StackRadar

CVE-2023-39325

High

Advisory

Published 11 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.038
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,886
of 17,787 indexed, latest versions
Container images
2,183
deployed by those charts
Fix available
2 of 3
affected packages

HTTP/2 rapid reset can cause excessive work in net/http

Carried by container images the latest versions of 1,886 of 17,787 indexed charts deploy, on 2,183 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+109 more1.20.102,132
OSV records
DEBIAN-CVE-2023-39325GHSA-4374-p667-p6c8GO-2023-2102
Also known as
BIT-golang-2023-39325

Charts affected

1,886 by stars
ChartLatestAffected imagesRadar Score
nfs-subdir-external-provisionernfs-subdir-external-provisioner4.0.181 of 1See more

nfs-subdir-external-provisioner nfs-subdir-external-provisioner 4.0.18

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15
0.17.0
1.20.10

Open the chart page →

2,745
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
stdlib@go1.20.5
1.20.10

Open the chart page →

30,167
nfs-server-provisionerkvaps1.8.01 of 1See more

nfs-server-provisioner kvaps 1.8.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.17.0
1.20.10

Open the chart page →

2,315
aws-node-termination-handleraws0.21.01 of 1See more

aws-node-termination-handler aws 0.21.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.19.0844478ebd5b8
golang.org/x/net@v0.2.0
stdlib@go1.19.5
0.17.0
1.20.10

Open the chart page →

1,445
openebsopenebsOfficialVerified publisher4.6.13 of 35See more

openebs openebs 4.6.1

3 of the 35 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
library/nats:2.9.17-alpine1a7b320b2942
stdlib@go1.19.9
1.20.10
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
stdlib@go1.19.4
1.20.10
natsio/prometheus-nats-exporter:0.11.031c02aac089a
stdlib@go1.20.3
1.20.10

Open the chart page →

24,009
open-webuiopen-webui16.5.01 of 4See more

open-webui open-webui 16.5.0

1 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
library/redis:7.4.2-alpine3.2102419de7eddf
stdlib@go1.18.2
1.20.10

Open the chart page →

1,288
actions-runner-controlleractions-runner-controller0.23.72 of 2See more

actions-runner-controller actions-runner-controller 0.23.7

2 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
summerwind/actions-runner-controller:v0.27.62128f81dbede
golang.org/x/net@v0.12.0
stdlib@go1.20.7
0.17.0
1.20.10
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
stdlib@go1.19.1
0.17.0
1.20.10

Open the chart page →

2,883
vpafairwinds-stableVerified publisher5.0.11 of 4See more

vpa fairwinds-stable 5.0.1

1 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/net@v0.7.0
stdlib@go1.20.1
0.17.0
1.20.10

Open the chart page →

1,233
terraformhashicorpVerified publisher1.1.21 of 1See more

terraform hashicorp 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.18.8
0.17.0
1.20.10

Open the chart page →

2,059
dagsterdagsterVerified publisher1.13.221 of 5See more

dagster dagster 1.13.22

1 of the 5 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
library/postgres:14.6f565573d74ae
stdlib@go1.18.2
1.20.10

Open the chart page →

3,459
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
stdlib@go1.18.2
1.20.10

Open the chart page →

5,557
rocketchatrocketchat-server7.0.22 of 12See more

rocketchat rocketchat-server 7.0.2

2 of the 12 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.17.0
1.20.10
bitnamilegacy/mongodb-exporter:0.39.0-debian-11-r106de7256c7adcd
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.17.0
1.20.10

Open the chart page →

12,283
influxdb2influxdata2.1.21 of 1See more

influxdb2 influxdata 2.1.2

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
library/influxdb:2.7.4-alpinea10d46445d68
stdlib@go1.20.3
1.20.10

Open the chart page →

2,102
solr-operatorapache-solrVerified publisher0.9.11 of 3See more

solr-operator apache-solr 0.9.1

1 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.17.0
1.20.10

Open the chart page →

2,943
chaos-meshchaos-meshVerified publisher2.8.41 of 4See more

chaos-mesh chaos-mesh 2.8.4

1 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

6,362
grafana-agentgrafana0.44.21 of 2See more

grafana-agent grafana 0.44.2

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
stdlib@go1.21.1
1.20.10

Open the chart page →

3,514
vclusterloftVerified publisher0.0.0-ci.31 of 2See more

vcluster loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.1.1-0.20221027164007-c63010009c80
stdlib@go1.19.4
0.17.0
1.20.10

