StackRadar

CVE-2019-11254

Medium

Advisory

Published 14 Apr 2021In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.031
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
120
of 17,781 indexed, latest versions
Container images
91
deployed by those charts
Fix available
1 of 2
affected packages

Excessive Platform Resource Consumption within a Loop in Kubernetes

Carried by container images the latest versions of 120 of 17,781 indexed charts deploy, on 91 images.

Affected packageAffected versionsFixed inImages
gopkg.in/yaml.v2golangv2.0.0-20170712054546-1be3d31502d6, v2.0.0-20170812160011-eb3733d160e7, v2.0.0-20190319135612-7b8349ac747c, v2.2.1+5 more2.2.885
github.com/go-yaml/yamlgolangv2.1.0+incompatibleno fix listed7
OSV records
GHSA-wxc4-f4m6-wwqv
Also known as
GO-2020-0036

Charts affected

120 by stars
ChartLatestAffected imagesRadar Score
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
gopkg.in/yaml.v2@v2.0.0-20190319135612-7b8349ac747c
2.2.8

Open the chart page →

8,694
preemptible-killersoftonic1.2.61 of 1See more

preemptible-killer softonic 1.2.6

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
softonic/preemptible-killer:1.2.6-294b87f1fb362
gopkg.in/yaml.v2@v2.2.1
2.2.8

Open the chart page →

2,338
webhook-receiversoftonic2.1.11 of 1See more

webhook-receiver softonic 2.1.1

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
almir/webhook:2.8.01698346f6077
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.8

Open the chart page →

1,927
spinnakerspinnakerVerified publisher2.2.131 of 4See more

spinnaker spinnaker 2.2.13

1 of the 4 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
gopkg.in/yaml.v2@v2.2.4
2.2.8

Open the chart page →

6,836
ecr-cleanersstarcher0.1.1+d13a1ab1 of 1See more

ecr-cleaner sstarcher 0.1.1+d13a1ab

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
sstarcher/ecr-cleaner:0.1.12d43c390cb19
gopkg.in/yaml.v2@v2.2.4
2.2.8

Open the chart page →

2,575
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
gopkg.in/yaml.v2@v2.2.4
2.2.8

Open the chart page →

3,096
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
gopkg.in/yaml.v2@v2.2.7
2.2.8

Open the chart page →

2,853
vaultstakaterVerified publisher0.8.41 of 2See more

vault stakater 0.8.4

1 of the 2 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed

Open the chart page →

5,864
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
gopkg.in/yaml.v2@v2.2.2
2.2.8

Open the chart page →

16,506
prometheus-operatorstatcan0.2.22 of 7See more

prometheus-operator statcan 0.2.2

2 of the 7 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
gopkg.in/yaml.v2@v2.2.5
2.2.8
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
gopkg.in/yaml.v2@v2.2.2
2.2.8

Open the chart page →

12,237
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
gopkg.in/yaml.v2@v2.2.5
2.2.8

Open the chart page →

4,222
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
gopkg.in/yaml.v2@v2.2.5
2.2.8

Open the chart page →

21,005
grafanatnh5.3.01 of 1See more

grafana tnh 5.3.0

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
gopkg.in/yaml.v2@v2.2.5
2.2.8

Open the chart page →

3,191
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
gopkg.in/yaml.v2@v2.2.2
2.2.8

Open the chart page →

8,484
monitorortrozz0.0.11 of 1See more

monitoror trozz 0.0.1

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
monitoror/monitoror:44b88edcf51ff
gopkg.in/yaml.v2@v2.2.2
2.2.8

Open the chart page →

3,109
gohttpserverutkuozdemirVerified publisher0.2.01 of 1See more

gohttpserver utkuozdemir 0.2.0

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
codeskyblue/gohttpserver:latestcaa862590e34
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed

Open the chart page →

1,898
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.8

Open the chart page →

2,030
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
gopkg.in/yaml.v2@v2.2.7
2.2.8

Open the chart page →

3,174
temporalwenerme0.15.13 of 13See more

temporal wenerme 0.15.1

3 of the 13 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
gopkg.in/yaml.v2@v2.2.5
2.2.8
prom/alertmanager:v0.20.07e4e9f7a0954
gopkg.in/yaml.v2@v2.2.2
2.2.8
prom/prometheus:v2.16.0e4ca62c0d62f
gopkg.in/yaml.v2@v2.2.7
2.2.8

Open the chart page →

22,665
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/yaml.v2@v2.2.2
2.2.8

Open the chart page →

2,791

Container images carrying it

91 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
olliai/exposecontroller:1.0.5a470d96525e4
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
olliai/k8s-replicator:1.3.05716f2a8bd4c
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
oxynozeta/prometheus-cachethq:1.1.131f11669d597
github.com/go-yaml/yaml@v2.1.0+incompatible
gopkg.in/yaml.v2@v2.2.2
no fix listed
2.2.8
1
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
prom/prometheus:v2.16.0e4ca62c0d62f
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
rancher/hardened-calico:v3.13.36d2cd61a338b
gopkg.in/yaml.v2@v2.2.5
2.2.8
1
rancher/hardened-calico:v3.13.3-build20210223c678c25d47c8
gopkg.in/yaml.v2@v2.2.5
2.2.8
1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
gopkg.in/yaml.v2@v2.0.0-20170712054546-1be3d31502d6
2.2.8
1
rancher/local-path-provisioner:v0.0.20d5999b20a1b1
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
rancher/local-path-provisioner:v0.0.22e34c88ae0aff
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
reportportal/service-index:5.0.112b27a2d7a87d
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
softonic/preemptible-killer:1.2.6-294b87f1fb362
gopkg.in/yaml.v2@v2.2.1
2.2.8
1
sstarcher/ecr-cleaner:0.1.12d43c390cb19
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
sstarcher/helm-exporter:0.5.011769d01ba35
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.10ebcf7f033b54
gopkg.in/yaml.v2@v2.2.5
2.2.8
1
surajwarbhe/grafana:v185248611e9f1
gopkg.in/yaml.v2@v2.2.5
2.2.8
1
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
tobiasbp/db-backup:0.0.314bee6e33a26
gopkg.in/yaml.v2@v2.2.5
2.2.8
1
weaveworks/flagger:0.19.0a9c2e9df4227
gopkg.in/yaml.v2@v2.2.2
2.2.8
1
weblate/weblate:3.11.3-182848df56ecd
gopkg.in/yaml.v2@v2.0.0-20190319135612-7b8349ac747c
2.2.8
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
gopkg.in/yaml.v2@v2.2.2
2.2.8
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
gopkg.in/yaml.v2@v2.2.2
2.2.8
1
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
gopkg.in/yaml.v2@v2.2.2
2.2.8
1
ghcr.io/ethpandaops/syncoor:master233aa9808fc7
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed
1
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.8
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
ghcr.io/k8s-at-home/lidarr:v1.0.0.225554ebc1f90963
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
ghcr.io/k8s-at-home/network-ups-tools:v2.7.4-2479-g86a32237cbd5d4cc1245
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
ghcr.io/k8s-at-home/readarr:v0.1.0.715ad943e9309e4
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
ghcr.io/k8s-at-home/tautulli:v2.7.74ea617c30397
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
gopkg.in/yaml.v2@v2.2.5
2.2.8
1
ghcr.io/podtato-head/entry:latestc3d9d9c98be7
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed
1
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
gopkg.in/yaml.v2@v2.2.2
2.2.8
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
gopkg.in/yaml.v2@v2.2.4
2.2.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.