StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,797 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,797 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
supersetnineinfra-charts0.11.21 of 4See more

superset nineinfra-charts 0.11.2

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,439
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.17.0

Open the chart page →

6,586
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.17.0

Open the chart page →

4,756
servernodejs0.0.21 of 1See more

server nodejs 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
maissacrement/pock8snodejs:0.0.16da0db1159da
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,904
nodejsweeklynodejsweekly1.1.01 of 1See more

nodejsweekly nodejsweekly 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
0.17.0

Open the chart page →

1,489
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
0.17.0
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
0.17.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
0.17.0
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
0.17.0
quay.io/prometheus/pushgateway:v1.6.05111de00e969
golang.org/x/net@v0.10.0
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

7,748
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

22,795
liquidsoapnorth141.0.01 of 1See more

liquidsoap north14 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,955
config-server-helm-chartnotesprojectchart0.1.01 of 1See more

config-server-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/config-server-another:lateste7f20450d2ae
tomcat-embed-core@9.0.65
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

3,425
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
tomcat-embed-core@9.0.64
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

5,919
ingress-helm-chartnotesprojectchart0.1.02 of 2See more

ingress-helm-chart notesprojectchart 0.1.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

2,956
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

4,558
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
tomcat-embed-core@9.0.64
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

6,896
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

15,210
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

15,282
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

15,266
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
tomcat-embed-core@9.0.64
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

5,960
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
tomcat-embed-core@9.0.64
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

5,917
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

2,254
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,537
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0

Open the chart page →

4,861
nfs-server-provisionernovum-rgi-charts1.1.21 of 1See more

nfs-server-provisioner novum-rgi-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.17.0

Open the chart page →

2,806
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
1.30.0-1ubuntu1+esm2
0.17.0
linuxserver/codimd:latestb801bbcf6386
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

27,548
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

27,757
cnaos-pvc-populatornutanix-helm-releasesVerified publisher1.1.0-174-prod1 of 2See more

cnaos-pvc-populator nutanix-helm-releases 1.1.0-174-prod

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

1,838
nutanix-flow-cninutanix-helm-releasesVerified publisher1.1.01 of 7See more

nutanix-flow-cni nutanix-helm-releases 1.1.0

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

4,997
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

17,161
cluster-gateway-addon-managerocm-helm-chartsVerified publisher1.4.01 of 1See more

cluster-gateway-addon-manager ocm-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

1,607
multicluster-meshocm-helm-chartsVerified publisher0.0.21 of 1See more

multicluster-mesh ocm-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

2,131
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

5,826
db-backupoleds-helm-chartsVerified publisher0.1.01 of 1See more

db-backup oleds-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
oled01/db-backup:0.1.06302fd2b5333
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

8,140
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

8,548
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
nghttp2@1.43.0-1build3
http2-common@9.4.51.v20230217
http2-server@9.4.51.v20230217
1.43.0-1ubuntu0.1
9.4.53
9.4.53

Open the chart page →

9,083
exposecontrollerolli-aiVerified publisher1.0.51 of 1See more

exposecontroller olli-ai 1.0.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
olliai/exposecontroller:1.0.5a470d96525e4
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,861
k8s-replicatorolli-aiVerified publisher1.3.01 of 1See more

k8s-replicator olli-ai 1.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
olliai/k8s-replicator:1.3.05716f2a8bd4c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,825
apicurioone-acre-fundVerified publisher2.3.04 of 5See more

apicurio one-acre-fund 2.3.0

4 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

18,668
one-green-coreone-green-coreVerified publisher0.0.73 of 8See more

one-green-core one-green-core 0.0.7

3 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:8.5.3ecc1b80b8ca2
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
0.17.0
library/influxdb:2.0.8ba10ac9ba17a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
library/telegraf:1.20.428e98eece020
golang.org/x/net@v0.0.0-20211005215030-d2e5035098b3
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

9,582
opa-nginxopa-nginx0.0.31 of 2See more

opa-nginx opa-nginx 0.0.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openpolicyagent/opa:0.53.16a58dea59933
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

2,176
commonground-gatewayopencatalogi1.5.32 of 7See more

commonground-gateway opencatalogi 1.5.3

2 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
nghttp2@1.47.0-r0
1.47.0-r2
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
nghttp2@1.52.0-1
nginx@1.25.1-1~bookworm
1.52.0-1+deb12u1
no fix listed

