StackRadar

CVE-2023-35945

High

Advisory

Published 13 Jul 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
69th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
207
of 17,781 indexed, latest versions
Container images
175
deployed by those charts
Fix available
2 of 2
affected packages

libnghttp2-14-1.55.1-1.1 on GA media

Carried by container images the latest versions of 207 of 17,781 indexed charts deploy, on 175 images.

Affected packageAffected versionsFixed inImages
nghttp2apk1.46.0-r0, 1.47.0-r0, 1.51.0-r01.46.0-r1, 1.47.0-r1, 1.51.0-r1165
nghttp2rpm1.39.2-lp151.3.3.1, 1.40.0-1.15, 1.40.0-3.6.31.40.0-150000.3.14.1, 1.40.0-150200.9.1, 1.55.1-1.110
OSV records
ALPINE-CVE-2023-35945openSUSE-SU-2024:13062-1SUSE-SU-2023:3997-1SUSE-SU-2023:4102-1

Charts affected

207 by stars
ChartLatestAffected imagesRadar Score
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:4.5.39e2c0107c7a3
nghttp2@1.47.0-r0
1.47.0-r1

Open the chart page →

8,607
queryservice-uiwbstack0.2.01 of 1See more

queryservice-ui wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
nghttp2@1.46.0-r0
1.46.0-r1

Open the chart page →

1,996
uiwbstack0.4.01 of 1See more

ui wbstack 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
ghcr.io/wbstack/ui:3.94b01f67faadf1
nghttp2@1.46.0-r0
1.46.0-r1

Open the chart page →

1,523
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
nghttp2@1.51.0-r0
1.51.0-r1

Open the chart page →

2,030
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
nghttp2@1.46.0-r0
1.46.0-r1

Open the chart page →

7,552
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
nghttp2@1.46.0-r0
1.46.0-r1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
nghttp2@1.46.0-r0
1.46.0-r1

Open the chart page →

16,083
zahori-consulzahoriVerified publisher1.0.11 of 2See more

zahori-consul zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-35945.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
nghttp2@1.51.0-r0
1.51.0-r1

