StackRadar

CVE-2023-39326

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,905
of 17,803 indexed, latest versions
Container images
2,219
deployed by those charts
Fix available
2 of 3
affected packages

Red Hat Security Advisory: skopeo security update

Carried by container images the latest versions of 1,905 of 17,803 indexed charts deploy, on 2,219 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
skopeorpm2:1.11.2-0.1.el92:1.13.3-4.el9_31
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+114 more1.20.122,219
OSV records
DEBIAN-CVE-2023-39326RHSA-2024:1149GO-2023-2382
Also known as
BIT-golang-2023-39326

Charts affected

1,905 by stars
ChartLatestAffected imagesRadar Score
presto-loadbalancerpresto-loadbalancer0.1.161 of 1See more

presto-loadbalancer presto-loadbalancer 0.1.16

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
garugaru/presto-loadbalancer:v0.1.589d66d117029
stdlib@go1.15.2
1.20.12

Open the chart page →

2,526
rds-exporterpresto-loadbalancer0.0.21 of 1See more

rds-exporter presto-loadbalancer 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
garugaru/aws-cloudwatch-exporter:latest541852cafda5
stdlib@go1.16.15
1.20.12

Open the chart page →

1,086
trino-exporterpresto-loadbalancer0.0.121 of 1See more

trino-exporter presto-loadbalancer 0.0.12

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
datappeal/trino-exporter:latest325b91c2b09e
stdlib@go1.16.15
1.20.12

Open the chart page →

1,969
trino-loadbalancerpresto-loadbalancer0.3.11 of 1See more

trino-loadbalancer presto-loadbalancer 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
datappeal/trino-loadbalancer:sha-950abbae6b5b9fdb2e6d
stdlib@go1.17.13
1.20.12

Open the chart page →

2,358
priceapp-chartpriceapp0.1.01 of 1See more

priceapp-chart priceapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ildarmukhametzyanov/priceapp:0.115d23720a3ee
stdlib@go1.21.1
1.20.12

Open the chart page →

8,254
primeprime1.0.01 of 1See more

prime prime 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
udhos/prime:1.0.0e432012dd34a
stdlib@go1.20.4
1.20.12

Open the chart page →

1,682
procestypecatalogusprocestypecatalogus1.1.01 of 4See more

procestypecatalogus procestypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
stdlib@go1.13.10
1.20.12

Open the chart page →

7,441
productenendienstencatalogusproductenendienstencatalogus1.0.01 of 3See more

productenendienstencatalogus productenendienstencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
stdlib@go1.13.10
1.20.12

Open the chart page →

7,520
wp-chartprojet-devops0.1.01 of 2See more

wp-chart projet-devops 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.20.12

Open the chart page →

5,316
jiralertprometheus-communityVerified publisher1.9.01 of 1See more

jiralert prometheus-community 1.9.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
quay.io/jiralert/jiralert-linux-amd64:v1.3.01983aa64761a
stdlib@go1.19.6
1.20.12

Open the chart page →

728
prometheus-couchdb-exporterprometheus-communityVerified publisher1.1.01 of 1See more

prometheus-couchdb-exporter prometheus-community 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
gesellix/couchdb-prometheus-exporter:v286266d063f5d5
stdlib@go1.13.13
1.20.12

Open the chart page →

1,300
prometheus-modbus-exporterprometheus-communityVerified publisher0.1.41 of 1See more

prometheus-modbus-exporter prometheus-community 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
openenergyprojects/modbus_exporter:20230617_a14455158990f24fb25
stdlib@go1.20.5
1.20.12

Open the chart page →

1,209
prometheus-optimizerprometheus-optimizer0.2.221 of 1See more

prometheus-optimizer prometheus-optimizer 0.2.22

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
stdlib@go1.21.4
1.20.12

Open the chart page →

4,468
alertmanagerprometheus-worawutchan0.3.01 of 1See more

alertmanager prometheus-worawutchan 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.20.12

Open the chart page →

2,306
prometheus-blackbox-exporterprometheus-worawutchan4.10.11 of 1See more

prometheus-blackbox-exporter prometheus-worawutchan 4.10.1

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.18.01ffc3f109eb3
stdlib@go1.15.2
1.20.12

