StackRadar

CVE-2023-45290

Medium

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.012
66th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,051
of 17,803 indexed, latest versions
Container images
2,420
deployed by those charts
Fix available
1 of 2
affected packages

Memory exhaustion in multipart form parsing in net/textproto and net/http

Carried by container images the latest versions of 2,051 of 17,803 indexed charts deploy, on 2,420 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+121 more1.21.82,420
OSV records
DEBIAN-CVE-2023-45290GO-2024-2599
Also known as
BIT-golang-2023-45290

Charts affected

2,051 by stars
ChartLatestAffected imagesRadar Score
satisfactoryschichtelVerified publisher0.3.31 of 1See more

satisfactory schichtel 0.3.3

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.9464d11e36e10
stdlib@go1.18.1
1.21.8

Open the chart page →

3,578
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
stdlib@go1.20.2
1.21.8

Open the chart page →

5,585
cert-manager-desec-webhookschmitzis0.0.11 of 1See more

cert-manager-desec-webhook schmitzis 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
su541/cert-manager-desec-webhook:latest371ee33f83c1
stdlib@go1.19.10
1.21.8

Open the chart page →

1,785
cert-manager-webhook-bunnyschmitzis0.1.11 of 1See more

cert-manager-webhook-bunny schmitzis 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
ghcr.io/schmitzis/cert-manager-webhook-bunny:latest125e31c8e85a
stdlib@go1.19.13
1.21.8

Open the chart page →

1,513
icinga2-masterschmitzis0.2.01 of 6See more

icinga2-master schmitzis 0.2.0

1 of the 6 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
grafana/grafana:8.0.3696823fbc561
stdlib@go1.16.1
1.21.8

Open the chart page →

3,738
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
stdlib@go1.19.4
1.21.8

Open the chart page →

4,444
version-checkerschmitzis0.2.21 of 1See more

version-checker schmitzis 0.2.2

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
stdlib@go1.15.2
1.21.8

Open the chart page →

3,024
openldapschoolguys-helmcharts0.1.31 of 1See more

openldap schoolguys-helmcharts 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.21.8

Open the chart page →

3,314
satisfactory-serverschoolguys-helmcharts0.1.81 of 1See more

satisfactory-server schoolguys-helmcharts 0.1.8

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
stdlib@go1.18.1
1.21.8

Open the chart page →

3,480
cernboxsciencebox0.0.41 of 6See more

cernbox sciencebox 0.0.4

1 of the 6 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
cs3org/revad:v1.19.03b57a34a7dfd
stdlib@go1.17.3
1.21.8

Open the chart page →

2,340
ldap-instance-configsciencebox0.0.11 of 1See more

ldap-instance-config sciencebox 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.21.8

Open the chart page →

3,314
centralbrainsciencemeshVerified publisher0.0.34 of 5See more

centralbrain sciencemesh 0.0.3

4 of the 5 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
grafana/grafana:7.3.315b977f5207d
stdlib@go1.15.1
1.21.8
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.21.8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.21.8
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
stdlib@go1.15.3
1.21.8

Open the chart page →

9,771
sealed-secrets-uisealed-secrets-uiVerified publisher0.0.81 of 1See more

sealed-secrets-ui sealed-secrets-ui 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
stdlib@go1.19.4
1.21.8

Open the chart page →

4,747
hermitcrabseal-ioVerified publisher0.1.42 of 2See more

hermitcrab seal-io 0.1.4

2 of the 2 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
sealio/hermitcrab:v0.1.4a326a2f03660
stdlib@go1.21.6
1.21.8
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
stdlib@go1.20.7
1.21.8

Open the chart page →

4,890
searchpesearchpe4.1.01 of 2See more

searchpe searchpe 4.1.0

1 of the 2 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
library/postgres:13.703652c675ae1
stdlib@go1.16.7
1.21.8

Open the chart page →

2,637
seaweedfs-operatorseaweedfs-operatorVerified publisher1.5.81 of 3See more

seaweedfs-operator seaweedfs-operator 1.5.8

1 of the 3 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
stdlib@go1.21.3
1.21.8

Open the chart page →

2,099
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
library/mysql:9.0.192dc86967801
stdlib@go1.18.2
1.21.8

Open the chart page →

5,505
aws-secretssecretsprovider0.1.01 of 1See more

aws-secrets secretsprovider 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45290.

