StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,792 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,792 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
pagespages-blackburn1.0.02 of 3See more

pages pages-blackburn 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-botes1.0.02 of 3See more

pages pages-botes 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-brian1.0.02 of 3See more

pages pages-brian 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-buckll1.0.02 of 3See more

pages pages-buckll 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-camden1.0.02 of 3See more

pages pages-camden 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-camden7711.0.02 of 3See more

pages pages-camden771 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-diarmuidkeane1.0.02 of 3See more

pages pages-diarmuidkeane 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-draco1.0.02 of 3See more

pages pages-draco 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-ellora1.0.02 of 3See more

pages pages-ellora 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-finchley1.0.02 of 3See more

pages pages-finchley 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-fornax1.0.02 of 3See more

pages pages-fornax 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-harsh1.0.02 of 3See more

pages pages-harsh 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespagesk1.0.02 of 3See more

pages pagesk 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-microservice-ashim1.0.02 of 3See more

pages pages-microservice-ashim 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-mihai1.0.02 of 3See more

pages pages-mihai 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-nivesh1.0.02 of 3See more

pages pages-nivesh 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespagessandeepgudu1.0.02 of 3See more

pages pagessandeepgudu 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-shubhanker1.0.02 of 3See more

pages pages-shubhanker 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-ssharma09091.0.02 of 3See more

pages pages-ssharma0909 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-sucharitha1.0.02 of 3See more

pages pages-sucharitha 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-sudhir1.0.02 of 3See more

pages pages-sudhir 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-sushi1.0.02 of 3See more

pages pages-sushi 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-vasanth58141.0.02 of 3See more

pages pages-vasanth5814 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagespages-vjp1.0.02 of 3See more

pages pages-vjp 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
Parpar0.1.01 of 1See more

Par par 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/jmcgrath207/par:v0.1.09977511cb142
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

889
blockscoutparadeum-teamVerified publisher0.1.51 of 1See more

blockscout paradeum-team 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/netwarps/blockscoutdigest-pinnedbecd3e39360a
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

3,450
parcaparca4.19.01 of 2See more

parca parca 4.19.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

3,364
parcaparca-chart0.1.01 of 1See more

parca parca-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,985
scaleway-webhookparticuleio0.0.11 of 1See more

scaleway-webhook particuleio 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,354
hammondpascaliskeVerified publisher2.0.01 of 2See more

hammond pascaliske 2.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
0.17.0

Open the chart page →

1,807
helloworldpauls-helm-charts2.0.01 of 1See more

helloworld pauls-helm-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
paulczar/spring-helloworld:latestc7140cecd5f7
tomcat-embed-core@9.0.16
9.0.81

Open the chart page →

5,598
pagespawan-pages1.0.02 of 3See more

pages pawan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
todo-apipb-todo-api-v10.1.01 of 2See more

todo-api pb-todo-api-v1 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
pavanelthepu/todo-api:1.0.2f47658e3b24c
tomcat-embed-core@9.0.48
9.0.81

Open the chart page →

2,547
permission-managerpermission-manager1.0.0-seal1 of 1See more

permission-manager permission-manager 1.0.0-seal

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,267
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0:1.33.0-4.el8_4.1
0.17.0

Open the chart page →

15,474
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0:1.33.0-4.el8_4.1
0.17.0

Open the chart page →

15,474
apache-knox-helmpfisterer-knox0.1.111 of 1See more

apache-knox-helm pfisterer-knox 0.1.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
farberg/apache-knox-docker:1.6.14b4a22487394
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

6,237
binaryvision-tlophntom0.0.41 of 1See more

binaryvision-tlo phntom 0.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phntom/binaryvision-tlo-static:0.0.4e8b9ac93a3dd
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,277
container-agentphntom100.0.11 of 1See more

container-agent phntom 100.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
circleci/container-agent:34d8d0ae5efc3
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,974
email-managerphntom0.1.221 of 2See more

email-manager phntom 0.1.22

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phntom/email-manager:0.1.22d8e2a9f2f085
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,566
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

4,644
kochiphntom1.1.41 of 1See more

kochi phntom 1.1.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phntom/kochi:1.1.33b82358bd56e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0

Open the chart page →

2,964
loki-stackphntom2.10.22 of 2See more

loki-stack phntom 2.10.2

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/loki:2.4.2b3af8ead67d7
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
0.17.0
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
0.17.0

Open the chart page →

5,724
mattermost-defaultbackendphntom0.1.41 of 1See more

mattermost-defaultbackend phntom 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phntom/mattermost-defaultbackend:6.4.0c318dc90a4bf
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,393
mindavphntom0.1.61 of 2See more

mindav phntom 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phntom/mindav:0.1.7-kix35695f546abbb
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.17.0

