CVE-2021-20329
MediumAdvisory
Published 15 Jun 2021In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.8
- base score, highest
- EPSS
- 0.010
- 60th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 72
- of 17,781 indexed, latest versions
- Container images
- 65
- deployed by those charts
- Fix available
- 1 of 1
- affected package
go.mongodb.org/mongo-driver improperly validates cstrings when marshalling Go objects into BSON
Carried by container images the latest versions of 72 of 17,781 indexed charts deploy, on 65 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| go.mongodb.org/ | v1.0.0, v1.0.3, v1.0.4, v1.1.0+12 more | 1.5.1 | 65 |
- OSV records
- GHSA-f6mq-5m25-4r72
- Also known as
- GO-2021-0112
Charts affected
72 by stars
Container images carrying it
65 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| thanosio/ | 88276fcd1491 | go.mongodb.org/ | 1.5.1 | 1 |
| thanosio/ | b12d5c31bf5a | go.mongodb.org/ | 1.5.1 | 1 |
| ghcr.io/ | e159ba41aede | go.mongodb.org/ | 1.5.1 | 1 |
| ghcr.io/ | 2fe6b69b20d7 | go.mongodb.org/ | 1.5.1 | 1 |
| ghcr.io/ | edc238a538a0 | go.mongodb.org/ | 1.5.1 | 1 |
| ghcr.io/ | b61c750ade19 | go.mongodb.org/ | 1.5.1 | 1 |
| ghcr.io/ | 31060be60bec | go.mongodb.org/ | 1.5.1 | 1 |
| quay.io/ | 5b6701d8fb31 | go.mongodb.org/ | 1.5.1 | 1 |
| quay.io/ | 5d1c2cf4c538 | go.mongodb.org/ | 1.5.1 | 1 |
| quay.io/ | 9663f06adcb1 | go.mongodb.org/ | 1.5.1 | 1 |
| quay.io/ | 4fbd63194674 | go.mongodb.org/ | 1.5.1 | 1 |
| quay.io/ | 6ba82beff18e | go.mongodb.org/ | 1.5.1 | 1 |
| quay.io/ | 5b62aaade3c9 | go.mongodb.org/ | 1.5.1 | 1 |
| quay.io/ | e362f02ed304 | go.mongodb.org/ | 1.5.1 | 1 |
| registry.gitlab.com/ | cf72810d33f5 | go.mongodb.org/ | 1.5.1 | 1 |