StackRadar

CVE-2022-46175

High

Advisory

Published 29 Dec 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.093
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
121
of 17,781 indexed, latest versions
Container images
114
deployed by those charts
Fix available
1 of 1
affected package

Prototype Pollution in JSON5 via Parse Method

Carried by container images the latest versions of 121 of 17,781 indexed charts deploy, on 114 images.

Affected packageAffected versionsFixed inImages
json5npm0.4.0, 0.5.1, 1.0.1, 2.0.0+6 more1.0.2, 2.2.2114
OSV records
GHSA-9c47-m6qq-7p4h

Charts affected

121 by stars
ChartLatestAffected imagesRadar Score
mongo-expresscowboysysopVerified publisher7.0.01 of 1See more

mongo-express cowboysysop 7.0.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
library/mongo-express:1.0.21b23d7976f02
json5@2.2.1
2.2.2

Open the chart page →

1,210
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
json5@1.0.1
1.0.2

Open the chart page →

9,203
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
json5@2.1.3
2.2.2

Open the chart page →

5,251
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
json5@2.1.3
2.2.2

Open the chart page →

8,213
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
json5@2.2.0
2.2.2

Open the chart page →

5,946
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
json5@0.5.1
1.0.2

Open the chart page →

9,261
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
json5@2.2.0
2.2.2

Open the chart page →

22,773
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
json5@1.0.1
1.0.2

Open the chart page →

7,579
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
json5@2.2.0
2.2.2

Open the chart page →

3,476
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
json5@2.2.1
2.2.2

Open the chart page →

10,311
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
json5@0.5.1
1.0.2

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
kobotoolbox/kpi:2.022.24dbcacc01bccd4
json5@2.2.1
2.2.2

Open the chart page →

18,517
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
json5@2.2.0
2.2.2

Open the chart page →

24,488
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.261 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

1 of the 6 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
thingsboard/tb-web-ui:3.6.0d388378062cc
json5@2.1.3
2.2.2

Open the chart page →

14,566
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
json5@2.1.3
2.2.2

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
json5@1.0.1
1.0.2

Open the chart page →

10,730
data-fairdata354-helmVerified publisher1.1.24 of 12See more

data-fair data354-helm 1.1.2

4 of the 12 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
koumoul/capture:17108d47be3b2
json5@1.0.1
1.0.2
koumoul/openapi-viewer:18eeca2e8285b
json5@0.4.0
1.0.2
ghcr.io/data-fair/metrics:0a8d40779eeae
json5@2.2.0
2.2.2
ghcr.io/data-fair/simple-directory:438a4f32fad82
json5@2.2.0
2.2.2

Open the chart page →

38,346
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
json5@1.0.1
1.0.2

Open the chart page →

3,925
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
json5@1.0.1
1.0.2

Open the chart page →

2,519
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
json5@1.0.1
1.0.2

Open the chart page →

3,444
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
json5@2.2.0
2.2.2

Open the chart page →

7,801
youtubedl-materialgeek-cookbookVerified publisher4.4.21 of 1See more

youtubedl-material geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.23720b856bd2f
json5@2.1.2
2.2.2

Open the chart page →

4,410
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
json5@1.0.1
1.0.2

Open the chart page →

17,284
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
json5@2.2.0
2.2.2

Open the chart page →

3,369
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
json5@2.2.1
2.2.2

Open the chart page →

3,143
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
json5@2.2.0
2.2.2

Open the chart page →

5,940
open5gs-webuiopen5gs-webuiVerified publisher2.3.11 of 2See more

open5gs-webui open5gs-webui 2.3.1

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
json5@0.5.1
1.0.2

Open the chart page →

5,300
pdf-editor-helmpdf-editor-web1.0.01 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

1 of the 4 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
json5@2.2.1
2.2.2

Open the chart page →

4,206
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
json5@2.2.0
2.2.2

Open the chart page →

6,879
ackeesudaVerified publisher0.2.11 of 1See more

ackee suda 0.2.1

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
electerious/ackee:3.2.05e7173fa321c
json5@2.2.0
2.2.2

Open the chart page →

1,602
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
json5@1.0.1
1.0.2

Open the chart page →

7,517
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
json5@2.0.0
2.2.2

Open the chart page →

3,833
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
json5@0.5.1
1.0.2

Open the chart page →

25,443
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
json5@0.5.1
1.0.2

Open the chart page →

3,237
angular-node-chartangular-webapp2.0.01 of 1See more

angular-node-chart angular-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
rakii8585/angular-node-webapp:latest026082a515ac
json5@1.0.1
1.0.2

Open the chart page →

2,616
apimap-developerapimapOfficialVerified publisher1.4.11 of 1See more

apimap-developer apimap 1.4.1

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
apimap/developer:v1.3.1406d3858e20c
json5@1.0.1
1.0.2

Open the chart page →

2,353
apimap-portalapimapOfficialVerified publisher2.4.01 of 1See more

apimap-portal apimap 2.4.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
apimap/portal:v2.4.0041a4790c65c
json5@1.0.1
1.0.2

Open the chart page →

2,396
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
json5@2.2.1
2.2.2
assistiot/smart-orchestrator_enabler:latest89f37e88c871
json5@2.2.1
2.2.2
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
json5@2.2.1
2.2.2

