StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,091
of 17,781 indexed, latest versions
Container images
2,444
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,091 of 17,781 indexed charts deploy, on 2,444 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more546
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more176
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+182 more0.17.01,549
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,091 by stars
ChartLatestAffected imagesRadar Score
taigaunxwaresVerified publisher2026.3.81 of 6See more

taiga unxwares 2026.3.8

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
taigaio/taiga-front:latest570c8792ce80
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

9,148
upbot-operatorupbot-operator0.0.201 of 2See more

upbot-operator upbot-operator 0.0.20

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
alpine/k8s:1.28.13e5c0b053fed7
golang.org/x/net@v0.12.0
0.17.0

Open the chart page →

4,460
user-componentuser-component1.2.02 of 4See more

user-component user-component 1.2.0

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/user-component-nginx:latestb721579df8c3
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
1.46.0-r2
0.17.0

Open the chart page →

7,303
v2ray-proxyv2ray-proxy0.2.41 of 1See more

v2ray-proxy v2ray-proxy 0.2.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
pinclr/v2ray-proxy:latestf37f250b7091
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,954
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
varnish@7.5.0
no fix listed

Open the chart page →

4,249
vearchvearch3.3.42 of 4See more

vearch vearch 3.3.4

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.17.0
vearch/vearch:3.3.40768af33f9d9
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

5,008
tdarrvhdirkVerified publisher5.0.52 of 2See more

tdarr vhdirk 5.0.5

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

26,657
postfixadminvolker-raschekVerified publisher0.3.11 of 1See more

postfixadmin volker-raschek 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
volkerraschek/postfixadmin:3.3.13c4f10aebf87b
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,083
phpipamvquieVerified publisher1.0.32 of 3See more

phpipam vquie 1.0.3

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phpipam/phpipam-cron:v1.5.2f770577cb946
nghttp2@1.46.0-r0
1.46.0-r2
phpipam/phpipam-www:v1.5.23c6fd1332aeb
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

7,025
vultr-ccmvultrVerified publisher1.3.01 of 1See more

vultr-ccm vultr 1.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vultr/vultr-cloud-controller-manager:v0.3.01806f17d620c
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

3,034
waardepapierenwaardepapieren1.0.02 of 3See more

waardepapieren waardepapieren 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-nginx:latestaf31cf6cd59f
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

8,079
waardepapieren-baliewaardepapieren-balie1.0.01 of 3See more

waardepapieren-balie waardepapieren-balie 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,871
waardepapieren-registerwaardepapieren-register1.1.01 of 4See more

waardepapieren-register waardepapieren-register 1.1.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,429
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

15,970
webhookswebhooks0.1.51 of 1See more

webhooks webhooks 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

2,030
frpswenerme1.0.11 of 1See more

frps wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wener/frps:v0.37.05c92cc9e8597
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0

Open the chart page →

3,359
wharf-ainowharf-helmVerified publisher0.1.56 of 7See more

wharf-aino wharf-helm 0.1.5

6 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.17.0
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
1.46.0-r2
0.17.0
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.17.0
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.17.0
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.17.0
quay.io/iver-wharf/wharf-web:v1.6.2dc5d1ed91c26
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

13,459
wharf-cmdwharf-helmVerified publisher0.3.31 of 1See more

wharf-cmd wharf-helm 0.3.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-cmd:v0.8.2e98d13459cdc
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
1.46.0-r2
0.17.0

Open the chart page →

3,427
external-monitoringwiremindVerified publisher0.3.01 of 1See more

external-monitoring wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

1,293
kubemodwiremindVerified publisher0.1.51 of 2See more

kubemod wiremind 0.1.5

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.13.0cadca39288ad
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0

Open the chart page →

3,030
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.12.0
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

10,090
pi-hole-exporterwyrihaximusnetVerified publisher0.1.31 of 1See more

pi-hole-exporter wyrihaximusnet 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ekofr/pihole-exporter:0.0.109fdad6f352e0
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
0.17.0

Open the chart page →

1,809
redis-db-assignment-operatorwyrihaximusnetVerified publisher1.0.61 of 1See more

redis-db-assignment-operator wyrihaximusnet 1.0.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/kubernetes-redis-db-assignment-operator:v1.0.831060be60bec
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

2,235
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

9,783
tailscale-relayzeet0.1.51 of 1See more

tailscale-relay zeet 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zeetdev/tailscale-relay:v1.24.21967aa2840b6
golang.org/x/net@v0.0.0-20220407224826-aac1ed45d8e3
0.17.0

Open the chart page →

2,165
abstract-nodeabstract-nodeVerified publisher0.1.491 of 2See more

abstract-node abstract-node 0.1.49

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/abstract-foundation/zksync-external-node-sidecar:v1.0.03e705d0eb1ce
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

4,554
accountaccount-serviceVerified publisher0.4.21 of 1See more

account account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vitalii1992/account-service:latest0e694d94551d
tomcat-embed-core@10.1.8
10.1.14

Open the chart page →

2,168
analyticsaccount-serviceVerified publisher0.4.21 of 1See more

analytics account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vitalii1992/analytics-service:latest8e798836ecea
tomcat-embed-core@10.1.8
10.1.14

Open the chart page →

2,326
gatewayaccount-serviceVerified publisher0.4.21 of 1See more

gateway account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vitalii1992/api-gateway-service:latestaabe6ac39356
tomcat-embed-core@10.1.8
10.1.14

