StackRadar

CVE-2023-39325

High

Advisory

Published 11 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.038
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,887
of 17,790 indexed, latest versions
Container images
2,183
deployed by those charts
Fix available
2 of 3
affected packages

HTTP/2 rapid reset can cause excessive work in net/http

Carried by container images the latest versions of 1,887 of 17,790 indexed charts deploy, on 2,183 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,572
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+109 more1.20.102,132
OSV records
DEBIAN-CVE-2023-39325GHSA-4374-p667-p6c8GO-2023-2102
Also known as
BIT-golang-2023-39325

Charts affected

1,887 by stars
ChartLatestAffected imagesRadar Score
kube-prometheuschoerodon9.3.14 of 7See more

kube-prometheus choerodon 9.3.1

4 of the 7 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.3
0.17.0
1.20.10
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
stdlib@go1.13.11
0.17.0
1.20.10
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/net@v0.0.0-20191003171128-d98b1b443823
stdlib@go1.13.4
0.17.0
1.20.10
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
stdlib@go1.14.3
0.17.0
1.20.10

Open the chart page →

12,251
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.24.061d866e93b56
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.17.0
1.20.10

Open the chart page →

3,048
waypointhashicorpVerified publisher0.1.211 of 2See more

waypoint hashicorp 0.1.21

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
hashicorp/waypoint:0.11.397d521a27498
golang.org/x/net@v0.1.0
stdlib@go1.19.4
0.17.0
1.20.10

Open the chart page →

4,176
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.16.9
0.17.0
1.20.10

Open the chart page →

7,923
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.15.15
0.17.0
1.20.10

Open the chart page →

4,412
dex-k8s-authenticatorsagikazarmarkVerified publisher0.0.31 of 1See more

dex-k8s-authenticator sagikazarmark 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
stdlib@go1.13.11
0.17.0
1.20.10

Open the chart page →

2,791
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
stdlib@go1.18.2
1.20.10

Open the chart page →

3,041
kubeviewcowboysysopVerified publisher6.0.01 of 1See more

kubeview cowboysysop 6.0.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/benc-uk/kubeview:0.1.31f8e7cd7325a3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
stdlib@go1.17.2
0.17.0
1.20.10

Open the chart page →

1,513
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
stdlib@go1.18.3
1.20.10

Open the chart page →

4,641
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
stdlib@go1.14.4
1.20.10

Open the chart page →

4,577
devtron-operatordevtron0.23.36 of 11See more

devtron-operator devtron 0.23.3

6 of the 11 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.18.2
0.17.0
1.20.10
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
stdlib@go1.16.6
0.17.0
1.20.10
quay.io/devtron/kubectl:latest2ad610626658
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.5
0.17.0
1.20.10
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
stdlib@go1.19.9
0.17.0
1.20.10
quay.io/devtron/postgres:14.91b594392f7cb
stdlib@go1.18.2
1.20.10
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.17.6
0.17.0
1.20.10

Open the chart page →

33,180
drone-runner-kubedroneVerified publisher0.1.101 of 1See more

drone-runner-kube drone 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.15
0.17.0
1.20.10

Open the chart page →

2,067
ilumilumOfficialVerified publisher6.7.31 of 19See more

ilum ilum 6.7.3

1 of the 19 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/net@v0.8.0
stdlib@go1.20.3
0.17.0
1.20.10

Open the chart page →

23,362
temporallemontechVerified publisher0.37.06 of 13See more

temporal lemontech 0.37.0

6 of the 13 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.13.4
0.17.0
1.20.10
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.20.10
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.16.9
0.17.0
1.20.10
temporalio/server:1.22.4c0a44c26397b
golang.org/x/net@v0.7.0
0.17.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
stdlib@go1.16.7
0.17.0
1.20.10
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
stdlib@go1.17.3
0.17.0
1.20.10

