StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,787 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,787 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
nfs-server-provisionermesosphere0.6.11 of 1See more

nfs-server-provisioner mesosphere 0.6.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/net@v0.0.0-20190812203447-cdfb69ac37fc
0.17.0

Open the chart page →

2,806
nvidiamesosphere0.4.41 of 2See more

nvidia mesosphere 0.4.4

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
nvidia/dcgm-exporter:2.2.9-2.4.1-ubuntu20.0491b20b66d1cd
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0

Open the chart page →

10,478
prometheus-operatormesosphere12.11.133 of 8See more

prometheus-operator mesosphere 12.11.13

3 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.17.0

Open the chart page →

11,690
traefik2mesosphere9.18.01 of 1See more

traefik2 mesosphere 9.18.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/traefik:2.4.8eda951fd29a8
golang.org/x/net@v0.0.0-20210220033124-5f55cee0dc0d
0.17.0

Open the chart page →

3,341
azuredisk-csi-drivermesosphere-stable0.8.16 of 6See more

azuredisk-csi-driver mesosphere-stable 0.8.1

6 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
0.17.0
mcr.microsoft.com/oss/kubernetes-csi/csi-node-driver-registrar:v2.0.1fc5d14e9f26f
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
mcr.microsoft.com/oss/kubernetes-csi/csi-provisioner:v1.6.1667b1b1ea1e4
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
0.17.0
mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.1.07997e0f236bc
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.17.0
mcr.microsoft.com/oss/kubernetes-csi/livenessprobe:v2.2.0b7d82802cca8
golang.org/x/net@v0.0.0-20201216054612-986b41b23924
0.17.0

Open the chart page →

14,067
cert-manager-setupmesosphere-stable0.2.104 of 5See more

cert-manager-setup mesosphere-stable 0.2.10

4 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
golang.org/x/net@v0.5.0
0.17.0
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
golang.org/x/net@v0.5.0
0.17.0
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
golang.org/x/net@v0.5.0
0.17.0
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
golang.org/x/net@v0.5.0
0.17.0

Open the chart page →

7,179
dexmesosphere-stable2.14.11 of 5See more

dex mesosphere-stable 2.14.1

1 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
golang.org/x/net@v0.11.0
0.17.0

Open the chart page →

18,583
gatekeepermesosphere-stable0.6.111 of 2See more

gatekeeper mesosphere-stable 0.6.11

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0

Open the chart page →

3,034
gcpdisk-csi-drivermesosphere-stable0.7.31 of 7See more

gcpdisk-csi-driver mesosphere-stable 0.7.3

1 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
0.17.0

Open the chart page →

3,605
kafka-operatormesosphere-stable0.25.11 of 2See more

kafka-operator mesosphere-stable 0.25.1

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,241
karmamesosphere-stable2.0.31 of 1See more

karma mesosphere-stable 2.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
lmierzwa/karma:v0.70d417abe7ddb5
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

1,966
knativemesosphere-stable1.10.87 of 7See more

knative mesosphere-stable 1.10.8

7 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.10.2c2994c2b6c2c
golang.org/x/net@v0.7.0
0.17.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.10.28319aa662b49
golang.org/x/net@v0.7.0
0.17.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpa:v1.10.2eb612b929eaa
golang.org/x/net@v0.7.0
0.17.0
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
golang.org/x/net@v0.7.0
0.17.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.10.2f66c41ad7a73
golang.org/x/net@v0.7.0
0.17.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.10.27368aaddf2be
golang.org/x/net@v0.7.0
0.17.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.10.24305209ce498
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

7,479
kommandermesosphere-stable0.39.218 of 29See more

kommander mesosphere-stable 0.39.2

18 of the 29 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:6.6.0052147d7e0ec
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0
mesosphere/karma:v0.55-d2iq-proxy4693bb4e0814
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
golang.org/x/net@v0.0.0-20201202161906-c7110b5ffcbb
0.17.0
mesosphere/kubeaddons-addon-initializer:v0.2.8c10011f866f2
golang.org/x/net@v0.0.0-20191209160850-c0dbc17a3553
0.17.0
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
1.40.0-1ubuntu0.2
0.17.0
prom/prometheus:v2.19.2cd134bd4fca0
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.17.0
thanosio/thanos:v0.19.088276fcd1491
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0
thanosio/thanos:v0.15.0b12d5c31bf5a
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
golang.org/x/net@v0.0.0-20190311183353-d8887717615a
0.17.0
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.17.0
quay.io/thanos/thanos:v0.17.1e362f02ed304
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0

