StackRadar

CVE-2023-29407

Medium

Advisory

Published 2 Aug 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
37
of 17,781 indexed, latest versions
Container images
36
deployed by those charts
Fix available
1 of 1
affected package

Golang TIFF decoder vulnerable to excessive CPU consumption

Carried by container images the latest versions of 37 of 17,781 indexed charts deploy, on 36 images.

Affected packageAffected versionsFixed inImages
golang.org/x/imagegolangv0.0.0-20190802002840-cff245a6509b, v0.0.0-20191009234506-e7c1f5e7dbb8, v0.0.0-20201208152932-35266b937fa6, v0.0.0-20210216034530-4410531fe030+11 more0.10.036
OSV records
GHSA-j3p8-6mrq-6g7h
Also known as
GO-2023-1990

Charts affected

37 by stars
ChartLatestAffected imagesRadar Score
codercoderOfficialVerified publisher1.44.61 of 2See more

coder coder 1.44.6

1 of the 2 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/image@v0.0.0-20210216034530-4410531fe030
0.10.0

Open the chart page →

6,849
filebrowserutkuozdemirVerified publisher1.0.01 of 1See more

filebrowser utkuozdemir 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.10.0

Open the chart page →

3,073
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/image@v0.8.0
0.10.0

Open the chart page →

8,722
listmonkdeliveryheroVerified publisher0.1.121 of 1See more

listmonk deliveryhero 0.1.12

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.10.0

Open the chart page →

2,537
filebrowsergeek-cookbookVerified publisher1.4.21 of 1See more

filebrowser geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.18.04fcd47af573c
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.10.0

Open the chart page →

3,474
focalboardgeek-cookbookVerified publisher4.4.21 of 1See more

focalboard geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
mattermost/focalboard:0.9.031078df7a3c8
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0

Open the chart page →

3,631
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.10.0

Open the chart page →

15,856
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/image@v0.0.0-20220302094943-723b81ca9867
0.10.0

Open the chart page →

2,312
cospacecospace0.0.341 of 3See more

cospace cospace 0.0.34

1 of the 3 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
ghcr.io/twigex/cospace:lateste5ecfd607e42
golang.org/x/image@v0.0.0-20210607152325-775e3b0c77b9
0.10.0

Open the chart page →

2,253
commentoduyet0.2.01 of 2See more

commento duyet 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.10.0

Open the chart page →

2,679
Navidromeemmas-chartsVerified publisher0.0.41 of 1See more

Navidrome emmas-charts 0.0.4

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
deluan/navidrome:0.49.311a24da08977
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.10.0

Open the chart page →

2,837
testnet-homepageethereum-helm-chartsVerified publisher0.2.31 of 1See more

testnet-homepage ethereum-helm-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0

Open the chart page →

2,681
dendritegeek-cookbookVerified publisher6.4.01 of 1See more

dendrite geek-cookbook 6.4.0

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.10.0

Open the chart page →

2,143
gatusgeek-cookbookVerified publisher1.1.21 of 1See more

gatus geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.10.0

Open the chart page →

1,881
gonicgeek-cookbookVerified publisher6.4.21 of 1See more

gonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
sentriz/gonic:v0.13.1a74012a6adf3
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.10.0

Open the chart page →

3,525
navidromegeek-cookbookVerified publisher6.4.21 of 1See more

navidrome geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.10.0

Open the chart page →

3,597
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.10.0

Open the chart page →

3,236
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/image@v0.0.0-20220617043117-41969df76e82
0.10.0

Open the chart page →

19,503
vikunjageek-cookbookVerified publisher6.2.01 of 4See more

vikunja geek-cookbook 6.2.0

1 of the 4 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
vikunja/api:0.17.18cba0520bf8c
golang.org/x/image@v0.0.0-20210504121937-7319ad40d33e
0.10.0

Open the chart page →

6,893
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0

Open the chart page →

4,455
listmonkhelm-charts-nr0.1.121 of 1See more

listmonk helm-charts-nr 0.1.12

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.10.0

Open the chart page →

2,537
imageproxyhmphuVerified publisher0.1.11 of 1See more

imageproxy hmphu 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.10.0

Open the chart page →

2,140
casdoor-helm-chartskubeblocksVerified publisher1.753.01 of 1See more

casdoor-helm-charts kubeblocks 1.753.0

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
casbin/casdoor:v1.753.0770ad9ec3190
golang.org/x/image@v0.0.0-20220302094943-723b81ca9867
0.10.0