Open the chart page →

14,916
netris-controllernetrisai2.8.25 of 14See more

netris-controller netrisai 2.8.2

5 of the 14 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
stdlib@go1.13.11
0.17.0
1.20.10
haproxytech/haproxy-alpine:2.8.08951be4b4e1c
golang.org/x/net@v0.11.0
stdlib@go1.20.5
0.17.0
1.20.10
netrisai/controller-web-session-generator:0.2.0a030a31289f4
stdlib@go1.14.15
1.20.10
netrisai/mariadb:10.11.4-debian-11-r460aa742a0b906
stdlib@go1.19.11
1.20.10
netrisai/mongodb:4.4.4-debian-10-r095abfb776bb4
stdlib@go1.15.1
1.20.10

Open the chart page →

30,504
nfs-server-provisionernfs-ganesha-server-and-external-provisioner1.8.01 of 1See more

nfs-server-provisioner nfs-ganesha-server-and-external-provisioner 1.8.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
stdlib@go1.16.2
0.17.0
1.20.10

Open the chart page →

2,315
syftopenmined0.9.53 of 6See more

syft openmined 0.9.5

3 of the 6 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
stdlib@go1.18.2
1.20.10
library/registry:2a3d8aaa63ed8
stdlib@go1.20.8
1.20.10
openmined/syft-frontend:0.9.5d11524a3854a
stdlib@go1.20.5
1.20.10

Open the chart page →

17,370
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.17.0
1.20.10
platform9community/api-gateway:latest40a4970de568
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.17.0
1.20.10
platform9community/customers-service:latest2089811e5cc6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.17.0
1.20.10
platform9community/vets-service:latestd1165c94dfb3
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.15.11
0.17.0
1.20.10
platform9community/visits-service:latest8d11b50368c6
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.4
0.17.0
1.20.10

Open the chart page →

41,926
helm-exportersstarcher0.5.01 of 1See more

helm-exporter sstarcher 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
sstarcher/helm-exporter:0.5.011769d01ba35
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
stdlib@go1.13.6
0.17.0
1.20.10

Open the chart page →

4,162
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
golang.org/x/net@v0.10.0
stdlib@go1.20.6
0.17.0
1.20.10

Open the chart page →

5,679
passboltcnieg1.1.171 of 2See more

passbolt cnieg 1.1.17

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
passbolt/passbolt:3.4.0-ce-non-root655547e17263
stdlib@go1.14.4
1.20.10

Open the chart page →

3,544
dronecommunity-chartsVerified publisher0.1.51 of 2See more

drone community-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.16.15
0.17.0
1.20.10

Open the chart page →

2,736
uptime-kumaduyet0.1.71 of 1See more

uptime-kuma duyet 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.18.5a84767d7934f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
stdlib@go1.18.5
0.17.0
1.20.10

Open the chart page →

4,522
emqx-operatoremqx-operator2.3.21 of 2See more

emqx-operator emqx-operator 2.3.2

1 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
alpine/k8s:1.31.49c4976d47656
golang.org/x/net@v0.12.0
stdlib@go1.20.5
0.17.0
1.20.10

Open the chart page →

4,548
kube-routerenixVerified publisher1.10.01 of 1See more

kube-router enix 1.10.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
golang.org/x/net@v0.4.0
stdlib@go1.19.5
0.17.0
1.20.10

Open the chart page →

2,351
logging-operatorkube-loggingVerified publisher4.2.31 of 1See more

logging-operator kube-logging 4.2.3

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/kube-logging/logging-operator:4.2.20dd85dcb1f73
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.17.0
1.20.10

Open the chart page →

880
missing-container-metricsmissing-container-metrics0.1.11 of 1See more

missing-container-metrics missing-container-metrics 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.2
0.17.0
1.20.10

Open the chart page →

2,418
rekorsigstoreVerified publisher1.8.62 of 9See more

rekor sigstore 1.8.6

2 of the 9 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
library/redisdigest-pinned148bb5411c18
stdlib@go1.18.2
1.20.10
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.20.10

Open the chart page →

5,373
uffizzi-controlleruffizzi-controller2.4.62 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

