StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,792 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,792 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
csi-driver-nfskeyporttech0.1.41 of 2See more

csi-driver-nfs keyporttech 0.1.4

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
golang.org/x/net@v0.0.0-20190415100556-4a65cf94b679
0.17.0

Open the chart page →

3,364
gogskeyporttech0.1.31 of 3See more

gogs keyporttech 0.1.3

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gogs/gogs:0.12.30195b095d0b2
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
0.17.0

Open the chart page →

3,524
helm-mongodb-operatorkeyporttech0.1.01 of 1See more

helm-mongodb-operator keyporttech 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0

Open the chart page →

8,829
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.21.08a4d7e9308de
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

12,559
connectkfirfer1.15.02 of 2See more

connect kfirfer 1.15.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
1password/connect-api:1.7.26aa94cf713f9
golang.org/x/net@v0.14.0
0.17.0
1password/connect-sync:1.7.2fe527ed9d81f
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

2,787
dex-k8s-authenticatorkfirfer0.0.31 of 1See more

dex-k8s-authenticator kfirfer 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/net@v0.0.0-20190522155817-f3200d17e092
0.17.0

Open the chart page →

2,792
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
nghttp2@1.55.1-r0
1.57.0-r0

Open the chart page →

6,458
keelkfirfer1.0.51 of 1See more

keel kfirfer 1.0.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
keelhq/keel:0.19.202ac4ea616c4
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

2,083
kingkfirfer0.1.01 of 1See more

king kfirfer 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kfirfer/king:latestc05d9fc7ae77
nghttp2@1.51.0-r1
1.51.0-r2

Open the chart page →

1,173
kubernetes-replicatorkfirfer2.9.11 of 1See more

kubernetes-replicator kfirfer 2.9.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/mittwald/kubernetes-replicator:v2.9.1baf5f784398b
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

864
phppgadminkfirfer0.1.121 of 1See more

phppgadmin kfirfer 0.1.12

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

10,319
scriptskfirfer0.1.361 of 1See more

scripts kfirfer 0.1.36

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kfirfer/scripts:0.0.2481e5c4e5d70e
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

2,320
kiaekiae0.1.66 of 9See more

kiae kiae 0.1.6

6 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
grafana/promtail:2.6.1072527b12cdf
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
istio/pilot:1.15.2db08d6963975
nghttp2@1.43.0-1build3
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
1.43.0-1ubuntu0.1
0.17.0
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
golang.org/x/net@v0.1.0
0.17.0
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.17.0
ghcr.io/kiaedev/kiae:latestebd03028ff6a
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

19,267
kloudlite-platformkloudlite1.1.51 of 3See more

kloudlite-platform kloudlite 1.1.5

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

1,971
cadvisorkrakazyabraVerified publisher1.0.11 of 1See more

cadvisor krakazyabra 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0

Open the chart page →

3,185
kubeflowkromanow94-kubeflow0.5.14 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

4 of the 30 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubeflownotebookswg/notebook-controller:v1.9.20f14bd28fdd5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
kubeflownotebookswg/poddefaults-webhook:v1.9.2bde88d98ad74
golang.org/x/net@v0.13.0
0.17.0
kubeflownotebookswg/profile-controller:v1.9.2f05a5538ae7e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
library/python:3.7eedf63967cdb
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

71,075
kron-aapm-agentkron-aapm-agent1.1.01 of 1See more

kron-aapm-agent kron-aapm-agent 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
krontechnology/aapm-agent:1.1.07feef7d2ab42
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.39
1.40.0-1ubuntu0.2
9.0.81

Open the chart page →

8,937
kron-aapm-sidecarkron-aapm-sidecar1.1.01 of 1See more

kron-aapm-sidecar kron-aapm-sidecar 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
krontechnology/aapm-sidecar-injector:1.1.0e078d54c1711
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
1.46.0-r2
0.17.0

Open the chart page →

2,111
astralkronkltdVerified publisher0.1.01 of 1See more

astral kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
duck1123/astral:latestf4d5b6526c2a
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

891
fileserverkronkltdVerified publisher0.3.101 of 1See more

fileserver kronkltd 0.3.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
duck1123/lnd-fileserver:latest9d6fb247b714
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

