StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,107
of 17,790 indexed, latest versions
Container images
2,471
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,107 of 17,790 indexed charts deploy, on 2,471 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,572
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,107 by stars
ChartLatestAffected imagesRadar Score
pagesalstom-pages-app1.0.02 of 3See more

pages alstom-pages-app 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
amorphieamorphie0.1.27 of 18See more

amorphie amorphie 0.1.2

7 of the 18 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
daprio/dashboard:0.14.07ba5d51e5b97
golang.org/x/net@v0.6.0
0.17.0
daprio/injector:1.11.2763b9b70b0c8
golang.org/x/net@v0.12.0
0.17.0
daprio/operator:1.11.2c584428aa12d
golang.org/x/net@v0.12.0
0.17.0
daprio/placement:1.11.2d8e1446da996
golang.org/x/net@v0.12.0
0.17.0
daprio/sentry:1.11.21f507c1a181b
golang.org/x/net@v0.12.0
0.17.0
hazelcast/hazelcast:5.3.18fe26efde8e1
nghttp2@1.55.1-r0
1.57.0-r0
hazelcast/management-center:5.3.2f9d34300d330
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

28,289
kaianchore-charts0.5.11 of 1See more

kai anchore-charts 0.5.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
anchore/kai:v0.5.08aad6d0912dd
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,326
pagesandrei-pages1.0.02 of 3See more

pages andrei-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
terjangandylibrianVerified publisher0.0.31 of 1See more

terjang andylibrian 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/andylibrian/terjang:latest20a46b199247
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.17.0

Open the chart page →

1,985
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

42,325
cert-manager-webhook-safednsansgroupVerified publisher1.3.01 of 1See more

cert-manager-webhook-safedns ansgroup 1.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,495
ddosifyanteonVerified publisher1.7.54 of 13See more

ddosify anteon 1.7.5

4 of the 13 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
chrislusf/seaweedfs:3.56ed80f00fde46
golang.org/x/net@v0.14.0
0.17.0
ddosify/selfhosted_hammer:1.4.2a97a1b8a66af
golang.org/x/net@v0.8.0
0.17.0
library/influxdb:2.6.1-alpine44a366dd7724
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
1.51.0-r2
0.17.0
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

25,816
antmediaantmediaVerified publisher3.1.02 of 4See more

antmedia antmedia 3.1.0

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
nghttp2@1.47.0-r0
golang.org/x/net@v0.1.0
1.47.0-r2
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

4,621
ingress-nginxantmediaVerified publisher4.4.02 of 2See more

ingress-nginx antmedia 4.4.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
nghttp2@1.47.0-r0
golang.org/x/net@v0.1.0
1.47.0-r2
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

3,323
nfs-server-provisioneranvibo1.3.01 of 1See more

nfs-server-provisioner anvibo 1.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.17.0

Open the chart page →

2,731
apache-iotdbapache-iotdb-single-nodeVerified publisher0.1.01 of 1See more

apache-iotdb apache-iotdb-single-node 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/iotdb:0.11.28647309f95d1
tomcat-embed-core@8.5.32
8.5.94

Open the chart page →

5,280
d.vazquezm.2021_helmapphelmVerified publisher1.0.02 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

2 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
davidvmar/urjc-davidvmar-worker:1.0.10d221e834a21
nghttp2@1.43.0-1
1.43.0-1+deb11u1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

19,788
test-chartapplication-chart0.2.01 of 1See more

test-chart application-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ahmedinfraplus/simple-app:STAGINGc50e6e81a637
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,197
app-mobilityappmo0.1.03 of 5See more

app-mobility appmo 0.1.0

3 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellemc/csm-application-mobility-controller:v0.1.0148ada9060a9
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220822230855-b0a4917ee28c
0:1.33.0-4.el8_6.1
0.17.0
dellemc/csm-application-mobility-velero-plugin:v0.1.0660cabd6d929
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0:1.33.0-4.el8_6.1
0.17.0
velero/velero:v1.8.18d784580931c
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

12,541
auditorappscodeVerified publisher2023.10.11 of 1See more

auditor appscode 2023.10.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
0.17.0