2 of the 11 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
golang.org/x/net@v0.12.0
stdlib@go1.20.1
0.17.0
1.20.10
uffizzi/uffizzi-cluster-operator:v1.6.55ca448a08783
golang.org/x/net@v0.8.0
stdlib@go1.19.13
0.17.0
1.20.10

Open the chart page →

14,327
filebrowserutkuozdemirVerified publisher1.0.01 of 1See more

filebrowser utkuozdemir 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.3
0.17.0
1.20.10

Open the chart page →

3,073
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.11.11da5c38c6a78
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
stdlib@go1.14.12
0.17.0
1.20.10

Open the chart page →

6,177
aad-pod-identityaad-pod-identity4.1.182 of 2See more

aad-pod-identity aad-pod-identity 4.1.18

2 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/azure/aad-pod-identity/mic:v1.8.173004b93fcb74
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.17.0
1.20.10
mcr.microsoft.com/oss/azure/aad-pod-identity/nmi:v1.8.1777788bf38938
golang.org/x/net@v0.7.0
stdlib@go1.19.10
0.17.0
1.20.10

Open the chart page →

2,858
mysql-operatorbitpokeVerified publisher0.6.32 of 2See more

mysql-operator bitpoke 0.6.3

2 of the 2 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
stdlib@go1.17.13
0.17.0
1.20.10
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.17.0
1.20.10

Open the chart page →

3,354
cadvisorcadvisorVerified publisher0.1.151 of 1See more

cadvisor cadvisor 0.1.15

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
golang.org/x/net@v0.8.0
stdlib@go1.19.9
0.17.0
1.20.10

Open the chart page →

1,705
cert-manager-webhook-hetznercert-manager-webhook-hetznerVerified publisher0.2.11 of 1See more

cert-manager-webhook-hetzner cert-manager-webhook-hetzner 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
stdlib@go1.16.7
0.17.0
1.20.10

Open the chart page →

3,087
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
grafana/grafana:7.3.5511bc20bfcd1
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
stdlib@go1.15.5
0.17.0
1.20.10
library/traefik:2.5.47d0228d19042
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
stdlib@go1.17.3
0.17.0
1.20.10

Open the chart page →

53,052
immudbcodenotaryVerified publisher1.9.71 of 1See more

immudb codenotary 1.9.7

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
codenotary/immudb:1.9.77c85d7cc4f22
stdlib@go1.18.10
1.20.10

Open the chart page →

1,254
csi-wekafsplugincsi-wekafsOfficialVerified publisher0.6.2-01 of 6See more

csi-wekafsplugin csi-wekafs 0.6.2-0

1 of the 6 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
stdlib@go1.13.3
0.17.0
1.20.10

Open the chart page →

2,831
daskhubdask2024.1.11 of 9See more

daskhub dask 2024.1.1

1 of the 9 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
quay.io/jupyterhub/k8s-image-awaiter:3.2.1f65b644ed6db
stdlib@go1.18.10
1.20.10

Open the chart page →

14,151
seafiledatamateVerified publisher0.6.01 of 6See more

seafile datamate 0.6.0

1 of the 6 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
datamate/seafile-professional:11.0.202dd66b722464
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

27,426
drone-runner-dockerdroneVerified publisher0.7.02 of 3See more

drone-runner-docker drone 0.7.0

2 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
drone/drone-runner-docker:1.8.1137e79c5e23c
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
stdlib@go1.16.15
0.17.0
1.20.10
library/docker:20-dindaf96c680a7e1
golang.org/x/net@v0.4.0
stdlib@go1.19.7
0.17.0
1.20.10

Open the chart page →

5,690
loadtesterflagger0.39.01 of 1See more

loadtester flagger 0.39.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.0.0-20181017193950-04a2e542c03f
0.17.0

Open the chart page →

1,767
flyteflyte1.16.81 of 11See more

flyte flyte 1.16.8

1 of the 11 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.1
0.17.0
1.20.10

