StackRadar

CVE-2023-39616

High

Advisory

Published 29 Aug 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
157
of 17,781 indexed, latest versions
Container images
166
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 157 of 17,781 indexed charts deploy, on 166 images.

Affected packageAffected versionsFixed inImages
aomdeb3.6.0-1, 3.6.0-1+deb12u1, 3.6.0-1+deb12u2, 3.6.0-1+deb12u3no fix listed166
OSV records
DEBIAN-CVE-2023-39616

Charts affected

157 by stars
ChartLatestAffected imagesRadar Score
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-39616.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
aom@3.6.0-1+deb12u1
no fix listed

Open the chart page →

10,086
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2023-39616.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
aom@3.6.0-1
no fix listed

Open the chart page →

17,323
opencloudunxwaresVerified publisher0.2.36 of 13See more

opencloud unxwares 0.2.3

6 of the 13 container images this version deploys carry CVE-2023-39616.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
aom@3.6.0-1+deb12u1
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
aom@3.6.0-1+deb12u1
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
aom@3.6.0-1+deb12u1
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
aom@3.6.0-1+deb12u1
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
aom@3.6.0-1+deb12u1
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
aom@3.6.0-1+deb12u1
no fix listed

Open the chart page →

45,239
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-39616.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
aom@3.6.0-1
no fix listed

Open the chart page →

14,358
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2023-39616.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
aom@3.6.0-1+deb12u1
no fix listed

Open the chart page →

10,795
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2023-39616.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
aom@3.6.0-1+deb12u2
no fix listed

Open the chart page →

9,117
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-39616.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
aom@3.6.0-1
no fix listed

Open the chart page →

7,673

Container images carrying it

166 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
aom@3.6.0-1+deb12u2
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
aom@3.6.0-1+deb12u2
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
aom@3.6.0-1
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
aom@3.6.0-1+deb12u1
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
aom@3.6.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
aom@3.6.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
aom@3.6.0-1+deb12u1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
aom@3.6.0-1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
aom@3.6.0-1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
aom@3.6.0-1
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
aom@3.6.0-1+deb12u1
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
aom@3.6.0-1
no fix listed
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
aom@3.6.0-1+deb12u1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
aom@3.6.0-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
aom@3.6.0-1+deb12u2
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
aom@3.6.0-1+deb12u2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.