StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,792 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,792 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
podinfoflagger6.1.41 of 1See more

podinfo flagger 6.1.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
1.46.0-r2
0.17.0

Open the chart page →

2,815
apm-hubflanksourceVerified publisher0.0.471 of 2See more

apm-hub flanksource 0.0.47

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

6,150
mission-control-tenantflanksourceVerified publisher1.0.923 of 3See more

mission-control-tenant flanksource 1.0.92

3 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
golang.org/x/net@v0.7.0
0.17.0
rancher/k3s:v1.28.2-k3s18c2599ecfca8
golang.org/x/net@v0.13.0
0.17.0
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

5,709
my-chartfleet-web-app0.1.02 of 6See more

my-chart fleet-web-app 0.1.0

2 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
richardchesterwood/k8s-fleetman-api-gateway:release2518f946b9f05
tomcat-embed-core@8.5.11
8.5.94
richardchesterwood/k8s-fleetman-position-tracker:release336c43961214c
tomcat-embed-core@8.5.4
8.5.94

Open the chart page →

24,300
flinkflink0.5.11 of 1See more

flink flink 0.5.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/flink:1.14.6-scala_2.122461f02672b3
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

5,693
base-depflofree-chartVerified publisher1.0.11 of 1See more

base-dep flofree-chart 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
flofree/base-project:2.1.16b6486c5f81e
tomcat-embed-core@9.0.78
9.0.81

Open the chart page →

2,800
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

8,049
fluent-operatorfluent-operatorVerified publisher0.1.01 of 2See more

fluent-operator fluent-operator 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubesphere/fluent-operator:v1.0.2702df77228c6
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

2,631
flyte-depsflyte1.16.81 of 3See more

flyte-deps flyte 1.16.8

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.17.0

Open the chart page →

2,245
mod-aesfolio-org0.1.331 of 1See more

mod-aes folio-org 0.1.33

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
folioci/mod-aes:latest6d67e9564270
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

2,282
mod-codex-ekbfolio-org0.1.341 of 1See more

mod-codex-ekb folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
folioci/mod-codex-ekb:latest235a3fa4adc9
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

2,113
mod-codex-inventoryfolio-org0.1.341 of 1See more

mod-codex-inventory folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
folioci/mod-codex-inventory:latest6d53ed758fd1
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,902
mod-codex-muxfolio-org0.1.341 of 1See more

mod-codex-mux folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
folioci/mod-codex-mux:latestd4138abfd30d
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,756
mod-data-import-converter-storagefolio-org0.1.341 of 1See more

mod-data-import-converter-storage folio-org 0.1.34

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
folioci/mod-data-import-converter-storage:latest3028f333778f
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

2,489
forkliftforklift0.1.42 of 2See more

forklift forklift 0.1.4

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wuhan005/forklift:daemon4e6da210e449
golang.org/x/net@v0.7.0
0.17.0
wuhan005/forklift:controllerbfbe82d59850
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,814
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

4,650
forwardforward1.3.11 of 1See more

forward forward 1.3.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
udhos/forward:1.1.312e120d39fdb
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0

Open the chart page →

2,212
maxscalefour-allportalVerified publisher4.1.162 of 3See more

maxscale four-allportal 4.1.16

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/mysqld-exporter:0.14.0-debian-11-r10304768b637c94
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
mariadb/maxscale:23.02.256c5e0908148
nghttp2@1.33.0-3.el8_3.1
0:1.33.0-5.el8_8

Open the chart page →

6,610
simple-websitefour-allportalVerified publisher1.0.21 of 1See more

simple-website four-allportal 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.23.3f4e3b6489888
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

831
aptlyg0dscookie0.4.01 of 2See more

aptly g0dscookie 0.4.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.212bcabc23b454
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

3,482
icinga2g0dscookie0.2.01 of 1See more

icinga2 g0dscookie 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

4,429
passboltg0dscookie0.5.21 of 2See more

passbolt g0dscookie 0.5.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

7,986
hammondgabe565Verified publisher0.6.41 of 1See more

hammond gabe565 0.6.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
golang.org/x/net@v0.0.0-20210410081132-afb366fc7cd1
0.17.0

