StackRadar

CVE-2023-48795

Medium

Advisory

Published 18 Dec 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.933
100th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,639
of 17,797 indexed, latest versions
Container images
1,763
deployed by those charts
Fix available
8 of 10
affected packages

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Carried by container images the latest versions of 1,639 of 17,797 indexed charts deploy, on 1,763 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+120 more0.0.0-20231218163308-9d2ee975ef9f, 0.17.01,387
libsshdeb0.9.3-2ubuntu2.1, 0.9.3-2ubuntu2.2, 0.9.3-2ubuntu2.3, 0.9.6-2build1+2 more0.9.3-2ubuntu2.4, 0.9.6-2ubuntu0.22.04.2, 0.10.6-0+deb12u1243
libsshrpm0.8.5-2.el8, 0.9.0-4.el8, 0.9.4-2.el8, 0.9.4-3.el8+4 more0:0.9.6-13.el8_8, 0:0.9.6-13.el8_9156
opensshdeb1:6.6p1-2ubuntu2, 1:6.6p1-2ubuntu2.13, 1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4+20 more1:7.2p2-4ubuntu2.10+esm5, 1:7.6p1-4ubuntu0.7+esm3, 1:8.2p1-4ubuntu0.10, 1:8.2p1-4ubuntu0.fips.0.10+2 more101
paramikopypi2.6.0, 2.7.1, 2.7.2, 2.8.0+9 more3.4.058
opensshapk9.0_p1-r1, 9.0_p1-r2, 9.0_p1-r4, 9.1_p1-r1+3 more9.0_p1-r5, 9.1_p1-r5, 9.3_p2-r122
libssh2apk1.10.0-r2, 1.10.0-r3, 1.10.0-r41.11.0-r010
paramikodeb1.10.1-1git1ubuntu0.1no fix listed2
dropbeardeb2022.83-4no fix listed1
php-phpseclibdeb2.0.14-1, 2.0.30-22.0.30-2+deb11u1, 2.0.30-2~deb10u22
OSV records
ALPINE-CVE-2023-48795DEBIAN-CVE-2023-48795GHSA-45x7-px36-x8w8RHSA-2024:0625RHSA-2024:0628UBUNTU-CVE-2023-48795DLA-3718-1DSA-5600-1
Also known as
GO-2023-2402, PYSEC-2026-1758, USN-6560-1, USN-6560-2, USN-6561-1

Charts affected

1,639 by stars
ChartLatestAffected imagesRadar Score
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9

Open the chart page →

11,571
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,854
tronadorstakaterVerified publisher0.0.11 of 1See more

tronador stakater 0.0.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/tronador:v0.0.137ce9acf2722
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,173
vaultstakaterVerified publisher0.8.41 of 2See more

vault stakater 0.8.4

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

5,871
whitelisterstakaterVerified publisher0.0.161 of 1See more

whitelister stakater 0.0.16

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/whitelister:v0.0.1639107924063e
golang.org/x/crypto@v0.0.0-20200220183623-bac4c82f6975
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,565
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
libssh@0.9.4-3.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,678
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
openssh@1:9.2p1-2
1:9.2p1-2+deb12u2

Open the chart page →

20,317
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.15d99fbb9585c7
golang.org/x/crypto@v0.0.0-20210322153248-0c34fe9e7dc2
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

6,595
argocd-operatorstatcan0.5.01 of 1See more

argocd-operator statcan 0.5.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
quay.io/argoprojlabs/argocd-operator:v0.4.0cf8faa986789
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,985
cost-analyzerstatcan1.82.24 of 9See more

cost-analyzer statcan 1.82.2

4 of the 9 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:7.5.609bb407e26ab
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
prom/prometheus:v2.22.2f7ffebdd428b
golang.org/x/crypto@v0.0.0-20201002170205-7f63de1d35b0
0.0.0-20231218163308-9d2ee975ef9f
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

16,537
ingress-istio-controllerstatcan1.4.01 of 1See more

ingress-istio-controller statcan 1.4.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
statcan/ingress-istio-controller:1.4.0d7d6bd180c46
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,583
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
golang.org/x/crypto@v0.0.0-20210421170649-83a5a9bb288b
libssh@0.9.4-2.el8
0.0.0-20231218163308-9d2ee975ef9f
0:0.9.6-13.el8_9

