StackRadar

CVE-2020-7919

High

Advisory

Published 23 Jun 2021In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.026
85th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
153
of 17,781 indexed, latest versions
Container images
130
deployed by those charts
Fix available
3 of 3
affected packages

Helm uses crypto package vulnerable to panic from malformed X.509 certificate

Carried by container images the latest versions of 153 of 17,781 indexed charts deploy, on 130 images.

Affected packageAffected versionsFixed inImages
golang.org/x/cryptogolangv0.0.0-20180808211826-de0752318171, v0.0.0-20181025213731-e84da0312774, v0.0.0-20181029021203-45a5f77698d3, v0.0.0-20181203042331-505ab145d0a9+27 more0.0.0-20200124225646-8b5121be2f68107
helm.sh/helm/v3golangv3.0.2, v3.0.33.1.03
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+2 more1.12.1654
OSV records
GHSA-cjjc-xp8v-855wGO-2022-0229
Also known as
BIT-golang-2020-7919

Charts affected

153 by stars
ChartLatestAffected imagesRadar Score
temporalwenerme0.15.14 of 13See more

temporal wenerme 0.15.1

4 of the 13 container images this version deploys carry CVE-2020-7919.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
stdlib@go1.13.4
0.0.0-20200124225646-8b5121be2f68
1.12.16
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/crypto@v0.0.0-20190617133340-57b3e21c3d56
stdlib@go1.13.5
0.0.0-20200124225646-8b5121be2f68
1.12.16
prom/prometheus:v2.16.0e4ca62c0d62f
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20200124225646-8b5121be2f68
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.12.16

Open the chart page →

22,665
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2020-7919.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20200124225646-8b5121be2f68

Open the chart page →

2,791
nginx-vts-exporterymrs0.1.21 of 1See more

nginx-vts-exporter ymrs 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-7919.

Container imageDigestPackageFixed in
sophos/nginx-vts-exporter:latestf1073556b29b
stdlib@go1.13.6
1.12.16

