StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,797 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,797 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
zentaorock8sVerified publisher0.0.11 of 1See more

zentao rock8s 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
easysoft/quickon-zentao:18.5592ad5df1f8b
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

1,535
argocdromholdings1.8.12 of 3See more

argocd romholdings 1.8.1

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/net@v0.0.0-20201024042810-be3efd7ff127
0.17.0
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.17.0

Open the chart page →

10,484
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
nghttp2@1.43.0-1build3
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

13,033
argo-workflowromholdings0.1.61 of 1See more

argo-workflow romholdings 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,587
calicoromholdings0.1.13 of 4See more

calico romholdings 0.1.1

3 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

10,094
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

6,237
devtron-enterpriseromholdings48.0.09 of 28See more

devtron-enterprise romholdings 48.0.0

9 of the 28 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
1.46.0-r2
0.17.0
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
1.52.0-1+deb12u1
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.17.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
quay.io/devtron/k8s-utils:tutum-curl38b970c84cce
nghttp2@1.46.0-r0
1.46.0-r2
quay.io/devtron/kubectl:latest2ad610626658
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.17.0
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.17.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

68,765
devtron-in-clustercdromholdings0.10.22 of 2See more

devtron-in-clustercd romholdings 0.10.2

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.17.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

5,055
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
nghttp2@1.43.0-1build3
golang.org/x/net@v0.8.0
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

4,979
devtron-operatorromholdings0.23.36 of 11See more

devtron-operator romholdings 0.23.3

6 of the 11 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
1.46.0-r2
0.17.0
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
nghttp2@1.52.0-1
1.52.0-1+deb12u1
quay.io/devtron/dex:v2.30.22e4c14d1b444
golang.org/x/net@v0.0.0-20210503060351-7fd8e65b6420
0.17.0
quay.io/devtron/kubectl:latest2ad610626658
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
golang.org/x/net@v0.10.0
0.17.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

33,219
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
1.40.0-1ubuntu0.2
0.17.0

Open the chart page →

11,981
kube-prometheus-stackromholdings19.3.03 of 6See more

kube-prometheus-stack romholdings 19.3.0

3 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
0.17.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

8,659
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.17.0

Open the chart page →

2,442
svn-git-syncromholdings0.1.31 of 1See more

svn-git-sync romholdings 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/svn-git-sync:v78e54bc2d261f
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,860
winter-soldierromholdings0.10.61 of 1See more

winter-soldier romholdings 0.10.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

1,176
zincromholdings0.1.21 of 1See more

zinc romholdings 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
golang.org/x/net@v0.0.0-20221002022538-bcab6841153b
0.17.0

Open the chart page →

1,514
pagesronan-pages1.0.02 of 3See more

pages ronan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
controllerrookout0.2.561 of 1See more

controller rookout 0.2.56

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rookout/controller:latest4451a6f6b8ec
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

1,967
datastorerookout0.1.481 of 1See more

datastore rookout 0.1.48

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rookout/data-on-prem:latest51c0fce64467
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

1,948
operatorrookout0.0.201 of 2See more

operator rookout 0.0.20

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rookout/k8s-operator:latest0d083f3ef1a7
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,209
rookout-hybridrookout0.3.12 of 2See more

rookout-hybrid rookout 0.3.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rookout/controller:latest4451a6f6b8ec
golang.org/x/net@v0.13.0
0.17.0
rookout/data-on-prem:latest51c0fce64467
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

3,915
routehub-serverroutehub-helm1.0.11 of 3See more

routehub-server routehub-helm 1.0.1

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2

Open the chart page →

6,978
routr-connectroutr0.4.31 of 10See more

routr-connect routr 0.4.3

1 of the 10 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
fonoster/routr-edgeport:2.13.6d08a8a574a50
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

11,025
smokepingrubxkubeVerified publisher1.2.11 of 1See more

smokeping rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/smokeping:2.9.02f4488c9afcd
golang.org/x/net@v0.6.0
0.17.0

Open the chart page →

915
nacossaber0.1.111 of 1See more

nacos saber 0.1.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
tomcat-embed-core@9.0.38
9.0.81

Open the chart page →

3,981
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

19,714
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

16,736
caddysagikazarmarkVerified publisher0.0.141 of 1See more

caddy sagikazarmark 0.0.14

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/caddy:2.4.5874405536b3e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

