StackRadar

CVE-2017-16137

Low

Advisory

Published 9 Aug 2018In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.028
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
139
of 17,781 indexed, latest versions
Container images
130
deployed by those charts
Fix available
1 of 1
affected package

Regular Expression Denial of Service in debug

Carried by container images the latest versions of 139 of 17,781 indexed charts deploy, on 130 images.

Affected packageAffected versionsFixed inImages
debugnpm0.7.2, 0.7.4, 0.8.1, 1.0.5+8 more2.6.9, 3.2.7, 4.3.1130
OSV records
GHSA-gxpj-cx7g-858c

Charts affected

139 by stars
ChartLatestAffected imagesRadar Score
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
oscarsotosanchez/weatherservice:v1.0911ec961d10b
debug@3.2.6
3.2.7

Open the chart page →

27,550
mergeabledoubanVerified publisher0.2.21 of 1See more

mergeable douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ghcr.io/leoquote/mergeable:latest451706815103
debug@4.1.1
4.3.1

Open the chart page →

4,223
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
oscarsotosanchez/weatherservice:v1.0911ec961d10b
debug@3.2.6
3.2.7

Open the chart page →

24,656
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
debug@4.1.1
4.3.1

Open the chart page →

11,174
eolicplantseolicplantsVerified publisher0.1.01 of 7See more

eolicplants eolicplants 0.1.0

1 of the 7 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
oscarsotosanchez/weatherservice:v1.0911ec961d10b
debug@3.2.6
3.2.7

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.01 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

1 of the 7 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
oscarsotosanchez/weatherservice:v1.0911ec961d10b
debug@3.2.6
3.2.7

Open the chart page →

27,256
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
debug@3.2.6
3.2.7

Open the chart page →

3,260
exposrexposr0.12.01 of 1See more

exposr exposr 0.12.0

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ghcr.io/exposr/exposrd:v0.12.0561c8f23bdb6
debug@4.1.1
4.3.1

Open the chart page →

570
logentriesfairwinds-incubator0.2.21 of 1See more

logentries fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
logentries/docker-logentries:0.2.1f1f90a236998
debug@2.6.0
2.6.9

Open the chart page →

1,597
iotagent-ulfiware0.1.21 of 1See more

iotagent-ul fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
fiware/iotagent-ul:1.14.0fe11f55a926d
debug@4.1.1
4.3.1

Open the chart page →

3,337
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
debug@2.2.0
2.6.9

Open the chart page →

5,941
flaresolverrgeek-cookbookVerified publisher5.4.21 of 1See more

flaresolverr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v1.2.896f8c08c0c1b
debug@4.2.0
4.3.1

Open the chart page →

1,870
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
debug@4.1.1
4.3.1

Open the chart page →

10,994
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
debug@4.1.1
4.3.1

Open the chart page →

4,043
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
debug@4.1.1
4.3.1

Open the chart page →

4,591
theloungegeek-cookbookVerified publisher3.4.21 of 1See more

thelounge geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
thelounge/thelounge:4.2.0-alpine639978459c3a
debug@3.2.6
3.2.7

Open the chart page →

2,689
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
debug@4.1.1
4.3.1

Open the chart page →

9,019
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
debug@0.8.1
2.6.9

Open the chart page →

22,512
Governify-Falcongovernify0.1.02 of 10See more

Governify-Falcon governify 0.1.0

2 of the 10 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
debug@0.8.1
2.6.9
governify/collector-dynamic:v1.3.06d3d1a5b46a9
debug@3.2.6
3.2.7

Open the chart page →

24,319
gitter-irc-bridgehalkeye0.1.11 of 1See more

gitter-irc-bridge halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
debug@0.8.1
2.6.9

Open the chart page →

3,642
hubothalkeye0.0.11 of 1See more

hubot halkeye 0.0.1

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
halkeye/hubot:latest9764d2202130
debug@4.1.1
4.3.1

Open the chart page →

2,116
irslackdhalkeye0.1.01 of 1See more

irslackd halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
halkeye/irslackd:latest7638bfba70b0
debug@4.1.1
4.3.1

Open the chart page →

2,064
matrix-appservice-gitterhalkeye0.1.01 of 1See more

matrix-appservice-gitter halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
debug@0.8.1
2.6.9

Open the chart page →

3,003
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
debug@4.1.1
4.3.1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
debug@3.2.6
3.2.7
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
debug@3.2.6
3.2.7
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
debug@3.2.6
3.2.7

Open the chart page →

89,959
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
debug@4.1.1
4.3.1

Open the chart page →

8,213
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
debug@4.1.1
4.3.1

Open the chart page →

4,253
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ibmcom/app-nav-init:1.0.1240ff499eb5b
debug@2.2.0
2.6.9
ibmcom/app-nav-ui:1.0.1e2a86997b36b
debug@3.2.6
3.2.7

Open the chart page →

32,915
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
debug@0.7.4
2.6.9

Open the chart page →

57,669
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
debug@3.2.6
3.2.7

Open the chart page →

4,505
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
frappe/frappe-socketio:v13.4.12095767a9e82
debug@4.1.1
4.3.1

Open the chart page →

6,501
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
debug@3.2.6
3.2.7

Open the chart page →

4,944
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
debug@4.1.1
4.3.1

Open the chart page →

10,494
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
debug@3.2.6
3.2.7

Open the chart page →

7,232
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
debug@0.7.4
2.6.9

Open the chart page →

4,614
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
debug@2.2.0
2.6.9

Open the chart page →

6,454
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
debug@4.1.1
4.3.1

Open the chart page →

4,667
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
debug@4.1.1
4.3.1

Open the chart page →

9,783
statsdkeyporttech0.1.191 of 1See more

statsd keyporttech 0.1.19

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
statsd/statsd:v0.8.6dab129e74c25
debug@4.1.1
4.3.1

