StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,107
of 17,790 indexed, latest versions
Container images
2,471
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,107 of 17,790 indexed charts deploy, on 2,471 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,572
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,107 by stars
ChartLatestAffected imagesRadar Score
subspacemglants0.1.01 of 1See more

subspace mglants 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
subspacecommunity/subspace:1.5.0e2042b63fb35
golang.org/x/net@v0.0.0-20200519113804-d87ec0cfa476
0.17.0

Open the chart page →

3,254
librenmsmidokura-communityVerified publisher0.3.21 of 6See more

librenms midokura-community 0.3.2

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
librenms/librenms:22.4.14f1f3d667cc7
nghttp2@1.46.0-r0
nginx@1.20.2-r0
1.46.0-r2
1.20.2-r2

Open the chart page →

8,968
nginx-staticmidokura-communityVerified publisher0.1.61 of 1See more

nginx-static midokura-community 0.1.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.23.03536d368b898
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,127
chartmuseummike75151.2.01 of 1See more

chartmuseum mike7515 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
golang.org/x/net@v0.0.0-20220531201128-c960675eff93
0.17.0

Open the chart page →

3,176
miniomilvus8.0.171 of 1See more

minio milvus 8.0.17

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

6,922
mlflow-controllermlflow-deployment-controller0.1.81 of 2See more

mlflow-controller mlflow-deployment-controller 0.1.8

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

8,957
mlflow-servermlflowserver0.1.91 of 3See more

mlflow-server mlflowserver 0.1.9

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
buntha/mlflow:2.1.1154542cc3083
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

5,804
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

13,812
podsyncmy0nVerified publisher1.5.41 of 2See more

podsync my0n 1.5.4

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
tdeutsch/podsync:v2.4.2b67186f4c9a5
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0

Open the chart page →

2,059
clowder2ncsaVerified publisher1.9.73 of 12See more

clowder2 ncsa 1.9.7

3 of the 12 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/keycloak:20.0.5cb04e49e6eb1
nghttp2@1.43.0-1
1.43.0-1+deb11u1
bitnamilegacy/mongodb:5.0.103bb1deeaf9d0
golang.org/x/net@v0.0.0-20220708220712-1185a9018129
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
bitnamilegacy/rabbitmq:3.10.88f7161d8ce19
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

37,504
marge-botnetpositiveVerified publisher1.1.01 of 1See more

marge-bot netpositive 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.12.1a96c10b61a59
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,253
ngrok-operatorngrok-operator1.1.01 of 2See more

ngrok-operator ngrok-operator 1.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zufardhiyaulhaq/ngrok-operator:v1.3.07cf2ae3fb1fb
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

1,896
node-exporternode-exporterVerified publisher0.1.101 of 1See more

node-exporter node-exporter 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/node-exporter:v1.6.0d2e48098c364
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,229
glowrootnovum-rgi-charts1.0.101 of 2See more

glowroot novum-rgi-charts 1.0.10

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
novumrgi/glowroot-central:0.14.0-beta.38c54790675b1
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,309
Helm-nginxnrr-test-app0.2.01 of 1See more

Helm-nginx nrr-test-app 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nrrrus/nginx-test:latest5f55cd4ef557
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

915
oadaoadaVerified publisher5.0.51 of 11See more

oada oada 5.0.5

1 of the 11 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0

Open the chart page →

13,329
nginx-s3olopostVerified publisher0.2.11 of 1See more

nginx-s3 olopost 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss3db8145349a3
nginx@1.27.2-1~bookworm
no fix listed

Open the chart page →

5,062
opencatalogiopencatalogi1.0.63 of 8See more

opencatalogi opencatalogi 1.0.6

3 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
nghttp2@1.47.0-r0
1.47.0-r2
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
nghttp2@1.52.0-1
nginx@1.25.1-1~bookworm
1.52.0-1+deb12u1
no fix listed
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

14,884
kubernetes-dashboard-proxyosc0.7.23 of 4See more

kubernetes-dashboard-proxy osc 0.7.2

3 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.7.02e500d29e9d5
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
kubernetesui/metrics-scraper:v1.0.876049887f07a
golang.org/x/net@v0.0.0-20220524220425-1d687d428aca
0.17.0
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

