StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,639
of 17,792 indexed, latest versions
Container images
1,763
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,639 of 17,792 indexed charts deploy, on 1,763 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,387
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,639 by stars
ChartLatestAffected imagesRadar Score
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9

Open the chart page →

11,557
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,853
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,173
vaultstakaterVerified publisher0.8.41 of 2See more

vault stakater 0.8.4

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

5,871
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,564
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,678
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
openssh@1:9.2p1-2
1:9.2p1-2+deb12u2

Open the chart page →

20,321
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

6,587
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,985
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
prom/prometheus:v2.22.2f7ffebdd428b
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

16,537
ingress-istio-controllerstatcan1.4.01 of 1See more

ingress-istio-controller statcan 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,583
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
golang.org/x/crypto@v0.0.0-20210421170649-83a5a9bb288b
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,596
prometheus-operatorstatcan0.2.24 of 7See more

prometheus-operator statcan 0.2.2

4 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/crypto@v0.0.0-20200406173513-056763e48d71
0.0.0-20231218163308-9d2ee975ef9f
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/crypto@v0.0.0-20181203042331-505ab145d0a9
0.0.0-20231218163308-9d2ee975ef9f
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/crypto@v0.0.0-20191002192127-34f69633bfdc
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

12,251
sidecar-terminatorstatcan1.3.51 of 1See more

sidecar-terminator statcan 1.3.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,315
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

13,844
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,222
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

13,696
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,242
sn-platform-slimstreamnative1.11.442 of 6See more

sn-platform-slim streamnative 1.11.44

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/crypto@v0.4.0
0.17.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

10,214
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
openssh@9.0_p1-r4
9.0_p1-r5

Open the chart page →

1,447
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,353
nocodbsudermanjr0.1.01 of 1See more

nocodb sudermanjr 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
nocodb/nocodb:0.84.15f9b799933aa8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,070
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,242
cludodsuperorbitalVerified publisher0.0.51 of 1See more

cludod superorbital 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
superorbital/cludod:0.0.2-alphad59732f61d6e
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,371
nfs-provisionersupporttools0.11.01 of 1See more

nfs-provisioner supporttools 0.11.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
openebs/provisioner-nfs:0.11.04f41dd782761
golang.org/x/crypto@v0.0.0-20201124201722-c8d3bf9c5392
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,680
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libssh@0.9.6-2build1
openssh@1:8.9p1-3
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,100
freeradiussvtech-public-helm-charts0.1.52 of 4See more

freeradius svtech-public-helm-charts 0.1.5

2 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
paramiko@2.11.0
3.4.0
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

12,712
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
golang.org/x/crypto@v0.4.0
libssh@0.9.3-2ubuntu2.3
0.17.0
0.9.3-2ubuntu2.4

Open the chart page →

10,959
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
paramiko@2.11.0
3.4.0

Open the chart page →

5,883
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libssh@0.9.6-2build1
openssh@1:8.9p1-3
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,100
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
golang.org/x/crypto@v0.7.0
libssh@0.9.3-2ubuntu2.3
openssh@1:8.2p1-4ubuntu0.7
paramiko@2.11.0
0.17.0
0.9.3-2ubuntu2.4
1:8.2p1-4ubuntu0.10
3.4.0

Open the chart page →

18,846
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
golang.org/x/crypto@v0.16.0
0.17.0

Open the chart page →

2,336
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
libssh@0.9.6-10.el8_8
0:0.9.6-13.el8_9

Open the chart page →

14,058
synadia-serversynadiaVerified publisher1.1.101 of 2See more

synadia-server synadia 1.1.10

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/crypto@v0.13.0
0.17.0

Open the chart page →

1,970
agentssynapse0.1.304 of 9See more

agents synapse 0.1.30

4 of the 9 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.42.07d32a4eddec7
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
mysql/mysql-server:latestd6c8301b7834
paramiko@2.11.0
3.4.0
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/crypto@v0.6.0
0.17.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/crypto@v0.6.0
0.17.0

Open the chart page →

7,272
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

1,822
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

1,711
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
paramiko@2.11.0
3.4.0

Open the chart page →

2,694
sinnersynapse0.1.02 of 6See more

sinner synapse 0.1.0

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
paramiko@2.11.0
3.4.0
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/crypto@v0.16.0
0.17.0

Open the chart page →

1,962
ccm-hcloudsyself1.0.111 of 1See more

ccm-hcloud syself 1.0.11

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,712
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,876
promtailt3n1.0.01 of 1See more

promtail t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,828
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,489
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
golang.org/x/crypto@v0.2.0
openssh@9.3_p2-r0
0.17.0
9.3_p2-r1

Open the chart page →

4,222
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,772
clickhousetemp-charts0.7.12 of 3See more

clickhouse temp-charts 0.7.1

2 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,706
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,585
istio-ingresstemp-charts0.3.31 of 1See more

istio-ingress temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.088c6c693e67a
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,531
temporaltemporal0.28.97 of 13See more

temporal temporal 0.28.9

7 of the 13 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
temporalio/admin-tools:1.22.0836af062af30
golang.org/x/crypto@v0.10.0
0.17.0
temporalio/server:1.22.0ddeebf8bad8f
golang.org/x/crypto@v0.12.0
0.17.0
temporalio/ui:2.16.2af9c9349708f
golang.org/x/crypto@v0.1.0
0.17.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

