StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,787 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,787 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
sippchetan-opensips0.1.01 of 1See more

sipp chetan-opensips 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
chetangautamm/repo:sipp.v3e7f7049e1544
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

12,531
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
tomcat-embed-core@8.5.14
8.5.94

Open the chart page →

9,808
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0

Open the chart page →

2,869
promtailchoerodon0.23.01 of 1See more

promtail choerodon 0.23.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0

Open the chart page →

2,821
supersetchoerodon1.0.01 of 3See more

superset choerodon 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,439
argocd-metrics-serverchristianhuthVerified publisher1.1.11 of 1See more

argocd-metrics-server christianhuth 1.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-extension-metrics:v1.0.30d614816c4b7
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,031
sloopchristianhuthVerified publisher0.4.01 of 1See more

sloop christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/salesforce/sloop:sha-2ce8bbe119e24f24b1d
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.17.0

Open the chart page →

2,290
mantlechronicleVerified publisher0.1.31 of 1See more

mantle chronicle 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mantlenetworkio/l2geth:v0.4.36bf383d14291
nghttp2@1.46.0-r1
golang.org/x/net@v0.10.0
1.46.0-r2
0.17.0

Open the chart page →

1,934
rpc-routerchronicleVerified publisher0.2.91 of 1See more

rpc-router chronicle 0.2.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
drpcorg/dshackle:0.54.08858fae1859d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

6,487
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.17.0

Open the chart page →

3,595
chekrckotzbauerVerified publisher0.5.31 of 2See more

chekr ckotzbauer 0.5.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/ckotzbauer/chekrdigest-pinnedf299baf467b5
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

3,470
capsule-rancher-addonclastixVerified publisher0.1.15 of 5See more

capsule-rancher-addon clastix 0.1.1

5 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
clastix/capsule-rancher-addon:v0.1.143d301afbca8
golang.org/x/net@v0.4.0
0.17.0
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/net@v0.5.0
0.17.0
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/net@v0.5.0
0.17.0
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/net@v0.5.0
0.17.0
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/net@v0.5.0
0.17.0

Open the chart page →

7,104
kamajiclastixVerified publisher0.0.0+latest2 of 4See more

kamaji clastix 0.0.0+latest

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
clastix/kubectl:v1.2187fabaccb3a6
nghttp2@1.46.0-r0
1.46.0-r2
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0

Open the chart page →

4,630
kamaji-etcdclastixVerified publisher0.17.02 of 4See more

kamaji-etcd clastix 0.17.0

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
clastix/kubectl:v1.22d0376d87ac6b
nghttp2@1.46.0-r0
1.46.0-r2
quay.io/coreos/etcd:v3.5.628cb0630cb85
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0

Open the chart page →

12,021
vcloud-csiclastixVerified publisher1.6.04 of 5See more

vcloud-csi clastix 1.6.0

4 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
0.17.0
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.17.0
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.17.0
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

7,386
kube-acp-stackcloudentity2.28.03 of 7See more

kube-acp-stack cloudentity 2.28.0

3 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cockroachdb/cockroach:v22.2.91116820f4134
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
curlimages/curl:7.87.0f7f265d5c64e
nghttp2@1.47.0-r0
1.47.0-r2
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.17.0

Open the chart page →

20,936
openbankingcloudentity0.1.96 of 6See more

openbanking cloudentity 0.1.9

6 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.17.0
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.17.0
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.17.0
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.17.0
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.17.0
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
golang.org/x/net@v0.0.0-20201207224615-747e23833adb
0.17.0

Open the chart page →

18,040
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

29,922
lampcloudnativeapp1.1.01 of 3See more

lamp cloudnativeapp 1.1.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/php:7-fpm-alpine0aeb129a60da
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,764
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
http2-common@9.4.8.v20171121
http2-server@9.4.8.v20171121
9.4.53
9.4.53

Open the chart page →

7,226
seleniumcloudnativeapp1.0.81 of 1See more

selenium cloudnativeapp 1.0.8

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

11,831
unificloudnativeapp0.4.21 of 1See more

unifi cloudnativeapp 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jacobalberty/unifi:5.10.19c409924e2463
tomcat-embed-core@8.5.34
8.5.94

Open the chart page →

22,448
cp4d-deployercloud-native-toolkit1.0.01 of 1See more

cp4d-deployer cloud-native-toolkit 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
nghttp2@1.33.0-3.el8_2.1
nginx@1:1.14.1-9.module+el8.0.0+4108+af250afe
golang.org/x/net@v0.14.0
0:1.33.0-5.el8_8
1:1.20.1-1.module+el8.8.0+20359+9bd89172.1
0.17.0

Open the chart page →

25,152
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
nghttp2@1.33.0-3.el8_2.1
nodejs@1:12.18.2-1.module+el8.2.0+7233+61d664c1
nodejs-nodemon@1.18.3-1.module+el8.1.0+3369+37ae6a45
0:1.33.0-3.el8_2.2
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:3.0.1-1.module+el8.8.0+19764+7eed1ca3

