StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,797 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,797 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
user-manager-neo4jmoreillonVerified publisher0.9.73 of 6See more

user-manager-neo4j moreillon 0.9.7

3 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
moreillon/group-manager-front:v3.3.1c9f85db3baa5
nginx@1.27.0-2~bookworm
no fix listed
moreillon/user-manager:v5.0.2e1c9bfab5c16
nghttp2@1.52.0-1
1.52.0-1+deb12u1
moreillon/user-manager-front:v5.1.06597e6b98d21
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

30,575
backupmorremeyer4.0.01 of 1See more

backup morremeyer 4.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
restic/restic:0.15.2579e4e6a4931
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

2,303
genericmorremeyer8.0.01 of 1See more

generic morremeyer 8.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.25.167f9a4f10d14
nghttp2@1.52.0-1
nginx@1.25.1-1~bookworm
1.52.0-1+deb12u1
no fix listed

Open the chart page →

6,894
hcloud-ccm-networksmorremeyer2.0.01 of 1See more

hcloud-ccm-networks morremeyer 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

1,746
hcloud-csi-drivermorremeyer3.0.06 of 6See more

hcloud-csi-driver morremeyer 3.0.0

6 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
golang.org/x/net@v0.7.0
0.17.0
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
golang.org/x/net@v0.4.0
0.17.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
golang.org/x/net@v0.4.0
0.17.0
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
golang.org/x/net@v0.4.0
0.17.0
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
golang.org/x/net@v0.4.0
0.17.0
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

7,187
acmemosquitto-helm-chart0.2.01 of 2See more

acme mosquitto-helm-chart 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
neilpang/acme.sh:3.0.2595809ad43a2
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

2,051
chirpstackmosquitto-helm-chart0.5.03 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

3 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
nghttp2@1.40.0-1build1
http2-common@9.4.43.v20210629
http2-server@9.4.43.v20210629
1.40.0-1ubuntu0.2
9.4.53
9.4.53
chirpstack/chirpstack-application-server:3fb7667fe037f
golang.org/x/net@v0.0.0-20220726230323-06994584191e
0.17.0
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

26,081
chirpstack-event-forwardmosquitto-helm-chart0.1.21 of 1See more

chirpstack-event-forward mosquitto-helm-chart 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0

Open the chart page →

1,854
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
nghttp2@1.40.0-1build1
http2-common@9.4.44.v20210927
http2-server@9.4.44.v20210927
1.40.0-1ubuntu0.2
9.4.53
9.4.53

Open the chart page →

15,749
replacermosquitto-helm-chart0.2.02 of 3See more

replacer mosquitto-helm-chart 0.2.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

3,931
configmapsecretsmozilla0.0.11 of 1See more

configmapsecrets mozilla 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0

Open the chart page →

2,109
devops-demomungari-development-charts1.0.41 of 4See more

devops-demo mungari-development-charts 1.0.4

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
tomcat-embed-core@9.0.65
0.17.0
9.0.81

Open the chart page →

9,004
my-music-appmusic-serverVerified publisher0.1.11 of 1See more

my-music-app music-server 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
abdullahkhabir/radio:latest56526d0cc929
nghttp2@1.51.0-r1
1.51.0-r2

Open the chart page →

1,561
pagesmuthu-pages1.0.02 of 3See more

pages muthu-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
approuvezmvisonneau0.1.11 of 1See more

approuvez mvisonneau 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0

Open the chart page →

1,978
unpollermvisonneau0.1.01 of 1See more

unpoller mvisonneau 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
golift/unifi-poller:v2.9.2585a29a06d05
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

1,190
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

12,867
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

12,867
authmyaVerified publisher22.4.31 of 1See more

auth mya 22.4.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.17.0

Open the chart page →

2,381
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

9,418
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

9,353
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

3,368
my-helm-chartmy-helm-charts-2024Verified publisher0.1.01 of 1See more

my-helm-chart my-helm-charts-2024 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
shamimkuet/nginx:1.0.2b82902a76a04
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

