StackRadar

CVE-2021-34558

Unscored

Advisory

Published 17 Feb 2022In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.070
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
563
of 17,787 indexed, latest versions
Container images
574
deployed by those charts
Fix available
1 of 1
affected package

Panic on certain certificates in crypto/tls

Carried by container images the latest versions of 563 of 17,787 indexed charts deploy, on 574 images.

Affected packageAffected versionsFixed inImages
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+45 more1.15.14574
OSV records
GO-2021-0243
Also known as
BIT-golang-2021-34558

Charts affected

563 by stars
ChartLatestAffected imagesRadar Score
contactmoment-componentcontactmoment-component0.1.01 of 4See more

contactmoment-component contactmoment-component 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
conduction/contactmoment-component-php:deve1d4ad1e22a8
stdlib@go1.13.10
1.15.14

Open the chart page →

8,408
katibcowboysysopVerified publisher2.4.21 of 4See more

katib cowboysysop 2.4.2

1 of the 4 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
kubeflowkatib/katib-db-manager:v0.12.0db88bf09d88e
stdlib@go1.13.3
1.15.14

Open the chart page →

6,542
kfservingcowboysysopVerified publisher1.3.11 of 3See more

kfserving cowboysysop 1.3.1

1 of the 3 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
kfserving/kfserving-controller:v0.6.163d79d04c2e3
stdlib@go1.14.14
1.15.14

Open the chart page →

3,830
mpi-operatorcowboysysopVerified publisher1.2.21 of 1See more

mpi-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
stdlib@go1.15.13
1.15.14

Open the chart page →

2,577
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
stdlib@go1.13.1
1.15.14

Open the chart page →

5,488
training-operatorcowboysysopVerified publisher1.2.21 of 1See more

training-operator cowboysysop 1.2.2

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
public.ecr.aws/j1r0q0g6/training/training-operator:760ac1171dd30039a7363ffa03c77454bd714da5ae59d222fd87
stdlib@go1.14.9
1.15.14

Open the chart page →

2,275
crossplane-controllerscrossplane0.12.01 of 1See more

crossplane-controllers crossplane 0.12.0

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
crossplane/crossplane:v0.12.066666e6963af
stdlib@go1.14.4
1.15.14

Open the chart page →

2,312
oam-kubernetes-runtimecrossplane0.0.3-71.g0f235901 of 2See more

oam-kubernetes-runtime crossplane 0.0.3-71.g0f23590

1 of the 2 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.0.3-71.g0f235900112171c45e3
stdlib@go1.13.14
1.15.14

Open the chart page →

2,248
oam-kubernetes-runtime-legacycrossplane0.3.1-5.g11e18941 of 1See more

oam-kubernetes-runtime-legacy crossplane 0.3.1-5.g11e1894

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
crossplane/oam-kubernetes-runtime:v0.3.1-5.g11e189407b8b410dc76
stdlib@go1.13.15
1.15.14

Open the chart page →

2,231
external-service-operatorcrowdfox0.1.01 of 1See more

external-service-operator crowdfox 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
crowdfox/external-service-operator:v1.1.06fa7e8063d27
stdlib@go1.14.2
1.15.14

Open the chart page →

4,624
electric-mailcryptexlabsVerified publisher0.0.11 of 5See more

electric-mail cryptexlabs 0.0.1

1 of the 5 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.13.1bebb03e8e800
stdlib@go1.16.3
1.15.14

Open the chart page →

5,973
purple-piecryptexlabsVerified publisher0.0.11 of 4See more

purple-pie cryptexlabs 0.0.1

1 of the 4 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
hashicorp/vault-k8s:0.13.1bebb03e8e800
stdlib@go1.16.3
1.15.14

Open the chart page →

5,973
openldapcsic-charts0.1.11 of 2See more

openldap csic-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.15.14

Open the chart page →

5,293
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
stdlib@go1.14.12
1.15.14

Open the chart page →

13,852
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
stdlib@go1.16
1.15.14

Open the chart page →

3,238
nfs-provisionerdasmeta1.0.31 of 1See more

nfs-provisioner dasmeta 1.0.3

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
stdlib@go1.13.4
1.15.14

Open the chart page →

2,806
datadog-csi-driverdatadogVerified publisher0.17.01 of 2See more

datadog-csi-driver datadog 0.17.0

1 of the 2 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.15.14

Open the chart page →

2,040
datadog-operatordatadog-test0.1.21 of 1See more

datadog-operator datadog-test 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
datadog/operator:0.3.117f08a860090
stdlib@go1.15.2
1.15.14

Open the chart page →

3,980
ambassador-operatordatawire0.3.01 of 1See more

ambassador-operator datawire 0.3.0

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
datawire/ambassador-operator:v1.3.0f95ae710d75c
stdlib@go1.16.5
1.15.14

