StackRadar

CVE-2023-4863

CriticalKEV

Advisory

Published 12 Sept 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.6
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 13 Sept 2023
Charts affected
454
of 17,781 indexed, latest versions
Container images
416
deployed by those charts
Fix available
5 of 5
affected packages

Red Hat Security Advisory: libwebp security update

Carried by container images the latest versions of 454 of 17,781 indexed charts deploy, on 416 images.

Affected packageAffected versionsFixed inImages
libwebprpm1.0.0-3.el8_40:1.0.0-7.el8_4.11
libwebpdeb0.6.1-2, 0.6.1-2.1, 0.6.1-2.1+deb11u1, 0.6.1-2+deb10u1+6 more0.6.1-2.1+deb11u2, 0.6.1-2+deb10u3, 0.6.1-2ubuntu0.18.04.2+esm1, 0.6.1-2ubuntu0.20.04.3+2 more300
libwebpapk1.2.2-r0, 1.2.3-r0, 1.2.3-r1, 1.2.4-r1+2 more1.2.2-r2, 1.2.3-r2, 1.2.4-r3, 1.3.1-r173
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+21 more10.0.168
SkiaSharpnuget2.80.2, 2.88.1-preview.71, 2.88.2, 2.88.32.88.66
OSV records
RHSA-2023:5222ALPINE-CVE-2023-4863DEBIAN-CVE-2023-4863GHSA-j7hp-h8jx-5pprPYSEC-2026-1794UBUNTU-CVE-2023-4863DLA-3570-1DSA-5497-2
Also known as
A-299477569, ASB-A-299477569, CVE-2023-5129, DSA-5497-1, RUSTSEC-2023-0060, RUSTSEC-2023-0061, USN-6369-1, USN-6369-2

Charts affected

454 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libwebp@1.2.2-r0
1.2.2-r2
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
libwebp@1.2.2-r0
1.2.2-r2

Open the chart page →

16,083
myfirstchartww-helm-charts-repo0.1.01 of 1See more

myfirstchart ww-helm-charts-repo 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginx:0.1.0205961b09a80
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2

Open the chart page →

1,838
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138

Container images carrying it

416 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
library/nginx:1.19.68e1095642250
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
library/nginx:1.23.2ab589a3c466e
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
library/nginx:1.17.6b2d89d0a2103
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
library/nginx:1.16.1d20aa6d1cae5
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
library/nginx:1.23.3f4e3b6489888
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
library/nginx:1.23f5747a42e3ad
libwebp@0.6.1-2.1+deb11u1
0.6.1-2.1+deb11u2
1
library/node:16.20f77a1aef2da8
libwebp@0.6.1-2+deb10u2
0.6.1-2+deb10u3
1
library/wordpress:6.0.0-php8.0-apache277c6c25980f
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
librenms/librenms:22.4.14f1f3d667cc7
libwebp@1.2.2-r0
1.2.2-r2
1
linuxserver/babybuddy:1.10.2f7d7c7704249
pillow@9.0.1
10.0.1
1
linuxserver/beets:1.5.0e36d16f7341c
pillow@8.4.0
10.0.1
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
libwebp@0.6.1-2ubuntu0.18.04.1
0.6.1-2ubuntu0.18.04.2+esm1
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
linuxserver/couchpotato:75e576ee-ls389cd8d5fb1ac
pillow@5.4.1
10.0.1
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
pillow@6.2.1
10.0.1
1
linuxserver/deluge:18.04.10ac871624394
libwebp@0.6.1-2ubuntu0.18.04.1
pillow@5.1.0
0.6.1-2ubuntu0.18.04.2+esm1
10.0.1
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
libwebp@0.6.1-2ubuntu0.18.04.1
pillow@5.1.0
0.6.1-2ubuntu0.18.04.2+esm1
10.0.1
1
linuxserver/grocy:4.0.1f8f5f96b6ea8
libwebp@1.3.1-r0
1.3.1-r1
1
linuxserver/jellyfin:10.7.72427dde159a2
libwebp@0.6.1-2ubuntu0.20.04.1
SkiaSharp@2.80.2
0.6.1-2ubuntu0.20.04.3
2.88.6
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
pillow@8.2.0
10.0.1
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
pillow@6.2.1
10.0.1
1
livekit/ingress:v1.2.21ab01641b366
libwebp@1.2.2-2ubuntu0.22.04.1
1.2.2-2ubuntu0.22.04.2
1
lnbitsdocker/lnbits-legend:0.10.6a11aaa6d2b21
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
lsstdm/alert-stream-simulator:v1.2.1973df082d006
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
lsstdm/lsst_alert_packet:tickets-DM-3274374c97a490940
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
lsstsqre/exposurelog:0.8.079b00fb67a65
pillow@9.0.1
10.0.1
1
lsstsqre/kafkaaggregator:masterbe1b21060854
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
lsstsqre/squash-api:0.5.34879415ec6ac
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
maissacrement/pock8snodejs:0.0.16da0db1159da
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
matrixdotorg/synapse:v1.53.0cb89c0f17ba1
pillow@9.0.1
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
matrixdotorg/synapse:v1.78.0def97fd537d8
pillow@9.4.0
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
mcronce/yadms-ftp:latestf820ef2e3c26
pillow@7.0.0
10.0.1
1
mcronce/yadms-web:latestc03c1c7f5aa9
pillow@7.0.0
10.0.1
1
mediagis/nominatim:3.7c15e941485ef
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
mide/minecraft-overviewer:latest4eee0dcb715f
pillow@8.1.2
10.0.1
1
mintproject/data-catalog-db:9be70359feabe03ed55bfdbf92c20a7e43ab928b9bf26fedd848
libwebp@1.2.3-r0
1.2.3-r2
1
mintproject/mint-ui-lit:246a8771e8c043f8c1840d3c32262d3d6a9a553208c1a13c3397
libwebp@1.2.3-r0
1.2.3-r2
1
mintproject/model-catalog-explorer:0b2f9f0a9124076aeb492add2f123d0757066f6bdeb80c93b4a9
libwebp@1.2.3-r0
1.2.3-r2
1
misskey/misskey:12.110.1e08b7c478093
libwebp@1.2.2-r0
1.2.2-r2
1
mnaggar3396/python-app:latest371d8ed84b15
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
mondata/mlflow:v2.3.0.s3.gc6f94c6caf8bf
pillow@9.5.0
10.0.1
1
moreillon/api-proxy:2373c1953739ef6956b5
libwebp@0.6.1-2+deb10u2
0.6.1-2+deb10u3
1
moreillon/camera-proxy:latestce60056b50c2
libwebp@0.6.1-2+deb10u2
0.6.1-2+deb10u3
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
pillow@8.4.0
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
moreillon/mqtt-logger-front:50030b8bfc4d12db1d3e
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
mozilla/sentencecollector:2.0.91da6ff5c4895
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
mvitale1989/docker-taiga:20191031-4.2.141504ccda06df
pillow@4.3.0
10.0.1
1
n8nio/n8n:0.212.0a9195bc499a3
libwebp@1.2.3-r0
1.2.3-r2
1
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.