StackRadar

CVE-2023-22467

High

Advisory

Published 9 Jan 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
28
of 17,781 indexed, latest versions
Container images
29
deployed by those charts
Fix available
1 of 1
affected package

Luxon Inefficient Regular Expression Complexity vulnerability

Carried by container images the latest versions of 28 of 17,781 indexed charts deploy, on 29 images.

Affected packageAffected versionsFixed inImages
luxonnpm1.13.1, 1.25.0, 1.26.0, 1.27.0+3 more1.28.1, 2.5.2, 3.2.129
OSV records
GHSA-3xq5-wjfh-ppjc

Charts affected

28 by stars
ChartLatestAffected imagesRadar Score
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
luxon@1.28.0
1.28.1

Open the chart page →

5,251
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
luxon@1.25.0
1.28.1

Open the chart page →

5,946
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
luxon@3.0.4
3.2.1

Open the chart page →

10,311
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
luxon@2.3.2
2.5.2

Open the chart page →

7,776
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
luxon@1.28.0
1.28.1

Open the chart page →

4,260
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
luxon@1.26.0
1.28.1

Open the chart page →

4,405
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
luxon@1.25.0
1.28.1

Open the chart page →

3,444
growthbookgrowthbook5.0.11 of 2See more

growthbook growthbook 5.0.1

1 of the 2 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
growthbook/growthbook:5.0.1f53ead646b5f
luxon@1.28.0
1.28.1

Open the chart page →

709
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
luxon@1.28.0
1.28.1

Open the chart page →

17,284
flamerlex0.3.01 of 1See more

flame rlex 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
pawelmalak/flame:2.1.193e7b0abb603
luxon@1.27.0
1.28.1

Open the chart page →

2,449
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
luxon@1.28.0
1.28.1

Open the chart page →

6,879
ackeesudaVerified publisher0.2.11 of 1See more

ackee suda 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
electerious/ackee:3.2.05e7173fa321c
luxon@1.28.0
1.28.1

Open the chart page →

1,602
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
luxon@1.25.0
1.28.1

Open the chart page →

3,833
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
luxon@1.28.0
1.28.1

Open the chart page →

4,455
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
luxon@1.28.0
1.28.1

Open the chart page →

4,083
flamegabe565Verified publisher0.6.01 of 1See more

flame gabe565 0.6.0

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
pawelmalak/flame:multiarch2.3.19f88b17692a0
luxon@1.27.0
1.28.1

Open the chart page →

2,172
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
luxon@1.28.0
1.28.1

Open the chart page →

12,222
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
luxon@1.28.0
1.28.1

Open the chart page →

9,019
Governify-Bluejaygovernify0.1.05 of 12See more

Governify-Bluejay governify 0.1.0

5 of the 12 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
luxon@1.28.0
1.28.1
governify/director:v1.4.0608c6940bb98
luxon@1.28.0
1.28.1
governify/registry:v3.4.0d3f37f4f8168
luxon@1.28.0
1.28.1
governify/render:v2.2.0daeca1ce28e6
luxon@1.28.0
1.28.1
governify/reporter:v2.2.038595913458f
luxon@1.28.0
1.28.1

Open the chart page →

22,512
Governify-Falcongovernify0.1.06 of 10See more

Governify-Falcon governify 0.1.0

6 of the 10 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
luxon@1.28.0
1.28.1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
luxon@1.28.0
1.28.1
governify/director:v1.4.0608c6940bb98
luxon@1.28.0
1.28.1
governify/registry:v3.4.0d3f37f4f8168
luxon@1.28.0
1.28.1
governify/render:v2.2.0daeca1ce28e6
luxon@1.28.0
1.28.1
governify/reporter:v2.2.038595913458f
luxon@1.28.0
1.28.1

Open the chart page →

24,319
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
luxon@3.0.4
3.2.1

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
luxon@3.0.4
3.2.1

Open the chart page →

2,682
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
luxon@1.25.0
1.28.1

Open the chart page →

4,253
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
luxon@1.27.0
1.28.1

Open the chart page →

7,232
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
luxon@1.13.1
1.28.1

Open the chart page →

7,929
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
luxon@1.28.0
1.28.1

Open the chart page →

4,960
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
luxon@1.28.0
1.28.1

Open the chart page →

3,576
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2023-22467.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
luxon@1.25.0
1.28.1

Open the chart page →

5,459

Container images carrying it

29 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
luxon@3.0.4
3.2.1
3
governify/assets-manager:v1.4.12987672448c7
luxon@1.28.0
1.28.1
2
governify/director:v1.4.0608c6940bb98
luxon@1.28.0
1.28.1
2
governify/registry:v3.4.0d3f37f4f8168
luxon@1.28.0
1.28.1
2
governify/render:v2.2.0daeca1ce28e6
luxon@1.28.0
1.28.1
2
governify/reporter:v2.2.038595913458f
luxon@1.28.0
1.28.1
2
requarks/wiki:2:latest68f0d1848261
luxon@1.25.0
1.28.1
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
luxon@1.13.1
1.28.1
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
luxon@1.26.0
1.28.1
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
luxon@1.28.0
1.28.1
1
catalysm/csmm:latestf003b35f54d9
luxon@1.28.0
1.28.1
1
electerious/ackee:3.2.05e7173fa321c
luxon@1.28.0
1.28.1
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
luxon@1.28.0
1.28.1
1
growthbook/growthbook:5.0.1f53ead646b5f
luxon@1.28.0
1.28.1
1
jakowenko/double-take:1.6.0b858bac9e32a
luxon@1.28.0
1.28.1
1
library/ghost:6.25.12654b1e90413
luxon@1.28.0
1.28.1
1
library/ghost:4.37.0767230c0f263
luxon@1.28.0
1.28.1
1
library/ghost:5.79.083f7bf209844
luxon@1.28.0
1.28.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
luxon@1.28.0
1.28.1
1
library/kibana:7.17.8c5781ba340ef
luxon@1.28.0
1.28.1
1
library/kibana:7.17.3e2e2031c15be
luxon@1.28.0
1.28.1
1
misskey/misskey:12.110.1e08b7c478093
luxon@1.28.0
1.28.1
1
n8nio/n8n:0.212.0a9195bc499a3
luxon@2.3.2
2.5.2
1
pawelmalak/flame:2.1.193e7b0abb603
luxon@1.27.0
1.28.1
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
luxon@1.27.0
1.28.1
1
requarks/wiki:canary-2.5.2438b5865a7386c
luxon@1.25.0
1.28.1
1
roadiehq/community-backstage-image:latestef355bf5b639
luxon@1.27.0
1.28.1
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
luxon@1.25.0
1.28.1
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
luxon@1.25.0
1.28.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.