StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,787 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,787 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
gotwaygotwayVerified publisher0.8.01 of 1See more

gotway gotway 0.8.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

1,826
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0

Open the chart page →

22,565
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
governify/dashboard:lateste83a17ba5038
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0

Open the chart page →

24,360
goweeklygoweekly2.0.01 of 1See more

goweekly goweekly 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zufardhiyaulhaq/goweekly:v2.0.008dcc130fbea
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.17.0

Open the chart page →

1,229
ingress-nginxgpg-dev4.9.01 of 2See more

ingress-nginx gpg-dev 4.9.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
0.17.0

Open the chart page →

2,316
jaegergpg-dev3.3.31 of 5See more

jaeger gpg-dev 3.3.3

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/cassandra:3.11.65aa8400b4b3b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

19,291
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

47,117
prometheus-operator-admission-webhookgpg-dev0.18.11 of 2See more

prometheus-operator-admission-webhook gpg-dev 0.18.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

1,685
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
nghttp2@1.40.0-1build1
tomcat-coyote@8.5.82
tomcat-embed-core@8.5.82
1.40.0-1ubuntu0.2
8.5.94
8.5.94

Open the chart page →

15,780
mimir-openshift-experimentalgrafana2.1.03 of 4See more

mimir-openshift-experimental grafana 2.1.0

3 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/mimir:2.0.080c1a8eb24dd
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
0.17.0
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0:1.33.0-5.el8_8
0.17.0
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

17,759
grafregistratiecomponentgrafregistratiecomponent1.0.01 of 3See more

grafregistratiecomponent grafregistratiecomponent 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,510
supertokensgraphql-hive1.0.01 of 1See more

supertokens graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
supertokens/supertokens-postgresql:3.1418d34c781347
tomcat-embed-core@8.5.47
8.5.94

Open the chart page →

2,709
siembolgresearch0.1.64 of 4See more

siembol gresearch 0.1.6

4 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
alpine/k8s:1.18.16a41efe02a041
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
tomcat-embed-core@9.0.68
9.0.81
gresearchdev/siembol-config-editor-ui:latest071e7109a981
nghttp2@1.47.0-r0
1.47.0-r2
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
tomcat-embed-core@9.0.68
9.0.81

Open the chart page →

14,312
loki-proxygroundcover0.1.11 of 1See more

loki-proxy groundcover 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

2,175
tailscale-subnet-routergtaylor1.2.11 of 1See more

tailscale-subnet-router gtaylor 1.2.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/tailscale/tailscale:v1.34.1ce1862e6b3a5
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

1,834
docker-authhalkeye0.1.11 of 1See more

docker-auth halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.17.0

Open the chart page →

2,374
matrix-media-repohalkeye1.0.51 of 1See more

matrix-media-repo halkeye 1.0.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0

Open the chart page →

4,455
tautullihalkeye1.1.41 of 2See more

tautulli halkeye 1.1.4

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
tautulli/tautulli:v2.7.7c4da15f058ea
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,473
hawk-envoy-pluginhawk0.1.01 of 4See more

hawk-envoy-plugin hawk 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/privacyengineering/consumer:main73f59c032812
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
0.17.0

Open the chart page →

9,151
cert-manager-webhook-arvanhbahadorzadeh0.1.11 of 1See more

cert-manager-webhook-arvan hbahadorzadeh 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

3,022
kubernetes-event-exporterhbahadorzadeh0.1.01 of 1See more

kubernetes-event-exporter hbahadorzadeh 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
golang.org/x/net@v0.0.0-20200520182314-0ba52f642ac2
0.17.0

Open the chart page →

2,630
hbasehbase0.1.71 of 4See more

hbase hbase 0.1.7

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
http2-common@9.4.34.v20201102
nghttp2@1.43.0-1
9.4.53
1.43.0-1+deb11u1

Open the chart page →

10,539
hdx-oss-v2hdx-oss-v20.8.41 of 5See more

hdx-oss-v2 hdx-oss-v2 0.8.4

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/mongo:5.0.14-focal50cae5081ab4
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

6,747
nacosheidaodageshiwoVerified publisher0.1.51 of 1See more

nacos heidaodageshiwo 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nacos/nacos-server:v2.1.0dcf04549c6d7
tomcat-embed-core@9.0.38
9.0.81

Open the chart page →

3,978
heliconehelicone0.1.422 of 14See more

helicone helicone 0.1.42

2 of the 14 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
nghttp2@1.52.0-1
1.52.0-1+deb12u1
supabase/gotrue:v2.91.07174d551d720
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