Open the chart page →

3,282
lndfold0.3.153 of 4See more

lnd fold 0.3.15

3 of the 4 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.16.4-beta-c287129953689
golang.org/x/net@v0.8.0
stdlib@go1.21.0
0.17.0
1.20.10
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
stdlib@go1.13.12
0.17.0
1.20.10
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
stdlib@go1.14.12
0.17.0
1.20.10

Open the chart page →

8,854
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
stdlib@go1.15.10
0.17.0
1.20.10

Open the chart page →

1,745
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
stdlib@go1.20.7
1.20.10

Open the chart page →

9,557
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
stdlib@go1.15.2
1.20.10

Open the chart page →

6,350
percona-xtradb-clusterkfirfer1.5.101 of 3See more

percona-xtradb-cluster kfirfer 1.5.10

1 of the 3 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster:8.0.32-24.21f978ab8912e
stdlib@go1.19.9
1.20.10

Open the chart page →

4,956
permission-managerkfirfer1.0.71 of 1See more

permission-manager kfirfer 1.0.7

1 of the 1 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.16.8
0.17.0
1.20.10

Open the chart page →

2,266
kubeflowkubeflow1.6.226 of 45See more

kubeflow kubeflow 1.6.2

26 of the 45 container images this version deploys carry CVE-2023-39325.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.13
0.17.0
1.20.10
istio/proxyv2:1.14.1df69c1a7af7c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.18.2
0.17.0
1.20.10
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/net@v0.0.0-20211205041911-012df41ee64c
stdlib@go1.17.7
0.17.0
1.20.10
kubeflow/training-operator:v1-e1434f6ff847e2b6af0
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
stdlib@go1.17.11
0.17.0
1.20.10
kubeflownotebookswg/kfam:v1.6.1f226fb44db57
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
stdlib@go1.17.13
0.17.0
1.20.10
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.17.0
1.20.10
kubeflownotebookswg/poddefaults-webhook:v1.6.17d42600e1524
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.13
0.17.0
1.20.10
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.13
0.17.0
1.20.10
kubeflownotebookswg/tensorboard-controller:v1.6.182ffdd2da285
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
stdlib@go1.17.13
0.17.0
1.20.10
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.16.7
0.17.0
1.20.10
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.17.0
1.20.10
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.6
0.17.0
1.20.10
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.17.0
1.20.10
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.17.0
1.20.10
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.17.0
1.20.10
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.17.0
1.20.10
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.17.0
1.20.10
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
stdlib@go1.17.8
0.17.0
1.20.10
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.17.0
1.20.10
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.17.0
1.20.10
gcr.io/ml-pipeline/mysql:5.7-debiandf28187b5455
stdlib@go1.16.7
1.20.10
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.17.0
1.20.10
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.17.0
1.20.10
gcr.io/ml-pipeline/viewer-crd-controller:2.0.0-alpha.534403f9f94be
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.6
0.17.0
1.20.10
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
stdlib@go1.17.11
0.17.0
1.20.10
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
stdlib@go1.13.10
0.17.0
1.20.10

