StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,803 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,803 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
harborsoftonic1.13.04 of 8See more

harbor softonic 1.13.0

4 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
golang.org/x/net@v0.10.0
0.17.0
goharbor/harbor-jobservice:v2.9.039435daedd0c
golang.org/x/net@v0.10.0
0.17.0
goharbor/harbor-registryctl:v2.9.0cce272836449
golang.org/x/net@v0.10.0
0.17.0
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
golang.org/x/net@v0.12.0
0.17.0

Open the chart page →

7,701
pod-defaultersoftonic0.1.31 of 1See more

pod-defaulter softonic 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
softonic/pod-defaulter:0.1.072017aed5902
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,561
policy-reportersoftonic2.18.21 of 1See more

policy-reporter softonic 2.18.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kyverno/policy-reporter:2.14.1e74c6bf33d1b
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,045
preemptible-killersoftonic1.2.61 of 1See more

preemptible-killer softonic 1.2.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
softonic/preemptible-killer:1.2.6-294b87f1fb362
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
0.17.0

Open the chart page →

2,339
rate-limit-operatorsoftonic1.1.01 of 2See more

rate-limit-operator softonic 1.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
softonic/rate-limit-operator:0.1.1910f6de37763
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0

Open the chart page →

2,220
sealed-secretssoftonic2.6.91 of 1See more

sealed-secrets softonic 2.6.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnami/sealed-secrets-controller:v0.18.50516f987fae2
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0

Open the chart page →

1,515
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

4,288
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

2,513
gloo-meshsolo-gloo-mesh1.1.21 of 1See more

gloo-mesh solo-gloo-mesh 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/gloo-mesh/gloo-mesh:1.1.2a4011eae6a0b
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

3,266
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
nghttp2@1.43.0-1build3
tomcat-coyote@9.0.40
1.43.0-1ubuntu0.1
9.0.81

Open the chart page →

13,678
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
tomcat-coyote@8.5.57
8.5.94

Open the chart page →

13,150
smtp-fake-serversomeblackmagic0.1.01 of 1See more

smtp-fake-server someblackmagic 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
someblackmagic/smtp-fake-server:latest0d63ba37a560
tomcat-embed-core@9.0.41
9.0.81

Open the chart page →

4,281
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
1.40.0-1ubuntu0.2
0.17.0

Open the chart page →

30,778
spinnakerspinnakerVerified publisher2.2.132 of 4See more

spinnaker spinnaker 2.2.13

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.17.0
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0

Open the chart page →

6,850
spotinst-ocean-network-clientspot1.0.01 of 1See more

spotinst-ocean-network-client spot 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

6,966
pagessrinipages1.0.02 of 3See more

pages srinipages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
servicexssl-hep1.8.52 of 16See more

servicex ssl-hep 1.8.5

2 of the 16 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
golang.org/x/net@v0.4.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
bitnamilegacy/rabbitmq:3.11.18-debian-11-r029b0a2330572
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

68,323
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
golang.org/x/net@v0.0.0-20191028085509-fe3aa8a45271
0.17.0

Open the chart page →

3,096
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
1.47.0-r2
0.17.0

Open the chart page →

3,075
umsappstacksimplifyVerified publisher1.0.01 of 3See more

umsapp stacksimplify 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
tomcat-embed-core@9.0.21
9.0.81

Open the chart page →

6,105
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0:1.33.0-4.el8_4.1
0.17.0

Open the chart page →

28,515
external-secretsstakaterVerified publisher0.3.12-40dbdfc1 of 1See more

external-secrets stakater 0.3.12-40dbdfc

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0.17.0

Open the chart page →

2,088
k8scostoptimizerstakaterVerified publisher0.0.51 of 1See more

k8scostoptimizer stakater 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
stakater/k8s-cost-optimizer:v0.0.5450415ce1b4e
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

1,409
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
nghttp2@1.33.0-3.el8_2.1
tomcat-embed-core@9.0.65
0:1.33.0-4.el8_6.1
9.0.81

Open the chart page →

11,571
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
nghttp2@1.33.0-3.el8_2.1
tomcat-embed-core@9.0.65
0:1.33.0-4.el8_6.1
9.0.81

Open the chart page →

11,571
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.17.0

Open the chart page →

2,854
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
tomcat-embed-core@8.5.23
8.5.94

Open the chart page →

11,845
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0

Open the chart page →

2,173
vaultstakaterVerified publisher0.8.42 of 2See more

vault stakater 0.8.4

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0
hashicorp/vault-k8s:0.14.0aff47b5ba39c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

5,871
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0

Open the chart page →

2,565
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

6,678
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

20,317
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0.17.0

Open the chart page →

6,595
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
nghttp2@1.30.0-1ubuntu1
tomcat-embed-core@9.0.58
1.30.0-1ubuntu1+esm2
9.0.81

Open the chart page →

14,596
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/net@v0.0.0-20220621193019-9d032be2e588
0.17.0

Open the chart page →

1,985
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
prom/prometheus:v2.22.2f7ffebdd428b
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0

Open the chart page →

16,537
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
http2-common@9.4.44.v20210927
http2-server@9.4.44.v20210927
nghttp2@1.43.0-1
9.4.53
9.4.53
1.43.0-1+deb11u1

Open the chart page →

6,069
ingress-istio-controllerstatcan1.4.01 of 1See more

ingress-istio-controller statcan 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

1,583
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
0:1.33.0-4.el8_4.1
0.17.0

Open the chart page →

6,596
prometheus-operatorstatcan0.2.24 of 7See more

prometheus-operator statcan 0.2.2

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
0.17.0
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/net@v0.0.0-20191003171128-d98b1b443823
0.17.0
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.17.0

