StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,787 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,787 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
pagesalstom-pages-app1.0.02 of 3See more

pages alstom-pages-app 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,233
amorphieamorphie0.1.27 of 18See more

amorphie amorphie 0.1.2

7 of the 18 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
0.17.0
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
0.17.0
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
0.17.0
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
0.17.0
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
0.17.0
hazelcast/hazelcast:5.3.18fe26efde8e1
nghttp2@1.55.1-r0
1.57.0-r0
hazelcast/management-center:5.3.2f9d34300d330
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

28,212
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,326
pagesandrei-pages1.0.02 of 3See more

pages andrei-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,233
terjangandylibrianVerified publisher0.0.31 of 1See more

terjang andylibrian 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/andylibrian/terjang:latest20a46b199247
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.17.0

Open the chart page →

1,985
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

42,345
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,488
ddosifyanteonVerified publisher1.7.54 of 13See more

ddosify anteon 1.7.5

4 of the 13 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
0.17.0
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
0.17.0
library/influxdb:2.6.1-alpine44a366dd7724
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
1.51.0-r2
0.17.0
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

25,720
antmediaantmediaVerified publisher3.1.02 of 4See more

antmedia antmedia 3.1.0

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
nghttp2@1.47.0-r0
golang.org/x/net@v0.1.0
1.47.0-r2
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

4,615
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
nghttp2@1.47.0-r0
golang.org/x/net@v0.1.0
1.47.0-r2
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

3,322
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.17.0

Open the chart page →

2,730
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
tomcat-embed-core@8.5.32
8.5.94

Open the chart page →

5,277
d.vazquezm.2021_helmapphelmVerified publisher1.0.02 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

2 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
nghttp2@1.43.0-1
1.43.0-1+deb11u1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

19,784
test-chartapplication-chart0.2.01 of 1See more

test-chart application-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ahmedinfraplus/simple-app:STAGINGc50e6e81a637
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,197
app-mobilityappmo0.1.03 of 5See more

app-mobility appmo 0.1.0

3 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
0:1.33.0-4.el8_6.1
0.17.0
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0:1.33.0-4.el8_6.1
0.17.0
velero/velero:v1.8.18d784580931c
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

12,520
auditorappscodeVerified publisher2023.10.11 of 1See more

auditor appscode 2023.10.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
0.17.0

Open the chart page →

1,673
capi-ops-managerappscodeVerified publisher2024.8.141 of 2See more

capi-ops-manager appscode 2024.8.14

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

3,416
docker-machine-operatorappscodeVerified publisher2024.7.91 of 1See more

docker-machine-operator appscode 2024.7.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

2,220
grafanaappscodeVerified publisher2026.9.111 of 1See more

grafana appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana:v2025.2.367d18880448c
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0

Open the chart page →

2,333
kube-auth-managerappscodeVerified publisher2023.11.141 of 1See more

kube-auth-manager appscode 2023.11.14

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,945
kube-auth-proxyappscodeVerified publisher2023.11.141 of 1See more

kube-auth-proxy appscode 2023.11.14

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,945
kubedb-communityappscodeVerified publisher0.24.21 of 2See more

kubedb-community appscode 0.24.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubedb/operator:v0.24.01a06ff0bda52
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

2,550
kubedb-enterpriseappscodeVerified publisher0.11.21 of 2See more

kubedb-enterprise appscode 0.11.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubedb/kubedb-enterprise:v0.11.05829bcedcb0d
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

2,575
kubedb-oneappscodeVerified publisher2023.12.283 of 10See more

kubedb-one appscode 2023.12.28

3 of the 10 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
ghcr.io/stashed/stash-crd-installer:v0.32.0c6f2a844b5dd
golang.org/x/net@v0.15.0
0.17.0
ghcr.io/stashed/stash-enterprise:v0.32.0e9bde36e34b7
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

15,016
kubedb-provider-awsappscodeVerified publisher2026.7.101 of 1See more

kubedb-provider-aws appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-aws:v0.27.049b1c312e342
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