Open the chart page →

6,596
prometheus-operatorstatcan0.2.24 of 7See more

prometheus-operator statcan 0.2.2

4 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
golang.org/x/crypto@v0.0.0-20200406173513-056763e48d71
0.0.0-20231218163308-9d2ee975ef9f
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/crypto@v0.0.0-20181203042331-505ab145d0a9
0.0.0-20231218163308-9d2ee975ef9f
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/crypto@v0.0.0-20191002192127-34f69633bfdc
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
golang.org/x/crypto@v0.0.0-20200510223506-06a226fb4e37
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

12,251
sidecar-terminatorstatcan1.3.51 of 1See more

sidecar-terminator statcan 1.3.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
statcan/kubernetes-sidecar-terminator:2.0.2bc361ee7748f
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,315
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
libssh@0.9.6-2build1
0.9.6-2ubuntu0.22.04.2

Open the chart page →

13,900
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

4,223
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
golang.org/x/crypto@v0.0.0-20220622213112-05595931fe9d
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4

Open the chart page →

13,704
pagesstephendillondell1.0.01 of 3See more

pages stephendillondell 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,262
sn-platform-slimstreamnative1.11.442 of 6See more

sn-platform-slim streamnative 1.11.44

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
golang.org/x/crypto@v0.4.0
0.17.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

10,270
studygovernorstudy-governorVerified publisher0.1.381 of 3See more

studygovernor study-governor 0.1.38

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
openssh@9.0_p1-r4
9.0_p1-r5

Open the chart page →

1,447
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,354
nocodbsudermanjr0.1.01 of 1See more

nocodb sudermanjr 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
nocodb/nocodb:0.84.15f9b799933aa8
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,070
pagessunilb2590-pages1.0.01 of 3See more

pages sunilb2590-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
libssh@0.9.3-2ubuntu2.1
0.9.3-2ubuntu2.4

Open the chart page →

20,262
cludodsuperorbitalVerified publisher0.0.51 of 1See more

cludod superorbital 0.0.5

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
superorbital/cludod:0.0.2-alphad59732f61d6e
golang.org/x/crypto@v0.0.0-20220112180741-5e0467b6c7ce
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,371
nfs-provisionersupporttools0.11.01 of 1See more

nfs-provisioner supporttools 0.11.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
openebs/provisioner-nfs:0.11.04f41dd782761
golang.org/x/crypto@v0.0.0-20201124201722-c8d3bf9c5392
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,680
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libssh@0.9.6-2build1
openssh@1:8.9p1-3
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,122
freeradiussvtech-public-helm-charts0.1.52 of 4See more

freeradius svtech-public-helm-charts 0.1.5

2 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
paramiko@2.11.0
3.4.0
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4

Open the chart page →

12,732
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
golang.org/x/crypto@v0.4.0
libssh@0.9.3-2ubuntu2.3
0.17.0
0.9.3-2ubuntu2.4

Open the chart page →

10,980
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:8.2.0212fe73edca5
paramiko@2.11.0
3.4.0

Open the chart page →

5,891
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
libssh@0.9.6-2build1
openssh@1:8.9p1-3
0.9.6-2ubuntu0.22.04.2
1:8.9p1-3ubuntu0.5

Open the chart page →

12,122
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
golang.org/x/crypto@v0.7.0
libssh@0.9.3-2ubuntu2.3
openssh@1:8.2p1-4ubuntu0.7
paramiko@2.11.0
0.17.0
0.9.3-2ubuntu2.4
1:8.2p1-4ubuntu0.10
3.4.0

Open the chart page →

18,853
syncthingsvtech-public-helm-charts1.0.01 of 2See more

syncthing svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
golang.org/x/crypto@v0.16.0
0.17.0

Open the chart page →

2,336
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
libssh@0.9.6-10.el8_8
0:0.9.6-13.el8_9

Open the chart page →

14,061
synadia-serversynadiaVerified publisher1.1.101 of 2See more

synadia-server synadia 1.1.10

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
golang.org/x/crypto@v0.13.0
0.17.0

Open the chart page →

1,971
agentssynapse0.1.304 of 9See more

agents synapse 0.1.30

4 of the 9 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.42.07d32a4eddec7
golang.org/x/crypto@v0.0.0-20220722155217-630584e8d5aa
0.0.0-20231218163308-9d2ee975ef9f
mysql/mysql-server:latestd6c8301b7834
paramiko@2.11.0
3.4.0
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
golang.org/x/crypto@v0.6.0
0.17.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
golang.org/x/crypto@v0.6.0
0.17.0

