StackRadar

CVE-2022-4899

High

Advisory

Published 31 Mar 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
298
of 17,781 indexed, latest versions
Container images
267
deployed by those charts
Fix available
1 of 2
affected packages

libzstd-devel-1.5.5-5.1 on GA media

Carried by container images the latest versions of 298 of 17,781 indexed charts deploy, on 267 images.

Affected packageAffected versionsFixed inImages
libzstddeb1.4.8+dfsg-3build1no fix listed265
zstdrpm1.4.2-lp151.3.3.11.5.5-5.12
OSV records
UBUNTU-CVE-2022-4899openSUSE-SU-2024:13613-1

Charts affected

298 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

6,556
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

9,145
zabbixcetic3.1.34 of 5See more

zabbix cetic 3.1.3

4 of the 5 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
libzstd@1.4.8+dfsg-3build1
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
libzstd@1.4.8+dfsg-3build1
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libzstd@1.4.8+dfsg-3build1
no fix listed
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

33,725
daskdask2024.1.11 of 2See more

dask dask 2024.1.1

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

12,746
oneuptimeoneuptimeOfficialVerified publisher13.0.41 of 7See more

oneuptime oneuptime 13.0.4

1 of the 7 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.701b81d1432c4
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

11,192
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

11,933
milvusmilvus-helm5.0.272 of 4See more

milvus milvus-helm 5.0.27

2 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
libzstd@1.4.8+dfsg-3build1
no fix listed
milvusdb/etcd:3.5.25-r1fededb2f2d63
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

10,670
zookeepercloudpirates-zookeeperVerified publisher0.13.111 of 1See more

zookeeper cloudpirates-zookeeper 0.13.11

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5cab8944a33a1
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,924
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.38.4447f857a0146
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

1,482
supabasetokens-studioVerified publisher1.0.01 of 14See more

supabase tokens-studio 1.0.0

1 of the 14 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/kong:3.8.0712e407b20ea
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

23,123
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,454
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,857
zillazillaOfficialVerified publisher2.4.21 of 1See more

zilla zilla 2.4.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

1,698
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,244
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
libzstd@1.4.8+dfsg-3build1
no fix listed
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

14,184
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,630
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,903
mssqlserver-2022simcube1.2.31 of 1See more

mssqlserver-2022 simcube 1.2.3

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,878
headwind-mdmchristianhuthVerified publisher5.10.11 of 2See more

headwind-mdm christianhuth 5.10.1

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
headwindmdm/hmdm:0.1.93550b4840840
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,870
daskhubdask2024.1.11 of 9See more

daskhub dask 2024.1.1

1 of the 9 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
pangeo/base-notebook:2024.01.155fbe688a4f80
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

14,094
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

27,267
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

13,953
ubuntuopen-charts1.2.11 of 1See more

ubuntu open-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/ubuntu:22.042edbbc5dc405
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

1,537
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

8,722
topolvmtopolvmVerified publisher17.2.01 of 1See more

topolvm topolvm 17.2.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,316
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

8,212
lighthousechronicleVerified publisher0.0.81 of 1See more

lighthouse chronicle 0.0.8

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
sigp/lighthouse:v7.1.0870934e38931
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

1,921
mariadbmariadbVerified publisher0.4.01 of 1See more

mariadb mariadb 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mariadb:10.11ce66c7be32a0
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,410
kubecostmesosphere-stable0.37.51 of 9See more

kubecost mesosphere-stable 0.37.5

1 of the 9 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

17,693
observalobservalVerified publisher1.13.11 of 8See more

observal observal 1.13.1

1 of the 8 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.3810861a2e2d0
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,828
repoflowrepoflow-helm-public0.9.11 of 8See more

repoflow repoflow-helm-public 0.9.1

1 of the 8 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.48.10f6c1c4b957d2
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

13,521
satisfactory-serversatisfactoryVerified publisher0.1.61 of 1See more

satisfactory-server satisfactory 0.1.6

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.10e103700ae6ae
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,427
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,751
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
thmmniii/fbs-core:v1.27.15438517d9fc2
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

28,534
argocdtwomartensVerified publisher0.1.11 of 3See more

argocd twomartens 0.1.1

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.8.6acaf37352569
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

10,315
paperless-ngxadnoctemVerified publisher0.4.21 of 5See more

paperless-ngx adnoctem 0.4.2

1 of the 5 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
apache/tika:2.9.0.092d055a84e9e
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

19,691
icat-k8salba-helm-chartsVerified publisher1.1.01 of 4See more

icat-k8s alba-helm-charts 1.1.0

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
payara/server-full:7.2026.2-jdk2531f1253f0cf8
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,697
mariadbalphani-helm-chartsVerified publisher10.10.31 of 1See more

mariadb alphani-helm-charts 10.10.3

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mariadb:10.10.2bfc25a68e113
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

8,341
apache-rangerapache-ranger0.1.01 of 2See more

apache-ranger apache-ranger 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
apache/ranger:2.7.076c176e8a0e4
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,740
dltbrokerassist-iot-distributed-broker0.2.01 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

1 of the 9 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.01 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

1 of the 9 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

77,687
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,190
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,190
clustereye-stackclustereyeVerified publisher0.1.11 of 5See more

clustereye-stack clustereye 0.1.1

1 of the 5 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31.02bf7f042e396
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,855
nifid4nVerified publisher2.0.01 of 5See more

nifi d4n 2.0.0

1 of the 5 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,398
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

10,858
elchi-stackelchi1.13.02 of 10See more

elchi-stack elchi 1.13.0

2 of the 10 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.33.056da5afd7df3
libzstd@1.4.8+dfsg-3build1
no fix listed
library/mongo:6.0.12646902910d6a
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

15,383
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,048
lighthouseethereum-helm-chartsVerified publisher1.1.91 of 2See more

lighthouse ethereum-helm-charts 1.1.9

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
sigp/lighthouse:latest9a62bb870545
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

1,548
fastapi-microservice-appfast-api-microservice-app1.3.01 of 4See more

fastapi-microservice-app fast-api-microservice-app 1.3.0

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mongo:7.0b6421fd6d1c5
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

9,562

Container images carrying it

267 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.1da0b5eb7721a
libzstd@1.4.8+dfsg-3build1
no fix listed
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
libzstd@1.4.8+dfsg-3build1
no fix listed
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/aerokube/keygen:1.0.1578934444f04
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
libzstd@1.4.8+dfsg-3build1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.