StackRadar

CVE-2022-4899

High

Advisory

Published 31 Mar 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
299
of 17,787 indexed, latest versions
Container images
268
deployed by those charts
Fix available
1 of 2
affected packages

libzstd-devel-1.5.5-5.1 on GA media

Carried by container images the latest versions of 299 of 17,787 indexed charts deploy, on 268 images.

Affected packageAffected versionsFixed inImages
libzstddeb1.4.8+dfsg-3build1no fix listed266
zstdrpm1.4.2-lp151.3.3.11.5.5-5.12
OSV records
UBUNTU-CVE-2022-4899openSUSE-SU-2024:13613-1

Charts affected

299 by stars
ChartLatestAffected imagesRadar Score
sonarquberedhat-cop0.1.131 of 1See more

sonarqube redhat-cop 0.1.13

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/sonarqube:10.7.0-community0842dcd4c8f8
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,242
reviewboardrock8sVerified publisher0.0.11 of 3See more

reviewboard rock8s 0.0.1

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

6,154
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

12,999
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,969
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,491
nadekobotryuunosukeds30.1.21 of 2See more

nadekobot ryuunosukeds3 0.1.2

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

8,720
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,385
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

16,159
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

8,073
mongodbsb-helm-charts0.4.01 of 1See more

mongodb sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mongo:7.0.140032d2ca20db
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,095
mindustryschichtelVerified publisher0.1.11 of 1See more

mindustry schichtel 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
pschichtel/mindustry-server:v145.1b543e9c2d371
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,265
satisfactoryschichtelVerified publisher0.3.31 of 1See more

satisfactory schichtel 0.3.3

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.9464d11e36e10
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,564
vikunjaschmitzis1.0.01 of 3See more

vikunja schmitzis 1.0.0

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
typesense/typesense:0.25.1035ccfbc3fd8
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,109
satisfactory-serverschoolguys-helmcharts0.1.81 of 1See more

satisfactory-server schoolguys-helmcharts 0.1.8

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,466
cortezasergiotocaliniVerified publisher1.0.11 of 1See more

corteza sergiotocalini 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.60bcdcbcd3c63
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,325
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,496
clickhouse-keepersinextraVerified publisher0.7.21 of 1See more

clickhouse-keeper sinextra 0.7.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.12.6a65ca89ddbe8
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,220
mongosqldsinextraVerified publisher0.3.71 of 1See more

mongosqld sinextra 0.3.7

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,599
mariadbsitepilot1.0.31 of 1See more

mariadb sitepilot 1.0.3

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mariadb:10.692e50059ea0a
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,862
oi-slurm-cluster-chartslurm-cluster-chart0.25.11 of 4See more

oi-slurm-cluster-chart slurm-cluster-chart 0.25.1

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,376
slurm-cluster-chartslurm-cluster-chart0.25.01 of 4See more

slurm-cluster-chart slurm-cluster-chart 0.25.0

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

4,376
amt-configuresmarthallVerified publisher0.1.11 of 1See more

amt-configure smarthall 0.1.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
boxcutter/meshcmd:1.1.384e13f01bcab
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,759
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

13,653
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

13,127
envoy-proxysqream-chartsVerified publisher0.6.01 of 2See more

envoy-proxy sqream-charts 0.6.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.1e596fda6a0ce
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,309
lighthouse-validatorstakewise7.0.11 of 2See more

lighthouse-validator stakewise 7.0.1

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
sigp/lighthouse:v7.0.12cae720e9a35
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,020
rethstakewise1.2.11 of 3See more

reth stakewise 1.2.1

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/paradigmxyz/reth:v1.3.121e5290e8b743
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

2,016
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

13,817
convert-datasvtechVerified publisher0.13.21 of 3See more

convert-data svtech 0.13.2

1 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,636
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

12,097
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,880
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

12,097
topolvmsyself1.3.01 of 1See more

topolvm syself 1.3.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,570
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
libzstd@1.4.8+dfsg-3build1
no fix listed
xeladock/nginx2:latestc259a67b1dff
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

17,561
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

36,661
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,652
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

20,362
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mongo:7-jammy406a4fdca9fc
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,336
orchestra-login-portaltremolo2.3.981 of 1See more

orchestra-login-portal tremolo 2.3.98

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

3,002
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
redis/redis-stack-server:7.2.0-v10e44b2b49d059
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,599
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

9,396
twenty-crmvictorlane0.0.12 of 3See more

twenty-crm victorlane 0.0.1

2 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
redis/redis-stack-server:latest798ab84d9f26
libzstd@1.4.8+dfsg-3build1
no fix listed
twentycrm/twenty-postgres-spilo:latest2f78405a78be
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

13,563
eth-validatorwateim1.4.52 of 3See more

eth-validator wateim 1.4.5

2 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
sigp/lighthouse:latest9a62bb870545
libzstd@1.4.8+dfsg-3build1
no fix listed
wateim/lighthouse-launch:latest2520149ee574
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

5,077
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

6,272
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
library/mariadb:10ce66c7be32a0
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

8,858
openebswenerme3.10.02 of 3See more

openebs wenerme 3.10.0

2 of the 3 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
libzstd@1.4.8+dfsg-3build1
no fix listed
openebs/node-disk-operator:2.1.06afe2123c457
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

10,568
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

9,296
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

14,172
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2022-4899.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libzstd@1.4.8+dfsg-3build1
no fix listed

Open the chart page →

7,916

Container images carrying it

268 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/topolvm/pie:0.18.0aa467443e407
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.41.170548dbe0c6a
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
libzstd@1.4.8+dfsg-3build1
no fix listed
1
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.1da0b5eb7721a
libzstd@1.4.8+dfsg-3build1
no fix listed
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
libzstd@1.4.8+dfsg-3build1
no fix listed
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/aerokube/keygen:1.0.1578934444f04
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
libzstd@1.4.8+dfsg-3build1
no fix listed
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
libzstd@1.4.8+dfsg-3build1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.