StackRadar

CVE-2020-16845

Unscored

Advisory

Published 1 Jul 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.047
91st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
247
of 17,781 indexed, latest versions
Container images
226
deployed by those charts
Fix available
1 of 1
affected package

Unbounded read from invalid inputs in encoding/binary

Carried by container images the latest versions of 247 of 17,781 indexed charts deploy, on 226 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+16 more1.13.15226
OSV records
GO-2021-0142
Also known as
BIT-golang-2020-16845, GHSA-q6gq-997w-f55g

Charts affected

247 by stars
ChartLatestAffected imagesRadar Score
hlf-peerowkin5.1.01 of 1See more

hlf-peer owkin 5.1.0

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
hyperledger/fabric-peer:2.2.1bf4995c86af6
stdlib@go1.14.4
1.13.15

Open the chart page →

3,688
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.13.15

Open the chart page →

31,844
prometheusprometheus-worawutchan13.0.03 of 6See more

prometheus prometheus-worawutchan 13.0.0

3 of the 6 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.13.15
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.13.15
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.13.15

Open the chart page →

9,939
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
stdlib@go1.14.2
1.13.15

Open the chart page →

23,964
prometheus-webhook-dingtalkrlex0.0.31 of 1See more

prometheus-webhook-dingtalk rlex 0.0.3

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
stdlib@go1.13.5
1.13.15

Open the chart page →

1,852
gcp-quota-exportersoftonic2.0.21 of 1See more

gcp-quota-exporter softonic 2.0.2

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
mintel/gcp-quota-exporter:v0.3.20e0707b7732b
stdlib@go1.13.12
1.13.15

Open the chart page →

2,637
go-ratelimitsoftonic1.0.72 of 3See more

go-ratelimit softonic 1.0.7

2 of the 3 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:v1.4.071081616da3e
stdlib@go1.14
1.13.15
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.13.15

Open the chart page →

5,098
node-policy-webhooksoftonic0.1.101 of 1See more

node-policy-webhook softonic 0.1.10

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
softonic/node-policy-webhook:0.1.2ab6098c04a53
stdlib@go1.14.6
1.13.15

Open the chart page →

2,591
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
oliver006/redis_exporter:v1.9.04af75e9f16f6
stdlib@go1.14.4
1.13.15

Open the chart page →

2,307
gitwebhookproxystakaterVerified publisher0.2.791 of 1See more

gitwebhookproxy stakater 0.2.79

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
stakater/gitwebhookproxy:v0.2.79c1226e5270cd
stdlib@go1.13.1
1.13.15

Open the chart page →

1,503
Grafanasurajwarbhe-grafana0.1.01 of 1See more

Grafana surajwarbhe-grafana 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
surajwarbhe/grafana:v185248611e9f1
stdlib@go1.14.3
1.13.15

Open the chart page →

2,597
atlantistrozz3.12.111 of 1See more

atlantis trozz 3.12.11

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
runatlantis/atlantis:v0.16.145fbaf7e207c
stdlib@go1.13.11
1.13.15

Open the chart page →

5,280
user-componentuser-component1.2.01 of 4See more

user-component user-component 1.2.0

1 of the 4 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/user-component-php:latest198db44fabb5
stdlib@go1.13.10
1.13.15

Open the chart page →

7,303
vearchvearch3.3.41 of 4See more

vearch vearch 3.3.4

1 of the 4 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.13.15

Open the chart page →

5,008
waardepapierenwaardepapieren1.0.01 of 3See more

waardepapieren waardepapieren 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-php:latestb2666ffcbad8
stdlib@go1.13.10
1.13.15

Open the chart page →

8,079
waardepapieren-baliewaardepapieren-balie1.0.01 of 3See more

waardepapieren-balie waardepapieren-balie 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-balie-php:latestf36c423cd259
stdlib@go1.13.10
1.13.15