Open the chart page →

68,330
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.2.09f863160127b
golang.org/x/net@v0.0.0-20190613194153-d28f0bde5980
0.17.0

Open the chart page →

7,027
veleromesosphere-stable3.2.51 of 1See more

velero mesosphere-stable 3.2.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
golang.org/x/net@v0.7.0
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1

Open the chart page →

1,871
cortexmetakube0.6.02 of 2See more

cortex metakube 0.6.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.212bcabc23b454
nghttp2@1.43.0-1
1.43.0-1+deb11u1
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
0.17.0

Open the chart page →

4,107
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
nghttp2@1.40.0-1build1
golang.org/x/net@v0.0.0-20211020060615-d418f374d309
1.40.0-1ubuntu0.2
0.17.0

Open the chart page →

8,940
wg-access-servermglants0.4.71 of 1See more

wg-access-server mglants 0.4.7

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,745
gogsmhio0.9.21 of 2See more

gogs mhio 0.9.2

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gogs/gogs:0.12.1420d53bb7277
golang.org/x/net@v0.0.0-20191014212845-da9a3fd4c582
0.17.0

Open the chart page →

3,230
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
tomcat-embed-core@10.1.13
10.1.14

Open the chart page →

3,684
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
tomcat-embed-core@10.1.13
10.1.14

Open the chart page →

5,141
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
tomcat-embed-core@10.1.13
10.1.14

Open the chart page →

4,612
kube-agent-chartmiddleware-labsVerified publisher0.1.21 of 1See more

kube-agent-chart middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

1,799
middleware-odigosmiddleware-labsVerified publisher0.2.414 of 6See more

middleware-odigos middleware-labs 0.2.41

4 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

8,370
middleware-visionmiddleware-labsVerified publisher0.2.654 of 6See more

middleware-vision middleware-labs 0.2.65

4 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

8,361
mw-kube-agentmiddleware-labsVerified publisher0.1.21 of 1See more

mw-kube-agent middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
golang.org/x/net@v0.14.0
0.17.0

Open the chart page →

1,594
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:2.19.0cafa03b94dac
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

12,862
errbotmidokura-communityVerified publisher0.0.51 of 1See more

errbot midokura-community 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
errbotio/errbot:6.1.900ee4e0953ab
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

2,233
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.59
1.40.0-1ubuntu0.2
9.0.81

Open the chart page →

11,254
pulsarv2milvus-helm2.7.83 of 4See more

pulsarv2 milvus-helm 2.7.8

3 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
tomcat-embed-core@8.5.31
8.5.94
prom/prometheus:v2.17.242d2395cd719
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.17.0
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
golang.org/x/net@v0.0.0-20190923162816-aa69164e4478
0.17.0

Open the chart page →

15,855
minio-operatorminio-operator4.3.71 of 2See more

minio-operator minio-operator 4.3.7

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20210421230115-4e50805a0758
0:1.33.0-5.el8_8
0.17.0

Open the chart page →

6,085
MINTmint8.0.25 of 15See more

MINT mint 8.0.2

5 of the 15 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
nghttp2@1.46.0-r0
1.46.0-r2
mintproject/data-catalog-db:9be70359feabe03ed55bfdbf92c20a7e43ab928b9bf26fedd848
nghttp2@1.47.0-r0
1.47.0-r2
mintproject/mint-ui-lit:246a8771e8c043f8c1840d3c32262d3d6a9a553208c1a13c3397
nghttp2@1.47.0-r0
1.47.0-r2
mintproject/model-catalog-explorer:0b2f9f0a9124076aeb492add2f123d0757066f6bdeb80c93b4a9
nghttp2@1.47.0-r0
1.47.0-r2
postgis/postgis:10-3.2-alpine7e3e68a36d53
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

