StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,090
of 17,787 indexed, latest versions
Container images
2,443
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,090 of 17,787 indexed charts deploy, on 2,443 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more546
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0212
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more176
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+182 more0.17.01,549
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,090 by stars
ChartLatestAffected imagesRadar Score
openldapfluktuid0.1.11 of 2See more

openldap fluktuid 0.1.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
0.17.0

Open the chart page →

3,313
fsmfsmOfficialVerified publisher0.2.113 of 5See more

fsm fsm 0.2.11

3 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
flomesh/curl:7.84.0bc34fa2aca2c
nghttp2@1.46.0-r0
1.46.0-r2
flomesh/fsm-ingress-pipy:0.2.11cc39c96711c4
golang.org/x/net@v0.10.0
0.17.0
flomesh/fsm-manager:0.2.1122f849c70b25
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

4,215
rss-bridgegabe565Verified publisher0.5.21 of 1See more

rss-bridge gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/rss-bridge/rss-bridge:latest606896116558
nginx@1.22.1-9+deb12u9
no fix listed

Open the chart page →

2,186
dexgabibbo974.0.41 of 1See more

dex gabibbo97 4.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0

Open the chart page →

3,391
gboxgboxVerified publisher1.0.51 of 2See more

gbox gbox 1.0.5

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gboxproxy/gbox:v1.0.63a9f4a711d5c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0

Open the chart page →

2,521
adguard-homegeek-cookbookVerified publisher5.5.21 of 2See more

adguard-home geek-cookbook 5.5.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.7b9974aed13d0
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.17.0

Open the chart page →

1,742
alertmanager-botgeek-cookbookVerified publisher6.4.21 of 1See more

alertmanager-bot geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
golang.org/x/net@v0.0.0-20181213202711-891ebc4b82d6
0.17.0

Open the chart page →

3,586
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

17,377
deepstackgeek-cookbookVerified publisher1.5.21 of 2See more

deepstack geek-cookbook 1.5.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
robmarkcole/deepstack-ui:latest410275726459
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

5,305
filebrowsergeek-cookbookVerified publisher1.4.21 of 1See more

filebrowser geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.18.04fcd47af573c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
0.17.0

Open the chart page →

3,474
focalboardgeek-cookbookVerified publisher4.4.21 of 1See more

focalboard geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mattermost/focalboard:0.9.031078df7a3c8
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.17.0

Open the chart page →

3,631
games-on-whalesgeek-cookbookVerified publisher1.8.21 of 7See more

games-on-whales geek-cookbook 1.8.2

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

35,305
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

15,653
homergeek-cookbookVerified publisher8.0.21 of 1See more

homer geek-cookbook 8.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
b4bz/homer:v22.07.248a81e130470
lighttpd@1.4.64-r0
1.4.73-r0

Open the chart page →

624
lazylibrariangeek-cookbookVerified publisher7.4.21 of 1See more

lazylibrarian geek-cookbook 7.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/lazylibrarian:version-1152df82f93d2560e233
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

11,662
monicageek-cookbookVerified publisher8.2.01 of 1See more

monica geek-cookbook 8.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/monica:3.7.0-apacheceb1ba4196ab
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,096
ombigeek-cookbookVerified publisher11.5.21 of 1See more

ombi geek-cookbook 11.5.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

5,136
otel-collectorgeek-cookbookVerified publisher1.2.21 of 1See more

otel-collector geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

2,556
owncastgeek-cookbookVerified publisher3.4.21 of 1See more

owncast geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gabekangas/owncast:0.0.797461aedb580
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
0.17.0

Open the chart page →

3,167
paperlessgeek-cookbookVerified publisher9.2.01 of 1See more

paperless geek-cookbook 9.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:1.8.09bbc9a90641e
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

3,924
protonmail-bridgegeek-cookbookVerified publisher5.4.21 of 1See more

protonmail-bridge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0

Open the chart page →

8,029
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

11,558
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.21.62bcabc23b454
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

7,801
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

10,231
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

13,025
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
golang.org/x/net@v0.0.0-20200822124328-c89045814202
0.17.0

Open the chart page →

15,856
tdarrgeek-cookbookVerified publisher4.6.22 of 2See more

tdarr geek-cookbook 4.6.2

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
haveagitgat/tdarr:2.00.181256348872ce
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
haveagitgat/tdarr_node:2.00.101e3f9328327d
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

31,000
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.17.0

Open the chart page →

5,079
vaultwardengeek-cookbookVerified publisher5.4.01 of 1See more

vaultwarden geek-cookbook 5.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,585
webtreesgeek-cookbookVerified publisher2.2.01 of 1See more

webtrees geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

3,646
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

7,660
temporalglasskubeVerified publisher0.45.2-gk.12 of 14See more

temporal glasskube 0.45.2-gk.1

2 of the 14 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
curlimages/curl:7.85.09fab1b73f45e
nghttp2@1.46.0-r0
1.46.0-r2
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

16,346
gorse-enterprisegorse-io0.4.23 of 5See more

gorse-enterprise gorse-io 0.4.2

3 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
0.17.0
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
0.17.0
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

4,380
gradle-examplegradle-exampleVerified publisher1.1.31 of 1See more

gradle-example gradle-example 1.1.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
tomcat-embed-core@9.0.46
9.0.81

Open the chart page →

3,393
phlaregrafana0.5.41 of 1See more

phlare grafana 0.5.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/phlare:0.5.1330f990cdad9
golang.org/x/net@v0.5.0
0.17.0

