StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,639
of 17,797 indexed, latest versions
Container images
1,763
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,639 of 17,797 indexed charts deploy, on 1,763 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,387
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,639 by stars
ChartLatestAffected imagesRadar Score
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9

Open the chart page →

11,571
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,854
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,173
vaultstakaterVerified publisher0.8.41 of 2See more

vault stakater 0.8.4

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

5,871
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,565
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,678
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
openssh@1:9.2p1-2
1:9.2p1-2+deb12u2

Open the chart page →

20,317
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

6,595
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,985
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
prom/prometheus:v2.22.2f7ffebdd428b
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

16,537
ingress-istio-controllerstatcan1.4.01 of 1See more

ingress-istio-controller statcan 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,583
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
golang.org/x/crypto@v0.0.0-20210421170649-83a5a9bb288b
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,596
prometheus-operatorstatcan0.2.24 of 7See more

prometheus-operator statcan 0.2.2

4 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/crypto@v0.0.0-20200406173513-056763e48d71
0.0.0-20231218163308-9d2ee975ef9f
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/crypto@v0.0.0-20181203042331-505ab145d0a9
0.0.0-20231218163308-9d2ee975ef9f
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/crypto@v0.0.0-20191002192127-34f69633bfdc
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

12,251
sidecar-terminatorstatcan1.3.51 of 1See more

sidecar-terminator statcan 1.3.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,315
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

13,900
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,223
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

13,704
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,262
sn-platform-slimstreamnative1.11.442 of 6See more

sn-platform-slim streamnative 1.11.44

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/crypto@v0.4.0
0.17.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

10,270
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
openssh@9.0_p1-r4
9.0_p1-r5

Open the chart page →

1,447
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,354
nocodbsudermanjr0.1.01 of 1See more

nocodb sudermanjr 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
nocodb/nocodb:0.84.15f9b799933aa8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,070
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,262
cludodsuperorbitalVerified publisher0.0.51 of 1See more

cludod superorbital 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
superorbital/cludod:0.0.2-alphad59732f61d6e
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,371
nfs-provisionersupporttools0.11.01 of 1See more

nfs-provisioner supporttools 0.11.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
openebs/provisioner-nfs:0.11.04f41dd782761
golang.org/x/crypto@v0.0.0-20201124201722-c8d3bf9c5392
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,680
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libssh@0.9.6-2build1
openssh@1:8.9p1-3
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,122
freeradiussvtech-public-helm-charts0.1.52 of 4See more

freeradius svtech-public-helm-charts 0.1.5

2 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
paramiko@2.11.0
3.4.0
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

12,732
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
golang.org/x/crypto@v0.4.0
libssh@0.9.3-2ubuntu2.3
0.17.0
0.9.3-2ubuntu2.4

Open the chart page →

10,980
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
paramiko@2.11.0
3.4.0

Open the chart page →

5,891
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libssh@0.9.6-2build1
openssh@1:8.9p1-3
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,122
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
golang.org/x/crypto@v0.7.0
libssh@0.9.3-2ubuntu2.3
openssh@1:8.2p1-4ubuntu0.7
paramiko@2.11.0
0.17.0
0.9.3-2ubuntu2.4
1:8.2p1-4ubuntu0.10
3.4.0

Open the chart page →

18,853
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
golang.org/x/crypto@v0.16.0
0.17.0

Open the chart page →

2,336
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
libssh@0.9.6-10.el8_8
0:0.9.6-13.el8_9

Open the chart page →

14,061
synadia-serversynadiaVerified publisher1.1.101 of 2See more

synadia-server synadia 1.1.10

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/crypto@v0.13.0
0.17.0

Open the chart page →

1,971
agentssynapse0.1.304 of 9See more

agents synapse 0.1.30

4 of the 9 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.42.07d32a4eddec7
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
mysql/mysql-server:latestd6c8301b7834
paramiko@2.11.0
3.4.0
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/crypto@v0.6.0
0.17.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/crypto@v0.6.0
0.17.0

Open the chart page →

7,272
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

1,822
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

1,711
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
paramiko@2.11.0
3.4.0

Open the chart page →

2,694
sinnersynapse0.1.02 of 6See more

sinner synapse 0.1.0

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
paramiko@2.11.0
3.4.0
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/crypto@v0.16.0
0.17.0

Open the chart page →

1,962
ccm-hcloudsyself1.0.111 of 1See more

ccm-hcloud syself 1.0.11

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,713
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,876
promtailt3n1.0.01 of 1See more

promtail t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,828
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,490
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
golang.org/x/crypto@v0.2.0
openssh@9.3_p2-r0
0.17.0
9.3_p2-r1