Open the chart page →

7,871
waardepapieren-registerwaardepapieren-register1.1.01 of 4See more

waardepapieren-register waardepapieren-register 1.1.0

1 of the 4 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/waardepapieren-register-php:latest9affab218351
stdlib@go1.13.10
1.13.15

Open the chart page →

7,429
adresserviceadresservice1.1.01 of 5See more

adresservice adresservice 1.1.0

1 of the 5 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
stdlib@go1.13.10
1.13.15

Open the chart page →

7,447
agendaserviceagendaservice1.0.01 of 3See more

agendaservice agendaservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
conduction/agendaservice-php:latest9cfeeb6c7c20
stdlib@go1.13.10
1.13.15

Open the chart page →

7,209
smartorchestratorassist-iot-smart-orchestrator4.0.01 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

1 of the 14 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.13
1.13.15

Open the chart page →

45,363
hcloud-csi-driveratem181.5.11 of 6See more

hcloud-csi-driver atem18 1.5.1

1 of the 6 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
stdlib@go1.13.3
1.13.15

Open the chart page →

6,491
authorization-componentauthorization-component1.0.01 of 3See more

authorization-component authorization-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
stdlib@go1.13.10
1.13.15

Open the chart page →

7,561
appmesh-prometheusaws1.0.31 of 2See more

appmesh-prometheus aws 1.0.3

1 of the 2 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.13.15

Open the chart page →

2,939
keptn-addonsazureorkestra0.1.01 of 4See more

keptn-addons azureorkestra 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
keptncontrib/prometheus-service:0.6.029969dd547de
stdlib@go1.13.7
1.13.15

Open the chart page →

10,621
prometheusazureorkestra14.8.01 of 6See more

prometheus azureorkestra 14.8.0

1 of the 6 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.13.15

Open the chart page →

9,661
webserverazureorkestra1.0.01 of 1See more

webserver azureorkestra 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
nmalhotr/webserver:v1.0.03419361fb0dd
stdlib@go1.13.10
1.13.15

Open the chart page →

3,037
balance-registrationbalance-registration0.1.01 of 4See more

balance-registration balance-registration 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
conduction/balance-registration-php:devc36094a41369
stdlib@go1.13.10
1.13.15

Open the chart page →

8,408
berichtserviceberichtservice1.0.01 of 3See more

berichtservice berichtservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/berichtservice-php:latestee6a21e66ff0
stdlib@go1.13.10
1.13.15

Open the chart page →

7,342
openldapccowleyVerified publisher2.0.41 of 3See more

openldap ccowley 2.0.4

1 of the 3 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
osixia/openldap:1.4.0ccd95cc6e61e
stdlib@go1.13.4
1.13.15

Open the chart page →

6,219
checkin-componentcheckin-component0.1.01 of 4See more

checkin-component checkin-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
conduction/checkin-component-php:dev3423845692c1
stdlib@go1.13.10
1.13.15

Open the chart page →

8,408
lokichoerodon0.29.01 of 1See more

loki choerodon 0.29.0

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
stdlib@go1.13.11
1.13.15

Open the chart page →

2,869
promtailchoerodon0.23.01 of 1See more

promtail choerodon 0.23.0

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
grafana/promtail:1.5.046e88d390cd6
stdlib@go1.13.11
1.13.15

Open the chart page →

2,821
chubaofschubaofs1.5.11 of 6See more

chubaofs chubaofs 1.5.1

1 of the 6 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
prom/prometheus:v2.13.10a8caa2e9f19
stdlib@go1.13.1
1.13.15

Open the chart page →

3,595
kube-acp-stackcloudentity2.28.01 of 7See more

kube-acp-stack cloudentity 2.28.0

1 of the 7 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
stdlib@go1.13.14
1.13.15

Open the chart page →

20,900
pact-brokercloud-native-toolkit0.3.01 of 1See more

pact-broker cloud-native-toolkit 0.3.0

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.101.0.0a3021fc42834
stdlib@go1.14.4
1.13.15

Open the chart page →

2,814
janisterminalcloudve0.1.01 of 2See more

janisterminal cloudve 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
stdlib@go1.13.1
1.13.15

