StackRadar

CVE-2022-4899

High

Advisory

Published 31 Mar 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
299
of 17,787 indexed, latest versions
Container images
268
deployed by those charts
Fix available
1 of 2
affected packages

libzstd-devel-1.5.5-5.1 on GA media

Carried by container images the latest versions of 299 of 17,787 indexed charts deploy, on 268 images.

Affected packageAffected versionsFixed inImages
libzstddeb1.4.8+dfsg-3build1no fix listed266
zstdrpm1.4.2-lp151.3.3.11.5.5-5.12
OSV records
UBUNTU-CVE-2022-4899openSUSE-SU-2024:13613-1

Charts affected

299 by stars
ChartLatestAffected imagesRadar Score
kubernetes-netskope-publisherkubernetes-netskope-publisherVerified publisher1.5.01 of 2See more

kubernetes-netskope-publisher kubernetes-netskope-publisher 1.5.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
netskopeprivateaccess/publisher_u22:latest93e2fd164a93
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,583
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

18,394
iomeshkubesphere-stable1.1.01 of 25See more

iomesh kubesphere-stable 1.1.0

1 of the 25 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.7.25d3f9bf9240b
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

48,833
IOMeshkubesphere-stable1.2.01 of 25See more

IOMesh kubesphere-stable 1.2.0

1 of the 25 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
iomesh/csi-driver:v2.8.01a151f602451
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

46,507
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
libzstd@1.4.8+dfsg-3build1
no fix listed
penpotapp/exporter:2.2.15c835ffd87ab
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

17,002
kusionkusionstackVerified publisher0.14.11 of 3See more

kusion kusionstack 0.14.1

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
kusionstack/kusion:v0.14.0126c8f0b0976
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

6,879
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,842
ingresslivekit-server1.2.21 of 1See more

ingress livekit-server 1.2.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
livekit/ingress:v1.2.21ab01641b366
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

10,773
vnode-runtimeloftVerified publisher0.3.31 of 1See more

vnode-runtime loft 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,507
rocketmq-exporterlogic3579Verified publisher0.0.21 of 1See more

rocketmq-exporter logic3579 0.0.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
apache/rocketmq-exporter:0.0.2c8fb51195444
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

6,674
loxilbloxilbVerified publisher0.1.02 of 2See more

loxilb loxilb 0.1.0

2 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/loxilb-io/kube-loxilb:latest6f65e53e252d
libzstd@1.4.8+dfsg-3build1
no fix listed
ghcr.io/loxilb-io/loxilb:latestc7ede1bab641
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,502
magistralamagistrala-devopsVerified publisher0.16.22 of 42See more

magistrala magistrala-devops 0.16.2

2 of the 42 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31-latestcaa5b411be16
libzstd@1.4.8+dfsg-3build1
no fix listed
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

24,488
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/rabbitmq:3.9-management8a279e9396a8
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

29,712
crdsmedia-streaming-meshVerified publisher0.0.11 of 2See more

crds media-streaming-mesh 0.0.1

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ciscolabs/msm-nc:0710202336d02faad958
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,707
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

11,694
group-managermoreillonVerified publisher0.4.41 of 3See more

group-manager moreillon 0.4.4

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

9,886
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

10,998
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

23,263
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/kong:3.6a42d2b4503e7
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

30,195
mongodbmulti-chart-app0.1.01 of 1See more

mongodb multi-chart-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mongo:7b096b4cb9269
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

1,984
my-multi-chart-appmulti-chart-app0.1.01 of 2See more

my-multi-chart-app multi-chart-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mongo:7b096b4cb9269
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,823
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

12,861
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

12,861
Practica_4_helmmy-heml-appVerified publisher0.1.01 of 7See more

Practica_4_helm my-heml-app 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/rabbitmq:3.9-management8a279e9396a8
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

27,812
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

6,542
firehose-ethereumnodeifyVerified publisher1.7.11 of 2See more

firehose-ethereum nodeify 1.7.1

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
sigp/lighthouse:v8.1.344aa773dcf27
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,652
db-backupoleds-helm-chartsVerified publisher0.1.01 of 1See more

db-backup oleds-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
oled01/db-backup:0.1.06302fd2b5333
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

8,130
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

9,059
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latestfa394da808cc
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

1,735
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,462
grrosdfir-infrastructureVerified publisher1.0.31 of 5See more

grr osdfir-infrastructure 1.0.3

1 of the 5 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mariadb:11.3.2e101f9db3191
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

10,965
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mariadb:11.3.2e101f9db3191
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

72,154
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,660
k3p2p-avs0.1.51 of 2See more

k3 p2p-avs 0.1.5

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,339
mishtip2p-avs0.1.01 of 2See more

mishti p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,038
ungatep2p-avs0.1.01 of 3See more

ungate p2p-avs 0.1.0

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

25,681
p4p40.1.02 of 7See more

p4 p4 0.1.0

2 of the 7 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/rabbitmq:3.11-managementc3f70098e01d
libzstd@1.4.8+dfsg-3build1
no fix listed
mastercloudapps/planner:v1.2340a950b311b2
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

27,667
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mongo:7.0.28-jammy88785f6f665a
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,601
pet-battle-nsffpetbattle0.0.21 of 4See more

pet-battle-nsff petbattle 0.0.2

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
tensorflow/serving:latest8a208c232297
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,717
clickhousepetersandor14.3.21 of 1See more

clickhouse petersandor 14.3.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.3.2.398745843b17f9
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,220
redis-stack-awsphamxuanduong0.1.01 of 1See more

redis-stack-aws phamxuanduong 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.4.0-v0887cf87cc744
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,277
piepieVerified publisher0.11.11 of 1See more

pie pie 0.11.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/topolvm/pie:0.18.0aa467443e407
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,149
firehose-corepinaxVerified publisher0.1.11 of 2See more

firehose-core pinax 0.1.1

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,527
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
sigp/lighthouse:latest-amd6450f66cfebb6d
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,149
spring-boot-openshiftpiominVerified publisher0.3.111 of 1See more

spring-boot-openshift piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,616
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/rabbitmq:3.9-management8a279e9396a8
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

27,649
flink-kubernetes-operatorpresto-loadbalancer1.10.01 of 1See more

flink-kubernetes-operator presto-loadbalancer 1.10.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,316
unifiqaoruVerified publisher1.1.21 of 2See more

unifi qaoru 1.1.2

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mongo:7.0-jammy406a4fdca9fc
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,719
qualys-caqualys-ca-helm3.1.01 of 1See more

qualys-ca qualys-ca-helm 3.1.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
nelssec/qualys-agent-bootstrapper:v2.1.05e471f0cdeaa
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

1,917
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
zstd@1.4.2-lp151.3.3.1
1.5.5-5.1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
zstd@1.4.2-lp151.3.3.1
1.5.5-5.1

Open the chart page →

11,942

Container images carrying it

268 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/topolvm/pie:0.18.0aa467443e407
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.1da0b5eb7721a
libzstd@1.4.8+dfsg-3build1
no fix listed
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
libzstd@1.4.8+dfsg-3build1
no fix listed
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/aerokube/keygen:1.0.1578934444f04
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
libzstd@1.4.8+dfsg-3build1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.