StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,792 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,792 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
user-manager-neo4jmoreillonVerified publisher0.9.73 of 6See more

user-manager-neo4j moreillon 0.9.7

3 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
moreillon/group-manager-front:v3.3.1c9f85db3baa5
nginx@1.27.0-2~bookworm
no fix listed
moreillon/user-manager:v5.0.2e1c9bfab5c16
nghttp2@1.52.0-1
1.52.0-1+deb12u1
moreillon/user-manager-front:v5.1.06597e6b98d21
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

30,575
backupmorremeyer4.0.01 of 1See more

backup morremeyer 4.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
restic/restic:0.15.2579e4e6a4931
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

2,303
genericmorremeyer8.0.01 of 1See more

generic morremeyer 8.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.25.167f9a4f10d14
nghttp2@1.52.0-1
nginx@1.25.1-1~bookworm
1.52.0-1+deb12u1
no fix listed

Open the chart page →

6,894
hcloud-ccm-networksmorremeyer2.0.01 of 1See more

hcloud-ccm-networks morremeyer 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

1,746
hcloud-csi-drivermorremeyer3.0.06 of 6See more

hcloud-csi-driver morremeyer 3.0.0

6 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
golang.org/x/net@v0.7.0
0.17.0
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
golang.org/x/net@v0.4.0
0.17.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
golang.org/x/net@v0.4.0
0.17.0
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
golang.org/x/net@v0.4.0
0.17.0
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
golang.org/x/net@v0.4.0
0.17.0
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

7,187
acmemosquitto-helm-chart0.2.01 of 2See more

acme mosquitto-helm-chart 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
neilpang/acme.sh:3.0.2595809ad43a2
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

2,051
chirpstackmosquitto-helm-chart0.5.03 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

3 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
nghttp2@1.40.0-1build1
http2-common@9.4.43.v20210629
http2-server@9.4.43.v20210629
1.40.0-1ubuntu0.2
9.4.53
9.4.53
chirpstack/chirpstack-application-server:3fb7667fe037f
golang.org/x/net@v0.0.0-20220726230323-06994584191e
0.17.0
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

26,081
chirpstack-event-forwardmosquitto-helm-chart0.1.21 of 1See more

chirpstack-event-forward mosquitto-helm-chart 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0

Open the chart page →

1,854
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
nghttp2@1.40.0-1build1
http2-common@9.4.44.v20210927
http2-server@9.4.44.v20210927
1.40.0-1ubuntu0.2
9.4.53
9.4.53

Open the chart page →

15,749
replacermosquitto-helm-chart0.2.02 of 3See more

replacer mosquitto-helm-chart 0.2.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

3,931
configmapsecretsmozilla0.0.11 of 1See more

configmapsecrets mozilla 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0

Open the chart page →

2,109
devops-demomungari-development-charts1.0.41 of 4See more

devops-demo mungari-development-charts 1.0.4

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
tomcat-embed-core@9.0.65
0.17.0
9.0.81

Open the chart page →

9,004
my-music-appmusic-serverVerified publisher0.1.11 of 1See more

my-music-app music-server 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
abdullahkhabir/radio:latest56526d0cc929
nghttp2@1.51.0-r1
1.51.0-r2

Open the chart page →

1,561
pagesmuthu-pages1.0.02 of 3See more

pages muthu-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
approuvezmvisonneau0.1.11 of 1See more

approuvez mvisonneau 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0

Open the chart page →

1,978
unpollermvisonneau0.1.01 of 1See more

unpoller mvisonneau 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
golift/unifi-poller:v2.9.2585a29a06d05
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

1,190
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

12,867
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

12,867
authmyaVerified publisher22.4.31 of 1See more

auth mya 22.4.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.17.0

Open the chart page →

2,381
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

9,418
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

9,353
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

3,368
my-helm-chartmy-helm-charts-2024Verified publisher0.1.01 of 1See more

my-helm-chart my-helm-charts-2024 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
shamimkuet/nginx:1.0.2b82902a76a04
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

5,411
Practica_4_helmmy-heml-appVerified publisher0.1.04 of 7See more

Practica_4_helm my-heml-app 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