3,778
lndkronkltdVerified publisher0.3.93 of 4See more

lnd kronkltd 0.3.9

3 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
0.17.0
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
0.17.0
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
0.17.0

Open the chart page →

8,472
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
duck1123/cert-downloader:latest0e29f19fa67c
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

5,655
casdoorkrzwiatrzyk1.0.01 of 1See more

casdoor krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
casbin/casdoor:v1.224.066f836ef778b
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
1.51.0-r2
0.17.0

Open the chart page →

3,649
nocodbkrzwiatrzyk0.0.11 of 1See more

nocodb krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nocodb/nocodb:0.100.2b0b91ec2a2dd
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20220805013720-a33c5aa5df48
1.46.0-r2
0.17.0

Open the chart page →

2,320
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
nginx@1.20.2-r0
1.20.2-r2

Open the chart page →

4,240
pipecdkrzwiatrzyk0.39.01 of 3See more

pipecd krzwiatrzyk 0.39.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
0.17.0

Open the chart page →

3,819
bc-depositorykubebb0.0.31 of 1See more

bc-depository kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,947
bc-explorerkubebb0.0.31 of 1See more

bc-explorer kubebb 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,947
chartmuseumkubebb3.10.21 of 1See more

chartmuseum kubebb 3.10.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

2,276
cluster-componentkubebb0.2.24 of 4See more

cluster-component kubebb 0.2.2

4 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubebb/cert-manager-cainjector:v1.8.0f83cd256229b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
kubebb/cert-manager-controller:v1.8.020509de4b399
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
kubebb/cert-manager-webhook:v1.8.060d3cba0c267
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
1.47.0-r2
0.17.0

Open the chart page →

8,174
fabric-operatorkubebb0.1.01 of 1See more

fabric-operator kubebb 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

3,995
hello-worldkubebb0.1.11 of 1See more

hello-world kubebb 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubebb/hello-world:0.1.0b746824819f3
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,225
ingress-nginxkubebb4.7.02 of 2See more

ingress-nginx kubebb 4.7.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

3,099
kubebb-corekubebb0.1.271 of 1See more

kubebb-core kubebb 0.1.27

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubebb/core:v0.1.62b9e7f451d6b
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

1,947
miniokubebb5.0.102 of 2See more

minio kubebb 5.0.10

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.4.0
0:1.33.0-5.el8_8
0.17.0
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

7,472
tampkubebb5.6.01 of 2See more

tamp kubebb 5.6.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubebb/gateway-api:v5.6.04d062f20309c
tomcat-embed-core@9.0.65
9.0.81

Open the chart page →

4,680
tapm-componentkubebb5.7.12 of 3See more

tapm-component kubebb 5.7.1

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
refar/apm-api:v5.7.1241373fa2972
tomcat-embed-core@9.0.37
9.0.81
refar/apm-operator-server:v5.7.1e5490f050f9f
tomcat-embed-core@9.0.37
9.0.81

Open the chart page →

10,284
tdsfkubebb5.7.02 of 3See more

tdsf kubebb 5.7.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubebb/mesh-api:v5.7.0a3879931dfa1
tomcat-embed-core@10.1.12
10.1.14
kubebb/mesh-operator:v5.7.0163ebbfc7a82
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

6,515
tekton-operatorkubebb0.64.02 of 2See more

tekton-operator kubebb 0.64.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0

Open the chart page →

2,432
u4a-componentkubebb0.2.106 of 8See more

u4a-component kubebb 0.2.10

6 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubebb/capsule-ce:v0.1.2-20221122a3dba2a95cef
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
kubebb/iam-controller:v0.2.0-202401288ffbfa2d67e9
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0
kubebb/iam-provider:v0.2.0-202401280ba03fcee3a7
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0
kubebb/kube-oidc-proxy-ce:v0.3.0-2022100858d5efec568b
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
kubebb/oidc-server:v0.2.02b5894ef1e2f
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.17.0
kubebb/resource-viewer:v0.2.065bb40b353db
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

13,835
weaviatekubebb16.3.01 of 1See more

weaviate kubebb 16.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
semitechnologies/weaviate:1.19.17a00d226f063
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,876
chaos-meshkubeblocksVerified publisher2.7.21 of 4See more

chaos-mesh kubeblocks 2.7.2

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/chaos-mesh/chaos-coredns:v0.2.678dc63bc5b89
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

