StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,787 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,787 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

6,597
nfs-subdir-external-provisionernfs-subdir-external-provisioner4.0.181 of 1See more

nfs-subdir-external-provisioner nfs-subdir-external-provisioner 4.0.18

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,745
nfs-server-provisionerkvaps1.8.01 of 1See more

nfs-server-provisioner kvaps 1.8.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0

Open the chart page →

2,315
keycloakcodecentricVerified publisher18.10.01 of 3See more

keycloak codecentric 18.10.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

7,713
aws-node-termination-handleraws0.21.01 of 1See more

aws-node-termination-handler aws 0.21.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.19.0844478ebd5b8
golang.org/x/net@v0.2.0
0.17.0

Open the chart page →

1,445
actions-runner-controlleractions-runner-controller0.23.72 of 2See more

actions-runner-controller actions-runner-controller 0.23.7

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
summerwind/actions-runner-controller:v0.27.62128f81dbede
golang.org/x/net@v0.12.0
0.17.0
quay.io/brancz/kube-rbac-proxy:v0.13.1738c854322f5
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
0.17.0

Open the chart page →

2,883
vpafairwinds-stableVerified publisher5.0.11 of 4See more

vpa fairwinds-stable 5.0.1

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,233
terraformhashicorpVerified publisher1.1.21 of 1See more

terraform hashicorp 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/terraform-k8s:1.1.2b19857bab620
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.17.0

Open the chart page →

2,059
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

5,557
rocketchatrocketchat-server7.0.23 of 12See more

rocketchat rocketchat-server 7.0.2

3 of the 12 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
bitnamilegacy/mongodb-exporter:0.39.0-debian-11-r106de7256c7adcd
golang.org/x/net@v0.7.0
0.17.0
bitnamilegacy/os-shell:11-debian-11-r722cb5982dcbf4
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

12,283
solr-operatorapache-solrVerified publisher0.9.12 of 3See more

solr-operator apache-solr 0.9.1

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
lachlanevenson/k8s-kubectl:v1.23.2e4d83478963b
nghttp2@1.46.0-r0
1.46.0-r2
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

2,943
chaos-meshchaos-meshVerified publisher2.8.41 of 4See more

chaos-mesh chaos-mesh 2.8.4

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.838bfdf5e3774
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

6,362
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

9,194
vclusterloftVerified publisher0.0.0-ci.31 of 2See more

vcluster loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.1.1-0.20221027164007-c63010009c80
0.17.0

Open the chart page →

2,453
milvusmilvus4.0.315 of 5See more

milvus milvus 4.0.31

5 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
nghttp2@1.40.0-1build1
http2-common@9.4.43.v20210629
http2-server@9.4.43.v20210629
1.40.0-1ubuntu0.2
9.4.53
9.4.53
milvusdb/etcd:3.5.5-r2102aac62827b
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0
milvusdb/milvus:v2.2.13a3a55e1c1497
nghttp2@1.40.0-1build1
golang.org/x/net@v0.10.0
1.40.0-1ubuntu0.2
0.17.0
milvusdb/milvus-config-tool:v0.1.12212dfb61401
golang.org/x/net@v0.0.0-20220706163947-c90051bbdb60
0.17.0
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.8.0
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

32,353
clearmlallegroaiOfficialVerified publisher7.15.02 of 4See more

clearml allegroai 7.15.0

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
nginx@1.22.1-9
no fix listed
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

10,648
signozsignoz0.141.13 of 5See more

signoz signoz 0.141.1

3 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/net@v0.7.0
0.17.0
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/net@v0.7.0
0.17.0
signoz/zookeeper:3.7.1fcc4a3288154
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

7,582
pulsarapache4.7.01 of 10See more

pulsar apache 4.7.0

1 of the 10 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rancher/kubectl:v1.25.085a0d1148784
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

9,869
ambassadordatawire6.9.51 of 2See more

ambassador datawire 6.9.5

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0

Open the chart page →

4,086
prometheus-msteamsprometheus-msteams1.3.61 of 1See more

prometheus-msteams prometheus-msteams 1.3.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheusmsteams/prometheus-msteams:v1.5.3a9f4d31ab811
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

941
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
0.17.0

Open the chart page →

4,159
oncallgrafana1.16.56 of 12See more

oncall grafana 1.16.5

6 of the 12 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.0e7b6203ccb37
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
quay.io/jetstack/cert-manager-controller:v1.8.0e1642bf8e933
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
quay.io/jetstack/cert-manager-webhook:v1.8.0fd798a5a773e
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

