StackRadar

CVE-2023-4863

CriticalKEV

Advisory

Published 12 Sept 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.6
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 13 Sept 2023
Charts affected
454
of 17,781 indexed, latest versions
Container images
416
deployed by those charts
Fix available
5 of 5
affected packages

Red Hat Security Advisory: libwebp security update

Carried by container images the latest versions of 454 of 17,781 indexed charts deploy, on 416 images.

Affected packageAffected versionsFixed inImages
libwebprpm1.0.0-3.el8_40:1.0.0-7.el8_4.11
libwebpdeb0.6.1-2, 0.6.1-2.1, 0.6.1-2.1+deb11u1, 0.6.1-2+deb10u1+6 more0.6.1-2.1+deb11u2, 0.6.1-2+deb10u3, 0.6.1-2ubuntu0.18.04.2+esm1, 0.6.1-2ubuntu0.20.04.3+2 more300
libwebpapk1.2.2-r0, 1.2.3-r0, 1.2.3-r1, 1.2.4-r1+2 more1.2.2-r2, 1.2.3-r2, 1.2.4-r3, 1.3.1-r173
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+21 more10.0.168
SkiaSharpnuget2.80.2, 2.88.1-preview.71, 2.88.2, 2.88.32.88.66
OSV records
RHSA-2023:5222ALPINE-CVE-2023-4863DEBIAN-CVE-2023-4863GHSA-j7hp-h8jx-5pprPYSEC-2026-1794UBUNTU-CVE-2023-4863DLA-3570-1DSA-5497-2
Also known as
A-299477569, ASB-A-299477569, CVE-2023-5129, DSA-5497-1, RUSTSEC-2023-0060, RUSTSEC-2023-0061, USN-6369-1, USN-6369-2

Charts affected

454 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libwebp@1.2.2-r0
1.2.2-r2
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
libwebp@1.2.2-r0
1.2.2-r2

Open the chart page →

16,083
myfirstchartww-helm-charts-repo0.1.01 of 1See more

myfirstchart ww-helm-charts-repo 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginx:0.1.0205961b09a80
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2

Open the chart page →

1,838
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138

Container images carrying it

416 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
esphome/esphome:1.18.03f51ec10e823
pillow@5.4.1
libwebp@0.6.1-2
10.0.1
0.6.1-2+deb10u3
1
evk02/mlflow:2.2.1ef6ff257ef35
pillow@9.4.0
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
factly/hunting:0.2.0-stagv1.2ca5bc71d1d5c
pillow@9.3.0
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
factly/mande-studio:0.34.19db4bee30e63
libwebp@1.2.4-r2
1.2.4-r3
1
fanzynoodle/smeejas:0.0.15f9916c1a287
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
fedodo/fedodo.ui.home:3c69413c4d690
libwebp@1.2.4-r2
1.2.4-r3
1
fedodo/fedodo.ui.micro:12b2b540081c21
libwebp@1.2.4-r2
1.2.4-r3
1
felipecs8/qrcode-generator:v1d5f4f17cb066
libwebp@1.2.4-r1
1.2.4-r3
1
firefart/requesttracker:nginx-nightly-202307101028236b42a0
libwebp@1.2.4-r2
1.2.4-r3
1
fireflyiii/core:version-5.6.142f4283bd0cf7
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
fluidtrendslab/platform:latestbf49de7a4100
libwebp@1.2.3-r0
1.2.3-r2
1
fossology/fossology:4.2.18bd1f22ba7bb
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
gcarrarom/landing:0.0.0769d19e441d9
libwebp@1.2.3-r0
1.2.3-r2
1
geoscienceaustralia/dea-k8s-data:latestf4039b45572a
libwebp@0.6.1-2
pillow@7.2.0
0.6.1-2ubuntu0.18.04.2+esm1
10.0.1
1
gethue/nginx:latest07f00f7c7903
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
gollumorg/gollum:latest7cd5305a3cf7
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
gresearchdev/siembol-config-editor-ui:latest071e7109a981
libwebp@1.2.3-r0
1.2.3-r2
1
guacamole/guacd:1.1.02288530a4d1c
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
guacamole/guacd:1.3.049d43948140f
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
ha33ona/python:test6affdfc644d0
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
haveagitgat/tdarr:2.00.181256348872ce
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
libwebp@0.6.1-2
0.6.1-2ubuntu0.20.04.3
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
heywood8/redisinsight:2.28.00bc9ab313d37
libwebp@0.6.1-2.1+deb11u1
0.6.1-2.1+deb11u2
1
hhyo/archery:v1.9.11aa41843419e
pillow@9.0.1
10.0.1
1
hiboxsystems/marge-bot:0.11.07235809b43b3
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
hkotel/mealie:api-v1.0.0beta-2a7e6b6abe087
pillow@8.4.0
10.0.1
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
libwebp@0.6.1-2
0.6.1-2ubuntu0.18.04.2+esm1
1
ianw/quickchart:v1.7.1dc49dd460c37
libwebp@1.2.2-r0
1.2.2-r2
1
improwised/erpnext-worker:v13.4.197280b55cbd4
pillow@8.2.0
10.0.1
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
invoiceninja/invoiceninja:5.6.241437916dee01
libwebp@1.3.1-r0
1.3.1-r1
1
jellyfin/jellyfin:10.8.1305a9734d7e83
SkiaSharp@2.88.2
2.88.6
1
jellyfin/jellyfin:10.8.1ee24f4459a40
SkiaSharp@2.88.1-preview.71
libwebp@0.6.1-2.1
2.88.6
0.6.1-2.1+deb11u2
1
julb/http-url-playlist:1.0.2782ef45279d5
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
kfirfer/king:latestc05d9fc7ae77
libwebp@1.2.4-r2
1.2.4-r3
1
kobotoolbox/kobocat:2.022.24ab15679454415
pillow@9.1.0
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
pillow@9.1.0
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
kubebb/hello-world:0.1.0b746824819f3
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
kubeshop/kusk-gateway-dashboard:v1.2.6ff9b5aa1258d
libwebp@1.2.3-r0
1.2.3-r2
1
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
libwebp@1.2.4-r2
1.2.4-r3
1
kyso/jupyter-diff:latest82299a9e5a86
libwebp@1.2.4-r2
1.2.4-r3
1
ldapaccountmanager/lam:7.295533a96a4c1
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
library/monica:3.7.0-apacheceb1ba4196ab
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
library/nextcloud:17.0.0-apache96104cb965fc
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
library/nginx:1.23.03536d368b898
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
library/nginx:1.23.2-alpine455c39afebd4
libwebp@1.2.3-r0
1.2.3-r2
1
library/nginx:1.25.167f9a4f10d14
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.