StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,187
of 17,821 indexed, latest versions
Container images
2,543
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,187 of 17,821 indexed charts deploy, on 2,543 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more575
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0217
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+8 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more182
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r0, 1.22.0-r1, 1.22.1-r0+2 more1.20.2-r2, 1.22.1-r1, 1.24.0-r714
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,614
tomcat-embed-coremaven8.5.4, 8.5.6, 8.5.11, 8.5.14+52 more8.5.94, 9.0.81, 10.1.14166
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+11 more9.4.53, 11.0.1721
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1717
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.47+8 more8.5.94, 9.0.8113
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,187 by stars
ChartLatestAffected imagesRadar Score
temporalwenerme0.15.15 of 13See more

temporal wenerme 0.15.1

5 of the 13 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.17.0
prom/prometheus:v2.16.0e4ca62c0d62f
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.17.0
temporalio/admin-tools:1.15.135034611d981
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
temporalio/server:1.15.1e26758f5a1bf
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

22,719
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.17.0

Open the chart page →

3,379
ceph-csi-cephfswikimedia0.1.85 of 5See more

ceph-csi-cephfs wikimedia 0.1.8

5 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/csi-provisioner:v3.2.14ad5fcdbe7e9
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
0.17.0
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

10,337
ceph-csi-rbdwikimedia0.1.136 of 6See more

ceph-csi-rbd wikimedia 0.1.13

6 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/csi-provisioner:v3.2.14ad5fcdbe7e9
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
0.17.0
quay.io/cephcsi/cephcsi:v3.7.2f7f8228f17cc
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

11,844
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

2,035
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,753
csi-driver-host-pathwiremindVerified publisher0.1.18 of 8See more

csi-driver-host-path wiremind 0.1.1

8 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
golang.org/x/net@v0.0.0-20220802222814-0bcc04d9c69b
0.17.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
0.17.0
registry.k8s.io/sig-storage/livenessprobe:v2.8.0cacee2b5c36d
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
0.17.0

Open the chart page →

12,666
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
0.17.0

Open the chart page →

2,793
prometheus-openstack-exporterwiremindVerified publisher0.5.01 of 1See more

prometheus-openstack-exporter wiremind 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/openstack-exporter/openstack-exporter:1.7.0e5146a7dd515
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,480
kafka-connect-uiwitcom-gmbh0.5.01 of 2See more

kafka-connect-ui witcom-gmbh 0.5.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0

Open the chart page →

2,513
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0

Open the chart page →

2,624
vaultwardenwitcom-gmbh0.2.01 of 2See more

vaultwarden witcom-gmbh 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,590
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,022
workadventureworkadventure1.1.03 of 9See more

workadventure workadventure 1.1.0

3 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
matthiasluedtke/iconserver:v3.16.0661d607b0fbc
golang.org/x/net@v0.7.0
0.17.0
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
nghttp2@1.46.0-r0
1.46.0-r2
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

16,106
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

11,563
commentopluspluswyrihaximusnetVerified publisher0.4.01 of 1See more

commentoplusplus wyrihaximusnet 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
caroga/commentoplusplus:v1.8.7f3233882b3bd
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

1,961
oauth2xdVerified publisher1.0.01 of 1See more

oauth2 xd 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
lishimeng/hufu:v1.2.13d5752dac834
golang.org/x/net@v0.12.0
0.17.0

Open the chart page →

2,008
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
golang.org/x/net@v0.8.0
0.17.0
lishimeng/passport-profile:v0.2.160970dfe5dc8f
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

3,978
tabbyxdVerified publisher1.0.62 of 2See more

tabby xd 1.0.6

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
nginx@1.25.5-1~bookworm
no fix listed
lishimeng/tabby:v1.0.48145c3dc83c8
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

7,770
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,999
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

2,070
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
golang.org/x/net@v0.5.0
0.17.0

Open the chart page →

13,925
canal-serverxxl-job-adminVerified publisher0.1.21 of 2See more

canal-server xxl-job-admin 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/dellnoantechnp/canal-server:v1.1.6af724c855f65
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

5,706
kadalu-operatorxxl-job-adminVerified publisher1.2.42 of 4See more

kadalu-operator xxl-job-admin 1.2.4

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kadalu/kadalu-operator:1.2.03726d7a805f2
golang.org/x/net@v0.13.0
0.17.0
raspbernetes/csi-node-driver-registrar:2.0.1a552705225fd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

4,928
nfs-subdir-external-provisionerxxl-job-adminVerified publisher4.0.181 of 1See more

nfs-subdir-external-provisioner xxl-job-admin 4.0.18

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,746
rocketmqxxl-job-adminVerified publisher1.0.12 of 2See more

rocketmq xxl-job-admin 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/rocketmq:4.9.479b41e2956de
tomcat-embed-core@8.5.46
8.5.94
apacherocketmq/rocketmq-dashboard:1.0.024799aff6cf8
tomcat-embed-core@9.0.29
9.0.81

Open the chart page →

9,133
xxl-job-adminxxl-job-adminVerified publisher1.1.31 of 1See more

xxl-job-admin xxl-job-admin 1.1.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
xuxueli/xxl-job-admin:2.4.0640093c35fd6
tomcat-embed-core@9.0.71
9.0.81

Open the chart page →

3,118
matrixdb-operatorymatrixOfficialVerified publisher0.13.01 of 2See more

matrixdb-operator ymatrix 0.13.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
matrixdb/kubebuilder_kube-rbac-proxy:v0.12.0ed3c7e6291e8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.17.0