Open the chart page →

4,185
nubladolsst-sqre0.9.231 of 5See more

nublado lsst-sqre 0.9.23

1 of the 5 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
lsstsqre/sciplat-hub:latest5e0ade6bed1c
debug@2.2.0
2.6.9

Open the chart page →

5,786
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
debug@4.1.1
4.3.1

Open the chart page →

17,779
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
debug@4.1.1
4.3.1

Open the chart page →

7,929
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
debug@4.1.1
4.3.1

Open the chart page →

3,651
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
debug@4.1.1
4.3.1

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
debug@4.1.1
4.3.1

Open the chart page →

10,603
iotmmontesVerified publisher0.3.22 of 7See more

iot mmontes 0.3.2

2 of the 7 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
debug@4.1.1
4.3.1
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
debug@4.1.1
4.3.1

Open the chart page →

10,608
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
debug@3.2.6
3.2.7

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
debug@3.2.6
3.2.7

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
debug@3.2.6
3.2.7

Open the chart page →

12,108
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
debug@0.7.2
2.6.9

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
debug@3.2.6
3.2.7
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
debug@3.2.6
3.2.7

Open the chart page →

11,479

Container images carrying it

130 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
inseefrlab/shelly:cloudshell31f04ca7436b
debug@4.1.1
4.3.1
1
jayfong/yapi:1.10.2163e5d621910
debug@2.2.0
2.6.9
1
jupyterhub/configurable-http-proxy:4.2.281bd96729c14
debug@3.2.6
3.2.7
1
jupyterhub/configurable-http-proxy:3.0.0c36cf3cc1c99
debug@2.2.0
2.6.9
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
debug@3.2.6
3.2.7
1
konradkleine/docker-registry-frontend:v2181aad54ee64
debug@1.0.5
2.6.9
1
koumoul/capture:17108d47be3b2
debug@3.2.6
3.2.7
1
koumoul/openapi-viewer:18eeca2e8285b
debug@2.6.8
2.6.9
1
lavandadelpatio/frontend:latest501c3f31e0bc
debug@4.1.1
4.3.1
1
library/ghost:6.25.12654b1e90413
debug@4.1.1
4.3.1
1
library/ghost:4.37.0767230c0f263
debug@4.1.1
4.3.1
1
library/ghost:5.79.083f7bf209844
debug@4.1.1
4.3.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
debug@4.1.1
4.3.1
1
linuxserver/cloud9:latest45c5fe102ff3
debug@2.2.0
2.6.9
1
linuxserver/code-server:4.10.1a5e43a05ae79
debug@4.1.1
4.3.1
1
linuxserver/codimd:latestb801bbcf6386
debug@4.1.1
4.3.1
1
logentries/docker-logentries:0.2.1f1f90a236998
debug@2.6.0
2.6.9
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
debug@4.1.1
4.3.1
1
lsstsqre/sciplat-hub:latest5e0ade6bed1c
debug@2.2.0
2.6.9
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
debug@4.2.0
4.3.1
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
debug@0.8.1
2.6.9
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
debug@2.6.7
2.6.9
1
minddocdev/hubot:0.1.96c60b11a4fa7
debug@1.0.5
2.6.9
1
misskey/misskey:12.110.1e08b7c478093
debug@4.1.1
4.3.1
1
mozilla/sentencecollector:2.0.91da6ff5c4895
debug@4.1.1
4.3.1
1
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
debug@2.2.0
2.6.9
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
debug@4.1.1
4.3.1
1
nodered/node-red-docker:0.19.6-v8070643219ea2
debug@3.2.6
3.2.7
1
ondrejsika/parking:latestb1fd497416c8
debug@4.1.1
4.3.1
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
debug@4.1.1
4.3.1
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
debug@4.1.1
4.3.1
1
openthread/otbr:latestf307f59f6432
debug@2.2.0
2.6.9
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
debug@3.2.6
3.2.7
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
debug@2.2.0
2.6.9
1
pachyderm/grpc-proxy:0.4.92b27f41d4d02
debug@3.2.6
3.2.7
1
phntom/codimd:2.4.31b9aafbb62e6
debug@4.1.1
4.3.1
1
polonel/trudesk:1.2.60cf6513f6fe3
debug@4.1.1
4.3.1
1
rakii8585/angular-node-webapp:latest026082a515ac
debug@3.2.6
3.2.7
1
requarks/wiki:canary-2.5.2438b5865a7386c
debug@4.1.1
4.3.1
1
roadiehq/community-backstage-image:latestef355bf5b639
debug@3.2.6
3.2.7
1
samajh/alprbackend:latestea742b4372ad
debug@4.1.1
4.3.1
1
shieldsio/shields:nextfa194b446e42
debug@4.1.1
4.3.1
1
shinobisystems/shinobi:dev3ca746937856
debug@4.1.1
4.3.1
1
shinobisystems/shinobi:latestc2f5ce2e1067
debug@4.1.1
4.3.1
1
slagattollas/weatherservice-practica:latest68e7f56393fc
debug@3.2.6
3.2.7
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
debug@2.6.1
2.6.9
1
socialmediamacroscope/smile_server:0.3.31a528c794270
debug@3.2.6
3.2.7
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
debug@4.1.1
4.3.1
1
temporalio/web:1.14.033cfa863d8ce
debug@3.2.6
3.2.7
1
testhubio/testhub-frontend:on-preme86c2db53be8
debug@3.2.6
3.2.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.