Open the chart page →

2,250
prometheus-druid-exporterprometheus-worawutchan0.9.01 of 1See more

prometheus-druid-exporter prometheus-worawutchan 0.9.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
quay.io/opstree/druid-exporter:v0.83f6d9885cfe2
stdlib@go1.14.6
1.20.12

Open the chart page →

2,090
prometheus-node-exporterprometheus-worawutchan1.12.01 of 1See more

prometheus-node-exporter prometheus-worawutchan 1.12.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.20.12

Open the chart page →

2,188
prometheus-pushgatewayprometheus-worawutchan1.5.01 of 1See more

prometheus-pushgateway prometheus-worawutchan 1.5.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
prom/pushgateway:v1.3.0c0d39b8d4cfe
stdlib@go1.15.2
1.20.12

Open the chart page →

1,286
prometheus-redis-exporterprometheus-worawutchan4.0.01 of 1See more

prometheus-redis-exporter prometheus-worawutchan 4.0.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.11.104d958d209ab
stdlib@go1.15
1.20.12

Open the chart page →

1,315
prometheus-statsd-exporterprometheus-worawutchan0.1.01 of 1See more

prometheus-statsd-exporter prometheus-worawutchan 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.18.0d23aca343b86
stdlib@go1.14.7
1.20.12

Open the chart page →

1,315
panproto-application-nldesign0.1.01 of 5See more

pan proto-application-nldesign 0.1.0

1 of the 5 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
conduction/pan-php:dev24f03c57568f
stdlib@go1.13.10
1.20.12

Open the chart page →

8,735
proto-component-commongroundproto-component-commonground1.0.01 of 3See more

proto-component-commonground proto-component-commonground 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
stdlib@go1.13.10
1.20.12

Open the chart page →

7,520
kspanpuckpuck0.2.41 of 1See more

kspan puckpuck 0.2.4

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
stdlib@go1.20.1
1.20.12

Open the chart page →

1,688
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
stdlib@go1.19.13
1.20.12

Open the chart page →

4,662
seashellpuckpuck1.2.01 of 1See more

seashell puckpuck 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/puckpuck/seashell:1.2ef5e31333821
stdlib@go1.20.10
1.20.12

Open the chart page →

4,221
pumperlypumperlyVerified publisher0.1.21 of 3See more

pumperly pumperly 0.1.2

1 of the 3 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
postgis/postgis:17-3.4-alpine5a1dbedac34e
stdlib@go1.18.2
1.20.12

Open the chart page →

2,856
cdmswebapppyalive-cdmswebappVerified publisher0.1.02 of 3See more

cdmswebapp pyalive-cdmswebapp 0.1.0

2 of the 3 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.20.12
sarwansharma/minio:v359d1da9385d1
stdlib@go1.18.3
1.20.12

Open the chart page →

6,702
loki-stackpyalive-cdmswebappVerified publisher2.6.52 of 4See more

loki-stack pyalive-cdmswebapp 2.6.5

2 of the 4 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
grafana/loki:2.5.0f9ef133793af
stdlib@go1.17.8
1.20.12
grafana/promtail:2.4.2626900031c4e
stdlib@go1.17.2
1.20.12

Open the chart page →

6,584
cf-operatorquarks2.3.0+0.g27a91cdf2 of 2See more

cf-operator quarks 2.3.0+0.g27a91cdf

2 of the 2 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
stdlib@go1.13.3
1.20.12
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
stdlib@go1.13.4
1.20.12

Open the chart page →

11,956
quarksquarks7.0.1+0.g5396b114 of 5See more

quarks quarks 7.0.1+0.g5396b11

4 of the 5 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
stdlib@go1.14.7
1.20.12
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
stdlib@go1.13.15
1.20.12
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
stdlib@go1.14.7
1.20.12
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
stdlib@go1.14.7
1.20.12

