StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,792 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,792 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
jackettgeek-cookbookVerified publisher11.7.21 of 1See more

jackett geek-cookbook 11.7.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/jackett:v0.20.13163a4715b46aa2
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

9,749
jellyfingeek-cookbookVerified publisher9.5.31 of 1See more

jellyfin geek-cookbook 9.5.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.8.1ee24f4459a40
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,380
komgageek-cookbookVerified publisher2.4.21 of 1See more

komga geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gotson/komga:0.99.49b15ea6bfc30
nghttp2@1.30.0-1ubuntu1
tomcat-embed-core@9.0.46
1.30.0-1ubuntu1+esm2
9.0.81

Open the chart page →

12,602
lidarrgeek-cookbookVerified publisher14.2.21 of 1See more

lidarr geek-cookbook 14.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

14,320
maddygeek-cookbookVerified publisher3.2.01 of 1See more

maddy geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
foxcpp/maddy:v0.5.28fa2bd8f6830
golang.org/x/net@v0.0.0-20211011170408-caeb26a5c8c0
0.17.0

Open the chart page →

2,630
minifluxgeek-cookbookVerified publisher5.2.01 of 2See more

miniflux geek-cookbook 5.2.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
miniflux/miniflux:2.0.36e2fb990dae74
golang.org/x/net@v0.0.0-20210916014120-12bc252f5db8
0.17.0

Open the chart page →

2,430
navidromegeek-cookbookVerified publisher6.4.21 of 1See more

navidrome geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
deluan/navidrome:0.43.04e9ae3bff6aa
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

3,597
nzbgetgeek-cookbookVerified publisher12.4.21 of 1See more

nzbget geek-cookbook 12.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbget:v21.1e5571acd10ce
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

12,150
nzbhydra2geek-cookbookVerified publisher10.4.21 of 1See more

nzbhydra2 geek-cookbook 10.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81

Open the chart page →

17,776
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

8,395
openhabgeek-cookbookVerified publisher1.5.21 of 1See more

openhab geek-cookbook 1.5.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openhab/openhab:3.2.0d0aa4af452c1
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,889
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
nghttp2@1.40.0-1build1
tomcat-coyote@8.5.69
1.40.0-1ubuntu0.2
8.5.94

Open the chart page →

28,054
owncloud-ocisgeek-cookbookVerified publisher2.4.21 of 1See more

owncloud-ocis geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
owncloud/ocis:1.7.0d2efcae92c84
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

3,243
photoprismgeek-cookbookVerified publisher7.2.01 of 1See more

photoprism geek-cookbook 7.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
photoprism/photoprism:220629-jammy2954334adbda
nghttp2@1.43.0-1build3
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

19,581
pod-gatewaygeek-cookbookVerified publisher5.6.21 of 2See more

pod-gateway geek-cookbook 5.6.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v3.5.0175512bb3f61
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

2,355
pod-gateway-settergeek-cookbookVerified publisher1.0.01 of 1See more

pod-gateway-setter geek-cookbook 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/gateway-admision-controller:v2.0.00d6d0df98fe4
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

1,641
privatebingeek-cookbookVerified publisher2.2.01 of 1See more

privatebin geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
privatebin/pdo:1.3.500466418121c
nginx@1.20.2-r0
1.20.2-r2

Open the chart page →

1,159
puppeteergeek-cookbookVerified publisher1.2.21 of 1See more

puppeteer geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

15,802
qbittorrentgeek-cookbookVerified publisher13.5.21 of 1See more

qbittorrent geek-cookbook 13.5.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/qbittorrent:v4.4.261deadd1ec78
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

11,873
radarrgeek-cookbookVerified publisher16.3.21 of 1See more

radarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/radarr:v4.1.0.61754273dfaf0295
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

10,431
readarrgeek-cookbookVerified publisher6.4.21 of 1See more

readarr geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

7,818
resilio-syncgeek-cookbookVerified publisher5.4.21 of 1See more

resilio-sync geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

5,911
rtorrent-rutorrentgeek-cookbookVerified publisher1.1.21 of 1See more

rtorrent-rutorrent geek-cookbook 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
nghttp2@1.51.0-r0
nginx@1.22.1-r0
1.51.0-r2
1.22.1-r1

Open the chart page →

4,233
rtsp-to-webgeek-cookbookVerified publisher2.2.21 of 1See more

rtsp-to-web geek-cookbook 2.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.17.0

Open the chart page →

1,467
seafilegeek-cookbookVerified publisher3.2.01 of 1See more

seafile geek-cookbook 3.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

24,374
searxgeek-cookbookVerified publisher5.6.22 of 4See more

searx geek-cookbook 5.6.2

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dalf/morty:latest248a4849c350
golang.org/x/net@v0.0.0-20220421235706-1d1ef9303861
0.17.0
library/caddy:2.2.0-alpine7367adca165f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

7,477
strongswangeek-cookbookVerified publisher0.3.21 of 1See more

strongswan geek-cookbook 0.3.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/reitermarkus/strongswan:v1.0.0e7a8afe6e6eb
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

1,605
teedygeek-cookbookVerified publisher6.2.01 of 1See more

teedy geek-cookbook 6.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
sismics/docs:v1.10f4b0ef019cf1
nghttp2@1.30.0-1ubuntu1
http2-common@9.4.36.v20210114
http2-server@9.4.36.v20210114
1.30.0-1ubuntu1+esm2
9.4.53
9.4.53