6,012
hlf-caowkin2.1.01 of 2See more

hlf-ca owkin 2.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0

Open the chart page →

3,431
hlf-ordowkin3.1.01 of 1See more

hlf-ord owkin 3.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledger/fabric-orderer:2.2.137294e05209b
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
0.17.0

Open the chart page →

3,357
hlf-peerowkin5.1.01 of 1See more

hlf-peer owkin 5.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hyperledger/fabric-peer:2.2.1bf4995c86af6
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
0.17.0

Open the chart page →

3,695
ngrok-operatorpaganuzzi0.0.21 of 1See more

ngrok-operator paganuzzi 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/paganuzzi/ngrokoperator:latest5a10cd095699
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.17.0

Open the chart page →

2,811
traefik-errorspascaliskeVerified publisher4.0.01 of 1See more

traefik-errors pascaliske 4.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/pascaliske/traefik-errors:1.1.00cf31753ce57
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

1,272
unboundpascaliskeVerified publisher2.0.01 of 1See more

unbound pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/pascaliske/unbound:0.1.09009fbd2ef16
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

1,958
patch-operatorpatch-operator0.1.112 of 2See more

patch-operator patch-operator 0.1.11

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0:1.33.0-5.el8_8
0.17.0
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

7,840
todo-apipavanelthepu0.1.01 of 2See more

todo-api pavanelthepu 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
pavanelthepu/todo-api:1.0.2f47658e3b24c
tomcat-embed-core@9.0.48
9.0.81

Open the chart page →

2,547
pdf-editor-helmpdf-editor-web1.0.01 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

4,206
spirephilips-labsVerified publisher0.12.25 of 6See more

spire philips-labs 0.12.2

5 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
golang.org/x/net@v0.7.0
0.17.0
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
golang.org/x/net@v0.7.0
0.17.0
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
golang.org/x/net@v0.7.0
0.17.0
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
golang.org/x/net@v0.7.0
0.17.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

7,269
chadbotphntom0.2.31 of 1See more

chadbot phntom 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phntom/chadbot:0.2.397c28e4178ad
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

1,103
chartmuseumphntom4.0.201 of 1See more

chartmuseum phntom 4.0.20

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
phntom/chartmuseum:v0.16.053883b65d9b7
nghttp2@1.55.1-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0

Open the chart page →

2,948
spring-boot-api-apppiominVerified publisher0.3.111 of 1See more

spring-boot-api-app piomin 0.3.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
nghttp2@1.43.0-1build3
tomcat-embed-core@9.0.65
1.43.0-1ubuntu0.1
9.0.81

Open the chart page →

7,622
pipelinewise-operatorpipelinewise-operatorVerified publisher0.5.11 of 1See more

pipelinewise-operator pipelinewise-operator 0.5.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0

Open the chart page →

2,121
secrets-store-csi-driver-provider-awsportefaix-hub0.4.01 of 1See more

secrets-store-csi-driver-provider-aws portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-2021.08.13.20.34-linux-amd6402aed3370fce
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0

Open the chart page →

2,212
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
nghttp2@1.43.0-1
1.43.0-1+deb11u1
library/elasticsearch:7.17.0332c6d416808
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

32,033
postgres-backuppostgres-backup0.3.01 of 2See more

postgres-backup postgres-backup 0.3.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nerzhul/mc-arm64:2020.10.034215df511f31
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0

Open the chart page →

5,468
rethinkdbpozetron1.1.91 of 1See more

rethinkdb pozetron 1.1.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.17.0

Open the chart page →

2,912
pritunl-slack-apppritunl-slack-appVerified publisher0.1.71 of 1See more

pritunl-slack-app pritunl-slack-app 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,871
prometheusprometheus-worawutchan13.0.03 of 6See more

prometheus prometheus-worawutchan 13.0.0

3 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.17.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.17.0
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0

Open the chart page →

9,948
kubernetes-dashboardpyalive-cdmswebappVerified publisher5.8.01 of 1See more

kubernetes-dashboard pyalive-cdmswebapp 5.8.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.6.1290bebc3cd96
golang.org/x/net@v0.0.0-20220526153639-5463443f8c37
0.17.0