2,967
tusdsagikazarmarkVerified publisher0.1.21 of 1See more

tusd sagikazarmark 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
tusproject/tusd:v1.10.01e457b59fd5b
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0

Open the chart page →

1,552
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

16,260
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

8,146
knative-helm-operatorsalaboy1.9.02 of 2See more

knative-helm-operator salaboy 1.9.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/operator/cmd/webhookdigest-pinned6c5c90cdf707
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
gcr.io/knative-releases/knative.dev/serving/cmd/default-domaindigest-pinned5e0429b70299
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

2,346
pagessamanvithkaranth1.0.02 of 3See more

pages samanvithkaranth 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
hellowsamarthya2.0.01 of 1See more

hellow samarthya 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
samarthya/spinnaker:v1.0ef06d81036af
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
0.17.0

Open the chart page →

2,121
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
santisbon/speedtest:latest8ee3a1697227
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

12,769
grocysarab97Verified publisher0.1.11 of 1See more

grocy sarab97 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/grocy:4.0.1f8f5f96b6ea8
nghttp2@1.55.1-r0
nginx@1.24.0-r6
1.57.0-r0
1.24.0-r7

Open the chart page →

2,448
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

4,752
pagessarubits-pages1.0.02 of 3See more

pages sarubits-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
unboundsavepointsamVerified publisher1.0.01 of 1See more

unbound savepointsam 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
savepointsam/unbound:1.15.09b9e0c057d23
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

754
pushgatewaysb-helm-charts0.3.01 of 1See more

pushgateway sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,173
ed-traefikscaleway-charts0.2.01 of 1See more

ed-traefik scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/traefik:v1.7.345d47b7bb2546
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
0.17.0

Open the chart page →

2,140
ed-traefik2scaleway-charts0.2.01 of 1See more

ed-traefik2 scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/traefik:2.5.62f603f8d3abe
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

3,168
scalyr-k8snode-managerscalyr-k8snode-managerVerified publisher0.1.71 of 1See more

scalyr-k8snode-manager scalyr-k8snode-manager 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

2,150
cosischichtelVerified publisher0.1.01 of 1See more

cosi schichtel 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/objectstorage-controller:v20221027-v0.1.1-8-g300019fa84b574e8027
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.17.0

Open the chart page →

1,309
sponge-vanillaschichtelVerified publisher0.1.21 of 1See more

sponge-vanilla schichtel 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/cubeengine/sponge:1.20.2-11.0.0-RC13755c85f2b82064
nghttp2@1.55.1-r0
1.57.0-r0

Open the chart page →

1,009
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/net@v0.4.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

5,584
cert-manager-desec-webhookschmitzis0.0.11 of 1See more

cert-manager-desec-webhook schmitzis 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
su541/cert-manager-desec-webhook:latest371ee33f83c1
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,777
cert-manager-webhook-bunnyschmitzis0.1.11 of 1See more

cert-manager-webhook-bunny schmitzis 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/schmitzis/cert-manager-webhook-bunny:latest125e31c8e85a
golang.org/x/net@v0.5.0
0.17.0

Open the chart page →

1,505
icinga2-masterschmitzis0.2.01 of 6See more

icinga2-master schmitzis 0.2.0

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:8.0.3696823fbc561
golang.org/x/net@v0.0.0-20210521195947-fe42d452be8f
0.17.0

Open the chart page →

3,738
otterwikischmitzis0.1.01 of 1See more

otterwiki schmitzis 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
redimp/otterwiki:2778bf30da3da
nginx@1.22.1-9+deb12u9
no fix listed