13,601
dt-platformkubeblocksVerified publisher0.1.21 of 1See more

dt-platform kubeblocks 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apecloud/dt-platform:0.1.1d48bcbd38066
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

880
grafanakubeblocksVerified publisher6.59.41 of 1See more

grafana kubeblocks 6.59.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:10.1.11b9ca4bbc4a2
nghttp2@1.55.1-r0
golang.org/x/net@v0.12.0
1.57.0-r0
0.17.0

Open the chart page →

3,568
jupyterhubkubeblocksVerified publisher0.1.03 of 7See more

jupyterhub kubeblocks 0.1.0

3 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:4.5.67adeeed34a36
nghttp2@1.55.1-r0
1.57.0-r0
jupyterhub/k8s-hub:3.0.1-0.dev.git.6287.hbfb05cd65a0ceed1300a
nghttp2@1.43.0-1
1.43.0-1+deb11u1
jupyterhub/k8s-singleuser-sample:3.0.1-0.dev.git.6287.hbfb05cd68e4778efec8e
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

7,386
kubeblocks-csi-driverkubeblocksVerified publisher0.1.31 of 6See more

kubeblocks-csi-driver kubeblocks 0.1.3

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

2,090
kubetrankubeblocksVerified publisher0.1.01 of 1See more

kubetran kubeblocks 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apecloud/kubetran-platform:latest32bd92c7f7fa
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

1,207
lokikubeblocksVerified publisher5.39.02 of 5See more

loki kubeblocks 5.39.0

2 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.34.1045c9125634c
golang.org/x/net@v0.10.0
0.17.0
nginxinc/nginx-unprivileged:1.24-alpinebe76a26e238d
nginx@1.24.0-r1
1.24.0-r7

Open the chart page →

5,862
nvidia-gpu-exporterkubeblocksVerified publisher0.3.11 of 1See more

nvidia-gpu-exporter kubeblocks 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

4,511
openebskubeblocksVerified publisher3.10.02 of 3See more

openebs kubeblocks 3.10.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

10,602

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
nghttp2@1.43.0-5.el9
nginx@1:1.20.1-13.el9
0:1.43.0-5.el9_2.1
1:1.22.1-5.module+el9.3.0.z+20438+032561a0
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
nghttp2@1.43.0-5.el9
0:1.43.0-5.el9_2.1
1
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
1.30.0-1ubuntu1+esm2
0.17.0
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
0.17.0
1
ghcr.io/eugenmayer/nist-data-mirror:0.1.1a2162df94729
nghttp2@1.51.0-r0
1.51.0-r2
1
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0.17.0
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/net@v0.10.0
0.17.0
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
1.40.0-1ubuntu0.2
0.17.0
1
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
golang.org/x/net@v0.8.0
0.17.0
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
http2-common@9.4.34.v20201102
nghttp2@1.43.0-1
9.4.53
1.43.0-1+deb11u1
1
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.0.0-20181017193950-04a2e542c03f
0.17.0
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.17.0
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/net@v0.4.0
0.17.0
1
ghcr.io/g0dscookie/icinga2:2.13.5da81246ccfc9
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
golang.org/x/net@v0.15.0
0.17.0
1
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
1
ghcr.io/grafana/tempo-operator/tempo-operator:v0.4.02627be646391
golang.org/x/net@v0.12.0
0.17.0
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/net@v0.10.0
0.17.0
1
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/net@v0.0.0-20220121210141-e204ce36a2ba
0.17.0
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
0.17.0
1
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.17.0
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nginx@1.29.1-1~bookworm
no fix listed
1
ghcr.io/jaconi-io/koptimize:1.2.5aca1bbd609b6
golang.org/x/net@v0.10.0
0.17.0
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-3.el8_2.2
1
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
ghcr.io/jlclx/runtimeclass-controller:latestb3a87f92a963
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
ghcr.io/jmcgrath207/par:v0.1.09977511cb142
golang.org/x/net@v0.10.0
0.17.0
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/k10app/businit:latest94c9a3e799c2
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.51.0-r2
0.17.0
1
ghcr.io/k10app/frontend:latest066b5ac6b119
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.