Open the chart page →

25,454
ibm-toolkit-installcloud-native-toolkit0.3.01 of 1See more

ibm-toolkit-install cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0

Open the chart page →

6,696
iteration-zerocloud-native-toolkit0.2.01 of 1See more

iteration-zero cloud-native-toolkit 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
1.47.0-r2
0.17.0

Open the chart page →

6,921
robot-shopcloud-native-toolkit1.1.15 of 12See more

robot-shop cloud-native-toolkit 1.1.1

5 of the 12 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
robotshop/rs-dispatch:latestde81f1d07b02
nghttp2@1.43.0-1
1.43.0-1+deb11u1
robotshop/rs-mongodb:latest119b545823cd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
robotshop/rs-payment:latest774b52c6180d
nghttp2@1.43.0-1
1.43.0-1+deb11u1
robotshop/rs-ratings:latest4899c686c249
nghttp2@1.43.0-1
1.43.0-1+deb11u1
robotshop/rs-shipping:latest89753ab48919
tomcat-embed-core@9.0.37
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

29,594
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad1 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.17.0

Open the chart page →

18,256
cloudlaunchcloudve0.6.01 of 5See more

cloudlaunch cloudve 0.6.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

12,505
cloudlaunch-servercloudve0.2.01 of 5See more

cloudlaunch-server cloudve 0.2.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

12,176
cloudlaunchservercloudve0.6.01 of 4See more

cloudlaunchserver cloudve 0.6.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cloudve/cloudlaunch-server:latest4a3d7fae90bb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

11,640
ctrox-csi-s3cloudve0.1.01 of 4See more

ctrox-csi-s3 cloudve 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ctrox/csi-s3:v1.2.0-rc.23c72862bea3c
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.17.0

Open the chart page →

3,136
galaxycloudve6.8.62 of 3See more

galaxy cloudve 6.8.6

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.22.0f0d28f204785
nghttp2@1.43.0-1
1.43.0-1+deb11u1
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

5,552
galaxy-depscloudve1.1.14 of 7See more

galaxy-deps cloudve 1.1.1

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq-cluster-operator:1.14.0-scratch-r567ac64a9623a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
bitnamilegacy/rmq-messaging-topology-operator:1.7.1-scratch-r33c26208691a1
golang.org/x/net@v0.0.0-20220614195744-fb05da6f9022
0.17.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
0.17.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

10,543
galaxykubemancloudve2.10.14 of 7See more

galaxykubeman cloudve 2.10.1

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
galaxy/cloudman-server:lateste5c265fe9fcd
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
1.40.0-1ubuntu0.2
0.17.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
golang.org/x/net@v0.8.0
0.17.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
golang.org/x/net@v0.8.0
0.17.0
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0

Open the chart page →

16,117
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.17.0

Open the chart page →

14,285
openstack-cinder-csicloudve1.2.01 of 5See more

openstack-cinder-csi cloudve 1.2.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
k8scloudprovider/cinder-csi-plugin:latesta30c7a2a594a
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

2,061
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.17.0

Open the chart page →

2,853
terminalmancloudve0.3.41 of 1See more

terminalman cloudve 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cloudve/ttyd:latestd79c1c5881c0
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

13,170
cluster-octopuscluster-octopus1.0.01 of 1See more

cluster-octopus cluster-octopus 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cgtysylr/cluster-octopus:1.0.0aec0f8a38a77
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

1,040
kovecmacraeVerified publisher0.2.01 of 1See more

kove cmacrae 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0

Open the chart page →

2,089
kove-deprecationscmacraeVerified publisher0.1.21 of 1See more

kove-deprecations cmacrae 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/cmacrae/kove:v0.1.0db1244edefc8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0

Open the chart page →

2,203
lgtmcmacraeVerified publisher0.1.01 of 1See more

lgtm cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cmacrae/lgtm:0.1.0dec8d490fe40
golang.org/x/net@v0.0.0-20181108082009-03003ca0c849
0.17.0

Open the chart page →

1,909
clamapicnieg2.0.52 of 2See more

clamapi cnieg 2.0.5

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
audig/clamapi:2.1.62c3fe34ee430
tomcat-embed-core@9.0.37
9.0.81
ghcr.io/mailu/clamav:1.9.5001d30483e4a8
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

4,672
default-chartcnieg3.0.81 of 1See more

default-chart cnieg 3.0.8

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.23.2ab589a3c466e
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

915
dependency-trackcnieg3.0.81 of 2See more

dependency-track cnieg 3.0.8

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dependencytrack/frontend:4.6.124422d762e08
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

2,503
ganttcnieg2.1.01 of 1See more

gantt cnieg 2.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cnieg/gantt:1.1.2d4b478d76f2a
tomcat-embed-core@9.0.65
9.0.81

Open the chart page →

2,390
pulsarcnieg1.0.82 of 2See more

pulsar cnieg 1.0.8

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.6.14db6ff0b4045
http2-common@9.4.11.v20180605
http2-server@9.4.11.v20180605
9.4.53
9.4.53
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
tomcat-embed-core@8.5.31
8.5.94