27,861
mystoremystore-chart0.1.02 of 3See more

mystore mystore-chart 0.1.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hazegoodlife/haaze:veggiesite50f02d2d5d4d
nginx@1.27.4-1~bookworm
no fix listed
hazegoodlife/haaze:milksite8d4c63169e14
nginx@1.27.4-1~bookworm
no fix listed

Open the chart page →

9,590
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hecrom/myweatherangularclient:1.3.11bb0372939c19
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

18,114
fargate-sidecar-injectormziyaboVerified publisher0.1.51 of 1See more

fargate-sidecar-injector mziyabo 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mziyabo/fargate-eks-sidecar-injector:latest3067dce17983
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,393
pagesnarain1.0.02 of 3See more

pages narain 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagesnarasimha-pages1.0.02 of 3See more

pages narasimha-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

12,909
traefik-forward-auth-openidnas-helm-chartsVerified publisher1.0.11 of 1See more

traefik-forward-auth-openid nas-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:latestb364aa6a4117
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.17.0

Open the chart page →

2,197
nats-operatornatsVerified publisher0.8.31 of 1See more

nats-operator nats 0.8.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
natsio/nats-operator:0.8.31261dae38389
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

2,354
pagesnavin-brixton1.0.02 of 3See more

pages navin-brixton 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
betydbncsaVerified publisher0.6.11 of 4See more

betydb ncsa 0.6.1

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

9,546
pecanncsaVerified publisher0.6.22 of 15See more

pecan ncsa 0.6.2

2 of the 15 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
nghttp2@1.43.0-1
1.43.0-1+deb11u1
pecan/web:1.7.2814d678c5550
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

14,158
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
http2-common@9.4.32.v20200930
http2-server@9.4.32.v20200930
9.4.53
9.4.53

Open the chart page →

55,728
smilencsaVerified publisher1.1.014 of 23See more

smile ncsa 1.1.0

14 of the 23 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/classification_train:0.1.207477060bba8
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/clowder_list:0.1.051cb17626519
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
nghttp2@1.52.0-1
1.52.0-1+deb12u1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
nghttp2@1.52.0-1
1.52.0-1+deb12u1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
nghttp2@1.52.0-1
1.52.0-1+deb12u1
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

110,325
swaggerncsaVerified publisher1.0.11 of 1See more

swagger ncsa 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
swaggerapi/swagger-ui:v4.15.511b20aebb92c
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,185
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

6,991
iamdnetsocVerified publisher0.6.11 of 2See more

iamd netsoc 0.6.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

2,891
shhdnetsocVerified publisher0.1.71 of 1See more

shhd netsoc 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0

Open the chart page →

3,987
webspacednetsocVerified publisher0.2.82 of 2See more

webspaced netsoc 0.2.8

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
0.17.0

Open the chart page →

5,193
nginx-samplenginx-sample0.5.01 of 1See more

nginx-sample nginx-sample 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

5,362
nginx-sample-dependentnginx-sample-dependent0.2.01 of 1See more

nginx-sample-dependent nginx-sample-dependent 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

5,362
node-upgrade-channelnimbolus0.1.11 of 1See more

node-upgrade-channel nimbolus 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

2,063
doris-operatornineinfra-charts1.3.11 of 1See more

doris-operator nineinfra-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
selectdb/doris.k8s-operator:1.3.1919210765cb8
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

870
kyuubi-operatornineinfra-charts0.7.01 of 1See more

kyuubi-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nineinfra/kyuubi-operator:v0.7.08d8ed87ef77c
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

815
metastore-operatornineinfra-charts0.7.01 of 1See more

metastore-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nineinfra/metastore-operator:v0.7.011259032fb04
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

815
minio-directpvnineinfra-charts4.0.85 of 5See more

minio-directpv nineinfra-charts 4.0.8

5 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/minio/csi-node-driver-registrardigest-pinnedc805fdc16676
golang.org/x/net@v0.8.0
0.17.0
quay.io/minio/csi-provisionerdigest-pinned7b5c070ec70d
golang.org/x/net@v0.8.0
0.17.0
quay.io/minio/csi-resizerdigest-pinned819f68a4daf7
golang.org/x/net@v0.8.0
0.17.0
quay.io/minio/directpv:v4.0.84560083eb77d
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.8.0
0:1.33.0-5.el8_8
0.17.0
quay.io/minio/livenessprobedigest-pinnedf3bc9a84f149
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

