StackRadar

CVE-2023-4863

CriticalKEV

Advisory

Published 12 Sept 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.6
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 13 Sept 2023
Charts affected
454
of 17,781 indexed, latest versions
Container images
416
deployed by those charts
Fix available
5 of 5
affected packages

Red Hat Security Advisory: libwebp security update

Carried by container images the latest versions of 454 of 17,781 indexed charts deploy, on 416 images.

Affected packageAffected versionsFixed inImages
libwebprpm1.0.0-3.el8_40:1.0.0-7.el8_4.11
libwebpdeb0.6.1-2, 0.6.1-2.1, 0.6.1-2.1+deb11u1, 0.6.1-2+deb10u1+6 more0.6.1-2.1+deb11u2, 0.6.1-2+deb10u3, 0.6.1-2ubuntu0.18.04.2+esm1, 0.6.1-2ubuntu0.20.04.3+2 more300
libwebpapk1.2.2-r0, 1.2.3-r0, 1.2.3-r1, 1.2.4-r1+2 more1.2.2-r2, 1.2.3-r2, 1.2.4-r3, 1.3.1-r173
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+21 more10.0.168
SkiaSharpnuget2.80.2, 2.88.1-preview.71, 2.88.2, 2.88.32.88.66
OSV records
RHSA-2023:5222ALPINE-CVE-2023-4863DEBIAN-CVE-2023-4863GHSA-j7hp-h8jx-5pprPYSEC-2026-1794UBUNTU-CVE-2023-4863DLA-3570-1DSA-5497-2
Also known as
A-299477569, ASB-A-299477569, CVE-2023-5129, DSA-5497-1, RUSTSEC-2023-0060, RUSTSEC-2023-0061, USN-6369-1, USN-6369-2

Charts affected

454 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libwebp@1.2.2-r0
1.2.2-r2
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
libwebp@1.2.2-r0
1.2.2-r2

Open the chart page →

16,083
myfirstchartww-helm-charts-repo0.1.01 of 1See more

myfirstchart ww-helm-charts-repo 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginx:0.1.0205961b09a80
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2

Open the chart page →

1,838
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138

Container images carrying it

416 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
santisbon/speedtest:latest8ee3a1697227
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1
scrapinghub/splash:3.4.1a5f89bc84606
libwebp@0.6.1-2
pillow@5.4.1
0.6.1-2ubuntu0.18.04.2+esm1
10.0.1
1
seafileltd/seafile-mc:9.0.106693911bcc40
libwebp@0.6.1-2ubuntu0.20.04.1
pillow@9.3.0
0.6.1-2ubuntu0.20.04.3
10.0.1
1
seafileltd/seafile-mc:10.0.170628f29c663
pillow@9.3.0
10.0.1
1
seafileltd/seafile-mc:9.0.97ac833196f60
libwebp@0.6.1-2ubuntu0.20.04.1
pillow@9.2.0
0.6.1-2ubuntu0.20.04.3
10.0.1
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
libwebp@0.6.1-2ubuntu0.20.04.1
pillow@8.3.1
0.6.1-2ubuntu0.20.04.3
10.0.1
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
libwebp@1.0.0-3.el8_4
0:1.0.0-7.el8_4.1
1
shinobisystems/shinobi:dev3ca746937856
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
shinobisystems/shinobi:latestc2f5ce2e1067
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
shyim/shopware:6.4.6.0a951c0e6b836
libwebp@1.2.3-r1
1.2.3-r2
1
simpleidserver/faaswebsite:0.0.4367218ae760f
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
sismics/docs:v1.10f4b0ef019cf1
libwebp@0.6.1-2ubuntu0.18.04.1
0.6.1-2ubuntu0.18.04.2+esm1
1
smailkoz/torrserver:1.0.1117b52d15de8f0
libwebp@1.2.2-r0
1.2.2-r2
1
snipe/snipe-it:v6.0.1455fb7636a98c
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
socialmediamacroscope/classification_predict:0.1.24fb86885d64d
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
socialmediamacroscope/classification_split:0.1.24bfda60829fe
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
socialmediamacroscope/classification_train:0.1.207477060bba8
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
socialmediamacroscope/clowder_create_collection:0.1.0c969f7677983
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
socialmediamacroscope/clowder_create_dataset:0.1.09b4211832429
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
socialmediamacroscope/clowder_create_space:0.1.0999f2ff2c128
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
socialmediamacroscope/clowder_list:0.1.051cb17626519
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
socialmediamacroscope/clowder_upload_file:0.1.274e35f64db68
libwebp@0.6.1-2.1+deb11u1
0.6.1-2.1+deb11u2
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1
socialmediamacroscope/screen_name_prompt:0.1.2724f3f5702e0
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1
solidnerd/bookstack:21.12762ffd5c51d3
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
soulou2019/angular-nginx:latesta3970f97c215
libwebp@1.2.2-r0
1.2.2-r2
1
stacksimplify/kube-nginxapp1:1.0.0ead648280067
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
stacksimplify/kube-nginxapp2:1.0.0ce2b15139aca
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
stanfordoval/almond-server:latest1a63cdccedaf
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
stashapp/stash:latest24dbd7607174
libwebp@0.6.1-2
0.6.1-2ubuntu0.20.04.3
1
stratospire/activityrelay:0.2.3a4c34cb01117
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
stremio/server:latest3dc145603def
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
swaggerapi/swagger-ui:v4.12.00d7088d47928
libwebp@1.2.2-r0
1.2.2-r2
1
swaggerapi/swagger-ui:v4.15.511b20aebb92c
libwebp@1.2.3-r0
1.2.3-r2
1
swaggerapi/swagger-ui:v5.6.2342808e22de4
libwebp@1.3.1-r0
1.3.1-r1
1
swaggerapi/swagger-ui:v4.15.27ff9a86f35ff
libwebp@1.2.3-r0
1.2.3-r2
1
swisscomcloud/esc-vm-scheduler-web:latestb6639d1a922e
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
tachyongroup/mlflow-deployment-controller-ui:mlflow-controller-0.1.8f4f7fabe1037
pillow@9.4.0
10.0.1
1
taemon1337/ingress-dashboard:0.0.10e8f5096c66bb
libwebp@1.2.2-r0
1.2.2-r2
1
taigaio/taiga-back:6.4.29f97323cc150
pillow@8.2.0
10.0.1
1
tdeutsch/podsync:v2.4.2b67186f4c9a5
libwebp@1.2.3-r0
1.2.3-r2
1
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libwebp@1.2.2-r0
1.2.2-r2
1
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
libwebp@1.2.2-r0
1.2.2-r2
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
libwebp@1.2.2-2
1.2.2-2ubuntu0.22.04.2
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
libwebp@1.2.2-2
1.2.2-2ubuntu0.22.04.2
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
libwebp@1.2.2-2
1.2.2-2ubuntu0.22.04.2
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
pillow@5.0.0
10.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.