StackRadar

CVE-2023-39326

Medium

Advisory

Published 6 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,904
of 17,792 indexed, latest versions
Container images
2,218
deployed by those charts
Fix available
2 of 3
affected packages

Red Hat Security Advisory: skopeo security update

Carried by container images the latest versions of 1,904 of 17,792 indexed charts deploy, on 2,218 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
skopeorpm2:1.11.2-0.1.el92:1.13.3-4.el9_31
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+113 more1.20.122,218
OSV records
DEBIAN-CVE-2023-39326RHSA-2024:1149GO-2023-2382
Also known as
BIT-golang-2023-39326

Charts affected

1,904 by stars
ChartLatestAffected imagesRadar Score
hlf-peerowkin5.1.01 of 1See more

hlf-peer owkin 5.1.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
hyperledger/fabric-peer:2.2.1bf4995c86af6
stdlib@go1.14.4
1.20.12

Open the chart page →

3,695
prometheus-cachethqoxyno-zetaVerified publisher1.1.11 of 1See more

prometheus-cachethq oxyno-zeta 1.1.1

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
oxynozeta/prometheus-cachethq:1.1.131f11669d597
stdlib@go1.15.1
1.20.12

Open the chart page →

1,714
ngrok-operatorpaganuzzi0.0.21 of 1See more

ngrok-operator paganuzzi 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/paganuzzi/ngrokoperator:latest5a10cd095699
stdlib@go1.15.12
1.20.12

Open the chart page →

2,811
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
stdlib@go1.20.5
1.20.12

Open the chart page →

6,897
patch-operatorpatch-operator0.1.111 of 2See more

patch-operator patch-operator 0.1.11

1 of the 2 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
stdlib@go1.15.15
1.20.12

Open the chart page →

7,840
pdf-editor-helmpdf-editor-web1.0.02 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

2 of the 4 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-backend-rotate316e203b8bf5
stdlib@go1.18.7
1.20.12
dipugodocker/pdf-editor:1.0-backend-merge70b07544a604
stdlib@go1.18.7
1.20.12

Open the chart page →

4,209
spirephilips-labsVerified publisher0.12.25 of 6See more

spire philips-labs 0.12.2

5 of the 6 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
stdlib@go1.20.1
1.20.12
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
stdlib@go1.20.1
1.20.12
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
stdlib@go1.20.1
1.20.12
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
stdlib@go1.20.1
1.20.12
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
stdlib@go1.19
1.20.12

Open the chart page →

7,269
chartmuseumphntom4.0.201 of 1See more

chartmuseum phntom 4.0.20

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
phntom/chartmuseum:v0.16.053883b65d9b7
stdlib@go1.19.3
1.20.12

Open the chart page →

2,948
phonebook-chartphonebook-chart0.1.01 of 3See more

phonebook-chart phonebook-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.20.12

Open the chart page →

3,032
phpipamphpipam-helmVerified publisher1.0.121 of 3See more

phpipam phpipam-helm 1.0.12

1 of the 3 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.20.12

Open the chart page →

3,778
pipelinewise-operatorpipelinewise-operatorVerified publisher0.5.11 of 1See more

pipelinewise-operator pipelinewise-operator 0.5.1

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
stdlib@go1.15.8
1.20.12

Open the chart page →

2,121
secrets-store-csi-driver-provider-awsportefaix-hub0.4.01 of 1See more

secrets-store-csi-driver-provider-aws portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Open the chart page →

2,213
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.20.12

Open the chart page →

32,112
postgres-backuppostgres-backup0.3.02 of 2See more

postgres-backup postgres-backup 0.3.0

2 of the 2 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.20.12
nerzhul/mc-arm64:2020.10.034215df511f31
stdlib@go1.15.2
1.20.12

Open the chart page →

5,469
rethinkdbpozetron1.1.91 of 1See more

rethinkdb pozetron 1.1.9

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
stdlib@go1.16.9
1.20.12

Open the chart page →

2,912
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.20.12

Open the chart page →

5,503
prometheus-druid-exporterprometheus-communityVerified publisher1.2.01 of 1See more

prometheus-druid-exporter prometheus-community 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
quay.io/opstree/druid-exporter:v0.119f01c9c5c2e3
stdlib@go1.15.15
1.20.12

