StackRadar

CVE-2023-1999

High

Advisory

Published 8 May 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.010
59th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
367
of 17,781 indexed, latest versions
Container images
324
deployed by those charts
Fix available
3 of 4
affected packages

Red Hat Security Advisory: libwebp security update

Carried by container images the latest versions of 367 of 17,781 indexed charts deploy, on 324 images.

Affected packageAffected versionsFixed inImages
libwebpapk1.2.2-r0, 1.2.3-r0, 1.2.4-r11.2.2-r1, 1.2.3-r1, 1.2.4-r254
libwebprpm1.0.0-1.el8, 1.0.0-3.el8_40:1.0.0-7.el8_2, 0:1.0.0-8.el8_72
libwebpdeb0.4.4-1, 0.6.1-2, 0.6.1-2.1, 0.6.1-2+deb10u1+3 more0.4.4-1ubuntu0.1~esm2, 0.6.1-2.1+deb11u1, 0.6.1-2+deb10u2, 0.6.1-2ubuntu0.18.04.2+2 more267
mozjs68deb68.6.0-1ubuntu1no fix listed1
OSV records
ALPINE-CVE-2023-1999RHSA-2023:2072RHSA-2023:2076UBUNTU-CVE-2023-1999DLA-3439-1DSA-5408-1
Also known as
RHSA-2023:2084, USN-6078-1, USN-6078-2

Charts affected

367 by stars
ChartLatestAffected imagesRadar Score
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-nginx:latest4473ce50435e
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-nginx:latestf449b82ce9d6
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-nginx:lateste0c5f8a95098
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-nginx:latest42c75ea8082c
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2

Open the chart page →

7,429
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2

Open the chart page →

3,129
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1

Open the chart page →

3,392
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1

Open the chart page →

2,132
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
libwebp@1.2.2-r0
1.2.2-r1

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
libwebp@1.2.2-r0
1.2.2-r1

Open the chart page →

1,523
weather-chartweather-web-app0.1.01 of 1See more

weather-chart weather-web-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
zohardocker12/weather_app_flask:latestb86d60dbb68d
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2

Open the chart page →

2,670
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1

Open the chart page →

7,552
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1

Open the chart page →

2,021
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libwebp@1.2.2-r0
1.2.2-r1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
libwebp@1.2.2-r0
1.2.2-r1

Open the chart page →

16,083
myfirstchartww-helm-charts-repo0.1.01 of 1See more

myfirstchart ww-helm-charts-repo 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginx:0.1.0205961b09a80
libwebp@0.6.1-2
0.6.1-2+deb10u2

Open the chart page →

1,138
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1

Open the chart page →

1,838
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-1999.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
libwebp@0.6.1-2
0.6.1-2+deb10u2

Open the chart page →

1,138

Container images carrying it

324 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
helga09/shoes_ukr:v1.1.17999bc8b77c0
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
hiboxsystems/marge-bot:0.11.07235809b43b3
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
libwebp@0.6.1-2
0.6.1-2ubuntu0.18.04.2
1
ianw/quickchart:v1.7.1dc49dd460c37
libwebp@1.2.2-r0
1.2.2-r1
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.2
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.2
1
jellyfin/jellyfin:10.8.1ee24f4459a40
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
julb/http-url-playlist:1.0.2782ef45279d5
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
kobotoolbox/kobocat:2.022.24ab15679454415
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
kubebb/hello-world:0.1.0b746824819f3
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
kubeshop/kusk-gateway-dashboard:v1.2.6ff9b5aa1258d
libwebp@1.2.3-r0
1.2.3-r1
1
ldapaccountmanager/lam:7.295533a96a4c1
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
library/monica:3.7.0-apacheceb1ba4196ab
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
library/nextcloud:17.0.0-apache96104cb965fc
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
library/nginx:1.23.03536d368b898
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
library/nginx:1.23.2-alpine455c39afebd4
libwebp@1.2.3-r0
1.2.3-r1
1
library/nginx:1.19.68e1095642250
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
library/nginx:1.23.2ab589a3c466e
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
library/nginx:1.17.6b2d89d0a2103
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
library/nginx:1.16.1d20aa6d1cae5
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
library/nginx:1.23.3f4e3b6489888
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
library/wordpress:6.0.0-php8.0-apache277c6c25980f
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
librenms/librenms:22.4.14f1f3d667cc7
libwebp@1.2.2-r0
1.2.2-r1
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
libwebp@0.6.1-2ubuntu0.18.04.1
0.6.1-2ubuntu0.18.04.2
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.2
1
linuxserver/deluge:18.04.10ac871624394
libwebp@0.6.1-2ubuntu0.18.04.1
0.6.1-2ubuntu0.18.04.2
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
libwebp@0.6.1-2ubuntu0.18.04.1
0.6.1-2ubuntu0.18.04.2
1
linuxserver/jellyfin:10.7.72427dde159a2
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.2
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
lsstdm/alert-stream-simulator:v1.2.1973df082d006
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2
1
lsstdm/lsst_alert_packet:tickets-DM-3274374c97a490940
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2
1
lsstsqre/kafkaaggregator:masterbe1b21060854
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
lsstsqre/squash-api:0.5.34879415ec6ac
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
maissacrement/pock8snodejs:0.0.16da0db1159da
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
matrixdotorg/synapse:v1.78.0def97fd537d8
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
mediagis/nominatim:3.7c15e941485ef
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.2
1
mintproject/data-catalog-db:9be70359feabe03ed55bfdbf92c20a7e43ab928b9bf26fedd848
libwebp@1.2.3-r0
1.2.3-r1
1
mintproject/mint-ui-lit:246a8771e8c043f8c1840d3c32262d3d6a9a553208c1a13c3397
libwebp@1.2.3-r0
1.2.3-r1
1
mintproject/model-catalog-explorer:0b2f9f0a9124076aeb492add2f123d0757066f6bdeb80c93b4a9
libwebp@1.2.3-r0
1.2.3-r1
1
misskey/misskey:12.110.1e08b7c478093
libwebp@1.2.2-r0
1.2.2-r1
1
mnaggar3396/python-app:latest371d8ed84b15
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u2
1
moreillon/mqtt-logger-front:50030b8bfc4d12db1d3e
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1
mozilla/sentencecollector:2.0.91da6ff5c4895
libwebp@0.6.1-2
0.6.1-2+deb10u2
1
n8nio/n8n:0.212.0a9195bc499a3
libwebp@1.2.3-r0
1.2.3-r1
1
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.