StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,220
of 17,828 indexed, latest versions
Container images
2,579
deployed by those charts
Fix available
21 of 23
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,220 of 17,828 indexed charts deploy, on 2,579 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more589
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0220
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+8 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more183
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+15 moreno fix listed54
nginxapk1.20.2-r0, 1.22.0-r0, 1.22.0-r1, 1.22.1-r0+2 more1.20.2-r2, 1.22.1-r1, 1.24.0-r715
nodebitnami18.4.0-0, 18.7.0-1, 18.12.1-0, 18.13.0-0+2 more18.18.210
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
Node.jsbitnami20.4.0, 20.5.118.18.22
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+185 more0.17.01,633
tomcat-embed-coremaven8.5.4, 8.5.6, 8.5.11, 8.5.14+52 more8.5.94, 9.0.81, 10.1.14166
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+11 more9.4.53, 11.0.1721
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1717
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.47+8 more8.5.94, 9.0.8113
akka-http-core_2.12maven10.1.1110.5.31
OSV records
ALPINE-CVE-2023-44487BIT-node-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,220 by stars
ChartLatestAffected imagesRadar Score
vaultintelVerified publisher0.8.12 of 2See more

vault intel 0.8.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/vault:1.12.18de4d5f31b38
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
hashicorp/vault-k8s:1.1.0844337076b72
golang.org/x/net@v0.0.0-20221004154528-8021a29435af
0.17.0

Open the chart page →

4,489
interbtc-hydrainterlay0.1.151 of 4See more

interbtc-hydra interlay 0.1.15

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
subsquid/hydra-indexer:5.0.0-alpha.37a7f8b9bad7ee
nghttp2@1.46.0-r0
1.46.0-r2

Open the chart page →

6,853
gravity-initinvisiblVerified publisher1.0.91 of 1See more

gravity-init invisibl 1.0.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
invisibl/gravity-init:v1.0.91a970f84178b
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.17.0

Open the chart page →

2,008
identity-managerinvisiblVerified publisher1.0.01 of 1See more

identity-manager invisibl 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
invisibl/identity-manager:1.0.01029f4fe20eb
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0

Open the chart page →

2,164
karpenteriometeVerified publisher0.19.31 of 1See more

karpenter iomete 0.19.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/karpenter/controller:v0.19.3f0e5ab60b2df
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

1,556
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
nghttp2@1.43.0-1build3
golang.org/x/net@v0.9.0
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

5,614
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
nghttp2@1.43.0-1build3
golang.org/x/net@v0.9.0
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

5,614
traefikitscontainedVerified publisher9.18.41 of 1See more

traefik itscontained 9.18.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/traefik:2.4.8eda951fd29a8
golang.org/x/net@v0.0.0-20210220033124-5f55cee0dc0d
0.17.0

Open the chart page →

3,350
adguard-homejacobcolvinVerified publisher0.4.01 of 2See more

adguard-home jacobcolvin 0.4.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
adguard/adguardhome:v0.107.3843ec119419a9
golang.org/x/net@v0.15.0
0.17.0

Open the chart page →

1,605
inlets-clientjacobcolvinVerified publisher0.1.21 of 1See more

inlets-client jacobcolvin 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0

Open the chart page →

1,754
inlets-serverjacobcolvinVerified publisher0.1.11 of 1See more

inlets-server jacobcolvin 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/cubed-it/inlets:4.0.0f02325f099bc
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0

Open the chart page →

1,754
opencloudjacobcolvinVerified publisher0.2.36 of 13See more

opencloud jacobcolvin 0.2.3

6 of the 13 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
nginx@1.27.4-1~bookworm
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
nginx@1.27.4-1~bookworm
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
nginx@1.27.4-1~bookworm
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
nginx@1.27.4-1~bookworm
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
nginx@1.27.4-1~bookworm
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
nginx@1.27.4-1~bookworm
no fix listed

Open the chart page →

44,581
rclonejacobcolvinVerified publisher1.0.11 of 1See more

rclone jacobcolvin 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rclone/rclone:1.63.008e1af3c8814
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

2,151
twitch-predictions-recorderjacobcolvinVerified publisher0.1.01 of 1See more

twitch-predictions-recorder jacobcolvin 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
golang.org/x/net@v0.1.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

2,671
koptimizejaconiVerified publisher0.5.42 of 2See more

koptimize jaconi 0.5.4

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
alpine/k8s:1.27.321b24e6bf801
nghttp2@1.53.0-r0
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
1.57.0-r0
0.17.0
ghcr.io/jaconi-io/koptimize:1.2.5aca1bbd609b6
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

