StackRadar

CVE-2023-27522

High

Advisory

Published 7 Mar 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.021
81st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
34
of 17,781 indexed, latest versions
Container images
34
deployed by those charts
Fix available
5 of 5
affected packages

Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting

Carried by container images the latest versions of 34 of 17,781 indexed charts deploy, on 34 images.

Affected packageAffected versionsFixed inImages
uwsgipypi2.0.15, 2.0.17.1, 2.0.18, 2.0.19+3 more2.0.2219
apache2deb2.4.41-4ubuntu3.11, 2.4.41-4ubuntu3.122.4.41-4ubuntu3.147
apache2apk2.4.53-r0, 2.4.54-r0, 2.4.54-r1, 2.4.55-r02.4.56-r05
httpdrpm2.4.37-43.module+el8.5.0+13806+b30d9eec.1, 2.4.37-56.module+el8.8.0+18758+b3a9c8da.60:2.4.37-56.module+el8.8.0+19808+379766d6.72
apachebitnami2.4.54-1572.4.561
OSV records
ALPINE-CVE-2023-27522BIT-apache-2023-27522GHSA-vcph-37mh-fqrhRHSA-2023:5050UBUNTU-CVE-2023-27522
Also known as
PYSEC-2026-1058, USN-5942-1

Charts affected

34 by stars
ChartLatestAffected imagesRadar Score
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14

Open the chart page →

18,509
phpipamstackhelmVerified publisher0.1.22 of 3See more

phpipam stackhelm 0.1.2

2 of the 3 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
phpipam/phpipam-cron:v1.5.2f770577cb946
apache2@2.4.55-r0
2.4.56-r0
phpipam/phpipam-www:v1.5.23c6fd1332aeb
apache2@2.4.55-r0
2.4.56-r0

Open the chart page →

1,874
alerta-webalerta-webVerified publisher0.1.121 of 2See more

alerta-web alerta-web 0.1.12

1 of the 2 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
hayk96/alerta-web:9.0.486377705e9e3
uwsgi@2.0.21
2.0.22

Open the chart page →

3,569
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
kobotoolbox/kobocat:2.022.24ab15679454415
uwsgi@2.0.20
2.0.22
kobotoolbox/kpi:2.022.24dbcacc01bccd4
uwsgi@2.0.20
2.0.22

Open the chart page →

18,517
open-zaakopen-zaak0.8.01 of 3See more

open-zaak open-zaak 0.8.0

1 of the 3 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
openzaak/open-zaak:1.6.02ca2ea6e0ae9
uwsgi@2.0.20
2.0.22

Open the chart page →

4,045
open-notificatiesopen-zaak0.7.01 of 4See more

open-notificaties open-zaak 0.7.0

1 of the 4 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
openzaak/open-notificaties:1.3.02e65313b9b10
uwsgi@2.0.20
2.0.22

Open the chart page →

2,850
alertasomeblackmagic0.2.31 of 2See more

alerta someblackmagic 0.2.3

1 of the 2 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
alerta/alerta-web:8.5.04786b9eaa606
uwsgi@2.0.19.1
2.0.22

Open the chart page →

3,162
healthchecksstackhelmVerified publisher0.1.01 of 2See more

healthchecks stackhelm 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
healthchecks/healthchecks:v2.8.1e82bb0836e30
uwsgi@2.0.21
2.0.22

Open the chart page →

2,236
phpipamvquieVerified publisher1.0.32 of 3See more

phpipam vquie 1.0.3

2 of the 3 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
phpipam/phpipam-cron:v1.5.2f770577cb946
apache2@2.4.55-r0
2.4.56-r0
phpipam/phpipam-www:v1.5.23c6fd1332aeb
apache2@2.4.55-r0
2.4.56-r0

Open the chart page →

7,025
aks-helloworldazure-sample0.1.11 of 1See more

aks-helloworld azure-sample 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
neilpeterson/aks-helloworld:v1fb47732ef36b
uwsgi@2.0.15
2.0.22

Open the chart page →

4,269
azure-voteazure-sample0.1.11 of 2See more

azure-vote azure-sample 0.1.1

1 of the 2 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
neilpeterson/azure-vote-front:v384062718347c
uwsgi@2.0.15
2.0.22

Open the chart page →

5,224
azure-vote-osbaazure-sample0.1.01 of 1See more

azure-vote-osba azure-sample 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
neilpeterson/azure-vote-front:v384062718347c
uwsgi@2.0.15
2.0.22

Open the chart page →

4,269
twitter-sentimentazure-sample0.1.01 of 3See more

twitter-sentiment azure-sample 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
neilpeterson/chart-tweet:latest64fd8dab075f
uwsgi@2.0.15
2.0.22

Open the chart page →

11,833
camerahubcamerahub0.10.211 of 2See more

camerahub camerahub 0.10.21

1 of the 2 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
camerahub/camerahub:0.36.23a5af37dd6e1b
uwsgi@2.0.21
2.0.22

Open the chart page →

2,507
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
httpd@2.4.37-56.module+el8.8.0+18758+b3a9c8da.6
0:2.4.37-56.module+el8.8.0+19808+379766d6.7

Open the chart page →

25,151
robot-shopcloud-native-toolkit1.1.11 of 12See more

robot-shop cloud-native-toolkit 1.1.1

1 of the 12 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
robotshop/rs-payment:latest774b52c6180d
uwsgi@2.0.19.1
2.0.22

