StackRadar

CVE-2023-44487

HighKEV

Advisory

Published 10 Oct 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 10 Oct 2023
Charts affected
2,106
of 17,787 indexed, latest versions
Container images
2,470
deployed by those charts
Fix available
19 of 21
affected packages

Red Hat Enhancement Advisory: nginx:1.22 bug fix and enhancement update

Carried by container images the latest versions of 2,106 of 17,787 indexed charts deploy, on 2,470 images.

Affected packageAffected versionsFixed inImages
nghttp2deb1.30.0-1ubuntu1, 1.40.0-1build1, 1.40.0-1ubuntu0.1, 1.43.0-1+2 more1.30.0-1ubuntu1+esm2, 1.40.0-1ubuntu0.2, 1.43.0-1+deb11u1, 1.43.0-1ubuntu0.1+1 more551
nghttp2apk1.46.0-r0, 1.46.0-r1, 1.47.0-r0, 1.47.0-r1+5 more1.46.0-r2, 1.47.0-r2, 1.51.0-r2, 1.57.0-r0213
nghttp2rpm1.33.0-1.el8, 1.33.0-1.el8_0.1, 1.33.0-3.el8_2.1, 1.33.0-3.el8_2.2+7 more0:1.33.0-3.el8_1.2, 0:1.33.0-3.el8_2.2, 0:1.33.0-4.el8_4.1, 0:1.33.0-4.el8_6.1+6 more177
nginxdeb1.22.1-9, 1.22.1-9+deb12u2, 1.22.1-9+deb12u3, 1.22.1-9+deb12u4+14 moreno fix listed53
nginxapk1.20.2-r0, 1.22.0-r1, 1.22.1-r0, 1.24.0-r1+1 more1.20.2-r2, 1.22.1-r1, 1.24.0-r713
nodejsrpm1:12.18.2-1.module+el8.2.0+7233+61d664c1, 1:14.16.0-2.module+el8.3.0+10180+b92e1eb6, 1:14.17.3-2.module+el8.4.0+11738+3bd427621:16.20.2-3.module+el8.8.0+20386+0b1f30938
nodejs-packagingrpm23-3.module+el8.3.0+6519+9f98ed830:26-1.module+el8.8.0+19857+6d2a104d6
nodejsdeb8.10.0~dfsg-2ubuntu0.4, 10.19.0~dfsg-3ubuntu1, 10.19.0~dfsg-3ubuntu1.38.10.0~dfsg-2ubuntu0.4+esm6, 10.19.0~dfsg-3ubuntu1.6+esm24
nginxrpm1:1.14.1-9.module+el8.0.0+4108+af250afe, 1:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.20.1-13.el91:1.20.1-1.module+el8.8.0+20359+9bd89172.1, 1:1.22.1-1.module+el8.8.0+20355+6d9c8a63.1, 1:1.22.1-5.module+el9.3.0.z+20438+032561a03
nodejs-nodemonrpm1.18.3-1.module+el8.1.0+3369+37ae6a45, 2.0.3-1.module+el8.3.0+6519+9f98ed83, 3.0.1-1.module+el8.8.0+19757+8ca870340:3.0.1-1.module+el8.8.0+19764+7eed1ca33
lighttpdapk1.4.64-r01.4.73-r02
Apache Tomcatbitnami9.0.808.5.941
tomcatbitnami9.0.80-18.5.941
varnishapk7.3.1-r17.4.2-r01
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+183 more0.17.01,571
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+50 more8.5.94, 9.0.81, 10.1.14162
http2-commonmaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+10 more9.4.53, 11.0.1720
http2-servermaven9.4.8.v20171121, 9.4.11.v20180605, 9.4.20.v20190813, 9.4.27.v20200227+9 more9.4.53, 11.0.1716
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+7 more8.5.94, 9.0.8112
akka-http-core_2.12maven10.1.1110.5.31
varnishdeb7.5.0, 7.6.3-1~bookwormno fix listed2
OSV records
ALPINE-CVE-2023-44487BIT-tomcat-2023-44487DEBIAN-CVE-2023-44487RHEA-2023:6562RHSA-2023:5712RHSA-2023:5713RHSA-2023:5766RHSA-2023:5767RHSA-2023:5768RHSA-2023:5769RHSA-2023:5837RHSA-2023:5838RHSA-2023:5850RHSA-2023:6746RLSA-2023:5837UBUNTU-CVE-2023-44487GHSA-qppj-fm5r-hxr3DSA-5570-1openSUSE-SU-2024:13336-1SUSE-SU-2023:4200-1SUSE-SU-2023:4492-1
Also known as
BIT-apisix-2023-44487, BIT-aspnet-core-2023-44487, BIT-contour-2023-44487, BIT-dotnet-2023-44487, BIT-dotnet-sdk-2023-44487, BIT-envoy-2023-44487, BIT-golang-2023-44487, BIT-jenkins-2023-44487, BIT-kong-2023-44487, BIT-nginx-2023-44487, BIT-nginx-gateway-2023-44487, BIT-node-2023-44487, BIT-node-min-2023-44487, BIT-solr-2023-44487, BIT-varnish-2023-44487, RHSA-2023:5711, RHSA-2023:6120, USN-6505-1, USN-6754-1, USN-7469-3

