StackRadar

CVE-2022-46175

High

Advisory

Published 29 Dec 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.093
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
121
of 17,781 indexed, latest versions
Container images
114
deployed by those charts
Fix available
1 of 1
affected package

Prototype Pollution in JSON5 via Parse Method

Carried by container images the latest versions of 121 of 17,781 indexed charts deploy, on 114 images.

Affected packageAffected versionsFixed inImages
json5npm0.4.0, 0.5.1, 1.0.1, 2.0.0+6 more1.0.2, 2.2.2114
OSV records
GHSA-9c47-m6qq-7p4h

Charts affected

121 by stars
ChartLatestAffected imagesRadar Score
eolicplantseolicplantsVerified publisher0.1.01 of 7See more

eolicplants eolicplants 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
json5@2.2.0
2.2.2

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.01 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
json5@2.2.0
2.2.2

Open the chart page →

27,256
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
json5@2.2.1
2.2.2

Open the chart page →

27,096
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
json5@1.0.1
1.0.2

Open the chart page →

3,260
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
json5@2.2.0
2.2.2

Open the chart page →

3,320
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
json5@0.5.1
1.0.2

Open the chart page →

64,489
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
json5@2.1.3
2.2.2

Open the chart page →

5,941
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
json5@2.1.3
2.2.2

Open the chart page →

4,043
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
json5@2.2.0
2.2.2

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
json5@2.2.0
2.2.2

Open the chart page →

24,319
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
json5@2.2.1
2.2.2

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
json5@2.2.1
2.2.2

Open the chart page →

2,682
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
json5@1.0.1
1.0.2
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
json5@1.0.1
1.0.2
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
json5@1.0.1
1.0.2
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
json5@1.0.1
1.0.2

Open the chart page →

89,959
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
json5@2.1.3
2.2.2

Open the chart page →

8,213
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
json5@1.0.1
1.0.2

Open the chart page →

25,017
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
json5@2.2.0
2.2.2

Open the chart page →

4,253
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
json5@0.5.1
1.0.2

Open the chart page →

32,915
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
json5@2.2.1
2.2.2

Open the chart page →

4,944
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
json5@2.1.1
2.2.2

Open the chart page →

10,494
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
json5@2.2.0
2.2.2

Open the chart page →

7,232
keyoxide-webittrident-oss0.2.31 of 1See more

keyoxide-web ittrident-oss 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
keyoxide/keyoxide:stable96f27a71269d
json5@2.2.0
2.2.2

Open the chart page →

2,363
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
json5@1.0.1
1.0.2

Open the chart page →

6,454
annotation-tooljtektVerified publisher0.1.51 of 2See more

annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
json5@2.2.1
2.2.2

Open the chart page →

2,315
polygonal-annotation-tooljtektVerified publisher0.1.51 of 2See more

polygonal-annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
json5@2.2.1
2.2.2

Open the chart page →

2,231
todo-appjunktext-via-aws1.2.101 of 1See more

todo-app junktext-via-aws 1.2.10

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.34d44adf5a4da2
json5@2.2.0
2.2.2

Open the chart page →

1,579
kube-admission-controller-starterk8s-validating-webhook0.2.01 of 2See more

kube-admission-controller-starter k8s-validating-webhook 0.2.0

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/kube-admission-controller-starter:maine9716966f30b
json5@2.2.1
2.2.2

Open the chart page →

2,166
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.11.0d0cd3d868aca
json5@2.2.0
2.2.2

Open the chart page →

5,604
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
json5@2.2.0
2.2.2

Open the chart page →

4,230
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
json5@2.2.1
2.2.2

Open the chart page →

5,410
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
json5@2.1.0
2.2.2

Open the chart page →

7,929
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
json5@1.0.1
1.0.2

Open the chart page →

2,247
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
json5@1.0.1
1.0.2

Open the chart page →

3,651
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
json5@0.5.1
1.0.2

Open the chart page →

5,287
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
json5@2.2.0
2.2.2

Open the chart page →

5,940
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
json5@2.2.1
2.2.2

Open the chart page →

29,588
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
json5@2.1.3
2.2.2

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
json5@2.1.3
2.2.2

Open the chart page →

10,603
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
library/mongo-express:latest1b23d7976f02
json5@2.2.1
2.2.2

