StackRadar

CVE-2021-27918

Unscored

Advisory

Published 17 Feb 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.025
84th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
454
of 17,787 indexed, latest versions
Container images
445
deployed by those charts
Fix available
1 of 1
affected package

Infinite loop when decoding inputs in encoding/xml

Carried by container images the latest versions of 454 of 17,787 indexed charts deploy, on 445 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+36 more1.15.9445
OSV records
GO-2021-0234
Also known as
BIT-golang-2021-27918

Charts affected

454 by stars
ChartLatestAffected imagesRadar Score
rawfile-csiymatrixVerified publisher0.2.12 of 4See more

rawfile-csi ymatrix 0.2.1

2 of the 4 container images this version deploys carry CVE-2021-27918.

Container imageDigestPackageFixed in
matrixdb/sig-storage_csi-node-driver-registrar:v2.2.0ba763bb01ddc
stdlib@go1.16
1.15.9
matrixdb/sig-storage_livenessprobe:v2.3.07ab06fe3d8a7
stdlib@go1.16
1.15.9

Open the chart page →

7,972
nginx-vts-exporterymrs0.1.21 of 1See more

nginx-vts-exporter ymrs 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-27918.

Container imageDigestPackageFixed in
sophos/nginx-vts-exporter:latestf1073556b29b
stdlib@go1.13.6
1.15.9

Open the chart page →

1,336
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2021-27918.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
stdlib@go1.15.2
1.15.9

Open the chart page →

3,023
zookeeper-exporterzookeeper-exporter0.1.01 of 1See more

zookeeper-exporter zookeeper-exporter 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-27918.

Container imageDigestPackageFixed in
dabealu/zookeeper-exporter:latest86106fec315f
stdlib@go1.14.15
1.15.9

Open the chart page →

1,248

Container images carrying it

445 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
stdlib@go1.15
1.15.9
1
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
stdlib@go1.13.10
1.15.9
1
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
stdlib@go1.15.2
1.15.9
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
stdlib@go1.13.4
1.15.9
1
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
stdlib@go1.15.6
1.15.9
1
ghcr.io/pipe-cd/pipecd:v0.39.00fae829caf29
stdlib@go1.14.6
1.15.9
1
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
stdlib@go1.15.7
1.15.9
1
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
stdlib@go1.15.4
1.15.9
1
mcr.microsoft.com/oss/kubernetes-csi/csi-attacher:v2.2.0f55f30876129
stdlib@go1.14
1.15.9
1
mcr.microsoft.com/oss/kubernetes-csi/csi-node-driver-registrar:v2.0.1fc5d14e9f26f
stdlib@go1.15
1.15.9
1
mcr.microsoft.com/oss/kubernetes-csi/csi-provisioner:v1.6.1667b1b1ea1e4
stdlib@go1.15.2
1.15.9
1
mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.1.07997e0f236bc
stdlib@go1.15.2
1.15.9
1
mcr.microsoft.com/oss/kubernetes-csi/livenessprobe:v2.2.0b7d82802cca8
stdlib@go1.15.6
1.15.9
1
public.ecr.aws/aws-observability/aws-sigv4-proxy-admission-controller:1.067b89ae52240
stdlib@go1.15.3
1.15.9
1
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r1-10-g1942553-2021.06.04.00.07-linux-amd64b32c99e7bc45
stdlib@go1.15.8
1.15.9
1
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
stdlib@go1.14.9
1.15.9
1
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
stdlib@go1.15.7
1.15.9
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
stdlib@go1.15.1
1.15.9
1
quay.io/evl.ms/pgbouncer-exporter:0.4.074f919b78494
stdlib@go1.14.4
1.15.9
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
stdlib@go1.15.1
1.15.9
1
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
stdlib@go1.15.6
1.15.9
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
stdlib@go1.14.1
1.15.9
1
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
stdlib@go1.13.8
1.15.9
1
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
stdlib@go1.13.8
1.15.9
1
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
stdlib@go1.13.8
1.15.9
1
quay.io/kube-ops/loki:2.2.14fbd63194674
stdlib@go1.15.3
1.15.9
1
quay.io/kube-ops/promtail:2.2.134de6387233b
stdlib@go1.15.3
1.15.9
1
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
stdlib@go1.15.3
1.15.9
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
stdlib@go1.13.15
1.15.9
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
stdlib@go1.14.10
1.15.9
1
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
stdlib@go1.14.4
1.15.9
1
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
stdlib@go1.16
1.15.9
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
stdlib@go1.13.1
1.15.9
1
quay.io/opstree/druid-exporter:v0.83f6d9885cfe2
stdlib@go1.14.6
1.15.9
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
stdlib@go1.16
1.15.9
1
quay.io/thanos/thanos:v0.17.1e362f02ed304
stdlib@go1.15
1.15.9
1
quay.io/tigera/operator:v1.20.1379efe0c2541
stdlib@go1.15.2
1.15.9
1
quay.io/tigera/operator:v1.15.1c6591da87aa8
stdlib@go1.15.2
1.15.9
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
stdlib@go1.13.15
1.15.9
1
quay.io/uswitch/kiam:v4.0be3a5846922d
stdlib@go1.13.8
1.15.9
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.15.9
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
stdlib@go1.14.2
1.15.9
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.15.9
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.15.9
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.15.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.