5,411
Practica_4_helmmy-heml-appVerified publisher0.1.04 of 7See more

Practica_4_helm my-heml-app 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

27,861
mystoremystore-chart0.1.02 of 3See more

mystore mystore-chart 0.1.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hazegoodlife/haaze:veggiesite50f02d2d5d4d
nginx@1.27.4-1~bookworm
no fix listed
hazegoodlife/haaze:milksite8d4c63169e14
nginx@1.27.4-1~bookworm
no fix listed

Open the chart page →

9,590
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hecrom/myweatherangularclient:1.3.11bb0372939c19
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

18,114
fargate-sidecar-injectormziyaboVerified publisher0.1.51 of 1See more

fargate-sidecar-injector mziyabo 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mziyabo/fargate-eks-sidecar-injector:latest3067dce17983
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,393
pagesnarain1.0.02 of 3See more

pages narain 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
pagesnarasimha-pages1.0.02 of 3See more

pages narasimha-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

12,909
traefik-forward-auth-openidnas-helm-chartsVerified publisher1.0.11 of 1See more

traefik-forward-auth-openid nas-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:latestb364aa6a4117
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.17.0

Open the chart page →

2,197
nats-operatornatsVerified publisher0.8.31 of 1See more

nats-operator nats 0.8.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
natsio/nats-operator:0.8.31261dae38389
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

2,354
pagesnavin-brixton1.0.02 of 3See more

pages navin-brixton 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
betydbncsaVerified publisher0.6.11 of 4See more

betydb ncsa 0.6.1

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

9,546
pecanncsaVerified publisher0.6.22 of 15See more

pecan ncsa 0.6.2

2 of the 15 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
pecan/bety:5.4.1f825d480cd62
nghttp2@1.43.0-1
1.43.0-1+deb11u1
pecan/web:1.7.2814d678c5550
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

14,158
polyglotncsaVerified publisher0.1.11 of 18See more

polyglot ncsa 0.1.1

1 of the 18 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
craigwillis/c2metadata-bd:latestae317d7e4724
http2-common@9.4.32.v20200930
http2-server@9.4.32.v20200930
9.4.53
9.4.53

Open the chart page →

55,728
smilencsaVerified publisher1.1.014 of 23See more

smile ncsa 1.1.0

14 of the 23 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/classification_train:0.1.207477060bba8
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/clowder_list:0.1.051cb17626519
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
nghttp2@1.52.0-1
1.52.0-1+deb12u1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
nghttp2@1.52.0-1
1.52.0-1+deb12u1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
nghttp2@1.52.0-1
1.52.0-1+deb12u1
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
nghttp2@1.43.0-1
1.43.0-1+deb11u1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

110,325
swaggerncsaVerified publisher1.0.11 of 1See more

swagger ncsa 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
swaggerapi/swagger-ui:v4.15.511b20aebb92c
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,185
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

6,991
iamdnetsocVerified publisher0.6.11 of 2See more

iamd netsoc 0.6.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

2,891
shhdnetsocVerified publisher0.1.71 of 1See more

shhd netsoc 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0

Open the chart page →

3,987
webspacednetsocVerified publisher0.2.82 of 2See more

webspaced netsoc 0.2.8

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
0.17.0

Open the chart page →

5,193
nginx-samplenginx-sample0.5.01 of 1See more

nginx-sample nginx-sample 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

5,362
nginx-sample-dependentnginx-sample-dependent0.2.01 of 1See more

nginx-sample-dependent nginx-sample-dependent 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.27.098f8ec75657d
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

5,362
node-upgrade-channelnimbolus0.1.11 of 1See more

node-upgrade-channel nimbolus 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

2,063
doris-operatornineinfra-charts1.3.11 of 1See more

doris-operator nineinfra-charts 1.3.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
selectdb/doris.k8s-operator:1.3.1919210765cb8
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

870
kyuubi-operatornineinfra-charts0.7.01 of 1See more

kyuubi-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nineinfra/kyuubi-operator:v0.7.08d8ed87ef77c
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