Open the chart page →

27,026
theme-parkgeek-cookbookVerified publisher1.2.21 of 1See more

theme-park geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/theme-park:v1.7.3f8a5ec8f4669
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,287
torrservergeek-cookbookVerified publisher1.2.21 of 1See more

torrserver geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
smailkoz/torrserver:1.0.1117b52d15de8f0
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.17.0

Open the chart page →

3,165
transmissiongeek-cookbookVerified publisher8.4.31 of 1See more

transmission geek-cookbook 8.4.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

11,927
vikunjageek-cookbookVerified publisher6.2.02 of 4See more

vikunja geek-cookbook 6.2.0

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/caddy:2.4.2-alpinefbc51bcf1ab0
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
vikunja/api:0.17.18cba0520bf8c
golang.org/x/net@v0.0.0-20210505024714-0287a6fb4125
0.17.0

Open the chart page →

6,893
webhook-receivergeek-cookbookVerified publisher0.0.11 of 1See more

webhook-receiver geek-cookbook 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

1,369
webtreesgeek-cookbookVerified publisher2.2.01 of 1See more

webtrees geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

3,646
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

17,985
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

4,558
rocketmqgengxiankun-charts0.3.01 of 1See more

rocketmq gengxiankun-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/rocketmq:5.3.0434d8398f996
tomcat-embed-core@8.5.46
8.5.94

Open the chart page →

4,978
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
geonetwork/gn-cloud-ogc-api-records-service:4.2.8-020c9bb761f67
golang.org/x/net@v0.11.0
tomcat-embed-core@9.0.41
0.17.0
9.0.81

Open the chart page →

34,936
istiogetindataVerified publisher1.11.12 of 2See more

istio getindata 1.11.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:1.11.1c552478f8f11
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
1.40.0-1ubuntu0.2
0.17.0
gcr.io/istio-release/proxyv2:1.11.19538fabe49fd
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
1.40.0-1ubuntu0.2
0.17.0

Open the chart page →

16,870
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
litestream/litestream:0.3c5a1e1b01916
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

9,097
emqxgin4.4.41 of 1See more

emqx gin 4.4.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
emqx/emqx:4.4.41d36535ba9de
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

1,430
gitanagitana1.4.01 of 1See more

gitana gitana 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ntakashi/gitana:1.4.04171ec641120
golang.org/x/net@v0.0.0-20210929161516-d455829e376d
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

3,478
gitlab-goproxygitlab-goproxy0.2.21 of 1See more

gitlab-goproxy gitlab-goproxy 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,332
apid-helpergkarthiks0.1.41 of 1See more

apid-helper gkarthiks 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

2,616
prometheus-container-resource-exportergkarthiks0.3.11 of 1See more

prometheus-container-resource-exporter gkarthiks 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gkarthics/container-resource-exporter:latest6799af333e8a
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,218
sunflare-toolsglenndehaanVerified publisher1.1.01 of 1See more

sunflare-tools glenndehaan 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
glenndehaan/sunflare-tools:latesta5b3f1dd865d
nghttp2@1.55.1-r0
1.57.0-r0

Open the chart page →

1,502
go-app-helmgo-app-helm0.1.01 of 1See more

go-app-helm go-app-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
manojchaulagain/go-k8s:0.1.0f237b5f637ae
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,594
gorsegorse-io0.4.23 of 4See more

gorse gorse-io 0.4.2

3 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
0.17.0
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
0.17.0
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

4,401
gotwaygotwayVerified publisher0.8.01 of 1See more

gotway gotway 0.8.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

1,826
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0

Open the chart page →

22,665

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
golang.org/x/net@v0.7.0
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controllerb2cd45b8a8a4
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controllerbac158dfb0c7
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/default-domain5e0429b70299
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mappinge384a295069b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.10.2f66c41ad7a73
golang.org/x/net@v0.7.0
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook15f1ce7f35b4
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.10.27368aaddf2be
golang.org/x/net@v0.7.0
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook1282a399cbb9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.10.24305209ce498
golang.org/x/net@v0.7.0
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookd27b4495ccc3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookf16c0e022203
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0
1
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0
1
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
gcr.io/ml-pipeline/viewer-crd-controller:2.0.0-alpha.534403f9f94be
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/net@v0.10.0
0.17.0
1
gcr.io/projectsigstore/cosigned784518ff3ee7
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
1
gcr.io/projectsigstore/policy-webhook82940e8c3e0d
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
tomcat-embed-core@9.0.30
9.0.81
1
ghcr.io/0xemma/reddark:main2a115e991894
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/abstract-foundation/zksync-external-node-sidecar:v1.0.03e705d0eb1ce
golang.org/x/net@v0.7.0
0.17.0
1
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
ghcr.io/alexellis/registry-creds:0.3.2-rc1f5c72501e559
golang.org/x/net@v0.5.0
0.17.0
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
ghcr.io/andylibrian/terjang:latest20a46b199247
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.17.0
1
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
0.17.0
1
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
golang.org/x/net@v0.14.0
0.17.0
1
ghcr.io/appscode/grafana:v2025.2.367d18880448c
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
1
ghcr.io/appuio/cloud-portal:v0.2.18c7e08d32d70
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
nghttp2@1.33.0-3.el8_3.1
0:1.33.0-5.el8_8
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
golang.org/x/net@v0.14.0
0.17.0
1
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
1.47.0-r2
0.17.0
1
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
golang.org/x/net@v0.8.0
0.17.0
1
ghcr.io/banzaicloud/kafka-operator:v0.20.2e341aefa9a90
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
0.17.0
1
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.17.0
1
ghcr.io/banzaicloud/logging-operator:3.17.623c2d4d54a64
golang.org/x/net@v0.0.0-20220114011407-0dd24b26b47d
0.17.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.