21,040
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
paramiko@2.11.0
3.4.0

Open the chart page →

17,590

Container images carrying it

1,763 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
library/traefik:2.10.61957e3314f43
golang.org/x/crypto@v0.14.0
0.17.0
1
library/traefik:2.5.62f603f8d3abe
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
1
library/traefik:v1.7.345d47b7bb2546
golang.org/x/crypto@v0.0.0-20210920023735-84f357641f63
0.0.0-20231218163308-9d2ee975ef9f
1
library/traefik:2.5.47d0228d19042
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
1
library/traefik:2.4.8eda951fd29a8
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
1
library/traefik:2.2.8f5af5a5ce17f
golang.org/x/crypto@v0.0.0-20200317142112-1b76d66859c6
0.0.0-20231218163308-9d2ee975ef9f
1
library/vault:1.13.3f98ac9dd97b0
golang.org/x/crypto@v0.6.0
0.17.0
1
library/zookeeper:3.8-temurin55d1e5b2e601
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
openssh@1:7.6p1-4ubuntu0.3
1:7.6p1-4ubuntu0.7+esm3
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
linuxserver/cloud9:latest45c5fe102ff3
golang.org/x/crypto@v0.0.0-20211202192323-5770296d904e
0.0.0-20231218163308-9d2ee975ef9f
1
linuxserver/code-server:4.10.1a5e43a05ae79
libssh@0.9.6-2build1
openssh@1:8.9p1-3ubuntu0.1
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5
1
linuxserver/couchpotato:75e576ee-ls32c4d2766b9eb7
paramiko@2.7.1
3.4.0
1
linuxserver/jellyfin:10.7.72427dde159a2
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
linuxserver/plex:1.25.24a13ced2326c
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
linuxserver/sickchill:v2020.08.07-1-ls40e48b479c1891
paramiko@2.7.1
3.4.0
1
linuxserver/unifi-controller:7.3.83ab105cc50322
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
lishimeng/hufu:v1.2.13d5752dac834
golang.org/x/crypto@v0.11.0
0.17.0
1
lishimeng/owl-console:v0.11.2c79a67657baf
golang.org/x/crypto@v0.14.0
0.17.0
1
lishimeng/owl-messager:v0.11.23d00485e64dc
golang.org/x/crypto@v0.14.0
0.17.0
1
lishimeng/passport:v0.2.163e7d05ded625
golang.org/x/crypto@v0.7.0
0.17.0
1
lishimeng/passport-profile:v0.2.160970dfe5dc8f
golang.org/x/crypto@v0.7.0
0.17.0
1
lishimeng/tabby:v1.0.48145c3dc83c8
golang.org/x/crypto@v0.7.0
0.17.0
1
lishimeng/tree:v0.2.89b2f8be6c7d3
golang.org/x/crypto@v0.7.0
0.17.0
1
lishimeng/zoo:v0.4.0e0b8d2d8ca28
golang.org/x/crypto@v0.13.0
0.17.0
1
litestream/litestream:0.3c5a1e1b01916
golang.org/x/crypto@v0.12.0
0.17.0
1
livekit/ingress:v1.2.21ab01641b366
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2
1
livekit/livekit-recorder:v0.3.13ecf1409c75e0
golang.org/x/crypto@v0.0.0-20210314154223-e6e6c4f2bb5b
0.0.0-20231218163308-9d2ee975ef9f
1
livekit/livekit-server:v1.0.08391fd1b834f
golang.org/x/crypto@v0.0.0-20220516162934-403b01795ae8
0.0.0-20231218163308-9d2ee975ef9f
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
1
loftsh/jspolicy:0.2.225deb9bd2683
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f
1
loftsh/virtual-cluster:0.0.28023b13bf5898
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f
1
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f
1
longhornio/longhorn-manager:v1.2.3dca34321452c
golang.org/x/crypto@v0.0.0-20201216223049-8b5274cf687f
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
golang.org/x/crypto@v0.8.0
0.17.0
1
louislam/uptime-kuma:1.23.1396510915e6be
golang.org/x/crypto@v0.16.0
0.17.0
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.0.0-20231218163308-9d2ee975ef9f
1
louislam/uptime-kuma:1.18.5a84767d7934f
golang.org/x/crypto@v0.0.0-20220427172511-eb4f295cb31f
0.0.0-20231218163308-9d2ee975ef9f
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
golang.org/x/crypto@v0.16.0
0.17.0
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
lumenvox/cloud-binary-storage:2.0.053decadc102d
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
lumenvox/cloud-license:2.0.09a69862e1248
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
1
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
openssh@1:8.2p1-4ubuntu0.13
1:8.2p1-4ubuntu0.fips.0.10
1
mantlenetworkio/l2geth:v0.4.36bf383d14291
golang.org/x/crypto@v0.9.0
0.17.0
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
golang.org/x/crypto@v0.4.0
0.17.0
1
masipcat/wireguard-go:latest696206e5954d
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.0.0-20231218163308-9d2ee975ef9f
1
masipcat/wireguard-go:0.0.20230223769f7bb64694
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.0.0-20231218163308-9d2ee975ef9f
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.