Charts affected

2,106 by stars
ChartLatestAffected imagesRadar Score
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/identity-manager_kc:latest0df4b4fa899a
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_6.1

Open the chart page →

12,799
locationprocessingassist-iot-location-processing1.0.02 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1
postgis/postgis:15-3.3a2fc46b52819
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

10,101
openapiassist-iot-open-api-management0.2.23 of 6See more

openapi assist-iot-open-api-management 0.2.2

3 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
assistiot/open_api_kong:1.0.03fe850384689
nghttp2@1.47.0-r0
1.47.0-r2
kong/kubernetes-ingress-controller:2.35e66021b64a8
golang.org/x/net@v0.0.0-20220325170049-de3da57026de
0.17.0

Open the chart page →

18,331
performanceandusagediagnosisassist-iot-pud1.0.04 of 7See more

performanceandusagediagnosis assist-iot-pud 1.0.0

4 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
grafana/grafana:9.1.19746858c20e6
golang.org/x/net@v0.0.0-20220615171555-694bf12d69de
0.17.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/net@v0.10.0
0.17.0
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

8,556
resource-provisioningassist-iot-resource-provisioning1.0.02 of 7See more

resource-provisioning assist-iot-resource-provisioning 1.0.0

2 of the 7 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
nghttp2@1.43.0-1
1.43.0-1+deb11u1
curlimages/curl:8.00.0d1658d9c8ef9
nghttp2@1.47.0-r0
1.47.0-r2

Open the chart page →

8,042
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
nghttp2@1.40.0-1ubuntu0.1
1.40.0-1ubuntu0.2

Open the chart page →

7,982
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

5,368
smartorchestratorassist-iot-smart-orchestrator4.0.02 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

2 of the 14 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
nghttp2@1.52.0-1
1.52.0-1+deb12u1
library/mongo:4.4.66efa05203990
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

42,460
dashboard-pui9assist-iot-tactile-dashboard0.2.02 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:web-latest25fc9f373524
nghttp2@1.47.0-r0
nginx@1.22.0-r1
1.47.0-r2
1.22.1-r1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
tomcat-coyote@9.0.65
9.0.81

Open the chart page →

4,145
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

13,986
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
nghttp2@1.43.0-1build3
1.43.0-1ubuntu0.1

Open the chart page →

31,807
graph-nodeastria0.2.21 of 3See more

graph-node astria 0.2.2

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ipfs/kubo:v0.17.0803fac58ba15
golang.org/x/net@v0.1.0
0.17.0

Open the chart page →

5,394
sequencerastria4.0.01 of 3See more

sequencer astria 4.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
rclone/rclone:1.56.0f2fc45c8bc57
golang.org/x/net@v0.0.0-20210415231046-e915ea6b2b7d
0.17.0

Open the chart page →

6,239
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.17.0

Open the chart page →

8,555
hcloud-csi-driveratem181.5.12 of 6See more

hcloud-csi-driver atem18 1.5.1

2 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
golang.org/x/net@v0.0.0-20201010224723-4f7140c49acb
0.17.0
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
golang.org/x/net@v0.0.0-20180301190904-22ae77b79946
0.17.0

