StackRadar

CVE-2023-23638

Critical

Advisory

Published 8 Mar 2023In the index since 9 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.048
92nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4
of 17,781 indexed, latest versions
Container images
2
deployed by those charts
Fix available
1 of 1
affected package

Apache Dubbo vulnerable to Deserialization of Untrusted Data

Carried by container images the latest versions of 4 of 17,781 indexed charts deploy, on 2 images.

Affected packageAffected versionsFixed inImages
dubbomaven2.7.8, 3.1.12.7.22, 3.1.52
OSV records
GHSA-933g-v89r-x8pf

Charts affected

4 by stars
ChartLatestAffected imagesRadar Score
shenyuerdeng2.4.211 of 2See more

shenyu erdeng 2.4.21

1 of the 2 container images this version deploys carry CVE-2023-23638.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
dubbo@2.7.8
2.7.22

Open the chart page →

12,513
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2023-23638.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
dubbo@3.1.1
3.1.5

Open the chart page →

8,804
shenyushenyu-helm-chart-test2.4.271 of 2See more

shenyu shenyu-helm-chart-test 2.4.27

1 of the 2 container images this version deploys carry CVE-2023-23638.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
dubbo@2.7.8
2.7.22

Open the chart page →

12,513
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2023-23638.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
dubbo@2.7.8
2.7.22

Open the chart page →

12,513

Container images carrying it

2 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
dubbo@2.7.8
2.7.22
3
apache/shenyu-bootstrap:2.5.11bd5756f6273
dubbo@3.1.1
3.1.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.