StackRadar

CVE-2019-11254

Medium

Advisory

Published 14 Apr 2021In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.031
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
120
of 17,781 indexed, latest versions
Container images
91
deployed by those charts
Fix available
1 of 2
affected packages

Excessive Platform Resource Consumption within a Loop in Kubernetes

Carried by container images the latest versions of 120 of 17,781 indexed charts deploy, on 91 images.

Affected packageAffected versionsFixed inImages
gopkg.in/yaml.v2golangv2.0.0-20170712054546-1be3d31502d6, v2.0.0-20170812160011-eb3733d160e7, v2.0.0-20190319135612-7b8349ac747c, v2.2.1+5 more2.2.885
github.com/go-yaml/yamlgolangv2.1.0+incompatibleno fix listed7
OSV records
GHSA-wxc4-f4m6-wwqv
Also known as
GO-2020-0036

Charts affected

120 by stars
ChartLatestAffected imagesRadar Score
weblateslamdev0.0.111 of 2See more

weblate slamdev 0.0.11

1 of the 2 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
weblate/weblate:3.11.3-182848df56ecd
gopkg.in/yaml.v2@v2.0.0-20190319135612-7b8349ac747c
2.2.8

Open the chart page →

8,694
preemptible-killersoftonic1.2.61 of 1See more

preemptible-killer softonic 1.2.6

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
softonic/preemptible-killer:1.2.6-294b87f1fb362
gopkg.in/yaml.v2@v2.2.1
2.2.8

Open the chart page →

2,338
webhook-receiversoftonic2.1.11 of 1See more

webhook-receiver softonic 2.1.1

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
almir/webhook:2.8.01698346f6077
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.8

Open the chart page →

1,927
spinnakerspinnakerVerified publisher2.2.131 of 4See more

spinnaker spinnaker 2.2.13

1 of the 4 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
gopkg.in/yaml.v2@v2.2.4
2.2.8

Open the chart page →

6,836
ecr-cleanersstarcher0.1.1+d13a1ab1 of 1See more

ecr-cleaner sstarcher 0.1.1+d13a1ab

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
sstarcher/ecr-cleaner:0.1.12d43c390cb19
gopkg.in/yaml.v2@v2.2.4
2.2.8

Open the chart page →

2,575
kube-ebs-taggersstarcher0.1.0+7abf4f71 of 1See more

kube-ebs-tagger sstarcher 0.1.0+7abf4f7

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
sstarcher/kube-ebs-tagger:0.1.01f8cae8cfa80
gopkg.in/yaml.v2@v2.2.4
2.2.8

Open the chart page →

3,096
proxyinjectorstakaterVerified publisher0.0.231 of 1See more

proxyinjector stakater 0.0.23

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
gopkg.in/yaml.v2@v2.2.7
2.2.8

Open the chart page →

2,853
vaultstakaterVerified publisher0.8.41 of 2See more

vault stakater 0.8.4

1 of the 2 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed

Open the chart page →

5,864
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
gopkg.in/yaml.v2@v2.2.2
2.2.8

Open the chart page →

16,506
prometheus-operatorstatcan0.2.22 of 7See more

prometheus-operator statcan 0.2.2

2 of the 7 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
gopkg.in/yaml.v2@v2.2.5
2.2.8
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
gopkg.in/yaml.v2@v2.2.2
2.2.8

Open the chart page →

12,237
vaultstatcan0.1.81 of 2See more

vault statcan 0.1.8

1 of the 2 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.6.05697b85bc69a
gopkg.in/yaml.v2@v2.2.5
2.2.8

Open the chart page →

4,222
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
gopkg.in/yaml.v2@v2.2.5
2.2.8

Open the chart page →

21,005
grafanatnh5.3.01 of 1See more

grafana tnh 5.3.0

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
gopkg.in/yaml.v2@v2.2.5
2.2.8

Open the chart page →

3,191
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
gopkg.in/yaml.v2@v2.2.2
2.2.8

Open the chart page →

8,484
monitorortrozz0.0.11 of 1See more

monitoror trozz 0.0.1

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
monitoror/monitoror:44b88edcf51ff
gopkg.in/yaml.v2@v2.2.2
2.2.8

Open the chart page →

3,109
gohttpserverutkuozdemirVerified publisher0.2.01 of 1See more

gohttpserver utkuozdemir 0.2.0

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
codeskyblue/gohttpserver:latestcaa862590e34
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed

Open the chart page →

1,898
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.8

Open the chart page →

2,030
filebrowserwenerme1.0.01 of 1See more

filebrowser wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.13.0c5d0a75a0041
gopkg.in/yaml.v2@v2.2.7
2.2.8

Open the chart page →

3,174
temporalwenerme0.15.13 of 13See more

temporal wenerme 0.15.1

3 of the 13 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
gopkg.in/yaml.v2@v2.2.5
2.2.8
prom/alertmanager:v0.20.07e4e9f7a0954
gopkg.in/yaml.v2@v2.2.2
2.2.8
prom/prometheus:v2.16.0e4ca62c0d62f
gopkg.in/yaml.v2@v2.2.7
2.2.8

