StackRadar

CVE-2023-43642

High

Advisory

Published 25 Sept 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.010
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
155
of 17,781 indexed, latest versions
Container images
150
deployed by those charts
Fix available
1 of 1
affected package

snappy-java's missing upper bound check on chunk length can lead to Denial of Service (DoS) impact

Carried by container images the latest versions of 155 of 17,781 indexed charts deploy, on 150 images.

Affected packageAffected versionsFixed inImages
snappy-javamaven1.0.3, 1.0.4.1, 1.0.5, 1.0.5.2+12 more1.1.10.4150
OSV records
GHSA-55g7-9cwv-5qfv

Charts affected

155 by stars
ChartLatestAffected imagesRadar Score
clickhousetemp-charts0.7.11 of 3See more

clickhouse temp-charts 0.7.1

1 of the 3 container images this version deploys carry CVE-2023-43642.

Container imageDigestPackageFixed in
library/zookeeper:3.6.180ad2170ad62
snappy-java@1.1.7
1.1.10.4

Open the chart page →

8,707
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2023-43642.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
snappy-java@1.1.8.4
1.1.10.4
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
snappy-java@1.1.8.4
1.1.10.4
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
snappy-java@1.1.8.4
1.1.10.4
thingsboard/tb-node:3.4.1645f43b688f7
snappy-java@1.1.8.4
1.1.10.4

Open the chart page →

25,394
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2023-43642.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
snappy-java@1.1.7.7
1.1.10.4

Open the chart page →

12,455
drillwearefrank1.3.62 of 3See more

drill wearefrank 1.3.6

2 of the 3 container images this version deploys carry CVE-2023-43642.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
snappy-java@1.1.8.1
1.1.10.4
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
snappy-java@1.1.10.1
1.1.10.4

Open the chart page →

9,397
jaegerwikimedia3.1.21 of 4See more

jaeger wikimedia 3.1.2

1 of the 4 container images this version deploys carry CVE-2023-43642.

Container imageDigestPackageFixed in
jaegertracing/jaeger-cassandra-schema:1.53.0d48d6dab2c65
snappy-java@1.1.10.1
1.1.10.4

Open the chart page →

9,248

Container images carrying it

150 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jacobalberty/unifi:v7.4.162b3edc809a3ff
snappy-java@1.1.8.4
1.1.10.4
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
snappy-java@1.0.3
1.1.10.4
1
library/cassandra:2.1.20cb079c0d7a57
snappy-java@1.0.5.2
1.1.10.4
1
library/logstash:7.17.817a4f64e9cf5
snappy-java@1.1.0.1
1.1.10.4
1
library/solr:8.7.0d124efd81fbb
snappy-java@1.1.7.6
1.1.10.4
1
library/storm:2.4.0bd5d420506d6
snappy-java@1.0.5
1.1.10.4
1
library/zookeeper:3.6.24c8a6d3b2338
snappy-java@1.1.7
1.1.10.4
1
library/zookeeper:3.8-temurin55d1e5b2e601
snappy-java@1.1.10.1
1.1.10.4
1
lightbend/spark-history-server:2.4.00bedf37f428a
snappy-java@1.1.7.1
1.1.10.4
1
linuxserver/unifi-controller:8.0.240ae315a3a456
snappy-java@1.1.8.4
1.1.10.4
1
linuxserver/unifi-controller:7.3.83ab105cc50322
snappy-java@1.1.8.4
1.1.10.4
1
lourdesmorente/new-planner:1.0.0608745878cdb
snappy-java@1.1.8.1
1.1.10.4
1
lsmaster/kafka-connect-wrapper:6.1.0-0.1061eb5fbfa00
snappy-java@1.1.7.7
1.1.10.4
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
snappy-java@1.1.8.2
1.1.10.4
1
molynx/planner:v1441c9f52f092
snappy-java@1.1.8.1
1.1.10.4
1
omecproject/c3po-hssdb:master-latest28a90cc26716
snappy-java@1.0.5.2
1.1.10.4
1
opencord/ves-agent:1.0.04187e2a8c918
snappy-java@1.1.7.1
1.1.10.4
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
snappy-java@1.1.0.1
1.1.10.4
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
snappy-java@1.1.10.3
1.1.10.4
1
pcarrascoponce/planner:v1.0981fc482442c
snappy-java@1.1.8.1
1.1.10.4
1
radarbase/kafka-manager:1.3.3.181d2af7dd5a4e
snappy-java@1.1.7.1
1.1.10.4
1
radondb/zookeeper:3.6.216981604f1a0
snappy-java@1.1.7
1.1.10.4
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
snappy-java@1.1.8.1
1.1.10.4
1
seataio/seata-server:latest703b5de7f1a6
snappy-java@1.1.8.4
1.1.10.4
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
snappy-java@1.0.5
1.1.10.4
1
sslhep/hive-metastore:3.1.39e80af083079
snappy-java@1.0.5
1.1.10.4
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
snappy-java@1.1.8.4
1.1.10.4
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
snappy-java@1.1.8.4
1.1.10.4
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
snappy-java@1.1.8.4
1.1.10.4
1
thingsboard/tb-node:3.4.1645f43b688f7
snappy-java@1.1.8.4
1.1.10.4
1
thingsboard/tb-node:3.6.0f40a542832c4
snappy-java@1.1.8.4
1.1.10.4
1
thmmniii/fbs-core:v1.27.15438517d9fc2
snappy-java@1.1.10.1
1.1.10.4
1
trinodb/trino:45038c6f24ab1a4
snappy-java@1.0.5
1.1.10.4
1
trinodb/trino:405ee80ab5eeab2
snappy-java@1.0.5
1.1.10.4
1
vitalii1992/analytics-service:latest8e798836ecea
snappy-java@1.1.8.4
1.1.10.4
1
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
snappy-java@1.1.8.4
1.1.10.4
1
vlebediantsev/logic-ms:latestdf8bf38c535b
snappy-java@1.1.8.4
1.1.10.4
1
vlebediantsev/registration-ms-final:latest427af418b75e
snappy-java@1.1.8.4
1.1.10.4
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
snappy-java@1.1.8.4
1.1.10.4
1
wistefan/mvf:lateste0887302b2d8
snappy-java@1.1.8.4
1.1.10.4
1
xeotek/kadeck:4.2.94c6b04d9ce55
snappy-java@1.1.8.4
1.1.10.4
1
xetusoss/archiva:v2.2.588f25242b9ee
snappy-java@1.0.5
1.1.10.4
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
snappy-java@1.1.8.4
1.1.10.4
1
ghcr.io/fleeksoft/hbase/hbase-base:2.4.13.2c144bdd688d7
snappy-java@1.0.5
1.1.10.4
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
snappy-java@1.1.8.2
1.1.10.4
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
snappy-java@1.1.8.2
1.1.10.4
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
snappy-java@1.1.8.4
1.1.10.4
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
snappy-java@1.1.8.2
1.1.10.4
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
snappy-java@1.1.8.4
1.1.10.4
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
snappy-java@1.1.10.1
1.1.10.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.