2,527
kubedb-provider-azureappscodeVerified publisher2026.7.101 of 1See more

kubedb-provider-azure appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.17.0

Open the chart page →

2,705
kubedb-provider-gcpappscodeVerified publisher2026.7.101 of 2See more

kubedb-provider-gcp appscode 2026.7.10

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

3,033
kubedb-ui-serverappscodeVerified publisher2021.12.211 of 1See more

kubedb-ui-server appscode 2021.12.21

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

2,047
kubeform-provider-awsappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-aws appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

2,796
kubeform-provider-azureappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-azure appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.17.0

Open the chart page →

2,716
kubeform-provider-gcpappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-gcp appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

2,743
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

4,043
stash-communityappscodeVerified publisher0.42.01 of 4See more

stash-community appscode 0.42.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

3,661
statefulsetappscodeVerified publisher0.0.11 of 3See more

statefulset appscode 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,732
cloud-portalappuio0.4.11 of 1See more

cloud-portal appuio 0.4.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appuio/cloud-portal:v0.2.18c7e08d32d70
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,286
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
golang.org/x/net@v0.11.0
nghttp2@1.52.0-1
0.17.0
1.52.0-1+deb12u1

Open the chart page →

4,899
maxscaleappuio2.0.11 of 1See more

maxscale appuio 2.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
nghttp2@1.33.0-3.el8_3.1
0:1.33.0-5.el8_8

Open the chart page →

2,902
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
tomcat-embed-core@9.0.38
9.0.81

Open the chart page →

8,904
appwriteappwrite-helmVerified publisher1.3.21 of 8See more

appwrite appwrite-helm 1.3.2

1 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubegems/bitnami-shell:12-debian-12-r24e42e3aaacdd3
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

9,847
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
0.17.0

Open the chart page →

5,203
arma-reforgerarma-reforger0.5.37 of 8See more

arma-reforger arma-reforger 0.5.3

7 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
stakater/reloader:v1.0.15f4b87a8e56d4
golang.org/x/net@v0.7.0
0.17.0
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
nghttp2@1.40.0-1build1
golang.org/x/net@v0.7.0
1.40.0-1ubuntu0.2
0.17.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
0.17.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
0.17.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

23,407
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

1,773
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.17.0
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

8,608
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2

Open the chart page →

22,677
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

14,725
dltkvassist-iot-data-integrity-verification0.2.04 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

4 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
hyperledger/fabric-tools:2.4b1194f509085
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
1.47.0-r2
0.17.0

Open the chart page →

77,821
dltflassist-iot-dlt-based-fl0.2.04 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

4 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
hyperledger/fabric-tools:2.4b1194f509085
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
1.47.0-r2
0.17.0

Open the chart page →

77,821
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

3,786
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.02 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:ui-latest20338b353aaf
nghttp2@1.47.0-r0
nginx@1.22.0-r1
1.47.0-r2
1.22.1-r1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

