StackRadar

CVE-2022-46175

High

Advisory

Published 29 Dec 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.093
95th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
121
of 17,781 indexed, latest versions
Container images
114
deployed by those charts
Fix available
1 of 1
affected package

Prototype Pollution in JSON5 via Parse Method

Carried by container images the latest versions of 121 of 17,781 indexed charts deploy, on 114 images.

Affected packageAffected versionsFixed inImages
json5npm0.4.0, 0.5.1, 1.0.1, 2.0.0+6 more1.0.2, 2.2.2114
OSV records
GHSA-9c47-m6qq-7p4h

Charts affected

121 by stars
ChartLatestAffected imagesRadar Score
samplesample0.1.01 of 2See more

sample sample 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
library/mongo-express:1.0.2-20-alpine3.191aae00775251
json5@2.2.1
2.2.2

Open the chart page →

2,309
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
json5@2.2.0
2.2.2

Open the chart page →

3,638
semaphoreschoenwald0.1.31 of 1See more

semaphore schoenwald 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
0hlov3/semaphore:v1.0.050f874ec096b
json5@1.0.1
1.0.2

Open the chart page →

1,796
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
json5@2.2.1
2.2.2

Open the chart page →

3,143
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
json5@1.0.1
1.0.2

Open the chart page →

3,696
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
json5@2.1.2
2.2.2

Open the chart page →

2,460
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
json5@2.2.0
2.2.2

Open the chart page →

3,228
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
json5@1.0.1
1.0.2

Open the chart page →

2,121
alert-mappersomeblackmagic0.2.01 of 1See more

alert-mapper someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
someblackmagic/alert-mapper:v0.1.088351d85c04c
json5@1.0.1
1.0.2

Open the chart page →

1,890
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
json5@2.2.0
2.2.2

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
json5@2.2.0
2.2.2

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
json5@1.0.1
1.0.2

Open the chart page →

3,881
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
json5@1.0.1
1.0.2

Open the chart page →

20,270
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
pysga1996/python-redis-web:latestfdeec30ad482
json5@2.2.0
2.2.2

Open the chart page →

4,661
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
json5@0.5.1
1.0.2

Open the chart page →

3,576
thingsboardthingsboardVerified publisher0.1.32 of 12See more

thingsboard thingsboard 0.1.3

2 of the 12 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
thingsboard/tb-js-executor:3.4.113e1eadf8ace
json5@2.1.3
2.2.2
thingsboard/tb-web-ui:3.4.157f98ed53b3d
json5@2.1.3
2.2.2

Open the chart page →

25,394
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
json5@2.2.0
2.2.2

Open the chart page →

3,129
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
json5@0.5.1
1.0.2

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
json5@0.5.1
1.0.2

Open the chart page →

22,665
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
json5@2.0.0
2.2.2

Open the chart page →

5,459
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2022-46175.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
json5@1.0.1
1.0.2

Open the chart page →

5,806

Container images carrying it

114 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
oscarsotosanchez/server:v1.06e2e1279126b
json5@2.2.0
2.2.2
4
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
json5@2.2.1
2.2.2
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
json5@1.0.1
1.0.2
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
json5@2.2.0
2.2.2
2
governify/assets-manager:v1.4.12987672448c7
json5@2.2.0
2.2.2
2
gradiant/open5gs-webui:2.7.5fbd10c017541
json5@0.5.1
1.0.2
2
library/mongo-express:1.0.2:latest1b23d7976f02
json5@2.2.1
2.2.2
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
json5@2.1.3
2.2.2
2
moreillon/api-proxy:a3e8b41e9e578c9653b6
json5@2.2.1
2.2.2
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
json5@2.1.3
2.2.2
2
requarks/wiki:2:latest68f0d1848261
json5@2.0.0
2.2.2
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
json5@2.2.0
2.2.2
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
json5@2.2.1
2.2.2
2
0hlov3/semaphore:v1.0.050f874ec096b
json5@1.0.1
1.0.2
1
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
json5@2.1.0
2.2.2
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
json5@1.0.1
1.0.2
1
apimap/developer:v1.3.1406d3858e20c
json5@1.0.1
1.0.2
1
apimap/portal:v2.4.0041a4790c65c
json5@1.0.1
1.0.2
1
arfath29/3-tier-app-frontend:latest384b3e377f47
json5@2.2.0
2.2.2
1
arturisimo/server-urjc:v1.0d8dc4430531e
json5@2.2.1
2.2.2
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
json5@1.0.1
1.0.2
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
json5@2.1.3
2.2.2
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
json5@2.2.1
2.2.2
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
json5@2.2.1
2.2.2
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
json5@2.2.1
2.2.2
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
json5@2.2.1
2.2.2
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
json5@2.2.0
2.2.2
1
catalysm/csmm:latestf003b35f54d9
json5@0.5.1
1.0.2
1
chatwoot/chatwoot:v4.15.167ebc751c171
json5@1.0.1
1.0.2
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
json5@1.0.1
1.0.2
1
conduction/conduction-ui-app:devd591f5e6f2a9
json5@1.0.1
1.0.2
1
daskdev/dask-notebook:1.1.0052630f5ca04
json5@0.5.1
1.0.2
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
json5@2.2.1
2.2.2
1
electerious/ackee:3.2.05e7173fa321c
json5@2.2.0
2.2.2
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
json5@2.2.1
2.2.2
1
ethersphere/bzz-token-service:latest7624f11a72ad
json5@1.0.1
1.0.2
1
ethersphere/onboarding-faucet:0.3.0513154aab230
json5@2.2.0
2.2.2
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
json5@0.5.1
1.0.2
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
json5@0.5.1
1.0.2
1
gristlabs/grist:0.7.96e71b1914a7e
json5@1.0.1
1.0.2
1
henrywhitaker3/speedtest-tracker:latest47159a940229
json5@2.1.2
2.2.2
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
json5@1.0.1
1.0.2
1
hugohg34/server:0.0.2503e5d8960ff
json5@2.2.1
2.2.2
1
ianw/quickchart:v1.7.1dc49dd460c37
json5@1.0.1
1.0.2
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
json5@0.5.1
1.0.2
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
json5@0.5.1
1.0.2
1
inseefrlab/shelly:cloudshell31f04ca7436b
json5@2.1.1
2.2.2
1
jayfong/yapi:1.10.2163e5d621910
json5@1.0.1
1.0.2
1
joplin/server:3.0-beta52af57880c0e
json5@2.2.0
2.2.2
1
joplin/server:2.14.2-betab87564ef34e9
json5@1.0.1
1.0.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.