StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,107
of 17,790 indexed, latest versions
Container images
2,471
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,107 of 17,790 indexed charts deploy, on 2,471 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,572
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,107 by stars
ChartLatestAffected imagesRadar Score
sn-platform-slimstreamnative1.11.442 of 6See more

sn-platform-slim streamnative 1.11.44

2 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/net@v0.8.0
0.17.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

10,214
student-producerstudentproducerVerified publisher2.0.01 of 1See more

student-producer studentproducer 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
aroralalit/student-producer:1.0.02a094f597b36
tomcat-embed-core@9.0.75
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1

Open the chart page →

3,021
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
nghttp2@1.47.0-r1
1.47.0-r2

Open the chart page →

12,541
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
nghttp2@1.47.0-r1
1.47.0-r2

Open the chart page →

12,541
substra-frontendsubstraVerified publisher1.2.31 of 1See more

substra-frontend substra 1.2.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
nginx@1.25.4-1~bookworm
no fix listed

Open the chart page →

3,053
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,353
nocodbsudermanjr0.1.01 of 1See more

nocodb sudermanjr 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nocodb/nocodb:0.84.15f9b799933aa8
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.17.0

Open the chart page →

2,070
pagessunilb2590-pages1.0.02 of 3See more

pages sunilb2590-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
cludodsuperorbitalVerified publisher0.0.51 of 1See more

cludod superorbital 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
superorbital/cludod:0.0.2-alphad59732f61d6e
golang.org/x/net@v0.0.0-20220111093109-d55c255bac03
0.17.0

Open the chart page →

2,371
do-operatorsupporttools0.1.71 of 2See more

do-operator supporttools 0.1.7

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
digitalocean/do-operator:v0.1.65e5deb4db76e
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0

Open the chart page →

1,063
nfs-provisionersupporttools0.11.01 of 1See more

nfs-provisioner supporttools 0.11.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openebs/provisioner-nfs:0.11.04f41dd782761
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

2,680
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

12,100
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

12,712
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
nghttp2@1.40.0-1ubuntu0.1
nodejs@10.19.0~dfsg-3ubuntu1.3
golang.org/x/net@v0.8.0
1.40.0-1ubuntu0.2
10.19.0~dfsg-3ubuntu1.6+esm2
0.17.0

Open the chart page →

10,959
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

12,100
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
nghttp2@1.40.0-1ubuntu0.1
golang.org/x/net@v0.8.0
1.40.0-1ubuntu0.2
0.17.0

Open the chart page →

18,846
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
nodejs-nodemon@3.0.1-1.module+el8.8.0+19757+8ca87034
0:3.0.1-1.module+el8.8.0+19764+7eed1ca3

Open the chart page →

14,058
synadia-serversynadiaVerified publisher1.1.101 of 2See more

synadia-server synadia 1.1.10

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

1,970
agentssynapse0.1.303 of 9See more

agents synapse 0.1.30

3 of the 9 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.42.07d32a4eddec7
golang.org/x/net@v0.5.0
0.17.0
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/net@v0.7.0
0.17.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

7,272
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,822
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,711
ccm-hcloudsyself1.0.111 of 1See more

ccm-hcloud syself 1.0.11

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

1,712
hcloud-csisyself0.1.11 of 6See more

hcloud-csi syself 0.1.1

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:1.6.01475d525f9a4
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

2,917
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0

Open the chart page →

2,876
promtailt3n1.0.01 of 1See more

promtail t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0

Open the chart page →

2,828
tidewayst3n2.0.11 of 1See more

tideways t3n 2.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
t3nde/tideways:1.7.2777e008f764db
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,206
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,489
super-mariotechpreta0.1.11 of 1See more

super-mario techpreta 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nirmalnaveen/supermario:latest8541a39162f3
nghttp2@1.52.0-1
nginx@1.25.3-1~bookworm
1.52.0-1+deb12u1
no fix listed

Open the chart page →

6,321
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
http2-common@9.4.34.v20201102
9.4.53

Open the chart page →

4,240
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

4,222
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0

Open the chart page →

3,772
clickhousetemp-charts0.7.12 of 3See more

clickhouse temp-charts 0.7.1

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0

Open the chart page →

8,706
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

10,585
istio-ingresstemp-charts0.3.31 of 1See more

istio-ingress temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.088c6c693e67a
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

10,531
temporaltemporal0.28.97 of 13See more

temporal temporal 0.28.9

7 of the 13 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
temporalio/admin-tools:1.22.0836af062af30
nghttp2@1.55.1-r0
golang.org/x/net@v0.14.0
1.57.0-r0
0.17.0
temporalio/server:1.22.0ddeebf8bad8f
nghttp2@1.55.1-r0
golang.org/x/net@v0.14.0
1.57.0-r0
0.17.0
temporalio/ui:2.16.2af9c9349708f
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
0.17.0

Open the chart page →

21,040
echoserverteochenglim0.1.01 of 1See more

echoserver teochenglim 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jmalloc/echo-server:0.3.1e4eaee2c7998
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0

Open the chart page →

1,443
pagestest43221.0.02 of 3See more

pages test4322 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/shenyu-admin:2.4.2e8b7c4ddd069
tomcat-embed-core@9.0.29
9.0.81

Open the chart page →

12,516
webapp1test-helm-chart-10.1.01 of 1See more

webapp1 test-helm-chart-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
devopsjourney1/mywebapp:latestbd1ec6838570
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

