CVE-2021-4235
MediumAdvisory
Published 14 Apr 2021In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.5
- base score, highest
- EPSS
- 0.004
- 35th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 60
- of 17,781 indexed, latest versions
- Container images
- 38
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
YAML Go package vulnerable to denial of service
Carried by container images the latest versions of 60 of 17,781 indexed charts deploy, on 38 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| gopkg.in/ | v2.0.0-20170712054546-1be3d31502d6, v2.0.0-20170812160011-eb3733d160e7, v2.0.0-20190319135612-7b8349ac747c, v2.2.1+1 more | 2.2.3 | 32 |
| github.com/ | v2.1.0+incompatible | no fix listed | 7 |
- OSV records
- GHSA-r88r-gmrh-7j83
- Also known as
- GO-2021-0061
Charts affected
60 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| webhook-receiversoftonic | 2.1.1 | 1 of 1See more | 1,927 |
| vaultstakaterVerified publisher | 0.8.4 | 1 of 2See more | 5,864 |
| cost-analyzerstatcan | 1.82.2 | 1 of 9See more | 16,506 |
| prometheus-operatorstatcan | 0.2.2 | 1 of 7See more | 12,237 |
| prometheustnh | 11.6.0 | 1 of 6See more | 8,484 |
| monitorortrozz | 0.0.1 | 1 of 1See more | 3,109 |
| gohttpserverutkuozdemirVerified publisher | 0.2.0 | 1 of 1See more | 1,898 |
| generic-webhookwebhooks | 0.1.1 | 1 of 1See more | 2,030 |
| temporalwenerme | 0.15.1 | 1 of 13See more | 22,665 |
| dex-k8s-authenticatorwiremindVerified publisher | 1.7.0 | 1 of 1See more | 2,791 |
Container images carrying it
38 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| prom/ | 7e4e9f7a0954 | gopkg.in/ | 2.2.3 | 5 |
| prom/ | 0a8caa2e9f19 | gopkg.in/ | 2.2.3 | 5 |
| mintel/ | caf71cee7b9a | gopkg.in/ | 2.2.3 | 3 |
| quay.io/ | f402e6039b3c | gopkg.in/ | 2.2.3 | 3 |
| registry.k8s.io/ | c825f3d5e28b | gopkg.in/ | 2.2.3 | 3 |
| cesanta/ | 4d16885f3d4c | gopkg.in/ | 2.2.3 | 2 |
| hashicorp/ | 4db614d40d0e | github.com/ | no fix listed | 2 |
| jettech/ | c42098c8d855 | gopkg.in/ | 2.2.3 | 2 |
| natsio/ | 9fbf7bf684e4 | gopkg.in/ | 2.2.3 | 2 |
| pottava/ | 20a0bcb15f76 | gopkg.in/ | 2.2.3 | 2 |
| weblate/ | 69c160d37a3c | gopkg.in/ | 2.2.3 | 2 |
| gcr.io/ | 2de1d15fc1f2 | gopkg.in/ | 2.2.3 | 2 |
| ghcr.io/ | f04718704dab | gopkg.in/ | 2.2.3 | 2 |
| almir/ | 1698346f6077 | gopkg.in/ | 2.2.3 | 1 |
| codercom/ | 1e2cc688008e | gopkg.in/ | 2.2.3 | 1 |
| codercom/ | 47605610ad8d | gopkg.in/ | 2.2.3 | 1 |
| codeskyblue/ | caa862590e34 | github.com/ | no fix listed | 1 |
| drone/ | 137e79c5e23c | gopkg.in/ | 2.2.3 | 1 |
| drone/ | 206df2280ecf | gopkg.in/ | 2.2.3 | 1 |
| gotify/ | 09c79bc1e403 | github.com/ | no fix listed | 1 |
| hashicorp/ | dfc3500beb0e | github.com/ | no fix listed | 1 |
| ianw/ | dc49dd460c37 | gopkg.in/ | 2.2.3 | 1 |
| layer5/ | 8c20a8a1d6a4 | gopkg.in/ | 2.2.3 | 1 |
| metalmatze/ | 426bc2ca7586 | gopkg.in/ | 2.2.3 | 1 |
| mirrorgitlabcontainers/ | 06b19a4bc805 | gopkg.in/ | 2.2.3 | 1 |
| monitoror/ | 4b88edcf51ff | gopkg.in/ | 2.2.3 | 1 |
| oxynozeta/ | 31f11669d597 | github.com/ gopkg.in/ | no fix listed 2.2.3 | 1 |
| rancher/ | 42784bb38ed3 | gopkg.in/ | 2.2.3 | 1 |
| softonic/ | 94b87f1fb362 | gopkg.in/ | 2.2.3 | 1 |
| weaveworks/ | a9c2e9df4227 | gopkg.in/ | 2.2.3 | 1 |
| weblate/ | 82848df56ecd | gopkg.in/ | 2.2.3 | 1 |
| gcr.io/ | 2b1a3d08caac | gopkg.in/ | 2.2.3 | 1 |
| gcr.io/ | a348db3e4d74 | gopkg.in/ | 2.2.3 | 1 |
| ghcr.io/ | 0c84c2d71006 | gopkg.in/ | 2.2.3 | 1 |
| ghcr.io/ | 233aa9808fc7 | github.com/ | no fix listed | 1 |
| ghcr.io/ | 72e7e77f8091 | gopkg.in/ | 2.2.3 | 1 |
| ghcr.io/ | c3d9d9c98be7 | github.com/ | no fix listed | 1 |
| quay.io/ | 6c308e9732e1 | gopkg.in/ | 2.2.3 | 1 |