StackRadar

CVE-2024-4067

Medium

Advisory

Published 14 May 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
193
of 17,781 indexed, latest versions
Container images
185
deployed by those charts
Fix available
1 of 2
affected packages

Regular Expression Denial of Service (ReDoS) in micromatch

Carried by container images the latest versions of 193 of 17,781 indexed charts deploy, on 185 images.

Affected packageAffected versionsFixed inImages
micromatchnpm2.3.5, 2.3.11, 3.1.10, 4.0.2+3 more4.0.8185
node-micromatchdeb4.0.5+~4.0.2-1no fix listed1
OSV records
GHSA-952p-6rrq-rcjvUBUNTU-CVE-2024-4067

Charts affected

193 by stars
ChartLatestAffected imagesRadar Score
ackeesudaVerified publisher0.2.11 of 1See more

ackee suda 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
electerious/ackee:3.2.05e7173fa321c
micromatch@4.0.4
4.0.8

Open the chart page →

1,602
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
micromatch@3.1.10
4.0.8

Open the chart page →

7,517
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
micromatch@3.1.10
4.0.8

Open the chart page →

3,833
scrapoxywiremindVerified publisher0.3.41 of 1See more

scrapoxy wiremind 0.3.4

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
wiremind/scrapoxy:lateste7048929a676
micromatch@2.3.11
4.0.8

Open the chart page →

2,154
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
micromatch@3.1.10
4.0.8

Open the chart page →

25,443
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
micromatch@4.0.5
4.0.8

Open the chart page →

4,880
katalogalpineworks0.1.21 of 5See more

katalog alpineworks 0.1.2

1 of the 5 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
micromatch@4.0.5
4.0.8

Open the chart page →

4,497
openhab-cloudandibraeuVerified publisher1.2.61 of 1See more

openhab-cloud andibraeu 1.2.6

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
openhab/openhab-cloud:a8138a329dd2bac8c4b
micromatch@3.1.10
4.0.8

Open the chart page →

3,437
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
micromatch@3.1.10
4.0.8

Open the chart page →

3,237
angular-node-chartangular-webapp2.0.01 of 1See more

angular-node-chart angular-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
rakii8585/angular-node-webapp:latest026082a515ac
micromatch@3.1.10
4.0.8

Open the chart page →

2,616
lametric-nightscout-proxyaolde0.1.01 of 1See more

lametric-nightscout-proxy aolde 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ghcr.io/aolde/lametric-nightscout-proxy:latest7d1951b6baf5
micromatch@4.0.5
4.0.8

Open the chart page →

1,186
apimap-developerapimapOfficialVerified publisher1.4.11 of 1See more

apimap-developer apimap 1.4.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
apimap/developer:v1.3.1406d3858e20c
micromatch@4.0.5
4.0.8

Open the chart page →

2,353
apimap-portalapimapOfficialVerified publisher2.4.01 of 1See more

apimap-portal apimap 2.4.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
apimap/portal:v2.4.0041a4790c65c
micromatch@4.0.4
4.0.8

Open the chart page →

2,396
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
assistiot/open_api_frontend:1.0.1f11d82defc70
micromatch@4.0.5
4.0.8

Open the chart page →

18,277
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
micromatch@4.0.5
4.0.8

Open the chart page →

32,501
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ltdstudio/terraforming-mars:latest0e76c6f4eac0
micromatch@4.0.4
4.0.8

Open the chart page →

7,152
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
micromatch@3.1.10
4.0.8

Open the chart page →

5,806
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
micromatch@4.0.5
4.0.8

Open the chart page →

4,455
bluerange-mosquittobluerangeOfficialVerified publisher1.0.41 of 1See more

bluerange-mosquitto bluerange 1.0.4

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
bluerange/bluerange-mosquitto:25f1bfbba84832
micromatch@4.0.2
4.0.8

Open the chart page →

1,168
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
micromatch@2.3.11
4.0.8