42,983
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

10,639
standard-application-stackmintel11.4.11 of 12See more

standard-application-stack mintel 11.4.1

1 of the 12 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
golang.org/x/net@v0.4.0
0.17.0

Open the chart page →

10,515
mitre-siphonmitre-siphon0.2.91 of 4See more

mitre-siphon mitre-siphon 0.2.9

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
tomcat-embed-core@10.1.8
10.1.14

Open the chart page →

3,083
cert-manager-webhook-duckdnsmmontesVerified publisher1.2.31 of 1See more

cert-manager-webhook-duckdns mmontes 1.2.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
golang.org/x/net@v0.0.0-20200822124328-c89045814202
0.17.0

Open the chart page →

2,847
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0:1.33.0-4.el8_4.1
0.17.0

Open the chart page →

7,775
echoperatormmontesVerified publisher0.0.21 of 1See more

echoperator mmontes 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0

Open the chart page →

1,826
mongodbmmontesVerified publisher0.5.01 of 1See more

mongodb mmontes 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/mongo:4.4.1305678ae4e5e1
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

7,148
corednsmoikot1.13.31 of 1See more

coredns moikot 1.13.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
coredns/coredns:1.7.073ca82b4ce82
golang.org/x/net@v0.0.0-20200324143707-d3edc9973b7e
0.17.0

Open the chart page →

2,547
smartthings-metricsmoikot0.1.01 of 1See more

smartthings-metrics moikot 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:0.1.08625f53aa9b7
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.17.0

Open the chart page →

1,744
smartthings-metrics-feat-log-detailsmoikot0.0.921 of 1See more

smartthings-metrics-feat-log-details moikot 0.0.92

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:feat-log-detailsfb8565140106
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.17.0

Open the chart page →

1,732
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

2,470
backendmojaloop0.1.03 of 6See more

backend mojaloop 0.1.0

3 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
nghttp2@1.43.0-1
1.43.0-1+deb11u1
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
golang.org/x/net@v0.0.0-20210726213435-c6fcb2dbf985
0.17.0
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.17.0

Open the chart page →

16,111
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

6,220
nginxmombe0903.0.11 of 1See more

nginx mombe090 3.0.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/nginx:1.22.0f0d28f204785
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

967
camera-viewermoreillonVerified publisher0.2.12 of 4See more

camera-viewer moreillon 0.2.1

2 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
moreillon/camera-viewer:lateste418cc694bd5
nginx@1.29.0-1~bookworm
no fix listed

Open the chart page →

11,694
face-recognitionmoreillonVerified publisher0.2.42 of 3See more

face-recognition moreillon 0.2.4

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

8,556
group-managermoreillonVerified publisher0.4.41 of 3See more

group-manager moreillon 0.4.4

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
moreillon/group-manager-front:v3.3.1c9f85db3baa5
nginx@1.27.0-2~bookworm
no fix listed

Open the chart page →

9,886
mqtt-loggermoreillonVerified publisher0.3.13 of 5See more

mqtt-logger moreillon 0.3.1

3 of the 5 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/net@v0.0.0-20220617184016-355a448f1bc9
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/net@v0.0.0-20220906165146-f3363e06e74c
nghttp2@1.43.0-1
0.17.0
1.43.0-1+deb11u1
moreillon/mqtt-logger-front:50030b8bfc4d12db1d3e
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