Open the chart page →

97,217

Container images carrying it

2,183 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
stdlib@go1.20.7
1.20.10
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
stdlib@go1.20.7
1.20.10
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
stdlib@go1.20.7
1.20.10
1
ghcr.io/keptn/certificate-operator:v1.1.08fdd311a6d33
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.17.0
1.20.10
1
ghcr.io/keptn/lifecycle-operator:v0.8.2487bfc37c4b4
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.17.0
1.20.10
1
ghcr.io/keptn/metrics-operator:v0.8.2acf22310e9dd
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.17.0
1.20.10
1
ghcr.io/keptn/scheduler:v0.8.20f7d277bb2b2
golang.org/x/net@v0.14.0
stdlib@go1.20.4
0.17.0
1.20.10
1
ghcr.io/kiaedev/kiae:latestebd03028ff6a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
stdlib@go1.18.9
0.17.0
1.20.10
1
ghcr.io/kore3lab/kore-board.backend:v0.5.5455f6e7a26fd
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.19.4
0.17.0
1.20.10
1
ghcr.io/kore3lab/kore-board.metrics-scraper:v0.5.547f88b18fb7c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
stdlib@go1.19.4
0.17.0
1.20.10
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.9
0.17.0
1.20.10
1
ghcr.io/kubedb/kubedb-dashboard:v0.16.07bfe1c07bd9b
stdlib@go1.20.7
1.20.10
1
ghcr.io/kubedb/kubedb-schema-manager:v0.16.09518de37eed5
stdlib@go1.20.7
1.20.10
1
ghcr.io/kubedb/provider-aws:v0.27.049b1c312e342
golang.org/x/net@v0.7.0
stdlib@go1.20.7
0.17.0
1.20.10
1
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.19.3
0.17.0
1.20.10
1
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
golang.org/x/net@v0.9.0
stdlib@go1.19.1
0.17.0
1.20.10
1
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
golang.org/x/net@v0.10.0
stdlib@go1.19.1
0.17.0
1.20.10
1
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
stdlib@go1.20.5
0.17.0
1.20.10
1
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
golang.org/x/net@v0.9.0
stdlib@go1.19.9
0.17.0
1.20.10
1
ghcr.io/kube-logging/log-generator:v0.4.105aa441b20aa
stdlib@go1.20.1
1.20.10
1
ghcr.io/kube-logging/log-generator:v0.6.08324bbc0ec08
golang.org/x/net@v0.7.0
stdlib@go1.20.4
0.17.0
1.20.10
1
ghcr.io/kube-logging/logging-operator:4.2.20dd85dcb1f73
golang.org/x/net@v0.10.0
stdlib@go1.20.5
0.17.0
1.20.10
1
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
golang.org/x/net@v0.7.0
stdlib@go1.19.7
0.17.0
1.20.10
1
ghcr.io/kvaps/kube-fencing-controller:v2.4.0313edfec2fca
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
stdlib@go1.18.8
0.17.0
1.20.10
1
ghcr.io/kvaps/kube-fencing-switcher:v2.4.0f8c378e63b78
stdlib@go1.18.8
1.20.10
1
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.15.14
0.17.0
1.20.10
1
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
stdlib@go1.15.14
0.17.0
1.20.10
1
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
stdlib@go1.15.14
0.17.0
1.20.10
1
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
stdlib@go1.15.14
0.17.0
1.20.10
1
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.9
0.17.0
1.20.10
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
stdlib@go1.17.9
0.17.0
1.20.10
1
ghcr.io/kyverno/policy-reporter:2.14.1e74c6bf33d1b
golang.org/x/net@v0.8.0
stdlib@go1.19.7
0.17.0
1.20.10
1
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
stdlib@go1.21.1
1.20.10
1
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
stdlib@go1.21.1
1.20.10
1
ghcr.io/leoquote/tencentcloud-exporter:masterca51b6bb15dd
stdlib@go1.21.1
1.20.10
1
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
stdlib@go1.18.3
0.17.0
1.20.10
1
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
stdlib@go1.17.10
0.17.0
1.20.10
1
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
stdlib@go1.17.7
0.17.0
1.20.10
1
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
stdlib@go1.17.7
0.17.0
1.20.10
1
ghcr.io/linuxserver/calibre-web:0.6.267c0464228f2f
stdlib@go1.17.8
1.20.10
1
ghcr.io/lldap/lldap:2025-05-193de697c3ba57
stdlib@go1.18.2
1.20.10
1
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/net@v0.14.0
stdlib@go1.21.0
0.17.0
1.20.10
1
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/net@v0.6.0
stdlib@go1.18.10
0.17.0
1.20.10
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.17.0
1.20.10
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
golang.org/x/net@v0.14.0
stdlib@go1.20.7
0.17.0
1.20.10
1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/net@v0.13.0
stdlib@go1.20.8
0.17.0
1.20.10
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/net@v0.8.0
stdlib@go1.20.5
0.17.0
1.20.10
1
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
stdlib@go1.16.15
0.17.0
1.20.10
1
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
stdlib@go1.18.5
0.17.0
1.20.10
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
stdlib@go1.19.8
1.20.10
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.