Open the chart page →

6,495
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

7,561
okd-webhookav1o-chartsVerified publisher0.1.01 of 1See more

okd-webhook av1o-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0

Open the chart page →

1,727
botkubeaveshaVerified publisher1.0.01 of 2See more

botkube avesha 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
golang.org/x/net@v0.7.0
0.17.0

Open the chart page →

5,074
istio-discoveryaveshaVerified publisher1.16.01 of 1See more

istio-discovery avesha 1.16.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/pilot:1.16.0ac0284d75ec9
nghttp2@1.43.0-1build3
golang.org/x/net@v0.0.0-20220921155015-db77216a4ee9
1.43.0-1ubuntu0.1
0.17.0

Open the chart page →

6,948
kubeslice-workeraveshaVerified publisher1.5.01 of 14See more

kubeslice-worker avesha 1.5.0

1 of the 14 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.1f6717ce72a26
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,631
webappavzi-webapp0.1.01 of 1See more

webapp avzi-webapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
avzini/web-app:latestf40b30210ed0
nghttp2@1.52.0-1
nginx@1.25.3-1~bookworm
1.52.0-1+deb12u1
no fix listed

Open the chart page →

5,291
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
adolfintel/speedtest:latest1f828fe83374
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

7,166
appmesh-jaegeraws1.0.31 of 1See more

appmesh-jaeger aws 1.0.3

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.2942822be7888b
golang.org/x/net@v0.0.0-20210917221730-978cfadd31cf
0.17.0

Open the chart page →

2,480
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/net@v0.0.0-20190724013045-ca1201d0de80
0.17.0

Open the chart page →

2,939
aws-node-termination-handler-2aws0.2.02 of 2See more

aws-node-termination-handler-2 aws 0.2.0

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/controller:v2.0.0-beta9637c80dd23f
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
public.ecr.aws/aws-ec2/aws-node-termination-handler-2/webhook:v2.0.0-beta86b0f7243250
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0

Open the chart page →

2,952
aws-sigv4-proxy-admission-controlleraws0.1.21 of 1See more

aws-sigv4-proxy-admission-controller aws 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0

Open the chart page →

2,139
aws9helmaws9helm0.1.04 of 4See more

aws9helm aws9helm 0.1.0

4 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
kuzwolka/aws9:main1ad759b961b1
nginx@1.27.5-1~bookworm
no fix listed
kuzwolka/aws9:news3e8880fbbb96
nginx@1.27.5-1~bookworm
no fix listed
kuzwolka/aws9:blog4a7707410bf1
nginx@1.27.5-1~bookworm
no fix listed
kuzwolka/aws9:shop84a9d9766345
nginx@1.27.5-1~bookworm
no fix listed

Open the chart page →

16,920
aws-web-service-proxifiedaws-web-service-proxified1.8.01 of 2See more

aws-web-service-proxified aws-web-service-proxified 1.8.0

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prefapp/nginx-proxified:latestf4d026fd9a26
nghttp2@1.47.0-r0
nginx@1.22.0-r1
1.47.0-r2
1.22.1-r1

Open the chart page →

3,021
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
Apache Tomcat@9.0.80
tomcat@9.0.80-1
tomcat-coyote@9.0.80
8.5.94
8.5.94
9.0.81

Open the chart page →

9,723
azure-advanced-backupazure-advanced-backup0.4.11 of 1See more

azure-advanced-backup azure-advanced-backup 0.4.1

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
1.47.0-r2
0.17.0

Open the chart page →

4,568
ambassadorazureorkestra6.7.91 of 2See more

ambassador azureorkestra 6.7.9

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
datawire/aes:1.13.62beb65062c8b
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.17.0

Open the chart page →

5,521
helm-controllerazureorkestra0.1.12 of 2See more

helm-controller azureorkestra 0.1.1

2 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
fluxcd/helm-controller:v0.9.092b891e495d8
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0
fluxcd/source-controller:v0.10.031a8c79a6803
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.17.0

Open the chart page →

7,705
keptn-addonsazureorkestra0.1.03 of 4See more

keptn-addons azureorkestra 0.1.0

3 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
keptn/distributor:0.8.36bc3df9e0d6a
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.17.0
keptncontrib/prometheus-service:0.6.029969dd547de
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.17.0
keptnsandbox/job-executor-service:0.1.36e6d323dd7ae
golang.org/x/net@v0.0.0-20210510120150-4163338589ed
0.17.0

