StackRadar

CVE-2023-26248

Medium

Advisory

Published 25 Oct 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
31
of 17,781 indexed, latest versions
Container images
28
deployed by those charts
Fix available
None
affected package

Content Censorship in the InterPlanetary File System (IPFS) via Kademlia DHT abuse

Carried by container images the latest versions of 31 of 17,781 indexed charts deploy, on 28 images.

Affected packageAffected versionsFixed inImages
github.com/libp2p/go-libp2p-kad-dhtgolangv0.11.1, v0.15.0, v0.16.0, v0.18.0+15 moreno fix listed28
OSV records
GHSA-mqr9-hjr8-2m9wGO-2024-3218

Charts affected

31 by stars
ChartLatestAffected imagesRadar Score
rancherrancher-stable2.15.11 of 2See more

rancher rancher-stable 2.15.1

1 of the 2 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/libp2p/go-libp2p-kad-dht@v0.40.0
no fix listed

Open the chart page →

1,456
rancherrancher-latest2.15.11 of 2See more

rancher rancher-latest 2.15.1

1 of the 2 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/libp2p/go-libp2p-kad-dht@v0.40.0
no fix listed

Open the chart page →

1,456
spegelspegelVerified publisher0.7.41 of 1See more

spegel spegel 0.7.4

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ghcr.io/spegel-org/spegeldigest-pinned26c60b05e08a
github.com/libp2p/go-libp2p-kad-dht@v0.41.0
no fix listed

Open the chart page →

176
local-ailocalai3.4.21 of 1See more

local-ai localai 3.4.2

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/libp2p/go-libp2p-kad-dht@v0.40.0
no fix listed

Open the chart page →

3,997
ipfs-clusterparadeum-teamVerified publisher0.0.192 of 2See more

ipfs-cluster paradeum-team 0.0.19

2 of the 2 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.13.117259397f587
github.com/libp2p/go-libp2p-kad-dht@v0.16.0
no fix listed
ipfs/ipfs-cluster:1.0.21511f6d57994
github.com/libp2p/go-libp2p-kad-dht@v0.16.0
no fix listed

Open the chart page →

3,757
aramid-indexerbiatec-repoVerified publisher3.9.01 of 5See more

aramid-indexer biatec-repo 3.9.0

1 of the 5 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
github.com/libp2p/go-libp2p-kad-dht@v0.28.0
no fix listed

Open the chart page →

13,357
aramid-participationbiatec-repoVerified publisher4.4.11 of 1See more

aramid-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
github.com/libp2p/go-libp2p-kad-dht@v0.28.0
no fix listed

Open the chart page →

7,190
aramid-relaybiatec-repoVerified publisher4.4.11 of 1See more

aramid-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
github.com/libp2p/go-libp2p-kad-dht@v0.28.0
no fix listed

Open the chart page →

5,059
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
github.com/libp2p/go-libp2p-kad-dht@v0.28.0
no fix listed

Open the chart page →

7,190
celestia-nodecelestia-node0.1.71 of 1See more

celestia-node celestia-node 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
github.com/libp2p/go-libp2p-kad-dht@v0.26.1
no fix listed

Open the chart page →

1,799
spectrechronicleVerified publisher0.3.81 of 1See more

spectre chronicle 0.3.8

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
github.com/libp2p/go-libp2p-kad-dht@v0.29.0
no fix listed

Open the chart page →

1,515
validatorchronicleVerified publisher0.8.01 of 1See more

validator chronicle 0.8.0

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/ghost:0.78.5951d71162065
github.com/libp2p/go-libp2p-kad-dht@v0.37.1
no fix listed

Open the chart page →

475
ipfs-clusterethereum-helm-chartsVerified publisher0.1.142 of 3See more

ipfs-cluster ethereum-helm-charts 0.1.14

2 of the 3 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ipfs/ipfs-cluster:latesta83266c524f1
github.com/libp2p/go-libp2p-kad-dht@v0.39.2
no fix listed
ipfs/kubo:latest63f5502f7a01
github.com/libp2p/go-libp2p-kad-dht@v0.42.1
no fix listed

