StackRadar

CVE-2023-4863

CriticalKEV

Advisory

Published 12 Sept 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.6
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 13 Sept 2023
Charts affected
454
of 17,781 indexed, latest versions
Container images
416
deployed by those charts
Fix available
5 of 5
affected packages

Red Hat Security Advisory: libwebp security update

Carried by container images the latest versions of 454 of 17,781 indexed charts deploy, on 416 images.

Affected packageAffected versionsFixed inImages
libwebprpm1.0.0-3.el8_40:1.0.0-7.el8_4.11
libwebpdeb0.6.1-2, 0.6.1-2.1, 0.6.1-2.1+deb11u1, 0.6.1-2+deb10u1+6 more0.6.1-2.1+deb11u2, 0.6.1-2+deb10u3, 0.6.1-2ubuntu0.18.04.2+esm1, 0.6.1-2ubuntu0.20.04.3+2 more300
libwebpapk1.2.2-r0, 1.2.3-r0, 1.2.3-r1, 1.2.4-r1+2 more1.2.2-r2, 1.2.3-r2, 1.2.4-r3, 1.3.1-r173
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+21 more10.0.168
SkiaSharpnuget2.80.2, 2.88.1-preview.71, 2.88.2, 2.88.32.88.66
OSV records
RHSA-2023:5222ALPINE-CVE-2023-4863DEBIAN-CVE-2023-4863GHSA-j7hp-h8jx-5pprPYSEC-2026-1794UBUNTU-CVE-2023-4863DLA-3570-1DSA-5497-2
Also known as
A-299477569, ASB-A-299477569, CVE-2023-5129, DSA-5497-1, RUSTSEC-2023-0060, RUSTSEC-2023-0061, USN-6369-1, USN-6369-2

Charts affected

454 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libwebp@1.2.2-r0
1.2.2-r2
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
libwebp@1.2.2-r0
1.2.2-r2

Open the chart page →

16,083
myfirstchartww-helm-charts-repo0.1.01 of 1See more

myfirstchart ww-helm-charts-repo 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginx:0.1.0205961b09a80
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2

Open the chart page →

1,838
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138

Container images carrying it

416 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ncsapolyglot/converters-ebook-convert:latest438d82cdbdb5
pillow@5.2.0
10.0.1
1
netboxcommunity/netbox:v3.2.83d652dca5351
pillow@9.2.0
10.0.1
1
nethermind/nethermind:1.14.615517708c3b6
libwebp@1.2.2-2
1.2.2-2ubuntu0.22.04.2
1
nginx/nginx-ingress:1.11.1eb5b4fd73325
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
nlmacamp/check_mk:latest5dbb8589f824
pillow@5.0.0
10.0.1
1
nrrrus/nginx-test:latest5f55cd4ef557
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
octoprint/octoprint:1.4.0106c26efcd8a
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
octoprint/octoprint:1.6.1ea3bffae2470
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libwebp@0.6.1-2
0.6.1-2ubuntu0.18.04.2+esm1
1
opendatacube/wms:latest1b90cdf68831
libwebp@0.6.1-2
pillow@5.1.0
0.6.1-2ubuntu0.18.04.2+esm1
10.0.1
1
opendatacube/wps:latest80df355a660b
pillow@9.0.1
10.0.1
1
openelevation/open-elevation:latest82fb21612e86
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
openemr/openemr:6.1.089eaa6d9a4e3
libwebp@1.2.2-r0
1.2.2-r2
1
openkm/openkm-ce:6.3.113bc465a7461b
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
openproject/community:12.0.2734743d11094
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
openspeedtest/latest:v2.0.0d4d62f4b7d85
libwebp@1.2.4-r2
1.2.4-r3
1
openwhisk/kafkaprovider:2.1.063dc3d2a0904
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
openzaak/open-zaak:1.6.02ca2ea6e0ae9
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
patdada/bella-docker:v1.0.075127147a624
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
pecan/monitor:1.7.273b2074f3fec
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
penpotapp/frontend:2.2.18974882a0542
libwebp@0.6.1-2.1+deb11u1
0.6.1-2.1+deb11u2
1
phntom/binaryvision-static-wordpress:0.0.385a2dfb83b11
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
phntom/email-manager:0.1.22d8e2a9f2f085
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
phntom/external-dns-host-network:0.0.123adadbac8443
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
phntom/kix-static-website:latest49ce665acb59
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
phntom/mattermost-defaultbackend:6.4.0c318dc90a4bf
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
photoprism/photoprism:220629-jammy2954334adbda
libwebp@1.2.2-2
1.2.2-2ubuntu0.22.04.2
1
phpmyadmin/phpmyadmin:5.138437e021deb
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
plumdog/db-operator:latest0c2fa2db0357
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
pnnlmiscscripts/k8s-node-image:1.20.15-nginx-18bbc7a777f9f7
libwebp@1.2.2-r0
1.2.3-r2
1
pnnlmiscscripts/k8s-node-image9:1.23.17-nginx-3479ada675515f
libwebp@1.2.4-r2
1.2.4-r3
1
pnnlmiscscripts/k8s-node-image9:1.22.17-nginx-34b85e437ae261
libwebp@1.2.4-r2
1.2.4-r3
1
pnnlmiscscripts/k8s-node-image9:1.21.14-nginx-33fa8f5906d36a
libwebp@1.2.4-r2
1.2.4-r3
1
postgis/postgis:15-3.3-alpine4738bee21eb6
libwebp@1.3.1-r0
1.3.1-r1
1
postgis/postgis:10-3.2-alpine7e3e68a36d53
libwebp@1.2.3-r0
1.2.3-r2
1
prefapp/nginx-proxified:latestf4d026fd9a26
libwebp@1.2.3-r0
1.2.3-r2
1
project2team4/react:latest3ff031a08887
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
rdavidoff/twitch-channel-points-miner-v2:1.8.67ae4c5135771
pillow@10.0.0
10.0.1
1
reportportal/service-ui:5.7.20a08784eb901
libwebp@1.2.2-r0
1.2.3-r2
1
rlex/jsonvisio:1.9.5cd50ff65118e
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
roadiehq/community-backstage-image:latestef355bf5b639
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
robmarkcole/deepstack-ui:latest410275726459
pillow@8.3.2
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
robotshop/rs-payment:latest774b52c6180d
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
robotshop/rs-web:latestb3c20d4a22f2
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
roundcube/roundcubemail:1.5.3-apachea8ea6fd751dc
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
samajh/alprbackend:latestea742b4372ad
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
samajh/alprfrontend:latest05ef4fddbb75
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
santisbon/evwatcher:latestc4e994ca4540
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1
santisbon/evworker:lateste807283f8d69
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.