Open the chart page →

14,270
proxyinjectorcloudve0.0.231 of 1See more

proxyinjector cloudve 0.0.23

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
stakater/proxyinjector:v0.0.2383fef483d497
stdlib@go1.13.1
1.13.15

Open the chart page →

2,853
lgtmcmacraeVerified publisher0.1.01 of 1See more

lgtm cmacrae 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
cmacrae/lgtm:0.1.0dec8d490fe40
stdlib@go1.14.1
1.13.15

Open the chart page →

1,909
traefik-forward-authcolearendt0.0.151 of 1See more

traefik-forward-auth colearendt 0.0.15

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:269a2c985d2c5
stdlib@go1.13.12
1.13.15

Open the chart page →

2,234
cgrccommongroundregistratiecomponent0.1.01 of 3See more

cgrc commongroundregistratiecomponent 0.1.0

1 of the 3 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
conduction/cgrc-php:dev25415534d245
stdlib@go1.13.10
1.13.15

Open the chart page →

7,572
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
conduction/conduction-ui-php:dev2744565516e8
stdlib@go1.13.10
1.13.15

Open the chart page →

12,907
betaalservicecontacten-catalog1.0.01 of 3See more

betaalservice contacten-catalog 1.0.0

1 of the 3 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
conduction/betaalservice-php:latestece1ab544c57
stdlib@go1.13.10
1.13.15

Open the chart page →

7,209
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
stdlib@go1.13.10
1.13.15

Open the chart page →

8,408
katibcowboysysopVerified publisher2.4.21 of 4See more

katib cowboysysop 2.4.2

1 of the 4 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
stdlib@go1.13.3
1.13.15

Open the chart page →

6,542
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
stdlib@go1.13.1
1.13.15

Open the chart page →

5,488
crossplane-controllerscrossplane0.12.01 of 1See more

crossplane-controllers crossplane 0.12.0

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
crossplane/crossplane:v0.12.066666e6963af
stdlib@go1.14.4
1.13.15

Open the chart page →

2,312
oam-kubernetes-runtimecrossplane0.0.3-71.g0f235901 of 2See more

oam-kubernetes-runtime crossplane 0.0.3-71.g0f23590

1 of the 2 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
stdlib@go1.13.14
1.13.15

Open the chart page →

2,248
external-service-operatorcrowdfox0.1.01 of 1See more

external-service-operator crowdfox 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
crowdfox/external-service-operator:v1.1.06fa7e8063d27
stdlib@go1.14.2
1.13.15

Open the chart page →

4,624
nfs-provisionerdasmeta1.0.31 of 1See more

nfs-provisioner dasmeta 1.0.3

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
stdlib@go1.13.4
1.13.15

Open the chart page →

2,806
aws-s3-proxydeliveryheroVerified publisher0.1.71 of 1See more

aws-s3-proxy deliveryhero 0.1.7

1 of the 1 container images this version deploys carry CVE-2020-16845.

Container imageDigestPackageFixed in
pottava/s3-proxy:2.020a0bcb15f76
stdlib@go1.13.7
1.13.15