7,070
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.13.0
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

3,425

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
linuxserver/calibre-web:version-0.6.12938810eca3d3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
linuxserver/cloud9:latest45c5fe102ff3
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
1.30.0-1ubuntu1+esm2
0.17.0
1
linuxserver/code-server:4.10.1a5e43a05ae79
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
linuxserver/codimd:latestb801bbcf6386
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
linuxserver/deluge:18.04.10ac871624394
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
linuxserver/grocy:4.0.1f8f5f96b6ea8
nghttp2@1.55.1-r0
nginx@1.24.0-r6
1.57.0-r0
1.24.0-r7
1
linuxserver/healthchecks:2.7.2023033194696dab3c50
nghttp2@1.51.0-r0
1.51.0-r2
1
linuxserver/jellyfin:10.7.72427dde159a2
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
linuxserver/plex:1.25.24a13ced2326c
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
linuxserver/smokeping:2.9.02f4488c9afcd
golang.org/x/net@v0.6.0
0.17.0
1
linuxserver/smokeping:2.8.2b7f906899cd3
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0
1
linuxserver/unifi-controller:8.0.240ae315a3a456
tomcat-embed-core@9.0.65
9.0.81
1
linuxserver/unifi-controller:7.3.83ab105cc50322
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.59
1.40.0-1ubuntu0.2
9.0.81
1
linuxserver/yq:3.2.26f5b9586a93e
nghttp2@1.55.1-r0
1.57.0-r0
1
lishimeng/hufu:v1.2.13d5752dac834
golang.org/x/net@v0.12.0
0.17.0
1
lishimeng/passport:v0.2.163e7d05ded625
golang.org/x/net@v0.8.0
0.17.0
1
lishimeng/passport-profile:v0.2.160970dfe5dc8f
golang.org/x/net@v0.8.0
0.17.0
1
lishimeng/tabby:v1.0.48145c3dc83c8
golang.org/x/net@v0.8.0
0.17.0
1
lishimeng/tree:v0.2.89b2f8be6c7d3
golang.org/x/net@v0.8.0
0.17.0
1
lishimeng/zoo:v0.4.0e0b8d2d8ca28
golang.org/x/net@v0.14.0
0.17.0
1
litestream/litestream:0.3c5a1e1b01916
golang.org/x/net@v0.14.0
0.17.0
1
litmuschaos/mongo:4.2.899961210d467
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
liukunup/jmeter:5.59c079617a81b
nghttp2@1.47.0-r0
1.47.0-r2
1
livekit/ingress:v1.2.21ab01641b366
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
livekit/livekit-recorder:v0.3.13ecf1409c75e0
golang.org/x/net@v0.0.0-20211004195052-b30845b58a23
0.17.0
1
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.17.0
1
lmierzwa/karma:v0.503751e5eed656
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0
1
lmierzwa/karma:v0.70d417abe7ddb5
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
localstack/localstack:3.19d278167f2b7
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
1
loftsh/jspolicy:0.2.225deb9bd2683
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
1
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
logiqai/flash-discovery:v2.0.3f5b551bca98e
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0
1
logiqai/logiqctl:2.0.4798306811f2d
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0
1
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
1
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
1
longhornio/longhorn-manager:v1.2.3dca34321452c
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
1.40.0-1ubuntu0.2
0.17.0
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
1.30.0-1ubuntu1+esm2
0.17.0
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
golang.org/x/net@v0.9.0
0.17.0
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.17.0
1
louislam/uptime-kuma:1.18.5a84767d7934f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.17.0
1
lsstsqre/exposurelog:0.8.079b00fb67a65
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
lsstsqre/narrativelog:0.1.0ce01de04ce21
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
nghttp2@1.40.0-1build1
nodejs@10.19.0~dfsg-3ubuntu1
1.40.0-1ubuntu0.2
10.19.0~dfsg-3ubuntu1.6+esm2
1
lsstsqre/strimzi-registry-operator:0.4.1e139fde946d7
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
lumenvox/cloud-binary-storage:2.0.053decadc102d
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.