StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,787 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,787 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
hcloud-fip-controllerrlex0.2.51 of 1See more

hcloud-fip-controller rlex 0.2.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
0.17.0

Open the chart page →

2,962
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rm3l/dev-feed-api:latest9a7f732245a3
nghttp2@1.43.0-5.el9_2.1
tomcat-embed-core@9.0.68
0:1.43.0-5.el9_3.1
9.0.81

Open the chart page →

9,885
service-names-port-numbersrm3lVerified publisher0.26.11 of 1See more

service-names-port-numbers rm3l 0.26.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rm3l/service-names-port-numbers:0.12.162d1cc4223e5
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.55
1.40.0-1ubuntu0.2
9.0.81

Open the chart page →

10,159
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
nginx@1.22.1-9+deb12u4
no fix listed

Open the chart page →

5,508
elasticsearchromanow-helm-chartsVerified publisher1.7.11 of 2See more

elasticsearch romanow-helm-charts 1.7.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.8fdc73b3249c1
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

6,085
grafanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

grafana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:8.3.4cf81d2c753c8
golang.org/x/net@v0.0.0-20210903162142-ad29c8ab022f
0.17.0

Open the chart page →

2,835
jaeger-collectorromanow-helm-chartsVerified publisher1.5.01 of 1See more

jaeger-collector romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

1,854
jaeger-queryromanow-helm-chartsVerified publisher1.5.01 of 1See more

jaeger-query romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jaegertracing/jaeger-query:1.41.0b636f0f464bc
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

1,797
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

6,918
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

7,567
routehub-client-hubroutehub-helm1.0.01 of 3See more

routehub-client-hub routehub-helm 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2

Open the chart page →

13,028
baikalrubxkubeVerified publisher1.3.11 of 1See more

baikal rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ckulka/baikal:0.10.1-nginx434bdd162247
nginx@1.29.0-1~bookworm
no fix listed

Open the chart page →

5,321
delugerubxkubeVerified publisher1.2.11 of 1See more

deluge rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/deluge:18.04.10ac871624394
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

13,562
rabbitmq-operatorsagikazarmarkVerified publisher0.0.31 of 1See more

rabbitmq-operator sagikazarmark 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0

Open the chart page →

2,001
ntfysarab97Verified publisher0.1.71 of 1See more

ntfy sarab97 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
binwiederhier/ntfy:v2.6.283e2e43d9956
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

1,766
scienceboxsciencebox0.0.72 of 17See more

sciencebox sciencebox 0.0.7

2 of the 17 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cs3org/revad:v1.19.03b57a34a7dfd
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.17.0
osixia/openldap:1.5.018742e9c449c
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
0.17.0

Open the chart page →

6,587
iopsciencemeshVerified publisher0.4.02 of 2See more

iop sciencemesh 0.4.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cs3org/revad:v1.24.0e80a4d67b352
golang.org/x/net@v0.7.0
0.17.0
cs3org/wopiserver:v9.4.202a9e78757b4
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

4,052
seldon-coreseldon0.2.72 of 3See more

seldon-core seldon 0.2.7

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
seldonio/apife:0.2.7ba81b17f00eb
tomcat-embed-core@8.5.34
8.5.94
seldonio/cluster-manager:0.2.729e362bb1ba2
tomcat-embed-core@8.5.34
8.5.94

Open the chart page →

13,798
sentinel-dashboardsentinel-dashboardVerified publisher0.1.01 of 1See more

sentinel-dashboard sentinel-dashboard 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
royalwang/sentinel-dashboard:1.8.4df99e2499f91
tomcat-embed-core@9.0.60
9.0.81

Open the chart page →

4,287
clickhousesignoz24.1.183 of 3See more

clickhouse signoz 24.1.18

3 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/net@v0.7.0
0.17.0
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/net@v0.7.0
0.17.0
signoz/zookeeper:3.7.1fcc4a3288154
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

4,697
cosignedsigstoreVerified publisher0.1.232 of 2See more

cosigned sigstore 0.1.23

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/projectsigstore/cosigneddigest-pinned784518ff3ee7
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
gcr.io/projectsigstore/policy-webhookdigest-pinned82940e8c3e0d
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0

Open the chart page →

5,118
scaffoldsigstoreVerified publisher0.6.1141 of 15See more

scaffold sigstore 0.6.114

1 of the 15 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

7,711
altinity-clickhouse-operatorslamdev0.1.22 of 2See more

altinity-clickhouse-operator slamdev 0.1.2

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.20.08f0f582d41f0
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0:1.33.0-5.el8_8
0.17.0
altinity/metrics-exporter:0.20.01a46d104406d
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

