StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,107
of 17,790 indexed, latest versions
Container images
2,471
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,107 of 17,790 indexed charts deploy, on 2,471 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,572
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,107 by stars
ChartLatestAffected imagesRadar Score
ves-agentopencord1.0.21 of 1See more

ves-agent opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
opencord/ves-agent:1.0.04187e2a8c918
tomcat-embed-core@8.5.31
8.5.94

Open the chart page →

6,353
volthaopencord2.14.02 of 2See more

voltha opencord 2.14.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
voltha/voltha-rw-core:3.4.87a325316fe59
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

3,824
voltha-infraopencord2.14.05 of 10See more

voltha-infra opencord 2.14.0

5 of the 10 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
atomix/atomix:3.1.127738ff4f5c63
nghttp2@1.43.0-1
1.43.0-1+deb11u1
freeradius/freeradius-server:3.0.2121c8bfa904d8
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
voltha/voltha-onos:5.1.8e038acb950d3
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

41,101
voltha-stackopencord2.14.02 of 4See more

voltha-stack opencord 2.14.0

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
voltha/voltha-rw-core:3.4.87a325316fe59
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

5,566
mqtt-connectoropenfaas0.4.71 of 1See more

mqtt-connector openfaas 0.4.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/openfaas/mqtt-connector:0.4.33311a30b8fe6
golang.org/x/net@v0.0.0-20200425230154-ff2c4b7c35a0
0.17.0

Open the chart page →

1,389
probuilderopenfaas0.2.01 of 2See more

probuilder openfaas 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
moby/buildkit:v0.10.0c2aeafaed434
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
1.46.0-r2
0.17.0

Open the chart page →

4,760
kruise-rolloutopenkruise0.6.21 of 1See more

kruise-rollout openkruise 0.6.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openkruise/kruise-rollout:v0.6.2a75e6739ea7d
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,034
kruise-state-metricsopenkruise0.2.01 of 1See more

kruise-state-metrics openkruise 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openkruise/kruise-state-metrics:v0.2.0a8108f771287
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,929
openldapopenldap0.1.12 of 2See more

openldap openldap 0.1.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ldapaccountmanager/lam:8.0.1d46cf25d1dda
nghttp2@1.43.0-1
1.43.0-1+deb11u1
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
0.17.0

Open the chart page →

5,294
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.4.0
0:1.33.0-5.el8_8
0.17.0
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

7,471
bpjstk-serviceopenshift1.0.06 of 6See more

bpjstk-service openshift 1.0.0

6 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
andrianrf/backoffice:latest047a7837651e
nginx@1:1.20.1-1.module+el8.8.0+20359+9bd89172.1
1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1
andrianrf/backoffice-be:latest6036614803d4
nghttp2@1.43.0-5.el9
tomcat-embed-core@9.0.75
0:1.43.0-5.el9_2.1
9.0.81
andrianrf/bpjstk-service:latest46abe878d9d8
tomcat-embed-core@9.0.38
9.0.81
andrianrf/bpjstk-simulator:latestb63fdb51d39d
tomcat-embed-core@9.0.38
9.0.81
andrianrf/iso-client:latestba560086ce15
tomcat-embed-core@9.0.38
9.0.81
andrianrf/iso-server:latest7da47f525c7d
nghttp2@1.43.0-5.el9
tomcat-embed-core@9.0.36
0:1.43.0-5.el9_2.1
9.0.81

Open the chart page →

35,116
flomesh-consoleopenshift0.70.0-30-ubi82 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

9,968
fsmopenshift0.1.8-ubi.64 of 6See more

fsm openshift 0.1.8-ubi.6

4 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0:1.33.0-5.el8_8
0.17.0
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0:1.33.0-5.el8_8
0.17.0
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0:1.33.0-5.el8_8
0.17.0
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

16,563
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

4,170
opscruiseopenshift0.35.1003 of 11See more

opscruise openshift 0.35.100

3 of the 11 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/loki:2.0.077e138f81a8e
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
grafana/promtail:2.0.05fd12edcc694
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.17.0

Open the chart page →

8,224
orion-ldopenshift1.0.32 of 2See more

orion-ld openshift 1.0.3

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_4.1

Open the chart page →

14,727
osm-edgeopenshift1.2.1-ubi86 of 7See more

osm-edge openshift 1.2.1-ubi8

6 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

19,471
redhat-springboot-restopenshift0.0.11 of 1See more

redhat-springboot-rest openshift 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