Open the chart page →

12,251
sidecar-terminatorstatcan1.3.51 of 1See more

sidecar-terminator statcan 1.3.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0

Open the chart page →

1,315
solrstatcan1.5.101 of 3See more

solr statcan 1.5.10

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/solr:8.11.18c5f7881cebb
http2-common@9.4.44.v20210927
http2-server@9.4.44.v20210927
nghttp2@1.43.0-1
9.4.53
9.4.53
1.43.0-1+deb11u1

Open the chart page →

8,809
starboard-operatorstatcan0.10.41 of 1See more

starboard-operator statcan 0.10.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
aquasec/starboard-operator:0.15.4be34f709e1ce
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

1,827
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
nghttp2@1.43.0-1build3
http2-common@9.4.49.v20220914
http2-server@9.4.49.v20220914
1.43.0-1ubuntu0.1
9.4.53
9.4.53

Open the chart page →

13,900
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
0.17.0

Open the chart page →

4,223
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.54 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

4 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
tomcat-embed-core@9.0.69
9.0.81
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
tomcat-embed-core@9.0.69
9.0.81
fimperato/static-src-people-detection:1.1.5-RELEASEc0cfaca070d9
tomcat-embed-core@9.0.69
9.0.81
library/mongo:4.4.18d23ec07162ca
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

13,704
pagesstephendillondell1.0.02 of 3See more

pages stephendillondell 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
tomcat-embed-core@8.5.11
8.5.94

Open the chart page →

8,557
sn-platform-slimstreamnative1.11.442 of 6See more

sn-platform-slim streamnative 1.11.44

2 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/net@v0.8.0
0.17.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

10,270
student-producerstudentproducerVerified publisher2.0.01 of 1See more

student-producer studentproducer 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
aroralalit/student-producer:1.0.02a094f597b36
tomcat-embed-core@9.0.75
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

3,022

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
tomcat-embed-core@9.0.63
9.0.81
1
thingsboard/tb-node:3.4.1645f43b688f7
tomcat-embed-core@9.0.63
9.0.81
1
thingsboard/tb-node:3.6.0f40a542832c4
tomcat-embed-core@9.0.73
9.0.81
1
thmmniii/fbs-core:v1.27.15438517d9fc2
nghttp2@1.43.0-1build3
tomcat-embed-core@9.0.75
1.43.0-1ubuntu0.1
9.0.81
1
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/net@v0.8.0
0.17.0
1
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.17.0
1
thomseddon/traefik-forward-auth:latestb364aa6a4117
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.17.0
1
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.17.0
1
thongngo3301/stakefish:latesta341af5976e3
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
0.17.0
1
tobirachel/node-project3:v17d9f37154994
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
torrespro/mca-worker:2.0.06d3bd305a1ba
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
toucansoftware/spa-reloader:latestc187b1fba501
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0
1
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
0.17.0
1
tranhailong/nfs-server:4.2-2-gcsfuse028662749be2
golang.org/x/net@v0.4.0
0.17.0
1
treeverse/lakefs:0.69.0478f37a6cffc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
1
trinodb/trino:405ee80ab5eeab2
nghttp2@1.43.0-1build3
http2-common@9.4.49.v20220914
http2-server@9.4.49.v20220914
1.43.0-1ubuntu0.1
9.4.53
9.4.53
1
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
tusproject/tusd:v1.10.01e457b59fd5b
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
1
tusproject/tusd:v1.13.0f8088058b80f
golang.org/x/net@v0.14.0
0.17.0
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.17.0
1
twinproduction/aws-eks-asg-rolling-update-handler:v1.7.08f38c206972e
golang.org/x/net@v0.1.0
0.17.0
1
twinproduction/gatus:v3.8.049dc0d9b2e2c
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ubercadence/server:0.23.22ac5491d13bb
golang.org/x/net@v0.0.0-20201031054903-ff519b6c9102
0.17.0
1
udhos/forward:1.1.312e120d39fdb
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
1
udhos/prime:1.0.0e432012dd34a
nghttp2@1.51.0-r0
1.51.0-r2
1
uffizzi/uffizzi-cluster-operator:v1.4.514e528bbd926
golang.org/x/net@v0.8.0
0.17.0
1
uffizzi/uffizzi-cluster-operator:v1.6.55ca448a08783
golang.org/x/net@v0.8.0
0.17.0
1
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
1
vaultwarden/server:1.27.0-alpine7cd450642c54
nghttp2@1.51.0-r0
1.51.0-r2
1
vaultwarden/server:1.29.1c2849f8189e4
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
vearch/vearch:3.3.40768af33f9d9
golang.org/x/net@v0.10.0
0.17.0
1
velero/velero:v1.9.0277fbfaf8dcf
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
velero/velero:v1.8.18d784580931c
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
victoriametrics/victoria-metrics:v1.93.577a9815d0640
golang.org/x/net@v0.15.0
0.17.0
1
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
tomcat-embed-core@9.0.50
0.17.0
9.0.81
1
vikunja/api:0.17.18cba0520bf8c
golang.org/x/net@v0.0.0-20210505024714-0287a6fb4125
0.17.0
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
vitalii1992/account-service:latest0e694d94551d
tomcat-embed-core@10.1.8
10.1.14
1
vitalii1992/analytics-service:latest8e798836ecea
tomcat-embed-core@10.1.8
10.1.14
1
vitalii1992/api-gateway-service:latestaabe6ac39356
tomcat-embed-core@10.1.8
10.1.14
1
vitalii1992/order-service:latest07c4a8833ce4
tomcat-embed-core@10.1.8
10.1.14
1
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
tomcat-embed-core@10.1.8
10.1.14
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.