Open the chart page →

4,614
mcpmcp-chartsVerified publisher0.0.231 of 7See more

mcp mcp-charts 0.0.23

1 of the 7 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
github.com/libp2p/go-libp2p-kad-dht@v0.35.1
no fix listed

Open the chart page →

6,929
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ipfs/kubo:v0.24.0e3de33bd746b
github.com/libp2p/go-libp2p-kad-dht@v0.24.4
no fix listed

Open the chart page →

4,661
celestia-localastria9.0.01 of 2See more

celestia-local astria 9.0.0

1 of the 2 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
github.com/libp2p/go-libp2p-kad-dht@v0.34.0
no fix listed

Open the chart page →

3,281
celestia-nodeastria0.7.11 of 1See more

celestia-node astria 0.7.1

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
github.com/libp2p/go-libp2p-kad-dht@v0.34.0
no fix listed

Open the chart page →

1,502
graph-nodeastria0.2.21 of 3See more

graph-node astria 0.2.2

1 of the 3 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ipfs/kubo:v0.17.0803fac58ba15
github.com/libp2p/go-libp2p-kad-dht@v0.18.0
no fix listed

Open the chart page →

5,495
algorand-participationbiatec-repoVerified publisher4.4.11 of 1See more

algorand-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
github.com/libp2p/go-libp2p-kad-dht@v0.28.0
no fix listed

Open the chart page →

7,190
algorand-relaybiatec-repoVerified publisher4.4.11 of 1See more

algorand-relay biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
github.com/libp2p/go-libp2p-kad-dht@v0.28.0
no fix listed

Open the chart page →

5,059
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
github.com/libp2p/go-libp2p-kad-dht@v0.15.0
no fix listed

Open the chart page →

7,956
ranchercarbide-charts2.15.11 of 2See more

rancher carbide-charts 2.15.1

1 of the 2 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/libp2p/go-libp2p-kad-dht@v0.40.0
no fix listed

Open the chart page →

1,456
spirechronicleVerified publisher0.3.61 of 1See more

spire chronicle 0.3.6

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
github.com/libp2p/go-libp2p-kad-dht@v0.29.0
no fix listed

Open the chart page →

1,515
csi-driver-ipfscsi-driver-ipfs0.2.01 of 6See more

csi-driver-ipfs csi-driver-ipfs 0.2.0

1 of the 6 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ghcr.io/ptrvsrg/csi-driver-ipfs:latest97d2d9ccd7a5
github.com/libp2p/go-libp2p-kad-dht@v0.40.0
no fix listed

Open the chart page →

3,629
ipfs-clustercsi-driver-ipfs0.2.02 of 2See more

ipfs-cluster csi-driver-ipfs 0.2.0

2 of the 2 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ipfs/ipfs-cluster:v1.1.6a83266c524f1
github.com/libp2p/go-libp2p-kad-dht@v0.39.2
no fix listed
ipfs/kubo:v0.41.00661819c2e09
github.com/libp2p/go-libp2p-kad-dht@v0.39.1
no fix listed

Open the chart page →

1,475
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
github.com/libp2p/go-libp2p-kad-dht@v0.11.1
no fix listed

Open the chart page →

4,455
edgemeshkubesphere-stable0.1.01 of 2See more

edgemesh kubesphere-stable 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
kubeedge/edgemesh-agent:latest460c6061b608
github.com/libp2p/go-libp2p-kad-dht@v0.21.0
no fix listed

Open the chart page →

4,096
ipfsstakewise2.2.01 of 2See more

ipfs stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
github.com/libp2p/go-libp2p-kad-dht@v0.28.2
no fix listed

Open the chart page →

1,239
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/libp2p/go-libp2p-kad-dht@v0.25.2
no fix listed

Open the chart page →

6,779
v3-backendstakewise3.6.01 of 5See more

v3-backend stakewise 3.6.0

1 of the 5 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
ipfs/kubo:v0.33.21a30f5ed8579
github.com/libp2p/go-libp2p-kad-dht@v0.28.2
no fix listed

Open the chart page →

1,239
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2023-26248.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/libp2p/go-libp2p-kad-dht@v0.40.0
no fix listed