Open the chart page →

1,179
prometheusprometheus-worawutchan13.0.05 of 6See more

prometheus prometheus-worawutchan 13.0.0

5 of the 6 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.20.12
prom/pushgateway:v1.3.0c0d39b8d4cfe
stdlib@go1.15.2
1.20.12
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.20.12
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.20.12
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
stdlib@go1.15.3
1.20.12

Open the chart page →

9,948
kubernetes-dashboardpyalive-cdmswebappVerified publisher5.8.01 of 1See more

kubernetes-dashboard pyalive-cdmswebapp 5.8.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.6.1290bebc3cd96
stdlib@go1.19
1.20.12

Open the chart page →

1,662
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
stdlib@go1.14.2
1.20.12

Open the chart page →

24,012
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
stdlib@go1.19.4
1.20.12

Open the chart page →

6,914
velero-s3-deploymentradar-baseVerified publisher0.4.22 of 4See more

velero-s3-deployment radar-base 0.4.2

2 of the 4 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
velero/velero:v1.9.0277fbfaf8dcf
stdlib@go1.18
1.20.12
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
stdlib@go1.17.11
1.20.12

Open the chart page →

4,819
docker-registry-mirrorregistry-mirror1.0.11 of 1See more

docker-registry-mirror registry-mirror 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.20.12

Open the chart page →

550
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.20.12

Open the chart page →

6,643
backup-repository-serverriotkit-org4.0.01 of 1See more

backup-repository-server riotkit-org 4.0.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
stdlib@go1.17.13
1.20.12

Open the chart page →

2,056
cloudflare-tunnelrlex0.8.01 of 1See more

cloudflare-tunnel rlex 0.8.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2023.10.0c18744ae1767
stdlib@go1.20.6
1.20.12

Open the chart page →

1,691
hcloud-fip-controllerrlex0.2.51 of 1See more

hcloud-fip-controller rlex 0.2.5

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
stdlib@go1.15.3
1.20.12

Open the chart page →

2,963
prometheus-webhook-dingtalkrlex0.0.31 of 1See more

prometheus-webhook-dingtalk rlex 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
stdlib@go1.13.5
1.20.12

Open the chart page →

1,852
kimai2robjuz5.0.141 of 2See more

kimai2 robjuz 5.0.14

1 of the 2 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:10.6.12-debian-11-r1678847062532a
stdlib@go1.19.7
1.20.12

Open the chart page →

4,721
grafanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

grafana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
grafana/grafana:8.3.4cf81d2c753c8
stdlib@go1.17.6
1.20.12

Open the chart page →

2,842
jaeger-collectorromanow-helm-chartsVerified publisher1.5.01 of 1See more

jaeger-collector romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
stdlib@go1.19.4
1.20.12

Open the chart page →

1,861
jaeger-queryromanow-helm-chartsVerified publisher1.5.01 of 1See more

jaeger-query romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
jaegertracing/jaeger-query:1.41.0b636f0f464bc
stdlib@go1.19.4
1.20.12

Open the chart page →

1,804
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
stdlib@go1.19.3
1.20.12

Open the chart page →

7,579
routehub-client-hubroutehub-helm1.0.02 of 3See more

routehub-client-hub routehub-helm 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
stdlib@go1.16.7
1.20.12
timescale/timescaledb-ha:pg16d7db8f1085a3
stdlib@go1.18.1
1.20.12

Open the chart page →

13,046
rabbitmq-operatorsagikazarmarkVerified publisher0.0.31 of 1See more

rabbitmq-operator sagikazarmark 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
stdlib@go1.17
1.20.12

Open the chart page →

2,001
conference-appsalaboy1.0.04 of 7See more

conference-app salaboy 1.0.0

4 of the 7 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
salaboy/agenda-service-0967b907d9920c99918e2b91b91937b3digest-pinnedce9ce8293e4e
stdlib@go1.20.1
1.20.12
salaboy/c4p-service-a3dc0474cbfa348afcdf47a8eee70ba9digest-pinnedbb64bf14467d
stdlib@go1.20.1
1.20.12
salaboy/frontend-go-1739aa83b5e69d4ccb8a5615830ae66cdigest-pinned1ff7c90845e4
stdlib@go1.20.1
1.20.12
salaboy/notifications-service-0e27884e01429ab7e350cb5dff61b525digest-pinned799c35f9f306
stdlib@go1.20.1
1.20.12