16,251
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.14.3f09282d281f6
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0

Open the chart page →

11,402
zabbixcetic3.1.33 of 5See more

zabbix cetic 3.1.3

3 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
nghttp2@1.43.0-1build3
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
1.43.0-1ubuntu0.1
0.17.0
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

33,907
chatwootchatwootVerified publisher2.0.242 of 3See more

chatwoot chatwoot 2.0.24

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/redis:6.2.7-debian-11-r37788b908dd0d
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ghcr.io/chatwoot/pgvector:14.4.0-debian-11-r0f759f1510d09
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

9,204
emissary-ingressdatawire7.1.8-ea1 of 1See more

emissary-ingress datawire 7.1.8-ea

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
datawire/emissary:2.0.2-ea9716efbdd24b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0

Open the chart page →

4,918
hostpath-provisionerrimusz0.2.131 of 1See more

hostpath-provisioner rimusz 0.2.13

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,039
dependency-trackevryfs-ossVerified publisher1.5.51 of 3See more

dependency-track evryfs-oss 1.5.5

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dependencytrack/frontend:4.6.124422d762e08
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

2,503
openldaphelm-openldapVerified publisher2.0.41 of 3See more

openldap helm-openldap 2.0.4

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.17.0

Open the chart page →

6,219
linkerd-jaegerlinkerd2Verified publisher30.12.112 of 4See more

linkerd-jaeger linkerd2 30.12.11

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
0.17.0
otel/opentelemetry-collector:0.59.0ee9da0b08d83
golang.org/x/net@v0.0.0-20220809184613-07c6da5e1ced
0.17.0

Open the chart page →

4,405
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

15,607
telepresence-osstelepresence-ossOfficialVerified publisher2.31.21 of 2See more

telepresence-oss telepresence-oss 2.31.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
curlimages/curl:8.1.15af13420d29b
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

1,037
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

7,917
scribebackube-helm-chartsVerified publisher0.2.01 of 2See more

scribe backube-helm-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/backube/scribe:0.2.0cdefc81c6b2e
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0:1.33.0-4.el8_4.1
0.17.0

Open the chart page →

6,853
edge-stackdatawire7.1.8-ea1 of 2See more

edge-stack datawire 7.1.8-ea

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
datawire/aes:2.0.3-ea07f8fe4f4f8e
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0

Open the chart page →

5,173
docker-mailserverdocker-mailserver0.4.01 of 2See more

docker-mailserver docker-mailserver 0.4.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mailserver/docker-mailserver:11.0.0e0809756dc96
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,382
glasskube-operatorglasskubeOfficialVerified publisher0.12.23 of 3See more

glasskube-operator glasskube 0.12.2

3 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
golang.org/x/net@v0.15.0
0.17.0
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.15.0
0:1.33.0-5.el8_8
0.17.0
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.15.0
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

11,971
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

18,570
vertical-pod-autoscalercluster-autoscaler0.12.01 of 4See more

vertical-pod-autoscaler cluster-autoscaler 0.12.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
0.17.0

Open the chart page →

1,062
aws-ebs-csi-driverdeliveryheroVerified publisher2.17.46 of 6See more

aws-ebs-csi-driver deliveryhero 2.17.4

6 of the 6 container images this version deploys carry CVE-2023-44487.

Open the chart page →

6,485
loki-simple-scalablegrafana1.8.112 of 3See more

loki-simple-scalable grafana 1.8.11

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

6,470
prometheus-operatorarldkaVerified publisher13.0.11 of 2See more

prometheus-operator arldka 13.0.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

2,107
frigateblakeblackshear7.8.01 of 1See more

frigate blakeblackshear 7.8.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

3,004
kube-prometheuschoerodon9.3.14 of 7See more

kube-prometheus choerodon 9.3.1

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
0.17.0
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/net@v0.0.0-20191003171128-d98b1b443823
0.17.0
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.17.0

Open the chart page →

12,237
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.24.061d866e93b56
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

3,037
waypointhashicorpVerified publisher0.1.211 of 2See more

waypoint hashicorp 0.1.21

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/waypoint:0.11.397d521a27498
nghttp2@1.51.0-r0
golang.org/x/net@v0.1.0
1.51.0-r2
0.17.0

