StackRadar

CVE-2023-26044

Medium

Advisory

Published 17 May 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
6
of 17,781 indexed, latest versions
Container images
4
deployed by those charts
Fix available
1 of 1
affected package

ReactPHP's HTTP server continues parsing unused multipart parts after reaching input field and file upload limits

Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 4 images.

Affected packageAffected versionsFixed inImages
react/httpcomposerv1.2.0, v1.4.0, v1.5.01.9.04
OSV records
GHSA-95x4-j7vc-h8mf

Charts affected

6 by stars
ChartLatestAffected imagesRadar Score
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2023-26044.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
react/http@v1.5.0
1.9.0

Open the chart page →

7,052
repmanrepman-helmchartVerified publisher1.0.121 of 3See more

repman repman-helmchart 1.0.12

1 of the 3 container images this version deploys carry CVE-2023-26044.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
react/http@v1.5.0
1.9.0

Open the chart page →

3,596
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-26044.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
react/http@v1.4.0
1.9.0

Open the chart page →

20,933
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2023-26044.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
react/http@v1.2.0
1.9.0

Open the chart page →

9,077
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2023-26044.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
react/http@v1.5.0
1.9.0

Open the chart page →

3,993
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-26044.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
react/http@v1.5.0
1.9.0

Open the chart page →

2,534

Container images carrying it

4 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
buddy/repman:1.4.0097c897f8b54
react/http@v1.5.0
1.9.0
3
jordan/icinga2:latestf75025fe8ea8
react/http@v1.2.0
1.9.0
1
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
react/http@v1.5.0
1.9.0
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
react/http@v1.4.0
1.9.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.