StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,107
of 17,790 indexed, latest versions
Container images
2,471
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,107 of 17,790 indexed charts deploy, on 2,471 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,572
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,107 by stars
ChartLatestAffected imagesRadar Score
datadog-csi-driverdatadogVerified publisher0.17.01 of 2See more

datadog-csi-driver datadog 0.17.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,055
datadog-operatordatadog-test0.1.21 of 1See more

datadog-operator datadog-test 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
datadog/operator:0.3.117f08a860090
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.17.0

Open the chart page →

3,978
agent-helmdatasaker0.1.81 of 6See more

agent-helm datasaker 0.1.8

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
datasaker/dsk-process-agent:latest2f38720a637d
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

7,606
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0:1.33.0-4.el8_4.1
0.17.0

Open the chart page →

7,494
eg-edge-stackdatawire0.0.15 of 7See more

eg-edge-stack datawire 0.0.1

5 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ambassador/aes-authsvc:v4.0.0-preview.12a4598b03a6a
golang.org/x/net@v0.11.0
0.17.0
ambassador/aes-eg-ext:v4.0.0-preview.1b7eb1be3345d
golang.org/x/net@v0.11.0
0.17.0
ambassador/aes-wafsvc:v4.0.0-preview.15fc571509b8c
golang.org/x/net@v0.11.0
0.17.0
envoyproxy/gateway:v0.5.02a9f99d28567
golang.org/x/net@v0.10.0
0.17.0
istio/kubectl:1.5.10dbb7726d1bf0
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

15,861
eg-edge-stack-crdsdatawire0.0.12 of 2See more

eg-edge-stack-crds datawire 0.0.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/gateway-api/admission-server:v0.7.1fe43ee5176a8
golang.org/x/net@v0.7.0
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

2,404
pagesdavid-pages1.0.02 of 3See more

pages david-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
db-connection-testdb-connection-testVerified publisher0.1.01 of 1See more

db-connection-test db-connection-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
felipecs8/app-db-connection-test:v129e06c9c6385
nginx@1.27.2-1~bookworm
no fix listed

Open the chart page →

10,163
ddns-kubernetes-controllerddns-kubernetes-controller0.1.01 of 1See more

ddns-kubernetes-controller ddns-kubernetes-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0

Open the chart page →

970
pagesdebasish-pages1.0.02 of 3See more

pages debasish-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
kube-better-nodedecayofmind0.0.41 of 1See more

kube-better-node decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

1,584
symfony-appdefault-ghVerified publisher0.6.53 of 3See more

symfony-app default-gh 0.6.5

3 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
alpine/git:2.36.366b210a97bc0
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
1.47.0-r2
0.17.0
library/nginx:1.23f5747a42e3ad
nghttp2@1.43.0-1
1.43.0-1+deb11u1
xvilo/php:8.2-composera138e57d3204
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

5,123
cortex-gatewaydeliveryheroVerified publisher0.1.91 of 1See more

cortex-gateway deliveryhero 0.1.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
0.17.0

Open the chart page →

2,241
k8s-cloudwatch-adapterdeliveryheroVerified publisher0.2.21 of 1See more

k8s-cloudwatch-adapter deliveryhero 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0

Open the chart page →

2,475
deploy-elibrarydeploy-elibrary-helm0.1.01 of 1See more

deploy-elibrary deploy-elibrary-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
psorab/elibrary:latest53b68896c4ce
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

7,254
deploy-elibrarydeploy-elibrary-oo0.1.01 of 1See more

deploy-elibrary deploy-elibrary-oo 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jedi132000/nextapp:latestdc2a81e92f23
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

8,149
kubeteach-coredergeberl0.2.31 of 1See more

kubeteach-core dergeberl 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

1,505
kubeteach-exerciseset1dergeberl0.2.31 of 2See more

kubeteach-exerciseset1 dergeberl 0.2.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

1,505
pleromaderp0.1.91 of 1See more

pleroma derp 0.1.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/mjohnson9/docker-pleroma:v0.1.44f08e2823756
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

2,707
seafilederp3.2.01 of 1See more

seafile derp 3.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:10.0.170628f29c663
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2

Open the chart page →

14,920
apachedevops0.1.02 of 4See more

apache devops 0.1.0

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ghcr.io/codingducksrl/laravel:8.15be52524664c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

30,156
laraveldevops0.10.32 of 4See more

laravel devops 0.10.3

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ghcr.io/codingducksrl/laravel:8.15be52524664c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

29,157
wordpressdevops0.12.02 of 4See more

wordpress devops 0.12.0

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.0ae6dadd9cf3c
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

13,039
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0

Open the chart page →

4,735
devopsweeklydevopsweekly2.1.01 of 1See more

devopsweekly devopsweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zufardhiyaulhaq/devopsweekly:v2.1.046625567fb60
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.17.0

Open the chart page →

1,217
lxd8sdevplayer0Verified publisher0.5.12 of 2See more

lxd8s devplayer0 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0

Open the chart page →

5,431
argocddevtron1.8.12 of 3See more

argocd devtron 1.8.1

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
0.17.0
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.17.0

Open the chart page →

10,484
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
nghttp2@1.43.0-1build3
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

13,011
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,587
devtron-enterprisedevtron48.0.09 of 28See more

devtron-enterprise devtron 48.0.0

9 of the 28 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
1.46.0-r2
0.17.0
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
1.52.0-1+deb12u1
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.17.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
quay.io/devtron/k8s-utils:tutum-curl38b970c84cce
nghttp2@1.46.0-r0
1.46.0-r2
quay.io/devtron/kubectl:latest2ad610626658
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.17.0
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.17.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

