StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,220
of 17,828 indexed, latest versions
Container images
2,579
deployed by those charts
Fix available
21 of 23
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,220 of 17,828 indexed charts deploy, on 2,579 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more589
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0220
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+8 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more183
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+15 moreno fix listed54
nginxapk1.20.2-r0, 1.22.0-r0, 1.22.0-r1, 1.22.1-r0+2 more1.20.2-r2, 1.22.1-r1, 1.24.0-r715
nodebitnami18.4.0-0, 18.7.0-1, 18.12.1-0, 18.13.0-0+2 more18.18.210
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
Node.jsbitnami20.4.0, 20.5.118.18.22
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+185 more0.17.01,633
tomcat-embed-coremaven8.5.4, 8.5.6, 8.5.11, 8.5.14+52 more8.5.94, 9.0.81, 10.1.14166
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+11 more9.4.53, 11.0.1721
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1717
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.47+8 more8.5.94, 9.0.8113
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-node-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,220 by stars
ChartLatestAffected imagesRadar Score
llo-docker-operatoreclipse-aeriosVerified publisher1.0.01 of 2See more

llo-docker-operator eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

2,194
llo-k8seclipse-aeriosVerified publisher1.1.02 of 2See more

llo-k8s eclipse-aerios 1.1.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
eclipseaerios/llo-k8s-operator:1.4.12b2c0cf26fd2
golang.org/x/net@v0.10.0
0.17.0
quay.io/brancz/kube-rbac-proxy:v0.14.158d91a5faaf8
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

2,166
mintakaeclipse-aeriosVerified publisher1.0.01 of 2See more

mintaka eclipse-aerios 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
fiware/mintaka:0.7.092a3c5cf43c0
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

11,492
openldap-stack-haeclipse-aeriosVerified publisher4.1.21 of 4See more

openldap-stack-ha eclipse-aerios 4.1.2

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

7,538
chartecr-toke-renew0.1.51 of 1See more

chart ecr-toke-renew 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
itzmanish/ecr-token-renew:latest02154d1c05b5
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0

Open the chart page →

2,820
marblerun-coordinatoredgelesssysVerified publisher0.5.01 of 1See more

marblerun-coordinator edgelesssys 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

11,079
pagesedgwarepages1.0.02 of 3See more

pages edgwarepages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,350
grafanaedu5.3.01 of 1See more

grafana edu 5.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0

Open the chart page →

3,200
prometheusedu11.6.03 of 6See more

prometheus edu 11.6.0

3 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.17.0
prom/prometheus:v2.19.0bfad037f95e5
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.17.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.17.0

Open the chart page →

8,495
education-componenteducation-component1.0.02 of 3See more

education-component education-component 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/education-component-nginx:latest38900bc76ee0
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ghcr.io/conductionnl/education-component-php:latestda6b05a1a601
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
1.46.0-r2
0.17.0

Open the chart page →

7,337
egeria-baseegeria-charts4.3.01 of 5See more

egeria-base egeria-charts 4.3.0

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

4,053
egeria-ctsegeria-charts4.3.01 of 3See more

egeria-cts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

4,040
egeria-ptsegeria-charts4.3.01 of 3See more

egeria-pts egeria-charts 4.3.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

4,040
odpi-egeria-labegeria-charts4.3.01 of 4See more

odpi-egeria-lab egeria-charts 4.3.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.37.052f376e64b9b
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8

Open the chart page →

4,040
eherkenning-uieherkenning-ui1.0.01 of 3See more

eherkenning-ui eherkenning-ui 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,518
mongodb-charteks-3-tier-app-chart0.1.01 of 1See more

mongodb-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

8,093
seafileeleksbai0.1.11 of 3See more

seafile eleksbai 0.1.1

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.106693911bcc40
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

90,228
Navidromeemmas-chartsVerified publisher0.0.41 of 1See more

Navidrome emmas-charts 0.0.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
deluan/navidrome:0.49.311a24da08977
golang.org/x/net@v0.5.0
0.17.0

Open the chart page →

2,838
parrot-mirroremmas-chartsVerified publisher1.0.01 of 1See more

parrot-mirror emmas-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

2,261
reddarkemmas-chartsVerified publisher0.0.21 of 1See more

reddark emmas-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/0xemma/reddark:main2a115e991894
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,001
elasticsearch-umbrellaempathyco0.8.121 of 3See more

elasticsearch-umbrella empathyco 0.8.12

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

10,691
emptyempty1.1.01 of 1See more

empty empty 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.22.0f0d28f204785
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

967
edge-operatoremqx-operator0.0.51 of 1See more

edge-operator emqx-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
emqx/edge-operator-controller:0.0.553865c1267d9
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

