StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,107
of 17,790 indexed, latest versions
Container images
2,471
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,107 of 17,790 indexed charts deploy, on 2,471 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,572
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,107 by stars
ChartLatestAffected imagesRadar Score
sn-platform-slimstreamnative1.11.442 of 6See more

sn-platform-slim streamnative 1.11.44

2 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/net@v0.8.0
0.17.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

10,214
student-producerstudentproducerVerified publisher2.0.01 of 1See more

student-producer studentproducer 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
aroralalit/student-producer:1.0.02a094f597b36
tomcat-embed-core@9.0.75
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

3,021
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
nghttp2@1.47.0-r1
1.47.0-r2

Open the chart page →

12,541
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
nghttp2@1.47.0-r1
1.47.0-r2

Open the chart page →

12,541
substra-frontendsubstraVerified publisher1.2.31 of 1See more

substra-frontend substra 1.2.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
nginx@1.25.4-1~bookworm
no fix listed

Open the chart page →

3,053
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,353
nocodbsudermanjr0.1.01 of 1See more

nocodb sudermanjr 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nocodb/nocodb:0.84.15f9b799933aa8
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.17.0

Open the chart page →

2,070
pagessunilb2590-pages1.0.02 of 3See more

pages sunilb2590-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
cludodsuperorbitalVerified publisher0.0.51 of 1See more

cludod superorbital 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
superorbital/cludod:0.0.2-alphad59732f61d6e
golang.org/x/net@v0.0.0-20220111093109-d55c255bac03
0.17.0

Open the chart page →

2,371
do-operatorsupporttools0.1.71 of 2See more

do-operator supporttools 0.1.7

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
digitalocean/do-operator:v0.1.65e5deb4db76e
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0

Open the chart page →

1,063
nfs-provisionersupporttools0.11.01 of 1See more

nfs-provisioner supporttools 0.11.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openebs/provisioner-nfs:0.11.04f41dd782761
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

2,680
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

12,100
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

12,712
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
nghttp2@1.40.0-1ubuntu0.1
nodejs@10.19.0~dfsg-3ubuntu1.3
golang.org/x/net@v0.8.0
1.40.0-1ubuntu0.2
10.19.0~dfsg-3ubuntu1.6+esm2
0.17.0

Open the chart page →

10,959
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

12,100
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
nghttp2@1.40.0-1ubuntu0.1
golang.org/x/net@v0.8.0
1.40.0-1ubuntu0.2
0.17.0

Open the chart page →

18,846
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
nodejs-nodemon@3.0.1-1.module+el8.8.0+19757+8ca87034
0:3.0.1-1.module+el8.8.0+19764+7eed1ca3

Open the chart page →

14,058
synadia-serversynadiaVerified publisher1.1.101 of 2See more

synadia-server synadia 1.1.10

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

1,970
agentssynapse0.1.303 of 9See more

agents synapse 0.1.30

3 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.42.07d32a4eddec7
golang.org/x/net@v0.5.0
0.17.0
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/net@v0.7.0
0.17.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

7,272
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,822
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,711
ccm-hcloudsyself1.0.111 of 1See more

ccm-hcloud syself 1.0.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

1,712
hcloud-csisyself0.1.11 of 6See more

hcloud-csi syself 0.1.1

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:1.6.01475d525f9a4
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

2,917
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0

Open the chart page →

2,876
promtailt3n1.0.01 of 1See more

promtail t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0

Open the chart page →

2,828
tidewayst3n2.0.11 of 1See more

tideways t3n 2.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
t3nde/tideways:1.7.2777e008f764db
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,206
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,489
super-mariotechpreta0.1.11 of 1See more

super-mario techpreta 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nirmalnaveen/supermario:latest8541a39162f3
nghttp2@1.52.0-1
nginx@1.25.3-1~bookworm
1.52.0-1+deb12u1
no fix listed

Open the chart page →

6,321
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
http2-common@9.4.34.v20201102
9.4.53

Open the chart page →

4,240
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

4,222
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0

Open the chart page →

3,772
clickhousetemp-charts0.7.12 of 3See more

clickhouse temp-charts 0.7.1

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

8,706
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

10,585
istio-ingresstemp-charts0.3.31 of 1See more

istio-ingress temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.088c6c693e67a
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

10,531
temporaltemporal0.28.97 of 13See more

temporal temporal 0.28.9

7 of the 13 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
temporalio/admin-tools:1.22.0836af062af30
nghttp2@1.55.1-r0
golang.org/x/net@v0.14.0
1.57.0-r0
0.17.0
temporalio/server:1.22.0ddeebf8bad8f
nghttp2@1.55.1-r0
golang.org/x/net@v0.14.0
1.57.0-r0
0.17.0
temporalio/ui:2.16.2af9c9349708f
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.17.0

Open the chart page →

21,040
echoserverteochenglim0.1.01 of 1See more

echoserver teochenglim 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jmalloc/echo-server:0.3.1e4eaee2c7998
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0

Open the chart page →

1,443
pagestest43221.0.02 of 3See more

pages test4322 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
tomcat-embed-core@9.0.29
9.0.81

Open the chart page →

12,516
webapp1test-helm-chart-10.1.01 of 1See more

webapp1 test-helm-chart-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
devopsjourney1/mywebapp:latestbd1ec6838570
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,469
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

