CVE-2023-31125
MediumAdvisory
Published 3 May 2023In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.5
- base score, highest
- EPSS
- 0.013
- 69th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 17
- of 17,781 indexed, latest versions
- Container images
- 16
- deployed by those charts
- Fix available
- 1 of 1
- affected package
engine.io Uncaught Exception vulnerability
Carried by container images the latest versions of 17 of 17,781 indexed charts deploy, on 16 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| engine.ionpm | 5.1.0, 5.1.1, 6.0.0, 6.1.3+3 more | 6.4.2 | 16 |
- OSV records
- GHSA-q9mw-68c2-j6m5
Charts affected
17 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| outlineoutline | 0.0.9 | 1 of 4See more | 4,431 |
| uptime-kumaduyet | 0.1.7 | 1 of 1See more | 4,515 |
| redisinsightheywood8-helm-chartsVerified publisher | 0.4.5 | 1 of 1See more | 2,828 |
| nightscoutgabe565Verified publisher | 0.13.0 | 1 of 2See more | 2,521 |
| audiobookshelfgeek-cookbookVerified publisher | 1.2.2 | 1 of 1See more | 1,959 |
| calibregeek-cookbookVerified publisher | 5.4.2 | 1 of 1See more | 22,773 |
| zwavejs2mqttgeek-cookbookVerified publisher | 5.4.2 | 1 of 1See more | 3,476 |
| kubeviouskubevious | 1.2.2 | 1 of 7See more | 14,204 |
| homebridgegeek-cookbookVerified publisher | 5.3.2 | 1 of 1See more | 15,653 |
| uptime-kumageek-cookbookVerified publisher | 1.4.2 | 1 of 1See more | 5,079 |
| mx-apibicarus-labs | 0.1.0 | 1 of 4See more | 4,455 |
| authfcryptexlabsVerified publisher | 0.12.13 | 1 of 4See more | 3,769 |
| double-takegeek-cookbookVerified publisher | 2.3.2 | 1 of 1See more | 12,222 |
| nightscoutmt190502 | 1.1.0 | 1 of 3See more | 6,608 |
| cloudcmdmy0nVerified publisher | 0.0.3 | 1 of 1See more | 3,128 |
| outlineschmitzis | 0.0.8 | 1 of 4See more | 4,431 |
| trudesktechpreta | 1.0.0 | 1 of 3See more | 4,017 |
Container images carrying it
16 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| outlinewiki/ | d060dcd8f9aa | engine.io | 6.4.2 | 2 |
| bicarus/ | dab88659ae3b | engine.io | 6.4.2 | 1 |
| coderaiser/ | b34a9775c7ce | engine.io | 6.4.2 | 1 |
| cryptexlabs/ | 189c07411d7c | engine.io | 6.4.2 | 1 |
| heywood8/ | 0bc9ab313d37 | engine.io | 6.4.2 | 1 |
| jakowenko/ | b858bac9e32a | engine.io | 6.4.2 | 1 |
| kubevious/ | 9bf567704de2 | engine.io | 6.4.2 | 1 |
| linuxserver/ | a847b5b2d860 | engine.io | 6.4.2 | 1 |
| louislam/ | a4eab252e5a2 | engine.io | 6.4.2 | 1 |
| louislam/ | a84767d7934f | engine.io | 6.4.2 | 1 |
| nightscout/ | ad29ca7a4de6 | engine.io | 6.4.2 | 1 |
| nightscout/ | f604dc4c03ca | engine.io | 6.4.2 | 1 |
| polonel/ | 0cf6513f6fe3 | engine.io | 6.4.2 | 1 |
| zwavejs/ | 15a6040fb468 | engine.io | 6.4.2 | 1 |
| ghcr.io/ | 140aed2752c3 | engine.io | 6.4.2 | 1 |
| ghcr.io/ | ff2af53897e7 | engine.io | 6.4.2 | 1 |