StackRadar

CVE-2020-7919

High

Advisory

Published 23 Jun 2021In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,781 indexed, latest versions
Container images
130
deployed by those charts
Fix available
3 of 3
affected packages

Helm uses crypto package vulnerable to panic from malformed X.509 certificate

Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 130 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+27 more0.0.0-20200124225646-8b5121be2f68107
helm.sh/helm/v3golangv3.0.2, v3.0.33.1.03
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+2 more1.12.1654
OSV records
GHSA-cjjc-xp8v-855wGO-2022-0229
Also known as
BIT-golang-2020-7919

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
temporalwenerme0.15.14 of 13See more

temporal wenerme 0.15.1

4 of the 13 container images this version deploys carry CVE-2020-7919.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
stdlib@go1.13.4
0.0.0-20200124225646-8b5121be2f68
1.12.16
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/crypto@v0.0.0-20190617133340-57b3e21c3d56
stdlib@go1.13.5
0.0.0-20200124225646-8b5121be2f68
1.12.16
prom/prometheus:v2.16.0e4ca62c0d62f
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20200124225646-8b5121be2f68
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.12.16

Open the chart page →

22,665
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2020-7919.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20200124225646-8b5121be2f68

Open the chart page →

2,791
nginx-vts-exporterymrs0.1.21 of 1See more

nginx-vts-exporter ymrs 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-7919.

Container imageDigestPackageFixed in
sophos/nginx-vts-exporter:latestf1073556b29b
stdlib@go1.13.6
1.12.16

Open the chart page →

1,336

Container images carrying it

130 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20200124225646-8b5121be2f68
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
golang.org/x/crypto@v0.0.0-20190911031432-227b76d455e7
0.0.0-20200124225646-8b5121be2f68
1
timescale/timescaledb-postgis:latest-pg127758704d4a14
golang.org/x/crypto@v0.0.0-20190911031432-227b76d455e7
0.0.0-20200124225646-8b5121be2f68
1
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
golang.org/x/crypto@v0.0.0-20191205180655-e7c4368fe9dd
stdlib@go1.13.5
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/crypto@v0.0.0-20200109152110-61a87790db17
0.0.0-20200124225646-8b5121be2f68
1
traggo/server:0.2.3f1ced637510e
golang.org/x/crypto@v0.0.0-20190513172903-22d7a77e9e5f
stdlib@go1.13.1
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
ubercadence/server:0.23.22ac5491d13bb
stdlib@go1.13.6
1.12.16
1
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
golang.org/x/crypto@v0.0.0-20190927123631-a832865fa7ad
stdlib@go1.13.6
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
weaveworks/flagger:0.19.0a9c2e9df4227
golang.org/x/crypto@v0.0.0-20181025213731-e84da0312774
stdlib@go1.13.1
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
weaveworks/flagger-loadtester:0.9.03cdac6928a63
stdlib@go1.13.1
1.12.16
1
weblate/weblate:3.11.3-182848df56ecd
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
stdlib@go1.13.5
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
wener/frpc:v0.37.0cc9fd4da44c0
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20200124225646-8b5121be2f68
1
wener/frps:v0.37.05c92cc9e8597
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20200124225646-8b5121be2f68
1
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
stdlib@go1.13
1.12.16
1
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
stdlib@go1.13.5
1.12.16
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20200124225646-8b5121be2f68
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20200124225646-8b5121be2f68
1
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20200124225646-8b5121be2f68
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
stdlib@go1.13.4
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20200124225646-8b5121be2f68
1
mcr.microsoft.com/oss/kubernetes-csi/csi-provisioner:v1.6.1667b1b1ea1e4
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20200124225646-8b5121be2f68
1
public.ecr.aws/j1r0q0g6/notebooks/notebook-controller:v1.4cac3ed9a9826
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20200124225646-8b5121be2f68
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20200124225646-8b5121be2f68
1
quay.io/ddn/exascaler-csi-file-driver:v2.2.6fe2e2e5a2751
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20200124225646-8b5121be2f68
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20200124225646-8b5121be2f68
1
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20200124225646-8b5121be2f68
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
stdlib@go1.13.1
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20200124225646-8b5121be2f68
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
golang.org/x/crypto@v0.0.0-20180808211826-de0752318171
0.0.0-20200124225646-8b5121be2f68
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
golang.org/x/crypto@v0.0.0-20190530122614-20be4c3c3ed5
0.0.0-20200124225646-8b5121be2f68
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.