StackRadar

CVE-2023-36478

High

Advisory

Published 10 Oct 2023In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.038
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
23
of 17,781 indexed, latest versions
Container images
20
deployed by those charts
Fix available
1 of 1
affected package

HTTP/2 HPACK integer overflow and buffer allocation

Carried by container images the latest versions of 23 of 17,781 indexed charts deploy, on 20 images.

Affected packageAffected versionsFixed inImages
http2-hpackmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1620
OSV records
GHSA-wgh7-54f2-x98r
Also known as
BIT-jenkins-2023-36478

Charts affected

23 by stars
ChartLatestAffected imagesRadar Score
milvusmilvus4.0.311 of 5See more

milvus milvus 4.0.31

1 of the 5 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
http2-hpack@9.4.43.v20210629
9.4.53

Open the chart page →

32,259
solrpreferred-aiVerified publisher3.2.01 of 3See more

solr preferred-ai 3.2.0

1 of the 3 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
library/solr:8.7.0d124efd81fbb
http2-hpack@9.4.27.v20200227
9.4.53

Open the chart page →

6,048
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
http2-hpack@9.4.34.v20201102
9.4.53

Open the chart page →

12,111
activemq-artemisactivemq-artemis-helm0.3.61 of 1See more

activemq-artemis activemq-artemis-helm 0.3.6

1 of the 1 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
vromero/activemq-artemis:2.16.0408d6a46b153
http2-hpack@9.4.27.v20200227
9.4.53

Open the chart page →

4,419
wiremockdeliveryheroVerified publisher1.4.61 of 2See more

wiremock deliveryhero 1.4.6

1 of the 2 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
http2-hpack@9.4.20.v20190813
9.4.53

Open the chart page →

2,140
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
http2-hpack@9.4.34.v20201102
9.4.53

Open the chart page →

12,019
metabasemetabase-helmVerified publisher2.7.11 of 1See more

metabase metabase-helm 2.7.1

1 of the 1 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
metabase/metabase:v0.46.09ebdc664a6b2
http2-hpack@11.0.14
11.0.16

Open the chart page →

2,221
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
http2-hpack@9.4.44.v20210927
9.4.53

Open the chart page →

24,930
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
http2-hpack@9.4.8.v20171121
9.4.53

Open the chart page →

7,226
pulsarcnieg1.0.81 of 2See more

pulsar cnieg 1.0.8

1 of the 2 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
http2-hpack@9.4.11.v20180605
9.4.53

Open the chart page →

16,860
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
http2-hpack@9.4.36.v20210114
9.4.53

Open the chart page →

26,944
hbasehbase0.1.71 of 4See more

hbase hbase 0.1.7

1 of the 4 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
http2-hpack@9.4.34.v20201102
9.4.53

Open the chart page →

10,540
wiremockhelm-charts-nr1.4.61 of 2See more

wiremock helm-charts-nr 1.4.6

1 of the 2 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
http2-hpack@9.4.20.v20190813
9.4.53

Open the chart page →

2,140
wiremocklebenitzaVerified publisher0.3.11 of 1See more

wiremock lebenitza 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.27.22328a9fce2bf
http2-hpack@9.4.30.v20200611
9.4.53

Open the chart page →

2,427
chirpstackmosquitto-helm-chart0.5.01 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

1 of the 8 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
http2-hpack@9.4.43.v20210629
9.4.53

Open the chart page →

25,933
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
http2-hpack@9.4.44.v20210927
9.4.53

Open the chart page →

15,675
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
http2-hpack@9.4.32.v20200930
9.4.53

Open the chart page →

55,726
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
http2-hpack@9.4.51.v20230217
9.4.53

Open the chart page →

9,005
bastillion-upstreamrock8sVerified publisher0.1.01 of 1See more

bastillion-upstream rock8s 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
iamdorsah/bastillion:v0.1db83a0254d81
http2-hpack@9.4.45.v20220203
9.4.53

Open the chart page →

3,051
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
http2-hpack@9.4.44.v20210927
9.4.53

Open the chart page →

6,065
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
http2-hpack@9.4.44.v20210927
9.4.53

Open the chart page →

8,806
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
http2-hpack@9.4.49.v20220914
9.4.53

Open the chart page →

13,767
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-36478.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
http2-hpack@9.4.34.v20201102
9.4.53

Open the chart page →

4,240

Container images carrying it

20 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/solr:8.11.18c5f7881cebb
http2-hpack@9.4.44.v20210927
9.4.53
3
rodolpheche/wiremock:2.26.03be08a386092
http2-hpack@9.4.20.v20190813
9.4.53
2
5200710/hadoop:3.2.3-java8092d3088a5fb
http2-hpack@9.4.34.v20201102
9.4.53
1
apache/hadoop:3af361b20bec0
http2-hpack@9.4.34.v20201102
9.4.53
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
http2-hpack@9.4.51.v20230217
9.4.53
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
http2-hpack@9.4.44.v20210927
9.4.53
1
apachepulsar/pulsar:2.6.14db6ff0b4045
http2-hpack@9.4.11.v20180605
9.4.53
1
apachepulsar/pulsar:2.9.0d056c89b7131
http2-hpack@9.4.43.v20210629
9.4.53
1
apachepulsar/pulsar:2.8.2d538416d5afe
http2-hpack@9.4.43.v20210629
9.4.53
1
bivas/presto:0.19605545994f806
http2-hpack@9.4.8.v20171121
9.4.53
1
craigwillis/c2metadata-bd:latestae317d7e4724
http2-hpack@9.4.32.v20200930
9.4.53
1
iamdorsah/bastillion:v0.1db83a0254d81
http2-hpack@9.4.45.v20220203
9.4.53
1
library/solr:8.7.0d124efd81fbb
http2-hpack@9.4.27.v20200227
9.4.53
1
metabase/metabase:v0.46.09ebdc664a6b2
http2-hpack@11.0.14
11.0.16
1
rodolpheche/wiremock:2.27.22328a9fce2bf
http2-hpack@9.4.30.v20200611
9.4.53
1
sismics/docs:v1.10f4b0ef019cf1
http2-hpack@9.4.36.v20210114
9.4.53
1
trinodb/trino:405ee80ab5eeab2
http2-hpack@9.4.49.v20220914
9.4.53
1
vromero/activemq-artemis:2.16.0408d6a46b153
http2-hpack@9.4.27.v20200227
9.4.53
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
http2-hpack@9.4.34.v20201102
9.4.53
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
http2-hpack@9.4.34.v20201102
9.4.53
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.