Open the chart page →

22,665
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2019-11254.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/yaml.v2@v2.2.2
2.2.8

Open the chart page →

2,791

Container images carrying it

91 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
grafana/grafana:7.0.3d72946c8e5d5
gopkg.in/yaml.v2@v2.2.5
2.2.8
6
prom/alertmanager:v0.20.07e4e9f7a0954
gopkg.in/yaml.v2@v2.2.2
2.2.8
5
prom/prometheus:v2.13.10a8caa2e9f19
gopkg.in/yaml.v2@v2.2.2
2.2.8
5
grafana/grafana:6.7.11ff3999e0fc0
gopkg.in/yaml.v2@v2.2.5
2.2.8
4
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/yaml.v2@v2.2.2
2.2.8
3
stakater/proxyinjector:v0.0.2383fef483d497
gopkg.in/yaml.v2@v2.2.7
2.2.8
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
gopkg.in/yaml.v2@v2.2.5
2.2.8
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
gopkg.in/yaml.v2@v2.2.2
2.2.8
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
gopkg.in/yaml.v2@v2.2.2
2.2.8
3
cesanta/docker_auth:1.6.04d16885f3d4c
gopkg.in/yaml.v2@v2.2.2
2.2.8
2
crate/crate_adapter:latestb8d89fa5d19b
gopkg.in/yaml.v2@v2.2.3
2.2.8
2
hashicorp/vault:1.8.34db614d40d0e
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed
2
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
gopkg.in/yaml.v2@v2.2.2
2.2.8
2
natsio/nats-box:0.11.09fbf7bf684e4
gopkg.in/yaml.v2@v2.2.2
2.2.8
2
pottava/s3-proxy:2.020a0bcb15f76
gopkg.in/yaml.v2@v2.2.2
2.2.8
2
prom/blackbox-exporter:v0.18.01ffc3f109eb3
gopkg.in/yaml.v2@v2.2.5
2.2.8
2
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
gopkg.in/yaml.v2@v2.2.4
2.2.8
2
weblate/weblate:4.2.2-169c160d37a3c
gopkg.in/yaml.v2@v2.2.1
2.2.8
2
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
gopkg.in/yaml.v2@v2.2.2
2.2.8
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.8
2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
gopkg.in/yaml.v2@v2.2.5
2.2.8
2
almir/webhook:2.8.01698346f6077
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.8
1
codercom/code-server:4.11.0-debian1e2cc688008e
gopkg.in/yaml.v2@v2.2.1
2.2.8
1
codercom/code-server:3.10.247605610ad8d
gopkg.in/yaml.v2@v2.2.1
2.2.8
1
codeskyblue/gohttpserver:latestcaa862590e34
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
devspacecloud/manager:0.3.349c397413f7b
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
drone/drone-runner-docker:1.8.1137e79c5e23c
gopkg.in/yaml.v2@v2.2.2
2.2.8
1
drone/kubernetes-secrets:latest206df2280ecf
gopkg.in/yaml.v2@v2.2.1
2.2.8
1
envoyproxy/ratelimit:v1.4.071081616da3e
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
filebrowser/filebrowser:v2.13.0c5d0a75a0041
gopkg.in/yaml.v2@v2.2.7
2.2.8
1
gotify/server:2.1.409c79bc1e403
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed
1
grafana/grafana:6.6.0052147d7e0ec
gopkg.in/yaml.v2@v2.2.5
2.2.8
1
grafana/grafana:6.5.1befcd84da2c1
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
hashicorp/vault:1.8.4dfc3500beb0e
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed
1
hashicorp/vault-k8s:0.6.05697b85bc69a
gopkg.in/yaml.v2@v2.2.5
2.2.8
1
ianw/quickchart:v1.7.1dc49dd460c37
gopkg.in/yaml.v2@v2.2.2
2.2.8
1
jmferrer/azure-devops-agent:latest030f68ec6998
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
kudobuilder/controller:v0.9.069072d979708
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
gopkg.in/yaml.v2@v2.2.2
2.2.8
1
lmierzwa/karma:v0.503751e5eed656
gopkg.in/yaml.v2@v2.2.5
2.2.8
1
mesosphere/traefik-forward-auth:3.1.05456581d7b76
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
gopkg.in/yaml.v2@v2.2.2
2.2.8
1
minio/mc:RELEASE.2020-04-25T00-43-23Z1806872732e1
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
minio/mc:RELEASE.2020-03-14T01-23-37Z571feb124476
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
minio/minio:RELEASE.2020-01-03T19-12-21Zf00aa6ef2b72
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
mirrorgitlabcontainers/gitaly:v13.2.283599461ef8b
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
gopkg.in/yaml.v2@v2.2.2
2.2.8
1
mirrorgitlabcontainers/gitlab-shell:v13.3.09f3654f1eafc
gopkg.in/yaml.v2@v2.2.4
2.2.8
1
monitoror/monitoror:44b88edcf51ff
gopkg.in/yaml.v2@v2.2.2
2.2.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.