5,741
mini-infrajaeki0.1.01 of 4See more

mini-infra jaeki 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/metallb/controller:v0.13.101b33357b3595
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,747
javascriptweeklyjavascriptweekly2.1.01 of 1See more

javascriptweekly javascriptweekly 2.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
zufardhiyaulhaq/javascriptweekly:v2.1.086424bd0b2a4
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0

Open the chart page →

1,238
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
nghttp2@1.33.0-1.el8_0.1
0:1.33.0-3.el8_1.2

Open the chart page →

9,856
jx-app-athensjenkins-x0.0.181 of 1See more

jx-app-athens jenkins-x 0.0.18

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/net@v0.0.0-20191027093000-83d349e8ac1a
0.17.0

Open the chart page →

4,233
jx-app-flaggerjenkins-x0.0.52 of 2See more

jx-app-flagger jenkins-x 0.0.5

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:6.5.1befcd84da2c1
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.17.0
weaveworks/flagger:1.0.0-rc.5174307de1b36
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.17.0

Open the chart page →

6,037
knative-servingjenkins-x0.19.124 of 4See more

knative-serving jenkins-x 0.19.12

4 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activatordigest-pinned1e3db4f2eeed
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdigest-pinneddb6ceff2aab4
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0
gcr.io/knative-releases/knative.dev/serving/cmd/controllerdigest-pinnedb2cd45b8a8a4
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhookdigest-pinnedd27b4495ccc3
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0

Open the chart page →

9,729
nexusjenkins-x0.1.371 of 1See more

nexus jenkins-x 0.1.37

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-3.el8_2.2

Open the chart page →

12,898
ingress-nginxjfrog4.5.22 of 2See more

ingress-nginx jfrog 4.5.2

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
nghttp2@1.51.0-r0
golang.org/x/net@v0.5.0
1.51.0-r2
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

3,800
vaultjfrog0.25.02 of 2See more

vault jfrog 0.25.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hashicorp/vault:1.14.0b2177a8bfe85
golang.org/x/net@v0.10.0
0.17.0
hashicorp/vault-k8s:1.2.14500e988b7ce
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

3,981
alpine-torjfwenischVerified publisher1.1.01 of 1See more

alpine-tor jfwenisch 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jfwenisch/alpine-tor:latest9e6c229f953c
golang.org/x/net@v0.0.0-20190328230028-74de082e2cca
0.17.0

Open the chart page →

4,462
discord-experiencebotjfwenischVerified publisher0.7.41 of 1See more

discord-experiencebot jfwenisch 0.7.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

7,929
kafka-offset-lag-for-prometheusjhidalgo3-githubVerified publisher2.3.01 of 1See more

kafka-offset-lag-for-prometheus jhidalgo3-github 2.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jhidalgo3/kafka-offset-lag-for-prometheus:latest0390e155c46d
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

1,472
missing-container-metricsjimdo-missing-container-metrics0.5.01 of 1See more

missing-container-metrics jimdo-missing-container-metrics 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dmilhdef/missing-container-metrics:v0.21.0fada1a6e7638
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0

Open the chart page →

2,418
xxl-job-adminjoelee2012Verified publisher1.1.01 of 2See more

xxl-job-admin joelee2012 1.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
xuxueli/xxl-job-admin:2.4.0640093c35fd6
tomcat-embed-core@9.0.71
9.0.81

Open the chart page →

3,118
haven-complinacy-dashboardjolle-devVerified publisher1.0.01 of 2See more

haven-complinacy-dashboard jolle-dev 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

3,843
annotation-tooljtektVerified publisher0.1.51 of 2See more

annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/annotation-tool:ef974ad9abd817eb6845
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,310
image-storage-servicejtektVerified publisher0.4.32 of 4See more

image-storage-service jtekt 0.4.3

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/net@v0.14.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
nginx@1.27.2-1~bookworm
no fix listed

Open the chart page →

22,853
polygonal-annotation-tooljtektVerified publisher0.1.51 of 2See more

polygonal-annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/polygonal-annotation-tool:a3fa936056efd38500d6
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,226
shinsei-managerjtektVerified publisher0.2.03 of 8See more

shinsei-manager jtekt 0.2.0

3 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
nghttp2@1.52.0-1
1.52.0-1+deb12u1
moreillon/user-manager-front:v5.0.3b067dbbbb6af
nghttp2@1.52.0-1
nginx@1.25.3-1~bookworm
1.52.0-1+deb12u1
no fix listed
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
nginx@1.25.3-1~bookworm
no fix listed

