StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,797 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,797 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
supersetnineinfra-charts0.11.21 of 4See more

superset nineinfra-charts 0.11.2

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,439
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.17.0

Open the chart page →

6,586
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/net@v0.0.0-20220812174116-3211cb980234
0.17.0

Open the chart page →

4,756
servernodejs0.0.21 of 1See more

server nodejs 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
maissacrement/pock8snodejs:0.0.16da0db1159da
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,904
nodejsweeklynodejsweekly1.1.01 of 1See more

nodejsweekly nodejsweekly 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zufardhiyaulhaq/nodejsweekly:v1.1.0306859a3f167
golang.org/x/net@v0.0.0-20211015210444-4f30a5c0130f
0.17.0

Open the chart page →

1,489
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
0.17.0
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
0.17.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
0.17.0
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
0.17.0
quay.io/prometheus/pushgateway:v1.6.05111de00e969
golang.org/x/net@v0.10.0
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

7,748
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

22,795
liquidsoapnorth141.0.01 of 1See more

liquidsoap north14 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,955
config-server-helm-chartnotesprojectchart0.1.01 of 1See more

config-server-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/config-server-another:lateste7f20450d2ae
tomcat-embed-core@9.0.65
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

3,425
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
tomcat-embed-core@9.0.64
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

5,919
ingress-helm-chartnotesprojectchart0.1.02 of 2See more

ingress-helm-chart notesprojectchart 0.1.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

2,956
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

4,558
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
tomcat-embed-core@9.0.64
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

6,896
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

15,210
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

15,282
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

15,266
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
tomcat-embed-core@9.0.64
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

5,960
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
tomcat-embed-core@9.0.64
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

5,917
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

2,254
notification-componentnotification-component1.0.01 of 4See more

notification-component notification-component 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,537
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0

Open the chart page →

4,861
nfs-server-provisionernovum-rgi-charts1.1.21 of 1See more

nfs-server-provisioner novum-rgi-charts 1.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.17.0

Open the chart page →

2,806
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
1.30.0-1ubuntu1+esm2
0.17.0
linuxserver/codimd:latestb801bbcf6386
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

27,548
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

27,757
cnaos-pvc-populatornutanix-helm-releasesVerified publisher1.1.0-174-prod1 of 2See more

cnaos-pvc-populator nutanix-helm-releases 1.1.0-174-prod

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

1,838
nutanix-flow-cninutanix-helm-releasesVerified publisher1.1.01 of 7See more

nutanix-flow-cni nutanix-helm-releases 1.1.0

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

4,997
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

17,161
cluster-gateway-addon-managerocm-helm-chartsVerified publisher1.4.01 of 1See more

cluster-gateway-addon-manager ocm-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

1,607
multicluster-meshocm-helm-chartsVerified publisher0.0.21 of 1See more

multicluster-mesh ocm-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

2,131
my-bloody-jenkinsodavid0.1.2181 of 1See more

my-bloody-jenkins odavid 0.1.218

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
odavid/my-bloody-jenkins:2.462.3-306e7ab3bbc948e
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

5,826
db-backupoleds-helm-chartsVerified publisher0.1.01 of 1See more

db-backup oleds-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
oled01/db-backup:0.1.06302fd2b5333
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

8,140
hive-metastoreolehrgfVerified publisher0.1.01 of 1See more

hive-metastore olehrgf 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

8,548
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
nghttp2@1.43.0-1build3
http2-common@9.4.51.v20230217
http2-server@9.4.51.v20230217
1.43.0-1ubuntu0.1
9.4.53
9.4.53

Open the chart page →

9,083
exposecontrollerolli-aiVerified publisher1.0.51 of 1See more

exposecontroller olli-ai 1.0.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
olliai/exposecontroller:1.0.5a470d96525e4
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,861
k8s-replicatorolli-aiVerified publisher1.3.01 of 1See more

k8s-replicator olli-ai 1.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
olliai/k8s-replicator:1.3.05716f2a8bd4c
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,825
apicurioone-acre-fundVerified publisher2.3.04 of 5See more

apicurio one-acre-fund 2.3.0

4 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
apicurio/apicurio-studio-ui:0.2.62.Final349c845270c2
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

18,668
one-green-coreone-green-coreVerified publisher0.0.73 of 8See more

one-green-core one-green-core 0.0.7

3 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:8.5.3ecc1b80b8ca2
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
0.17.0
library/influxdb:2.0.8ba10ac9ba17a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
library/telegraf:1.20.428e98eece020
golang.org/x/net@v0.0.0-20211005215030-d2e5035098b3
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

9,582
opa-nginxopa-nginx0.0.31 of 2See more

opa-nginx opa-nginx 0.0.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openpolicyagent/opa:0.53.16a58dea59933
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

2,176
commonground-gatewayopencatalogi1.5.32 of 7See more

commonground-gateway opencatalogi 1.5.3

2 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
nghttp2@1.47.0-r0
1.47.0-r2
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
nghttp2@1.52.0-1
nginx@1.25.1-1~bookworm
1.52.0-1+deb12u1
no fix listed

Open the chart page →

9,766
opentickopenchartVerified publisher0.1.01 of 1See more

opentick openchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.25.5a484819eb602
nginx@1.25.5-1~bookworm
no fix listed