Open the chart page →

7,272
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
golang.org/x/crypto@v0.7.0
0.17.0

Open the chart page →

1,822
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
golang.org/x/crypto@v0.9.0
0.17.0

Open the chart page →

1,711
scribesynapse0.2.161 of 7See more

scribe synapse 0.2.16

1 of the 7 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
paramiko@2.11.0
3.4.0

Open the chart page →

2,694
sinnersynapse0.1.02 of 6See more

sinner synapse 0.1.0

2 of the 6 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
mysql/mysql-server:latestd6c8301b7834
paramiko@2.11.0
3.4.0
ghcr.io/synapsecns/sanguine/sinner:latest3e98a98f6074
golang.org/x/crypto@v0.16.0
0.17.0

Open the chart page →

1,962
ccm-hcloudsyself1.0.111 of 1See more

ccm-hcloud syself 1.0.11

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
golang.org/x/crypto@v0.0.0-20220829220503-c86fa9a7ed90
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

1,713
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,876
promtailt3n1.0.01 of 1See more

promtail t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

2,828
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
golang.org/x/crypto@v0.0.0-20200414173820-0848c9571904
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

7,490
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
golang.org/x/crypto@v0.2.0
openssh@9.3_p2-r0
0.17.0
9.3_p2-r1

Open the chart page →

4,218
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

3,772
clickhousetemp-charts0.7.12 of 3See more

clickhouse temp-charts 0.7.1

2 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.16.1db7dde971407
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f
altinity/metrics-exporter:0.16.185b4fdbae053
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

8,707
istio-discoverytemp-charts0.3.31 of 1See more

istio-discovery temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
istio/pilot:1.10.0294ca55bd1cc
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,606
istio-ingresstemp-charts0.3.31 of 1See more

istio-ingress temp-charts 0.3.3

1 of the 1 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.088c6c693e67a
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

10,551
temporaltemporal0.28.97 of 13See more

temporal temporal 0.28.9

7 of the 13 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20231218163308-9d2ee975ef9f
prom/pushgateway:v1.4.2a684e7c830a4
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
temporalio/admin-tools:1.22.0836af062af30
golang.org/x/crypto@v0.10.0
0.17.0
temporalio/server:1.22.0ddeebf8bad8f
golang.org/x/crypto@v0.12.0
0.17.0
temporalio/ui:2.16.2af9c9349708f
golang.org/x/crypto@v0.1.0
0.17.0
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
golang.org/x/crypto@v0.0.0-20210616213533-5ff15b29337e
0.0.0-20231218163308-9d2ee975ef9f

Open the chart page →

21,042
tensor_apptensor-app0.2.21 of 3See more

tensor_app tensor-app 0.2.2

1 of the 3 container images this version deploys carry CVE-2023-48795.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
paramiko@2.11.0
3.4.0