Open the chart page →

2,220
secret-syncsecret-syncVerified publisher0.1.111 of 1See more

secret-sync secret-sync 0.1.11

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
csepulvedab/secret-sync:0.5227a6f2b0ff8
stdlib@go1.19.4
1.21.8

Open the chart page →

1,443
cloudflaredsectionmeVerified publisher2022.3.41 of 1See more

cloudflared sectionme 2022.3.4

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
quay.io/giantswarm/cloudflared:2022.3.40b20d2fe9a6b
stdlib@go1.17.1
1.21.8

Open the chart page →

2,440
influxdb_exportersectionmeVerified publisher0.0.21 of 1See more

influxdb_exporter sectionme 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
quay.io/prometheus/influxdb-exporter:v0.10.03854d8af7bd4
stdlib@go1.18.3
1.21.8

Open the chart page →

922
seldon-core-analyticsseldon1.17.14 of 8See more

seldon-core-analytics seldon 1.17.1

4 of the 8 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.21.8
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.21.8
prom/prometheus:v2.18.15880ec936055
stdlib@go1.14.2
1.21.8
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.21.8

Open the chart page →

10,749
miniosergiotocaliniVerified publisher1.0.01 of 1See more

minio sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
stdlib@go1.19.11
1.21.8

Open the chart page →

4,351
service-binding-operatorservice-binding-operator-helm-chart1.4.11 of 1See more

service-binding-operator service-binding-operator-helm-chart 1.4.1

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
quay.io/redhat-developer/servicebinding-operatordigest-pinned16286ac84ddd
stdlib@go1.20.6
1.21.8

Open the chart page →

796
serviceexampleserviceexample0.1.03 of 5See more

serviceexample serviceexample 0.1.0

3 of the 5 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
library/nats:2.9.20-alpined6c6ae7df4a0
stdlib@go1.19.11
1.21.8
natsio/nats-box:0.13.559cf2e949181
stdlib@go1.19.5
1.21.8
natsio/nats-server-config-reloader:0.11.0c3a755eab2cc
stdlib@go1.20.5
1.21.8

Open the chart page →

5,451
service-exampleservice-example-10.1.04 of 7See more

service-example service-example-1 0.1.0

4 of the 7 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
library/nats:2.9.11-alpineccbe811b8575
stdlib@go1.19.4
1.21.8
natsio/nats-box:0.13.3c507bd7e3831
stdlib@go1.19.4
1.21.8
natsio/nats-server-config-reloader:0.8.06bdaceb63aa5
stdlib@go1.19.4
1.21.8
natsio/prometheus-nats-exporter:0.10.1bce728062c4f
stdlib@go1.19.3
1.21.8

Open the chart page →

9,132
ccx-monitoringseveralnines0.6.213 of 7See more

ccx-monitoring severalnines 0.6.21

3 of the 7 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
victoriametrics/vmalert:v1.96.0150cd08fde94
stdlib@go1.21.5
1.21.8
quay.io/prometheus/alertmanager:v0.26.0361db356b330
stdlib@go1.20.7
1.21.8
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
stdlib@go1.20.10
1.21.8

Open the chart page →

7,740
apache-shardingsphere-operator-chartsshardingsphere0.3.01 of 2See more

apache-shardingsphere-operator-charts shardingsphere 0.3.0

1 of the 2 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
stdlib@go1.19.10
1.21.8

Open the chart page →

1,699
shopwareshopware-storeVerified publisher2.1.21 of 5See more

shopware shopware-store 2.1.2

1 of the 5 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
stdlib@go1.21.7
1.21.8

Open the chart page →

4,132
backendsignalen4.24.02 of 4See more

backend signalen 4.24.0

2 of the 4 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
stdlib@go1.16.7
1.21.8
bitnamilegacy/rabbitmq:3.10.7-debian-11-r4cf93e2772250
stdlib@go1.16.7
1.21.8

Open the chart page →

11,751
alertmanagersignoz0.5.21 of 1See more

alertmanager signoz 0.5.2

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
signoz/alertmanager:0.5.07bc7de2e33c2
stdlib@go1.14
1.21.8