Open the chart page →

2,453
milvusmilvus4.0.314 of 5See more

milvus milvus 4.0.31

4 of the 5 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
milvusdb/etcd:3.5.5-r2102aac62827b
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
stdlib@go1.18.2
0.17.0
1.20.10
milvusdb/milvus:v2.2.13a3a55e1c1497
golang.org/x/net@v0.10.0
stdlib@go1.18.3
0.17.0
1.20.10
milvusdb/milvus-config-tool:v0.1.12212dfb61401
golang.org/x/net@v0.0.0-20220706163947-c90051bbdb60
stdlib@go1.16.15
0.17.0
1.20.10
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.17.0
1.20.10

Open the chart page →

32,353
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
stdlib@go1.19.12
0.17.0
1.20.10

Open the chart page →

10,648
signozsignoz0.141.13 of 5See more

signoz signoz 0.141.1

3 of the 5 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.17.0
1.20.10
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.17.0
1.20.10
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.20.10

Open the chart page →

7,582
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
stdlib@go1.19.8
1.20.10

Open the chart page →

4,808
nacosygqygq2Verified publisher2.1.102 of 4See more

nacos ygqygq2 2.1.10

2 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
nacos/nacos-peer-finder-plugin:latesta9c769301fa6
stdlib@go1.13.5
1.20.10
ygqygq2/mysql-exec-sql:latest54f30def1558
stdlib@go1.18.2
1.20.10

Open the chart page →

4,984
pulsarapache4.7.01 of 10See more

pulsar apache 4.7.0

1 of the 10 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.17.0
1.20.10

Open the chart page →

9,869
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
bitnamilegacy/redis:7.0.11-debian-11-r121161dcd293a0
stdlib@go1.19.9
1.20.10

Open the chart page →

22,115
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.17.0
1.20.10

Open the chart page →

4,086
prometheus-msteamsprometheus-msteams1.3.61 of 1See more

prometheus-msteams prometheus-msteams 1.3.6

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
quay.io/prometheusmsteams/prometheus-msteams:v1.5.3a9f4d31ab811
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

941
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
stdlib@go1.16.8
0.17.0
1.20.10

Open the chart page →

4,159
oncallgrafana1.16.56 of 12See more

oncall grafana 1.16.5

6 of the 12 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.17.0
1.20.10
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.17.0
1.20.10
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.17.0
1.20.10
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.17.8
0.17.0
1.20.10
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18.2
0.17.0
1.20.10
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.17.0
1.20.10

Open the chart page →

16,251
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.17.0
1.20.10

Open the chart page →

11,402
zabbixcetic3.1.32 of 5See more

zabbix cetic 3.1.3

2 of the 5 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.18.1
0.17.0
1.20.10
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
stdlib@go1.18.1
1.20.10

Open the chart page →

33,907
chatwootchatwootVerified publisher2.0.242 of 3See more

chatwoot chatwoot 2.0.24

2 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
stdlib@go1.18.2
1.20.10
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
stdlib@go1.16.7
1.20.10

Open the chart page →

9,204
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.17.0
1.20.10

Open the chart page →

4,918
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
stdlib@go1.17.1
1.20.10

Open the chart page →

7,706
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
stdlib@go1.19.8
1.20.10

Open the chart page →

6,550
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/redis:7.2.8-alpinec88ea2979a49
stdlib@go1.18.2
1.20.10

Open the chart page →

5,278
hostpath-provisionerrimusz0.2.131 of 1See more

hostpath-provisioner rimusz 0.2.13

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.16.7
0.17.0
1.20.10

Open the chart page →

2,039
openldaphelm-openldapVerified publisher2.0.41 of 3See more

openldap helm-openldap 2.0.4

1 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.13.4
0.17.0
1.20.10

Open the chart page →

6,219
linkerd-jaegerlinkerd2Verified publisher30.12.112 of 4See more

linkerd-jaeger linkerd2 30.12.11

2 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
stdlib@go1.17.6
0.17.0
1.20.10
otel/opentelemetry-collector:0.59.0ee9da0b08d83
golang.org/x/net@v0.0.0-20220809184613-07c6da5e1ced
stdlib@go1.18.5
0.17.0
1.20.10