Open the chart page →

18,202
quarks-statefulsetquarks0.0.1304-g4b4f2ac51 of 1See more

quarks-statefulset quarks 0.0.1304-g4b4f2ac5

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
stdlib@go1.14.7
1.20.12

Open the chart page →

4,011
ingress-controllerqumine0.8.5001 of 1See more

ingress-controller qumine 0.8.500

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
qumine/ingress-controller:v0.8.5f2c8a2148381
stdlib@go1.19
1.20.12

Open the chart page →

1,533
cupsr2dlan-helm-chartsVerified publisher0.1.01 of 1See more

cups r2dlan-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
anujdatar/cups:25.07.01685df04a643b
stdlib@go1.19.8
1.20.12

Open the chart page →

7,847
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v3.6.96fa9042f6128
stdlib@go1.20.6
1.20.12

Open the chart page →

21,370
saleorrc-helm-charts0.1.11 of 5See more

saleor rc-helm-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.22.0ca6b73330616
stdlib@go1.15.8
1.20.12

Open the chart page →

3,746
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
stdlib@go1.15.14
1.20.12

Open the chart page →

15,300
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
stdlib@go1.15.14
1.20.12

Open the chart page →

15,300
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
stdlib@go1.15.14
1.20.12

Open the chart page →

11,447
sonatype-nexusredhat-cop1.1.131 of 2See more

sonatype-nexus redhat-cop 1.1.13

1 of the 2 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
stdlib@go1.21.3
1.20.12

Open the chart page →

16,391
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
stdlib@go1.16
1.20.12

Open the chart page →

29,584
redisredis-arm17.8.01 of 1See more

redis redis-arm 17.8.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/zcube/bitnami-compat/redis:7.0-debian-11-r55118a403046f7
stdlib@go1.19.4
1.20.12

Open the chart page →

1,906
registry-credsregistry-creds0.2.31 of 1See more

registry-creds registry-creds 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/alexellis/registry-creds:0.3.2-rc1f5c72501e559
stdlib@go1.19.5
1.20.12

Open the chart page →

1,042
reporting-chartreporting-application0.1.01 of 1See more

reporting-chart reporting-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ibarreche/cloud-reporting-ci:latest1f45af91da6a
stdlib@go1.16.15
1.20.12

Open the chart page →

1,585
reportportalreportportal5.7.22 of 8See more

reportportal reportportal 5.7.2

2 of the 8 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
reportportal/migrations:5.7.0da5d8e1395fe
stdlib@go1.13.6
1.20.12
reportportal/service-index:5.0.112b27a2d7a87d
stdlib@go1.17.1
1.20.12

Open the chart page →

25,720
resource-manager-operatorresource-manager-operator0.1.01 of 1See more

resource-manager-operator resource-manager-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/tikalk/resource-manager:latest7f21d50e69cb
stdlib@go1.19
1.20.12

Open the chart page →

1,624
spoolmanretsamedocVerified publisher26.9.01 of 1See more

spoolman retsamedoc 26.9.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
stdlib@go1.19.8
1.20.12

Open the chart page →

1,823
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
stdlib@go1.13.10
1.20.12

Open the chart page →

7,502
whoamirgnu1.0.01 of 1See more

whoami rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
traefik/whoami:v1.6.0d38496bf0900
stdlib@go1.15.2
1.20.12

Open the chart page →

1,229
security-sample-chartrimusz0.2.11 of 3See more

security-sample-chart rimusz 0.2.1

1 of the 3 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
rimusz/security-sample-app:0.2.0b9a178ca76ef
stdlib@go1.14.4
1.20.12

Open the chart page →

1,348
backup-maker-controllerriotkit-org0.1.21 of 1See more

backup-maker-controller riotkit-org 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/backup-maker-controller:v0.1.262370545ba3d
stdlib@go1.19.4
1.20.12

Open the chart page →

1,576

Container images carrying it

2,219 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
stdlib@go1.19
1.20.12
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.0cd21e19cd8bb
stdlib@go1.20.5
1.20.12
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.20.12
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
stdlib@go1.19
1.20.12
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
stdlib@go1.18
1.20.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.20.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
stdlib@go1.18
1.20.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.20.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.20.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.20.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.20.12
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.20.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.20.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.20.12
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.20.12
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.20.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.20.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.20.12
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.20.12
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.