1,330
kube-ecp-stackemqx-operator2.5.13 of 16See more

kube-ecp-stack emqx-operator 2.5.1

3 of the 16 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
emqx/ecp-ui:2.5.1e33e9816f147
nginx@1.27.2-1~bookworm
no fix listed
emqx/emqx:4.4.1971db5ed95db3
nghttp2@1.46.0-r0
1.46.0-r2
library/telegraf:1.27507a3eecf809
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

24,087
kube-packetloss-exporterenixVerified publisher0.2.11 of 2See more

kube-packetloss-exporter enix 0.2.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

6,219
eoapi-supporteoapiVerified publisher0.1.75 of 7See more

eoapi-support eoapi 0.1.7

5 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
0.17.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
0.17.0
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
0.17.0
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

8,700
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
oscarsotosanchez/weatherservice:v1.0911ec961d10b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

27,563
eoloPlanteolo-plannerVerified publisher0.1.04 of 7See more

eoloPlant eolo-planner 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
mastercloudapps/planner:v1.2340a950b311b2
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
mastercloudapps/server:v2.23f3d24dfe2686
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
mastercloudapps/weatherservice:v1.23de859d29c116
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

28,008
eoloplannereoloplannerVerified publisher0.1.05 of 7See more

eoloplanner eoloplanner 0.1.0

5 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

32,681
eoloPlannerCommunicationsKubernetes3eoloplannercommunicationskuberneteshelmVerified publisher0.1.04 of 7See more

eoloPlannerCommunicationsKubernetes3 eoloplannercommunicationskuberneteshelm 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
mastercloudapps/planner:v1.2340a950b311b2
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
mastercloudapps/server:v2.23f3d24dfe2686
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
mastercloudapps/weatherservice:v1.23de859d29c116
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

28,008
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/mongo:4.2.12-bionic628741415fc9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2
oscarsotosanchez/weatherservice:v1.0911ec961d10b
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

27,529
eoloplannereoloplanner-molynx-gat0.1.04 of 7See more

eoloplanner eoloplanner-molynx-gat 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

28,763
eolo-plannereolo-planner-repo0.1.03 of 7See more

eolo-planner eolo-planner-repo 0.1.0

3 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

27,394
eoloplanteoloplant1.0.04 of 7See more

eoloplant eoloplant 1.0.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
mastercloudapps/planner:v1.2340a950b311b2
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
mastercloudapps/server:v2.23f3d24dfe2686
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
mastercloudapps/weatherservice:v1.23de859d29c116
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

28,008
eoloplantseoloplants-urjcVerified publisher0.1.04 of 7See more

eoloplants eoloplants-urjc 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

28,034
servereoloserverVerified publisher0.1.05 of 7See more

server eoloserver 0.1.0

5 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
codeurjc/planner:v1.0800cf520c245
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
codeurjc/server:v1.0310bea5b1ee7
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
codeurjc/toposervice:v1.09fb4c11e6a49
golang.org/x/net@v0.7.0
0.17.0
codeurjc/weatherservice:v1.0b9e2f7234349
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
library/mongo:5.0.6-focal8e70544b6c76
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

32,681
download-from-github-repoeosc-lot-1Verified publisher0.1.01 of 2See more

download-from-github-repo eosc-lot-1 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

993
flywayeosc-lot-1Verified publisher0.7.01 of 3See more

flyway eosc-lot-1 0.7.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
flyway/flyway:9.1545b5d7cdc75a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

70,422
postgresql-verify-backupeosc-lot-1Verified publisher0.2.01 of 3See more

postgresql-verify-backup eosc-lot-1 0.2.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
postgis/postgis:15-3.3-alpine4738bee21eb6
nghttp2@1.55.1-r0
1.57.0-r0

Open the chart page →

2,062
rabbitmq-usereosc-lot-1Verified publisher0.1.01 of 1See more

rabbitmq-user eosc-lot-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/eosc-lot-1/curl-jq:8156beafae7ca
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

970
epinio-uiepinioVerified publisher1.7.21 of 1See more

epinio-ui epinio 1.7.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/net@v0.0.0-20220826154423-83b083e8dc8b
0.17.0

Open the chart page →

1,694
upgrade-responderepinioVerified publisher0.2.02 of 5See more

upgrade-responder epinio 0.2.0

2 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
curlimages/curl:7.85.09fab1b73f45e
nghttp2@1.46.0-r0
1.46.0-r2
grafana/grafana:10.1.50679e877ba20
golang.org/x/net@v0.12.0
0.17.0