Open the chart page →

2,853
keycloakaccount-serviceVerified publisher18.4.51 of 2See more

keycloak account-service 18.4.5

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

7,713
orderaccount-serviceVerified publisher0.4.21 of 1See more

order account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vitalii1992/order-service:latest07c4a8833ce4
tomcat-embed-core@10.1.8
10.1.14

Open the chart page →

2,221
quotes-provideraccount-serviceVerified publisher0.4.21 of 1See more

quotes-provider account-service 0.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
tomcat-embed-core@10.1.8
10.1.14

Open the chart page →

2,205
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

25,443
admin-portaladmin-web-portal1.2.11 of 2See more

admin-portal admin-web-portal 1.2.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
soulou2019/angular-nginx:latesta3970f97c215
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

3,419
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,447
bootaerokube1.0.11 of 4See more

boot aerokube 1.0.1

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/aerokube/keygen:1.0.1578934444f04
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

7,834
moonaerokube1.1.371 of 3See more

moon aerokube 1.1.37

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
aerokube/selenoid-ui:1.10.113f3e299509fd
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

2,472
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,209
agentkube-operatoragentkube-operator0.3.01 of 1See more

agentkube-operator agentkube-operator 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,716
airports-apiairports-api0.1.01 of 1See more

airports-api airports-api 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dina1993/airports-api:latestac731244aed1
tomcat-embed-core@10.1.7
10.1.14

Open the chart page →

1,958
airports-consumerairports-consumer0.1.01 of 1See more

airports-consumer airports-consumer 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dina1993/airports-consumer:latest669d146a5e63
tomcat-embed-core@10.1.7
10.1.14

Open the chart page →

1,947
airports-frontendairports-frontend0.1.01 of 1See more

airports-frontend airports-frontend 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
daniacobext/airports-frontend:latest9eae4d39fc33
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

1,271
airports-kafkaairports-kafka0.1.01 of 2See more

airports-kafka airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

4,547
airports-producerairports-producer0.1.01 of 1See more

airports-producer airports-producer 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dina1993/airports-producer:latest3d6b0dac1cb4
tomcat-embed-core@10.1.7
10.1.14

Open the chart page →

1,947
akriakri0.12.551 of 3See more

akri akri 0.12.55

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

1,545
aktoakto0.2.02 of 7See more

akto akto 0.2.0

2 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

13,613
akto-protectionakto0.1.02 of 4See more

akto-protection akto 0.1.0

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

11,285
kpubberalekcVerified publisher0.0.41 of 1See more

kpubber alekc 0.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

2,228
gitlab-code-review-notifieralmorgvVerified publisher0.1.21 of 2See more

gitlab-code-review-notifier almorgv 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0

Open the chart page →

2,115
pagesalstom-pages-app1.0.02 of 3See more

pages alstom-pages-app 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,190

Container images carrying it

2,444 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/clair:4.3.675fb847ac045
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0:1.33.0-5.el8_8
0.17.0
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.17.0
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
3
quay.io/devtron/k8s-utils:tutum-curl38b970c84cce
nghttp2@1.46.0-r0
1.46.0-r2
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
nghttp2@1.43.0-1build3
golang.org/x/net@v0.8.0
1.43.0-1ubuntu0.1
0.17.0
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
golang.org/x/net@v0.8.0
0.17.0
3
quay.io/devtron/nats-box:latest48cdd3054b20
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
0.17.0
3
quay.io/devtron/svn-git-sync:v78e54bc2d261f
nghttp2@1.47.0-r0
1.47.0-r2
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.17.0
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.17.0
3
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
0.17.0
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
nghttp2@1.33.0-4.el8_6.1
0:1.33.0-5.el8_8
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
0.17.0
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.17.0
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
0.17.0
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
3
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
golang.org/x/net@v0.0.0-20210610132358-84b48f89b13b
0.17.0
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
0.17.0
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
0.17.0
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.17.0
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
0.17.0
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0:1.33.0-5.el8_8
0.17.0
3
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
nghttp2@1.47.0-r0
golang.org/x/net@v0.1.0
1.47.0-r2
0.17.0
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
golang.org/x/net@v0.8.0
0.17.0
3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
golang.org/x/net@v0.8.0
0.17.0
3
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
golang.org/x/net@v0.8.0
0.17.0
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0
3
1password/scim:v2.3.129d0c6cb67eb
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
2
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
nghttp2@1.51.0-r0
1.51.0-r2
2
altinity/clickhouse-operator:0.21.2cd9252644ce0
golang.org/x/net@v0.7.0
0.17.0
2
altinity/metrics-exporter:0.21.2df3d57215356
golang.org/x/net@v0.7.0
0.17.0
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
tomcat-embed-core@8.5.31
8.5.94
2
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
0.17.0
2
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
2
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.17.0
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/net@v0.7.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
2
bitnamilegacy/os-shell:11-debian-11-r722cb5982dcbf4
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
0.17.0
2
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
0.17.0
2
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.17.0
2
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
nghttp2@1.55.1-r0
1.57.0-r0
2
confluentinc/cp-kafka:6.2.11-1-ubi8ac776fad95a5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
2
confluentinc/cp-zookeeper:6.2.11-1-ubi8cae577096489
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.