Open the chart page →

17,661

Container images carrying it

1,763 by charts deploying them

A fixed version is listed for 8 of the 10 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
libssh@0.9.4-2.el8
0:0.9.6-13.el8_9
1
ghcr.io/dask/dask:2024.1.0080150de7d86
libssh@0.9.3-2ubuntu2.3
0.9.3-2ubuntu2.4
1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
ghcr.io/deepch/rtsptoweb:v2.2.0f9de3a1a5deb
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/devplayer0/octolxd:0.1.119b18fd97eab
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/djcass44/cso-proxy:cccf49fdb360d44125ad
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/djcass44/gitlab-goproxy:v0.1.8a43323732181
golang.org/x/crypto@v0.6.0
0.17.0
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
golang.org/x/crypto@v0.0.0-20220314234724-5d542ad81a58
openssh@9.0_p1-r2
paramiko@2.10.1
0.0.0-20231218163308-9d2ee975ef9f
9.0_p1-r5
3.4.0
1
ghcr.io/doodlescheduling/k8s-pause:v0.1.16b3215e37738
golang.org/x/crypto@v0.0.0-20210817164053-32db794688a5
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/doodlescheduling/k8svault-controller:v0.2.0627e5e211766
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/drewburr-labs/mum-discord-bot:3.1.26e82914e1051
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u2
1
ghcr.io/drogue-iot/drogue-event-source:0.2.1e2e812a4cf8e
libssh@0.9.4-3.el8
0:0.9.6-13.el8_9
1
ghcr.io/drogue-iot/postgresql-pusher:0.2.1c6bb121ced90
libssh@0.9.4-3.el8
0:0.9.6-13.el8_9
1
ghcr.io/drogue-iot/test-cert-generator:0.11.06ba7e1608286
libssh@0.9.6-3.el8
0:0.9.6-13.el8_9
1
ghcr.io/ducksify/pgdump-to-s3:latestc42c0946bd0f
paramiko@2.11.0
3.4.0
1
ghcr.io/dysnix/bitnami/mongodb:4.4.11-debian-10-r5073116e61007
golang.org/x/crypto@v0.0.0-20200302210943-78000ba7a073
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/edgelesssys/coordinator:v0.5.0bcd5b8d4c45c
golang.org/x/crypto@v0.0.0-20210513164829-c07d793c2f9a
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/edgelesssys/edgelessdb-sgx-1gb:v0.3.27e1d7a11a11a
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
golang.org/x/crypto@v0.16.0
0.17.0
1
ghcr.io/epinio/epinio-ui:v1.7.1-0.0.1d3de52dfb0b4
golang.org/x/crypto@v0.0.0-20220511200225-c6db032c6c88
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
golang.org/x/crypto@v0.16.0
0.17.0
1
ghcr.io/external-secrets/external-secrets:v0.3.1156a1ea4490ba
golang.org/x/crypto@v0.0.0-20210220033148-5ea612d1eb83
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
golang.org/x/crypto@v0.6.0
0.17.0
1
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
golang.org/x/crypto@v0.0.0-20220208050332-20e1d8d225ab
libssh@0.9.3-2ubuntu2.2
0.0.0-20231218163308-9d2ee975ef9f
0.9.3-2ubuntu2.4
1
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/fikaworks/grgate:v0.6.37104f60d8972
golang.org/x/crypto@v0.7.0
0.17.0
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
golang.org/x/crypto@v0.0.0-20220926161630-eccd6366d1be
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
golang.org/x/crypto@v0.4.0
0.17.0
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
golang.org/x/crypto@v0.14.0
0.17.0
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lsdserver:1.9.0cdba39e3f3d0
golang.org/x/crypto@v0.14.0
0.17.0
1
ghcr.io/g0dscookie/aptly:latestedd095d3c0ee
golang.org/x/crypto@v0.0.0-20220331220935-ae2d96664a29
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/gabe565/limo:latest6dfdbc9853bb
golang.org/x/crypto@v0.6.0
0.17.0
1
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
golang.org/x/crypto@v0.14.0
0.17.0
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libssh@0.9.3-2ubuntu2.2
openssh@1:8.2p1-4ubuntu0.5
0.9.3-2ubuntu2.4
1:8.2p1-4ubuntu0.10
1
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
golang.org/x/crypto@v0.9.0
0.17.0
1
ghcr.io/helm/chartmuseum:v0.14.0878ef6a31fa0
golang.org/x/crypto@v0.0.0-20211215153901-e495a2d5b3d3
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
golang.org/x/crypto@v0.0.0-20220525230936-793ad666bf5e
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
paramiko@2.10.4
0.0.0-20231218163308-9d2ee975ef9f
3.4.0
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
golang.org/x/crypto@v0.0.0-20201221181555-eec23a3978ad
libssh2@1.10.0-r4
openssh@9.3_p2-r0
paramiko@3.3.1
0.0.0-20231218163308-9d2ee975ef9f
1.11.0-r0
9.3_p2-r1
3.4.0
1
ghcr.io/honeycombio/kspan/kspan:0.2c966a4f8a4b7
golang.org/x/crypto@v0.0.0-20200622213623-75b288015ac9
0.0.0-20231218163308-9d2ee975ef9f
1
ghcr.io/jaconi-io/koptimize:1.2.5aca1bbd609b6
golang.org/x/crypto@v0.9.0
0.17.0
1
ghcr.io/jenkins-x/nexus:0.1.378caf5289fe73
libssh@0.9.0-4.el8
0:0.9.6-13.el8_9
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
libssh@0.9.3-2ubuntu2.2
0.9.3-2ubuntu2.4
1
ghcr.io/k10app/businit:latest94c9a3e799c2
golang.org/x/crypto@v0.0.0-20220315160706-3147a52a75dd
0.0.0-20231218163308-9d2ee975ef9f
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.