StackRadar

CVE-2022-41727

Medium

Advisory

Published 16 Feb 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.003
23rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
32
of 17,781 indexed, latest versions
Container images
31
deployed by those charts
Fix available
1 of 1
affected package

Uncontrolled Resource Consumption in golang.org/x/image

Carried by container images the latest versions of 32 of 17,781 indexed charts deploy, on 31 images.

Affected packageAffected versionsFixed inImages
golang.org/x/imagegolangv0.0.0-20190802002840-cff245a6509b, v0.0.0-20191009234506-e7c1f5e7dbb8, v0.0.0-20201208152932-35266b937fa6, v0.0.0-20210216034530-4410531fe030+8 more0.5.031
OSV records
GHSA-qgc7-mgm3-q253
Also known as
GO-2023-1572

Charts affected

32 by stars
ChartLatestAffected imagesRadar Score
codercoderOfficialVerified publisher1.44.61 of 2See more

coder coder 1.44.6

1 of the 2 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/image@v0.0.0-20210216034530-4410531fe030
0.5.0

Open the chart page →

6,849
filebrowserutkuozdemirVerified publisher1.0.01 of 1See more

filebrowser utkuozdemir 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.5.0

Open the chart page →

3,073
listmonkdeliveryheroVerified publisher0.1.121 of 1See more

listmonk deliveryhero 0.1.12

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.5.0

Open the chart page →

2,537
filebrowsergeek-cookbookVerified publisher1.4.21 of 1See more

filebrowser geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.18.04fcd47af573c
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.5.0

Open the chart page →

3,474
focalboardgeek-cookbookVerified publisher4.4.21 of 1See more

focalboard geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
mattermost/focalboard:0.9.031078df7a3c8
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0

Open the chart page →

3,631
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.5.0

Open the chart page →

15,856
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/image@v0.0.0-20220302094943-723b81ca9867
0.5.0

Open the chart page →

2,312
cospacecospace0.0.341 of 3See more

cospace cospace 0.0.34

1 of the 3 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
ghcr.io/twigex/cospace:lateste5ecfd607e42
golang.org/x/image@v0.0.0-20210607152325-775e3b0c77b9
0.5.0

Open the chart page →

2,253
commentoduyet0.2.01 of 2See more

commento duyet 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.5.0

Open the chart page →

2,679
Navidromeemmas-chartsVerified publisher0.0.41 of 1See more

Navidrome emmas-charts 0.0.4

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
deluan/navidrome:0.49.311a24da08977
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.5.0

Open the chart page →

2,837
testnet-homepageethereum-helm-chartsVerified publisher0.2.31 of 1See more

testnet-homepage ethereum-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0

Open the chart page →

2,681
dendritegeek-cookbookVerified publisher6.4.01 of 1See more

dendrite geek-cookbook 6.4.0

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.5.0

Open the chart page →

2,143
gatusgeek-cookbookVerified publisher1.1.21 of 1See more

gatus geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.5.0

Open the chart page →

1,881
gonicgeek-cookbookVerified publisher6.4.21 of 1See more

gonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
sentriz/gonic:v0.13.1a74012a6adf3
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.5.0

Open the chart page →

3,525
navidromegeek-cookbookVerified publisher6.4.21 of 1See more

navidrome geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.5.0

Open the chart page →

3,597
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.5.0

Open the chart page →

3,236
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/image@v0.0.0-20220617043117-41969df76e82
0.5.0

Open the chart page →

19,503
vikunjageek-cookbookVerified publisher6.2.01 of 4See more

vikunja geek-cookbook 6.2.0

1 of the 4 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
vikunja/api:0.17.18cba0520bf8c
golang.org/x/image@v0.0.0-20210504121937-7319ad40d33e
0.5.0

Open the chart page →

6,893
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0

Open the chart page →

4,455
listmonkhelm-charts-nr0.1.121 of 1See more

listmonk helm-charts-nr 0.1.12

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.5.0

Open the chart page →

2,537
imageproxyhmphuVerified publisher0.1.11 of 1See more

imageproxy hmphu 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.5.0

Open the chart page →

2,140
casdoor-helm-chartskubeblocksVerified publisher1.753.01 of 1See more

casdoor-helm-charts kubeblocks 1.753.0

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
casbin/casdoor:v1.753.0770ad9ec3190
golang.org/x/image@v0.0.0-20220302094943-723b81ca9867
0.5.0

Open the chart page →

2,299
metadockvalitetsitVerified publisher0.0.71 of 2See more

metadoc kvalitetsit 0.0.7

1 of the 2 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0

Open the chart page →

4,026
focalboardmattermostVerified publisher0.5.01 of 1See more

focalboard mattermost 0.5.0

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
mattermost/focalboard:0.6.7f2f987dada52
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0

Open the chart page →

4,014
mattermost-chaos-enginemattermostVerified publisher0.2.01 of 1See more

mattermost-chaos-engine mattermost 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
mattermost/mattermost-app-chaosengine:c153e436268954edd67
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0

Open the chart page →

4,067
mindavphntom0.1.61 of 2See more

mindav phntom 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.5.0

Open the chart page →

4,158
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.5.0

Open the chart page →

5,582
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.5.0

Open the chart page →

3,073
agentssynapse0.1.302 of 9See more

agents synapse 0.1.30

2 of the 9 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.5.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.5.0

Open the chart page →

7,244
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.5.0

Open the chart page →

1,955
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.5.0

Open the chart page →

3,174
commentopluspluswyrihaximusnetVerified publisher0.4.01 of 1See more

commentoplusplus wyrihaximusnet 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-41727.

Container imageDigestPackageFixed in
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0

Open the chart page →

1,960

Container images carrying it

31 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.5.0
2
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.5.0
2
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0
1
casbin/casdoor:v1.753.0770ad9ec3190
golang.org/x/image@v0.0.0-20220302094943-723b81ca9867
0.5.0
1
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/image@v0.0.0-20210216034530-4410531fe030
0.5.0
1
deluan/navidrome:0.49.311a24da08977
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.5.0
1
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.5.0
1
filebrowser/filebrowser:v2.18.04fcd47af573c
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.5.0
1
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.5.0
1
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.5.0
1
mattermost/focalboard:0.9.031078df7a3c8
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0
1
mattermost/focalboard:0.6.7f2f987dada52
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0
1
mattermost/mattermost-app-chaosengine:c153e436268954edd67
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0
1
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.5.0
1
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.5.0
1
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/image@v0.0.0-20220617043117-41969df76e82
0.5.0
1
sentriz/gonic:v0.13.1a74012a6adf3
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.5.0
1
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0
1
stashapp/stash:latest24dbd7607174
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.5.0
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.5.0
1
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.5.0
1
vikunja/api:0.17.18cba0520bf8c
golang.org/x/image@v0.0.0-20210504121937-7319ad40d33e
0.5.0
1
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.5.0
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/image@v0.0.0-20220302094943-723b81ca9867
0.5.0
1
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.5.0
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.5.0
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.5.0
1
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.5.0
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
golang.org/x/image@v0.0.0-20210607152325-775e3b0c77b9
0.5.0
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.