CVE-2021-41772
UnscoredAdvisory
Published 13 Jan 2022In the index since 5 Sept 2026
- Severity
- Unscored
- worst across findings
- CVSS
- —
- base score, highest
- EPSS
- 0.033
- 88th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 751
- of 17,787 indexed, latest versions
- Container images
- 763
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Panic when opening certain archives in archive/zip
Carried by container images the latest versions of 751 of 17,787 indexed charts deploy, on 763 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+54 more | 1.16.10 | 763 |
- OSV records
- GO-2021-0264
- Also known as
- BIT-golang-2021-41772
Charts affected
751 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| zookeeper-exporterzookeeper-exporter | 0.1.0 | 1 of 1See more | 1,248 |
Container images carrying it
763 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| prom/ | a5df60347882 | stdlib | 1.16.10 | 2 |
| prom/ | c0d39b8d4cfe | stdlib | 1.16.10 | 2 |
| qingcloud/ | 4cd5366a9f51 | stdlib | 1.16.10 | 2 |
| scaleway/ | dcc14608d000 | stdlib | 1.16.10 | 2 |
| squareup/ | 70f4cf270425 | stdlib | 1.16.10 | 2 |
| statping/ | e874da513a5c | stdlib | 1.16.10 | 2 |
| thesisrobot/ | 89ae07e787ca | stdlib | 1.16.10 | 2 |
| thesisrobot/ | 2d1c388a4bda | stdlib | 1.16.10 | 2 |
| thomasnyambati/ | 1e18a0944ceb | stdlib | 1.16.10 | 2 |
| thomasnyambati/ | 148ae3f99fea | stdlib | 1.16.10 | 2 |
| tkpd/ | 74441dadcfbd | stdlib | 1.16.10 | 2 |
| voltha/ | 8feb9ef89e97 | stdlib | 1.16.10 | 2 |
| voltha/ | 7a325316fe59 | stdlib | 1.16.10 | 2 |
| weblate/ | 69c160d37a3c | stdlib | 1.16.10 | 2 |
| yzhou442/ | a3f7ca69e28d | stdlib | 1.16.10 | 2 |
| gcr.io/ | 2de1d15fc1f2 | stdlib | 1.16.10 | 2 |
| ghcr.io/ | 0df4ae70e3bd | stdlib | 1.16.10 | 2 |
| ghcr.io/ | f02325f099bc | stdlib | 1.16.10 | 2 |
| ghcr.io/ | 99efbe55412b | stdlib | 1.16.10 | 2 |
| ghcr.io/ | 5e88f2205de1 | stdlib | 1.16.10 | 2 |
| quay.io/ | c9b7f6d0d953 | stdlib | 1.16.10 | 2 |
| quay.io/ | 5f6f8ba0b671 | stdlib | 1.16.10 | 2 |
| quay.io/ | 464a3af4dfe0 | stdlib | 1.16.10 | 2 |
| quay.io/ | 8a3a33cad0bd | stdlib | 1.16.10 | 2 |
| quay.io/ | 983627001c89 | stdlib | 1.16.10 | 2 |
| quay.io/ | b899dbd1b901 | stdlib | 1.16.10 | 2 |
| registry.k8s.io/ | 63d5e04551ec | stdlib | 1.16.10 | 2 |
| absaoss/ | ad538a1285a0 | stdlib | 1.16.10 | 1 |
| adrianberger/ | 76848c0d2780 | stdlib | 1.16.10 | 1 |
| alex6021710/ | 6c7a47e470c3 | stdlib | 1.16.10 | 1 |
| alex6021710/ | 744b8a924f35 | stdlib | 1.16.10 | 1 |
| alex6021710/ | 5837d9b30cc7 | stdlib | 1.16.10 | 1 |
| alex6021710/ | f73e8d60fd03 | stdlib | 1.16.10 | 1 |
| almir/ | 1698346f6077 | stdlib | 1.16.10 | 1 |
| almorgv/ | 5f2a7d2b44d8 | stdlib | 1.16.10 | 1 |
| alpine/ | 00ac10bcb759 | stdlib | 1.16.10 | 1 |
| alpine/ | a41efe02a041 | stdlib | 1.16.10 | 1 |
| altinity/ | db7dde971407 | stdlib | 1.16.10 | 1 |
| altinity/ | 85b4fdbae053 | stdlib | 1.16.10 | 1 |
| amazon/ | b55277652ea8 | stdlib | 1.16.10 | 1 |
| amazon/ | c9b14856fd22 | stdlib | 1.16.10 | 1 |
| amazon/ | e745d1783c93 | stdlib | 1.16.10 | 1 |
| anchore/ | bde9eedf639d | stdlib | 1.16.10 | 1 |
| ansgroup/ | cd6b0ef2b309 | stdlib | 1.16.10 | 1 |
| ansiblesemaphore/ | 03d1f8684027 | stdlib | 1.16.10 | 1 |
| apache/ | c010ea7d1694 | stdlib | 1.16.10 | 1 |
| apache/ | 412f92cde0b3 | stdlib | 1.16.10 | 1 |
| apache/ | 133d35d2c263 | stdlib | 1.16.10 | 1 |
| apache/ | 641237e0299b | stdlib | 1.16.10 | 1 |
| apache/ | b4ec8c18d079 | stdlib | 1.16.10 | 1 |