Open the chart page →

7,469
admin-console-operatorepmdedpVerified publisher2.14.02 of 2See more

admin-console-operator epmdedp 2.14.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/admin-console-operator:2.14.090f9921d8d58
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
0.17.0
epamedp/edp-admin-console:2.14.0616c678ba3e7
golang.org/x/net@v0.0.0-20211029224645-99673261e6eb
0.17.0

Open the chart page →

4,311
edp-argocd-operatorepmdedpVerified publisher0.2.01 of 1See more

edp-argocd-operator epmdedp 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/edp-argocd-operator:0.2.0976a662a5e72
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

1,575
edp-tekton-interceptorepmdedpVerified publisher0.2.41 of 1See more

edp-tekton-interceptor epmdedp 0.2.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/edp-tekton:0.2.4924939850655
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

1,352
perf-operatorepmdedpVerified publisher2.13.01 of 1See more

perf-operator epmdedp 2.13.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/perf-operator:2.13.0bd2079b7bfcb
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,114
reconcilerepmdedpVerified publisher2.12.01 of 1See more

reconciler epmdedp 2.12.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/reconciler:2.12.0d33e938b6d59
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
0.17.0

Open the chart page →

2,182
codebase-operatorepmdedp-devVerified publisher2.12.0-MDTU-DDM-SNAPSHOT.101 of 1See more

codebase-operator epmdedp-dev 2.12.0-MDTU-DDM-SNAPSHOT.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
0.17.0

Open the chart page →

2,828
gerrit-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.21 of 1See more

gerrit-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
0.17.0

Open the chart page →

2,814
jenkins-operatorepmdedp-devVerified publisher2.11.0-MDTU-DDM-SNAPSHOT.11 of 1See more

jenkins-operator epmdedp-dev 2.11.0-MDTU-DDM-SNAPSHOT.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
golang.org/x/net@v0.0.0-20210928044308-7d9f5e0b762b
0.17.0

Open the chart page →

2,269

Container images carrying it

2,579 by charts deploying them

A fixed version is listed for 21 of the 23 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/pushgateway:v1.6.05111de00e969
golang.org/x/net@v0.10.0
0.17.0
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
nghttp2@1.43.0-5.el9
golang.org/x/net@v0.11.0
0:1.43.0-5.el9_2.1
0.17.0
1
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.17.3-2.module+el8.4.0+11738+3bd42762
nodejs-nodemon@2.0.3-1.module+el8.3.0+6519+9f98ed83
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:3.0.1-1.module+el8.8.0+19764+7eed1ca3
0.17.0
1
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
quay.io/sergeyshevch/s3manager:feature_refactoringff59fcdf44eb
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
quay.io/skopeo/stable:v1.134853591bd1d2
golang.org/x/net@v0.11.0
0.17.0
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
quay.io/solo-io/certgen:0.0.0-forkb17a8c7d1f32
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
quay.io/solo-io/gloo-envoy-wrapper:0.0.0-fork26ae185e835a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
quay.io/spotahome/redis-operator:latest8c772955184e
golang.org/x/net@v0.8.0
0.17.0
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
tomcat-embed-core@9.0.46
9.0.81
1
quay.io/strimzi/operator:0.32.0c5e0e5dca750
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/net@v0.10.0
0.17.0
1
quay.io/thanos/thanos:v0.17.1e362f02ed304
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
1
quay.io/tigera/operator:v1.20.1379efe0c2541
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
quay.io/tigera/operator:v1.15.1c6591da87aa8
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
quay.io/uswitch/kiam:v4.0be3a5846922d
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.17.0
1
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
golang.org/x/net@v0.5.0
0.17.0
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.11826b984e75d4
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.17.0
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
registry.gitlab.com/bitspur/rock8s/easy-olm-operator:0.0.1779454fea06c
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
golang.org/x/net@v0.13.0
0.17.0
1
registry.gitlab.com/bitspur/rock8s/resource-binding-operator:0.1.063cf51392ce7
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/net@v0.0.0-20180811021610-c39426892332
0.17.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_4.1
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0:1.33.0-5.el8_8
0.17.0
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
golang.org/x/net@v0.14.0
0.17.0
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0:1.33.0-5.el8_8
0.17.0
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/net@v0.13.0
0.17.0
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
registry.k8s.io/gateway-api/admission-server:v0.7.1fe43ee5176a8
golang.org/x/net@v0.7.0
0.17.0
1
registry.k8s.io/git-sync/git-sync:v3.6.96fa9042f6128
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
nghttp2@1.51.0-r0
golang.org/x/net@v0.5.0
1.51.0-r2
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
nghttp2@1.51.0-r0
golang.org/x/net@v0.8.0
1.51.0-r2
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
1.47.0-r2
0.17.0
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.