6,420
docker-registry-uislamdev0.0.11 of 1See more

docker-registry-ui slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quiq/docker-registry-ui:0.9.491281da47036
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
0.17.0

Open the chart page →

2,200
external-secrets-operatorslamdev0.0.151 of 1See more

external-secrets-operator slamdev 0.0.15

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
slamdev/external-secrets-operator:0.0.8855f6625dda4
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,301
smallest-self-hostsmallest-self-hostVerified publisher0.2.21 of 12See more

smallest-self-host smallest-self-host 0.2.2

1 of the 12 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

7,684
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

46,028
smarter-edgesmarterOfficialVerified publisher0.0.151 of 1See more

smarter-edge smarter 0.0.15

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/smarter-device-manager:v1.20.12228f7f44594a
golang.org/x/net@v0.2.0
0.17.0

Open the chart page →

1,144
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
aquasec/trivy:0.43.1944a04445179
nghttp2@1.53.0-r0
golang.org/x/net@v0.11.0
1.57.0-r0
0.17.0

Open the chart page →

14,504
gcp-quota-exportersoftonic2.0.21 of 1See more

gcp-quota-exporter softonic 2.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0

Open the chart page →

2,637
go-ratelimitsoftonic1.0.71 of 3See more

go-ratelimit softonic 1.0.7

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:v1.4.071081616da3e
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
0.17.0

Open the chart page →

5,098
node-policy-webhooksoftonic0.1.101 of 1See more

node-policy-webhook softonic 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
softonic/node-policy-webhook:0.1.2ab6098c04a53
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,591
gloosolo-gloo-edge0.0.0-fork4 of 5See more

gloo solo-gloo-edge 0.0.0-fork

4 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/solo-io/certgen:0.0.0-forkb17a8c7d1f32
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
quay.io/solo-io/gloo-envoy-wrapper:0.0.0-fork26ae185e835a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

9,224
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

5,688
sp-otel-collectorsp-otel-collectorVerified publisher1.1.61 of 1See more

sp-otel-collector sp-otel-collector 1.1.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

2,022
sql-operatorsql-operatorOfficialVerified publisher0.11.21 of 1See more

sql-operator sql-operator 0.11.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/stenic/sql-operator:1.13.2f4324baa2aad
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

1,594
healthchecksstackhelmVerified publisher0.1.01 of 2See more

healthchecks stackhelm 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
healthchecks/healthchecks:v2.8.1e82bb0836e30
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,236
splunk-operatorstakaterVerified publisher0.0.61 of 2See more

splunk-operator stakater 0.0.6

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
splunk/splunk-operator:2.0.0c4e0d3146226
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
0:1.33.0-4.el8_6.1
0.17.0

Open the chart page →

11,459
mayastorstartechnicaVerified publisher0.2.03 of 13See more

mayastor startechnica 0.2.0

3 of the 13 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
registry.k8s.io/sig-storage/livenessprobe:v2.8.0cacee2b5c36d
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
0.17.0

Open the chart page →

4,348
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
tomcat-embed-core@9.0.70
9.0.81

Open the chart page →

13,532
ckanstatcan0.0.352 of 8See more

ckan statcan 0.0.35

2 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
http2-common@9.4.44.v20210927
http2-server@9.4.44.v20210927
nghttp2@1.43.0-1
9.4.53
9.4.53
1.43.0-1+deb11u1
statcan/ckan:2.93921305425b8
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

24,984
statpingstatping0.1.141 of 1See more

statping statping 0.1.14

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0

Open the chart page →

3,371
hlf-k8ssubstraVerified publisher10.2.43 of 7See more

hlf-k8s substra 10.2.4

3 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:1.5.0f270dfeee91d
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
ghcr.io/substra/fabric-peer:0.2.4f681e0343a31
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
1.47.0-r2
0.17.0

Open the chart page →

12,006
synapsesudermanjr1.1.51 of 1See more

synapse sudermanjr 1.1.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

3,332
Grafanasurajwarbhe-grafana0.1.01 of 1See more

Grafana surajwarbhe-grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
surajwarbhe/grafana:v185248611e9f1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0

Open the chart page →

2,597
terraform-controllerterraform-controller0.0.201 of 1See more

terraform-controller terraform-controller 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
absaoss/terraform-controller:v0.0.20ad538a1285a0
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

3,538
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
golang.org/x/net@v0.7.0
1.52.0-1+deb12u1
0.17.0

Open the chart page →

9,108
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
golang.org/x/net@v0.7.0
1.52.0-1+deb12u1
0.17.0