Open the chart page →

1,456

Container images carrying it

28 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
rancher/rancher:v2.15.15f6c4dc52a05
github.com/libp2p/go-libp2p-kad-dht@v0.40.0
no fix listed
4
ipfs/ipfs-cluster:latest:v1.1.6a83266c524f1
github.com/libp2p/go-libp2p-kad-dht@v0.39.2
no fix listed
2
ipfs/kubo:v0.33.21a30f5ed8579
github.com/libp2p/go-libp2p-kad-dht@v0.28.2
no fix listed
2
ghcr.io/celestiaorg/celestia-node:v0.27.5-mocha4768ea1c5fd2
github.com/libp2p/go-libp2p-kad-dht@v0.34.0
no fix listed
2
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
github.com/libp2p/go-libp2p-kad-dht@v0.15.0
no fix listed
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/libp2p/go-libp2p-kad-dht@v0.25.2
no fix listed
1
ipfs/go-ipfs:v0.13.117259397f587
github.com/libp2p/go-libp2p-kad-dht@v0.16.0
no fix listed
1
ipfs/ipfs-cluster:1.0.21511f6d57994
github.com/libp2p/go-libp2p-kad-dht@v0.16.0
no fix listed
1
ipfs/kubo:v0.41.00661819c2e09
github.com/libp2p/go-libp2p-kad-dht@v0.39.1
no fix listed
1
ipfs/kubo:latest63f5502f7a01
github.com/libp2p/go-libp2p-kad-dht@v0.42.1
no fix listed
1
ipfs/kubo:v0.17.0803fac58ba15
github.com/libp2p/go-libp2p-kad-dht@v0.18.0
no fix listed
1
ipfs/kubo:v0.24.0e3de33bd746b
github.com/libp2p/go-libp2p-kad-dht@v0.24.4
no fix listed
1
kubeedge/edgemesh-agent:latest460c6061b608
github.com/libp2p/go-libp2p-kad-dht@v0.21.0
no fix listed
1
scholtz2/algorand-participation-aramidmain-extended:4.4.1-stablef12ce1cfb72e
github.com/libp2p/go-libp2p-kad-dht@v0.28.0
no fix listed
1
scholtz2/algorand-participation-mainnet-extended:4.4.1-stable5aaa5d4ab8b8
github.com/libp2p/go-libp2p-kad-dht@v0.28.0
no fix listed
1
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
github.com/libp2p/go-libp2p-kad-dht@v0.28.0
no fix listed
1
scholtz2/algorand-relay-mainnet:4.4.1-stablee9af7d8ff6bb
github.com/libp2p/go-libp2p-kad-dht@v0.28.0
no fix listed
1
scholtz2/aramid-algo-follow-node:v4.3.0-stable1ec63eca86b6
github.com/libp2p/go-libp2p-kad-dht@v0.28.0
no fix listed
1
scholtz2/aramid-algo-node:v4.4.1-stable70263d8fab5b
github.com/libp2p/go-libp2p-kad-dht@v0.28.0
no fix listed
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
github.com/libp2p/go-libp2p-kad-dht@v0.11.1
no fix listed
1
ghcr.io/celestiaorg/celestia-node:v0.16.041177982c584
github.com/libp2p/go-libp2p-kad-dht@v0.26.1
no fix listed
1
ghcr.io/chronicleprotocol/ghost:0.78.5951d71162065
github.com/libp2p/go-libp2p-kad-dht@v0.37.1
no fix listed
1
ghcr.io/chronicleprotocol/spectre:0.68.34e872bc016e8
github.com/libp2p/go-libp2p-kad-dht@v0.29.0
no fix listed
1
ghcr.io/chronicleprotocol/spire:0.68.379df4fb20322
github.com/libp2p/go-libp2p-kad-dht@v0.29.0
no fix listed
1
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
github.com/libp2p/go-libp2p-kad-dht@v0.35.1
no fix listed
1
ghcr.io/ptrvsrg/csi-driver-ipfs:latest97d2d9ccd7a5
github.com/libp2p/go-libp2p-kad-dht@v0.40.0
no fix listed
1
ghcr.io/spegel-org/spegel26c60b05e08a
github.com/libp2p/go-libp2p-kad-dht@v0.41.0
no fix listed
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/libp2p/go-libp2p-kad-dht@v0.40.0
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.