39,273
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

28,944
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

28,515
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

28,990
vehicle-dashboardtest-vehi-dash0.1.02 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

2 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
library/mongo:5.0.217c81758cb295
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2

Open the chart page →

20,378
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
tomcat-embed-core@9.0.63
9.0.81
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
tomcat-embed-core@9.0.63
9.0.81
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
tomcat-embed-core@9.0.63
9.0.81
thingsboard/tb-node:3.4.1645f43b688f7
tomcat-embed-core@9.0.63
9.0.81

Open the chart page →

25,423
pagesthiru-pages1.0.02 of 3See more

pages thiru-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
mc-routerthl-chartsVerified publisher0.1.01 of 1See more

mc-router thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
itzg/mc-router:1.16.1bb552b59fb53
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
0.17.0

Open the chart page →

1,855
monitoringthl-chartsVerified publisher0.1.17 of 10See more

monitoring thl-charts 0.1.1

7 of the 10 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
0.17.0
grafana/loki:2.5.0f9ef133793af
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
0.17.0
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
quay.io/prometheus/prometheus:v2.34.0b37103e03399
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

18,940
pagesthuy-pages1.0.02 of 3See more

pages thuy-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nginx/nginx-ingress:1.11.1eb5b4fd73325
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.17.0

Open the chart page →

6,888

Container images carrying it

2,471 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.17.0
1
bitnamilegacy/rabbitmq:3.11.18-debian-11-r029b0a2330572
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/rabbitmq:3.10.88f7161d8ce19
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/net@v0.0.0-20220614195744-fb05da6f9022
0.17.0
1
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
1
bitpoke/wordpress-operator:v0.12.421284d1df473
golang.org/x/net@v0.8.0
0.17.0
1
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
golang.org/x/net@v0.8.0
0.17.0
1
bivas/presto:0.19605545994f806
http2-common@9.4.8.v20171121
http2-server@9.4.8.v20171121
9.4.53
9.4.53
1
blipai/deckard:0.0.28737d5d19a312
golang.org/x/net@v0.10.0
0.17.0
1
blockscout/blockscout:5.1.5c365a8f2dc12
nghttp2@1.47.0-r0
1.47.0-r2
1
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
bsgrigorov/helm-operator:latest45ab095f09c8
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0:1.33.0-5.el8_8
0.17.0
1
buildkite/agent:3.25.0aec38cfaae0e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0
1
bulich/domain-exporter:latest6d0b780f7c7b
golang.org/x/net@v0.10.0
0.17.0
1
buntha/mlflow:2.1.1154542cc3083
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
golang.org/x/net@v0.10.0
0.17.0
1
camerahub/camerahub:0.36.23a5af37dd6e1b
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
camptocamp/bucket-cloner:latestacfafc308d88
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
0.17.0
1
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
casbin/casdoor:v1.224.066f836ef778b
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
1.51.0-r2
0.17.0
1
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
0.17.0
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
nghttp2@1.39.2-lp151.3.3.1
0.17.0
1.57.0-1.1
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
nghttp2@1.39.2-lp151.3.3.1
0.17.0
1.57.0-1.1
1
cfcontainerization/quarks-job:v0.0.124-g03faac87366b11c5fa5
nghttp2@1.40.0-3.6.3
1.40.0-150000.3.17.1
1
cfcontainerization/quarks-secret:v0.0.677-ga060bb643131dbc0c8f
nghttp2@1.40.0-3.6.3
1.40.0-150000.3.17.1
1
cgtysylr/cluster-octopus:1.0.0aec0f8a38a77
golang.org/x/net@v0.13.0
0.17.0
1
chaerr/kridge:demo-operator-v0.1.266833deec017
golang.org/x/net@v0.7.0
0.17.0
1
chandanteekinavar/findery-market-order-service:1.00cf52bf5ee9a
tomcat-embed-core@9.0.53
9.0.81
1
chaosnative/cle-auth-server:2.7.072ee352bc333
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
chaosnative/cle-frontend:2.7.007b82a82a702
nghttp2@1.46.0-r0
1.46.0-r2
1
chaosnative/cle-license-module:2.7.062cf6adc355e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
chaosnative/cle-server:2.7.0e7bcff4a20c0
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
0.17.0
1
charmcli/soft-serve:v0.4.039523c1a6ba8
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
1.47.0-r2
0.17.0
1
chetangautamm/repo:sipp.v3e7f7049e1544
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.17.0
1
chirpstack/chirpstack-application-server:3fb7667fe037f
golang.org/x/net@v0.0.0-20220726230323-06994584191e
0.17.0
1
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
0.17.0
1
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
golang.org/x/net@v0.8.0
0.17.0
1
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
1
choerodon/event-store-service:0.8.03c94c97f6f69
tomcat-embed-core@8.5.14
8.5.94
1
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
0.17.0
1
chriswells0/first-mate:1.0.5f3918ec8471c
nghttp2@1.53.0-r0
golang.org/x/net@v0.8.0
1.57.0-r0
0.17.0
1
chubaofs/cfs-client:3.2.015ff74209ce7
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
chubaofs/cfs-server:3.2.0205030e045f2
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
circleci/container-agent:34d8d0ae5efc3
golang.org/x/net@v0.8.0
0.17.0
1
ciscolabs/msm-nc:0710202336d02faad958
golang.org/x/net@v0.10.0
0.17.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.