Open the chart page →

11,052
ntfysarab97Verified publisher0.1.71 of 1See more

ntfy sarab97 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.6.283e2e43d9956
stdlib@go1.20.5
1.20.12

Open the chart page →

1,772
uptime-kumasb-helm-charts0.4.01 of 1See more

uptime-kuma sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.24c364ef96aad
stdlib@go1.20.5
1.20.12

Open the chart page →

38,479
scienceboxsciencebox0.0.72 of 17See more

sciencebox sciencebox 0.0.7

2 of the 17 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
cs3org/revad:v1.19.03b57a34a7dfd
stdlib@go1.17.3
1.20.12
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.20.12

Open the chart page →

6,595
iopsciencemeshVerified publisher0.4.01 of 2See more

iop sciencemesh 0.4.0

1 of the 2 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
cs3org/revad:v1.24.0e80a4d67b352
stdlib@go1.20.4
1.20.12

Open the chart page →

4,060
karakeepself-hosters-by-nightVerified publisher2.5.11 of 1See more

karakeep self-hosters-by-night 2.5.1

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
stdlib@go1.20.7
1.20.12

Open the chart page →

5,222
sentry-k8ssentry-k8sVerified publisher1.4.12 of 11See more

sentry-k8s sentry-k8s 1.4.1

2 of the 11 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
library/redis:6.2.20-alpine77697a75da9f
stdlib@go1.18.2
1.20.12
ghcr.io/getsentry/sentry:26.7.27c5052aa4e3c
stdlib@go1.19.8
1.20.12

Open the chart page →

16,646
vuiseriohub1.0.61 of 3See more

vui seriohub 1.0.6

1 of the 3 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
dserio83/velero-api:0.3.16b3d9115fee2
stdlib@go1.19.8
1.20.12

Open the chart page →

11,564
clickhousesignoz24.1.183 of 3See more

clickhouse signoz 24.1.18

3 of the 3 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.21.2cd9252644ce0
stdlib@go1.19.10
1.20.12
altinity/metrics-exporter:0.21.2df3d57215356
stdlib@go1.19.10
1.20.12
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.20.12

Open the chart page →

4,698
cosignedsigstoreVerified publisher0.1.232 of 2See more

cosigned sigstore 0.1.23

2 of the 2 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
gcr.io/projectsigstore/cosigneddigest-pinned784518ff3ee7
stdlib@go1.17.9
1.20.12
gcr.io/projectsigstore/policy-webhookdigest-pinned82940e8c3e0d
stdlib@go1.17.9
1.20.12

Open the chart page →

5,132
scaffoldsigstoreVerified publisher0.6.1152 of 15See more

scaffold sigstore 0.6.115

2 of the 15 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
library/redisdigest-pinned148bb5411c18
stdlib@go1.18.2
1.20.12
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.20.12

Open the chart page →

7,688
postgresql-singlesinextraVerified publisher1.15.11 of 1See more

postgresql-single sinextra 1.15.1

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
stdlib@go1.16.15
1.20.12

Open the chart page →

4,952
altinity-clickhouse-operatorslamdev0.1.22 of 2See more

altinity-clickhouse-operator slamdev 0.1.2

2 of the 2 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.20.08f0f582d41f0
stdlib@go1.17.13
1.20.12
altinity/metrics-exporter:0.20.01a46d104406d
stdlib@go1.17.13
1.20.12

Open the chart page →

6,420
docker-registry-uislamdev0.0.11 of 1See more

docker-registry-ui slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
quiq/docker-registry-ui:0.9.491281da47036
stdlib@go1.18
1.20.12

Open the chart page →

2,201
external-secrets-operatorslamdev0.0.151 of 1See more

external-secrets-operator slamdev 0.0.15

1 of the 1 container images this version deploys carry CVE-2023-39326.

Container imageDigestPackageFixed in
slamdev/external-secrets-operator:0.0.8855f6625dda4
stdlib@go1.13.15
1.20.12

Open the chart page →

2,301

Container images carrying it

2,218 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.0cd21e19cd8bb
stdlib@go1.20.5
1.20.12
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.20.12
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
stdlib@go1.19
1.20.12
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
stdlib@go1.18
1.20.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.20.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
stdlib@go1.18
1.20.12
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.20.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.20.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.20.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.20.12
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.20.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.20.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.20.12
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.20.12
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.20.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.20.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.20.12
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.20.12
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.