1,469
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

39,273
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

28,944
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

28,515
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

28,990
vehicle-dashboardtest-vehi-dash0.1.02 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

2 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
library/mongo:5.0.217c81758cb295
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2

Open the chart page →

20,378
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
tomcat-embed-core@9.0.63
9.0.81
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
tomcat-embed-core@9.0.63
9.0.81
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
tomcat-embed-core@9.0.63
9.0.81
thingsboard/tb-node:3.4.1645f43b688f7
tomcat-embed-core@9.0.63
9.0.81

Open the chart page →

25,423
pagesthiru-pages1.0.02 of 3See more

pages thiru-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
mc-routerthl-chartsVerified publisher0.1.01 of 1See more

mc-router thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
itzg/mc-router:1.16.1bb552b59fb53
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
0.17.0

Open the chart page →

1,855
monitoringthl-chartsVerified publisher0.1.17 of 10See more

monitoring thl-charts 0.1.1

7 of the 10 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
0.17.0
grafana/loki:2.5.0f9ef133793af
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
grafana/promtail:2.4.2626900031c4e
golang.org/x/net@v0.0.0-20211101193420-4a448f8816b3
0.17.0
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
quay.io/prometheus/prometheus:v2.34.0b37103e03399
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

18,940
pagesthuy-pages1.0.02 of 3See more

pages thuy-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,242
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nginx/nginx-ingress:1.11.1eb5b4fd73325
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.17.0

Open the chart page →

6,888

Container images carrying it

2,471 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
iomesh/snapshot-controller:v6.2.2fb95b65bb88f
golang.org/x/net@v0.8.0
0.17.0
2
iomesh/zookeeper-operator:0.2.159b38b5c7a61d
golang.org/x/net@v0.7.0
0.17.0
2
istio/kubectl:1.5.10dbb7726d1bf0
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
2
istio/proxyv2:1.18.0757d28c24100
nghttp2@1.43.0-1build3
golang.org/x/net@v0.9.0
1.43.0-1ubuntu0.1
0.17.0
2
istio/proxyv2:1.10.3a78b7a165744
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0
2
jaegertracing/all-in-one:1.3104d224a9999b
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
0.17.0
2
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
nghttp2@1.52.0-1
golang.org/x/net@v0.7.0
1.52.0-1+deb12u1
0.17.0
2
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/net@v0.0.0-20190108225652-1e06a53dbb7e
0.17.0
2
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
2
jmalloc/echo-server:0.3.1e4eaee2c7998
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0
2
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
nghttp2@1.47.0-r0
golang.org/x/net@v0.5.0
1.47.0-r2
0.17.0
2
kodekloud/examplevotingapp_vote:v13a856afb02a3
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2
krtk6160/galoy-nostrcc82a694f818
nghttp2@1.51.0-r0
1.51.0-r2
2
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.17.0
2
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
nghttp2@1.47.0-r1
1.47.0-r2
2
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.51.0-r2
0.17.0
2
ldapaccountmanager/lam:8.0.1d46cf25d1dda
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2
library/cassandra:3.11.65aa8400b4b3b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
2
library/elasticsearch:7.17.35e6ac15bf6a5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
2
library/influxdb:2.6.1-alpine44a366dd7724
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
1.51.0-r2
0.17.0
2
library/mongo:4.2.358b25d51baa1
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
2
library/nginx:1.27.098f8ec75657d
nginx@1.27.0-2~bookworm
no fix listed
2
library/python:3.7eedf63967cdb
nghttp2@1.52.0-1
1.52.0-1+deb12u1
2
library/traefik:v2.57d5a6ae66572
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
2
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
1.40.0-1ubuntu0.2
0.17.0
2
metabase/metabase:v0.45.21fb334ce4820
nghttp2@1.51.0-r0
1.51.0-r2
2
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.17.0
2
minio/operator:v4.3.754393e03f3b2
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
0:1.33.0-5.el8_8
0.17.0
2
moreillon/group-manager-front:v3.3.1c9f85db3baa5
nginx@1.27.0-2~bookworm
no fix listed
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
nghttp2@1.52.0-1
1.52.0-1+deb12u1
2
moreillon/user-manager-front:v5.0.3b067dbbbb6af
nghttp2@1.52.0-1
nginx@1.25.3-1~bookworm
1.52.0-1+deb12u1
no fix listed
2
nacos/nacos-server:v2.1.0dcf04549c6d7
tomcat-embed-core@9.0.38
9.0.81
2
natsio/nats-box:0.11.09fbf7bf684e4
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
nginx@1.27.4-1~bookworm
no fix listed
2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
nginx@1.27.4-1~bookworm
no fix listed
2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
nginx@1.27.4-1~bookworm
no fix listed
2
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
nginx@1.27.4-1~bookworm
no fix listed
2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
nginx@1.27.4-1~bookworm
no fix listed
2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
nginx@1.27.4-1~bookworm
no fix listed
2
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
2
openebs/node-disk-operator:2.1.06afe2123c457
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
2
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
2
oryd/kratos:v1.0.0d06fc5845f63
golang.org/x/net@v0.8.0
0.17.0
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
golang.org/x/net@v0.9.0
0.17.0
2
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/net@v0.0.0-20190404232315-eb5bcb51f2a3
0.17.0
2
passbolt/passbolt:3.4.0-ce-non-root655547e17263
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2
pecan/bety:5.4.1f825d480cd62
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.