Open the chart page →

4,218
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,772
clickhousetemp-charts0.7.12 of 3See more

clickhouse temp-charts 0.7.1

2 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,707
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,606
istio-ingresstemp-charts0.3.31 of 1See more

istio-ingress temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.088c6c693e67a
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,551
temporaltemporal0.28.97 of 13See more

temporal temporal 0.28.9

7 of the 13 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
temporalio/admin-tools:1.22.0836af062af30
golang.org/x/crypto@v0.10.0
0.17.0
temporalio/server:1.22.0ddeebf8bad8f
golang.org/x/crypto@v0.12.0
0.17.0
temporalio/ui:2.16.2af9c9349708f
golang.org/x/crypto@v0.1.0
0.17.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

21,042
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
paramiko@2.11.0
3.4.0

Open the chart page →

17,661

Container images carrying it

1,763 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/knative-releases/knative.dev/serving/cmd/activatora5de0fb75046
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler2ef460356b17
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/knative-releases/knative.dev/serving/cmd/autoscalerdb6ceff2aab4
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller30ce73388ae5
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
golang.org/x/crypto@v0.1.0
0.17.0
1
gcr.io/knative-releases/knative.dev/serving/cmd/controllerb2cd45b8a8a4
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/knative-releases/knative.dev/serving/cmd/controllerbac158dfb0c7
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookd27b4495ccc3
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/knative-releases/knative.dev/serving/cmd/webhookf16c0e022203
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
golang.org/x/crypto@v0.15.0
0.17.0
1
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
golang.org/x/crypto@v0.0.0-20220128200615-198e4374d7ed
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
golang.org/x/crypto@v0.0.0-20220128200615-198e4374d7ed
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
golang.org/x/crypto@v0.0.0-20220128200615-198e4374d7ed
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
golang.org/x/crypto@v0.0.0-20220128200615-198e4374d7ed
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
golang.org/x/crypto@v0.0.0-20220128200615-198e4374d7ed
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
golang.org/x/crypto@v0.1.0
0.17.0
1
gcr.io/projectsigstore/cosigned784518ff3ee7
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f
1
gcr.io/projectsigstore/policy-webhook82940e8c3e0d
golang.org/x/crypto@v0.0.0-20220411220226-7b82a4e95df4
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
golang.org/x/crypto@v0.0.0-20211209193657-4570a0811e8b
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/akhilrex/podgrab:1.0.0bce133f3f511
golang.org/x/crypto@v0.0.0-20200820211705-5c72a883971a
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
golang.org/x/crypto@v0.1.0
0.17.0
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
golang.org/x/crypto@v0.15.0
0.17.0
1
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
golang.org/x/crypto@v0.0.0-20220214200702-86341886e292
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
golang.org/x/crypto@v0.15.0
0.17.0
1
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
golang.org/x/crypto@v0.12.0
0.17.0
1
ghcr.io/appscode/grafana:v2025.2.367d18880448c
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/appscode/kube-rbac-proxy:v0.15.0d8cc6ffb9819
golang.org/x/crypto@v0.14.0
0.17.0
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
golang.org/x/crypto@v0.12.0
0.17.0
1
ghcr.io/astriaorg/ria-faucet:0.0.1a06c8ebef427
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/autobrr/autobrr:v1.10.0d4022cd32df5
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
golang.org/x/crypto@v0.7.0
0.17.0
1
ghcr.io/banzaicloud/kafka-operator:v0.20.2e341aefa9a90
golang.org/x/crypto@v0.0.0-20210921155107-089bfa567519
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/banzaicloud/logging-operator:3.17.623c2d4d54a64
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
golang.org/x/crypto@v0.14.0
0.17.0
1
ghcr.io/blakeblackshear/frigate:0.14.122e3d0b486df
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
golang.org/x/crypto@v0.14.0
0.17.0
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
golang.org/x/crypto@v0.3.0
libssh@0.9.3-2ubuntu2.2
openssh@1:8.2p1-4ubuntu0.5
0.17.0
0.9.3-2ubuntu2.4
1:8.2p1-4ubuntu0.10
1
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
golang.org/x/crypto@v0.0.0-20211215165025-cf75a172585e
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
golang.org/x/crypto@v0.14.0
0.17.0
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
libssh@0.9.6-2ubuntu0.22.04.1
0.9.6-2ubuntu0.22.04.2
1
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.