Open the chart page →

5,179
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
json5@1.0.1
1.0.2

Open the chart page →

6,438
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
json5@2.2.1
2.2.2

Open the chart page →

8,556
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
json5@1.0.1
1.0.2

Open the chart page →

6,684
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
json5@1.0.1
1.0.2

Open the chart page →

3,128
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
json5@2.2.0
2.2.2

Open the chart page →

3,269
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
json5@0.5.1
1.0.2

Open the chart page →

109,294
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
json5@1.0.1
1.0.2

Open the chart page →

27,465
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
json5@1.0.1
1.0.2

Open the chart page →

9,968
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
json5@1.0.1
1.0.2

Open the chart page →

6,524
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
json5@2.2.0
2.2.2

Open the chart page →

28,484
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
json5@1.0.1
1.0.2

Open the chart page →

5,215
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
json5@2.2.0
2.2.2

Open the chart page →

7,413

Container images carrying it

114 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
oscarsotosanchez/server:v1.06e2e1279126b
json5@2.2.0
2.2.2
4
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
json5@2.2.1
2.2.2
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
json5@1.0.1
1.0.2
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
json5@2.2.0
2.2.2
2
governify/assets-manager:v1.4.12987672448c7
json5@2.2.0
2.2.2
2
gradiant/open5gs-webui:2.7.5fbd10c017541
json5@0.5.1
1.0.2
2
library/mongo-express:1.0.2:latest1b23d7976f02
json5@2.2.1
2.2.2
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
json5@2.1.3
2.2.2
2
moreillon/api-proxy:a3e8b41e9e578c9653b6
json5@2.2.1
2.2.2
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
json5@2.1.3
2.2.2
2
requarks/wiki:2:latest68f0d1848261
json5@2.0.0
2.2.2
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
json5@2.2.0
2.2.2
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
json5@2.2.1
2.2.2
2
0hlov3/semaphore:v1.0.050f874ec096b
json5@1.0.1
1.0.2
1
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
json5@2.1.0
2.2.2
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
json5@1.0.1
1.0.2
1
apimap/developer:v1.3.1406d3858e20c
json5@1.0.1
1.0.2
1
apimap/portal:v2.4.0041a4790c65c
json5@1.0.1
1.0.2
1
arfath29/3-tier-app-frontend:latest384b3e377f47
json5@2.2.0
2.2.2
1
arturisimo/server-urjc:v1.0d8dc4430531e
json5@2.2.1
2.2.2
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
json5@1.0.1
1.0.2
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
json5@2.1.3
2.2.2
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
json5@2.2.1
2.2.2
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
json5@2.2.1
2.2.2
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
json5@2.2.1
2.2.2
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
json5@2.2.1
2.2.2
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
json5@2.2.0
2.2.2
1
catalysm/csmm:latestf003b35f54d9
json5@0.5.1
1.0.2
1
chatwoot/chatwoot:v4.15.167ebc751c171
json5@1.0.1
1.0.2
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
json5@1.0.1
1.0.2
1
conduction/conduction-ui-app:devd591f5e6f2a9
json5@1.0.1
1.0.2
1
daskdev/dask-notebook:1.1.0052630f5ca04
json5@0.5.1
1.0.2
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
json5@2.2.1
2.2.2
1
electerious/ackee:3.2.05e7173fa321c
json5@2.2.0
2.2.2
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
json5@2.2.1
2.2.2
1
ethersphere/bzz-token-service:latest7624f11a72ad
json5@1.0.1
1.0.2
1
ethersphere/onboarding-faucet:0.3.0513154aab230
json5@2.2.0
2.2.2
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
json5@0.5.1
1.0.2
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
json5@0.5.1
1.0.2
1
gristlabs/grist:0.7.96e71b1914a7e
json5@1.0.1
1.0.2
1
henrywhitaker3/speedtest-tracker:latest47159a940229
json5@2.1.2
2.2.2
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
json5@1.0.1
1.0.2
1
hugohg34/server:0.0.2503e5d8960ff
json5@2.2.1
2.2.2
1
ianw/quickchart:v1.7.1dc49dd460c37
json5@1.0.1
1.0.2
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
json5@0.5.1
1.0.2
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
json5@0.5.1
1.0.2
1
inseefrlab/shelly:cloudshell31f04ca7436b
json5@2.1.1
2.2.2
1
jayfong/yapi:1.10.2163e5d621910
json5@1.0.1
1.0.2
1
joplin/server:3.0-beta52af57880c0e
json5@2.2.0
2.2.2
1
joplin/server:2.14.2-betab87564ef34e9
json5@1.0.1
1.0.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.