Open the chart page →

10,621
prometheusazureorkestra14.8.03 of 6See more

prometheus azureorkestra 14.8.0

3 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.17.0
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.17.0
quay.io/prometheus/prometheus:v2.26.038d40a760569
golang.org/x/net@v0.0.0-20210324051636-2c4c8ecb7826
0.17.0

Open the chart page →

9,661
prometheus-blackbox-exporterbackbox-exporter7.8.01 of 1See more

prometheus-blackbox-exporter backbox-exporter 7.8.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
prom/blackbox-exporter:v0.23.0ca04aa9d9093
golang.org/x/net@v0.2.0
0.17.0

Open the chart page →

1,494
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
conduction/balance-registration-php:devc36094a41369
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0

Open the chart page →

8,408
basic-auth-s3-nginxbasic-auth-s3-nginxVerified publisher1.0.01 of 1See more

basic-auth-s3-nginx basic-auth-s3-nginx 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
nghttp2@1.52.0-1
nginx@1.25.3-1~bookworm
1.52.0-1+deb12u1
no fix listed

Open the chart page →

6,310
bookinfobasictechno0.1.03 of 6See more

bookinfo basictechno 0.1.0

3 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.17.0b8f16a765eea
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
istio/examples-bookinfo-reviews-v2:1.17.072f25a55f078
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
istio/examples-bookinfo-reviews-v3:1.17.08f92fc1b6592
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2

Open the chart page →

20,785
block-buster-helm-appbb-app-helm-chartsVerified publisher7.6.21 of 1See more

block-buster-helm-app bb-app-helm-charts 7.6.2

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
siddharth67/block-buster-dev:7.6.04e1151ea5774
nghttp2@1.43.0-1
1.43.0-1+deb11u1

Open the chart page →

977
url-shortenerbeastob1.0.21 of 3See more

url-shortener beastob 1.0.2

1 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
beastob/url-shortener:1.0.299a49885ab33
tomcat-embed-core@9.0.53
9.0.81

Open the chart page →

3,607
berichtserviceberichtservice1.0.02 of 3See more

berichtservice berichtservice 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-nginx:latest833d26df3840
nghttp2@1.43.0-1
1.43.0-1+deb11u1
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
nghttp2@1.46.0-r0
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
1.46.0-r2
0.17.0

Open the chart page →

7,342
pagesberrutig-pages1.0.02 of 3See more

pages berrutig-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
nghttp2@1.40.0-1build1
tomcat-embed-core@9.0.36
1.40.0-1ubuntu0.2
9.0.81
flyway/flyway:6.4.422d97ceb0c47
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

20,233
trident-operatorberyju-org21.10.01 of 1See more

trident-operator beryju-org 21.10.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
netapp/trident-operator:21.10.049cfe552d9c2
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0

Open the chart page →

2,072
mx-nodebicarus-labs0.1.01 of 1See more

mx-node bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
0.17.0

Open the chart page →

8,004
mx-notifierbicarus-labs1.1.91 of 1See more

mx-notifier bicarus-labs 1.1.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bicarus/mx-notifier:1.1.8bed688d16762
golang.org/x/net@v0.2.0
0.17.0

Open the chart page →

3,760
wg-access-serverbicarus-labs0.9.91 of 1See more

wg-access-server bicarus-labs 0.9.9

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bicarus/wg-access-server:v0.8.206cab48e9334
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220418201149-a630d4f3e7a2
1.47.0-r2
0.17.0

Open the chart page →

2,748
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
nghttp2@1.30.0-1ubuntu1
1.30.0-1ubuntu1+esm2

Open the chart page →

22,916
bitpokebitpokeVerified publisher1.8.191 of 1See more

bitpoke bitpoke 1.8.19

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/net@v0.10.0
0.17.0

Open the chart page →

2,318
stackbitpokeVerified publisher0.12.45 of 6See more

stack bitpoke 0.12.4

5 of the 6 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
golang.org/x/net@v0.8.0
0.17.0
bitpoke/mysql-operator-orchestrator:v0.6.3d86560c75bed
golang.org/x/net@v0.8.0
0.17.0
bitpoke/wordpress-operator:v0.12.27fb3aad37b5f
golang.org/x/net@v0.8.0
0.17.0
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
nghttp2@1.47.0-r0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
1.47.0-r2
0.17.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.3.0549e71a6ca24
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0

Open the chart page →

9,897
wordpress-operatorbitpokeVerified publisher0.12.41 of 1See more

wordpress-operator bitpoke 0.12.4

1 of the 1 container images this version deploys carry CVE-2023-44487.