Open the chart page →

3,234

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
natsio/nats-box:0.14.2e808e0644ce1
golang.org/x/net@v0.15.0
0.17.0
1
natsio/nats-operator:0.8.31261dae38389
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
neilpang/acme.sh:3.0.2595809ad43a2
nghttp2@1.46.0-r0
1.46.0-r2
1
nerzhul/mc-arm64:2020.10.034215df511f31
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0
1
netapp/trident-operator:21.10.049cfe552d9c2
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
1
netboxcommunity/netbox:v3.2.83d652dca5351
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
netrisai/netris-operator:v4.0.244f60aa0d898
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
nginx/nginx-ingress:1.11.1eb5b4fd73325
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.17.0
1
nineinfra/kyuubi-operator:v0.7.08d8ed87ef77c
golang.org/x/net@v0.13.0
0.17.0
1
nineinfra/metastore-operator:v0.7.011259032fb04
golang.org/x/net@v0.13.0
0.17.0
1
nirmalnaveen/supermario:latest8541a39162f3
nghttp2@1.52.0-1
nginx@1.25.3-1~bookworm
1.52.0-1+deb12u1
no fix listed
1
nocodb/nocodb:0.100.2b0b91ec2a2dd
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20220805013720-a33c5aa5df48
1.46.0-r2
0.17.0
1
nocodb/nocodb:0.84.15f9b799933aa8
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.17.0
1
novumrgi/glowroot-central:0.14.0-beta.38c54790675b1
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
nrrrus/nginx-test:latest5f55cd4ef557
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ntakashi/cole:1.2.3f7b68bee2a68
golang.org/x/net@v0.10.0
0.17.0
1
ntakashi/gitana:1.4.04171ec641120
golang.org/x/net@v0.0.0-20210929161516-d455829e376d
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
nvidia/dcgm-exporter:2.2.9-2.4.1-ubuntu20.0491b20b66d1cd
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
golang.org/x/net@v0.7.0
0.17.0
1
ofekmeister/csi-gcs:v0.9.030d70fa9211b
golang.org/x/net@v0.0.0-20220513224357-95641704303c
0.17.0
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
nginx@1.20.2-r0
1.20.2-r2
1
okteto/civo-webhook:0.5.357cd51176538
golang.org/x/net@v0.15.0
0.17.0
1
oled01/db-backup:0.1.06302fd2b5333
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
olliai/exposecontroller:1.0.5a470d96525e4
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
olliai/k8s-replicator:1.3.05716f2a8bd4c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
omecproject/c3po-hssdb:master-latest28a90cc26716
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
nghttp2@1.30.0-1ubuntu1
tomcat-coyote@8.5.38
tomcat-embed-core@8.5.38
1.30.0-1ubuntu1+esm2
8.5.94
8.5.94
1
onosproject/onos:2.2.144914a8d4b3f
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
openbas/caldera-server:5.1.0a277796d9724
golang.org/x/net@v0.14.0
0.17.0
1
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
1
opencord/ves-agent:1.0.04187e2a8c918
tomcat-embed-core@8.5.31
8.5.94
1
opendatacube/pipelines:wofs-1.225d810e8504b8
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
opendatacube/restcube:latest91870111837c
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
opendatacube/wms:latest1b90cdf68831
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
openebs/provisioner-nfs:0.11.04f41dd782761
golang.org/x/net@v0.10.0
0.17.0
1
openelevation/open-elevation:latest82fb21612e86
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
openemr/openemr:6.1.089eaa6d9a4e3
nghttp2@1.46.0-r0
1.46.0-r2
1
openenergyprojects/modbus_exporter:20230617_a14455158990f24fb25
golang.org/x/net@v0.8.0
0.17.0
1
openhab/openhab:3.2.0d0aa4af452c1
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
openkm/openkm-ce:6.3.113bc465a7461b
nghttp2@1.40.0-1build1
tomcat-coyote@8.5.69
1.40.0-1ubuntu0.2
8.5.94
1
openkruise/kruise-rollout:v0.6.2a75e6739ea7d
golang.org/x/net@v0.7.0
0.17.0
1
openkruise/kruise-state-metrics:v0.2.0a8108f771287
golang.org/x/net@v0.8.0
0.17.0
1
openpolicyagent/opa:0.53.16a58dea59933
golang.org/x/net@v0.10.0
0.17.0
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
1
openspeedtest/latest:v2.0.0d4d62f4b7d85
nghttp2@1.51.0-r0
1.51.0-r2
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
1
openthread/otbr:latestf307f59f6432
nghttp2@1.30.0-1ubuntu1
nodejs@8.10.0~dfsg-2ubuntu0.4
1.30.0-1ubuntu1+esm2
8.10.0~dfsg-2ubuntu0.4+esm6
1
openverso/ueransim:3.2.6733f1232b7d3
nghttp2@1.47.0-r0
1.47.0-r2
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.