Open the chart page →

2,182
zookeepersignoz0.0.11 of 1See more

zookeeper signoz 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
signoz/zookeeper:3.7.1fcc4a3288154
stdlib@go1.21.2
1.21.8

Open the chart page →

2,923
trilliansigstoreVerified publisher0.3.201 of 5See more

trillian sigstore 0.3.20

1 of the 5 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
gcr.io/trillian-opensource-ci/db_serverdigest-pinned2a685a38dd01
stdlib@go1.18.2
1.21.8

Open the chart page →

2,757
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
stdlib@go1.19.6
1.21.8

Open the chart page →

2,870
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
stdlib@go1.21.4
1.21.8

Open the chart page →

2,347
metrics-generatorsikalabs0.2.01 of 1See more

metrics-generator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
sikalabs/slu:v0.34.0fdc0c6711add
stdlib@go1.17.6
1.21.8

Open the chart page →

2,381
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
stdlib@go1.20.5
1.21.8

Open the chart page →

1,502
keydbsinextraVerified publisher0.31.01 of 1See more

keydb sinextra 0.31.0

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/keydb:6.3.376a19ddc3626
stdlib@go1.18.10
1.21.8

Open the chart page →

2,172
mimirskyloud-helm-chartsVerified publisher5.5.12 of 5See more

mimir skyloud-helm-charts 5.5.1

2 of the 5 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
stdlib@go1.21.1
1.21.8
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
stdlib@go1.21.1
1.21.8

Open the chart page →

10,819
config-connector-templaterslamdev0.0.51 of 1See more

config-connector-templater slamdev 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
slamdev/config-connector-templater:0.0.3a234541c9fa8
stdlib@go1.16.5
1.21.8

Open the chart page →

2,110
flux-notifierslamdev0.0.71 of 1See more

flux-notifier slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
slamdev/flux-notifier:v0.0.8b173d809132d
stdlib@go1.13.11
1.21.8

Open the chart page →

2,016
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
stdlib@go1.17.9
1.21.8

Open the chart page →

9,261
gke-preemptible-notifierslamdev0.0.61 of 1See more

gke-preemptible-notifier slamdev 0.0.6

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
slamdev/gke-preemptible-notifier:v0.0.3d5d6430108a3
stdlib@go1.13.11
1.21.8

Open the chart page →

2,861
octavia-ingress-controllerslamdev0.0.71 of 1See more

octavia-ingress-controller slamdev 0.0.7

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
k8scloudprovider/octavia-ingress-controller:v1.20.26ddf80b34265
stdlib@go1.15
1.21.8

Open the chart page →

2,761
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
stdlib@go1.13.5
1.21.8

Open the chart page →

8,732
oi-slurm-cluster-chartslurm-cluster-chart0.25.11 of 4See more

oi-slurm-cluster-chart slurm-cluster-chart 0.25.1

1 of the 4 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.21.8

Open the chart page →

4,390
slurm-cluster-chartslurm-cluster-chart0.25.01 of 4See more

slurm-cluster-chart slurm-cluster-chart 0.25.0

1 of the 4 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
library/mariadb:10.10334b315c10e5
stdlib@go1.18.2
1.21.8

Open the chart page →

4,390
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
stdlib@go1.19.2
1.21.8

Open the chart page →

3,471
smarter-device-managersmarter-device-manager0.0.101 of 1See more

smarter-device-manager smarter-device-manager 0.0.10

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/smarter-device-manager:v1.20.12228f7f44594a
stdlib@go1.19.3
1.21.8

Open the chart page →

1,151
mealiesmarthallVerified publisher0.0.101 of 1See more

mealie smarthall 0.0.10

1 of the 1 container images this version deploys carry CVE-2023-45290.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
stdlib@go1.19.8
1.21.8

Open the chart page →

5,621

Container images carrying it

2,420 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.0cd21e19cd8bb
stdlib@go1.20.5
1.21.8
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.21.8
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
stdlib@go1.19
1.21.8
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
stdlib@go1.18
1.21.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.21.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
stdlib@go1.18
1.21.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.21.8
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.21.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.21.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.21.8
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.21.8
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.21.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.21.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.12.05baeb4a6d7d5
stdlib@go1.21.5
1.21.8
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.21.8
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.21.8
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.21.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.21.8
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.21.8
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.21.8
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.