CVE-2023-24535
HighAdvisory
Published 14 Mar 2023In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.011
- 63rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 6
- of 17,781 indexed, latest versions
- Container images
- 5
- deployed by those charts
- Fix available
- 1 of 1
- affected package
google.golang.org/protobuf vulnerable to panic leading to denial of service
Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 5 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| google.golang.org/ | v1.29.0 | 1.29.1 | 5 |
- OSV records
- GHSA-hw7c-3rfg-p46j
- Also known as
- GO-2023-1631
Charts affected
6 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| sn-platformstreamnative | 1.11.44 | 1 of 9See more | 15,477 |
| agentkube-operatoragentkube-operator | 0.3.0 | 1 of 1See more | 1,716 |
| sn-platform-slimstreamnative | 1.11.44 | 1 of 6See more | 10,134 |
| passportxdVerified publisher | 0.2.16 | 2 of 2See more | 3,974 |
| tabbyxdVerified publisher | 1.0.6 | 1 of 2See more | 7,673 |
| treexdVerified publisher | 0.1.10 | 1 of 1See more | 1,997 |
Container images carrying it
5 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | f5c29683a301 | google.golang.org/ | 1.29.1 | 3 |
| lishimeng/ | 3e7d05ded625 | google.golang.org/ | 1.29.1 | 1 |
| lishimeng/ | 0970dfe5dc8f | google.golang.org/ | 1.29.1 | 1 |
| lishimeng/ | 8145c3dc83c8 | google.golang.org/ | 1.29.1 | 1 |
| lishimeng/ | 9b2f8be6c7d3 | google.golang.org/ | 1.29.1 | 1 |