StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,220
of 17,828 indexed, latest versions
Container images
2,579
deployed by those charts
Fix available
21 of 23
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,220 of 17,828 indexed charts deploy, on 2,579 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more589
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0220
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+8 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more183
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+15 moreno fix listed54
nginxapk1.20.2-r0, 1.22.0-r0, 1.22.0-r1, 1.22.1-r0+2 more1.20.2-r2, 1.22.1-r1, 1.24.0-r715
nodebitnami18.4.0-0, 18.7.0-1, 18.12.1-0, 18.13.0-0+2 more18.18.210
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
Node.jsbitnami20.4.0, 20.5.118.18.22
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+185 more0.17.01,633
tomcat-embed-coremaven8.5.4, 8.5.6, 8.5.11, 8.5.14+52 more8.5.94, 9.0.81, 10.1.14166
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+11 more9.4.53, 11.0.1721
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1717
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.47+8 more8.5.94, 9.0.8113
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-node-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,220 by stars
ChartLatestAffected imagesRadar Score
carettagroundcover0.0.163 of 3See more

caretta groundcover 0.0.16

3 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
quay.io/groundcover/grafana:9.3.18c65b333a3d3
golang.org/x/net@v0.1.0
0.17.0
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

6,865
hawkhawk1.1.52 of 4See more

hawk hawk 1.1.5

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
golang.org/x/net@v0.0.0-20211118161319-6a13c67c3ce4
0.17.0
ghcr.io/privacyengineering/hawk-monitor:master13309f068a56
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

13,784
seata-serverheidaodageshiwoVerified publisher1.0.01 of 1See more

seata-server heidaodageshiwo 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
seataio/seata-server:1.5.1ee1ed55f4144
tomcat-embed-core@9.0.55
9.0.81

Open the chart page →

5,621
jenkinshelm-chart-to-deploy-jenkins0.1.01 of 1See more

jenkins helm-chart-to-deploy-jenkins 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
anuja9431/jenkins-image:v1994f35723cb4
http2-common@9.4.41.v20210516
http2-server@9.4.41.v20210516
9.4.53
9.4.53

Open the chart page →

4,154
helm-operatorhelm-operatorVerified publisher0.0.21 of 1See more

helm-operator helm-operator 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bsgrigorov/helm-operator:latest45ab095f09c8
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

6,990
helmuphelmupVerified publisher0.1.01 of 3See more

helmup helmup 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

16,732
cratedb-adapter-v2hmdmph0.2.11 of 1See more

cratedb-adapter-v2 hmdmph 0.2.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
crate/crate_adapter:latestb8d89fa5d19b
golang.org/x/net@v0.0.0-20210423184538-5f58ad60dda6
0.17.0

Open the chart page →

2,922
holoinsightholoinsight0.2.54 of 6See more

holoinsight holoinsight 0.2.5

4 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ceresdb/ceresdb-server:v1.0.053b2d0dbba1f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
holoinsight/otelcontribcol:latest42ba8dc3113c
nghttp2@1.55.1-r0
golang.org/x/net@v0.8.0
1.57.0-r0
0.17.0
holoinsight/server:latest88978988756b
tomcat-embed-core@9.0.60
9.0.81
library/elasticsearch:7.16.18d5fd89230d7
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

27,944
holoinsight-agentholoinsight0.2.51 of 2See more

holoinsight-agent holoinsight 0.2.5

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
holoinsight/agent:latest5c3994e742f8
golang.org/x/net@v0.5.0
0.17.0

Open the chart page →

1,805
demoryhuseyinbabalOfficialVerified publisher0.7.01 of 1See more

demory huseyinbabal 0.7.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
golang.org/x/net@v0.0.0-20210907225631-ff17edfbf26d
0.17.0

Open the chart page →

1,580
ilum-coreilumOfficialVerified publisher6.7.31 of 5See more

ilum-core ilum 6.7.3

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ilum/mongodb:6.0.542b6d774c37d
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

3,560
inbucketinbucketVerified publisher2.5.01 of 1See more

inbucket inbucket 2.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
inbucket/inbucket:3.0.01f10a0efea69
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0

Open the chart page →

2,168
elasticinseefrlab2.2.02 of 2See more

elastic inseefrlab 2.2.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
library/kibana:7.17.3e2e2031c15be
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

17,521
supersetinseefrlab1.4.01 of 4See more

superset inseefrlab 1.4.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

7,137
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

71,989
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

72,063
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

72,009
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

72,009
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
nghttp2@1.30.0-1ubuntu1
golang.org/x/net@v0.0.0-20210323141857-08027d57d8cf
1.30.0-1ubuntu1+esm2
0.17.0

Open the chart page →

72,290
istio-ratelimitistio-ratelimitVerified publisher0.0.51 of 2See more

istio-ratelimit istio-ratelimit 0.0.5

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:4d2efd61ede09a75a84c
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
0.17.0