Open the chart page →

1,966
rawfile-csiymatrixVerified publisher0.2.14 of 4See more

rawfile-csi ymatrix 0.2.1

4 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
matrixdb/custom-external-provisioner:4622a07d7-202204247e9ffe249a51
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
matrixdb/rawfile-csi:v0.2.195b2e38e913d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.17.0
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
golang.org/x/net@v0.0.0-20210316092652-d523dce5a7f4
0.17.0

Open the chart page →

8,002
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

3,025
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
nghttp2@1.51.0-r0
golang.org/x/net@v0.8.0
1.51.0-r2
0.17.0
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

5,077
zahori-moonzahoriVerified publisher1.0.13 of 3See more

zahori-moon zahori 1.0.1

3 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/aerokube/moon:2.5.1a8837b00ba1c
golang.org/x/net@v0.7.0
0.17.0
quay.io/aerokube/moon-conf:2.5.19ca307b30080
golang.org/x/net@v0.7.0
0.17.0
quay.io/aerokube/moon-ui:2.0.589990b146824
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

2,908
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
tomcat-embed-core@10.1.10
10.1.14

Open the chart page →

3,498
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
tomcat-embed-core@9.0.71
9.0.81

Open the chart page →

5,847
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

6,027
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,839
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

3,701

Container images carrying it

2,543 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
gophish/gophish:0.12.18a57cd171999
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.17.0
1
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
gotify/server-arm7:2.0.23d91e302ad1d0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
gotson/komga:0.99.49b15ea6bfc30
nghttp2@1.30.0-1ubuntu1
tomcat-embed-core@9.0.46
1.30.0-1ubuntu1+esm2
9.0.81
1
gradiant/hdfs:3.2.2e3bf364fe713
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
grafana/agent:v0.20.0825c09373d27
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
0.17.0
1
grafana/agent-operator:v0.34.1045c9125634c
golang.org/x/net@v0.10.0
0.17.0
1
grafana/grafana:6.6.0052147d7e0ec
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0
1
grafana/grafana:10.1.50679e877ba20
golang.org/x/net@v0.12.0
0.17.0
1
grafana/grafana:7.5.609bb407e26ab
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
grafana/grafana:7.3.315b977f5207d
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
0.17.0
1
grafana/grafana:9.4.71a359d92f40e
golang.org/x/net@v0.4.0
0.17.0
1
grafana/grafana:10.1.11b9ca4bbc4a2
nghttp2@1.55.1-r0
golang.org/x/net@v0.12.0
1.57.0-r0
0.17.0
1
grafana/grafana:9.5.239c849cebccc
nghttp2@1.51.0-r0
golang.org/x/net@v0.8.0
1.51.0-r2
0.17.0
1
grafana/grafana:8.0.3696823fbc561
golang.org/x/net@v0.0.0-20210521195947-fe42d452be8f
0.17.0
1
grafana/grafana:7.3.46d42886b3ebe
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
0.17.0
1
grafana/grafana:7.2.1733842cca5bd
golang.org/x/net@v0.0.0-20200813134508-3edf25e44fcc
0.17.0
1
grafana/grafana:9.4.376dcf36e7d2a
golang.org/x/net@v0.4.0
0.17.0
1
grafana/grafana:9.1.19746858c20e6
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
0.17.0
1
grafana/grafana:9.0.1a738d0744784
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.17.0
1
grafana/grafana:8.1.5b7dd9cd0e59d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
grafana/grafana:6.5.1befcd84da2c1
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.17.0
1
grafana/grafana:8.3.5cd7cb4345aa7
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
0.17.0
1
grafana/grafana:8.3.4cf81d2c753c8
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
0.17.0
1
grafana/grafana:7.4.5d322192ed2fa
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
0.17.0
1
grafana/grafana:9.3.6e5a9655dabef
golang.org/x/net@v0.1.0
0.17.0
1
grafana/grafana:8.5.3ecc1b80b8ca2
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
0.17.0
1
grafana/kubernetes-diff-logger:0.0.598f6d1cd1e25
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
grafana/logcli:main-c90366d-amd643d85bb66e39b
golang.org/x/net@v0.0.0-20210505214959-0714010a04ed
0.17.0
1
grafana/loki:2.0.077e138f81a8e
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
1
grafana/loki:2.8.2b1da1d23037e
golang.org/x/net@v0.7.0
0.17.0
1
grafana/loki:2.4.2b3af8ead67d7
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
0.17.0
1
grafana/loki-canary:2.6.1ab2a2569307b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
0.17.0
1
grafana/phlare:0.5.1330f990cdad9
golang.org/x/net@v0.5.0
0.17.0
1
grafana/promtail:2.6.1072527b12cdf
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
grafana/promtail:2.0.05fd12edcc694
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
1
grafana/promtail:2.7.0c16c710f7333
golang.org/x/net@v0.0.0-20220920203100-d0c6ba3f52d9
0.17.0
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0
1
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
tomcat-embed-core@9.0.68
9.0.81
1
gresearchdev/siembol-config-editor-ui:latest071e7109a981
nghttp2@1.47.0-r0
1.47.0-r2
1
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
tomcat-embed-core@9.0.68
9.0.81
1
groundnuty/k8s-wait-for:v1.684edcf796267
nghttp2@1.46.0-r0
1.46.0-r2
1
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
1
guacamole/guacamole:1.1.0333a7f40c145
tomcat-coyote@8.5.41
8.5.94
1
guacamole/guacamole:1.3.0739cb6820ae8
tomcat-coyote@8.5.61
8.5.94
1
gulacedia/web-dvwa-new:v367b467d961ca
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
tomcat-embed-core@9.0.60
9.0.81
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
tomcat-embed-core@9.0.60
9.0.81
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
tomcat-embed-core@9.0.60
9.0.81
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.