StackRadar

CVE-2017-16137

Low

Advisory

Published 9 Aug 2018In the index since 6 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.028
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
139
of 17,781 indexed, latest versions
Container images
130
deployed by those charts
Fix available
1 of 1
affected package

Regular Expression Denial of Service in debug

Carried by container images the latest versions of 139 of 17,781 indexed charts deploy, on 130 images.

Affected packageAffected versionsFixed inImages
debugnpm0.7.2, 0.7.4, 0.8.1, 1.0.5+8 more2.6.9, 3.2.7, 4.3.1130
OSV records
GHSA-gxpj-cx7g-858c

Charts affected

139 by stars
ChartLatestAffected imagesRadar Score
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
oscarsotosanchez/weatherservice:v1.0911ec961d10b
debug@3.2.6
3.2.7

Open the chart page →

27,550
mergeabledoubanVerified publisher0.2.21 of 1See more

mergeable douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ghcr.io/leoquote/mergeable:latest451706815103
debug@4.1.1
4.3.1

Open the chart page →

4,223
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
oscarsotosanchez/weatherservice:v1.0911ec961d10b
debug@3.2.6
3.2.7

Open the chart page →

24,656
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
debug@4.1.1
4.3.1

Open the chart page →

11,174
eolicplantseolicplantsVerified publisher0.1.01 of 7See more

eolicplants eolicplants 0.1.0

1 of the 7 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
oscarsotosanchez/weatherservice:v1.0911ec961d10b
debug@3.2.6
3.2.7

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.01 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

1 of the 7 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
oscarsotosanchez/weatherservice:v1.0911ec961d10b
debug@3.2.6
3.2.7

Open the chart page →

27,256
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
debug@3.2.6
3.2.7

Open the chart page →

3,260
exposrexposr0.12.01 of 1See more

exposr exposr 0.12.0

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ghcr.io/exposr/exposrd:v0.12.0561c8f23bdb6
debug@4.1.1
4.3.1

Open the chart page →

570
logentriesfairwinds-incubator0.2.21 of 1See more

logentries fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
logentries/docker-logentries:0.2.1f1f90a236998
debug@2.6.0
2.6.9

Open the chart page →

1,597
iotagent-ulfiware0.1.21 of 1See more

iotagent-ul fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
fiware/iotagent-ul:1.14.0fe11f55a926d
debug@4.1.1
4.3.1

Open the chart page →

3,337
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
debug@2.2.0
2.6.9

Open the chart page →

5,941
flaresolverrgeek-cookbookVerified publisher5.4.21 of 1See more

flaresolverr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v1.2.896f8c08c0c1b
debug@4.2.0
4.3.1

Open the chart page →

1,870
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
debug@4.1.1
4.3.1

Open the chart page →

10,994
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
debug@4.1.1
4.3.1

Open the chart page →

4,043
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
debug@4.1.1
4.3.1

Open the chart page →

4,591
theloungegeek-cookbookVerified publisher3.4.21 of 1See more

thelounge geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
thelounge/thelounge:4.2.0-alpine639978459c3a
debug@3.2.6
3.2.7

Open the chart page →

2,689
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
debug@4.1.1
4.3.1

Open the chart page →

9,019
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
debug@0.8.1
2.6.9

Open the chart page →

22,512
Governify-Falcongovernify0.1.02 of 10See more

Governify-Falcon governify 0.1.0

2 of the 10 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
debug@0.8.1
2.6.9
governify/collector-dynamic:v1.3.06d3d1a5b46a9
debug@3.2.6
3.2.7

Open the chart page →

24,319
gitter-irc-bridgehalkeye0.1.11 of 1See more

gitter-irc-bridge halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
debug@0.8.1
2.6.9

Open the chart page →

3,642
hubothalkeye0.0.11 of 1See more

hubot halkeye 0.0.1

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
halkeye/hubot:latest9764d2202130
debug@4.1.1
4.3.1

Open the chart page →

2,116
irslackdhalkeye0.1.01 of 1See more

irslackd halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
halkeye/irslackd:latest7638bfba70b0
debug@4.1.1
4.3.1

Open the chart page →

2,064
matrix-appservice-gitterhalkeye0.1.01 of 1See more

matrix-appservice-gitter halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
debug@0.8.1
2.6.9

Open the chart page →

3,003
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
debug@4.1.1
4.3.1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
debug@3.2.6
3.2.7
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
debug@3.2.6
3.2.7
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
debug@3.2.6
3.2.7

Open the chart page →

89,959
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
debug@4.1.1
4.3.1

Open the chart page →

8,213
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
debug@4.1.1
4.3.1

Open the chart page →

4,253
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ibmcom/app-nav-init:1.0.1240ff499eb5b
debug@2.2.0
2.6.9
ibmcom/app-nav-ui:1.0.1e2a86997b36b
debug@3.2.6
3.2.7

Open the chart page →

32,915
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
debug@0.7.4
2.6.9

Open the chart page →

57,669
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
debug@3.2.6
3.2.7

Open the chart page →

4,505
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
frappe/frappe-socketio:v13.4.12095767a9e82
debug@4.1.1
4.3.1

