StackRadar

CVE-2021-3121

High

Advisory

Published 14 Apr 2021In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.6
base score, highest
EPSS
0.035
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
308
of 17,781 indexed, latest versions
Container images
308
deployed by those charts
Fix available
1 of 1
affected package

Improper Input Validation in GoGo Protobuf

Carried by container images the latest versions of 308 of 17,781 indexed charts deploy, on 308 images.

Affected packageAffected versionsFixed inImages
github.com/gogo/protobufgolangv0.0.0-20160824171236-909568be09de, v0.0.0-20170307180453-100ba4e88506, v1.0.0, v1.1.1+7 more1.3.2308
OSV records
GHSA-c3h9-896r-86jm
Also known as
BIT-consul-2021-3121, BIT-protobuf-2021-3121, GO-2021-0053

Charts affected

308 by stars
ChartLatestAffected imagesRadar Score
ambassadorwenerme6.9.51 of 2See more

ambassador wenerme 6.9.5

1 of the 2 container images this version deploys carry CVE-2021-3121.

Container imageDigestPackageFixed in
datawire/aes:1.14.48588eafe6862
github.com/gogo/protobuf@v1.3.1
1.3.2

Open the chart page →

4,086
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2021-3121.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
github.com/gogo/protobuf@v1.2.0
1.3.2

Open the chart page →

4,984
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2021-3121.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
github.com/gogo/protobuf@v1.3.1
1.3.2

Open the chart page →

6,915
nfs-subdir-external-provisionerwenerme4.0.181 of 1See more

nfs-subdir-external-provisioner wenerme 4.0.18

1 of the 1 container images this version deploys carry CVE-2021-3121.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.263d5e04551ec
github.com/gogo/protobuf@v1.3.1
1.3.2

Open the chart page →

2,743
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2021-3121.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
github.com/gogo/protobuf@v1.2.2-0.20190730201129-28a6bbf47e48
1.3.2
prom/prometheus:v2.16.0e4ca62c0d62f
github.com/gogo/protobuf@v1.2.2-0.20190730201129-28a6bbf47e48
1.3.2

Open the chart page →

22,665
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2021-3121.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
github.com/gogo/protobuf@v1.3.0
1.3.2

Open the chart page →

3,369
csi-driver-host-pathwiremindVerified publisher0.1.11 of 8See more

csi-driver-host-path wiremind 0.1.1

1 of the 8 container images this version deploys carry CVE-2021-3121.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
github.com/gogo/protobuf@v1.3.1
1.3.2

Open the chart page →

12,606
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2021-3121.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
github.com/gogo/protobuf@v1.3.1
1.3.2

Open the chart page →

3,023

Container images carrying it

308 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/tigera/operator:v1.20.1379efe0c2541
github.com/gogo/protobuf@v1.3.1
1.3.2
1
quay.io/tigera/operator:v1.15.1c6591da87aa8
github.com/gogo/protobuf@v1.3.1
1.3.2
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
github.com/gogo/protobuf@v1.2.2-0.20190723190241-65acae22fc9d
1.3.2
1
quay.io/uswitch/kiam:v4.0be3a5846922d
github.com/gogo/protobuf@v1.2.1
1.3.2
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
github.com/gogo/protobuf@v1.3.1
1.3.2
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
github.com/gogo/protobuf@v1.3.1
1.3.2
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
github.com/gogo/protobuf@v1.3.1
1.3.2
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
github.com/gogo/protobuf@v1.3.1
1.3.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.