3,066
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
nghttp2@1.43.0-5.el9
golang.org/x/net@v0.11.0
0:1.43.0-5.el9_2.1
0.17.0

Open the chart page →

8,643
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
tomcat-embed-core@9.0.60
9.0.81

Open the chart page →

13,612
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
tomcat-embed-core@9.0.60
9.0.81

Open the chart page →

13,573
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
tomcat-embed-core@9.0.60
9.0.81

Open the chart page →

13,556
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
tomcat-embed-core@9.0.60
9.0.81

Open the chart page →

13,460
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
tomcat-embed-core@9.0.60
9.0.81

Open the chart page →

13,105
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

15,602
openvscode-serveropenvscode-server-helmVerified publisher2.7.371 of 2See more

openvscode-server openvscode-server-helm 2.7.37

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/docker:23.0.1-dindd9a0fd8bdd15
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

4,298
openwhiskopenwhisk1.0.02 of 10See more

openwhisk openwhisk 1.0.0

2 of the 10 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openwhisk/invoker:1.0.0f5831ec85525
akka-http-core_2.12@10.1.11
10.5.3
openwhisk/ow-utils:1.0.0c80dba0de3aa
nghttp2@1.30.0-1ubuntu1
nodejs@8.10.0~dfsg-2ubuntu0.4
1.30.0-1ubuntu1+esm2
8.10.0~dfsg-2ubuntu0.4+esm6

Open the chart page →

36,252
gitlab-proxyopslevelVerified publisher0.0.81 of 1See more

gitlab-proxy opslevel 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/caddy:2.660fb54d36b4b
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,879
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.7.0
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

5,658
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
tomcat-embed-core@9.0.26
9.0.81

Open the chart page →

26,364
orderregistratiecomponentorderregistratiecomponent1.0.01 of 3See more

orderregistratiecomponent orderregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,501
prometheusosc0.26.22 of 12See more

prometheus osc 0.26.2

2 of the 12 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
golang.org/x/net@v0.9.0
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.2ec5732e28f15
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

3,381
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

72,547
osm-edgeosm-edgeVerified publisher1.3.95 of 7See more

osm-edge osm-edge 1.3.9

5 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
golang.org/x/net@v0.5.0
0.17.0
flomesh/osm-edge-controller:1.3.9add7a4da4622
golang.org/x/net@v0.5.0
0.17.0
flomesh/osm-edge-injector:1.3.947287e3ad324
golang.org/x/net@v0.5.0
0.17.0
flomesh/osm-edge-preinstall:1.3.9bd224d55ed0f
golang.org/x/net@v0.5.0
0.17.0
flomesh/pipy-repo:0.90.3-3874975c50e3d9
nghttp2@1.47.0-r1
1.47.0-r2

Open the chart page →

5,610
logging-operatorot-container-kit0.4.01 of 1See more

logging-operator ot-container-kit 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/opstree/logging-operator:v0.4.0fd8bb57ef3cf
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0

Open the chart page →

1,802
lokiot-container-kit1.0.11 of 5See more

loki ot-container-kit 1.0.1

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.24-alpinebe76a26e238d
nginx@1.24.0-r1
1.24.0-r7

Open the chart page →

4,844
mongodb-operatorot-container-kit0.3.11 of 1See more

mongodb-operator ot-container-kit 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/opstree/mongodb-operator:v0.3.0879b9bead838
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

1,873
vmot-container-kit0.0.31 of 7See more

vm ot-container-kit 0.0.3

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
curlimages/curl:7.85.09fab1b73f45e
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

5,418
kubernetes-taggeroxyno-zetaVerified publisher1.1.21 of 1See more

kubernetes-tagger oxyno-zeta 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

1,826
p4p40.1.04 of 7See more

p4 p4 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
mastercloudapps/planner:v1.2340a950b311b2
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
mastercloudapps/server:v2.23f3d24dfe2686
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
mastercloudapps/weatherservice:v1.23de859d29c116
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

27,702
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

19,728
pagespages1.0.02 of 3See more

pages pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
pagespages-10.1.01 of 1See more

pages pages-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:1.04d2eb25b9225
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.43
1.40.0-1ubuntu0.2
9.0.81

