StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,792 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,792 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

25,217
pageshelm-repo1.0.02 of 3See more

pages helm-repo 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,262
todo-apihelm-repo-sharif0.1.01 of 2See more

todo-api helm-repo-sharif 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
pavanelthepu/todo-api:1.0.2f47658e3b24c
tomcat-embed-core@9.0.48
9.0.81

Open the chart page →

2,547
samplehelmapphelmtraining3.0.01 of 1See more

samplehelmapp helmtraining 3.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
praravind1801/helmimages:3.0.0f29d637b9ce1
nginx@1.25.3-1~bookworm
no fix listed

Open the chart page →

6,013
postgres-backup-localheywood8-helm-chartsVerified publisher0.1.131 of 1See more

postgres-backup-local heywood8-helm-charts 0.1.13

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

2,435
goshimmerhiveroad0.2.141 of 1See more

goshimmer hiveroad 0.2.14

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
iotaledger/goshimmer:v0.8.6b02a8f77474f
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0

Open the chart page →

2,551
cratedb-adapterhmdmph0.1.01 of 1See more

cratedb-adapter hmdmph 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
0.17.0

Open the chart page →

2,920
printserverhmediadeVerified publisher1.0.21 of 4See more

printserver hmediade 1.0.2

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
0.17.0

Open the chart page →

11,002
imageproxyhmphuVerified publisher0.1.11 of 1See more

imageproxy hmphu 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
willnorris/imageproxy:latest21d0c90f4c31
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

2,147
cert-managerhomeenterpriseinc1.10.13 of 3See more

cert-manager homeenterpriseinc 1.10.1

3 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.10.1b5657161d2c2
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
0.17.0
quay.io/jetstack/cert-manager-controller:v1.10.11143471c90db
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
0.17.0
quay.io/jetstack/cert-manager-webhook:v1.10.164121721c665
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
0.17.0

Open the chart page →

4,735
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

16,444
privatebinhomelabcihelmchartstestVerified publisher2.1.71 of 1See more

privatebin homelabcihelmchartstest 2.1.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
privatebin/pdo:1.3.500466418121c
nginx@1.20.2-r0
1.20.2-r2

Open the chart page →

1,159
httpbin2022httpbin2022Verified publisher0.1.11 of 1See more

httpbin2022 httpbin2022 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mshanley80/httpbin2022:latest5b189a70c0fb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

8,807
eoloplanthttpd-eoloplant0.1.05 of 7See more

eoloplant httpd-eoloplant 0.1.0

5 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

32,456
http-headershttp-headers1.2.11 of 1See more

http-headers http-headers 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/k8start/http-headers:1.2.0c7a9987f2ac5
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

2,009
sys-info-web-env-view-serverhuajuan-helm-charts0.1.11 of 2See more

sys-info-web-env-view-server huajuan-helm-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
huajuan6848/env-view-server:0.0.1-SNAPSHOTa303f3d9f6e0
tomcat-embed-core@10.1.11
10.1.14

Open the chart page →

1,992
cac-systemhuangchengwu-helm-chart0.1.07 of 9See more

cac-system huangchengwu-helm-chart 0.1.0

7 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
nghttp2@1.46.0-r0
golang.org/x/net@v0.10.0
1.46.0-r2
0.17.0
quay.io/jetstack/cert-manager-cainjector:v1.12.0e0a5b06b231c
golang.org/x/net@v0.9.0
0.17.0
quay.io/jetstack/cert-manager-controller:v1.12.04a9d0264055b
golang.org/x/net@v0.9.0
0.17.0
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
golang.org/x/net@v0.9.0
0.17.0
quay.io/jetstack/cert-manager-webhook:v1.12.0ec4306b243d9
golang.org/x/net@v0.9.0
0.17.0
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
0.17.0
quay.io/metallb/speaker:v0.13.1000406ccb1fa0
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

11,221
nexus3huangchengwu-helm-chart0.1.01 of 1See more

nexus3 huangchengwu-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
sonatype/nexus3:3.53.04bd975493104
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

4,463
prometheushuangchengwu-helm-chart0.1.02 of 3See more

prometheus huangchengwu-helm-chart 0.1.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:9.2.0133d35d2c263
nghttp2@1.43.0-1build3
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
1.43.0-1ubuntu0.1
0.17.0
apache/skywalking-ui:9.2.0295f1dc87d98
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

16,516
skywalking-v1huangchengwu-helm-chart0.1.02 of 4See more

skywalking-v1 huangchengwu-helm-chart 0.1.0

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/skywalking-oap-server:8.9.1b4ec8c18d079
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
1.40.0-1ubuntu0.2
0.17.0
apache/skywalking-ui:8.9.180530f0308a5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

