StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,107
of 17,790 indexed, latest versions
Container images
2,471
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,107 of 17,790 indexed charts deploy, on 2,471 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,572
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,107 by stars
ChartLatestAffected imagesRadar Score
grafana-dashboardsdysnixVerified publisher0.2.21 of 2See more

grafana-dashboards dysnix 0.2.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:7.4.5d322192ed2fa
golang.org/x/net@v0.0.0-20201022231255-08b38378de70
0.17.0

Open the chart page →

5,167
heimdalldysnixVerified publisher0.0.11 of 1See more

heimdall dysnix 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
0xpolygon/heimdall:1.0.134ddf259993c
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,373
local-path-provisionerdysnixVerified publisher0.0.201 of 1See more

local-path-provisioner dysnix 0.0.20

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.17.0

Open the chart page →

2,925
servicemonitor-appsdysnixVerified publisher0.1.01 of 1See more

servicemonitor-apps dysnix 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ethpandaops/ethereum-metrics-exporter:0.21.0d1780db2e286
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
0.17.0

Open the chart page →

1,578
eav-componenteav-component1.0.02 of 3See more

eav-component eav-component 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eav-component-nginx:latestd785c893096c
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ghcr.io/conductionnl/eav-component-php:latest24bbca4a52a8
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
1.46.0-r2
0.17.0

Open the chart page →

7,265
aeros-orchestrator-overlayeclipse-aeriosVerified publisher2.0.01 of 2See more

aeros-orchestrator-overlay eclipse-aerios 2.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
masipcat/wireguard-go:latest696206e5954d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

1,195
iotaeclipse-aeriosVerified publisher1.0.22 of 4See more

iota eclipse-aerios 1.0.2

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
iotaledger/hornet:2.001206f1ba89c
golang.org/x/net@v0.14.0
0.17.0
iotaledger/inx-dashboard:1.012c669cb8748
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

13,487
llo-docker-operatoreclipse-aeriosVerified publisher1.0.01 of 2See more

llo-docker-operator eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

2,193
llo-k8seclipse-aeriosVerified publisher1.1.02 of 2See more

llo-k8s eclipse-aerios 1.1.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
golang.org/x/net@v0.10.0
0.17.0
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

2,164
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

11,483
openldap-stack-haeclipse-aeriosVerified publisher4.1.21 of 4See more

openldap-stack-ha eclipse-aerios 4.1.2

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

7,534
chartecr-toke-renew0.1.51 of 1See more

chart ecr-toke-renew 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

2,818
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

10,998
pagesedgwarepages1.0.02 of 3See more

pages edgwarepages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
grafanaedu5.3.01 of 1See more

grafana edu 5.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0

Open the chart page →

3,198
prometheusedu11.6.03 of 6See more

prometheus edu 11.6.0

3 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.17.0
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.17.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.17.0

Open the chart page →

8,491
education-componenteducation-component1.0.02 of 3See more

education-component education-component 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-nginx:latest38900bc76ee0
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
1.46.0-r2
0.17.0

Open the chart page →

7,337
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

4,047
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

4,034
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

4,034
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

4,034
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,519
mongodb-charteks-3-tier-app-chart0.1.01 of 1See more

mongodb-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

8,049
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

25,263
Navidromeemmas-chartsVerified publisher0.0.41 of 1See more

Navidrome emmas-charts 0.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
deluan/navidrome:0.49.311a24da08977
golang.org/x/net@v0.5.0
0.17.0

Open the chart page →

2,837
parrot-mirroremmas-chartsVerified publisher1.0.01 of 1See more

parrot-mirror emmas-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

2,243
reddarkemmas-chartsVerified publisher0.0.21 of 1See more

reddark emmas-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/0xemma/reddark:main2a115e991894
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,998
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

10,610
emptyempty1.1.01 of 1See more

empty empty 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.22.0f0d28f204785
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

967
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

1,329
kube-ecp-stackemqx-operator2.5.13 of 16See more

kube-ecp-stack emqx-operator 2.5.1

3 of the 16 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
emqx/ecp-ui:2.5.1e33e9816f147
nginx@1.27.2-1~bookworm
no fix listed
emqx/emqx:4.4.1971db5ed95db3
nghttp2@1.46.0-r0
1.46.0-r2
library/telegraf:1.27507a3eecf809
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

23,813
kube-packetloss-exporterenixVerified publisher0.2.11 of 2See more

kube-packetloss-exporter enix 0.2.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

6,165
eoapi-supporteoapiVerified publisher0.1.75 of 7See more

eoapi-support eoapi 0.1.7

5 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
0.17.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
0.17.0
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
0.17.0
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

8,667
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
oscarsotosanchez/weatherservice:v1.0911ec961d10b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

27,361
eoloPlanteolo-plannerVerified publisher0.1.04 of 7See more

eoloPlant eolo-planner 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
mastercloudapps/planner:v1.2340a950b311b2
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
mastercloudapps/server:v2.23f3d24dfe2686
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
mastercloudapps/weatherservice:v1.23de859d29c116
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

27,702
eoloplannereoloplannerVerified publisher0.1.05 of 7See more

eoloplanner eoloplanner 0.1.0

5 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

32,372
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.04 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
mastercloudapps/planner:v1.2340a950b311b2
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
mastercloudapps/server:v2.23f3d24dfe2686
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
mastercloudapps/weatherservice:v1.23de859d29c116
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

27,702
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
oscarsotosanchez/weatherservice:v1.0911ec961d10b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

27,327
eoloplannereoloplanner-molynx-gat0.1.04 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

