StackRadar

CVE-2022-4899

High

Advisory

Published 31 Mar 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
299
of 17,787 indexed, latest versions
Container images
268
deployed by those charts
Fix available
1 of 2
affected packages

libzstd-devel-1.5.5-5.1 on GA media

Carried by container images the latest versions of 299 of 17,787 indexed charts deploy, on 268 images.

Affected packageAffected versionsFixed inImages
libzstddeb1.4.8+dfsg-3build1no fix listed266
zstdrpm1.4.2-lp151.3.3.11.5.5-5.12
OSV records
UBUNTU-CVE-2022-4899openSUSE-SU-2024:13613-1

Charts affected

299 by stars
ChartLatestAffected imagesRadar Score
dump1090fnzv0.2.81 of 1See more

dump1090 fnzv 0.2.8

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
fnzv/dump1090:latestb3079b95c336
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,123
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,641
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

12,124
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

19,560
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

10,418
satisfactorygeek-cookbookVerified publisher1.2.21 of 1See more

satisfactory geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:lateste103700ae6ae
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,466
jaegergpg-dev3.3.31 of 5See more

jaeger gpg-dev 3.3.3

1 of the 5 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

19,291
kubernetes-dashboardgpg-dev7.5.01 of 5See more

kubernetes-dashboard gpg-dev 7.5.0

1 of the 5 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

6,075
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontendproxy9fdec1be03e4
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

47,117
gravitino-iceberg-rest-server-helmgravitino-iceberg-rest-server1.3.111 of 1See more

gravitino-iceberg-rest-server-helm gravitino-iceberg-rest-server 1.3.11

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
apache/gravitino-iceberg-rest:1.3.080136ae753ee
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,604
grayloggraylogVerified publisher1.0.21 of 4See more

graylog graylog 1.0.2

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
graylog/graylog:6.1.1019de1aff48c2
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,339
routergroundcover1.12.3591 of 7See more

router groundcover 1.12.359

1 of the 7 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

6,038
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
kong/httpbin:latesta6ac46531193
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

9,151
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.4.2.11dc5658853ce1
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

23,472
nginx-charthelm-chart-sample-app0.1.01 of 1See more

nginx-chart helm-chart-sample-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
rraahul/test:latestbfe2c1183bc0
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,596
ckanhelmforgeVerified publisher1.3.81 of 6See more

ckan helmforge 1.3.8

1 of the 6 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

9,991
clickhousehelmforgeVerified publisher2.0.11 of 1See more

clickhouse helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.8.2fa394da808cc
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

1,735
druidhelmforgeVerified publisher1.3.61 of 4See more

druid helmforge 1.3.6

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5f258365d4882
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

8,598
zookeeperhelmforgeVerified publisher1.0.21 of 1See more

zookeeper helmforge 1.0.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5f258365d4882
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,142
svacerhelm-svacer0.6.01 of 1See more

svacer helm-svacer 0.6.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ispras/svacer:11-2-042aa9fa9f189
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

6,076
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

14,350
printserverhmediadeVerified publisher1.0.22 of 4See more

printserver hmediade 1.0.2

2 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
hmediade/printserver:latest481a552c8e1c
libzstd@1.4.8+dfsg-3build1
no fix listed
hmediade/printserver-init:latest7f005eb6c718
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

10,918
eoloplanthttpd-eoloplant0.1.02 of 7See more

eoloplant httpd-eoloplant 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
libzstd@1.4.8+dfsg-3build1
no fix listed
library/rabbitmq:3.9-management8a279e9396a8
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

32,336
prometheushuangchengwu-helm-chart0.1.02 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

2 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
libzstd@1.4.8+dfsg-3build1
no fix listed
apache/skywalking-ui:9.2.0295f1dc87d98
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

