StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,639
of 17,792 indexed, latest versions
Container images
1,763
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,639 of 17,792 indexed charts deploy, on 1,763 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,387
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,639 by stars
ChartLatestAffected imagesRadar Score
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
golang.org/x/crypto@v0.6.0
0.17.0

Open the chart page →

2,470
backendmojaloop0.1.02 of 6See more

backend mojaloop 0.1.0

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
golang.org/x/crypto@v0.0.0-20201208171446-5f87f3452ae9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

16,304
reporting-nifi-processor-svcmojaloop0.0.21 of 3See more

reporting-nifi-processor-svc mojaloop 0.0.2

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mongo:6.0.271a63fc2438e
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

6,232
mongodb-query-exportermongodb-query-exporterVerified publisher5.1.01 of 1See more

mongodb-query-exporter mongodb-query-exporter 5.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/raffis/mongodb-query-exporter:v5.1.0ca6ac8a5b329
golang.org/x/crypto@v0.13.0
0.17.0

Open the chart page →

989
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

11,738
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,561
mqtt-loggermoreillonVerified publisher0.3.12 of 5See more

mqtt-logger moreillon 0.3.1

2 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
golang.org/x/crypto@v0.0.0-20220331220935-ae2d96664a29
0.0.0-20231218163308-9d2ee975ef9f
bitnamilegacy/mongodb:6.0.4-debian-11-r10016dce036593
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

11,020
user-manager-mongodbmoreillonVerified publisher0.6.22 of 4See more

user-manager-mongodb moreillon 0.6.2

2 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:6.0.10-debian-11-r842319decb591
golang.org/x/crypto@v0.12.0
0.17.0
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u2

Open the chart page →

25,877
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u2

Open the chart page →

30,575
backupmorremeyer4.0.01 of 1See more

backup morremeyer 4.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
restic/restic:0.15.2579e4e6a4931
golang.org/x/crypto@v0.7.0
openssh@9.1_p1-r2
0.17.0
9.1_p1-r5

Open the chart page →

2,303
hcloud-ccm-networksmorremeyer2.0.01 of 1See more

hcloud-ccm-networks morremeyer 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
golang.org/x/crypto@v0.10.0
0.17.0

Open the chart page →

1,746
chirpstackmosquitto-helm-chart0.5.02 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

2 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.9.0d056c89b7131
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
chirpstack/chirpstack-application-server:3fb7667fe037f
golang.org/x/crypto@v0.0.0-20200709230013-948cd5f35899
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

26,081
chirpstack-event-forwardmosquitto-helm-chart0.1.21 of 1See more

chirpstack-event-forward mosquitto-helm-chart 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,854
pulsarmosquitto-helm-chart0.2.01 of 1See more

pulsar mosquitto-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.10.03b262ab7a7d9
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

15,749
replacermosquitto-helm-chart0.2.01 of 3See more

replacer mosquitto-helm-chart 0.2.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/replacer:v1.1.00b2a41c2a43e
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,931
configmapsecretsmozilla0.0.11 of 1See more

configmapsecrets mozilla 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,109
mum-discord-botmum-discord-botVerified publisher0.3.71 of 1See more

mum-discord-bot mum-discord-bot 0.3.7

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u2

Open the chart page →

13,772
pagesmuthu-pages1.0.01 of 3See more

pages muthu-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,262
unpollermvisonneau0.1.01 of 1See more

unpoller mvisonneau 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
golift/unifi-poller:v2.9.2585a29a06d05
golang.org/x/crypto@v0.13.0
0.17.0

Open the chart page →

1,190
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

12,867
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

12,867
authmyaVerified publisher22.4.31 of 1See more

auth mya 22.4.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,381
my-app-namemy-app-name0.0.21 of 1See more

my-app-name my-app-name 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
libssh@0.9.4-3.el8
0:0.9.6-13.el8_9

Open the chart page →

9,418
elasticsearch-chartmy-elasticsearch0.1.01 of 2See more

elasticsearch-chart my-elasticsearch 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

9,353
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
golang.org/x/crypto@v0.0.0-20211108221036-ceb1ce70b4fa
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,368
Practica_4_helmmy-heml-appVerified publisher0.1.03 of 7See more

