4.21 of 1See more

owncast geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
gabekangas/owncast:0.0.797461aedb580
stdlib@go1.15.2
1.18.8

Open the chart page →

3,167
protonmail-bridgegeek-cookbookVerified publisher5.4.21 of 1See more

protonmail-bridge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
stdlib@go1.15.12
1.18.8

Open the chart page →

8,035
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
stdlib@go1.16.8
1.18.8

Open the chart page →

11,606
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
stdlib@go1.15
1.18.8

Open the chart page →

10,279
sambageek-cookbookVerified publisher6.2.21 of 1See more

samba geek-cookbook 6.2.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/crazy-max/samba:4.15.5bed6f4ec2e82
stdlib@go1.17.2
1.18.8

Open the chart page →

2,318
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
stdlib@go1.18.4
1.18.8

Open the chart page →

13,071
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
stdlib@go1.13.15
1.18.8

Open the chart page →

15,917
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
stdlib@go1.17.5
1.18.8

Open the chart page →

5,079
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.18.8

Open the chart page →

7,698
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.31 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

1 of the 9 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
library/postgres:15.38775adb39f0d
stdlib@go1.18.2
1.18.8

Open the chart page →

15,606
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
library/mariadb:10.6.218a16204dc96c
stdlib@go1.18.2
1.18.8

Open the chart page →

6,458
carettagroundcover0.0.161 of 3See more

caretta groundcover 0.0.16

1 of the 3 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
stdlib@go1.18
1.18.8

Open the chart page →

6,799
hawkhawk1.1.52 of 4See more

hawk hawk 1.1.5

2 of the 4 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
stdlib@go1.17.9
1.18.8
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.18.8

Open the chart page →

13,656
guacamolehelmforgeVerified publisher1.5.21 of 5See more

guacamole helmforge 1.5.2

1 of the 5 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
library/postgres:17.5-bookwormfbcea1bd13b6
stdlib@go1.18.2
1.18.8

Open the chart page →

8,773
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
stdlib@go1.15.12
1.18.8

Open the chart page →

6,977
cratedb-adapter-v2hmdmph0.2.11 of 1See more

cratedb-adapter-v2 hmdmph 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
stdlib@go1.16.3
1.18.8

Open the chart page →

2,913
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
stdlib@go1.17
1.18.8

Open the chart page →

6,810
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
stdlib@go1.17.2
1.18.8

Open the chart page →

1,573
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
stdlib@go1.18.2
1.18.8

Open the chart page →

15,749
inbucketinbucketVerified publisher2.5.01 of 1See more

inbucket inbucket 2.5.0

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
inbucket/inbucket:3.0.01f10a0efea69
stdlib@go1.17.1
1.18.8

Open the chart page →

2,167
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
stdlib@go1.16.6
1.18.8

Open the chart page →

10,415
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
stdlib@go1.16.6
1.18.8

Open the chart page →

10,489
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.18.8

Open the chart page →

10,435
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.18.8

Open the chart page →

10,435
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
stdlib@go1.16.6
1.18.8

Open the chart page →

10,716
istio-ratelimitistio-ratelimitVerified publisher0.0.51 of 2See more

istio-ratelimit istio-ratelimit 0.0.5

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:4d2efd61ede09a75a84c
stdlib@go1.14.15
1.18.8

Open the chart page →

1,812
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
stdlib@go1.17.13
1.18.8

Open the chart page →

9,318
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
stdlib@go1.18.7
1.18.8

Open the chart page →

3,369
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.18.8

Open the chart page →

5,302
giteakeyporttech0.2.102 of 4See more

gitea keyporttech 0.2.10

2 of the 4 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
gitea/gitea:1.12.485416d6f65fe
stdlib@go1.14.8
1.18.8
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.18.8

Open the chart page →

5,408
kubefedkubefed0.10.01 of 2See more

kubefed kubefed 0.10.0

1 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
quay.io/kubernetes-multicluster/kubefed:v0.10.0c4635c95730e
stdlib@go1.16.6
1.18.8

Open the chart page →

2,419
kubernetes-stateless-chartkubernetes-stateless-chart1.0.31 of 1See more

kubernetes-stateless-chart kubernetes-stateless-chart 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
stdlib@go1.18.7
1.18.8

Open the chart page →

3,275
mesherykubesphere-stable0.5.02 of 13See more

meshery kubesphere-stable 0.5.0

2 of the 13 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
stdlib@go1.13.1
1.18.8
layer5/meshery-nsm:stable-latestebd6a8faf21f
stdlib@go1.15.12
1.18.8

Open the chart page →

24,690
aws-efs-csi-driverkubesphere-testVerified publisher0.1.01 of 3See more

aws-efs-csi-driver kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
stdlib@go1.13.4
1.18.8

Open the chart page →

2,605
kube-state-metricskubestar-state-metricsVerified publisher0.1.101 of 1See more

kube-state-metrics kubestar-state-metrics 0.1.10

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
stdlib@go1.18.5
1.18.8

Open the chart page →

1,575
kubemodkubmod0.5.22 of 2See more

kubemod kubmod 0.5.2

2 of the 2 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.19.11f8154f7e80c
stdlib@go1.18
1.18.8
kubemod/kubemod-crt:v1.3.0028347c9fa77
stdlib@go1.18.1
1.18.8

Open the chart page →

4,542
kubeservice-namespace-node-affinitykubservice-chartsVerified publisher1.1.21 of 5See more

kubeservice-namespace-node-affinity kubservice-charts 1.1.2

1 of the 5 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
dongjiang1989/ns-node-affinity:latest451f7823723c
stdlib@go1.18.5
1.18.8

Open the chart page →

6,872
linstorkvaps1.14.04 of 11See more

linstor kvaps 1.14.0

4 of the 11 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
stdlib@go1.15.14
1.18.8
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
stdlib@go1.15.14
1.18.8
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
stdlib@go1.15.14
1.18.8
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
stdlib@go1.15.14
1.18.8

Open the chart page →

15,551
landelijketabellencataloguslandelijketabellencatalogus1.0.01 of 3See more

landelijketabellencatalogus landelijketabellencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
stdlib@go1.13.10
1.18.8

Open the chart page →

7,510
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
stdlib@go1.13.8
1.18.8

Open the chart page →

4,456
linkerd-jaegerlinkerd2-edgeVerified publisher30.14.11-edge1 of 4See more

linkerd-jaeger linkerd2-edge 30.14.11-edge

1 of the 4 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
stdlib@go1.17.6
1.18.8

Open the chart page →

4,389
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2022-41716.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
stdlib@go1.18.2
1.18.8

Open the chart page →

7,915

Container images carrying it

1,435 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.18.8
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.18.8
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
stdlib@go1.14.2
1.18.8
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.18.8
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
stdlib@go1.16.14
1.18.8
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
stdlib@go1.15.15
1.18.8
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
stdlib@go1.18.3
1.18.8
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
stdlib@go1.18.2
1.18.8
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
stdlib@go1.18.2
1.18.8
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
stdlib@go1.18.2
1.18.8
1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
stdlib@go1.18.2
1.18.8
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
stdlib@go1.19
1.18.8
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
stdlib@go1.19
1.18.8
1
registry.k8s.io/kube-scheduler:v1.23.143e149d206076
stdlib@go1.17.13
1.18.8
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
stdlib@go1.18
1.18.8
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
stdlib@go1.18
1.18.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.18.8
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
stdlib@go1.18
1.18.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
stdlib@go1.18
1.18.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.18.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.18.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.18.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.18.8
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.18.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.18.8
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.18.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.18.8
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.18.8
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.