815
metastore-operatornineinfra-charts0.7.01 of 1See more

metastore-operator nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nineinfra/metastore-operator:v0.7.011259032fb04
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

815
minio-directpvnineinfra-charts4.0.85 of 5See more

minio-directpv nineinfra-charts 4.0.8

5 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/minio/csi-node-driver-registrardigest-pinnedc805fdc16676
golang.org/x/net@v0.8.0
0.17.0
quay.io/minio/csi-provisionerdigest-pinned7b5c070ec70d
golang.org/x/net@v0.8.0
0.17.0
quay.io/minio/csi-resizerdigest-pinned819f68a4daf7
golang.org/x/net@v0.8.0
0.17.0
quay.io/minio/directpv:v4.0.84560083eb77d
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.8.0
0:1.33.0-5.el8_8
0.17.0
quay.io/minio/livenessprobedigest-pinnedf3bc9a84f149
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

7,070
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.13.0
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

3,425

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
tomcat-embed-core@10.1.10
10.1.14
1
zahoriaut/zahori-server:0.1.17b2de13916f3e
tomcat-embed-core@9.0.71
9.0.81
1
zbalogh/reservation-api-server:1.0.97c247e399a1f
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
zeetdev/tailscale-relay:v1.24.21967aa2840b6
golang.org/x/net@v0.0.0-20220407224826-aac1ed45d8e3
0.17.0
1
zufardhiyaulhaq/community-operator-v2:v1.0.07f1bbbe114eb
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
1
zufardhiyaulhaq/devopsweekly:v2.1.046625567fb60
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.17.0
1
zufardhiyaulhaq/goweekly:v2.0.008dcc130fbea
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.17.0
1
zufardhiyaulhaq/javascriptweekly:v2.1.086424bd0b2a4
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
zufardhiyaulhaq/kubernetesweekly:v2.1.0a287ada277c6
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
0.17.0
1
zufardhiyaulhaq/ngrok-operator:v1.3.07cf2ae3fb1fb
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
1
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
0.17.0
1
zzorica/k8s-mgmt-pod:0.5.2640ca4de2922
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
golang.org/x/net@v0.8.0
0.17.0
1
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0
1
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.17.0
1
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
gcr.io/gke-release/custom-metrics-stackdriver-adapter:v0.13.1-gke.06937c0a9b203
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
gcr.io/gloo-mesh/gloo-mesh:1.1.2a4011eae6a0b
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
gcr.io/google-samples/microservices-demo/cartservice:v0.2.3566733b4d2d5
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
1
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
1
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
1
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
0.17.0
1
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
1
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
golang.org/x/net@v0.0.0-20190628185345-da137c7871d7
0.17.0
1
gcr.io/google-samples/microservices-demo/recommendationservice:v0.2.35f60c4988859
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
1
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
1
gcr.io/istio-release/pilot:1.11.1c552478f8f11
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
1.40.0-1ubuntu0.2
0.17.0
1
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
1.40.0-1ubuntu0.2
0.17.0
1
gcr.io/k8s-staging-multitenancy/hnc-manager:v1.1.08ab8229f6a89
golang.org/x/net@v0.3.0
0.17.0
1
gcr.io/k8s-staging-sig-storage/objectstorage-controller:v20221027-v0.1.1-8-g300019fa84b574e8027
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.17.0
1
gcr.io/knative-releases/knative.dev/net-certmanager/cmd/webhook873b968f02b5
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
gcr.io/knative-releases/knative.dev/net-kourier/cmd/kourier197fbb71d1f1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
gcr.io/knative-releases/knative.dev/operator/cmd/webhook6c5c90cdf707
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator08315309da4b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator1e3db4f2eeed
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activatora5de0fb75046
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.10.2c2994c2b6c2c
golang.org/x/net@v0.7.0
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler105bdd14ecaa
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler2ef460356b17
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.10.28319aa662b49
golang.org/x/net@v0.7.0
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdb6ceff2aab4
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpa:v1.10.2eb612b929eaa
golang.org/x/net@v0.7.0
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller30ce73388ae5
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.