Open the chart page →

1,680
capi-ops-managerappscodeVerified publisher2024.8.141 of 2See more

capi-ops-manager appscode 2024.8.14

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

3,430
docker-machine-operatorappscodeVerified publisher2024.7.91 of 1See more

docker-machine-operator appscode 2024.7.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

2,227
grafanaappscodeVerified publisher2026.9.111 of 1See more

grafana appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/grafana:v2025.2.367d18880448c
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0

Open the chart page →

2,340
kube-auth-managerappscodeVerified publisher2023.11.141 of 1See more

kube-auth-manager appscode 2023.11.14

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,946
kube-auth-proxyappscodeVerified publisher2023.11.141 of 1See more

kube-auth-proxy appscode 2023.11.14

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-auth-manager:v0.0.1789692ab9193
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,946
kubedb-communityappscodeVerified publisher0.24.21 of 2See more

kubedb-community appscode 0.24.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubedb/operator:v0.24.01a06ff0bda52
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

2,557
kubedb-enterpriseappscodeVerified publisher0.11.21 of 2See more

kubedb-enterprise appscode 0.11.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubedb/kubedb-enterprise:v0.11.05829bcedcb0d
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

2,581
kubedb-oneappscodeVerified publisher2023.12.283 of 10See more

kubedb-one appscode 2023.12.28

3 of the 10 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
ghcr.io/stashed/stash-crd-installer:v0.32.0c6f2a844b5dd
golang.org/x/net@v0.15.0
0.17.0
ghcr.io/stashed/stash-enterprise:v0.32.0e9bde36e34b7
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

15,265
kubedb-provider-awsappscodeVerified publisher2026.7.101 of 1See more

kubedb-provider-aws appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-aws:v0.27.049b1c312e342
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

2,534
kubedb-provider-azureappscodeVerified publisher2026.7.101 of 1See more

kubedb-provider-azure appscode 2026.7.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.17.0

Open the chart page →

2,712
kubedb-provider-gcpappscodeVerified publisher2026.7.101 of 2See more

kubedb-provider-gcp appscode 2026.7.10

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

3,040
kubedb-ui-serverappscodeVerified publisher2021.12.211 of 1See more

kubedb-ui-server appscode 2021.12.21

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

2,054
kubeform-provider-awsappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-aws appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

2,803
kubeform-provider-azureappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-azure appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.17.0

Open the chart page →

2,724
kubeform-provider-gcpappscodeVerified publisher2023.11.11 of 1See more

kubeform-provider-gcp appscode 2023.11.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

2,750
minioappscodeVerified publisher2026.9.111 of 1See more

minio appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2023-01-12T02-06-16Zfc6bedc99355
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

4,050
stash-communityappscodeVerified publisher0.42.01 of 4See more

stash-community appscode 0.42.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

3,669
statefulsetappscodeVerified publisher0.0.11 of 3See more

statefulset appscode 0.0.1

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appscode/kube-rbac-proxy:v0.11.00df4ae70e3bd
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,739
cloud-portalappuio0.4.11 of 1See more

cloud-portal appuio 0.4.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appuio/cloud-portal:v0.2.18c7e08d32d70
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,287
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
nghttp2@1.52.0-1
golang.org/x/net@v0.11.0
1.52.0-1+deb12u1
0.17.0

Open the chart page →

5,680
maxscaleappuio2.0.11 of 1See more

maxscale appuio 2.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/appuio/maxscale-docker:6.4.613a01be102b0
nghttp2@1.33.0-3.el8_3.1
0:1.33.0-5.el8_8

Open the chart page →

2,902
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
tomcat-embed-core@9.0.38
9.0.81

Open the chart page →

8,913
appwriteappwrite-helmVerified publisher1.3.21 of 8See more

appwrite appwrite-helm 1.3.2

1 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubegems/bitnami-shell:12-debian-12-r24e42e3aaacdd3
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

9,855
harbor-scanner-trivyaqua-helm0.17.01 of 1See more

harbor-scanner-trivy aqua-helm 0.17.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
0.17.0

