StackRadar

CVE-2023-45853

Critical

Advisory

Published 14 Oct 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.032
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
773
of 17,787 indexed, latest versions
Container images
840
deployed by those charts
Fix available
2 of 3
affected packages

pyminizip affected by zlib's integer overflow/heap based buffer overflow vulnerability due to vulnerable dependency

Carried by container images the latest versions of 773 of 17,787 indexed charts deploy, on 840 images.

Affected packageAffected versionsFixed inImages
zlibdeb1:1.2.8.dfsg-1ubuntu1, 1:1.2.8.dfsg-1ubuntu1.1, 1:1.2.13.dfsg-1, 1:1.3.dfsg+really1.3.1-1+b11:1.2.8.dfsg-1ubuntu1.1+esm3837
pyminizippypi0.2.6no fix listed2
minizipdeb1.1-8+b11.1-8+deb10u12
OSV records
DEBIAN-CVE-2023-45853GHSA-mq29-j5xf-cjwrUBUNTU-CVE-2023-45853DLA-3670-1
Also known as
PYSEC-2026-501, USN-7107-1

Charts affected

773 by stars
ChartLatestAffected imagesRadar Score
opencloudunxwaresVerified publisher0.2.36 of 13See more

opencloud unxwares 0.2.3

6 of the 13 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
zlib@1:1.2.13.dfsg-1
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
zlib@1:1.2.13.dfsg-1
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
zlib@1:1.2.13.dfsg-1
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
zlib@1:1.2.13.dfsg-1
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
zlib@1:1.2.13.dfsg-1
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

45,239
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

14,358
telegram-rebotvcnngrVerified publisher1.0.02 of 3See more

telegram-rebot vcnngr 1.0.0

2 of the 3 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
vcnngr/telegram-login:latest1a849a997b6d
zlib@1:1.2.13.dfsg-1
no fix listed
vcnngr/telegram-rebot:latest30f1f05e57a6
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

5,026
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

4,382
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

10,795
api-gatewaywallarmVerified publisher0.2.01 of 1See more

api-gateway wallarm 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
wallarm/api-gateway:0.2.0a3d4d2f780e8
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,288
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

5,984
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

10,001
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,678
apisixwenerme2.17.01 of 3See more

apisix wenerme 2.17.0

1 of the 3 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

3,045
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

1,616
giteawenerme12.7.03 of 4See more

gitea wenerme 12.7.0

3 of the 4 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
zlib@1:1.2.13.dfsg-1
no fix listed
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
zlib@1:1.2.13.dfsg-1
no fix listed
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

8,811
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

9,117
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.7.45f2a56b95266
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

14,983
keycloakwiremindVerified publisher25.3.12 of 2See more

keycloak wiremind 25.3.1

2 of the 2 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
zlib@1:1.2.13.dfsg-1
no fix listed
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

7,624
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

5,542
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,473
rediswiremindVerified publisher23.0.61 of 1See more

redis wiremind 23.0.6

1 of the 1 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,113
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

7,673
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
zlib@1:1.2.13.dfsg-1
no fix listed
hamzaarshad10/querypodpy:1.7154f38e8668e
zlib@1:1.2.13.dfsg-1
no fix listed
murtazashah46/helmfile:latest4d11726cf803
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

13,677
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-45853.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
zlib@1:1.2.13.dfsg-1
no fix listed