68,695
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.17.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

5,055
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
nghttp2@1.43.0-1build3
golang.org/x/net@v0.8.0
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

4,972
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
1.40.0-1ubuntu0.2
0.17.0

Open the chart page →

11,959
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
0.17.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

8,659
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.17.0

Open the chart page →

2,441
svn-git-syncdevtron0.1.31 of 1See more

svn-git-sync devtron 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/svn-git-sync:v78e54bc2d261f
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,860
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

1,176
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
0.17.0

Open the chart page →

1,514
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
0.17.0
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.17.0

Open the chart page →

10,484
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
nghttp2@1.43.0-1build3
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

13,011
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,587
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

10,094
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.09 of 28See more

devtron-enterprise devtron-labs 48.0.0

9 of the 28 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
1.46.0-r2
0.17.0
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
1.52.0-1+deb12u1
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.17.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
quay.io/devtron/k8s-utils:tutum-curl38b970c84cce
nghttp2@1.46.0-r0
1.46.0-r2
quay.io/devtron/kubectl:latest2ad610626658
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.17.0
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.17.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

68,695
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.17.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

5,055
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
nghttp2@1.43.0-1build3
golang.org/x/net@v0.8.0
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

4,972
devtron-operatordevtron-labs0.23.36 of 11See more

devtron-operator devtron-labs 0.23.3

6 of the 11 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
1.46.0-r2
0.17.0
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
1.52.0-1+deb12u1
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.17.0
quay.io/devtron/kubectl:latest2ad610626658
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.17.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

33,180
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
1.40.0-1ubuntu0.2
0.17.0

Open the chart page →

11,959
kube-prometheus-stackdevtron-labs19.3.03 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

3 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
0.17.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

8,659
securitydevtron-labs0.2.21 of 1See more

security devtron-labs 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.17.0

Open the chart page →

2,441

Container images carrying it

2,471 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
hecrom/myweatherangularclient:1.3.11bb0372939c19
nginx@1.27.0-2~bookworm
no fix listed
1
helga09/php_shoes_ukr:v1.1.1e283539bcb8c
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
golang.org/x/net@v0.11.0
0.17.0
1
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
hetznercloud/hcloud-csi-driver:1.6.01475d525f9a4
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
1
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
0.17.0
1
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
golang.org/x/net@v0.7.0
0.17.0
1
hhyo/archery:v1.9.11aa41843419e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
hiboxsystems/marge-bot:0.11.07235809b43b3
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
hiboxsystems/marge-bot:0.12.1a96c10b61a59
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
hivemq/hivemq4:dns-4.5.144d194450d48e
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
0.17.0
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
holiman/nodemonitor:latest5cd609761065
golang.org/x/net@v0.9.0
0.17.0
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
nghttp2@1.55.1-r0
1.57.0-r0
1
housewrecker/gaps:latestf417dd0a7547
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.60
1.40.0-1ubuntu0.2
9.0.81
1
huajuan6848/env-view-server:0.0.1-SNAPSHOTa303f3d9f6e0
tomcat-embed-core@10.1.11
10.1.14
1
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
nghttp2@1.46.0-r0
golang.org/x/net@v0.10.0
1.46.0-r2
0.17.0
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
hugohg34/server:0.0.2503e5d8960ff
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
hugohg34/toposervice:0.0.2812a03b3f274
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
golang.org/x/net@v0.0.0-20210907225631-ff17edfbf26d
0.17.0
1
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
1
hyperledger/fabric-ca:1.5.0f270dfeee91d
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
1
hyperledger/fabric-orderer:2.2.137294e05209b
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
0.17.0
1
hyperledger/fabric-peer:2.2.1bf4995c86af6
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
0.17.0
1
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
golang.org/x/net@v0.8.0
0.17.0
1
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
golang.org/x/net@v0.8.0
0.17.0
1
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0:1.33.0-5.el8_8
0.17.0
1
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.4.0
0:1.33.0-5.el8_8
0.17.0
1
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0
1
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
i4trust/activation-service:2.2.09f3719176893
nghttp2@1.53.0-r0
1.57.0-r0
1
iamdorsah/bastillion:v0.1db83a0254d81
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
http2-common@9.4.45.v20220203
http2-server@9.4.45.v20220203
0.17.0
9.4.53
9.4.53
1
ianw/quickchart:v1.7.1dc49dd460c37
nghttp2@1.46.0-r0
1.46.0-r2
1
ibarreche/cloud-back-ci:lateste16a469c5791
nghttp2@1.46.0-r0
1.46.0-r2
1
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-3.el8_2.2
1
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-3.el8_2.2
1
ibmcom/ibm-enterprise-mongodb-ppc64le:4.4d28bf361327a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
tomcat-embed-core@8.5.15
8.5.94
1
ibmcom/microclimate-theia:lateste17bdccc5030
tomcat-embed-core@8.5.15
8.5.94
1
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
nghttp2@1.33.0-1.el8
0:1.33.0-5.el8_8
1
ibmcom/skydive:0.22.0395e60cc6e3d
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
inbucket/inbucket:3.0.01f10a0efea69
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0
1
inseefrlab/shelly:cloudshell31f04ca7436b
golang.org/x/net@v0.13.0
0.17.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.