StackRadar

CVE-2022-45199

High

Advisory

Published 14 Nov 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.012
65th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
33
of 17,781 indexed, latest versions
Container images
31
deployed by those charts
Fix available
1 of 1
affected package

Pillow subject to DoS via SAMPLESPERPIXEL tag

Carried by container images the latest versions of 33 of 17,781 indexed charts deploy, on 31 images.

Affected packageAffected versionsFixed inImages
pillowpypi4.3.0, 5.0.0, 5.1.0, 5.2.0+9 more9.3.031
OSV records
GHSA-q4mp-jvh2-76fjPYSEC-2022-42980
Also known as
BIT-pillow-2022-45199

Charts affected

33 by stars
ChartLatestAffected imagesRadar Score
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
pillow@9.2.0
9.3.0

Open the chart page →

9,145
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pillow@9.1.0
9.3.0

Open the chart page →

7,705
taigarc-helm-charts0.1.01 of 7See more

taiga rc-helm-charts 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
taigaio/taiga-back:6.4.29f97323cc150
pillow@8.2.0
9.3.0

Open the chart page →

7,255
frigategeek-cookbookVerified publisher8.2.21 of 1See more

frigate geek-cookbook 8.2.2

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
pillow@8.1.0
9.3.0

Open the chart page →

10,598
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
pillow@8.4.0
9.3.0

Open the chart page →

7,579
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
pillow@9.1.0
9.3.0
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pillow@9.1.0
9.3.0

Open the chart page →

18,517
weblatedeliveryheroVerified publisher0.3.21 of 3See more

weblate deliveryhero 0.3.2

1 of the 3 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
pillow@7.2.0
9.3.0

Open the chart page →

7,984
lazylibrariangeek-cookbookVerified publisher7.4.21 of 1See more

lazylibrarian geek-cookbook 7.4.2

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
linuxserver/lazylibrarian:version-1152df82f93d2560e233
pillow@8.2.0
9.3.0

Open the chart page →

11,662
paperlessgeek-cookbookVerified publisher9.2.01 of 1See more

paperless geek-cookbook 9.2.0

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
pillow@9.2.0
9.3.0

Open the chart page →

3,924
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
pillow@9.0.0
9.3.0

Open the chart page →

7,801
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
pillow@9.1.0
9.3.0

Open the chart page →

7,129
helm-taigamvitale1989-helm-taigaVerified publisher0.2.51 of 2See more

helm-taiga mvitale1989-helm-taiga 0.2.5

1 of the 2 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pillow@4.3.0
9.3.0

Open the chart page →

5,104
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0
9.3.0

Open the chart page →

13,541
pgadminarunalakmalVerified publisher0.1.01 of 1See more

pgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
9.3.0

Open the chart page →

2,418
swdpgadminarunalakmalVerified publisher0.1.01 of 1See more

swdpgadmin arunalakmal 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
9.3.0

Open the chart page →

2,418
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
9.3.0

Open the chart page →

10,061
frigatebryopsida0.2.11 of 2See more

frigate bryopsida 0.2.1

1 of the 2 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@9.2.0
9.3.0

Open the chart page →

2,573
check-mkcloudnativeapp0.2.11 of 1See more

check-mk cloudnativeapp 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
nlmacamp/check_mk:latest5dbb8589f824
pillow@5.0.0
9.3.0

Open the chart page →

2,408
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
daskdev/dask:1.1.04ecd7bc35500
pillow@5.3.0
9.3.0

Open the chart page →

29,901
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pillow@5.0.0
9.3.0

Open the chart page →

77,758
yadmscronce0.3.02 of 2See more

yadms cronce 0.3.0

2 of the 2 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
mcronce/yadms-ftp:latestf820ef2e3c26
pillow@7.0.0
9.3.0
mcronce/yadms-web:latestc03c1c7f5aa9
pillow@7.0.0
9.3.0

Open the chart page →

2,500
datacubedatacube-charts0.18.21 of 1See more

datacube datacube-charts 0.18.2

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0
9.3.0

Open the chart page →

27,728
datacube-datadatacube-charts0.2.61 of 1See more

datacube-data datacube-charts 0.2.6

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
pillow@7.2.0
9.3.0

Open the chart page →

18,863
beetsgeek-cookbookVerified publisher1.4.21 of 1See more

beets geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
9.3.0

Open the chart page →

1,150
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0
9.3.0

Open the chart page →

13,551
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
pillow@7.2.0
9.3.0

Open the chart page →

7,984
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
improwised/erpnext-worker:v13.4.197280b55cbd4
pillow@8.2.0
9.3.0

Open the chart page →

6,501
frigatek8s-home-lab-repo9.1.11 of 1See more

frigate k8s-home-lab-repo 9.1.1

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@9.2.0
9.3.0

Open the chart page →

2,370
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pillow@8.4.0
9.3.0

Open the chart page →

8,556
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
9.3.0

Open the chart page →

55,726
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
pillow@9.2.0
9.3.0

Open the chart page →

22,084
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
pillow@7.0.0
9.3.0

Open the chart page →

8,694
krokiteochenglim1.0.11 of 5See more

kroki teochenglim 1.0.1

1 of the 5 container images this version deploys carry CVE-2022-45199.

Container imageDigestPackageFixed in
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pillow@8.4.0
9.3.0

Open the chart page →

8,715

Container images carrying it

31 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dpage/pgadmin4:6.12781369df9994
pillow@9.2.0
9.3.0
3
blakeblackshear/frigate:0.11.18330b0a265b8
pillow@9.2.0
9.3.0
2
weblate/weblate:4.2.2-169c160d37a3c
pillow@7.2.0
9.3.0
2
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
pillow@9.1.0
9.3.0
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
pillow@8.1.0
9.3.0
1
daskdev/dask:1.1.04ecd7bc35500
pillow@5.3.0
9.3.0
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
pillow@7.2.0
9.3.0
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
pillow@8.4.0
9.3.0
1
improwised/erpnext-worker:v13.4.197280b55cbd4
pillow@8.2.0
9.3.0
1
kobotoolbox/kobocat:2.022.24ab15679454415
pillow@9.1.0
9.3.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pillow@9.1.0
9.3.0
1
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
9.3.0
1
linuxserver/deluge:18.04.10ac871624394
pillow@5.1.0
9.3.0
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
pillow@5.1.0
9.3.0
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
pillow@8.2.0
9.3.0
1
mcronce/yadms-ftp:latestf820ef2e3c26
pillow@7.0.0
9.3.0
1
mcronce/yadms-web:latestc03c1c7f5aa9
pillow@7.0.0
9.3.0
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pillow@8.4.0
9.3.0
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pillow@4.3.0
9.3.0
1
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
9.3.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
pillow@9.2.0
9.3.0
1
nlmacamp/check_mk:latest5dbb8589f824
pillow@5.0.0
9.3.0
1
opendatacube/wms:latest1b90cdf68831
pillow@5.1.0
9.3.0
1
seafileltd/seafile-mc:9.0.97ac833196f60
pillow@9.2.0
9.3.0
1
taigaio/taiga-back:6.4.29f97323cc150
pillow@8.2.0
9.3.0
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pillow@5.0.0
9.3.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
pillow@9.0.0
9.3.0
1
weblate/weblate:3.11.3-182848df56ecd
pillow@7.0.0
9.3.0
1
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pillow@8.4.0
9.3.0
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
pillow@9.1.0
9.3.0
1
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
pillow@9.2.0
9.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.