Open the chart page →

1,820
statpingitscontainedVerified publisher0.1.91 of 1See more

statping itscontained 0.1.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
statping/statping:v0.90.6532f26fffca46
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.17.0

Open the chart page →

3,539
traefik-forward-authitscontainedVerified publisher1.0.21 of 1See more

traefik-forward-auth itscontained 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.17.0

Open the chart page →

2,235
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0:1.33.0-4.el8_6.1
0.17.0

Open the chart page →

9,413
jmeterjmeterVerified publisher1.2.51 of 1See more

jmeter jmeter 1.2.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
liukunup/jmeter:5.59c079617a81b
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

2,069
forecastlejmmaloney41.1.1201 of 1See more

forecastle jmmaloney4 1.1.120

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
stakater/forecastle:v1.0.13886b24cdef409
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

1,814
hncjouveVerified publisher0.8.31 of 1See more

hnc jouve 0.8.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-multitenancy/hnc-manager:v1.1.08ab8229f6a89
golang.org/x/net@v0.3.0
0.17.0

Open the chart page →

1,079
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

3,383
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2

Open the chart page →

5,344
giteakeyporttech0.2.101 of 4See more

gitea keyporttech 0.2.10

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gitea/gitea:1.12.485416d6f65fe
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.17.0

Open the chart page →

5,410
kokukokuVerified publisher1.0.01 of 7See more

koku koku 1.0.0

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
http2-common@9.4.34.v20201102
9.4.53

Open the chart page →

11,404
ks-corekubeblocksVerified publisher1.1.31 of 5See more

ks-core kubeblocks 1.1.3

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubesphere/kubectl:v1.27.1649b445b1b732
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

4,740
kubefedkubefed0.10.01 of 2See more

kubefed kubefed 0.10.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/kubernetes-multicluster/kubefed:v0.10.0c4635c95730e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0

Open the chart page →

2,427
kubegems-localkubegemsOfficial1.24.101 of 2See more

kubegems-local kubegems 1.24.10

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubegems/kubectl:latestc3b4be9a54f5
nghttp2@1.51.0-r0
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
1.51.0-r2
0.17.0

Open the chart page →

6,109
kubernetes-stateless-chartkubernetes-stateless-chart1.0.31 of 1See more

kubernetes-stateless-chart kubernetes-stateless-chart 1.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

3,285
juicefskubesphere-stable0.16.21 of 4See more

juicefs kubesphere-stable 0.16.2

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.20.043978fc60798
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

2,523
mesherykubesphere-stable0.5.06 of 13See more

meshery kubesphere-stable 0.5.0

6 of the 13 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
layer5/meshery-app-mesh:stable-latest77d59943b3d6
golang.org/x/net@v0.2.0
0.17.0
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
golang.org/x/net@v0.0.0-20190827160401-ba9fcec4b297
0.17.0
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
golang.org/x/net@v0.9.0
0.17.0
layer5/meshery-nsm:stable-latestebd6a8faf21f
golang.org/x/net@v0.0.0-20200822124328-c89045814202
0.17.0
layer5/meshery-osm:stable-latestec898e5786c6
golang.org/x/net@v0.5.0
0.17.0
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
golang.org/x/net@v0.9.0
0.17.0

Open the chart page →

24,965
aws-efs-csi-driverkubesphere-testVerified publisher0.1.01 of 3See more

aws-efs-csi-driver kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.17.0

Open the chart page →

2,613
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

7,810
kube-state-metricskubestar-state-metricsVerified publisher0.1.101 of 1See more

kube-state-metrics kubestar-state-metrics 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

1,576
kube-vault-controllerkube-vault-controller1.2.01 of 1See more

kube-vault-controller kube-vault-controller 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,551
kubmeta-libkubmeta3.1.121 of 1See more

kubmeta-lib kubmeta 3.1.12

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.212bcabc23b454
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

1,127
kubemodkubmod0.5.22 of 2See more

kubemod kubmod 0.5.2

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.19.11f8154f7e80c
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.17.0
kubemod/kubemod-crt:v1.3.0028347c9fa77
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0

Open the chart page →

4,545
kubeservice-cosign-webhookkubservice-chartsVerified publisher1.1.15 of 5See more

kubeservice-cosign-webhook kubservice-charts 1.1.1

5 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
golang.org/x/net@v0.11.0
0.17.0
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
0.17.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
0.17.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
0.17.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

7,135
kubeservice-cpupools-controllerkubservice-chartsVerified publisher0.1.12 of 2See more

kubeservice-cpupools-controller kubservice-charts 0.1.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dongjiang1989/cpusets-controller:v1.1.1dc5bd483874c
golang.org/x/net@v0.10.0
0.17.0
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

3,130
kubeservice-custom-limitrangekubservice-chartsVerified publisher1.3.04 of 5See more

kubeservice-custom-limitrange kubservice-charts 1.3.0

4 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
0.17.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
0.17.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
0.17.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