10,998

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
phntom/kochi:1.1.33b82358bd56e
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
2
phpipam/phpipam-cron:v1.5.2f770577cb946
nghttp2@1.46.0-r0
1.46.0-r2
2
phpipam/phpipam-www:v1.5.23c6fd1332aeb
nghttp2@1.46.0-r0
1.46.0-r2
2
piomin/sample-spring-kotlin-microservice:1.1871f784dd6bc
nghttp2@1.43.0-1build3
tomcat-embed-core@9.0.65
1.43.0-1ubuntu0.1
9.0.81
2
place1/wg-access-server:v0.4.62b2f3ea80ed6
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
2
postgis/postgis:15-3.3a2fc46b52819
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2
privatebin/pdo:1.3.500466418121c
nginx@1.20.2-r0
1.20.2-r2
2
prom/blackbox-exporter:v0.18.01ffc3f109eb3
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.17.0
2
prom/prometheus:v2.17.242d2395cd719
golang.org/x/net@v0.0.0-20200301022130-244492dfa37a
0.17.0
2
prom/prometheus:v2.37.98176adea328e
golang.org/x/net@v0.7.0
0.17.0
2
prom/prometheus:v2.21.0d43417c260e5
golang.org/x/net@v0.0.0-20200822124328-c89045814202
0.17.0
2
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.17.0
2
rancher/k3s:v1.26.0-k3s19380f5dbae9a
golang.org/x/net@v0.1.1-0.20221027164007-c63010009c80
0.17.0
2
ribbybibby/ssl-exporter:2.4.2718abe7f5e79
golang.org/x/net@v0.0.0-20220708220712-1185a9018129
0.17.0
2
rodolpheche/wiremock:2.26.03be08a386092
http2-common@9.4.20.v20190813
http2-server@9.4.20.v20190813
9.4.53
9.4.53
2
rookout/controller:latest4451a6f6b8ec
golang.org/x/net@v0.13.0
0.17.0
2
rookout/data-on-prem:latest51c0fce64467
golang.org/x/net@v0.13.0
0.17.0
2
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
tomcat-embed-core@9.0.55
9.0.81
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
tomcat-embed-core@9.0.55
9.0.81
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
tomcat-embed-core@9.0.55
9.0.81
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
tomcat-embed-core@9.0.55
9.0.81
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
tomcat-embed-core@9.0.55
9.0.81
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
tomcat-embed-core@9.0.55
9.0.81
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
tomcat-embed-core@9.0.55
9.0.81
2
scorpiobroker/scorpio:config-server_1.1.0c46c1517e523
tomcat-embed-core@9.0.26
nghttp2@1.43.0-1
9.0.81
1.43.0-1+deb11u1
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
tomcat-embed-core@9.0.55
9.0.81
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
tomcat-embed-core@9.0.55
9.0.81
2
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/net@v0.0.0-20191003171128-d98b1b443823
0.17.0
2
stakater/stakater-nordmart-review:1.0.35954d2be66e95
nghttp2@1.33.0-3.el8_2.1
tomcat-embed-core@9.0.65
0:1.33.0-4.el8_6.1
9.0.81
2
statping/statping:v0.90.74e874da513a5c
golang.org/x/net@v0.0.0-20200904194848-62affa334b73
0.17.0
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/net@v0.8.0
0.17.0
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
2
taigaio/taiga-front:latest570c8792ce80
nghttp2@1.51.0-r0
1.51.0-r2
2
temporalio/server:1.22.4c0a44c26397b
golang.org/x/net@v0.7.0
0.17.0
2
temporalio/ui:2.16.2af9c9349708f
nghttp2@1.53.0-r0
golang.org/x/net@v0.10.0
1.57.0-r0
0.17.0
2
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
0.17.0
2
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
0.17.0
2
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
2
uffizzi/controller:latest0344805f267b
golang.org/x/net@v0.12.0
0.17.0
2
vaultwarden/server:1.25.239f34c5159a2
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
2
voltha/voltha-rw-core:3.4.87a325316fe59
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.17.0
2
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/net@v0.0.0-20190620200207-3b0461eec859
0.17.0
2
xelalex/dregsy:0.4.3574054e1c417
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
2
yzhou442/equiz:latesta3f7ca69e28d
nghttp2@1.43.0-1
1.43.0-1+deb11u1
2
zhenghaoz/gorse-master:0.4.12033046b432ec
golang.org/x/net@v0.7.0
0.17.0
2
zhenghaoz/gorse-server:0.4.1239c565685b01
golang.org/x/net@v0.7.0
0.17.0
2
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
golang.org/x/net@v0.7.0
0.17.0
2

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.