Practica_4_helm my-heml-app 0.1.0

3 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
codeurjc/server:v1.0310bea5b1ee7
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
codeurjc/weatherservice:v1.0b9e2f7234349
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
library/mongo:5.0.6-focal8e70544b6c76
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

27,861
phonebook-chartmy-phonebook-chart0.1.01 of 3See more

phonebook-chart my-phonebook-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
paramiko@2.11.0
3.4.0

Open the chart page →

3,032
mychartmysqlweb0.1.01 of 1See more

mychart mysqlweb 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
qichenxu4pd/mysqlweb:1.2d758d41d9c6b
paramiko@2.11.0
3.4.0

Open the chart page →

1,156
pagesnarain1.0.01 of 3See more

pages narain 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,262
pagesnarasimha-pages1.0.01 of 3See more

pages narasimha-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,262
traefik-forward-auth-openidnas-helm-chartsVerified publisher1.0.11 of 1See more

traefik-forward-auth-openid nas-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:latestb364aa6a4117
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,197
nats-kafkanatsVerified publisher0.15.41 of 1See more

nats-kafka nats 0.15.4

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
natsio/nats-kafka:1.4.2bb241956b0dc
golang.org/x/crypto@v0.15.0
0.17.0

Open the chart page →

1,731
pagesnavin-brixton1.0.01 of 3See more

pages navin-brixton 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,262
elasticsearch2ncsaVerified publisher0.2.21 of 2See more

elasticsearch2 ncsa 0.2.2

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
elastichq/elasticsearch-hq:latestbb3bd22c2b87
paramiko@2.6.0
3.4.0

Open the chart page →

4,913
incorencsaVerified publisher1.38.01 of 29See more

incore ncsa 1.38.0

1 of the 29 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:4.4.5e3c9d6b4bc92
golang.org/x/crypto@v0.0.0-20190530122614-20be4c3c3ed5
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

15,453
mlflowncsaVerified publisher1.2.11 of 4See more

mlflow ncsa 1.2.1

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
evk02/mlflow:2.2.1ef6ff257ef35
paramiko@2.12.0
3.4.0

Open the chart page →

5,456
smilencsaVerified publisher1.1.05 of 23See more

smile ncsa 1.1.0

5 of the 23 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
socialmediamacroscope/autophrase:0.1.570fb11d4f531
libssh@0.9.3-2ubuntu2.3
openssh@1:8.2p1-4ubuntu0.9
0.9.3-2ubuntu2.4
1:8.2p1-4ubuntu0.10
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
openssh@1:9.2p1-2
1:9.2p1-2+deb12u2
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
openssh@1:9.2p1-2
1:9.2p1-2+deb12u2
socialmediamacroscope/preprocessing:0.1.3ca863306314b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u2
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
openssh@1:9.2p1-2
1:9.2p1-2+deb12u2

Open the chart page →

110,325
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
golang.org/x/crypto@v0.0.0-20220128200615-198e4374d7ed
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,991
iamdnetsocVerified publisher0.6.11 of 2See more

iamd netsoc 0.6.1

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,891
shhdnetsocVerified publisher0.1.71 of 1See more

shhd netsoc 0.1.7

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/netsoc/shhd:0.1.60bb44992b62c
golang.org/x/crypto@v0.0.0-20210711020723-a769d52b0f97
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,987
webspacednetsocVerified publisher0.2.81 of 2See more

webspaced netsoc 0.2.8

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

5,193
cloudnative-pgnineinfra-charts0.19.11 of 1See more

cloudnative-pg nineinfra-charts 0.19.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.21.19f707d91de1c
golang.org/x/crypto@v0.14.0
0.17.0

Open the chart page →

1,188
minio-directpvnineinfra-charts4.0.81 of 5See more

minio-directpv nineinfra-charts 4.0.8

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/minio/directpv:v4.0.84560083eb77d
libssh@0.9.6-10.el8_8
0:0.9.6-13.el8_8