16,482
hyperglance-helmhyperglance-helmVerified publisher10.0.54 of 6See more

hyperglance-helm hyperglance-helm 10.0.5

4 of the 6 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
hyperglance/init:wildfly467ad8491bc3
libzstd@1.4.8+dfsg-3build1
no fix listed
hyperglance/init:postgres9fd5faf1fe80
libzstd@1.4.8+dfsg-3build1
no fix listed
hyperglance/init:apacheb2f8c6d52623
libzstd@1.4.8+dfsg-3build1
no fix listed
hyperglance/postgresql-v2:10.0.5eb4d383894b8
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

11,171
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,184
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,902
eoloserverihuertas2021-vmartinp2021-helm0.1.01 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/rabbitmq:3.9-management8a279e9396a8
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

27,812
ikigaiikigai-chartVerified publisher0.0.92 of 58See more

ikigai ikigai-chart 0.0.9

2 of the 58 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
libzstd@1.4.8+dfsg-3build1
no fix listed
library/zookeeper:3.8-temurin55d1e5b2e601
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

37,844
apexkube-agentimprowisedVerified publisher1.4.01 of 2See more

apexkube-agent improwised 1.4.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31.02bf7f042e396
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,350
nifi-registryimprowisedVerified publisher1.0.01 of 2See more

nifi-registry improwised 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
apache/nifi-registry:1.27.063b8e3e40742
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,360
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

10,542
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,570
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,570
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,813
unifi-network-applicationjanip81-helm-chartsVerified publisher0.2.91 of 3See more

unifi-network-application janip81-helm-charts 0.2.9

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mongo:7.0b6421fd6d1c5
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,182
dayz-dedicated-server-razorbladex401jespernohrVerified publisher1.0.31 of 1See more

dayz-dedicated-server-razorbladex401 jespernohr 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
razorbladex401/dayz:latest6a4d79248e7d
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,256
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

22,665
valheim-serverk8s-chartsVerified publisher1.3.01 of 1See more

valheim-server k8s-charts 1.3.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
mbround18/valheim:3.1.070bd4da591cd
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

6,136
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

9,832
kadeck-teamskadeck1.1.211 of 1See more

kadeck-teams kadeck 1.1.21

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
xeotek/kadeck:6.3.439a3b37a17c5
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,615
rabbitmqkfirfer0.7.211 of 2See more

rabbitmq kfirfer 0.7.21

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/rabbitmq:3.12.100742852455ad
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,484
kiaekiae0.1.61 of 9See more

kiae kiae 0.1.6

1 of the 9 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
istio/pilot:1.15.2db08d6963975
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

19,208
adventureworkskronkltdVerified publisher0.1.01 of 1See more

adventureworks kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
chriseaton/adventureworks:latest54c3384ce701
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,462
fileserverkronkltdVerified publisher0.3.101 of 1See more

fileserver kronkltd 0.3.10

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
duck1123/lnd-fileserver:latest9d6fb247b714
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,769
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
duck1123/cert-downloader:latest0e29f19fa67c
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,644
aapm-servicekron-pam-aapm-helmcharts1.2.51 of 1See more

aapm-service kron-pam-aapm-helmcharts 1.2.5

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
krontechnology/aapm-service:1.1.39dd602db8baa
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,645
kron-aapm-agentkron-pam-aapm-helmcharts1.2.51 of 1See more

kron-aapm-agent kron-pam-aapm-helmcharts 1.2.5

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.8.41cc7d5be6529
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,746
ciliumkubeblocksVerified publisher1.15.11 of 2See more

cilium kubeblocks 1.15.1

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.15.1351d6685dc6f
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,114
openebskubeblocksVerified publisher3.10.02 of 3See more

openebs kubeblocks 3.10.0

2 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
libzstd@1.4.8+dfsg-3build1
no fix listed
openebs/node-disk-operator:2.1.06afe2123c457
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

10,568

Container images carrying it

268 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/topolvm/pie:0.18.0aa467443e407
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.1da0b5eb7721a
libzstd@1.4.8+dfsg-3build1
no fix listed
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
libzstd@1.4.8+dfsg-3build1
no fix listed
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/aerokube/keygen:1.0.1578934444f04
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
libzstd@1.4.8+dfsg-3build1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.