9,407
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

4,367

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
andrianrf/iso-server:latest7da47f525c7d
nghttp2@1.43.0-5.el9
tomcat-embed-core@9.0.36
0:1.43.0-5.el9_2.1
9.0.81
1
anguda/ant-media:2.5c435285fc241
nghttp2@1.40.0-1build1
tomcat-coyote@8.5.82
tomcat-embed-core@8.5.82
1.40.0-1ubuntu0.2
8.5.94
8.5.94
1
anonaddy/anonaddy:0.12.3957a95565166
nghttp2@1.47.0-r0
nginx@1.22.0-r1
1.47.0-r2
1.22.1-r1
1
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
apache/apisix-dashboard:2.9.0c010ea7d1694
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0
1
apache/apisix-ingress-controller:1.3.0412f92cde0b3
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0
1
apache/camel-k:1.10.43bb13d14f64a
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0:1.33.0-4.el8_6.1
0.17.0
1
apache/drill:1.21.11f96558fd292
tomcat-embed-core@8.5.46
nghttp2@1.43.0-1
8.5.94
1.43.0-1+deb11u1
1
apache/hadoop:3af361b20bec0
http2-common@9.4.34.v20201102
9.4.53
1
apache/iotdb:0.11.28647309f95d1
tomcat-embed-core@8.5.32
8.5.94
1
apache/iotdb:0.13.3-nodeafa47bf1692a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
apachepinot/pinot:latest-jdk110018bb04ced7
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
nghttp2@1.43.0-1build3
http2-common@9.4.51.v20230217
http2-server@9.4.51.v20230217
1.43.0-1ubuntu0.1
9.4.53
9.4.53
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
nghttp2@1.40.0-1build1
http2-common@9.4.44.v20210927
http2-server@9.4.44.v20210927
1.40.0-1ubuntu0.2
9.4.53
9.4.53
1
apachepulsar/pulsar:2.6.14db6ff0b4045
http2-common@9.4.11.v20180605
http2-server@9.4.11.v20180605
9.4.53
9.4.53
1
apachepulsar/pulsar:2.9.0d056c89b7131
nghttp2@1.40.0-1build1
http2-common@9.4.43.v20210629
http2-server@9.4.43.v20210629
1.40.0-1ubuntu0.2
9.4.53
9.4.53
1
apachepulsar/pulsar:2.8.2d538416d5afe
nghttp2@1.40.0-1build1
http2-common@9.4.43.v20210629
http2-server@9.4.43.v20210629
1.40.0-1ubuntu0.2
9.4.53
9.4.53
1
apache/rocketmq:5.3.0434d8398f996
tomcat-embed-core@8.5.46
8.5.94
1
apache/rocketmq:4.9.35ac2a4e0f627
tomcat-embed-core@8.5.46
8.5.94
1
apache/rocketmq-exporter:0.0.2c8fb51195444
tomcat-embed-core@9.0.74
9.0.81
1
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
tomcat-embed-core@9.0.29
9.0.81
1
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
golang.org/x/net@v0.10.0
0.17.0
1
apache/shenyu-admin:2.5.1e2be712fc4f4
tomcat-embed-core@9.0.63
9.0.81
1
apache/skywalking-oap-server:9.2.0133d35d2c263
nghttp2@1.43.0-1build3
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
1.43.0-1ubuntu0.1
0.17.0
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
1.40.0-1ubuntu0.2
0.17.0
1
apache/skywalking-ui:9.2.0295f1dc87d98
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
tomcat-embed-core@8.5.29
0.17.0
8.5.94
1
apache/skywalking-ui:8.9.180530f0308a5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
apecloud/dt-platform:0.1.1d48bcbd38066
golang.org/x/net@v0.8.0
0.17.0
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
golang.org/x/net@v0.15.0
0.17.0
1
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
apecloud/kubetran-platform:latest32bd92c7f7fa
golang.org/x/net@v0.15.0
0.17.0
1
apecloud/pyroscope:0.37.2dbca95a15bc1
golang.org/x/net@v0.1.0
0.17.0
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
golang.org/x/net@v0.5.0
0.17.0
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_4.1
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
0.17.0
1
aquasec/postee:2.12.0-amd640795cba777e7
nghttp2@1.53.0-r0
golang.org/x/net@v0.7.0
1.57.0-r0
0.17.0
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
golang.org/x/net@v0.7.0
0.17.0
1
aquasec/starboard-operator:0.15.4be34f709e1ce
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
aquasec/trivy:0.43.1944a04445179
nghttp2@1.53.0-r0
golang.org/x/net@v0.11.0
1.57.0-r0
0.17.0
1
aquasec/trivy:0.32.0973d0df16189
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
1
archish27/python-fastapi-postgres:latest6610071a2101
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
aristidetm/basic-notebook:3.6.5469dbc951224
golang.org/x/net@v0.7.0
0.17.0
1
aroralalit/student-producer:1.0.02a094f597b36
tomcat-embed-core@9.0.75
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1
1
arturisimo/webapp-db-java:v2c95524e90b57
tomcat-embed-core@9.0.56
9.0.81
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.