CVE-2023-44273
MediumAdvisory
Published 5 Oct 2023In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.1
- base score, highest
- EPSS
- 0.008
- 56th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 6
- of 17,781 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 1 of 1
- affected package
gnark-crypto doesn't range check input values during ECDSA and EdDSA signature deserialization
Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v0.6.0 | 0.12.0 | 6 |
- OSV records
- GHSA-fr8m-434r-g3xp
- Also known as
- GHSA-9xfq-8j3r-xp5g, GO-2023-2096, GO-2025-4027
Charts affected
6 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| dltbrokerassist-iot-distributed-broker | 0.2.0 | 3 of 9See more | 77,706 |
| dltloggingassist-iot-logging-auditing | 0.2.0 | 3 of 9See more | 77,687 |
| hlf-k8ssubstraVerified publisher | 10.2.4 | 2 of 7See more | 12,006 |
| dltkvassist-iot-data-integrity-verification | 0.2.0 | 3 of 9See more | 77,706 |
| dltflassist-iot-dlt-based-fl | 0.2.0 | 3 of 9See more | 77,706 |
| fabric-operatorkubebb | 0.1.0 | 1 of 1See more | 3,988 |
Container images carrying it
6 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| hyperledger/ | 6ec3fe59ea55 | github.com/ | 0.12.0 | 4 |
| hyperledger/ | 6ff36af21eb1 | github.com/ | 0.12.0 | 4 |
| hyperledger/ | b1194f509085 | github.com/ | 0.12.0 | 4 |
| hyperledgerk8s/ | 29a8af8be270 | github.com/ | 0.12.0 | 1 |
| ghcr.io/ | f681e0343a31 | github.com/ | 0.12.0 | 1 |
| ghcr.io/ | 3491a0f31c4a | github.com/ | 0.12.0 | 1 |