Open the chart page →

10,437
pagespages101.0.02 of 3See more

pages pages10 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
pagespages1111.0.02 of 3See more

pages pages111 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
pagespages21.0.02 of 3See more

pages pages2 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
pagespages-alexchmielu1.0.02 of 3See more

pages pages-alexchmielu 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
pagespages-alps1.0.02 of 3See more

pages pages-alps 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
pagespages-alstom1.0.02 of 3See more

pages pages-alstom 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
pagespages-ambala1.0.02 of 3See more

pages pages-ambala 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242

Container images carrying it

2,471 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.17.0
1
bitnamilegacy/rabbitmq:3.11.18-debian-11-r029b0a2330572
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/rabbitmq:3.10.88f7161d8ce19
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/net@v0.0.0-20220614195744-fb05da6f9022
0.17.0
1
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
1
bitpoke/wordpress-operator:v0.12.421284d1df473
golang.org/x/net@v0.8.0
0.17.0
1
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
golang.org/x/net@v0.8.0
0.17.0
1
bivas/presto:0.19605545994f806
http2-common@9.4.8.v20171121
http2-server@9.4.8.v20171121
9.4.53
9.4.53
1
blipai/deckard:0.0.28737d5d19a312
golang.org/x/net@v0.10.0
0.17.0
1
blockscout/blockscout:5.1.5c365a8f2dc12
nghttp2@1.47.0-r0
1.47.0-r2
1
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
bsgrigorov/helm-operator:latest45ab095f09c8
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0:1.33.0-5.el8_8
0.17.0
1
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0
1
bulich/domain-exporter:latest6d0b780f7c7b
golang.org/x/net@v0.10.0
0.17.0
1
buntha/mlflow:2.1.1154542cc3083
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
golang.org/x/net@v0.10.0
0.17.0
1
camerahub/camerahub:0.36.23a5af37dd6e1b
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
camptocamp/bucket-cloner:latestacfafc308d88
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
0.17.0
1
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
casbin/casdoor:v1.224.066f836ef778b
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
1.51.0-r2
0.17.0
1
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
0.17.0
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
nghttp2@1.39.2-lp151.3.3.1
0.17.0
1.57.0-1.1
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
nghttp2@1.39.2-lp151.3.3.1
0.17.0
1.57.0-1.1
1
cfcontainerization/quarks-job:v0.0.124-g03faac87366b11c5fa5
nghttp2@1.40.0-3.6.3
1.40.0-150000.3.17.1
1
cfcontainerization/quarks-secret:v0.0.677-ga060bb643131dbc0c8f
nghttp2@1.40.0-3.6.3
1.40.0-150000.3.17.1
1
cgtysylr/cluster-octopus:1.0.0aec0f8a38a77
golang.org/x/net@v0.13.0
0.17.0
1
chaerr/kridge:demo-operator-v0.1.266833deec017
golang.org/x/net@v0.7.0
0.17.0
1
chandanteekinavar/findery-market-order-service:1.00cf52bf5ee9a
tomcat-embed-core@9.0.53
9.0.81
1
chaosnative/cle-auth-server:2.7.072ee352bc333
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
chaosnative/cle-frontend:2.7.007b82a82a702
nghttp2@1.46.0-r0
1.46.0-r2
1
chaosnative/cle-license-module:2.7.062cf6adc355e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
chaosnative/cle-server:2.7.0e7bcff4a20c0
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
0.17.0
1
charmcli/soft-serve:v0.4.039523c1a6ba8
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
1.47.0-r2
0.17.0
1
chetangautamm/repo:sipp.v3e7f7049e1544
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.17.0
1
chirpstack/chirpstack-application-server:3fb7667fe037f
golang.org/x/net@v0.0.0-20220726230323-06994584191e
0.17.0
1
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
0.17.0
1
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
golang.org/x/net@v0.8.0
0.17.0
1
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
1
choerodon/event-store-service:0.8.03c94c97f6f69
tomcat-embed-core@8.5.14
8.5.94
1
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
0.17.0
1
chriswells0/first-mate:1.0.5f3918ec8471c
nghttp2@1.53.0-r0
golang.org/x/net@v0.8.0
1.57.0-r0
0.17.0
1
chubaofs/cfs-client:3.2.015ff74209ce7
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
chubaofs/cfs-server:3.2.0205030e045f2
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
circleci/container-agent:34d8d0ae5efc3
golang.org/x/net@v0.8.0
0.17.0
1
ciscolabs/msm-nc:0710202336d02faad958
golang.org/x/net@v0.10.0
0.17.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.