20,763
tdenginehuangchengwu-helm-chart3.0.21 of 1See more

tdengine huangchengwu-helm-chart 3.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
tdengine/tdengine:3.0.2.24140a4021ddb
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
0.17.0

Open the chart page →

3,763
activation-servicei4trustVerified publisher2.3.11 of 1See more

activation-service i4trust 2.3.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
i4trust/activation-service:2.2.09f3719176893
nghttp2@1.53.0-r0
1.57.0-r0

Open the chart page →

2,057
mvfi4trustVerified publisher1.1.21 of 1See more

mvf i4trust 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wistefan/mvf:lateste0887302b2d8
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

7,257
vcverifieri4trustVerified publisher1.0.231 of 1See more

vcverifier i4trust 1.0.23

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/fiware/vcverifier:2.0.1cd36290dc849
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,784
vcwaltidi4trustVerified publisher0.0.191 of 1See more

vcwaltid i4trust 0.0.19

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
nghttp2@1.43.0-1build3
golang.org/x/net@v0.8.0
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

7,984
stoloniamalryz0.10.01 of 2See more

stolon iamalryz 0.10.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

4,052
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
tomcat-embed-core@8.5.15
8.5.94
ibmcom/microclimate-theia:lateste17bdccc5030
tomcat-embed-core@8.5.15
8.5.94

Open the chart page →

57,842
ibm-object-storage-pluginibm-charts1.1.52 of 2See more

ibm-object-storage-plugin ibm-charts 1.1.5

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-3.el8_2.2
ibmcom/ibmcloud-object-storage-plugin:1.8.169c73804b37a3
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-3.el8_2.2

Open the chart page →

12,461
ibm-skydive-devibm-charts1.1.21 of 1See more

ibm-skydive-dev ibm-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ibmcom/skydive:0.22.0395e60cc6e3d
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

12,650
ibm-ucv-prodibm-helm5.2.62 of 16See more

ibm-ucv-prod ibm-helm 5.2.6

2 of the 16 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.22.13d0e426ccff33
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ibmcom/opencontent-common-utils:1.1.2cd5065df7304
nghttp2@1.33.0-1.el8
0:1.33.0-5.el8_8

Open the chart page →

12,184
eoloserverihuertas2021-vmartinp2021-helm0.1.04 of 7See more

eoloserver ihuertas2021-vmartinp2021-helm 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

27,861
ikigaiikigai-chartVerified publisher0.0.94 of 58See more

ikigai ikigai-chart 0.0.9

4 of the 58 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dremio/dremio-oss:24.1.080ed2e3b7c43
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
library/zookeeper:3.8-temurin55d1e5b2e601
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
golang.org/x/net@v0.0.0-20220802222814-0bcc04d9c69b
0.17.0

Open the chart page →

37,983
apexkube-agentimprowisedVerified publisher1.4.01 of 2See more

apexkube-agent improwised 1.4.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
masipcat/wireguard-go:0.0.20230223769f7bb64694
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

3,360
frigateimprowisedVerified publisher1.1.01 of 1See more

frigate improwised 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/blakeblackshear/frigate:0.13.07a5244e4c8dc
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

2,160
healthchecksimprowisedVerified publisher1.1.11 of 2See more

healthchecks improwised 1.1.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/healthchecks:2.7.2023033194696dab3c50
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

2,629
kore-boardimprowisedVerified publisher0.5.83 of 4See more

kore-board improwised 0.5.8

3 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kore3lab/kore-board.backend:v0.5.5455f6e7a26fd
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
ghcr.io/kore3lab/kore-board.metrics-scraper:v0.5.547f88b18fb7c
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

16,253
chronografinfluxdata1.2.61 of 1See more

chronograf influxdata 1.2.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/chronograf:1.9.496d8a3f65a4f
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

2,205
l2gethinfradao0.0.11 of 1See more

l2geth infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ethereumoptimism/l2geth:0.5.315577036dc36d
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
1.46.0-r2
0.17.0

Open the chart page →

2,659
ingress-dashboardingress-dashboard0.1.12 of 3See more

ingress-dashboard ingress-dashboard 0.1.1

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
taemon1337/image-api:0.0.1247bc1dc4f07
nghttp2@1.46.0-r0
1.46.0-r2
taemon1337/ingress-dashboard:0.0.10e8f5096c66bb
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

4,543
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

10,575
lakefsinseefrlab0.0.61 of 2See more

lakefs inseefrlab 0.0.6

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
treeverse/lakefs:0.69.0478f37a6cffc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.17.0

Open the chart page →

2,652
openrefineinseefrlab3.5.01 of 1See more

openrefine inseefrlab 3.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
easypi/openrefine:3.7.0d2950a36a576
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,757
pinotinseefrlab0.2.01 of 2See more

pinot inseefrlab 0.2.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apachepinot/pinot:latest-jdk110018bb04ced7
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