Open the chart page →

5,716
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0:1.33.0-4.el8_4.1
0.17.0

Open the chart page →

18,032
bbsimopencord4.8.111 of 1See more

bbsim opencord 4.8.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
voltha/bbsim:1.16.7d90403d58016
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.17.0

Open the chart page →

3,915
bbsim-sadis-serveropencord0.3.51 of 1See more

bbsim-sadis-server opencord 0.3.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
voltha/bbsim-sadis-server:0.4.0762b272d439e
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

3,729
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
nghttp2@1.30.0-1ubuntu1
tomcat-coyote@8.5.38
tomcat-embed-core@8.5.38
1.30.0-1ubuntu1+esm2
8.5.94
8.5.94

Open the chart page →

63,509
freeradiusopencord1.0.41 of 1See more

freeradius opencord 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

15,738
nem-monitoringopencord1.3.221 of 9See more

nem-monitoring opencord 1.3.22

1 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.17.0

Open the chart page →

4,619
omec-control-planeopencord0.1.311 of 8See more

omec-control-plane opencord 0.1.31

1 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
omecproject/c3po-hssdb:master-latest28a90cc26716
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

40,941
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

12,953
ves-agentopencord1.0.21 of 1See more

ves-agent opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
opencord/ves-agent:1.0.04187e2a8c918
tomcat-embed-core@8.5.31
8.5.94

Open the chart page →

6,353
volthaopencord2.14.02 of 2See more

voltha opencord 2.14.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
voltha/voltha-rw-core:3.4.87a325316fe59
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

3,825

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
nginx@1.27.2-1~bookworm
no fix listed
1
public.ecr.aws/jtekt-corporation/polygonal-annotation-tool:a3fa936056efd38500d6
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
nginx@1.25.3-1~bookworm
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
public.ecr.aws/karpenter/controller:v0.19.3f0e5ab60b2df
golang.org/x/net@v0.1.0
0.17.0
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
1.30.0-1ubuntu1+esm2
0.17.0
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
1.40.0-1ubuntu0.2
0.17.0
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
http2-common@9.4.34.v20201102
9.4.53
1
quay.io/aerokube/keygen:1.0.1578934444f04
golang.org/x/net@v0.8.0
0.17.0
1
quay.io/aerokube/moon:2.5.1a8837b00ba1c
golang.org/x/net@v0.7.0
0.17.0
1
quay.io/aerokube/moon-conf:2.5.19ca307b30080
golang.org/x/net@v0.7.0
0.17.0
1
quay.io/aerokube/moon-ui:2.0.589990b146824
golang.org/x/net@v0.11.0
0.17.0
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
nghttp2@1.43.0-1build3
golang.org/x/net@v0.0.0-20220621193019-9d032be2e588
1.43.0-1ubuntu0.1
0.17.0
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
nghttp2@1.43.0-1build3
golang.org/x/net@v0.8.0
1.43.0-1ubuntu0.1
0.17.0
1
quay.io/argoprojlabs/argocd-extension-metrics:v1.0.30d614816c4b7
golang.org/x/net@v0.10.0
0.17.0
1
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/net@v0.0.0-20220621193019-9d032be2e588
0.17.0
1
quay.io/backube/scribe:0.2.0cdefc81c6b2e
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0:1.33.0-4.el8_4.1
0.17.0
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
1
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
golang.org/x/net@v0.7.0
0.17.0
1
quay.io/cephcsi/cephcsi:v3.5.128a674af1df2
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
1
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
0.17.0
1
quay.io/cilium/tetragon-operator:v0.8.34ab8e6604204
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
0.17.0
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
1.47.0-r2
0.17.0
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
nghttp2@1.33.0-3.el8_2.1
nginx@1:1.14.1-9.module+el8.0.0+4108+af250afe
golang.org/x/net@v0.14.0
0:1.33.0-5.el8_8
1:1.20.1-1.module+el8.8.0+20359+9bd89172.1
0.17.0
1
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
0.17.0
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.16.0-2.module+el8.3.0+10180+b92e1eb6
nodejs-packaging@23-3.module+el8.3.0+6519+9f98ed83
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:26-1.module+el8.8.0+19857+6d2a104d
1
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0:1.33.0-4.el8_4.1
0.17.0
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
1
quay.io/evryfs/github-actions-runner-operator:v0.11.16b084e0bd082
golang.org/x/net@v0.12.0
0.17.0
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
nghttp2@1.53.0-r0
1.57.0-r0
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
golang.org/x/net@v0.1.0
0.17.0
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
1
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
quay.io/fiware/orion-ld:1.0.1ea838e5b4051
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
1
quay.io/fiware/vcverifier:2.0.1cd36290dc849
golang.org/x/net@v0.8.0
0.17.0
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
nghttp2@1.43.0-1build3
golang.org/x/net@v0.8.0
1.43.0-1ubuntu0.1
0.17.0
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0:1.33.0-5.el8_8
0.17.0
1
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0:1.33.0-5.el8_8
0.17.0
1
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0:1.33.0-5.el8_8
0.17.0
1
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0
1
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0
1
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0
1
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.