StackRadar

CVE-2023-4863

CriticalKEV

Advisory

Published 12 Sept 2023In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.6
base score, highest
EPSS
1.000
100th percentile
CISA KEV
Listed
since 13 Sept 2023
Charts affected
454
of 17,781 indexed, latest versions
Container images
416
deployed by those charts
Fix available
5 of 5
affected packages

Red Hat Security Advisory: libwebp security update

Carried by container images the latest versions of 454 of 17,781 indexed charts deploy, on 416 images.

Affected packageAffected versionsFixed inImages
libwebprpm1.0.0-3.el8_40:1.0.0-7.el8_4.11
libwebpdeb0.6.1-2, 0.6.1-2.1, 0.6.1-2.1+deb11u1, 0.6.1-2+deb10u1+6 more0.6.1-2.1+deb11u2, 0.6.1-2+deb10u3, 0.6.1-2ubuntu0.18.04.2+esm1, 0.6.1-2ubuntu0.20.04.3+2 more300
libwebpapk1.2.2-r0, 1.2.3-r0, 1.2.3-r1, 1.2.4-r1+2 more1.2.2-r2, 1.2.3-r2, 1.2.4-r3, 1.3.1-r173
pillowpypi2.6.1, 4.3.0, 5.0.0, 5.1.0+21 more10.0.168
SkiaSharpnuget2.80.2, 2.88.1-preview.71, 2.88.2, 2.88.32.88.66
OSV records
RHSA-2023:5222ALPINE-CVE-2023-4863DEBIAN-CVE-2023-4863GHSA-j7hp-h8jx-5pprPYSEC-2026-1794UBUNTU-CVE-2023-4863DLA-3570-1DSA-5497-2
Also known as
A-299477569, ASB-A-299477569, CVE-2023-5129, DSA-5497-1, RUSTSEC-2023-0060, RUSTSEC-2023-0061, USN-6369-1, USN-6369-2

Charts affected

454 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-chat:v1.17.7da12f37e6795
libwebp@1.2.2-r0
1.2.2-r2
thecodingmachine/workadventure-ejabberd:v1.17.701df99622ad3
libwebp@1.2.2-r0
1.2.2-r2

Open the chart page →

16,083
myfirstchartww-helm-charts-repo0.1.01 of 1See more

myfirstchart ww-helm-charts-repo 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginx:0.1.0205961b09a80
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2

Open the chart page →

1,838
myfirstchartzikilabVerified publisher0.2.01 of 1See more

myfirstchart zikilab 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-4863.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kubenginxhelm:0.2.0ae2268dcc930
libwebp@0.6.1-2
0.6.1-2+deb10u3

Open the chart page →

1,138

Container images carrying it

416 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
libwebp@0.6.1-2+deb10u2
0.6.1-2+deb10u3
1
ghcr.io/volosoft/eshoponabp/app-web:1.0.0056bb4271626
libwebp@1.2.3-r0
1.2.3-r2
1
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
ghcr.io/wbstack/queryservice-ui:1.4bc79fbb50230
libwebp@1.2.2-r0
1.2.2-r2
1
ghcr.io/wbstack/ui:3.94b01f67faadf1
libwebp@1.2.2-r0
1.2.2-r2
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
pillow@9.4.0
10.0.1
1
public.ecr.aws/jtekt-corporation/annotation-tool:ef974ad9abd817eb6845
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
public.ecr.aws/jtekt-corporation/polygonal-annotation-tool:a3fa936056efd38500d6
libwebp@0.6.1-2.1
0.6.1-2.1+deb11u2
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libwebp@0.6.1-2ubuntu0.20.04.1
0.6.1-2ubuntu0.20.04.3
1
quay.io/fairwinds/yelb-appserver:v0.6.0fae21f06131f
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
quay.io/fairwinds/yelb-ui:v0.1.05ac114e567ed
libwebp@0.6.1-2
0.6.1-2+deb10u3
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
libwebp@0.6.1-2+deb10u1
0.6.1-2+deb10u3
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libwebp@1.2.4-0.2
1.2.4-0.2+deb12u1
1
registry.gitlab.com/open-forms/design-catalogue:latestf21f19346b29
libwebp@0.6.1-2
0.6.1-2+deb10u3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.