Open the chart page →

4,069
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
micromatch@3.1.10
4.0.8

Open the chart page →

4,083
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
micromatch@4.0.5
4.0.8
countly/frontend:25.05.42acbc11499b6
micromatch@4.0.5
4.0.8

Open the chart page →

7,295
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
micromatch@3.1.10
4.0.8

Open the chart page →

29,901
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
micromatch@2.3.11
4.0.8

Open the chart page →

27,417
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
micromatch@3.1.10
4.0.8

Open the chart page →

2,580
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
micromatch@2.3.11
4.0.8

Open the chart page →

25,456
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
micromatch@4.0.5
node-micromatch@4.0.5+~4.0.2-1
4.0.8
no fix listed

Open the chart page →

13,220
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
micromatch@4.0.5
4.0.8

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
micromatch@4.0.5
4.0.8

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
micromatch@4.0.5
4.0.8

Open the chart page →

5,141
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
micromatch@3.1.10
4.0.8

Open the chart page →

12,907
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
coldatom/containers-security-front:latest7c2fbbb41bcf
micromatch@4.0.5
4.0.8

Open the chart page →

9,146
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
micromatch@3.1.10
4.0.8

Open the chart page →

13,852
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
micromatch@4.0.5
4.0.8

Open the chart page →

2,529
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
micromatch@3.1.10
4.0.8

Open the chart page →

11,174
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
micromatch@3.1.10
4.0.8

Open the chart page →

3,744
ethstatsethereum-helm-chartsVerified publisher0.1.41 of 1See more

ethstats ethereum-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
skylenet/ethstats-server:pow-latestd757cc016198
micromatch@4.0.5
4.0.8

Open the chart page →

1,109
testnet-faucetethereum-helm-chartsVerified publisher0.1.31 of 1See more

testnet-faucet ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
parithoshj/testnet-faucet:9859e0dcdca426fea6d
micromatch@3.1.10
4.0.8

Open the chart page →

3,005
bee-localchainethersphereVerified publisher0.2.01 of 1See more

bee-localchain ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
micromatch@4.0.5
4.0.8

Open the chart page →

2,266
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
micromatch@4.0.4
4.0.8

Open the chart page →

3,260
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
micromatch@4.0.5
4.0.8

Open the chart page →

4,756
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
micromatch@4.0.4
4.0.8

Open the chart page →

3,320
iotagent-ulfiware0.1.21 of 1See more

iotagent-ul fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
fiware/iotagent-ul:1.14.0fe11f55a926d
micromatch@3.1.10
4.0.8

Open the chart page →

3,337
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
micromatch@2.3.11
4.0.8

Open the chart page →

5,941
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
micromatch@4.0.2
4.0.8

Open the chart page →

4,043
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
micromatch@3.1.10
4.0.8

Open the chart page →

4,591
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
micromatch@4.0.4
4.0.8

Open the chart page →

34,754
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
micromatch@3.1.10
4.0.8

Open the chart page →

9,019
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
governify/registry:v3.4.0d3f37f4f8168
micromatch@4.0.2
4.0.8

Open the chart page →

22,512
Governify-Falcongovernify0.1.02 of 10See more

Governify-Falcon governify 0.1.0

2 of the 10 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
governify/collector-dynamic:v1.3.06d3d1a5b46a9
micromatch@4.0.2
4.0.8
governify/registry:v3.4.0d3f37f4f8168
micromatch@4.0.2
4.0.8

