StackRadar

CVE-2023-35945

High

Advisory

Published 13 Jul 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
207
of 17,781 indexed, latest versions
Container images
175
deployed by those charts
Fix available
2 of 2
affected packages

libnghttp2-14-1.55.1-1.1 on GA media

Carried by container images the latest versions of 207 of 17,781 indexed charts deploy, on 175 images.

Affected packageAffected versionsFixed inImages
nghttp2apk1.46.0-r0, 1.47.0-r0, 1.51.0-r01.46.0-r1, 1.47.0-r1, 1.51.0-r1165
nghttp2rpm1.39.2-lp151.3.3.1, 1.40.0-1.15, 1.40.0-3.6.31.40.0-150000.3.14.1, 1.40.0-150200.9.1, 1.55.1-1.110
OSV records
ALPINE-CVE-2023-35945openSUSE-SU-2024:13062-1SUSE-SU-2023:3997-1SUSE-SU-2023:4102-1

Charts affected

207 by stars
ChartLatestAffected imagesRadar Score
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:4.5.39e2c0107c7a3
nghttp2@1.47.0-r0
1.47.0-r1

Open the chart page →

8,607
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
nghttp2@1.46.0-r0
1.46.0-r1

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
nghttp2@1.46.0-r0
1.46.0-r1

Open the chart page →

1,523
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
nghttp2@1.51.0-r0
1.51.0-r1

Open the chart page →

2,030
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
nghttp2@1.46.0-r0
1.46.0-r1

Open the chart page →

7,552
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
nghttp2@1.46.0-r0
1.46.0-r1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
nghttp2@1.46.0-r0
1.46.0-r1

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
nghttp2@1.51.0-r0
1.51.0-r1

Open the chart page →

5,033

Container images carrying it

175 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
nghttp2@1.46.0-r0
1.46.0-r1
1
ghcr.io/eugenmayer/nist-data-mirror:0.1.1a2162df94729
nghttp2@1.51.0-r0
1.51.0-r1
1
ghcr.io/k10app/businit:latest94c9a3e799c2
nghttp2@1.51.0-r0
1.51.0-r1
1
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
nghttp2@1.47.0-r0
1.47.0-r1
1
ghcr.io/mailu/clamav:1.9.5001d30483e4a8
nghttp2@1.51.0-r0
1.51.0-r1
1
ghcr.io/mjohnson9/docker-pleroma:v0.1.44f08e2823756
nghttp2@1.47.0-r0
1.47.0-r1
1
ghcr.io/pascaliske/traefik-errors:1.1.00cf31753ce57
nghttp2@1.51.0-r0
1.51.0-r1
1
ghcr.io/pascaliske/unbound:0.1.09009fbd2ef16
nghttp2@1.51.0-r0
1.51.0-r1
1
ghcr.io/petio-team/petio:new-uia5802962de0f
nghttp2@1.47.0-r0
1.47.0-r1
1
ghcr.io/reitermarkus/strongswan:v1.0.0e7a8afe6e6eb
nghttp2@1.46.0-r0
1.46.0-r1
1
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
nghttp2@1.46.0-r0
1.46.0-r1
1
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
nghttp2@1.47.0-r0
1.47.0-r1
1
ghcr.io/volosoft/eshoponabp/app-web:1.0.0056bb4271626
nghttp2@1.47.0-r0
1.47.0-r1
1
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
nghttp2@1.46.0-r0
1.46.0-r1
1
ghcr.io/wbstack/ui:3.94b01f67faadf1
nghttp2@1.46.0-r0
1.46.0-r1
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
nghttp2@1.47.0-r0
1.47.0-r1
1
quay.io/k8start/http-headers:1.2.0c7a9987f2ac5
nghttp2@1.47.0-r0
1.47.0-r1
1
quay.io/netwarps/blockscoutbecd3e39360a
nghttp2@1.46.0-r0
1.46.0-r1
1
quay.io/opsmxpublic/awsgit:v2-openssh0d21ba756f44
nghttp2@1.46.0-r0
1.46.0-r1
1
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
nghttp2@1.51.0-r0
1.51.0-r1
1
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
nghttp2@1.47.0-r0
1.47.0-r1
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
nghttp2@1.51.0-r0
1.51.0-r1
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
nghttp2@1.47.0-r0
1.47.0-r1
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
nghttp2@1.51.0-r0
1.51.0-r1
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
nghttp2@1.47.0-r0
1.47.0-r1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.