23,472
hello-worldhello-world-pponyVerified publisher0.3.01 of 1See more

hello-world hello-world-ppony 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.25.49ff236ed47fe
nginx@1.25.4-1~bookworm
no fix listed

Open the chart page →

5,851
7dtdhelm-7dtd0.1.01 of 1See more

7dtd helm-7dtd 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vinanrra/7dtd-server:v0.4.4f9534490bd2b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

10,655
helm-airportshelm-airports0.1.05 of 7See more

helm-airports helm-airports 0.1.0

5 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
daniacobext/airports-frontend:latest9eae4d39fc33
nghttp2@1.51.0-r0
1.51.0-r2
dina1993/airports-api:latestac731244aed1
tomcat-embed-core@10.1.7
10.1.14
dina1993/airports-consumer:latest669d146a5e63
tomcat-embed-core@10.1.7
10.1.14
dina1993/airports-producer:latest3d6b0dac1cb4
tomcat-embed-core@10.1.7
10.1.14
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

12,696
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

4,547
helm-airportshelm-airports-dan0.1.01 of 7See more

helm-airports helm-airports-dan 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

5,573
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

4,547
pageshelm-chart-repos-camden1.0.02 of 3See more

pages helm-chart-repos-camden 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,233
ditto-operatorhelm-chartsVerified publisher0.3.01 of 1See more

ditto-operator helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/ctron/ditto-operator:0.4.061a9bb81b85c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

2,673
hawkbit-operatorhelm-chartsVerified publisher0.1.41 of 1See more

hawkbit-operator helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ctron/hawkbit-operator:0.1.48fdea8f76499
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-3.el8_2.2

Open the chart page →

5,791
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.16.0-2.module+el8.3.0+10180+b92e1eb6
nodejs-packaging@23-3.module+el8.3.0+6519+9f98ed83
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:26-1.module+el8.8.0+19857+6d2a104d

Open the chart page →

24,174
streamsheetshelm-chartsVerified publisher0.2.35 of 8See more

streamsheets helm-charts 0.2.3

5 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.16.0-2.module+el8.3.0+10180+b92e1eb6
nodejs-packaging@23-3.module+el8.3.0+6519+9f98ed83
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:26-1.module+el8.8.0+19857+6d2a104d
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.16.0-2.module+el8.3.0+10180+b92e1eb6
nodejs-packaging@23-3.module+el8.3.0+6519+9f98ed83
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:26-1.module+el8.8.0+19857+6d2a104d
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.16.0-2.module+el8.3.0+10180+b92e1eb6
nodejs-packaging@23-3.module+el8.3.0+6519+9f98ed83
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:26-1.module+el8.8.0+19857+6d2a104d
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.16.0-2.module+el8.3.0+10180+b92e1eb6
nodejs-packaging@23-3.module+el8.3.0+6519+9f98ed83
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:26-1.module+el8.8.0+19857+6d2a104d
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.16.0-2.module+el8.3.0+10180+b92e1eb6
nodejs-packaging@23-3.module+el8.3.0+6519+9f98ed83
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:26-1.module+el8.8.0+19857+6d2a104d

Open the chart page →

89,949
springboothelmcharts1.0.01 of 1See more

springboot helmcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kimb88/hello-world-spring-boot:latest0639155241cb
tomcat-embed-core@8.5.32
8.5.94

Open the chart page →

6,451
logging-stackhelm-charts-alexis-carbillet0.1.04 of 9See more

logging-stack helm-charts-alexis-carbillet 0.1.0

4 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/agent-operator:v0.25.1a136c6208aa3
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
grafana/loki:2.6.11ee60f980950
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
grafana/loki:2.8.2b1da1d23037e
golang.org/x/net@v0.7.0
0.17.0
grafana/loki-canary:2.6.1ab2a2569307b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

12,650
monitoring-stackhelm-charts-alexis-carbillet0.1.02 of 11See more

monitoring-stack helm-charts-alexis-carbillet 0.1.0

2 of the 11 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/net@v0.10.0
0.17.0
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

9,461
aws-ebs-csi-driverhelm-charts-nr2.17.46 of 6See more

aws-ebs-csi-driver helm-charts-nr 2.17.4

6 of the 6 container images this version deploys carry CVE-2023-44487.