Open the chart page →

4,159
npre-essentialsphntom0.1.6012 of 22See more

npre-essentials phntom 0.1.60

12 of the 22 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
curlimages/curl:7.85.09fab1b73f45e
nghttp2@1.46.0-r0
1.46.0-r2
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
grafana/promtail:2.7.0c16c710f7333
golang.org/x/net@v0.0.0-20220920203100-d0c6ba3f52d9
0.17.0
phntom/chartmuseum:v0.15.29242b4df9e65
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.17.0
phntom/kochi:1.1.33b82358bd56e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
phntom/oauth2-proxy:v7.3.48ea656a2a895
golang.org/x/net@v0.0.0-20221012135044-0b7e1fb9d458
0.17.0
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/net@v0.1.0
0.17.0
quay.io/prometheus-operator/prometheus-operator:v0.61.1cd7d1a82ef00
golang.org/x/net@v0.2.0
0.17.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
0.17.0
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
nghttp2@1.47.0-r0
golang.org/x/net@v0.1.0
1.47.0-r2
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
0.17.0

Open the chart page →

26,888
postgresql-backupphntom0.1.91 of 1See more

postgresql-backup phntom 0.1.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phntom/postgresql-backup-s3:1.0.2249b6488f618b
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

2,556
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

22,165
pagespighosh-pages1.0.02 of 3See more

pages pighosh-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
firehose-corepinaxVerified publisher0.1.11 of 2See more

firehose-core pinax 0.1.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.17.0

Open the chart page →

3,544

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
grafana/loki:2.0.077e138f81a8e
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
1
grafana/loki:2.8.2b1da1d23037e
golang.org/x/net@v0.7.0
0.17.0
1
grafana/loki:2.4.2b3af8ead67d7
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
0.17.0
1
grafana/loki-canary:2.6.1ab2a2569307b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
0.17.0
1
grafana/phlare:0.5.1330f990cdad9
golang.org/x/net@v0.5.0
0.17.0
1
grafana/promtail:2.6.1072527b12cdf
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
grafana/promtail:2.0.05fd12edcc694
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
1
grafana/promtail:2.7.0c16c710f7333
golang.org/x/net@v0.0.0-20220920203100-d0c6ba3f52d9
0.17.0
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0
1
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
tomcat-embed-core@9.0.68
9.0.81
1
gresearchdev/siembol-config-editor-ui:latest071e7109a981
nghttp2@1.47.0-r0
1.47.0-r2
1
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
tomcat-embed-core@9.0.68
9.0.81
1
groundnuty/k8s-wait-for:v1.684edcf796267
nghttp2@1.46.0-r0
1.46.0-r2
1
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
1
guacamole/guacamole:1.1.0333a7f40c145
tomcat-coyote@8.5.41
8.5.94
1
guacamole/guacamole:1.3.0739cb6820ae8
tomcat-coyote@8.5.61
8.5.94
1
gulacedia/web-dvwa-new:v367b467d961ca
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
tomcat-embed-core@9.0.60
9.0.81
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
tomcat-embed-core@9.0.60
9.0.81
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
tomcat-embed-core@9.0.60
9.0.81
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
tomcat-embed-core@9.0.60
9.0.81
1
gurolakman/ussigw-core:1.0.48739565c3ea2
tomcat-embed-core@9.0.60
9.0.81
1
gutmensch/podnat-controller:0.5.2566979793fc4
golang.org/x/net@v0.4.0
0.17.0
1
ha33ona/python:test6affdfc644d0
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
haproxytech/haproxy-alpine:2.6.614e4afa90dfd
golang.org/x/net@v0.2.0
0.17.0
1
haproxytech/haproxy-alpine:2.8.08951be4b4e1c
golang.org/x/net@v0.11.0
0.17.0
1
hashicorp/boundary:0.8.1fb70bd9210ff
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
hashicorp/consul:1.15.3ddff34041c5c
nghttp2@1.51.0-r0
golang.org/x/net@v0.8.0
1.51.0-r2
0.17.0
1
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
golang.org/x/net@v0.7.0
0.17.0
1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/net@v0.7.0
0.17.0
1
hashicorp/terraform:1.44dcb45513699
nghttp2@1.55.1-r0
golang.org/x/net@v0.6.0
1.57.0-r0
0.17.0
1
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.17.0
1
hashicorp/vault:1.14.0b2177a8bfe85
golang.org/x/net@v0.10.0
0.17.0
1
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0
1
hashicorp/vault-k8s:1.2.14500e988b7ce
golang.org/x/net@v0.7.0
0.17.0
1
hashicorp/vault-k8s:0.6.05697b85bc69a
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
0.17.0
1
hashicorp/vault-k8s:0.14.0aff47b5ba39c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
1
hashicorp/waypoint:0.11.397d521a27498
nghttp2@1.51.0-r0
golang.org/x/net@v0.1.0
1.51.0-r2
0.17.0
1
hasura/graphql-engine:v2.34.0-ce0111b0204136
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
haugene/transmission-openvpn:4.0059216cfae4b
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
haveagitgat/tdarr:2.00.181256348872ce
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
1
hazegoodlife/haaze:veggiesite50f02d2d5d4d
nginx@1.27.4-1~bookworm
no fix listed
1
hazegoodlife/haaze:milksite8d4c63169e14
nginx@1.27.4-1~bookworm
no fix listed
1
hazelcast/hazelcast:5.3.18fe26efde8e1
nghttp2@1.55.1-r0
1.57.0-r0
1
hazelcast/management-center:5.3.2f9d34300d330
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
healthchecks/healthchecks:v2.8.1e82bb0836e30
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.