Open the chart page →

2,299
metadockvalitetsitVerified publisher0.0.71 of 2See more

metadoc kvalitetsit 0.0.7

1 of the 2 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0

Open the chart page →

4,026
focalboardmattermostVerified publisher0.5.01 of 1See more

focalboard mattermost 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
mattermost/focalboard:0.6.7f2f987dada52
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0

Open the chart page →

4,014
mattermost-chaos-enginemattermostVerified publisher0.2.01 of 1See more

mattermost-chaos-engine mattermost 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
mattermost/mattermost-app-chaosengine:c153e436268954edd67
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0

Open the chart page →

4,067
mindavphntom0.1.61 of 2See more

mindav phntom 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.10.0

Open the chart page →

4,158
imgproxyrock8sVerified publisher0.8.301 of 1See more

imgproxy rock8s 0.8.30

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/image@v0.5.0
0.10.0

Open the chart page →

2,022
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.10.0

Open the chart page →

5,582
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.10.0

Open the chart page →

3,073
agentssynapse0.1.302 of 9See more

agents synapse 0.1.30

2 of the 9 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.10.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.10.0

Open the chart page →

7,244
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
golang.org/x/image@v0.6.0
0.10.0

Open the chart page →

8,518
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
golang.org/x/image@v0.6.0
0.10.0

Open the chart page →

2,680
sinnersynapse0.1.01 of 6See more

sinner synapse 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.10.0

Open the chart page →

1,955
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.10.0

Open the chart page →

3,174
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/image@v0.5.0
0.10.0

Open the chart page →

16,083
commentopluspluswyrihaximusnetVerified publisher0.4.01 of 1See more

commentoplusplus wyrihaximusnet 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-29407.

Container imageDigestPackageFixed in
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0

Open the chart page →

1,960

Container images carrying it

36 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.10.0
2
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.10.0
2
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0
1
casbin/casdoor:v1.753.0770ad9ec3190
golang.org/x/image@v0.0.0-20220302094943-723b81ca9867
0.10.0
1
coderenvs/coder-service:1.44.61deffc4670e6
golang.org/x/image@v0.0.0-20210216034530-4410531fe030
0.10.0
1
darthsim/imgproxy:v3.15.040f6eb807444
golang.org/x/image@v0.5.0
0.10.0
1
deluan/navidrome:0.49.311a24da08977
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.10.0
1
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.10.0
1
filebrowser/filebrowser:v2.18.04fcd47af573c
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.10.0
1
filebrowser/filebrowser:v2.13.0c5d0a75a0041
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.10.0
1
kvalitetsit/metadoc-web:mainf57e7553f5bd
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.10.0
1
mattermost/focalboard:0.9.031078df7a3c8
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0
1
mattermost/focalboard:0.6.7f2f987dada52
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0
1
mattermost/mattermost-app-chaosengine:c153e436268954edd67
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0
1
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/image@v0.5.0
0.10.0
1
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.10.0
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/image@v0.8.0
0.10.0
1
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.10.0
1
photoprism/photoprism:220629-jammy2954334adbda
golang.org/x/image@v0.0.0-20220617043117-41969df76e82
0.10.0
1
sentriz/gonic:v0.13.1a74012a6adf3
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.10.0
1
skylenet/ethereum-testnet-homepage:latest8698903e379f
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0
1
stashapp/stash:latest24dbd7607174
golang.org/x/image@v0.0.0-20190802002840-cff245a6509b
0.10.0
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/image@v0.0.0-20210220032944-ac19c3e999fb
0.10.0
1
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/image@v0.0.0-20210628002857-a66eb6448b8d
0.10.0
1
vikunja/api:0.17.18cba0520bf8c
golang.org/x/image@v0.0.0-20210504121937-7319ad40d33e
0.10.0
1
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/image@v0.0.0-20201208152932-35266b937fa6
0.10.0
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/image@v0.0.0-20220302094943-723b81ca9867
0.10.0
1
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/image@v0.0.0-20220413100746-70e8d0d3baa9
0.10.0
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.10.0
1
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
golang.org/x/image@v0.6.0
0.10.0
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.10.0
1
ghcr.io/synapsecns/sanguine/scribe:latest81edba952403
golang.org/x/image@v0.6.0
0.10.0
1
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/image@v0.0.0-20220902085622-e7cb96979f69
0.10.0
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
golang.org/x/image@v0.0.0-20210607152325-775e3b0c77b9
0.10.0
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/image@v0.0.0-20191009234506-e7c1f5e7dbb8
0.10.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.