10,781
instemmingserviceinstemmingservice1.0.01 of 3See more

instemmingservice instemmingservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,519
consulintelVerified publisher0.8.12 of 2See more

consul intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
1.46.0-r2
0.17.0
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

5,403
evi-consulintelVerified publisher3.0.32 of 2See more

evi-consul intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/consul:1.14.2e38576edcdfd
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
1.46.0-r2
0.17.0
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

5,403
evi-kesintelVerified publisher3.0.31 of 1See more

evi-kes intel 3.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
minio/kes:2023-04-03T16-41-28Zf93c2d9088df
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,765
evi-miniointelVerified publisher3.0.32 of 2See more

evi-minio intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.4.0
0:1.33.0-5.el8_8
0.17.0
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

7,472
evi-vaultintelVerified publisher3.0.32 of 2See more

evi-vault intel 3.0.3

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/net@v0.0.0-20221004154528-8021a29435af
0.17.0

Open the chart page →

4,487
itm-mqtt-brokerintelVerified publisher1.0.01 of 1See more

itm-mqtt-broker intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hivemq/hivemq4:dns-4.5.144d194450d48e
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,655

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/stefanprodan/podinfo:6.1.3f25ebb9c6788
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
1.46.0-r2
0.17.0
1
ghcr.io/stenic/sql-operator:1.13.2f4324baa2aad
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.17.0
1
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.17.0
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.17.0
1
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.17.0
1
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.17.0
1
ghcr.io/substra/fabric-peer:0.2.4f681e0343a31
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
1
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
1.47.0-r2
0.17.0
1
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
nginx@1.25.4-1~bookworm
no fix listed
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/net@v0.7.0
0.17.0
1
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
golang.org/x/net@v0.8.0
0.17.0
1
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
golang.org/x/net@v0.10.0
0.17.0
1
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/net@v0.7.0
0.17.0
1
ghcr.io/tailscale/tailscale:v1.34.1ce1862e6b3a5
golang.org/x/net@v0.1.0
0.17.0
1
ghcr.io/tikalk/resource-manager:latest7f21d50e69cb
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
0.17.0
1
ghcr.io/volosoft/eshoponabp/app-web:1.0.0056bb4271626
nghttp2@1.47.0-r0
1.47.0-r2
1
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
golang.org/x/net@v0.8.0
0.17.0
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
nghttp2@1.52.0-1
golang.org/x/net@v0.11.0
1.52.0-1+deb12u1
0.17.0
1
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
nghttp2@1.46.0-r0
1.46.0-r2
1
ghcr.io/wbstack/ui:3.94b01f67faadf1
nghttp2@1.46.0-r0
1.46.0-r2
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
nghttp2@1.52.0-1
nginx@1.22.1-9
1.52.0-1+deb12u1
no fix listed
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
ghcr.io/wyrihaximusnet/kubernetes-redis-db-assignment-operator:v1.0.831060be60bec
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
ghcr.io/yeonghoo2/crashloop-operator:0.0.6565d1115e6bd
golang.org/x/net@v0.13.0
0.17.0
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
golang.org/x/net@v0.0.0-20220802222814-0bcc04d9c69b
0.17.0
1
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
mcr.microsoft.com/oss/azure/aad-pod-identity/mic:v1.8.173004b93fcb74
golang.org/x/net@v0.7.0
0.17.0
1
mcr.microsoft.com/oss/azure/aad-pod-identity/nmi:v1.8.1777788bf38938
golang.org/x/net@v0.7.0
0.17.0
1
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
0.17.0
1
mcr.microsoft.com/oss/kubernetes-csi/csi-node-driver-registrar:v2.0.1fc5d14e9f26f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
mcr.microsoft.com/oss/kubernetes-csi/csi-provisioner:v1.6.1667b1b1ea1e4
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
0.17.0
1
mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.1.07997e0f236bc
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.17.0
1
mcr.microsoft.com/oss/kubernetes-csi/livenessprobe:v2.2.0b7d82802cca8
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.17.0
1
public.ecr.aws/aws-ec2/aws-node-termination-handler:v1.19.0844478ebd5b8
golang.org/x/net@v0.2.0
0.17.0
1
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/webhook:v2.0.0-beta86b0f7243250
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-2021.08.13.20.34-linux-amd6402aed3370fce
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r1-10-g1942553-2021.06.04.00.07-linux-amd64b32c99e7bc45
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
golang.org/x/net@v0.5.0
0.17.0
1
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0
1
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0
1
public.ecr.aws/jtekt-corporation/annotation-tool:ef974ad9abd817eb6845
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.