Open the chart page →

4,405
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.20.10

Open the chart page →

4,431
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
stdlib@go1.17.1
1.20.10

Open the chart page →

6,040
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.12
0.17.0
1.20.10

Open the chart page →

6,853
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
stdlib@go1.15
0.17.0
1.20.10

Open the chart page →

5,173
glasskube-operatorglasskubeOfficialVerified publisher0.12.23 of 3See more

glasskube-operator glasskube 0.12.2

3 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
golang.org/x/net@v0.15.0
stdlib@go1.20.8
0.17.0
1.20.10
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.17.0
1.20.10
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
golang.org/x/net@v0.15.0
stdlib@go1.21.1
0.17.0
1.20.10

Open the chart page →

11,971
plane-cemakeplaneOfficialVerified publisher1.8.11 of 11See more

plane-ce makeplane 1.8.1

1 of the 11 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
stdlib@go1.18.2
1.20.10

Open the chart page →

4,854
zookeepercloudpirates-zookeeperVerified publisher0.13.111 of 1See more

zookeeper cloudpirates-zookeeper 0.13.11

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5cab8944a33a1
stdlib@go1.18.1
1.20.10

Open the chart page →

2,963
vertical-pod-autoscalercluster-autoscaler0.12.01 of 4See more

vertical-pod-autoscaler cluster-autoscaler 0.12.0

1 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
0.17.0

Open the chart page →

1,062
aws-ebs-csi-driverdeliveryheroVerified publisher2.17.46 of 6See more

aws-ebs-csi-driver deliveryhero 2.17.4

6 of the 6 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
public.ecr.aws/ebs-csi-driver/aws-ebs-csi-driver:v1.16.11564359e1e0e
golang.org/x/net@v0.4.0
stdlib@go1.19.6
0.17.0
1.20.10
public.ecr.aws/eks-distro/kubernetes-csi/external-attacher:v4.1.0-eks-1-25-latest701eea03388c
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.17.0
1.20.10
public.ecr.aws/eks-distro/kubernetes-csi/external-provisioner:v3.4.0-eks-1-25-latest460ee1a59fea
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.17.0
1.20.10
public.ecr.aws/eks-distro/kubernetes-csi/external-resizer:v1.7.0-eks-1-25-lateste711da25e7a0
golang.org/x/net@v0.4.0
stdlib@go1.19.8
0.17.0
1.20.10
public.ecr.aws/eks-distro/kubernetes-csi/livenessprobe:v2.9.0-eks-1-25-latest8a305e162caa
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.17.0
1.20.10
public.ecr.aws/eks-distro/kubernetes-csi/node-driver-registrar:v2.7.0-eks-1-25-latestf4345e67df8f
golang.org/x/net@v0.7.0
stdlib@go1.19.8
0.17.0
1.20.10

Open the chart page →

6,485
loki-simple-scalablegrafana1.8.112 of 3See more

loki-simple-scalable grafana 1.8.11

2 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.18
0.17.0
1.20.10
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.9
0.17.0
1.20.10

Open the chart page →

6,470
prometheus-operatorarldkaVerified publisher13.0.11 of 2See more

prometheus-operator arldka 13.0.1

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.17.0
1.20.10

Open the chart page →

2,107
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
golang.org/x/net@v0.8.0
stdlib@go1.17.1
0.17.0
1.20.10