Open the chart page →

4,167
hivemq-operatorhivemqOfficialVerified publisher0.11.622 of 2See more

hivemq-operator hivemq 0.11.62

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

7,896
mauticone-acre-fundVerified publisher0.1.71 of 3See more

mautic one-acre-fund 0.1.7

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mautic/mautic:v4-apache94ea4acf4049
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,667
purelbpurelb0.0.0-106-ipv6-lbip-052cedab1 of 2See more

purelb purelb 0.0.0-106-ipv6-lbip-052cedab

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

4,412
dex-k8s-authenticatorsagikazarmarkVerified publisher0.0.31 of 1See more

dex-k8s-authenticator sagikazarmark 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
0.17.0

Open the chart page →

2,791

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
0.17.0
1
library/kapacitor:1.6.37232f6388a4d
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
0.17.0
1
library/kibana:7.17.8c5781ba340ef
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/kibana:7.17.3e2e2031c15be
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/logstash:7.17.817a4f64e9cf5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/mongo:4.4.1305678ae4e5e1
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/mongo:4.4-bionic3d0e6df9fd5b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
library/mongo:5.0.14-focal50cae5081ab4
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/mongo:4.2699d652ed674
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
library/mongo:4.2.16ca49afbcb2b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
library/mongo:6.0.271a63fc2438e
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/mongo:5.0.217c81758cb295
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
1
library/mongo:4.2.21-bionic9cb28f7291d9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
library/mongo:4.4.18d23ec07162ca
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/monica:3.7.0-apacheceb1ba4196ab
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/nginx:1.27.409369da6b103
nginx@1.27.4-1~bookworm
no fix listed
1
library/nginx:1.23.03536d368b898
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/nginx:1.23.2-alpine455c39afebd4
nghttp2@1.47.0-r0
1.47.0-r2
1
library/nginx:1.276784fb0834aa
nginx@1.27.5-1~bookworm
no fix listed
1
library/nginx:1.25.167f9a4f10d14
nghttp2@1.52.0-1
nginx@1.25.1-1~bookworm
1.52.0-1+deb12u1
no fix listed
1
library/nginx:1.25.49ff236ed47fe
nginx@1.25.4-1~bookworm
no fix listed
1
library/nginx:1.23.2ab589a3c466e
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/nginx:1.23.3f4e3b6489888
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/nginx:1.23f5747a42e3ad
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/nginx:1.27.3fb197595ebe7
nginx@1.27.3-1~bookworm
no fix listed
1
library/php:7-fpm-alpine0aeb129a60da
nghttp2@1.47.0-r0
1.47.0-r2
1
library/php:7.3-apacheb9872cd287ef
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/solr:8.7.0d124efd81fbb
http2-common@9.4.27.v20200227
http2-server@9.4.27.v20200227
nghttp2@1.43.0-1
9.4.53
9.4.53
1.43.0-1+deb11u1
1
library/sonarqube:6.7.6-community0ae5169e3d0f
tomcat-embed-core@8.5.23
8.5.94
1
library/sonarqube:8.2-communitya246bc64207e
tomcat-embed-core@8.5.41
8.5.94
1
library/sonarqube:10.0.0-communityef9723cf4fe4
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
library/telegraf:1.20.428e98eece020
golang.org/x/net@v0.0.0-20211005215030-d2e5035098b3
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
library/telegraf:1.27507a3eecf809
golang.org/x/net@v0.14.0
0.17.0
1
library/telegraf:1.19.0-alpine794079a7f241
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0
1
library/tomcat:8.5.41-alpine04feaf74f8bb
tomcat-coyote@8.5.41
8.5.94
1
library/traefik:v2.10.11489caffaedb
golang.org/x/net@v0.7.0
0.17.0
1
library/traefik:2.5.62f603f8d3abe
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
library/traefik:v1.7.345d47b7bb2546
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
0.17.0
1
library/traefik:2.5.47d0228d19042
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
library/traefik:2.4.8eda951fd29a8
golang.org/x/net@v0.0.0-20210220033124-5f55cee0dc0d
0.17.0
1
library/traefik:2.2.8f5af5a5ce17f
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.17.0
1
library/varnish:7.5.04d0bb287d87b
varnish@7.5.0
no fix listed
1
library/varnish:7.3-alpine6db2c9e4c2dd
varnish@7.3.1-r1
7.4.2-r0
1
library/vault:1.13.3f98ac9dd97b0
golang.org/x/net@v0.8.0
0.17.0
1
library/wordpress:6.0.0-php8.0-apache277c6c25980f
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/zookeeper:3.8-temurin55d1e5b2e601
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
librenms/librenms:22.4.14f1f3d667cc7
nghttp2@1.46.0-r0
nginx@1.20.2-r0
1.46.0-r2
1.20.2-r2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.