Open the chart page →

6,485
cortex-gatewayhelm-charts-nr0.1.91 of 1See more

cortex-gateway helm-charts-nr 0.1.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
golang.org/x/net@v0.0.0-20220403103023-749bd193bc2b
0.17.0

Open the chart page →

2,234
dregsyhelm-charts-nr0.1.51 of 1See more

dregsy helm-charts-nr 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

2,969
k8s-cloudwatch-adapterhelm-charts-nr0.2.21 of 1See more

k8s-cloudwatch-adapter helm-charts-nr 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0

Open the chart page →

2,468
k8s-event-loggerhelm-charts-nr1.1.91 of 1See more

k8s-event-logger helm-charts-nr 1.1.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
maxrocketinternet/k8s-event-logger:2.111224534789d
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

864
labelsmanager-controllerhelm-charts-nr1.0.41 of 1See more

labelsmanager-controller helm-charts-nr 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

2,305
listmonkhelm-charts-nr0.1.121 of 1See more

listmonk helm-charts-nr 0.1.12

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

2,537
metabasehelm-charts-nr0.14.41 of 1See more

metabase helm-charts-nr 0.14.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
metabase/metabase:v0.45.21fb334ce4820
nghttp2@1.51.0-r0
1.51.0-r2

Open the chart page →

2,572
weblatehelm-charts-nr0.3.21 of 3See more

weblate helm-charts-nr 0.3.2

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
0.17.0

Open the chart page →

7,987
wiremockhelm-charts-nr1.4.61 of 2See more

wiremock helm-charts-nr 1.4.6

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rodolpheche/wiremock:2.26.03be08a386092
http2-common@9.4.20.v20190813
http2-server@9.4.20.v20190813
9.4.53
9.4.53

Open the chart page →

2,140
chart-bookhelm-deploy-book0.1.02 of 3See more

chart-book helm-deploy-book 0.1.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dannielkil/book-backend:lateste3b479a55a69
tomcat-embed-core@9.0.65
9.0.81
dannielkil/book-frontend:latest937993927694
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

8,618

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
golang.org/x/net@v0.8.0
0.17.0
2
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
golang.org/x/net@v0.7.0
0.17.0
2
istio/kubectl:1.5.10dbb7726d1bf0
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
2
istio/proxyv2:1.18.0757d28c24100
nghttp2@1.43.0-1build3
golang.org/x/net@v0.9.0
1.43.0-1ubuntu0.1
0.17.0
2
istio/proxyv2:1.10.3a78b7a165744
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0
2
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
0.17.0
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
golang.org/x/net@v0.7.0
1.52.0-1+deb12u1
0.17.0
2
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
0.17.0
2
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
2
jmalloc/echo-server:0.3.1e4eaee2c7998
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0
2
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
nghttp2@1.47.0-r0
golang.org/x/net@v0.5.0
1.47.0-r2
0.17.0
2
kodekloud/examplevotingapp_vote:v13a856afb02a3
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2
krtk6160/galoy-nostrcc82a694f818
nghttp2@1.51.0-r0
1.51.0-r2
2
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.17.0
2
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
nghttp2@1.47.0-r1
1.47.0-r2
2
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.51.0-r2
0.17.0
2
ldapaccountmanager/lam:8.0.1d46cf25d1dda
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2
library/cassandra:3.11.65aa8400b4b3b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
2
library/elasticsearch:7.17.35e6ac15bf6a5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
2
library/influxdb:2.6.1-alpine44a366dd7724
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
1.51.0-r2
0.17.0
2
library/mongo:4.2.358b25d51baa1
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
2
library/nginx:1.27.098f8ec75657d
nginx@1.27.0-2~bookworm
no fix listed
2
library/python:3.7eedf63967cdb
nghttp2@1.52.0-1
1.52.0-1+deb12u1
2
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
2
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
1.40.0-1ubuntu0.2
0.17.0
2
metabase/metabase:v0.45.21fb334ce4820
nghttp2@1.51.0-r0
1.51.0-r2
2
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.17.0
2
minio/operator:v4.3.754393e03f3b2
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
0:1.33.0-5.el8_8
0.17.0
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
nginx@1.27.0-2~bookworm
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
nghttp2@1.52.0-1
1.52.0-1+deb12u1
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
nghttp2@1.52.0-1
nginx@1.25.3-1~bookworm
1.52.0-1+deb12u1
no fix listed
2
nacos/nacos-server:v2.1.0dcf04549c6d7
tomcat-embed-core@9.0.38
9.0.81
2
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
nginx@1.27.4-1~bookworm
no fix listed
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
nginx@1.27.4-1~bookworm
no fix listed
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
nginx@1.27.4-1~bookworm
no fix listed
2
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
nginx@1.27.4-1~bookworm
no fix listed
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
nginx@1.27.4-1~bookworm
no fix listed
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
nginx@1.27.4-1~bookworm
no fix listed
2
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
2
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
2
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
2
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
0.17.0
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
0.17.0
2
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.17.0
2
passbolt/passbolt:3.4.0-ce-non-root655547e17263
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2
pecan/bety:5.4.1f825d480cd62
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.