Open the chart page →

1,323

Container images carrying it

226 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.13.15
1
codercom/code-server:3.10.247605610ad8d
stdlib@go1.14.4
1.13.15
1
conduction/agendaservice-php:latest9cfeeb6c7c20
stdlib@go1.13.10
1.13.15
1
conduction/balance-registration-php:devc36094a41369
stdlib@go1.13.10
1.13.15
1
conduction/betaalservice-php:latestece1ab544c57
stdlib@go1.13.10
1.13.15
1
conduction/cgrc-php:dev25415534d245
stdlib@go1.13.10
1.13.15
1
conduction/checkin-component-php:dev3423845692c1
stdlib@go1.13.10
1.13.15
1
conduction/conduction-ui-php:dev2744565516e8
stdlib@go1.13.10
1.13.15
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
stdlib@go1.13.10
1.13.15
1
conduction/docparser-php:devb6f95c8ead7d
stdlib@go1.13.10
1.13.15
1
conduction/kvk-php:dev8f177f9f8a7b
stdlib@go1.13.10
1.13.15
1
conduction/pan-php:dev24f03c57568f
stdlib@go1.13.10
1.13.15
1
containous/maesh:v1.3.2587162516502
stdlib@go1.14.4
1.13.15
1
coredns/coredns:1.7.073ca82b4ce82
stdlib@go1.14.4
1.13.15
1
crossplane/crossplane:v0.12.066666e6963af
stdlib@go1.14.4
1.13.15
1
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
stdlib@go1.13.14
1.13.15
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
stdlib@go1.14.2
1.13.15
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
stdlib@go1.14.4
1.13.15
1
datadog/agent:7.22.08f20e56b5311
stdlib@go1.13.11
1.13.15
1
datappeal/hive-metastore:lateste38c085a3567
stdlib@go1.13.4
1.13.15
1
devspacecloud/manager:0.3.349c397413f7b
stdlib@go1.13.8
1.13.15
1
douz/overlord:latestf2bc7fc068c1
stdlib@go1.14.5
1.13.15
1
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
stdlib@go1.14.4
1.13.15
1
envoyproxy/ratelimit:v1.4.071081616da3e
stdlib@go1.14
1.13.15
1
factly/vidcheck-server:0.12.087064eb0463c
stdlib@go1.14.2
1.13.15
1
gesellix/couchdb-prometheus-exporter:v27.2.05b891f1fc2b9
stdlib@go1.13.10
1.13.15
1
gitlab/gitlab-runner:alpine-v13.2.1fd7e5dfb9f30
stdlib@go1.13.8
1.13.15
1
golift/unifi-poller:2.0.0cafac968b540
stdlib@go1.13.7
1.13.15
1
gomods/athens:v0.8.1d714c7ff0231
stdlib@go1.13.4
1.13.15
1
gomods/athens:v0.11.0efb811df7844
stdlib@go1.13.10
1.13.15
1
grafana/grafana:6.6.0052147d7e0ec
stdlib@go1.13.4
1.13.15
1
grafana/grafana:6.5.1befcd84da2c1
stdlib@go1.13.1
1.13.15
1
grafana/loki:2.0.077e138f81a8e
stdlib@go1.14.2
1.13.15
1
grafana/promtail:2.0.05fd12edcc694
stdlib@go1.14.2
1.13.15
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
stdlib@go1.13.11
1.13.15
1
hashicorp/vault-k8s:0.6.05697b85bc69a
stdlib@go1.13.5
1.13.15
1
hyperledger/fabric-orderer:2.2.137294e05209b
stdlib@go1.14.4
1.13.15
1
hyperledger/fabric-peer:2.2.1bf4995c86af6
stdlib@go1.14.4
1.13.15
1
ianw/quickchart:v1.7.1dc49dd460c37
stdlib@go1.13.1
1.13.15
1
jaegertracing/all-in-one:1.18db45c07f2e1b
stdlib@go1.14.4
1.13.15
1
jfwenisch/alpine-tor:latest9e6c229f953c
stdlib@go1.14.6
1.13.15
1
jmferrer/azure-devops-agent:latest030f68ec6998
stdlib@go1.13.5
1.13.15
1
keptncontrib/prometheus-service:0.6.029969dd547de
stdlib@go1.13.7
1.13.15
1
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
stdlib@go1.14.2
1.13.15
1
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
stdlib@go1.13.3
1.13.15
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
stdlib@go1.14
1.13.15
1
kudobuilder/controller:v0.9.069072d979708
stdlib@go1.13
1.13.15
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
stdlib@go1.13.1
1.13.15
1
library/traefik:2.2.8f5af5a5ce17f
stdlib@go1.14.6
1.13.15
1
lmierzwa/karma:v0.503751e5eed656
stdlib@go1.13.4
1.13.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.