Open the chart page →

1,336

Container images carrying it

130 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20200124225646-8b5121be2f68
6
prom/alertmanager:v0.20.07e4e9f7a0954
golang.org/x/crypto@v0.0.0-20190617133340-57b3e21c3d56
stdlib@go1.13.5
0.0.0-20200124225646-8b5121be2f68
1.12.16
5
prom/prometheus:v2.13.10a8caa2e9f19
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
stdlib@go1.13.1
0.0.0-20200124225646-8b5121be2f68
1.12.16
5
quay.io/k8scsi/csi-node-driver-registrar:v1.3.0e6df72478956
stdlib@go1.13.3
1.12.16
5
grafana/grafana:6.7.11ff3999e0fc0
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
stdlib@go1.13.4
0.0.0-20200124225646-8b5121be2f68
1.12.16
4
argoproj/argocd:v1.8.1830e86cacefd
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20200124225646-8b5121be2f68
3
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20200124225646-8b5121be2f68
3
stakater/proxyinjector:v0.0.2383fef483d497
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
stdlib@go1.13.1
0.0.0-20200124225646-8b5121be2f68
1.12.16
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20200124225646-8b5121be2f68
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
stdlib@go1.13.4
0.0.0-20200124225646-8b5121be2f68
1.12.16
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
golang.org/x/crypto@v0.0.0-20190923035154-9ee001bba392
0.0.0-20200124225646-8b5121be2f68
3
cesanta/docker_auth:1.6.04d16885f3d4c
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20200124225646-8b5121be2f68
2
csiplugin/csi-qingcloud:v1.4.00766163dc046
golang.org/x/crypto@v0.0.0-20190611184440-5c40567a22f8
0.0.0-20200124225646-8b5121be2f68
2
grafana/loki:1.5.0922b3f412fdd
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20200124225646-8b5121be2f68
2
grafana/promtail:1.5.046e88d390cd6
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
0.0.0-20200124225646-8b5121be2f68
2
iomesh/hostpath-provisioner:v0.5.1f4878c8ae53a
stdlib@go1.13.1
1.12.16
2
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
golang.org/x/crypto@v0.0.0-20181203042331-505ab145d0a9
0.0.0-20200124225646-8b5121be2f68
2
osixia/openldap:1.4.0ccd95cc6e61e
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
stdlib@go1.13.4
0.0.0-20200124225646-8b5121be2f68
1.12.16
2
prom/blackbox-exporter:v0.18.01ffc3f109eb3
golang.org/x/crypto@v0.0.0-20191011191535-87dc89f01550
0.0.0-20200124225646-8b5121be2f68
2
prom/prometheus:v2.17.242d2395cd719
golang.org/x/crypto@v0.0.0-20191206172530-e9b2fee46413
0.0.0-20200124225646-8b5121be2f68
2
prom/pushgateway:v1.0.1a5df60347882
stdlib@go1.13.5
1.12.16
2
squareup/ghostunnel:v1.5.270f4cf270425
golang.org/x/crypto@v0.0.0-20191002192127-34f69633bfdc
stdlib@go1.13.4
0.0.0-20200124225646-8b5121be2f68
1.12.16
2
thomasnyambati/labelsmanager-controller:1.0.0148ae3f99fea
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20200124225646-8b5121be2f68
2
weblate/weblate:4.2.2-169c160d37a3c
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
stdlib@go1.13.5
0.0.0-20200124225646-8b5121be2f68
1.12.16
2
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20200124225646-8b5121be2f68
2
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/crypto@v0.0.0-20190701094942-4def268fd1a4
0.0.0-20200124225646-8b5121be2f68
2
alpine/k8s:1.18.16a41efe02a041
stdlib@go1.13.4
1.12.16
1
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
stdlib@go1.13.4
1.12.16
1
ansgroup/cert-manager-webhook-safedns:v1.0.1cd6b0ef2b309
golang.org/x/crypto@v0.0.0-20191202143827-86a70503ff7e
0.0.0-20200124225646-8b5121be2f68
1
apache/skywalking-oap-server:8.1.0-es7641237e0299b
golang.org/x/crypto@v0.0.0-20191122220453-ac88ee75c92c
stdlib@go1.13.3
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
apache/skywalking-ui:8.1.067d50e4deff4
golang.org/x/crypto@v0.0.0-20191122220453-ac88ee75c92c
stdlib@go1.13.3
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
assistiot/smart-orchestrator_helm:latest9bb46ea14e8e
stdlib@go1.13
1.12.16
1
bitnamilegacy/mongodb:4.4.5e3c9d6b4bc92
golang.org/x/crypto@v0.0.0-20190530122614-20be4c3c3ed5
0.0.0-20200124225646-8b5121be2f68
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
stdlib@go1.13.3
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
stdlib@go1.13.4
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
chandanteekinavar/findery-market-payment-service:1.0c96f759b6ce4
stdlib@go1.13
1.12.16
1
cloudposse/bastion:latest0d9507e8a760
stdlib@go1.13.3
1.12.16
1
codercom/code-server:3.10.247605610ad8d
golang.org/x/crypto@v0.0.0-20191206172530-e9b2fee46413
0.0.0-20200124225646-8b5121be2f68
1
crowdfox/external-service-operator:v1.1.06fa7e8063d27
golang.org/x/crypto@v0.0.0-20190605123033-f99c8df09eb5
0.0.0-20200124225646-8b5121be2f68
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
golang.org/x/crypto@v0.0.0-20190308221718-c2843e01d9a2
0.0.0-20200124225646-8b5121be2f68
1
datappeal/hive-metastore:lateste38c085a3567
golang.org/x/crypto@v0.0.0-20191112222119-e1110fd1c708
stdlib@go1.13.4
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
golang.org/x/crypto@v0.0.0-20191028145041-f83a4685e152
helm.sh/helm/v3@v3.0.3
0.0.0-20200124225646-8b5121be2f68
3.1.0
1
devspacecloud/manager:0.3.349c397413f7b
golang.org/x/crypto@v0.0.0-20190820162420-60c769a6c586
0.0.0-20200124225646-8b5121be2f68
1
drone/drone-runner-docker:1.8.1137e79c5e23c
golang.org/x/crypto@v0.0.0-20190621222207-cc06ce4a13d4
0.0.0-20200124225646-8b5121be2f68
1
drone/kubernetes-secrets:latest206df2280ecf
golang.org/x/crypto@v0.0.0-20180808211826-de0752318171
0.0.0-20200124225646-8b5121be2f68
1
engrmth/bnkr:2.1.06d8464e6f0e8
golang.org/x/crypto@v0.0.0-20190530122614-20be4c3c3ed5
0.0.0-20200124225646-8b5121be2f68
1
envoyproxy/ratelimit:v1.4.071081616da3e
golang.org/x/crypto@v0.0.0-20191219195013-becbf705a915
0.0.0-20200124225646-8b5121be2f68
1
gitlab/gitlab-runner:alpine-v13.2.1fd7e5dfb9f30
golang.org/x/crypto@v0.0.0-20190426145343-a29dc8fdc734
0.0.0-20200124225646-8b5121be2f68
1
gomods/athens:v0.8.1d714c7ff0231
golang.org/x/crypto@v0.0.0-20190513172903-22d7a77e9e5f
stdlib@go1.13.4
0.0.0-20200124225646-8b5121be2f68
1.12.16
1
gomods/athens:v0.11.0efb811df7844
golang.org/x/crypto@v0.0.0-20191206172530-e9b2fee46413
0.0.0-20200124225646-8b5121be2f68
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.