Open the chart page →

1,662
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0

Open the chart page →

24,027
qrcode-generatorqrcode-generatorVerified publisher0.1.01 of 1See more

qrcode-generator qrcode-generator 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
felipecs8/qrcode-generator:v1d5f4f17cb066
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

1,884
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
nghttp2@1.43.0-1build3
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

6,868
velero-s3-deploymentradar-baseVerified publisher0.4.22 of 4See more

velero-s3-deployment radar-base 0.4.2

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
velero/velero:v1.9.0277fbfaf8dcf
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

4,819
shinyproxyremche0.6.61 of 2See more

shinyproxy remche 0.6.6

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
remche/shinyproxy:2.6.18bcda8a04d3b
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

3,959
repmanrepman-helmchartVerified publisher1.0.121 of 3See more

repman repman-helmchart 1.0.12

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.21.62bcabc23b454
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

3,596
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zbalogh/reservation-api-server:1.0.97c247e399a1f
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

6,640
backup-repository-serverriotkit-org4.0.01 of 1See more

backup-repository-server riotkit-org 4.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
golang.org/x/net@v0.0.0-20220401154927-543a649e0bdd
0.17.0

Open the chart page →

2,056
rke2-canalrke2-charts3.13.32 of 2See more

rke2-canal rke2-charts 3.13.3

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rancher/hardened-calico:v3.13.36d2cd61a338b
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0

Open the chart page →

7,002
cloudflare-tunnelrlex0.8.01 of 1See more

cloudflare-tunnel rlex 0.8.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2023.10.0c18744ae1767
golang.org/x/net@v0.12.0
0.17.0

Open the chart page →

1,691

Container images carrying it

2,471 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.17.0
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0
1
ghcr.io/kyverno/policy-reporter:2.14.1e74c6bf33d1b
golang.org/x/net@v0.8.0
0.17.0
1
ghcr.io/leoquote/tencentcloud-exporter:masterca51b6bb15dd
nghttp2@1.55.1-r0
1.57.0-r0
1
ghcr.io/leoquote/tencentcloud-info-exporter:maind523c2c010cd
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
1
ghcr.io/leoquote/tinyproxy_exporter:master6b4103d88dbb
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0
1
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/libretime/libretime-legacy:latest35b4531189c2
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
nghttp2@1.30.0-1ubuntu1
tomcat-embed-core@9.0.37
1.30.0-1ubuntu1+esm2
9.0.81
1
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
golang.org/x/net@v0.14.0
0.17.0
1
ghcr.io/loft-sh/agent:3.2.45c109914ff73
golang.org/x/net@v0.6.0
0.17.0
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
golang.org/x/net@v0.8.0
0.17.0
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
nghttp2@1.55.1-r0
golang.org/x/net@v0.14.0
1.57.0-r0
0.17.0
1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
golang.org/x/net@v0.13.0
0.17.0
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
golang.org/x/net@v0.8.0
0.17.0
1
ghcr.io/lsst-sqre/strimzi-registry-operator:0.6.07e25f7048aff
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
1
ghcr.io/mailu/clamav:1.9.5001d30483e4a8
nghttp2@1.51.0-r0
1.51.0-r2
1
ghcr.io/matrix-org/dendrite-monolith:v0.9.43267d27d392f
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
0.17.0
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
golang.org/x/net@v0.4.0
0.17.0
1
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
golang.org/x/net@v0.14.0
0.17.0
1
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
ghcr.io/mjohnson9/docker-pleroma:v0.1.44f08e2823756
nghttp2@1.47.0-r0
1.47.0-r2
1
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
1
ghcr.io/mohammadv184/cert-manager-webhook-arvancloud:latest179bee5ef8b2
golang.org/x/net@v0.9.0
0.17.0
1
ghcr.io/mroxso/pollstr:latest0b4f97faa3d0
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0
1
ghcr.io/nabokihms/events_exporter:latest68d44646e8b2
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
ghcr.io/nathanvaughn/webtrees:2.0.1969423a100fab
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/nefelim4ag/k8s-ondemand-proxy:0.0.2078b25d48cf7
golang.org/x/net@v0.13.0
0.17.0
1
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.