Open the chart page →

16,860
door-agentcnoVerified publisher3.0.154 of 15See more

door-agent cno 3.0.15

4 of the 15 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
beopenit/door-helm:v3.0.1b4d9f9bee224
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.15.0
0:1.33.0-5.el8_8
0.17.0
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
golang.org/x/net@v0.7.0
0.17.0
envoyproxy/ratelimit:6f5de117b6cb6e16f8c9
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
0.17.0
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
0.17.0

Open the chart page →

19,380
colecole1.4.21 of 1See more

cole cole 1.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ntakashi/cole:1.2.3f7b68bee2a68
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

838

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0:1.33.0-4.el8_6.1
0.17.0
1
deluan/navidrome:0.49.311a24da08977
golang.org/x/net@v0.5.0
0.17.0
1
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
1
devopstales/trivy-operator:2.575136aa7a26e
nghttp2@1.51.0-r0
golang.org/x/net@v0.4.0
1.51.0-r2
0.17.0
1
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
digitalocean/do-operator:v0.1.65e5deb4db76e
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
nghttp2@1.46.0-r0
1.46.0-r2
1
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
dniel/api-posts:master45a667852f2a
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
dniel/forwardauth:latestf67129ea1c64
tomcat-embed-core@9.0.21
9.0.81
1
dnsforge/xteve:latest4d9a685c8c28
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
1.51.0-r2
0.17.0
1
dollarshaveclub/furan2:master14a257836529
golang.org/x/net@v0.0.0-20201002202402-0a1ea396d57c
0.17.0
1
dollarshaveclub/thermite:0.0.31663cbf25fcfe
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0.17.0
1
domainmod/domainmod:4.23.04017bfe4c597
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
golang.org/x/net@v0.11.0
0.17.0
1
dongjiang1989/cpusets-controller:v1.1.1dc5bd483874c
golang.org/x/net@v0.10.0
0.17.0
1
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
golang.org/x/net@v0.10.0
0.17.0
1
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
golang.org/x/net@v0.7.0
0.17.0
1
dongjiang1989/ns-node-affinity:latest451f7823723c
golang.org/x/net@v0.7.0
0.17.0
1
douz/helpdesk:latest4384103d0219
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
douz/overlord:latestf2bc7fc068c1
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.17.0
1
dremio/dremio-oss:24.1.080ed2e3b7c43
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
drone/drone-runner-docker:1.8.1137e79c5e23c
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.17.0
1
drone/kubernetes-secrets:latest206df2280ecf
golang.org/x/net@v0.0.0-20180811021610-c39426892332
0.17.0
1
drpcorg/dshackle:0.54.08858fae1859d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
drumsergio/duplicacy-container:0.1.0dd3ee9703969
golang.org/x/net@v0.10.0
0.17.0
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
nghttp2@1.51.0-r0
golang.org/x/net@v0.5.0
1.51.0-r2
0.17.0
1
duck1123/astral:latestf4d5b6526c2a
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
duck1123/cert-downloader:latest0e29f19fa67c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
duck1123/lnd-fileserver:latest9d6fb247b714
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
duck1123/me.untethr.nostr-relay:0.2.1119fc5d4cbfb
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
duyetdev/applause-btn:latest25e59d223eaa
golang.org/x/net@v0.0.0-20200822124328-c89045814202
0.17.0
1
dvdlevanon/kubernetes-database-scaler:v0.0.361e79c1643fe4
golang.org/x/net@v0.8.0
0.17.0
1
dysnix/gke-upgrade-notification-handler:latestc166f958f86a
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
easypi/openrefine:3.7.0d2950a36a576
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
easysoft/quickon-zentao:18.5592ad5df1f8b
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
golang.org/x/net@v0.0.0-20200822124328-c89045814202
0.17.0
1
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
golang.org/x/net@v0.10.0
0.17.0
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
nghttp2@1.46.0-r0
1.46.0-r2
1
ekofr/pihole-exporter:0.0.109fdad6f352e0
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
0.17.0
1
elastic/apm-server:7.17.6c7a1c63257d0
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
1.40.0-1ubuntu0.2
0.17.0
1
elastictranscoder/media:627e21dc963ab3858c6b
nghttp2@1.30.0-1ubuntu1
tomcat-embed-core@9.0.46
1.30.0-1ubuntu1+esm2
9.0.81
1
elastictranscoder/media-storage:f6d861a026208b8c2359
nghttp2@1.30.0-1ubuntu1
tomcat-embed-core@9.0.46
1.30.0-1ubuntu1+esm2
9.0.81
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
nghttp2@1.30.0-1ubuntu1
tomcat-embed-core@9.0.46
1.30.0-1ubuntu1+esm2
9.0.81
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
nghttp2@1.30.0-1ubuntu1
tomcat-embed-core@9.0.46
1.30.0-1ubuntu1+esm2
9.0.81
1
elyra/kernel-image-puller:3.2.2c922f1f1646a
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
emqx/ecp-ui:2.5.1e33e9816f147
nginx@1.27.2-1~bookworm
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.