StackRadar

CVE-2023-35945

High

Advisory

Published 13 Jul 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
207
of 17,781 indexed, latest versions
Container images
175
deployed by those charts
Fix available
2 of 2
affected packages

libnghttp2-14-1.55.1-1.1 on GA media

Carried by container images the latest versions of 207 of 17,781 indexed charts deploy, on 175 images.

Affected packageAffected versionsFixed inImages
nghttp2apk1.46.0-r0, 1.47.0-r0, 1.51.0-r01.46.0-r1, 1.47.0-r1, 1.51.0-r1165
nghttp2rpm1.39.2-lp151.3.3.1, 1.40.0-1.15, 1.40.0-3.6.31.40.0-150000.3.14.1, 1.40.0-150200.9.1, 1.55.1-1.110
OSV records
ALPINE-CVE-2023-35945openSUSE-SU-2024:13062-1SUSE-SU-2023:3997-1SUSE-SU-2023:4102-1

Charts affected

207 by stars
ChartLatestAffected imagesRadar Score
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:4.5.39e2c0107c7a3
nghttp2@1.47.0-r0
1.47.0-r1

Open the chart page →

8,607
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
nghttp2@1.46.0-r0
1.46.0-r1

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
nghttp2@1.46.0-r0
1.46.0-r1

Open the chart page →

1,523
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
nghttp2@1.51.0-r0
1.51.0-r1

Open the chart page →

2,030
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
nghttp2@1.46.0-r0
1.46.0-r1

Open the chart page →

7,552
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
nghttp2@1.46.0-r0
1.46.0-r1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
nghttp2@1.46.0-r0
1.46.0-r1

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
nghttp2@1.51.0-r0
1.51.0-r1

Open the chart page →

5,033

Container images carrying it

175 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
clastix/kubectl:v1.22d0376d87ac6b
nghttp2@1.46.0-r0
1.46.0-r1
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
nghttp2@1.51.0-r0
1.51.0-r1
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
nghttp2@1.51.0-r0
1.51.0-r1
1
curlimages/curl:8.1.15af13420d29b
nghttp2@1.51.0-r0
1.51.0-r1
1
curlimages/curl:8.00.19e886c104cae
nghttp2@1.47.0-r0
1.47.0-r1
1
curlimages/curl:8.00.0d1658d9c8ef9
nghttp2@1.47.0-r0
1.47.0-r1
1
curlimages/curl:7.83.1e83fef2d5a03
nghttp2@1.46.0-r0
1.46.0-r1
1
devopstales/trivy-operator:2.575136aa7a26e
nghttp2@1.51.0-r0
1.51.0-r1
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
nghttp2@1.46.0-r0
1.46.0-r1
1
dnsforge/xteve:latest4d9a685c8c28
nghttp2@1.51.0-r0
1.51.0-r1
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
nghttp2@1.51.0-r0
1.51.0-r1
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
nghttp2@1.46.0-r0
1.46.0-r1
1
emqx/emqx:4.4.41d36535ba9de
nghttp2@1.46.0-r0
1.46.0-r1
1
emqx/emqx:4.4.1971db5ed95db3
nghttp2@1.46.0-r0
1.46.0-r1
1
ethereumoptimism/l2geth:0.5.315577036dc36d
nghttp2@1.46.0-r0
1.46.0-r1
1
fedodo/fedodo.ui.home:3c69413c4d690
nghttp2@1.51.0-r0
1.51.0-r1
1
fedodo/fedodo.ui.micro:12b2b540081c21
nghttp2@1.51.0-r0
1.51.0-r1
1
felipecs8/qrcode-generator:v1d5f4f17cb066
nghttp2@1.51.0-r0
1.51.0-r1
1
firefart/requesttracker:nginx-nightly-202307101028236b42a0
nghttp2@1.51.0-r0
1.51.0-r1
1
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
nghttp2@1.47.0-r0
1.47.0-r1
1
flomesh/curl:7.84.0bc34fa2aca2c
nghttp2@1.46.0-r0
1.46.0-r1
1
folioci/mod-aes:latest6d67e9564270
nghttp2@1.47.0-r0
1.47.0-r1
1
folioci/mod-codex-ekb:latest235a3fa4adc9
nghttp2@1.47.0-r0
1.47.0-r1
1
folioci/mod-codex-inventory:latest6d53ed758fd1
nghttp2@1.47.0-r0
1.47.0-r1
1
folioci/mod-codex-mux:latestd4138abfd30d
nghttp2@1.47.0-r0
1.47.0-r1
1
folioci/mod-data-import-converter-storage:latest3028f333778f
nghttp2@1.51.0-r0
1.51.0-r1
1
gcarrarom/landing:0.0.0769d19e441d9
nghttp2@1.47.0-r0
1.47.0-r1
1
grafana/grafana:9.5.239c849cebccc
nghttp2@1.51.0-r0
1.51.0-r1
1
gresearchdev/siembol-config-editor-ui:latest071e7109a981
nghttp2@1.47.0-r0
1.47.0-r1
1
groundnuty/k8s-wait-for:v1.684edcf796267
nghttp2@1.46.0-r0
1.46.0-r1
1
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
nghttp2@1.47.0-r0
1.47.0-r1
1
hashicorp/consul:1.15.3ddff34041c5c
nghttp2@1.51.0-r0
1.51.0-r1
1
hashicorp/waypoint:0.11.397d521a27498
nghttp2@1.51.0-r0
1.51.0-r1
1
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
nghttp2@1.46.0-r0
1.46.0-r1
1
ianw/quickchart:v1.7.1dc49dd460c37
nghttp2@1.46.0-r0
1.46.0-r1
1
ibarreche/cloud-back-ci:lateste16a469c5791
nghttp2@1.46.0-r0
1.46.0-r1
1
jupyterhub/configurable-http-proxy:4.5.1723028bf9b3c
nghttp2@1.46.0-r0
1.46.0-r1
1
jupyterhub/configurable-http-proxy:4.5.39e2c0107c7a3
nghttp2@1.47.0-r0
1.47.0-r1
1
kfirfer/scripts:0.0.2481e5c4e5d70e
nghttp2@1.46.0-r0
1.46.0-r1
1
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
nghttp2@1.46.0-r0
1.46.0-r1
1
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
nghttp2@1.47.0-r0
1.47.0-r1
1
kubeshop/kusk-gateway-dashboard:v1.2.6ff9b5aa1258d
nghttp2@1.47.0-r0
1.47.0-r1
1
lachlanevenson/k8s-kubectl:v1.22.1638b7962cd016
nghttp2@1.51.0-r0
1.51.0-r1
1
library/nginx:1.23.2-alpine455c39afebd4
nghttp2@1.47.0-r0
1.47.0-r1
1
library/php:7-fpm-alpine0aeb129a60da
nghttp2@1.47.0-r0
1.47.0-r1
1
librenms/librenms:22.4.14f1f3d667cc7
nghttp2@1.46.0-r0
1.46.0-r1
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
nghttp2@1.51.0-r0
1.51.0-r1
1
liukunup/jmeter:5.59c079617a81b
nghttp2@1.47.0-r0
1.47.0-r1
1
metabase/metabase:v0.46.09ebdc664a6b2
nghttp2@1.51.0-r0
1.51.0-r1
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
nghttp2@1.46.0-r0
1.46.0-r1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.