StackRadar

CVE-2024-4067

Medium

Advisory

Published 14 May 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
193
of 17,781 indexed, latest versions
Container images
185
deployed by those charts
Fix available
1 of 2
affected packages

Regular Expression Denial of Service (ReDoS) in micromatch

Carried by container images the latest versions of 193 of 17,781 indexed charts deploy, on 185 images.

Affected packageAffected versionsFixed inImages
micromatchnpm2.3.5, 2.3.11, 3.1.10, 4.0.2+3 more4.0.8185
node-micromatchdeb4.0.5+~4.0.2-1no fix listed1
OSV records
GHSA-952p-6rrq-rcjvUBUNTU-CVE-2024-4067

Charts affected

193 by stars
ChartLatestAffected imagesRadar Score
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
micromatch@4.0.5
4.0.8

Open the chart page →

49,025
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
micromatch@4.0.5
4.0.8

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
micromatch@4.0.5
4.0.8

Open the chart page →

2,682
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
micromatch@4.0.2
4.0.8

Open the chart page →

8,213
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
micromatch@4.0.5
4.0.8

Open the chart page →

18,813
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
micromatch@4.0.5
4.0.8

Open the chart page →

25,017
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
micromatch@3.1.10
4.0.8

Open the chart page →

4,253
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
micromatch@4.0.5
4.0.8

Open the chart page →

3,407
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ibmcom/app-nav-init:1.0.1240ff499eb5b
micromatch@2.3.5
4.0.8
ibmcom/app-nav-ui:1.0.1e2a86997b36b
micromatch@3.1.10
4.0.8

Open the chart page →

32,915
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
micromatch@3.1.10
4.0.8
ibmcom/microclimate-portal:latested5505e5c7ec
micromatch@2.3.11
4.0.8

Open the chart page →

57,669
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
micromatch@3.1.10
4.0.8

Open the chart page →

4,944
interbtc-hydrainterlay0.1.151 of 4See more

interbtc-hydra interlay 0.1.15

1 of the 4 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
micromatch@4.0.4
4.0.8

Open the chart page →

6,831
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
micromatch@4.0.2
4.0.8

Open the chart page →

7,232
keyoxide-webittrident-oss0.2.31 of 1See more

keyoxide-web ittrident-oss 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
keyoxide/keyoxide:stable96f27a71269d
micromatch@4.0.4
4.0.8

Open the chart page →

2,363
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
micromatch@3.1.10
4.0.8

Open the chart page →

6,454
todo-appjunktext-via-aws1.2.101 of 1See more

todo-app junktext-via-aws 1.2.10

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.34d44adf5a4da2
micromatch@4.0.4
4.0.8

Open the chart page →

1,579
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
micromatch@3.1.10
4.0.8

Open the chart page →

4,667
skoonerkfirfer0.0.61 of 1See more

skooner kfirfer 0.0.6

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
micromatch@4.0.5
4.0.8

Open the chart page →

1,341
visual-regression-trackerkokuwa5.1.01 of 4See more

visual-regression-tracker kokuwa 5.1.0

1 of the 4 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
visualregressiontracker/api:5.0.11941aeb8c8bf9
micromatch@4.0.5
4.0.8

Open the chart page →

9,098
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
micromatch@4.0.4
4.0.8

Open the chart page →

4,230
component-storekubebb0.0.231 of 1See more

component-store kubebb 0.0.23

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
kubebb/component-store:latestfd8ecbd73213
micromatch@4.0.5
4.0.8

Open the chart page →

2,178
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
kubebb/bff-server:v0.2.0-202312040fbb732379bc
micromatch@4.0.5
4.0.8

Open the chart page →

13,819
workload-operatorkubevious0.0.31 of 1See more

workload-operator kubevious 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
kubevious/workload-operator:1.0.20b0f4c507eb6
micromatch@4.0.5
4.0.8

Open the chart page →

2,008
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
micromatch@4.0.5
4.0.8

Open the chart page →

2,685
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
micromatch@3.1.10
4.0.8

Open the chart page →

7,929
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
micromatch@4.0.4
4.0.8

Open the chart page →

2,247
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
micromatch@3.1.10
4.0.8

Open the chart page →

3,651
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
micromatch@4.0.5
4.0.8

Open the chart page →

9,774
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
micromatch@2.3.11
4.0.8

Open the chart page →

5,287
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
micromatch@3.1.10
4.0.8

Open the chart page →

5,940
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
micromatch@3.1.10
4.0.8

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
micromatch@3.1.10
4.0.8

Open the chart page →

10,603
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
micromatch@4.0.4
4.0.8

Open the chart page →

12,108
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
micromatch@4.0.5
4.0.8

Open the chart page →

14,809
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
micromatch@4.0.4
4.0.8

Open the chart page →

19,226
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
micromatch@4.0.5
4.0.8

Open the chart page →

2,316
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
micromatch@3.1.10
4.0.8

Open the chart page →

6,438
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
micromatch@4.0.2
4.0.8

Open the chart page →

6,684
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
micromatch@4.0.5
4.0.8

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
micromatch@3.1.10
4.0.8

Open the chart page →

4,960
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
micromatch@4.0.5
4.0.8

