StackRadar

CVE-2021-4235

Medium

Advisory

Published 14 Apr 2021In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
60
of 17,781 indexed, latest versions
Container images
38
deployed by those charts
Fix available
1 of 2
affected packages

YAML Go package vulnerable to denial of service

Carried by container images the latest versions of 60 of 17,781 indexed charts deploy, on 38 images.

Affected packageAffected versionsFixed inImages
gopkg.in/yaml.v2golangv2.0.0-20170712054546-1be3d31502d6, v2.0.0-20170812160011-eb3733d160e7, v2.0.0-20190319135612-7b8349ac747c, v2.2.1+1 more2.2.332
github.com/go-yaml/yamlgolangv2.1.0+incompatibleno fix listed7
OSV records
GHSA-r88r-gmrh-7j83
Also known as
GO-2021-0061

Charts affected

60 by stars
ChartLatestAffected imagesRadar Score
webhook-receiversoftonic2.1.11 of 1See more

webhook-receiver softonic 2.1.1

1 of the 1 container images this version deploys carry CVE-2021-4235.

Container imageDigestPackageFixed in
almir/webhook:2.8.01698346f6077
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.3

Open the chart page →

1,927
vaultstakaterVerified publisher0.8.41 of 2See more

vault stakater 0.8.4

1 of the 2 container images this version deploys carry CVE-2021-4235.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed

Open the chart page →

5,864
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2021-4235.

Container imageDigestPackageFixed in
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
gopkg.in/yaml.v2@v2.2.2
2.2.3

Open the chart page →

16,506
prometheus-operatorstatcan0.2.21 of 7See more

prometheus-operator statcan 0.2.2

1 of the 7 container images this version deploys carry CVE-2021-4235.

Container imageDigestPackageFixed in
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
gopkg.in/yaml.v2@v2.2.2
2.2.3

Open the chart page →

12,237
prometheustnh11.6.01 of 6See more

prometheus tnh 11.6.0

1 of the 6 container images this version deploys carry CVE-2021-4235.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
gopkg.in/yaml.v2@v2.2.2
2.2.3

Open the chart page →

8,484
monitorortrozz0.0.11 of 1See more

monitoror trozz 0.0.1

1 of the 1 container images this version deploys carry CVE-2021-4235.

Container imageDigestPackageFixed in
monitoror/monitoror:44b88edcf51ff
gopkg.in/yaml.v2@v2.2.2
2.2.3

Open the chart page →

3,109
gohttpserverutkuozdemirVerified publisher0.2.01 of 1See more

gohttpserver utkuozdemir 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-4235.

Container imageDigestPackageFixed in
codeskyblue/gohttpserver:latestcaa862590e34
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed

Open the chart page →

1,898
generic-webhookwebhooks0.1.11 of 1See more

generic-webhook webhooks 0.1.1

1 of the 1 container images this version deploys carry CVE-2021-4235.

Container imageDigestPackageFixed in
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.3

Open the chart page →

2,030
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-4235.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
gopkg.in/yaml.v2@v2.2.2
2.2.3

Open the chart page →

22,665
dex-k8s-authenticatorwiremindVerified publisher1.7.01 of 1See more

dex-k8s-authenticator wiremind 1.7.0

1 of the 1 container images this version deploys carry CVE-2021-4235.

Container imageDigestPackageFixed in
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/yaml.v2@v2.2.2
2.2.3

