StackRadar

CVE-2023-25166

Medium

Advisory

Published 8 Feb 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 1
affected package

@sideway/formula contains Regular Expression Denial of Service (ReDoS) Vulnerability

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
@sideway/formulanpm3.0.03.0.115
OSV records
GHSA-c2jc-4fpr-4vhg

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
kubeviouskubevious1.2.21 of 7See more

kubevious kubevious 1.2.2

1 of the 7 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
kubevious/guard:1.2.19bf567704de2
@sideway/formula@3.0.0
3.0.1

Open the chart page →

14,204
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
@sideway/formula@3.0.0
3.0.1

Open the chart page →

24,488
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
@sideway/formula@3.0.0
3.0.1

Open the chart page →

17,284
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
@sideway/formula@3.0.0
3.0.1

Open the chart page →

6,879
apimap-developerapimapOfficialVerified publisher1.4.11 of 1See more

apimap-developer apimap 1.4.1

1 of the 1 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
apimap/developer:v1.3.1406d3858e20c
@sideway/formula@3.0.0
3.0.1

Open the chart page →

2,353
apimap-portalapimapOfficialVerified publisher2.4.01 of 1See more

apimap-portal apimap 2.4.0

1 of the 1 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
apimap/portal:v2.4.0041a4790c65c
@sideway/formula@3.0.0
3.0.1

Open the chart page →

2,396
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
@sideway/formula@3.0.0
3.0.1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
@sideway/formula@3.0.0
3.0.1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
@sideway/formula@3.0.0
3.0.1

Open the chart page →

45,363
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
@sideway/formula@3.0.0
3.0.1

Open the chart page →

5,410
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
@sideway/formula@3.0.0
3.0.1

Open the chart page →

1,927
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@sideway/formula@3.0.0
3.0.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@sideway/formula@3.0.0
3.0.1

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@sideway/formula@3.0.0
3.0.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@sideway/formula@3.0.0
3.0.1

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
@sideway/formula@3.0.0
3.0.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@sideway/formula@3.0.0
3.0.1

Open the chart page →

12,108
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@sideway/formula@3.0.0
3.0.1
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
@sideway/formula@3.0.0
3.0.1

Open the chart page →

11,479
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2023-25166.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@sideway/formula@3.0.0
3.0.1
mojaloop/central-ledger:v13.14.01abc8a7aa71c
@sideway/formula@3.0.0
3.0.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@sideway/formula@3.0.0
3.0.1
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
@sideway/formula@3.0.0
3.0.1

Open the chart page →

19,226

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@sideway/formula@3.0.0
3.0.1
5
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@sideway/formula@3.0.0
3.0.1
3
mojaloop/central-ledger:v13.14.01abc8a7aa71c
@sideway/formula@3.0.0
3.0.1
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
@sideway/formula@3.0.0
3.0.1
2
apimap/developer:v1.3.1406d3858e20c
@sideway/formula@3.0.0
3.0.1
1
apimap/portal:v2.4.0041a4790c65c
@sideway/formula@3.0.0
3.0.1
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
@sideway/formula@3.0.0
3.0.1
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
@sideway/formula@3.0.0
3.0.1
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
@sideway/formula@3.0.0
3.0.1
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
@sideway/formula@3.0.0
3.0.1
1
kubevious/guard:1.2.19bf567704de2
@sideway/formula@3.0.0
3.0.1
1
kubevious/parser:1.0.151acf1a1f0b47
@sideway/formula@3.0.0
3.0.1
1
library/kibana:7.17.8c5781ba340ef
@sideway/formula@3.0.0
3.0.1
1
library/kibana:7.17.3e2e2031c15be
@sideway/formula@3.0.0
3.0.1
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
@sideway/formula@3.0.0
3.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.