Open the chart page →

6,608
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
micromatch@3.1.10
4.0.8

Open the chart page →

3,128
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
micromatch@4.0.5
4.0.8

Open the chart page →

2,116
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
micromatch@4.0.5
4.0.8

Open the chart page →

2,116
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
micromatch@4.0.5
4.0.8

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
micromatch@4.0.5
4.0.8

Open the chart page →

2,116
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
micromatch@4.0.5
4.0.8

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
micromatch@3.1.10
4.0.8

Open the chart page →

3,269
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
micromatch@2.3.11
4.0.8
socialmediamacroscope/smile_server:0.3.31a528c794270
micromatch@3.1.10
4.0.8

Open the chart page →

109,294
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-4067.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
micromatch@4.0.5
4.0.8

Open the chart page →

15,132

Container images carrying it

185 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
enketo/enketo-express:3.0.4dcad9c2273f6
micromatch@4.0.4
4.0.8
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
micromatch@2.3.11
4.0.8
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
micromatch@3.1.10
4.0.8
1
ethersphere/bzz-token-service:latest7624f11a72ad
micromatch@4.0.4
4.0.8
1
ethersphere/onboarding-faucet:0.3.0513154aab230
micromatch@4.0.4
4.0.8
1
fiware/iotagent-ul:1.14.0fe11f55a926d
micromatch@3.1.10
4.0.8
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
micromatch@4.0.2
4.0.8
1
getferdi/ferdi-server:1.3.26e620b85afaa
micromatch@3.1.10
4.0.8
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
micromatch@4.0.2
4.0.8
1
gristlabs/grist:0.7.96e71b1914a7e
micromatch@3.1.10
4.0.8
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
micromatch@4.0.5
4.0.8
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
micromatch@4.0.5
4.0.8
1
henrywhitaker3/speedtest-tracker:latest47159a940229
micromatch@3.1.10
4.0.8
1
heywood8/redisinsight:2.28.00bc9ab313d37
micromatch@4.0.5
4.0.8
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
micromatch@4.0.4
4.0.8
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
micromatch@3.1.10
4.0.8
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
micromatch@2.3.5
4.0.8
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
micromatch@3.1.10
4.0.8
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
micromatch@3.1.10
4.0.8
1
ibmcom/microclimate-portal:latested5505e5c7ec
micromatch@2.3.11
4.0.8
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
micromatch@4.0.4
4.0.8
1
jayfong/yapi:1.10.2163e5d621910
micromatch@3.1.10
4.0.8
1
joplin/server:3.0-beta52af57880c0e
micromatch@3.1.10
4.0.8
1
joplin/server:2.14.2-betab87564ef34e9
micromatch@3.1.10
4.0.8
1
junktext/getting-started:1.0.5a70936c04aed
micromatch@4.0.4
4.0.8
1
junktext/getting-started:1.0.34d44adf5a4da2
micromatch@4.0.4
4.0.8
1
jupyterhub/jupyterhub:5.4.63974ba945e65
micromatch@4.0.5
node-micromatch@4.0.5+~4.0.2-1
4.0.8
no fix listed
1
keyoxide/keyoxide:stable96f27a71269d
micromatch@4.0.4
4.0.8
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
micromatch@4.0.5
4.0.8
1
konradkleine/docker-registry-frontend:v2181aad54ee64
micromatch@2.3.11
4.0.8
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
micromatch@4.0.5
4.0.8
1
kubebb/component-store:latestfd8ecbd73213
micromatch@4.0.5
4.0.8
1
kubevious/backend:1.2.22d9ba6eb46b6
micromatch@4.0.5
4.0.8
1
kubevious/collector:1.2.1f58226f9d84e
micromatch@4.0.5
4.0.8
1
kubevious/parser:1.2.299ae7a5168c2
micromatch@4.0.5
4.0.8
1
kubevious/workload-operator:1.0.20b0f4c507eb6
micromatch@4.0.5
4.0.8
1
kyleslugg/klusterview:latestba8c36dfdfbd
micromatch@4.0.5
4.0.8
1
kyso/kyso-front:lateste52595c5c16f
micromatch@4.0.5
4.0.8
1
lavandadelpatio/frontend:latest501c3f31e0bc
micromatch@3.1.10
4.0.8
1
library/ghost:6.25.12654b1e90413
micromatch@3.1.10
4.0.8
1
library/ghost:4.37.0767230c0f263
micromatch@3.1.10
4.0.8
1
library/ghost:5.79.083f7bf209844
micromatch@3.1.10
4.0.8
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
micromatch@3.1.10
4.0.8
1
library/kibana:7.17.150172f1c538e7
micromatch@4.0.4
4.0.8
1
library/kibana:7.17.8c5781ba340ef
micromatch@4.0.2
4.0.8
1
library/kibana:7.17.3e2e2031c15be
micromatch@4.0.2
4.0.8
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
micromatch@4.0.4
4.0.8
1
linuxserver/code-server:4.10.1a5e43a05ae79
micromatch@4.0.5
4.0.8
1
linuxserver/codimd:latestb801bbcf6386
micromatch@2.3.11
4.0.8
1
lissy93/dashy:2.0.51991f7be5ed0
micromatch@3.1.10
4.0.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.