28,549
eolo-plannereolo-planner-repo0.1.03 of 7See more

eolo-planner eolo-planner-repo 0.1.0

3 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

27,197
eoloplanteoloplant1.0.04 of 7See more

eoloplant eoloplant 1.0.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
mastercloudapps/planner:v1.2340a950b311b2
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
mastercloudapps/server:v2.23f3d24dfe2686
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
mastercloudapps/weatherservice:v1.23de859d29c116
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

27,702
eoloplantseoloplants-urjcVerified publisher0.1.04 of 7See more

eoloplants eoloplants-urjc 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

27,822
servereoloserverVerified publisher0.1.05 of 7See more

server eoloserver 0.1.0

5 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

32,372
download-from-github-repoeosc-lot-1Verified publisher0.1.01 of 2See more

download-from-github-repo eosc-lot-1 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

992
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

9,402
postgresql-verify-backupeosc-lot-1Verified publisher0.2.01 of 3See more

postgresql-verify-backup eosc-lot-1 0.2.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3-alpine4738bee21eb6
nghttp2@1.55.1-r0
1.57.0-r0

Open the chart page →

2,061
rabbitmq-usereosc-lot-1Verified publisher0.1.01 of 1See more

rabbitmq-user eosc-lot-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

969
epinio-uiepinioVerified publisher1.7.21 of 1See more

epinio-ui epinio 1.7.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
0.17.0

Open the chart page →

1,693
upgrade-responderepinioVerified publisher0.2.02 of 5See more

upgrade-responder epinio 0.2.0

2 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
curlimages/curl:7.85.09fab1b73f45e
nghttp2@1.46.0-r0
1.46.0-r2
grafana/grafana:10.1.50679e877ba20
golang.org/x/net@v0.12.0
0.17.0

Open the chart page →

7,376
admin-console-operatorepmdedpVerified publisher2.14.02 of 2See more

admin-console-operator epmdedp 2.14.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/admin-console-operator:2.14.090f9921d8d58
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
0.17.0
epamedp/edp-admin-console:2.14.0616c678ba3e7
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
0.17.0

Open the chart page →

4,309

Container images carrying it

2,471 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
tomcat-embed-core@9.0.63
9.0.81
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
tomcat-embed-core@9.0.63
9.0.81
1
thingsboard/tb-node:3.4.1645f43b688f7
tomcat-embed-core@9.0.63
9.0.81
1
thingsboard/tb-node:3.6.0f40a542832c4
tomcat-embed-core@9.0.73
9.0.81
1
thmmniii/fbs-core:v1.27.15438517d9fc2
nghttp2@1.43.0-1build3
tomcat-embed-core@9.0.75
1.43.0-1ubuntu0.1
9.0.81
1
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/net@v0.8.0
0.17.0
1
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.17.0
1
thomseddon/traefik-forward-auth:latestb364aa6a4117
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.17.0
1
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.17.0
1
thongngo3301/stakefish:latesta341af5976e3
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
0.17.0
1
tobirachel/node-project3:v17d9f37154994
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
torrespro/mca-worker:2.0.06d3bd305a1ba
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
toucansoftware/spa-reloader:latestc187b1fba501
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0
1
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
0.17.0
1
tranhailong/nfs-server:4.2-2-gcsfuse028662749be2
golang.org/x/net@v0.4.0
0.17.0
1
treeverse/lakefs:0.69.0478f37a6cffc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
1
trinodb/trino:405ee80ab5eeab2
nghttp2@1.43.0-1build3
http2-common@9.4.49.v20220914
http2-server@9.4.49.v20220914
1.43.0-1ubuntu0.1
9.4.53
9.4.53
1
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
tusproject/tusd:v1.10.01e457b59fd5b
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
1
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/net@v0.14.0
0.17.0
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.17.0
1
twinproduction/aws-eks-asg-rolling-update-handler:v1.7.08f38c206972e
golang.org/x/net@v0.1.0
0.17.0
1
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ubercadence/server:0.23.22ac5491d13bb
golang.org/x/net@v0.0.0-20201031054903-ff519b6c9102
0.17.0
1
udhos/forward:1.1.312e120d39fdb
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
1
udhos/prime:1.0.0e432012dd34a
nghttp2@1.51.0-r0
1.51.0-r2
1
uffizzi/uffizzi-cluster-operator:v1.4.514e528bbd926
golang.org/x/net@v0.8.0
0.17.0
1
uffizzi/uffizzi-cluster-operator:v1.6.55ca448a08783
golang.org/x/net@v0.8.0
0.17.0
1
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
1
vaultwarden/server:1.27.0-alpine7cd450642c54
nghttp2@1.51.0-r0
1.51.0-r2
1
vaultwarden/server:1.29.1c2849f8189e4
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
vearch/vearch:3.3.40768af33f9d9
golang.org/x/net@v0.10.0
0.17.0
1
velero/velero:v1.9.0277fbfaf8dcf
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
velero/velero:v1.8.18d784580931c
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
victoriametrics/victoria-metrics:v1.93.577a9815d0640
golang.org/x/net@v0.15.0
0.17.0
1
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
tomcat-embed-core@9.0.50
0.17.0
9.0.81
1
vikunja/api:0.17.18cba0520bf8c
golang.org/x/net@v0.0.0-20210505024714-0287a6fb4125
0.17.0
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
vitalii1992/account-service:latest0e694d94551d
tomcat-embed-core@10.1.8
10.1.14
1
vitalii1992/analytics-service:latest8e798836ecea
tomcat-embed-core@10.1.8
10.1.14
1
vitalii1992/api-gateway-service:latestaabe6ac39356
tomcat-embed-core@10.1.8
10.1.14
1
vitalii1992/order-service:latest07c4a8833ce4
tomcat-embed-core@10.1.8
10.1.14
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.