Open the chart page →

5,033

Container images carrying it

175 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
pnnlmiscscripts/anaconda:20201029-1700-nginx-105827b9efa7b
nghttp2@1.47.0-r0
1.47.0-r1
10
curlimages/curl:7.85.09fab1b73f45e
nghttp2@1.46.0-r0
1.46.0-r1
6
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
nghttp2@1.46.0-r0
1.46.0-r1
6
quay.io/devtron/kubectl:latest2ad610626658
nghttp2@1.47.0-r0
1.47.0-r1
6
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
nghttp2@1.47.0-r0
1.47.0-r1
5
curlimages/curl:7.87.0:multiarch-7.87.0f7f265d5c64e
nghttp2@1.47.0-r0
1.47.0-r1
4
hyperledger/fabric-tools:2.4b1194f509085
nghttp2@1.47.0-r0
1.47.0-r1
4
groundnuty/k8s-wait-for:v2.0c14d7271e401
nghttp2@1.47.0-r0
1.47.0-r1
3
lachlanevenson/k8s-kubectl:v1.23.2e4d83478963b
nghttp2@1.46.0-r0
1.46.0-r1
3
pnnlmiscscripts/anaconda9:1683907016.7470503-nginx-19a2fe06a1472
nghttp2@1.51.0-r0
1.51.0-r1
3
quay.io/devtron/k8s-utils:tutum-curl38b970c84cce
nghttp2@1.46.0-r0
1.46.0-r1
3
quay.io/devtron/svn-git-sync:v78e54bc2d261f
nghttp2@1.47.0-r0
1.47.0-r1
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
nghttp2@1.47.0-r0
1.47.0-r1
3
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
nghttp2@1.51.0-r0
1.51.0-r1
2
cs3org/wopiserver:v9.4.202a9e78757b4
nghttp2@1.51.0-r0
1.51.0-r1
2
daniacobext/airports-frontend:latest9eae4d39fc33
nghttp2@1.51.0-r0
1.51.0-r1
2
dependencytrack/frontend:4.6.124422d762e08
nghttp2@1.47.0-r0
1.47.0-r1
2
devopsjourney1/mywebapp:latestbd1ec6838570
nghttp2@1.47.0-r0
1.47.0-r1
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
nghttp2@1.47.0-r0
1.47.0-r1
2
hashicorp/consul:1.14.2e38576edcdfd
nghttp2@1.46.0-r0
1.46.0-r1
2
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
nghttp2@1.47.0-r0
1.47.0-r1
2
krtk6160/galoy-nostrcc82a694f818
nghttp2@1.51.0-r0
1.51.0-r1
2
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
nghttp2@1.51.0-r0
1.51.0-r1
2
library/influxdb:2.6.1-alpine44a366dd7724
nghttp2@1.51.0-r0
1.51.0-r1
2
metabase/metabase:v0.45.21fb334ce4820
nghttp2@1.51.0-r0
1.51.0-r1
2
phpipam/phpipam-cron:v1.5.2f770577cb946
nghttp2@1.46.0-r0
1.46.0-r1
2
phpipam/phpipam-www:v1.5.23c6fd1332aeb
nghttp2@1.46.0-r0
1.46.0-r1
2
taigaio/taiga-front:latest570c8792ce80
nghttp2@1.51.0-r0
1.51.0-r1
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
nghttp2@1.51.0-r0
1.51.0-r1
2
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
nghttp2@1.46.0-r0
1.46.0-r1
2
quay.io/iver-wharf/wharf-web:v1.6.2dc5d1ed91c26
nghttp2@1.46.0-r0
1.46.0-r1
2
ahmedinfraplus/simple-app:STAGINGc50e6e81a637
nghttp2@1.47.0-r0
1.47.0-r1
1
akaunting/akaunting:3.1.21-fpm-alpine-nginxe7d5c245b1a0
nghttp2@1.46.0-r0
1.46.0-r1
1
alpine/git:2.36.366b210a97bc0
nghttp2@1.47.0-r0
1.47.0-r1
1
alpine/k8s:1.22.600ac10bcb759
nghttp2@1.46.0-r0
1.46.0-r1
1
anonaddy/anonaddy:0.12.3957a95565166
nghttp2@1.47.0-r0
1.47.0-r1
1
aquasec/trivy:0.32.0973d0df16189
nghttp2@1.47.0-r0
1.47.0-r1
1
assistiot/fl_orchestrator:ui-latest20338b353aaf
nghttp2@1.47.0-r0
1.47.0-r1
1
assistiot/open_api_kong:1.0.03fe850384689
nghttp2@1.47.0-r0
1.47.0-r1
1
assistiot/tacticle_dashboard:web-latest25fc9f373524
nghttp2@1.47.0-r0
1.47.0-r1
1
bicarus/wg-access-server:v0.8.206cab48e9334
nghttp2@1.47.0-r0
1.47.0-r1
1
blockscout/blockscout:5.1.5c365a8f2dc12
nghttp2@1.47.0-r0
1.47.0-r1
1
casbin/casdoor:v1.224.066f836ef778b
nghttp2@1.51.0-r0
1.51.0-r1
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
nghttp2@1.39.2-lp151.3.3.1
1.55.1-1.1
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
nghttp2@1.39.2-lp151.3.3.1
1.55.1-1.1
1
cfcontainerization/quarks-job:v0.0.124-g03faac87366b11c5fa5
nghttp2@1.40.0-3.6.3
1.40.0-150000.3.14.1
1
cfcontainerization/quarks-secret:v0.0.677-ga060bb643131dbc0c8f
nghttp2@1.40.0-3.6.3
1.40.0-150000.3.14.1
1
chaosnative/cle-frontend:2.7.007b82a82a702
nghttp2@1.46.0-r0
1.46.0-r1
1
charmcli/soft-serve:v0.4.039523c1a6ba8
nghttp2@1.47.0-r0
1.47.0-r1
1
clastix/kubectl:v1.2187fabaccb3a6
nghttp2@1.46.0-r0
1.46.0-r1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.