Open the chart page →

5,211
arma-reforgerarma-reforger0.5.37 of 8See more

arma-reforger arma-reforger 0.5.3

7 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/pushgateway:v1.5.128fe26c8b8b1
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
stakater/reloader:v1.0.15f4b87a8e56d4
golang.org/x/net@v0.7.0
0.17.0
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
nghttp2@1.40.0-1build1
golang.org/x/net@v0.7.0
1.40.0-1ubuntu0.2
0.17.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
golang.org/x/net@v0.4.0
0.17.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
0.17.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

23,425
cluster-autoscalerarzu9.19.11 of 1See more

cluster-autoscaler arzu 9.19.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
breton/cool:dev41b1bb483aa2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

1,779
itera-lmaarzu1.34.604 of 6See more

itera-lma arzu 1.34.60

4 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:9.0.1a738d0744784
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.17.0
quay.io/prometheus-operator/prometheus-operator:v0.57.0a2d502c204f9
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

8,621
keystonearzu0.2.292 of 4See more

keystone arzu 0.2.29

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2

Open the chart page →

22,663
automatedconfigurationassist-iot-automated-configuration1.0.02 of 5See more

automatedconfiguration assist-iot-automated-configuration 1.0.0

2 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:7.5.1dc9b972db002
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
confluentinc/cp-zookeeper:7.5.10bec03c1f3ce
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

14,823
dltkvassist-iot-data-integrity-verification0.2.04 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

4 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
hyperledger/fabric-tools:2.4b1194f509085
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
1.47.0-r2
0.17.0

Open the chart page →

77,883
dltflassist-iot-dlt-based-fl0.2.04 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

4 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/dlt_based_fl:1.1.04bc3d92788ed
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
hyperledger/fabric-orderer:2.46ec3fe59ea55
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
hyperledger/fabric-peer:2.46ff36af21eb1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
hyperledger/fabric-tools:2.4b1194f509085
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
1.47.0-r2
0.17.0

Open the chart page →

77,883
fllocaloperationsassist-iot-fl-local-operations1.1.01 of 3See more

fllocaloperations assist-iot-fl-local-operations 1.1.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

3,786
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.02 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:ui-latest20338b353aaf
nghttp2@1.47.0-r0
nginx@1.22.0-r1
1.47.0-r2
1.22.1-r1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

9,411
flrepositorydbassist-iot-fl-repository1.1.01 of 2See more

flrepositorydb assist-iot-fl-repository 1.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/fl_repository_db:latestad8f72108636
golang.org/x/net@v0.12.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

4,367

Container images carrying it

2,471 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.17.0
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
1
ghcr.io/kyverno/policy-reporter:2.14.1e74c6bf33d1b
golang.org/x/net@v0.8.0
0.17.0
1
ghcr.io/leoquote/tencentcloud-exporter:masterca51b6bb15dd
nghttp2@1.55.1-r0
1.57.0-r0
1
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
1
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0
1
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/libretime/libretime-legacy:latest35b4531189c2
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
nghttp2@1.30.0-1ubuntu1
tomcat-embed-core@9.0.37
1.30.0-1ubuntu1+esm2
9.0.81
1
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/net@v0.14.0
0.17.0
1
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/net@v0.6.0
0.17.0
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/net@v0.8.0
0.17.0
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
nghttp2@1.55.1-r0
golang.org/x/net@v0.14.0
1.57.0-r0
0.17.0
1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/net@v0.13.0
0.17.0
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/net@v0.8.0
0.17.0
1
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
1
ghcr.io/mailu/clamav:1.9.5001d30483e4a8
nghttp2@1.51.0-r0
1.51.0-r2
1
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
0.17.0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
golang.org/x/net@v0.4.0
0.17.0
1
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
golang.org/x/net@v0.14.0
0.17.0
1
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/mjohnson9/docker-pleroma:v0.1.44f08e2823756
nghttp2@1.47.0-r0
1.47.0-r2
1
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
1
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/net@v0.9.0
0.17.0
1
ghcr.io/mroxso/pollstr:latest0b4f97faa3d0
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0
1
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/nefelim4ag/k8s-ondemand-proxy:0.0.2078b25d48cf7
golang.org/x/net@v0.13.0
0.17.0
1
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.