Open the chart page →

29,555
galaxy-stablecloudve2.0.01 of 5See more

galaxy-stable cloudve 2.0.0

1 of the 5 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
galaxy/galaxy-init:v18.010267bad550e6
uwsgi@2.0.15
2.0.22

Open the chart page →

70,895
openldap-stack-haeclipse-aeriosVerified publisher4.1.21 of 4See more

openldap-stack-ha eclipse-aerios 4.1.2

1 of the 4 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
apache2@2.4.54-r0
2.4.56-r0

Open the chart page →

7,534
equizequiz0.0.11 of 3See more

equiz equiz 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.56

Open the chart page →

7,541
equizequiz-chart0.0.11 of 3See more

equiz equiz-chart 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.56

Open the chart page →

7,541
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.14

Open the chart page →

20,933
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14

Open the chart page →

14,659
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
apache2@2.4.53-r0
2.4.56-r0

Open the chart page →

8,392
rtorrent-rutorrentgeek-cookbookVerified publisher1.1.21 of 1See more

rtorrent-rutorrent geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
apache2@2.4.54-r1
2.4.56-r0

Open the chart page →

4,232
phppgadminkfirfer0.1.121 of 1See more

phppgadmin kfirfer 0.1.12

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14

Open the chart page →

10,248
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
lsstsqre/squash-api:0.5.34879415ec6ac
uwsgi@2.0.19.1
2.0.22

Open the chart page →

6,611
mtlsmtls0.3.41 of 1See more

mtls mtls 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
drgrove/mtls-server:v0.14.2361721759a2b
uwsgi@2.0.17.1
2.0.22

Open the chart page →

1,458
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14

Open the chart page →

22,658
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14

Open the chart page →

9,167
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
reportportal/service-auto-analyzer:5.7.295ada4a216ce
uwsgi@2.0.18
2.0.22
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
uwsgi@2.0.18
2.0.22

Open the chart page →

25,737
classificationsignalen4.24.01 of 1See more

classification signalen 4.24.0

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
uwsgi@2.0.19
2.0.22

Open the chart page →

1,553
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.14

Open the chart page →

30,687
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
httpd@2.4.37-43.module+el8.5.0+13806+b30d9eec.1
0:2.4.37-56.module+el8.8.0+19808+379766d6.7

Open the chart page →

6,671
datapusherstatcan1.0.01 of 1See more

datapusher statcan 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-27522.

Container imageDigestPackageFixed in
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
uwsgi@2.0.19.1
2.0.22

Open the chart page →

3,044

Container images carrying it

34 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
neilpeterson/azure-vote-front:v384062718347c
uwsgi@2.0.15
2.0.22
2
phpipam/phpipam-cron:v1.5.2f770577cb946
apache2@2.4.55-r0
2.4.56-r0
2
phpipam/phpipam-www:v1.5.23c6fd1332aeb
apache2@2.4.55-r0
2.4.56-r0
2
yzhou442/equiz:latesta3f7ca69e28d
apache@2.4.54-157
2.4.56
2
alerta/alerta-web:8.5.04786b9eaa606
uwsgi@2.0.19.1
2.0.22
1
camerahub/camerahub:0.36.23a5af37dd6e1b
uwsgi@2.0.21
2.0.22
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
apache2@2.4.54-r1
2.4.56-r0
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14
1
drgrove/mtls-server:v0.14.2361721759a2b
uwsgi@2.0.17.1
2.0.22
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
apache2@2.4.54-r0
2.4.56-r0
1
galaxy/galaxy-init:v18.010267bad550e6
uwsgi@2.0.15
2.0.22
1
hayk96/alerta-web:9.0.486377705e9e3
uwsgi@2.0.21
2.0.22
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
uwsgi@2.0.21
2.0.22
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
uwsgi@2.0.19.1
2.0.22
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14
1
kobotoolbox/kobocat:2.022.24ab15679454415
uwsgi@2.0.20
2.0.22
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
uwsgi@2.0.20
2.0.22
1
lsstsqre/squash-api:0.5.34879415ec6ac
uwsgi@2.0.19.1
2.0.22
1
mediagis/nominatim:3.7c15e941485ef
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14
1
neilpeterson/aks-helloworld:v1fb47732ef36b
uwsgi@2.0.15
2.0.22
1
neilpeterson/chart-tweet:latest64fd8dab075f
uwsgi@2.0.15
2.0.22
1
openemr/openemr:6.1.089eaa6d9a4e3
apache2@2.4.53-r0
2.4.56-r0
1
openzaak/open-notificaties:1.3.02e65313b9b10
uwsgi@2.0.20
2.0.22
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
uwsgi@2.0.20
2.0.22
1
reportportal/service-auto-analyzer:5.7.295ada4a216ce
uwsgi@2.0.18
2.0.22
1
reportportal/service-metrics-gatherer:1.1.202a0e6dc11161
uwsgi@2.0.18
2.0.22
1
robotshop/rs-payment:latest774b52c6180d
uwsgi@2.0.19.1
2.0.22
1
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
uwsgi@2.0.19
2.0.22
1
snipe/snipe-it:v6.0.1455fb7636a98c
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.14
1
stakater/workshop-operator:v0.0.3897bf456cc97c
httpd@2.4.37-43.module+el8.5.0+13806+b30d9eec.1
0:2.4.37-56.module+el8.8.0+19808+379766d6.7
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
apache2@2.4.41-4ubuntu3.12
2.4.41-4ubuntu3.14
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.14
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
httpd@2.4.37-56.module+el8.8.0+18758+b3a9c8da.6
0:2.4.37-56.module+el8.8.0+19808+379766d6.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.