StackRadar

CVE-2023-4863

CriticalKEV

Advisory

Published 12 Sept 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.6
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 13 Sept 2023
Charts affected
454
of 17,781 indexed, latest versions
Container images
416
deployed by those charts
Fix available
5 of 5
affected packages

Red Hat Security Advisory: libwebp security update

Carried by container images the latest versions of 454 of 17,781 indexed charts deploy, on 416 images.

Affected packageAffected versionsFixed inImages
libwebprpm1.0.0-3.el8_40:1.0.0-7.el8_4.11
libwebpdeb0.6.1-2, 0.6.1-2.1, 0.6.1-2.1+deb11u1, 0.6.1-2+deb10u1+6 more0.6.1-2.1+deb11u2, 0.6.1-2+deb10u3, 0.6.1-2ubuntu0.18.04.2+esm1, 0.6.1-2ubuntu0.20.04.3+2 more300
libwebpapk1.2.2-r0, 1.2.3-r0, 1.2.3-r1, 1.2.4-r1+2 more1.2.2-r2, 1.2.3-r2, 1.2.4-r3, 1.3.1-r173
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+21 more10.0.168
SkiaSharpnuget2.80.2, 2.88.1-preview.71, 2.88.2, 2.88.32.88.66
OSV records
RHSA-2023:5222ALPINE-CVE-2023-4863DEBIAN-CVE-2023-4863GHSA-j7hp-h8jx-5pprPYSEC-2026-1794UBUNTU-CVE-2023-4863DLA-3570-1DSA-5497-2
Also known as
A-299477569, ASB-A-299477569, CVE-2023-5129, DSA-5497-1, RUSTSEC-2023-0060, RUSTSEC-2023-0061, USN-6369-1, USN-6369-2

Charts affected

454 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libwebp@1.2.2-r0
1.2.2-r2
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
libwebp@1.2.2-r0
1.2.2-r2

Open the chart page →

16,083
myfirstchartww-helm-charts-repo0.1.01 of 1See more

myfirstchart ww-helm-charts-repo 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginx:0.1.0205961b09a80
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2

Open the chart page →

1,838
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138

Container images carrying it

416 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
timothyclarke/wptserver:2018-03-0840a80ced8031
pillow@2.6.1
10.0.1
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
pillow@9.0.0
10.0.1
1
vikunja/frontend:0.17.0863a426a8e49
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
vlebediantsev/notes-admin-front:latest007c6670ff48
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1
vlebediantsev/notes-project-front:latest945675fd2636
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1
weblate/weblate:3.11.3-182848df56ecd
pillow@5.4.1
libwebp@0.6.1-2
10.0.1
0.6.1-2+deb10u3
1
xeladock/mysql_dns:latest4baf531453f1
libwebp@1.2.2-2
1.2.2-2ubuntu0.22.04.2
1
xeladock/nginx2:latestc259a67b1dff
libwebp@1.2.2-2
1.2.2-2ubuntu0.22.04.2
1
youssef11gaber10/deployment-ui-react:latestba6853e35c60
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
pillow@8.4.0
10.0.1
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
libwebp@1.2.2-2
1.2.2-2ubuntu0.22.04.2
1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
libwebp@0.6.1-2.1
1.2.2-2ubuntu0.22.04.2
1
zammad/zammad-docker-compose:zammad-4.1.0-312808e2dfa810
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
zohardocker12/weather_app_flask:latestb86d60dbb68d
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
gcr.io/ml-pipeline/metadata-writer:2.0.0-alpha.5ec3ae9f6df47
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
ghcr.io/0xemma/reddark:main2a115e991894
libwebp@0.6.1-2.1+deb11u1
0.6.1-2.1+deb11u2
1
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
libwebp@1.2.2-r0
1.2.2-r2
1
ghcr.io/appuio/cloud-portal:v0.2.18c7e08d32d70
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
SkiaSharp@2.88.2
2.88.6
1
ghcr.io/blakeblackshear/frigate:0.12.0c862771e38e8
pillow@8.1.2
libwebp@0.6.1-2.1
10.0.1
0.6.1-2.1+deb11u2
1
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/codingducksrl/wordpress:6.0.23113c0960507
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
ghcr.io/conductionnl/adresservice-nginx:latest849af80ab017
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/authorization-component-nginx:latest02d0644aa99b
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/berichtservice-nginx:latest833d26df3840
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
ghcr.io/conductionnl/bisc-frontend:latestd8a0334cddfc
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/brpservice-nginx:latest4db9b77c4425
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/commonground-gateway-frontend:dev3b3fbb57cae8
libwebp@1.2.3-r0
1.2.3-r2
1
ghcr.io/conductionnl/contactcatalogus-nginx:latest480c84fa9e63
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
ghcr.io/conductionnl/digispoof-interface-nginx:latest8fa4597217a4
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
ghcr.io/conductionnl/eav-component-nginx:latestd785c893096c
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
ghcr.io/conductionnl/education-component-nginx:latest38900bc76ee0
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
ghcr.io/conductionnl/eherkenning-ui-nginx:latestfcd2100d863f
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/grafregistratiecomponent-nginx:latestd0daf48dec68
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/instemmingservice-nginx:latesteeeb4e9f0485
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/landelijketabellencatalogus-nginx:lateste7076242888a
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/loggingcomponent-nginx:latestcee37e9cef09
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/logicservice-nginx:latest7c8ee08c591c
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/medewerkercatalogus-nginx:latest06c3b27462e6
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
ghcr.io/conductionnl/memo-component-nginx:latestfd28182f7ecf
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/notification-component-nginx:latestd53bda41ee3b
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/ocatiecatalogus-nginx:latestc46374fc8f32
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/orderregistratiecomponent-nginx:latest42acee4ab31c
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/procestypecatalogus-nginx:latestca6fc575a3ba
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/productenendienstencatalogus-nginx:latest4095e7207822
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/proto-component-commonground-nginx:latest5b1384e29b7d
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
ghcr.io/conductionnl/review-component-nginx:latest5df5f92870a5
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.