Open the chart page →

1,807
podgrabgabe565Verified publisher0.5.21 of 1See more

podgrab gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

2,401
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

13,250
smarter-device-managergabe565Verified publisher0.5.21 of 1See more

smarter-device-manager gabe565 0.5.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.11826b984e75d4
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0

Open the chart page →

1,226
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
guacamole/guacamole:1.3.0739cb6820ae8
tomcat-coyote@8.5.61
8.5.94

Open the chart page →

6,437
galoygaloymoney0.34.73 of 24See more

galoy galoymoney 0.34.7

3 of the 24 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
0.17.0
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

8,700
galoy-depsgaloymoney0.10.203 of 9See more

galoy-deps galoymoney 0.10.20

3 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.17.0
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

11,982
galoy-paygaloymoney0.11.481 of 2See more

galoy-pay galoymoney 0.11.48

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
krtk6160/galoy-nostrdigest-pinnedcc82a694f818
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

2,529
galoygaloymoney20.34.73 of 24See more

galoy galoymoney2 0.34.7

3 of the 24 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
0.17.0
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

8,700
galoy-depsgaloymoney20.10.203 of 9See more

galoy-deps galoymoney2 0.10.20

3 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.17.0
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

11,982
galoy-paygaloymoney20.11.481 of 2See more

galoy-pay galoymoney2 0.11.48

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
krtk6160/galoy-nostrdigest-pinnedcc82a694f818
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

2,529
pagesgary-pages1.0.02 of 3See more

pages gary-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.46
1.40.0-1ubuntu0.2
9.0.81

Open the chart page →

18,203
anonaddygeek-cookbookVerified publisher6.0.01 of 1See more

anonaddy geek-cookbook 6.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
anonaddy/anonaddy:0.12.3957a95565166
nghttp2@1.47.0-r0
nginx@1.22.0-r1
1.47.0-r2
1.22.1-r1

Open the chart page →

4,789
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

14,705
autobrrgeek-cookbookVerified publisher1.1.31 of 1See more

autobrr geek-cookbook 1.1.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
1.47.0-r2
0.17.0

Open the chart page →

2,236
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
nghttp2@1.30.0-1ubuntu1
tomcat-embed-core@9.0.37
1.30.0-1ubuntu1+esm2
9.0.81

Open the chart page →

19,246
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

16,176
cryptofoliogeek-cookbookVerified publisher1.4.21 of 1See more

cryptofolio geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
xtrendence/cryptofolio:V.2.2.0e6e6612bb94c
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,493
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

13,568
dendritegeek-cookbookVerified publisher6.4.01 of 1See more

dendrite geek-cookbook 6.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
0.17.0

Open the chart page →

2,143
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

12,290
embygeek-cookbookVerified publisher3.4.21 of 1See more

emby geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

8,587
gapsgeek-cookbookVerified publisher5.4.21 of 1See more

gaps geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
housewrecker/gaps:latestf417dd0a7547
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.60
1.40.0-1ubuntu0.2
9.0.81

Open the chart page →

8,988
gatusgeek-cookbookVerified publisher1.1.21 of 1See more

gatus geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

1,881
gonicgeek-cookbookVerified publisher6.4.21 of 1See more

gonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
sentriz/gonic:v0.13.1a74012a6adf3
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0

Open the chart page →

3,525
gotifygeek-cookbookVerified publisher1.2.21 of 1See more

gotify geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gotify/server:2.1.409c79bc1e403
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