Open the chart page →

24,319

Container images carrying it

185 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
enketo/enketo-express:3.0.4dcad9c2273f6
micromatch@4.0.4
4.0.8
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
micromatch@2.3.11
4.0.8
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
micromatch@3.1.10
4.0.8
1
ethersphere/bzz-token-service:latest7624f11a72ad
micromatch@4.0.4
4.0.8
1
ethersphere/onboarding-faucet:0.3.0513154aab230
micromatch@4.0.4
4.0.8
1
fiware/iotagent-ul:1.14.0fe11f55a926d
micromatch@3.1.10
4.0.8
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
micromatch@4.0.2
4.0.8
1
getferdi/ferdi-server:1.3.26e620b85afaa
micromatch@3.1.10
4.0.8
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
micromatch@4.0.2
4.0.8
1
gristlabs/grist:0.7.96e71b1914a7e
micromatch@3.1.10
4.0.8
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
micromatch@4.0.5
4.0.8
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
micromatch@4.0.5
4.0.8
1
henrywhitaker3/speedtest-tracker:latest47159a940229
micromatch@3.1.10
4.0.8
1
heywood8/redisinsight:2.28.00bc9ab313d37
micromatch@4.0.5
4.0.8
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
micromatch@4.0.4
4.0.8
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
micromatch@3.1.10
4.0.8
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
micromatch@2.3.5
4.0.8
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
micromatch@3.1.10
4.0.8
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
micromatch@3.1.10
4.0.8
1
ibmcom/microclimate-portal:latested5505e5c7ec
micromatch@2.3.11
4.0.8
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
micromatch@4.0.4
4.0.8
1
jayfong/yapi:1.10.2163e5d621910
micromatch@3.1.10
4.0.8
1
joplin/server:3.0-beta52af57880c0e
micromatch@3.1.10
4.0.8
1
joplin/server:2.14.2-betab87564ef34e9
micromatch@3.1.10
4.0.8
1
junktext/getting-started:1.0.5a70936c04aed
micromatch@4.0.4
4.0.8
1
junktext/getting-started:1.0.34d44adf5a4da2
micromatch@4.0.4
4.0.8
1
jupyterhub/jupyterhub:5.4.63974ba945e65
micromatch@4.0.5
node-micromatch@4.0.5+~4.0.2-1
4.0.8
no fix listed
1
keyoxide/keyoxide:stable96f27a71269d
micromatch@4.0.4
4.0.8
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
micromatch@4.0.5
4.0.8
1
konradkleine/docker-registry-frontend:v2181aad54ee64
micromatch@2.3.11
4.0.8
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
micromatch@4.0.5
4.0.8
1
kubebb/component-store:latestfd8ecbd73213
micromatch@4.0.5
4.0.8
1
kubevious/backend:1.2.22d9ba6eb46b6
micromatch@4.0.5
4.0.8
1
kubevious/collector:1.2.1f58226f9d84e
micromatch@4.0.5
4.0.8
1
kubevious/parser:1.2.299ae7a5168c2
micromatch@4.0.5
4.0.8
1
kubevious/workload-operator:1.0.20b0f4c507eb6
micromatch@4.0.5
4.0.8
1
kyleslugg/klusterview:latestba8c36dfdfbd
micromatch@4.0.5
4.0.8
1
kyso/kyso-front:lateste52595c5c16f
micromatch@4.0.5
4.0.8
1
lavandadelpatio/frontend:latest501c3f31e0bc
micromatch@3.1.10
4.0.8
1
library/ghost:6.25.12654b1e90413
micromatch@3.1.10
4.0.8
1
library/ghost:4.37.0767230c0f263
micromatch@3.1.10
4.0.8
1
library/ghost:5.79.083f7bf209844
micromatch@3.1.10
4.0.8
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
micromatch@3.1.10
4.0.8
1
library/kibana:7.17.150172f1c538e7
micromatch@4.0.4
4.0.8
1
library/kibana:7.17.8c5781ba340ef
micromatch@4.0.2
4.0.8
1
library/kibana:7.17.3e2e2031c15be
micromatch@4.0.2
4.0.8
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
micromatch@4.0.4
4.0.8
1
linuxserver/code-server:4.10.1a5e43a05ae79
micromatch@4.0.5
4.0.8
1
linuxserver/codimd:latestb801bbcf6386
micromatch@2.3.11
4.0.8
1
lissy93/dashy:2.0.51991f7be5ed0
micromatch@3.1.10
4.0.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.