Open the chart page →

2,791

Container images carrying it

38 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
prom/alertmanager:v0.20.07e4e9f7a0954
gopkg.in/yaml.v2@v2.2.2
2.2.3
5
prom/prometheus:v2.13.10a8caa2e9f19
gopkg.in/yaml.v2@v2.2.2
2.2.3
5
mintel/dex-k8s-authenticator:1.4.0caf71cee7b9a
gopkg.in/yaml.v2@v2.2.2
2.2.3
3
quay.io/kubernetes_incubator/nfs-provisioner:v2.3.0f402e6039b3c
gopkg.in/yaml.v2@v2.2.2
2.2.3
3
registry.k8s.io/sig-storage/nfs-provisioner:v4.0.8c825f3d5e28b
gopkg.in/yaml.v2@v2.2.2
2.2.3
3
cesanta/docker_auth:1.6.04d16885f3d4c
gopkg.in/yaml.v2@v2.2.2
2.2.3
2
hashicorp/vault:1.8.34db614d40d0e
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed
2
jettech/kube-webhook-certgen:v1.2.1c42098c8d855
gopkg.in/yaml.v2@v2.2.2
2.2.3
2
natsio/nats-box:0.11.09fbf7bf684e4
gopkg.in/yaml.v2@v2.2.2
2.2.3
2
pottava/s3-proxy:2.020a0bcb15f76
gopkg.in/yaml.v2@v2.2.2
2.2.3
2
weblate/weblate:4.2.2-169c160d37a3c
gopkg.in/yaml.v2@v2.2.1
2.2.3
2
gcr.io/k8s-staging-sig-storage/nfs-provisioner:v3.0.02de1d15fc1f2
gopkg.in/yaml.v2@v2.2.2
2.2.3
2
ghcr.io/thecatlady/webhook:2.8.0f04718704dab
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.3
2
almir/webhook:2.8.01698346f6077
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.3
1
codercom/code-server:4.11.0-debian1e2cc688008e
gopkg.in/yaml.v2@v2.2.1
2.2.3
1
codercom/code-server:3.10.247605610ad8d
gopkg.in/yaml.v2@v2.2.1
2.2.3
1
codeskyblue/gohttpserver:latestcaa862590e34
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed
1
drone/drone-runner-docker:1.8.1137e79c5e23c
gopkg.in/yaml.v2@v2.2.2
2.2.3
1
drone/kubernetes-secrets:latest206df2280ecf
gopkg.in/yaml.v2@v2.2.1
2.2.3
1
gotify/server:2.1.409c79bc1e403
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed
1
hashicorp/vault:1.8.4dfc3500beb0e
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed
1
ianw/quickchart:v1.7.1dc49dd460c37
gopkg.in/yaml.v2@v2.2.2
2.2.3
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
gopkg.in/yaml.v2@v2.2.2
2.2.3
1
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
gopkg.in/yaml.v2@v2.2.2
2.2.3
1
mirrorgitlabcontainers/gitlab-container-registry:v2.9.1-gitlab06b19a4bc805
gopkg.in/yaml.v2@v2.2.2
2.2.3
1
monitoror/monitoror:44b88edcf51ff
gopkg.in/yaml.v2@v2.2.2
2.2.3
1
oxynozeta/prometheus-cachethq:1.1.131f11669d597
github.com/go-yaml/yaml@v2.1.0+incompatible
gopkg.in/yaml.v2@v2.2.2
no fix listed
2.2.3
1
rancher/hardened-flannel:v0.13.0-rancher142784bb38ed3
gopkg.in/yaml.v2@v2.0.0-20170712054546-1be3d31502d6
2.2.3
1
softonic/preemptible-killer:1.2.6-294b87f1fb362
gopkg.in/yaml.v2@v2.2.1
2.2.3
1
weaveworks/flagger:0.19.0a9c2e9df4227
gopkg.in/yaml.v2@v2.2.2
2.2.3
1
weblate/weblate:3.11.3-182848df56ecd
gopkg.in/yaml.v2@v2.0.0-20190319135612-7b8349ac747c
2.2.3
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
gopkg.in/yaml.v2@v2.2.2
2.2.3
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
gopkg.in/yaml.v2@v2.2.2
2.2.3
1
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
gopkg.in/yaml.v2@v2.2.2
2.2.3
1
ghcr.io/ethpandaops/syncoor:master233aa9808fc7
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed
1
ghcr.io/geek-cookbook/webhook-receiver:2.8.172e7e77f8091
gopkg.in/yaml.v2@v2.0.0-20170812160011-eb3733d160e7
2.2.3
1
ghcr.io/podtato-head/entry:latestc3d9d9c98be7
github.com/go-yaml/yaml@v2.1.0+incompatible
no fix listed
1
quay.io/chriscowley/openldap_exporter:v2.1.16c308e9732e1
gopkg.in/yaml.v2@v2.2.2
2.2.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.