Container imageDigestPackageFixed in
bitpoke/wordpress-operator:v0.12.421284d1df473
golang.org/x/net@v0.8.0
0.17.0

Open the chart page →

1,123

Container images carrying it

2,470 by charts deploying them

A fixed version is listed for 19 of the 21 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.15.0
0:1.33.0-5.el8_8
0.17.0
2
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.12.0
0:1.33.0-5.el8_8
0.17.0
2
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.5.0
0:1.33.0-5.el8_8
0.17.0
2
quay.io/oauth2-proxy/oauth2-proxy:v7.3.08c21390be87d
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0
2
quay.io/opencloudio/ibm-mongodb:4.0.24d8c631a6dc43
nghttp2@1.33.0-3.el8_2.1
0:1.33.0-4.el8_4.1
2
quay.io/openshift/origin-cli:4.7464a3af4dfe0
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0:1.33.0-4.el8_4.1
0.17.0
2
quay.io/openshift/origin-cli:4.8bb5e052770e5
nghttp2@1.33.0-3.el8_2.1
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0:1.33.0-4.el8_4.1
0.17.0
2
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
golang.org/x/net@v0.9.0
0.17.0
2
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
2
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/net@v0.0.0-20200513185701-a91f0712d120
0.17.0
2
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
golang.org/x/net@v0.0.0-20210525063256-abc453219eb5
0.17.0
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/net@v0.12.0
0.17.0
2
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
2
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
golang.org/x/net@v0.0.0-20201006153459-a7d1128ccaa0
0.17.0
2
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/net@v0.12.0
0.17.0
2
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
golang.org/x/net@v0.0.0-20220520000938-2e3eb7b945c2
0.17.0
2
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
golang.org/x/net@v0.10.0
0.17.0
2
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
golang.org/x/net@v0.0.0-20211112202133-69e39bad7dc2
0.17.0
2
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
golang.org/x/net@v0.7.0
0.17.0
2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.17.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
0.17.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.17.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/net@v0.10.0
0.17.0
2
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
2
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.17.0
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.17.0
2
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
2
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
2
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.17.0
2
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
golang.org/x/net@v0.13.0
0.17.0
2
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.17.0
2
registry.k8s.io/sig-storage/livenessprobe:v2.8.0cacee2b5c36d
golang.org/x/net@v0.0.0-20220921203646-d300de134e69
0.17.0
2
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.17.0
2
0xpolygon/heimdall:1.0.134ddf259993c
golang.org/x/net@v0.8.0
0.17.0
1
1password/connect-api:1.7.26aa94cf713f9
golang.org/x/net@v0.14.0
0.17.0
1
1password/connect-sync:1.7.2fe527ed9d81f
golang.org/x/net@v0.14.0
0.17.0
1
1password/kubernetes-secrets-injector:1.0.25884757f7879
golang.org/x/net@v0.8.0
0.17.0
1
5200710/hadoop:3.2.3-java8092d3088a5fb
http2-common@9.4.34.v20201102
9.4.53
1
abdullahkhabir/radio:latest56526d0cc929
nghttp2@1.51.0-r1
1.51.0-r2
1
absaoss/terraform-controller:v0.0.20ad538a1285a0
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.17.0
1
adguard/adguardhome:v0.107.3843ec119419a9
golang.org/x/net@v0.15.0
0.17.0
1
adguard/adguardhome:v0.107.7b9974aed13d0
golang.org/x/net@v0.0.0-20220425223048-2871e0cb64e4
0.17.0
1
adolfintel/speedtest:latest1f828fe83374
nghttp2@1.43.0-1
1.43.0-1+deb11u1
1
adrianberger/fluxcd-webui:latest76848c0d2780
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.17.0
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
nghttp2@1.40.0-1build1
1.40.0-1ubuntu0.2
1
aerokube/selenoid-ui:1.10.113f3e299509fd
golang.org/x/net@v0.10.0
0.17.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.