3,132
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

11,038

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
library/influxdb:2.0.8ba10ac9ba17a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
library/influxdb:2.3.0-alpined7f5dd5f70e2
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
0.17.0
1
library/kapacitor:1.6.37232f6388a4d
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
0.17.0
1
library/kibana:7.17.8c5781ba340ef
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/kibana:7.17.3e2e2031c15be
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/logstash:7.17.817a4f64e9cf5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/mongo:4.4.1305678ae4e5e1
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/mongo:4.4-bionic3d0e6df9fd5b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
library/mongo:5.0.14-focal50cae5081ab4
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/mongo:4.2699d652ed674
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
library/mongo:4.2.16ca49afbcb2b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
library/mongo:6.0.271a63fc2438e
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/mongo:5.0.217c81758cb295
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
1
library/mongo:4.2.21-bionic9cb28f7291d9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
library/mongo:4.4.18d23ec07162ca
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
library/monica:3.7.0-apacheceb1ba4196ab
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/nginx:1.27.409369da6b103
nginx@1.27.4-1~bookworm
no fix listed
1
library/nginx:1.23.03536d368b898
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/nginx:1.23.2-alpine455c39afebd4
nghttp2@1.47.0-r0
1.47.0-r2
1
library/nginx:1.276784fb0834aa
nginx@1.27.5-1~bookworm
no fix listed
1
library/nginx:1.25.167f9a4f10d14
nghttp2@1.52.0-1
nginx@1.25.1-1~bookworm
1.52.0-1+deb12u1
no fix listed
1
library/nginx:1.25.49ff236ed47fe
nginx@1.25.4-1~bookworm
no fix listed
1
library/nginx:1.23.2ab589a3c466e
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/nginx:1.23.3f4e3b6489888
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/nginx:1.23f5747a42e3ad
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/nginx:1.27.3fb197595ebe7
nginx@1.27.3-1~bookworm
no fix listed
1
library/php:7-fpm-alpine0aeb129a60da
nghttp2@1.47.0-r0
1.47.0-r2
1
library/php:7.3-apacheb9872cd287ef
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/solr:8.7.0d124efd81fbb
http2-common@9.4.27.v20200227
http2-server@9.4.27.v20200227
nghttp2@1.43.0-1
9.4.53
9.4.53
1.43.0-1+deb11u1
1
library/sonarqube:6.7.6-community0ae5169e3d0f
tomcat-embed-core@8.5.23
8.5.94
1
library/sonarqube:8.2-communitya246bc64207e
tomcat-embed-core@8.5.41
8.5.94
1
library/sonarqube:10.0.0-communityef9723cf4fe4
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
library/telegraf:1.20.428e98eece020
golang.org/x/net@v0.0.0-20211005215030-d2e5035098b3
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
library/telegraf:1.27507a3eecf809
golang.org/x/net@v0.14.0
0.17.0
1
library/telegraf:1.19.0-alpine794079a7f241
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
library/telegraf:1.19-alpineaddb86c0c520
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0
1
library/tomcat:8.5.41-alpine04feaf74f8bb
tomcat-coyote@8.5.41
8.5.94
1
library/traefik:v2.10.11489caffaedb
golang.org/x/net@v0.7.0
0.17.0
1
library/traefik:2.5.62f603f8d3abe
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
library/traefik:v1.7.345d47b7bb2546
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
0.17.0
1
library/traefik:2.5.47d0228d19042
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
library/traefik:2.4.8eda951fd29a8
golang.org/x/net@v0.0.0-20210220033124-5f55cee0dc0d
0.17.0
1
library/traefik:2.2.8f5af5a5ce17f
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.17.0
1
library/varnish:7.5.04d0bb287d87b
varnish@7.5.0
no fix listed
1
library/varnish:7.3-alpine6db2c9e4c2dd
varnish@7.3.1-r1
7.4.2-r0
1
library/vault:1.13.3f98ac9dd97b0
golang.org/x/net@v0.8.0
0.17.0
1
library/wordpress:6.0.0-php8.0-apache277c6c25980f
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
library/zookeeper:3.8-temurin55d1e5b2e601
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
librenms/librenms:22.4.14f1f3d667cc7
nghttp2@1.46.0-r0
nginx@1.20.2-r0
1.46.0-r2
1.20.2-r2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.