Open the chart page →

6,501
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
debug@3.2.6
3.2.7

Open the chart page →

4,944
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
debug@4.1.1
4.3.1

Open the chart page →

10,494
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
debug@3.2.6
3.2.7

Open the chart page →

7,232
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
debug@0.7.4
2.6.9

Open the chart page →

4,614
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
debug@2.2.0
2.6.9

Open the chart page →

6,454
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
debug@4.1.1
4.3.1

Open the chart page →

4,667
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
debug@4.1.1
4.3.1

Open the chart page →

9,783
statsdkeyporttech0.1.191 of 1See more

statsd keyporttech 0.1.19

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
statsd/statsd:v0.8.6dab129e74c25
debug@4.1.1
4.3.1

Open the chart page →

4,185
nubladolsst-sqre0.9.231 of 5See more

nublado lsst-sqre 0.9.23

1 of the 5 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
lsstsqre/sciplat-hub:latest5e0ade6bed1c
debug@2.2.0
2.6.9

Open the chart page →

5,786
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
debug@4.1.1
4.3.1

Open the chart page →

17,779
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
debug@4.1.1
4.3.1

Open the chart page →

7,929
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
debug@4.1.1
4.3.1

Open the chart page →

3,651
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
debug@4.1.1
4.3.1

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
debug@4.1.1
4.3.1

Open the chart page →

10,603
iotmmontesVerified publisher0.3.22 of 7See more

iot mmontes 0.3.2

2 of the 7 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
debug@4.1.1
4.3.1
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
debug@4.1.1
4.3.1

Open the chart page →

10,608
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
debug@3.2.6
3.2.7

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
debug@3.2.6
3.2.7

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
debug@3.2.6
3.2.7

Open the chart page →

12,108
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
debug@0.7.2
2.6.9

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2017-16137.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
debug@3.2.6
3.2.7
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
debug@3.2.6
3.2.7

Open the chart page →

11,479

Container images carrying it

130 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
debug@3.2.6
3.2.7
5
kodekloud/examplevotingapp_result:v1e510023fdf38
debug@4.1.1
4.3.1
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
debug@3.2.6
3.2.7
4
pantsel/konga:latestc8172b75607d
debug@2.2.0
2.6.9
3
agoldis/sorry-cypress-director:2.5.1110228ecd353b
debug@4.2.0
4.3.1
2
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
debug@4.1.1
4.3.1
2
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
debug@3.2.6
3.2.7
2
governify/assets-manager:v1.4.12987672448c7
debug@0.8.1
2.6.9
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
debug@4.1.1
4.3.1
2
migmartri/prerender:latest486aacfd5aa9
debug@0.7.4
2.6.9
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
debug@3.2.6
3.2.7
2
mojaloop/reporting:v12.1.0d480a62103d6
debug@0.7.2
2.6.9
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
debug@4.1.1
4.3.1
2
requarks/wiki:2:latest68f0d1848261
debug@4.1.1
4.3.1
2
statsd/statsd:v0.8.6dab129e74c25
debug@4.1.1
4.3.1
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
debug@4.1.1
4.3.1
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
debug@4.1.1
4.3.1
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
debug@4.1.1
4.3.1
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
debug@4.1.1
4.3.1
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
debug@4.1.1
4.3.1
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
debug@4.1.1
4.3.1
1
catalysm/csmm:latestf003b35f54d9
debug@4.1.1
4.3.1
1
cnieg/maildev:v1.1.998ee05668915
debug@4.1.1
4.3.1
1
codercom/code-server:4.11.0-debian1e2cc688008e
debug@4.1.1
4.3.1
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
debug@4.1.1
4.3.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
debug@3.2.6
3.2.7
1
datarhei/restreamer:0.6.4655e12f9eeed
debug@4.1.1
4.3.1
1
davidvmar/urjc-davidvmar-external-service:1.0.02a68e9ac7f09
debug@3.2.6
3.2.7
1
decayofmind/hubot:3.3.21e18e92fe694
debug@3.2.6
3.2.7
1
devkrishan001/backend:latestf1c3acadeabe
debug@0.7.4
2.6.9
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
debug@0.7.4
2.6.9
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
debug@3.2.6
3.2.7
1
ethersphere/bzz-token-service:latest7624f11a72ad
debug@3.2.6
3.2.7
1
fiware/iotagent-ul:1.14.0fe11f55a926d
debug@4.1.1
4.3.1
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
debug@4.1.1
4.3.1
1
frappe/frappe-socketio:v13.4.12095767a9e82
debug@4.1.1
4.3.1
1
getferdi/ferdi-server:1.3.26e620b85afaa
debug@4.1.1
4.3.1
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
debug@3.2.6
3.2.7
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
debug@4.1.1
4.3.1
1
gristlabs/grist:0.7.96e71b1914a7e
debug@3.2.6
3.2.7
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
debug@0.8.1
2.6.9
1
halkeye/hubot:latest9764d2202130
debug@4.1.1
4.3.1
1
halkeye/irslackd:latest7638bfba70b0
debug@4.1.1
4.3.1
1
hansehe/graphql-gateway:1.0.458e09540afbc
debug@4.2.0
4.3.1
1
henrywhitaker3/speedtest-tracker:latest47159a940229
debug@3.2.6
3.2.7
1
ianw/quickchart:v1.7.1dc49dd460c37
debug@3.2.6
3.2.7
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
debug@2.2.0
2.6.9
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
debug@3.2.6
3.2.7
1
ibmcom/microclimate-portal:latested5505e5c7ec
debug@0.7.4
2.6.9
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
debug@3.2.6
3.2.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.