StackRadar

CVE-2023-1999

High

Advisory

Published 8 May 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.010
59th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
367
of 17,781 indexed, latest versions
Container images
324
deployed by those charts
Fix available
3 of 4
affected packages

Red Hat Security Advisory: libwebp security update

Carried by container images the latest versions of 367 of 17,781 indexed charts deploy, on 324 images.

Affected packageAffected versionsFixed inImages
libwebpapk1.2.2-r0, 1.2.3-r0, 1.2.4-r11.2.2-r1, 1.2.3-r1, 1.2.4-r254
libwebprpm1.0.0-1.el8, 1.0.0-3.el8_40:1.0.0-7.el8_2, 0:1.0.0-8.el8_72
libwebpdeb0.4.4-1, 0.6.1-2, 0.6.1-2.1, 0.6.1-2+deb10u1+3 more0.4.4-1ubuntu0.1~esm2, 0.6.1-2.1+deb11u1, 0.6.1-2+deb10u2, 0.6.1-2ubuntu0.18.04.2+2 more267
mozjs68deb68.6.0-1ubuntu1no fix listed1
OSV records
ALPINE-CVE-2023-1999RHSA-2023:2072RHSA-2023:2076UBUNTU-CVE-2023-1999DLA-3439-1DSA-5408-1
Also known as
RHSA-2023:2084, USN-6078-1, USN-6078-2

Charts affected

367 by stars
ChartLatestAffected imagesRadar Score
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-nginx:latest4473ce50435e
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-nginx:latestf449b82ce9d6
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-nginx:lateste0c5f8a95098
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-nginx:latest42c75ea8082c
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2

Open the chart page →

7,429
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2

Open the chart page →

3,129
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1

Open the chart page →

3,392
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1

Open the chart page →

2,132
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
libwebp@1.2.2-r0
1.2.2-r1

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
libwebp@1.2.2-r0
1.2.2-r1

Open the chart page →

1,523
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2

Open the chart page →

2,670
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1

Open the chart page →

7,552
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libwebp@1.2.2-r0
1.2.2-r1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
libwebp@1.2.2-r0
1.2.2-r1

Open the chart page →

16,083
myfirstchartww-helm-charts-repo0.1.01 of 1See more

myfirstchart ww-helm-charts-repo 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginx:0.1.0205961b09a80
libwebp@0.6.1-2
0.6.1-2+deb10u2

Open the chart page →

1,138
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1

Open the chart page →

1,838
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
libwebp@0.6.1-2
0.6.1-2+deb10u2

Open the chart page →

1,138

Container images carrying it

324 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
assistiot/tacticle_dashboard:web-latest25fc9f373524
libwebp@1.2.3-r0
1.2.3-r1
1
azhar008/flaskapplication:latesta1e827b0adea
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.2
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.2
1
buntha/mlflow:2.1.1154542cc3083
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
camerahub/camerahub:0.36.23a5af37dd6e1b
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
camptocamp/bucket-cloner:latestacfafc308d88
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2
1
camptocamp/ekorre:0.1.035c91d5fda04
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
cdignam/kodiak:v0.54.05a6a55b39cee
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
ceticasbl/pg-ldap-sync:latest6c0aa7567145
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
chaosnative/cle-frontend:2.7.007b82a82a702
libwebp@1.2.2-r0
1.2.2-r1
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
libwebp@1.2.4-r1
1.2.4-r2
1
danuk/telegram-sender:0.0.1026560388070
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
daskdev/dask-notebook:1.1.0052630f5ca04
libwebp@0.6.1-2
0.6.1-2ubuntu0.18.04.2
1
deconzcommunity/deconz:2.12.066541bbb78952
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2
1
deluan/navidrome:0.49.311a24da08977
libwebp@1.2.4-r1
1.2.4-r2
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.2
1
digitalist/nginx:1.21.6eec27ad73eaa
libwebp@1.2.2-r0
1.2.2-r1
1
dnsforge/xteve:latest4d9a685c8c28
libwebp@1.2.4-r1
1.2.4-r2
1
douz/helpdesk:latest4384103d0219
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
douz/overlord:latestf2bc7fc068c1
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
duck1123/astral:latestf4d5b6526c2a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
libwebp@1.2.2-r0
1.2.2-r1
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libwebp@0.6.1-2ubuntu0.18.04.1
0.6.1-2ubuntu0.18.04.2
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libwebp@0.6.1-2ubuntu0.18.04.1
0.6.1-2ubuntu0.18.04.2
1
elyra/kernel-image-puller:3.2.2c922f1f1646a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
erlangsolutions/wombatoam:4.1.284680c990147a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
esailors/aws-ecr-http-proxy:1.5.15608ae045fa7
libwebp@1.2.2-r0
1.2.2-r1
1
esphome/esphome:1.18.03f51ec10e823
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
evk02/mlflow:2.2.1ef6ff257ef35
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
fanzynoodle/smeejas:0.0.15f9916c1a287
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
felipecs8/qrcode-generator:v1d5f4f17cb066
libwebp@1.2.4-r1
1.2.4-r2
1
fireflyiii/core:version-5.6.142f4283bd0cf7
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
mozjs68@68.6.0-1ubuntu1
no fix listed
1
fluidtrendslab/platform:latestbf49de7a4100
libwebp@1.2.3-r0
1.2.3-r1
1
fossology/fossology:4.2.18bd1f22ba7bb
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2
1
gcarrarom/landing:0.0.0769d19e441d9
libwebp@1.2.3-r0
1.2.3-r1
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
libwebp@0.6.1-2
0.6.1-2ubuntu0.18.04.2
1
gethue/nginx:latest07f00f7c7903
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2
1
gollumorg/gollum:latest7cd5305a3cf7
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
gresearchdev/siembol-config-editor-ui:latest071e7109a981
libwebp@1.2.3-r0
1.2.3-r1
1
guacamole/guacd:1.1.02288530a4d1c
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
guacamole/guacd:1.3.049d43948140f
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
ha33ona/python:test6affdfc644d0
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
haveagitgat/tdarr:2.00.181256348872ce
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.2
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
libwebp@0.6.1-2
0.6.1-2ubuntu0.20.04.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.