CVE-2023-3978
MediumAdvisory
Published 2 Aug 2023In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.1
- base score, highest
- EPSS
- 0.008
- 56th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 1,253
- of 17,792 indexed, latest versions
- Container images
- 1,507
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Improper rendering of text nodes in golang.org/x/net/html
Carried by container images the latest versions of 1,253 of 17,792 indexed charts deploy, on 1,507 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang.org/ | v0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+179 more | 0.13.0 | 1,507 |
- OSV records
- GHSA-2wrh-6pvc-2jm9
- Also known as
- GO-2023-1988
Charts affected
1,253 by stars
Container images carrying it
1,507 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| registry.k8s.io/ | 89e900a160a9 | golang.org/ | 0.13.0 | 1 |
| registry.k8s.io/ | 92257881c1d6 | golang.org/ | 0.13.0 | 1 |
| registry.k8s.io/ | 2b10b24dafdc | golang.org/ | 0.13.0 | 1 |
| registry.k8s.io/ | 3ce0fdba4d8e | golang.org/ | 0.13.0 | 1 |
| registry.k8s.io/ | 95587f8777d7 | golang.org/ | 0.13.0 | 1 |
| registry.k8s.io/ | 98bab4eaf23c | golang.org/ | 0.13.0 | 1 |
| registry.k8s.io/ | d35884236461 | golang.org/ | 0.13.0 | 1 |