6,128
kubeservice-namespace-node-affinitykubservice-chartsVerified publisher1.1.25 of 5See more

kubeservice-namespace-node-affinity kubservice-charts 1.1.2

5 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dongjiang1989/ns-node-affinity:latest451f7823723c
golang.org/x/net@v0.7.0
0.17.0
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
golang.org/x/net@v0.15.0
0.17.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
golang.org/x/net@v0.15.0
0.17.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
golang.org/x/net@v0.15.0
0.17.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

6,913
kubeservice-scheduler-pluskubservice-chartsVerified publisher0.2.11 of 2See more

kubeservice-scheduler-plus kubservice-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,804
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

12,552
kube-fencingkvaps2.4.11 of 2See more

kube-fencing kvaps 2.4.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kube-fencing-controller:v2.4.0313edfec2fca
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

2,539
linstorkvaps1.14.04 of 11See more

linstor kvaps 1.14.0

4 of the 11 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
golang.org/x/net@v0.0.0-20200226121028-0de0cce0169b
0.17.0
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.17.0

Open the chart page →

15,581

Container images carrying it

2,579 by charts deploying them

A fixed version is listed for 21 of the 23 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/pushgateway:v1.6.05111de00e969
golang.org/x/net@v0.10.0
0.17.0
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
nghttp2@1.43.0-5.el9
golang.org/x/net@v0.11.0
0:1.43.0-5.el9_2.1
0.17.0
1
quay.io/redhat-cop/cert-utils-operator:v1.3.120290e7b2800a
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
1
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
nghttp2@1.33.0-3.el8_2.1
nodejs@1:14.17.3-2.module+el8.4.0+11738+3bd42762
nodejs-nodemon@2.0.3-1.module+el8.3.0+6519+9f98ed83
golang.org/x/net@v0.0.0-20200927032502-5d4f70055728
0:1.33.0-4.el8_4.1
1:16.20.2-3.module+el8.8.0+20386+0b1f3093
0:3.0.1-1.module+el8.8.0+19764+7eed1ca3
0.17.0
1
quay.io/rimusz/hostpath-provisioner:v0.2.587f0398ec7ff
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
quay.io/sergeyshevch/s3manager:feature_refactoringff59fcdf44eb
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
quay.io/skopeo/stable:v1.134853591bd1d2
golang.org/x/net@v0.11.0
0.17.0
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
quay.io/solo-io/certgen:0.0.0-forkb17a8c7d1f32
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
quay.io/solo-io/gloo-envoy-wrapper:0.0.0-fork26ae185e835a
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
quay.io/spotahome/redis-operator:latest8c772955184e
golang.org/x/net@v0.8.0
0.17.0
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
tomcat-embed-core@9.0.46
9.0.81
1
quay.io/strimzi/operator:0.32.0c5e0e5dca750
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
quay.io/superq/smokeping-prober:v0.7.125d07dfc1d7e
golang.org/x/net@v0.10.0
0.17.0
1
quay.io/thanos/thanos:v0.17.1e362f02ed304
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
1
quay.io/tigera/operator:v1.20.1379efe0c2541
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
quay.io/tigera/operator:v1.15.1c6591da87aa8
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
quay.io/uswitch/kiam:v4.0be3a5846922d
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.17.0
1
quay.io/vouch/vouch-proxy:0.39d34e220de3cf
golang.org/x/net@v0.5.0
0.17.0
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-5.el8_8
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.11826b984e75d4
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0
1
registry.gitlab.com/autokubeops/kube-image-webhook:v0.2.0fcf464708a21
golang.org/x/net@v0.0.0-20211216030914-fe4d6282115f
0.17.0
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
1
registry.gitlab.com/bitspur/rock8s/easy-olm-operator:0.0.1779454fea06c
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
golang.org/x/net@v0.13.0
0.17.0
1
registry.gitlab.com/bitspur/rock8s/resource-binding-operator:0.1.063cf51392ce7
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/net@v0.0.0-20180811021610-c39426892332
0.17.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_4.1
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210805182204-aaa1db679c0d
0:1.33.0-5.el8_8
0.17.0
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
golang.org/x/net@v0.14.0
0.17.0
1
registry.gitlab.com/purelb/purelb/allocator:v0.0.0-106-ipv6-lbip-052cedab9d1fcb78f529
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0:1.33.0-5.el8_8
0.17.0
1
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
golang.org/x/net@v0.13.0
0.17.0
1
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
registry.k8s.io/gateway-api/admission-server:v0.7.1fe43ee5176a8
golang.org/x/net@v0.7.0
0.17.0
1
registry.k8s.io/git-sync/git-sync:v3.6.96fa9042f6128
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
nghttp2@1.52.0-1
1.52.0-1+deb12u1
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
nghttp2@1.51.0-r0
golang.org/x/net@v0.5.0
1.51.0-r2
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.2.15516d103a9c2
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
nghttp2@1.51.0-r0
golang.org/x/net@v0.8.0
1.51.0-r2
0.17.0
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
1.47.0-r2
0.17.0
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.