Open the chart page →

2,661

Container images carrying it

840 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
contentsquareplatform/chproxy:v1.26.524555f22d4be
zlib@1:1.2.13.dfsg-1
no fix listed
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
zlib@1:1.2.13.dfsg-1
no fix listed
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
zlib@1:1.2.13.dfsg-1
no fix listed
1
cspconsole/config-provider:1.0.365524a26a6c23
zlib@1:1.2.13.dfsg-1
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
zlib@1:1.2.13.dfsg-1
no fix listed
1
cspconsole/report-collector:1.0.15839750248193b
zlib@1:1.2.13.dfsg-1
no fix listed
1
cspconsole/report-processor:1.0.279a2d8840bfdf
zlib@1:1.2.13.dfsg-1
no fix listed
1
cubejs/cubestore:v1.5.334ac523a9bab
zlib@1:1.2.13.dfsg-1
no fix listed
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
zlib@1:1.2.13.dfsg-1
no fix listed
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
zlib@1:1.2.13.dfsg-1
no fix listed
1
dacinfomotion/h2p:latest68fa393b472c
minizip@1.1-8+b1
1.1-8+deb10u1
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
zlib@1:1.2.13.dfsg-1
no fix listed
1
dannielkil/book-frontend:latest937993927694
zlib@1:1.2.13.dfsg-1
no fix listed
1
datafuselabs/databend-meta:v1.2.279ba877ee6cb4d
zlib@1:1.2.13.dfsg-1
no fix listed
1
datafuselabs/databend-query:v1.2.279a936843b85b4
zlib@1:1.2.13.dfsg-1
no fix listed
1
dbgate/dbgate:7.2.3f2dc7423ea88
zlib@1:1.2.13.dfsg-1
no fix listed
1
ddosify/alaz:v0.12.0ea602056d9ce
zlib@1:1.2.13.dfsg-1
no fix listed
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
zlib@1:1.2.13.dfsg-1
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
zlib@1:1.2.13.dfsg-1
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
zlib@1:1.2.13.dfsg-1
no fix listed
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
zlib@1:1.2.13.dfsg-1
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
zlib@1:1.2.13.dfsg-1
no fix listed
1
defactops/defactops-backend:1.0.2307b663c0092a
zlib@1:1.2.13.dfsg-1
no fix listed
1
dessalines/lemmy:0.19.2079e9f02c286c
zlib@1:1.2.13.dfsg-1
no fix listed
1
devopsgoofy/k8s-platform:latestad865312099f
zlib@1:1.2.13.dfsg-1
no fix listed
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
zlib@1:1.2.13.dfsg-1
no fix listed
1
diygod/rsshub:2025-11-097a6312cac0d5
zlib@1:1.2.13.dfsg-1
no fix listed
1
djjudas21/alertify:0.1.0ba22be670c37
zlib@1:1.2.13.dfsg-1
no fix listed
1
dobtc/bitcoin:25.1a870f7cb1105
zlib@1:1.2.13.dfsg-1
no fix listed
1
docmost/docmost:0.95.041c8d777cf23
zlib@1:1.2.13.dfsg-1
no fix listed
1
dolibarr/dolibarr:24.0.069ec52e3b7ef
zlib@1:1.2.13.dfsg-1
no fix listed
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
zlib@1:1.2.13.dfsg-1
no fix listed
1
domainmod/domainmod:4.23.04017bfe4c597
zlib@1:1.2.13.dfsg-1
no fix listed
1
dragonflyoss/client:v1.5.4a1b52779c4dd
zlib@1:1.2.13.dfsg-1
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
zlib@1:1.2.13.dfsg-1
no fix listed
1
drorivry4/rego:lateste035d49b15ca
zlib@1:1.2.13.dfsg-1
no fix listed
1
drumsergio/genieacs:1.2.16.028244054e1bf
zlib@1:1.2.13.dfsg-1
no fix listed
1
dserio83/velero-api:0.3.16b3d9115fee2
zlib@1:1.2.13.dfsg-1
no fix listed
1
dserio83/velero-watchdog:0.1.8d5deae589229
zlib@1:1.2.13.dfsg-1
no fix listed
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
zlib@1:1.2.13.dfsg-1
no fix listed
1
emqx/ecp-ui:2.5.1e33e9816f147
zlib@1:1.2.13.dfsg-1
no fix listed
1
erigontech/erigon:latest2252efdf9abe
zlib@1:1.2.13.dfsg-1
no fix listed
1
erigontech/erigon:v2.61.288706754b627
zlib@1:1.2.13.dfsg-1
no fix listed
1
esphome/esphome:2024.3.09ab8cc88b28c
zlib@1:1.2.13.dfsg-1
no fix listed
1
esphome/esphome:2024.12.2b2c6322700ac
zlib@1:1.2.13.dfsg-1
no fix listed
1
esphome/esphome:2025.3.0def8b6e4f517
zlib@1:1.2.13.dfsg-1
no fix listed
1
ethersphere/bee:2.2.0a884fd84b72f
zlib@1:1.2.13.dfsg-1
no fix listed
1
ethersphere/beekeeper:lateste4cda693ed63
zlib@1:1.2.13.dfsg-1
no fix listed
1
ethpandaops/observoor:masterc7e5055defcb
zlib@1:1.2.13.dfsg-1
no fix listed
1
falcosecurity/event-generator:latest932956d86c99
zlib@1:1.2.13.dfsg-1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.