StackRadar

CVE-2023-4863

CriticalKEV

Advisory

Published 12 Sept 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.6
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 13 Sept 2023
Charts affected
454
of 17,781 indexed, latest versions
Container images
416
deployed by those charts
Fix available
5 of 5
affected packages

Red Hat Security Advisory: libwebp security update

Carried by container images the latest versions of 454 of 17,781 indexed charts deploy, on 416 images.

Affected packageAffected versionsFixed inImages
libwebprpm1.0.0-3.el8_40:1.0.0-7.el8_4.11
libwebpdeb0.6.1-2, 0.6.1-2.1, 0.6.1-2.1+deb11u1, 0.6.1-2+deb10u1+6 more0.6.1-2.1+deb11u2, 0.6.1-2+deb10u3, 0.6.1-2ubuntu0.18.04.2+esm1, 0.6.1-2ubuntu0.20.04.3+2 more300
libwebpapk1.2.2-r0, 1.2.3-r0, 1.2.3-r1, 1.2.4-r1+2 more1.2.2-r2, 1.2.3-r2, 1.2.4-r3, 1.3.1-r173
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+21 more10.0.168
SkiaSharpnuget2.80.2, 2.88.1-preview.71, 2.88.2, 2.88.32.88.66
OSV records
RHSA-2023:5222ALPINE-CVE-2023-4863DEBIAN-CVE-2023-4863GHSA-j7hp-h8jx-5pprPYSEC-2026-1794UBUNTU-CVE-2023-4863DLA-3570-1DSA-5497-2
Also known as
A-299477569, ASB-A-299477569, CVE-2023-5129, DSA-5497-1, RUSTSEC-2023-0060, RUSTSEC-2023-0061, USN-6369-1, USN-6369-2

Charts affected

454 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libwebp@1.2.2-r0
1.2.2-r2
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
libwebp@1.2.2-r0
1.2.2-r2

Open the chart page →

16,083
myfirstchartww-helm-charts-repo0.1.01 of 1See more

myfirstchart ww-helm-charts-repo 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginx:0.1.0205961b09a80
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2

Open the chart page →

1,838
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138

Container images carrying it

416 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
anujdatar/cups:25.07.01685df04a643b
pillow@9.4.0
10.0.1
1
apache/superset:9cdaa280429ec297db16d56c94fd77b5d2aff107975ab033580d
pillow@9.1.0
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
apsl/thumbor:6.7.051e2de5c2c70
pillow@5.4.1
10.0.1
1
archish27/python-fastapi-postgres:latest6610071a2101
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
arfath29/3-tier-app-backend:latestee0750b18406
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
arfath29/3-tier-app-frontend:latest384b3e377f47
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
arturisimo/server-urjc:v1.0d8dc4430531e
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
asdkant/fastapi-hello-world:latesta23d8bf7c885
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
asonix/pictrs:0.4.0-beta.19480d36cd97e5
libwebp@1.2.3-r0
1.2.3-r2
1
assistiot/dlt_api:2.1.0c8a170683be7
libwebp@0.6.1-2+deb10u2
0.6.1-2+deb10u3
1
assistiot/fl_orchestrator:ui-latest20338b353aaf
libwebp@1.2.3-r0
1.2.3-r2
1
assistiot/resource-provisioning_prc:1.0.08b5d118bdf0e
libwebp@0.6.1-2.1+deb11u1
0.6.1-2.1+deb11u2
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
pillow@9.5.0
10.0.1
1
assistiot/tacticle_dashboard:web-latest25fc9f373524
libwebp@1.2.3-r0
1.2.3-r2
1
avinash263/pyredis263:latestaa2b8727f1a6
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1
azhar008/flaskapplication:latesta1e827b0adea
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
libwebp@0.6.1-2ubuntu0.20.04.1
pillow@8.1.0
0.6.1-2ubuntu0.20.04.3
10.0.1
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
buntha/mlflow:2.1.1154542cc3083
pillow@9.3.0
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
camerahub/camerahub:0.36.23a5af37dd6e1b
pillow@9.5.0
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
camptocamp/bucket-cloner:latestacfafc308d88
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
camptocamp/ekorre:0.1.035c91d5fda04
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
cdignam/kodiak:v0.54.05a6a55b39cee
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
ceticasbl/pg-ldap-sync:latest6c0aa7567145
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
chaosnative/cle-frontend:2.7.007b82a82a702
libwebp@1.2.2-r0
1.2.2-r2
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
libwebp@1.2.4-r1
1.2.4-r3
1
dacinfomotion/h2p:latest68fa393b472c
libwebp@0.6.1-2+deb10u2
0.6.1-2+deb10u3
1
danuk/telegram-sender:0.0.1026560388070
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
daskdev/dask:1.1.04ecd7bc35500
pillow@5.3.0
10.0.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
libwebp@0.6.1-2
pillow@5.4.1
0.6.1-2ubuntu0.18.04.2+esm1
10.0.1
1
deconzcommunity/deconz:2.29.2062de2362641
pillow@9.4.0
10.0.1
1
deconzcommunity/deconz:2.12.066541bbb78952
pillow@5.4.1
libwebp@0.6.1-2+deb10u1
10.0.1
0.6.1-2+deb10u3
1
deluan/navidrome:0.49.311a24da08977
libwebp@1.2.4-r1
1.2.4-r3
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
digitalist/nginx:1.21.6eec27ad73eaa
libwebp@1.2.2-r0
1.2.2-r2
1
dnsforge/xteve:latest4d9a685c8c28
libwebp@1.2.4-r1
1.2.4-r3
1
douz/helpdesk:latest4384103d0219
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
douz/overlord:latestf2bc7fc068c1
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
dpage/pgadmin4:7.537946e4f3e7b
pillow@9.5.0
10.0.1
1
duck1123/astral:latestf4d5b6526c2a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
eclipseaerios/self-service-password:5.2.32f93bfa4cf0d
libwebp@1.2.2-r0
1.2.2-r2
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
libwebp@0.6.1-2ubuntu0.18.04.1
0.6.1-2ubuntu0.18.04.2+esm1
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
libwebp@0.6.1-2ubuntu0.18.04.1
0.6.1-2ubuntu0.18.04.2+esm1
1
elyra/kernel-image-puller:3.2.2c922f1f1646a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
emby/embyserver:4.9.1.8022298eefb428
SkiaSharp@2.88.3
2.88.6
1
erlangsolutions/wombatoam:4.1.284680c990147a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
esailors/aws-ecr-http-proxy:1.5.15608ae045fa7
libwebp@1.2.2-r0
1.2.2-r2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.