Open the chart page →

45,363
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ltdstudio/terraforming-mars:latest0e76c6f4eac0
json5@2.2.0
2.2.2

Open the chart page →

7,152
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
json5@1.0.1
1.0.2

Open the chart page →

5,806
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
json5@2.2.1
2.2.2

Open the chart page →

4,455
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
json5@0.5.1
1.0.2

Open the chart page →

29,901
kube-slackcloudnativeapp1.0.01 of 1See more

kube-slack cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
willwill/kube-slack:v4.1.1d443017aae98
json5@1.0.1
1.0.2

Open the chart page →

1,937
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
json5@2.1.1
2.2.2

Open the chart page →

25,456
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
json5@1.0.1
1.0.2

Open the chart page →

12,907
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
json5@1.0.1
1.0.2

Open the chart page →

5,488
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
json5@2.2.0
2.2.2

Open the chart page →

27,550
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
json5@2.2.0
2.2.2

Open the chart page →

24,656
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
json5@1.0.1
1.0.2

Open the chart page →

11,174
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
json5@2.2.0
2.2.2

Open the chart page →

3,744

Container images carrying it

114 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
junktext/getting-started:1.0.5a70936c04aed
json5@2.2.0
2.2.2
1
junktext/getting-started:1.0.34d44adf5a4da2
json5@2.2.0
2.2.2
1
keyoxide/keyoxide:stable96f27a71269d
json5@2.2.0
2.2.2
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
json5@2.2.1
2.2.2
1
koumoul/capture:17108d47be3b2
json5@1.0.1
1.0.2
1
koumoul/openapi-viewer:18eeca2e8285b
json5@0.4.0
1.0.2
1
lavandadelpatio/frontend:latest501c3f31e0bc
json5@1.0.1
1.0.2
1
library/kibana:7.17.8c5781ba340ef
json5@2.2.0
2.2.2
1
library/kibana:7.17.3e2e2031c15be
json5@1.0.1
1.0.2
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
json5@2.2.1
2.2.2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
json5@2.2.0
2.2.2
1
linuxserver/codimd:latestb801bbcf6386
json5@1.0.1
1.0.2
1
lissy93/dashy:2.0.51991f7be5ed0
json5@2.2.0
2.2.2
1
lsstsqre/squareone:0.4.09ded78e7fe03
json5@1.0.1
1.0.2
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
json5@2.2.0
2.2.2
1
misskey/misskey:12.110.1e08b7c478093
json5@2.1.3
2.2.2
1
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
json5@2.2.1
2.2.2
1
mozilla/sentencecollector:2.0.91da6ff5c4895
json5@1.0.1
1.0.2
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
json5@2.1.3
2.2.2
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
json5@2.2.0
2.2.2
1
ondrejsika/parking:latestb1fd497416c8
json5@1.0.1
1.0.2
1
openbas/caldera-server:5.1.0a277796d9724
json5@1.0.1
1.0.2
1
phntom/codimd:2.4.31b9aafbb62e6
json5@1.0.1
1.0.2
1
pysga1996/python-redis-web:latestfdeec30ad482
json5@2.2.0
2.2.2
1
rakii8585/angular-node-webapp:latest026082a515ac
json5@1.0.1
1.0.2
1
requarks/wiki:canary-2.5.2438b5865a7386c
json5@2.2.0
2.2.2
1
roadiehq/community-backstage-image:latestef355bf5b639
json5@2.2.0
2.2.2
1
samajh/alprfrontend:latest05ef4fddbb75
json5@1.0.1
1.0.2
1
shahanafarooqui/rtl:0.11.0d0cd3d868aca
json5@2.2.0
2.2.2
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
json5@1.0.1
1.0.2
1
slagattollas/server-practica:latest6dd8ead8e2b1
json5@2.2.0
2.2.2
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
json5@0.5.1
1.0.2
1
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
json5@1.0.1
1.0.2
1
someblackmagic/alert-mapper:v0.1.088351d85c04c
json5@1.0.1
1.0.2
1
stanfordoval/almond-server:latest1a63cdccedaf
json5@2.2.0
2.2.2
1
temporalio/web:1.14.033cfa863d8ce
json5@0.5.1
1.0.2
1
testhubio/testhub-frontend:on-preme86c2db53be8
json5@1.0.1
1.0.2
1
thingsboard/tb-js-executor:3.4.113e1eadf8ace
json5@2.1.3
2.2.2
1
thingsboard/tb-web-ui:3.4.157f98ed53b3d
json5@2.1.3
2.2.2
1
thingsboard/tb-web-ui:3.6.0d388378062cc
json5@2.1.3
2.2.2
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
json5@2.2.1
2.2.2
1
tzahi12345/youtubedl-material:4.23720b856bd2f
json5@2.1.2
2.2.2
1
ubercadence/web:v3.29.58564a5b44a6d
json5@0.5.1
1.0.2
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
json5@2.2.0
2.2.2
1
wekanteam/wekan:v4.2268a51f0327df
json5@2.1.3
2.2.2
1
willwill/kube-slack:v4.1.1d443017aae98
json5@1.0.1
1.0.2
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
json5@2.2.0
2.2.2
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
json5@1.0.1
1.0.2
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
json5@1.0.1
1.0.2
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
json5@1.0.1
1.0.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.