Open the chart page →

64,552
time-series-storagejtektVerified publisher0.1.102 of 2See more

time-series-storage jtekt 0.1.10

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
nghttp2@1.52.0-1
1.52.0-1+deb12u1

Open the chart page →

16,692
firstchartjuanjmerono0.2.01 of 1See more

firstchart juanjmerono 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jmalloc/echo-server:0.3.1e4eaee2c7998
golang.org/x/net@v0.0.0-20210813160813-60bc85c4be6d
0.17.0

Open the chart page →

1,444
alertmanager-irc-relayjuppi880.0.11 of 1See more

alertmanager-irc-relay juppi88 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
maldridge/alertmanager-irc-relay:v0.4.1391de2b76128
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0

Open the chart page →

1,616
k10appk10app0.2.13 of 11See more

k10app k10app 0.2.1

3 of the 11 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/k10app/businit:latest94c9a3e799c2
nghttp2@1.51.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.51.0-r2
0.17.0
ghcr.io/k10app/frontend:latest066b5ac6b119
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ghcr.io/k10app/staticcache:lateste77805689a8e
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

10,168
multusk3s4.0.201+upv4.0.2-build20240208011 of 2See more

multus k3s 4.0.201+upv4.0.2-build2024020801

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rancher/hardened-multus-cni:v4.0.2-build202402087d0f41b72eb7
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

1,623
snapshot-controllerk3s1.6.1+up1.6.01 of 1See more

snapshot-controller k3s 1.6.1+up1.6.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rancher/mirrored-sig-storage-snapshot-controller:v6.1.0934863015367
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0

Open the chart page →

1,373
snapshot-validation-webhookk3s1.6.1+up1.6.01 of 1See more

snapshot-validation-webhook k3s 1.6.1+up1.6.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rancher/mirrored-sig-storage-snapshot-validation-webhook:v6.1.0deac027820ae
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0

Open the chart page →

1,373
traefikk3s20.3.1+up20.3.01 of 1See more

traefik k3s 20.3.1+up20.3.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rancher/mirrored-library-traefik:2.9.40842af6afcdf
golang.org/x/net@v0.0.0-20220927171203-f486391704dc
0.17.0

Open the chart page →

3,325
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

9,925
k8s-ondemand-proxyk8s-ondemand-proxy0.0.61 of 1See more

k8s-ondemand-proxy k8s-ondemand-proxy 0.0.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/k8s-ondemand-proxy:0.0.2078b25d48cf7
golang.org/x/net@v0.13.0
0.17.0

Open the chart page →

815
librephotosk8sonlabVerified publisher1.1.61 of 7See more

librephotos k8sonlab 1.1.6

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
alpine/k8s:1.22.600ac10bcb759
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20220107192237-5cfca573fb4d
1.46.0-r2
0.17.0

Open the chart page →

15,063
k8s-pausek8s-pause0.1.41 of 1See more

k8s-pause k8s-pause 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0

Open the chart page →

1,848
k8svault-controllerk8svault-controller0.1.21 of 1See more

k8svault-controller k8svault-controller 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/net@v0.0.0-20211108170745-6635138e15ea
0.17.0

Open the chart page →

1,886
kadeck-webkadeck0.6.01 of 1See more

kadeck-web kadeck 0.6.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
xeotek/kadeck:4.2.94c6b04d9ce55
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

7,421
kanbanapp-demokanbanapp-demo0.3.01 of 3See more

kanbanapp-demo kanbanapp-demo 0.3.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
sdandey/dandey-apps:kanban-board-kanban-appbef0f599737b
tomcat-embed-core@9.0.21
9.0.81

Open the chart page →

7,496
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

81,165

Container images carrying it

2,579 by charts deploying them

A fixed version is listed for 21 of the 23 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/net@v0.7.0
0.17.0
1
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.05658d0011a41
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.2ec5732e28f15
golang.org/x/net@v0.7.0
0.17.0
1
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.11.1e6a43c83ab16
golang.org/x/net@v0.8.0
0.17.0
1
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/sig-storage/csi-attacher:v3.5.0dd245051317e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
1
registry.k8s.io/sig-storage/csi-external-health-monitor-controller:v0.7.080b9ba94aa2a
golang.org/x/net@v0.0.0-20220802222814-0bcc04d9c69b
0.17.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
golang.org/x/net@v0.0.0-20201209123823-ac852fbbde11
0.17.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
golang.org/x/net@v0.13.0
0.17.0
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.17.0
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
golang.org/x/net@v0.4.0
0.17.0
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.