Open the chart page →

2,084
supertokensgraphql-hive-subcharts1.0.01 of 1See more

supertokens graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
supertokens/supertokens-postgresql:3.1418d34c781347
tomcat-embed-core@8.5.47
8.5.94

Open the chart page →

2,709
carettagroundcover0.0.163 of 3See more

caretta groundcover 0.0.16

3 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/net@v0.1.0
0.17.0
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

6,799
hawkhawk1.1.52 of 4See more

hawk hawk 1.1.5

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
0.17.0
ghcr.io/privacyengineering/hawk-monitor:master13309f068a56
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

13,610
seata-serverheidaodageshiwoVerified publisher1.0.01 of 1See more

seata-server heidaodageshiwo 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
seataio/seata-server:1.5.1ee1ed55f4144
tomcat-embed-core@9.0.55
9.0.81

Open the chart page →

5,624
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

6,977
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

16,514
cratedb-adapter-v2hmdmph0.2.11 of 1See more

cratedb-adapter-v2 hmdmph 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
0.17.0

Open the chart page →

2,913
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
golang.org/x/net@v0.0.0-20210907225631-ff17edfbf26d
0.17.0

Open the chart page →

1,573
ilum-coreilumOfficialVerified publisher6.7.31 of 5See more

ilum-core ilum 6.7.3

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

3,556
inbucketinbucketVerified publisher2.5.01 of 1See more

inbucket inbucket 2.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
inbucket/inbucket:3.0.01f10a0efea69
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0

Open the chart page →

2,167
elasticinseefrlab2.2.02 of 2See more

elastic inseefrlab 2.2.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
library/kibana:7.17.3e2e2031c15be
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

17,284
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

7,129
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

10,400
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

10,475
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

10,421

Container images carrying it

2,443 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
assistiot/distributed_broker:1.0.033e02dad168f
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
assistiot/fl_orchestrator:ui-latest20338b353aaf
nghttp2@1.47.0-r0
nginx@1.22.0-r1
1.47.0-r2
1.22.1-r1
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
assistiot/identity-manager_kc:latest0df4b4fa899a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
1
assistiot/location_processing:lateste9bae124095f
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
assistiot/logging_auditing:1.0.0790dbb198e86
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
1
assistiot/open_api_backend:1.1.230812ba93555
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
assistiot/open_api_kong:1.0.03fe850384689
nghttp2@1.47.0-r0
1.47.0-r2
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
assistiot/tacticle_dashboard:web-latest25fc9f373524
nghttp2@1.47.0-r0
nginx@1.22.0-r1
1.47.0-r2
1.22.1-r1
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
tomcat-coyote@9.0.65
9.0.81
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
atlassian/confluence-server:7.10.03b9222ab32ef
nghttp2@1.43.0-1build3
tomcat-coyote@9.0.40
1.43.0-1ubuntu0.1
9.0.81
1
atlassian/jira-software:8.14.037bc46cbec1a
tomcat-coyote@8.5.57
8.5.94
1
atlassian/jira-software:9.7.264a75aa4ec4e
tomcat-coyote@9.0.73
9.0.81
1
atomix/atomix:3.1.127738ff4f5c63
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
audig/clamapi:2.1.62c3fe34ee430
tomcat-embed-core@9.0.37
9.0.81
1
avinash263/pyredis263:latestaa2b8727f1a6
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
avzini/web-app:latestf40b30210ed0
nghttp2@1.52.0-1
nginx@1.25.3-1~bookworm
1.52.0-1+deb12u1
no fix listed
1
azhar008/flaskapplication:latesta1e827b0adea
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
b4bz/homer:v22.07.248a81e130470
lighttpd@1.4.64-r0
1.4.73-r0
1
b4bz/homer:v22.11.1678ac390d7c9
lighttpd@1.4.64-r0
1.4.73-r0
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
1.40.0-1ubuntu0.2
0.17.0
1
beastob/url-shortener:1.0.299a49885ab33
tomcat-embed-core@9.0.53
9.0.81
1
bedag/goblackhole:0.2.0447a88598f4c
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0
1
beopenit/door-helm:v3.0.1b4d9f9bee224
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.15.0
0:1.33.0-5.el8_8
0.17.0
1
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/net@v0.7.0
0.17.0
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
0.17.0
1
bicarus/mx-notifier:1.1.8bed688d16762
golang.org/x/net@v0.2.0
0.17.0
1
bicarus/wg-access-server:v0.8.206cab48e9334
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220418201149-a630d4f3e7a2
1.47.0-r2
0.17.0
1
binhex/arch-nzbhydra2:3.1.0-1-01fb8952921ab6
tomcat-embed-core@9.0.36
9.0.81
1
binwiederhier/ntfy:v2.6.283e2e43d9956
golang.org/x/net@v0.11.0
0.17.0
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0
1
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/kubectl:1.22.13d0e426ccff33
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
golang.org/x/net@v0.4.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
bitnamilegacy/mongodb:5.0.103bb1deeaf9d0
golang.org/x/net@v0.0.0-20220708220712-1185a9018129
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
bitnamilegacy/mongodb-exporter:0.39.0-debian-11-r106de7256c7adcd
golang.org/x/net@v0.7.0
0.17.0
1
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
1
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.17.0
1
bitnamilegacy/rabbitmq:3.11.18-debian-11-r029b0a2330572
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/rabbitmq:3.10.88f7161d8ce19
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.