Open the chart page →

7,486
aws-s3-proxydeliveryheroVerified publisher0.1.71 of 1See more

aws-s3-proxy deliveryhero 0.1.7

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
pottava/s3-proxy:2.020a0bcb15f76
stdlib@go1.13.7
1.15.14

Open the chart page →

1,323
aws-service-events-exporterdeliveryheroVerified publisher1.0.71 of 1See more

aws-service-events-exporter deliveryhero 1.0.7

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
thomasnyambati/aws-service-events-exporter:1.0.01e18a0944ceb
stdlib@go1.15.6
1.15.14

Open the chart page →

1,299
k8s-cloudwatch-adapterdeliveryheroVerified publisher0.2.21 of 1See more

k8s-cloudwatch-adapter deliveryhero 0.2.2

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
chankh/k8s-cloudwatch-adapter:v0.9.0963c44c7f8b1
stdlib@go1.14.5
1.15.14

Open the chart page →

2,468
killgravedeliveryheroVerified publisher1.0.21 of 1See more

killgrave deliveryhero 1.0.2

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
friendsofgo/killgrave:0.4.139cfbecca342
stdlib@go1.16.3
1.15.14

Open the chart page →

1,181
prometheus-soti-mobicontrol-exporterdeliveryheroVerified publisher1.0.31 of 1See more

prometheus-soti-mobicontrol-exporter deliveryhero 1.0.3

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
stdlib@go1.14
1.15.14

Open the chart page →

1,644
prometheus-statsd-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-statsd-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.18.0d23aca343b86
stdlib@go1.14.7
1.15.14

Open the chart page →

1,315
pushproxdevopstalesVerified publisher0.1.62 of 2See more

pushprox devopstales 0.1.6

2 of the 2 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
stdlib@go1.16.4
1.15.14
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
stdlib@go1.16.4
1.15.14

Open the chart page →

3,754
lxd8sdevplayer0Verified publisher0.5.12 of 2See more

lxd8s devplayer0 0.5.1

2 of the 2 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
stdlib@go1.16.5
1.15.14
ghcr.io/devplayer0/lxd8s:0.3.1e159ba41aede
stdlib@go1.16.5
1.15.14

Open the chart page →

5,431
argocddevtron1.8.12 of 3See more

argocd devtron 1.8.1

2 of the 3 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
stdlib@go1.14.12
1.15.14
quay.io/dexidp/dex:v2.25.07bcf286807b8
stdlib@go1.14.9
1.15.14

Open the chart page →

10,466
devtron-enterprisedevtron48.0.02 of 28See more

devtron-enterprise devtron 48.0.0

2 of the 28 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
quay.io/devtron/dex:v2.30.22e4c14d1b444
stdlib@go1.15.7
1.15.14
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
stdlib@go1.14.15
1.15.14

Open the chart page →

68,240
devtron-in-clustercddevtron0.10.21 of 2See more

devtron-in-clustercd devtron 0.10.2

1 of the 2 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
stdlib@go1.15.7
1.15.14

Open the chart page →

5,039
kube-prometheus-stackdevtron19.3.01 of 6See more

kube-prometheus-stack devtron 19.3.0

1 of the 6 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
stdlib@go1.16
1.15.14

Open the chart page →

8,645
argocddevtron-labs1.8.12 of 3See more

argocd devtron-labs 1.8.1

2 of the 3 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
stdlib@go1.14.12
1.15.14
quay.io/dexidp/dex:v2.25.07bcf286807b8
stdlib@go1.14.9
1.15.14

Open the chart page →

10,466
calicodevtron-labs0.1.14 of 4See more

calico devtron-labs 0.1.1

4 of the 4 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
stdlib@go1.15.2
1.15.14
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
stdlib@go1.15.2
1.15.14
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
stdlib@go1.15.2
1.15.14
quay.io/devtron/calico-networking:pod2daemon-flexvol-v3.19.1c1f36b6e18e0
stdlib@go1.15.2
1.15.14

Open the chart page →

10,071
devtron-enterprisedevtron-labs48.0.02 of 28See more

devtron-enterprise devtron-labs 48.0.0

2 of the 28 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
quay.io/devtron/dex:v2.30.22e4c14d1b444
stdlib@go1.15.7
1.15.14
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
stdlib@go1.14.15
1.15.14

Open the chart page →

68,240
devtron-in-clustercddevtron-labs0.10.21 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

1 of the 2 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
stdlib@go1.15.7
1.15.14

Open the chart page →

5,039
devtron-operatordevtron-labs0.23.31 of 11See more

devtron-operator devtron-labs 0.23.3

1 of the 11 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
quay.io/devtron/dex:v2.30.22e4c14d1b444
stdlib@go1.15.7
1.15.14

Open the chart page →

32,902
kube-prometheus-stackdevtron-labs19.3.01 of 6See more

kube-prometheus-stack devtron-labs 19.3.0

1 of the 6 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
stdlib@go1.16
1.15.14