Open the chart page →

9,766
opentickopenchartVerified publisher0.1.01 of 1See more

opentick openchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.25.5a484819eb602
nginx@1.25.5-1~bookworm
no fix listed

Open the chart page →

5,716
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0:1.33.0-4.el8_4.1
0.17.0

Open the chart page →

18,032
bbsimopencord4.8.111 of 1See more

bbsim opencord 4.8.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
voltha/bbsim:1.16.7d90403d58016
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0

Open the chart page →

3,915
bbsim-sadis-serveropencord0.3.51 of 1See more

bbsim-sadis-server opencord 0.3.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
voltha/bbsim-sadis-server:0.4.0762b272d439e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

3,729
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
nghttp2@1.30.0-1ubuntu1
tomcat-coyote@8.5.38
tomcat-embed-core@8.5.38
1.30.0-1ubuntu1+esm2
8.5.94
8.5.94

Open the chart page →

63,509
freeradiusopencord1.0.41 of 1See more

freeradius opencord 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

15,738
nem-monitoringopencord1.3.221 of 9See more

nem-monitoring opencord 1.3.22

1 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.17.0

Open the chart page →

4,619
omec-control-planeopencord0.1.311 of 8See more

omec-control-plane opencord 0.1.31

1 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
omecproject/c3po-hssdb:master-latest28a90cc26716
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

40,941
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

12,953
ves-agentopencord1.0.21 of 1See more

ves-agent opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
opencord/ves-agent:1.0.04187e2a8c918
tomcat-embed-core@8.5.31
8.5.94

Open the chart page →

6,353
volthaopencord2.14.02 of 2See more

voltha opencord 2.14.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
voltha/voltha-rw-core:3.4.87a325316fe59
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

3,825

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/review-component-php:latestafe623824b82
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/skeleton-pip:devce1ebe9387a2
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/user-component-nginx:latestb721579df8c3
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
1.46.0-r2
0.17.0
1
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/waardepapieren-nginx:latestaf31cf6cd59f
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
1.46.0-r2
0.17.0
1
ghcr.io/cosmo-workspace/cosmo-controller-manager:v0.9.08c7fa5552028
golang.org/x/net@v0.10.0
0.17.0
1
ghcr.io/cosmo-workspace/cosmo-dashboard:v0.9.16a1c4a81a924
golang.org/x/net@v0.10.0
0.17.0
1
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.16.0-2.module+el8.3.0+10180+b92e1eb6
nodejs-packaging@23-3.module+el8.3.0+6519+9f98ed83
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:26-1.module+el8.8.0+19857+6d2a104d
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.16.0-2.module+el8.3.0+10180+b92e1eb6
nodejs-packaging@23-3.module+el8.3.0+6519+9f98ed83
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:26-1.module+el8.8.0+19857+6d2a104d
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.16.0-2.module+el8.3.0+10180+b92e1eb6
nodejs-packaging@23-3.module+el8.3.0+6519+9f98ed83
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:26-1.module+el8.8.0+19857+6d2a104d
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.16.0-2.module+el8.3.0+10180+b92e1eb6
nodejs-packaging@23-3.module+el8.3.0+6519+9f98ed83
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:26-1.module+el8.8.0+19857+6d2a104d
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.16.0-2.module+el8.3.0+10180+b92e1eb6
nodejs-packaging@23-3.module+el8.3.0+6519+9f98ed83
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:26-1.module+el8.8.0+19857+6d2a104d
1
ghcr.io/cubeengine/sponge:1.20.2-11.0.0-RC13755c85f2b82064
nghttp2@1.55.1-r0
1.57.0-r0
1
ghcr.io/cubefs/cfs-csi-driver:3.2.0.150.08723616a976a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
tomcat-embed-core@10.1.8
10.1.14
1
ghcr.io/daocloud/dao-2048:v1.4.121275bc02f75
nghttp2@1.51.0-r0
1.51.0-r2
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/data-fair/metrics:0a8d40779eeae
nghttp2@1.53.0-r0
1.57.0-r0
1
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
1
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.17.0
1
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.17.0
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/net@v0.11.0
0.17.0
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/net@v0.0.0-20210908191846-a5e095526f91
0.17.0
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/net@v0.10.0
0.17.0
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
1.47.0-r2
0.17.0
1
ghcr.io/dodevops/scalyr-k8snode-manager:latestfc39fcdd3968
nghttp2@1.46.0-r0
1.46.0-r2
1
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
1
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
0.17.0
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.