Open the chart page →

9,108
spa-reloadertoucanVerified publisher0.1.01 of 1See more

spa-reloader toucan 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
toucansoftware/spa-reloader:latestc187b1fba501
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0

Open the chart page →

2,245
atlantistrozz3.12.111 of 1See more

atlantis trozz 3.12.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
runatlantis/atlantis:v0.16.145fbaf7e207c
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
0.17.0

Open the chart page →

5,280

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
milvusdb/etcd:3.5.5-r2102aac62827b
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0
1
milvusdb/milvus:v2.2.13a3a55e1c1497
nghttp2@1.40.0-1build1
golang.org/x/net@v0.10.0
1.40.0-1ubuntu0.2
0.17.0
1
milvusdb/milvus-config-tool:v0.1.12212dfb61401
golang.org/x/net@v0.0.0-20220706163947-c90051bbdb60
0.17.0
1
miniflux/miniflux:2.0.36e2fb990dae74
golang.org/x/net@v0.0.0-20210916014120-12bc252f5db8
0.17.0
1
minio/kes:v0.22.255f3aef5803e
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
0:1.33.0-5.el8_8
0.17.0
1
minio/kes:2023-04-03T16-41-28Zf93c2d9088df
golang.org/x/net@v0.7.0
0.17.0
1
minio/mc:RELEASE.2020-04-25T00-43-23Z1806872732e1
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0:1.33.0-5.el8_8
0.17.0
1
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0:1.33.0-5.el8_8
0.17.0
1
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0
1
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.7.0
0:1.33.0-5.el8_8
0.17.0
1
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0
1
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0:1.33.0-5.el8_8
0.17.0
1
minio/minio:RELEASE.2023-03-20T20-16-18Z6d770d7f255c
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.8.0
0:1.33.0-5.el8_8
0.17.0
1
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0
1
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0
1
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.1.0
0:1.33.0-4.el8_6.1
0.17.0
1
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0
1
minio/operator:v5.0.9170b154d2c61
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.13.0
0:1.33.0-5.el8_8
0.17.0
1
minio/operator:v4.1.02adc5be088f5
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
0:1.33.0-4.el8_4.1
0.17.0
1
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
nghttp2@1.46.0-r0
1.46.0-r2
1
mintproject/data-catalog-db:9be70359feabe03ed55bfdbf92c20a7e43ab928b9bf26fedd848
nghttp2@1.47.0-r0
1.47.0-r2
1
mintproject/mint-ui-lit:246a8771e8c043f8c1840d3c32262d3d6a9a553208c1a13c3397
nghttp2@1.47.0-r0
1.47.0-r2
1
mintproject/model-catalog-explorer:0b2f9f0a9124076aeb492add2f123d0757066f6bdeb80c93b4a9
nghttp2@1.47.0-r0
1.47.0-r2
1
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
0.17.0
1
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
0.17.0
1
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
golang.org/x/net@v0.0.0-20200114155413-6afb5195e5aa
0.17.0
1
mirrorgitlabcontainers/gitlab-workhorse-ce:v13.2.2a6d7bf42805a
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0
1
mnaggar3396/python-app:latest371d8ed84b15
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
moby/buildkit:v0.10.0c2aeafaed434
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
1.46.0-r2
0.17.0
1
moikot/smartthings-metrics:0.1.08625f53aa9b7
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.17.0
1
moikot/smartthings-metrics:feat-log-detailsfb8565140106
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.17.0
1
monitoror/monitoror:44b88edcf51ff
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
0.17.0
1
moreillon/camera-viewer:lateste418cc694bd5
nginx@1.29.0-1~bookworm
no fix listed
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
moreillon/mqtt-logger-front:50030b8bfc4d12db1d3e
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
moreillon/user-manager-front:v5.1.06597e6b98d21
nginx@1.27.0-2~bookworm
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0
1
mshanley80/httpbin2022:latest5b189a70c0fb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
murtazashah46/helmfile:latest4d11726cf803
golang.org/x/net@v0.5.0
0.17.0
1
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
mziyabo/fargate-eks-sidecar-injector:latest3067dce17983
golang.org/x/net@v0.7.0
0.17.0
1
n22107670/sample-app:0.4.08f3072db7aeb
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
n8nio/n8n:0.212.0a9195bc499a3
nghttp2@1.47.0-r0
1.47.0-r2
1
nacos/nacos-server:1.4.1fe6e5688cdf3
tomcat-embed-core@9.0.38
9.0.81
1
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
natsio/nats-box:0.13.559cf2e949181
nghttp2@1.51.0-r0
1.51.0-r2
1
natsio/nats-box:0.13.3c507bd7e3831
golang.org/x/net@v0.4.0
0.17.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.