StackRadar

CVE-2023-0996

High

Advisory

Published 24 Feb 2023In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.003
23rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
libheifdeb1.12.0-2build11.12.0-2ubuntu0.1~esm114
OSV records
UBUNTU-CVE-2023-0996
Also known as
USN-6847-1

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
owncloudkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

owncloud kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
owncloud/server:10.16.274c53d341076
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

9,858
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg16d7db8f1085a3
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

12,930
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

32,501
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

20,900
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

29,033
ownclouddjjudas21Verified publisher0.3.231 of 3See more

owncloud djjudas21 0.3.23

1 of the 3 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
owncloud/server:10.16.3b3f9efdcd7f7
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

10,035
codecovdoubanVerified publisher0.2.41 of 8See more

codecov douban 0.2.4

1 of the 8 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

24,917
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

30,699
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

19,503
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

14,290
penpotkubitodevVerified publisher1.2.12 of 5See more

penpot kubitodev 1.2.1

2 of the 5 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
penpotapp/backend:2.2.147853d9bb9dd
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
penpotapp/exporter:2.2.15c835ffd87ab
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

16,877
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

12,791
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

12,791
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2023-0996.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1

Open the chart page →

7,849

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/codingducksrl/laravel:8.15be52524664c
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
2
mediagis/nominatim:4.2d0eae7b51374
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
1
owncloud/server:10.16.274c53d341076
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
1
owncloud/server:10.16.3b3f9efdcd7f7
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
1
penpotapp/backend:2.2.147853d9bb9dd
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
1
penpotapp/exporter:2.2.15c835ffd87ab
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
1
photoprism/photoprism:220629-jammy2954334adbda
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
1
timescale/timescaledb-ha:pg16d7db8f1085a3
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
1
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
libheif@1.12.0-2build1
1.12.0-2ubuntu0.1~esm1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.