Open the chart page →

7,070
minio-operatornineinfra-charts5.0.91 of 1See more

minio-operator nineinfra-charts 5.0.9

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
minio/operator:v5.0.9170b154d2c61
golang.org/x/crypto@v0.11.0
libssh@0.9.6-10.el8_8
0.17.0
0:0.9.6-13.el8_8

Open the chart page →

3,425
nineinfranineinfra-charts0.7.01 of 1See more

nineinfra nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
nineinfra/nineinfra:v0.7.0d4aad414eccd
golang.org/x/crypto@v0.14.0
0.17.0

Open the chart page →

1,120
supersetnineinfra-charts0.11.21 of 4See more

superset nineinfra-charts 0.11.2

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
apache/superset:dockerizeafe59523a6c8
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

1,439
firehose-corenodeifyVerified publisher1.2.61 of 2See more

firehose-core nodeify 1.2.6

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.12.391fca773a63f
golang.org/x/crypto@v0.0.0-20220817201139-bc19a97f63c8
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

6,586
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
golang.org/x/crypto@v0.0.0-20220817201139-bc19a97f63c8
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,756
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
golang.org/x/crypto@v0.16.0
0.17.0

Open the chart page →

2,973
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
golang.org/x/crypto@v0.11.0
0.17.0
quay.io/prometheus/alertmanager:v0.26.0361db356b330
golang.org/x/crypto@v0.8.0
0.17.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
golang.org/x/crypto@v0.8.0
0.17.0
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
golang.org/x/crypto@v0.11.0
0.17.0
quay.io/prometheus/pushgateway:v1.6.05111de00e969
golang.org/x/crypto@v0.8.0
0.17.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

7,748

Container images carrying it

1,763 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
ghcr.io/dask/dask:2024.1.0080150de7d86
libssh@0.9.3-2ubuntu2.3
0.9.3-2ubuntu2.4
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/crypto@v0.6.0
0.17.0
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
golang.org/x/crypto@v0.0.0-20220314234724-5d542ad81a58
openssh@9.0_p1-r2
paramiko@2.10.1
0.0.0-20231218163308-9d2ee975ef9f
9.0_p1-r5
3.4.0
1
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u2
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
libssh@0.9.4-3.el8
0:0.9.6-13.el8_9
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
libssh@0.9.4-3.el8
0:0.9.6-13.el8_9
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
1
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
paramiko@2.11.0
3.4.0
1
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
golang.org/x/crypto@v0.16.0
0.17.0
1
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/crypto@v0.0.0-20220511200225-c6db032c6c88
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
golang.org/x/crypto@v0.16.0
0.17.0
1
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/crypto@v0.6.0
0.17.0
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
golang.org/x/crypto@v0.0.0-20220208050332-20e1d8d225ab
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4
1
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
golang.org/x/crypto@v0.7.0
0.17.0
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/crypto@v0.4.0
0.17.0
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
golang.org/x/crypto@v0.14.0
0.17.0
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lsdserver:1.9.0cdba39e3f3d0
golang.org/x/crypto@v0.14.0
0.17.0
1
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
golang.org/x/crypto@v0.0.0-20220331220935-ae2d96664a29
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/gabe565/limo:latest6dfdbc9853bb
golang.org/x/crypto@v0.6.0
0.17.0
1
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
golang.org/x/crypto@v0.14.0
0.17.0
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libssh@0.9.3-2ubuntu2.2
openssh@1:8.2p1-4ubuntu0.5
0.9.3-2ubuntu2.4
1:8.2p1-4ubuntu0.10
1
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/crypto@v0.9.0
0.17.0
1
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
paramiko@2.10.4
0.0.0-20231218163308-9d2ee975ef9f
3.4.0
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
libssh2@1.10.0-r4
openssh@9.3_p2-r0
paramiko@3.3.1
0.0.0-20231218163308-9d2ee975ef9f
1.11.0-r0
9.3_p2-r1
3.4.0
1
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/jaconi-io/koptimize:1.2.5aca1bbd609b6
golang.org/x/crypto@v0.9.0
0.17.0
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
libssh@0.9.0-4.el8
0:0.9.6-13.el8_9
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
ghcr.io/k10app/businit:latest94c9a3e799c2
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.0.0-20231218163308-9d2ee975ef9f
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.