Open the chart page →

3,004

Container images carrying it

2,183 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0
1
rancher/hardened-flannel:v0.14.1-build20211022d6a47d394c03
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.17.0
1
rancher/k3s:v1.28.2-k3s18c2599ecfca8
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.17.0
1.20.10
1
rancher/k3s:v1.25.3-k3s1eaa270df79cc
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.19.2
0.17.0
1.20.10
1
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19
0.17.0
1.20.10
1
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.16.6
0.17.0
1.20.10
1
rancher/local-path-provisioner:v0.0.22e34c88ae0aff
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
stdlib@go1.16.15
0.17.0
1.20.10
1
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
stdlib@go1.16.4
1.20.10
1
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
stdlib@go1.16.4
1.20.10
1
rclone/rclone:1.63.008e1af3c8814
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.17.0
1.20.10
1
rclone/rclone:1.57.01e6eeabddc01
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.2
0.17.0
1.20.10
1
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
stdlib@go1.16.6
0.17.0
1.20.10
1
redislabs/redisearch:2.4.1433561794c5c8
stdlib@go1.16.7
1.20.10
1
reportportal/migrations:5.7.0da5d8e1395fe
golang.org/x/net@v0.0.0-20190424112056-4829fb13d2c6
stdlib@go1.13.6
0.17.0
1.20.10
1
reportportal/service-index:5.0.112b27a2d7a87d
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
stdlib@go1.17.1
0.17.0
1.20.10
1
restic/restic:0.15.2579e4e6a4931
golang.org/x/net@v0.8.0
stdlib@go1.19.8
0.17.0
1.20.10
1
rezachalak/bzen-mongo:1.0.034f694325191
stdlib@go1.19.12
1.20.10
1
ribbybibby/s3-exporter:v0.5.0998184c51a00
stdlib@go1.15.15
1.20.10
1
richardjennings/opa-nginx:0.0.366424aca125d
stdlib@go1.20.5
1.20.10
1
rimusz/security-sample-app:0.2.0b9a178ca76ef
stdlib@go1.14.4
1.20.10
1
robjuz/postgresql-nominatim:latest805c7bab76df
stdlib@go1.16.5
1.20.10
1
robotshop/rs-dispatch:latestde81f1d07b02
stdlib@go1.17
1.20.10
1
robotshop/rs-mongodb:latest119b545823cd
stdlib@go1.16.3
1.20.10
1
rogerrum/alertmanager-discord:1.0.3827593369625
stdlib@go1.17.4
1.20.10
1
rookout/k8s-operator:latest0d083f3ef1a7
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.15
0.17.0
1.20.10
1
runatlantis/atlantis:v0.16.145fbaf7e207c
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
stdlib@go1.14.7
0.17.0
1.20.10
1
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3ce9ce8293e4e
stdlib@go1.20.1
1.20.10
1
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9bb64bf14467d
stdlib@go1.20.1
1.20.10
1
salaboy/frontend-go-1739aa83b5e69d4ccb8a5615830ae66c1ff7c90845e4
stdlib@go1.20.1
1.20.10
1
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525799c35f9f306
stdlib@go1.20.1
1.20.10
1
samarthya/spinnaker:v1.0ef06d81036af
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
stdlib@go1.17.6
0.17.0
1.20.10
1
sarwansharma/minio:v359d1da9385d1
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
stdlib@go1.18.3
0.17.0
1.20.10
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
stdlib@go1.19.8
1.20.10
1
seafileltd/seafile-mc:9.0.106693911bcc40
stdlib@go1.19
1.20.10
1
seafileltd/seafile-mc:10.0.170628f29c663
stdlib@go1.20
1.20.10
1
seafileltd/seafile-mc:9.0.97ac833196f60
stdlib@go1.19
1.20.10
1
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.17.0
1.20.10
1
selectdb/doris.k8s-operator:1.3.1919210765cb8
golang.org/x/net@v0.10.0
stdlib@go1.19.13
0.17.0
1.20.10
1
semitechnologies/weaviate:1.19.17a00d226f063
golang.org/x/net@v0.7.0
stdlib@go1.19.9
0.17.0
1.20.10
1
sentriz/gonic:v0.13.1a74012a6adf3
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
stdlib@go1.16.4
0.17.0
1.20.10
1
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
stdlib@go1.15.12
0.17.0
1.20.10
1
shyim/shopware:6.4.6.0a951c0e6b836
stdlib@go1.20.7
1.20.10
1
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
golang.org/x/net@v0.1.0
stdlib@go1.19.2
0.17.0
1.20.10
1
signald/signald:0.18.20ffad7ccc2eb
stdlib@go1.18.1
1.20.10
1
signald/signald:0.23.2edbff058278c
stdlib@go1.18.10
1.20.10
1
signoz/alertmanager:0.5.07bc7de2e33c2
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.14
0.17.0
1.20.10
1
sikalabs/slu:v0.34.0fdc0c6711add
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.17.0
1.20.10
1
simonschneider/traefik-jwt-decode:latestd674ac370f80
stdlib@go1.17.13
1.20.10
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.