Open the chart page →

8,645
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.15.14

Open the chart page →

27,550
digital-mobiusdigital-mobius0.1.41 of 1See more

digital-mobius digital-mobius 0.1.4

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
qoveryrd/digital-mobius:0.1.4b30a9398a83c
stdlib@go1.15.5
1.15.14

Open the chart page →

2,287
snmp-exporterdniel0.0.21 of 1See more

snmp-exporter dniel 0.0.2

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
prom/snmp-exporter:v0.20.09d226d7de223
stdlib@go1.15.8
1.15.14

Open the chart page →

2,126
whoamidniel0.8.11 of 1See more

whoami dniel 0.8.1

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
containous/whoami:latest7d6a3c8f9147
stdlib@go1.14
1.15.14

Open the chart page →

1,279
docparserdocparser0.1.01 of 4See more

docparser docparser 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
conduction/docparser-php:devb6f95c8ead7d
stdlib@go1.13.10
1.15.14

Open the chart page →

8,408
overlorddoubanVerified publisher0.2.21 of 1See more

overlord douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
douz/overlord:latestf2bc7fc068c1
stdlib@go1.14.5
1.15.14

Open the chart page →

3,693
prometheus-memcached-exporterdoubanVerified publisher0.1.31 of 1See more

prometheus-memcached-exporter douban 0.1.3

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
prom/memcached-exporter:v0.9.001267317c95d
stdlib@go1.16.2
1.15.14

Open the chart page →

2,114
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
oscarsotosanchez/weatherservice:v1.0911ec961d10b
stdlib@go1.15.6
1.15.14

Open the chart page →

24,656
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
stdlib@go1.15.6
1.15.14

Open the chart page →

30,699
drogue-cloud-metricsdrogue-iotVerified publisher0.7.115 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

5 of the 8 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.15.14
prom/pushgateway:v1.3.18305a33fb80a
stdlib@go1.15.6
1.15.14
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.15.14
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
stdlib@go1.15.8
1.15.14
quay.io/prometheus/prometheus:v2.26.038d40a760569
stdlib@go1.16.2
1.15.14

Open the chart page →

13,558
drone-kubernetes-secretsdroneVerified publisher0.1.41 of 1See more

drone-kubernetes-secrets drone 0.1.4

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
drone/kubernetes-secrets:latest206df2280ecf
stdlib@go1.13.15
1.15.14

Open the chart page →

2,760
temporaldtrdnk-helm-chartsVerified publisher0.35.02 of 13See more

temporal dtrdnk-helm-charts 0.35.0

2 of the 13 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
grafana/grafana:6.7.11ff3999e0fc0
stdlib@go1.13.4
1.15.14
jimmidyson/configmap-reload:v0.5.0904d08e9f701
stdlib@go1.15.7
1.15.14

Open the chart page →

20,205
applause-btnduyet0.1.11 of 1See more

applause-btn duyet 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-34558.

Container imageDigestPackageFixed in
duyetdev/applause-btn:latest25e59d223eaa
stdlib@go1.14.9
1.15.14

Open the chart page →

2,636

Container images carrying it

574 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/metallb/controller:v0.10.221164241c045
stdlib@go1.16.5
1.15.14
1
quay.io/metallb/speaker:v0.10.258cb99053bb3
stdlib@go1.16.5
1.15.14
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
stdlib@go1.13.15
1.15.14
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
stdlib@go1.14.10
1.15.14
1
quay.io/oauth2-proxy/oauth2-proxy:v6.1.1791aef35b8d1
stdlib@go1.14.4
1.15.14
1
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
stdlib@go1.16
1.15.14
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
stdlib@go1.13.1
1.15.14
1
quay.io/opstree/druid-exporter:v0.83f6d9885cfe2
stdlib@go1.14.6
1.15.14
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
stdlib@go1.16
1.15.14
1
quay.io/thanos/thanos:v0.17.1e362f02ed304
stdlib@go1.15
1.15.14
1
quay.io/tigera/operator:v1.20.1379efe0c2541
stdlib@go1.15.2
1.15.14
1
quay.io/tigera/operator:v1.15.1c6591da87aa8
stdlib@go1.15.2
1.15.14
1
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
stdlib@go1.13.15
1.15.14
1
quay.io/uswitch/kiam:v4.0be3a5846922d
stdlib@go1.13.8
1.15.14
1
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
stdlib@go1.16.4
1.15.14
1
registry.gitlab.com/av1o/go-prism:4fdcff7d3870c28e5f024b6947cb552d4b956ee27a6f84b81c4e
stdlib@go1.16.2
1.15.14
1
registry.gitlab.com/av1o/okd-webhook:v0.1.028c3e5eb2650
stdlib@go1.16
1.15.14
1
registry.gitlab.com/commento/commento:v1.8.0e0ab1fc86761
stdlib@go1.14.2
1.15.14
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/mongodb:4.4.5cf72810d33f5
stdlib@go1.15.8
1.15.14
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.15.14
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.15.14
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.15.14
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.15.14
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.15.14
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.