StackRadar

CVE-2023-47108

High

Advisory

Published 12 Nov 2023In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.016
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
59
of 17,781 indexed, latest versions
Container images
55
deployed by those charts
Fix available
1 of 1
affected package

otelgrpc DoS vulnerability due to unbound cardinality metrics

Carried by container images the latest versions of 59 of 17,781 indexed charts deploy, on 55 images.

Affected packageAffected versionsFixed inImages
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpcgolangv0.37.0, v0.38.0, v0.39.0, v0.40.0+7 more0.46.055
OSV records
GHSA-8pgv-569h-w5rw
Also known as
GO-2023-2331

Charts affected

59 by stars
ChartLatestAffected imagesRadar Score
parcaparca-chart0.1.01 of 1See more

parca parca-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-47108.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.44.0
0.46.0

Open the chart page →

1,978
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2023-47108.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.40.0
0.46.0

Open the chart page →

10,134
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2023-47108.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.40.0
0.46.0

Open the chart page →

10,902
agentssynapse0.1.303 of 9See more

agents synapse 0.1.30

3 of the 9 container images this version deploys carry CVE-2023-47108.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.42.07d32a4eddec7
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.37.0
0.46.0
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.40.0
0.46.0
ghcr.io/synapsecns/sanguine/scribe:6e3887fc2a05aff0d159453cedbfbe5024b910bf5e0a3dfa9f96
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.40.0
0.46.0

Open the chart page →

7,244
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2023-47108.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.40.0
0.46.0

Open the chart page →

1,815
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-47108.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.40.0
0.46.0

Open the chart page →

4,212
temporaltemporal0.28.92 of 13See more

temporal temporal 0.28.9

2 of the 13 container images this version deploys carry CVE-2023-47108.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.42.0
0.46.0
temporalio/server:1.22.0ddeebf8bad8f
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.42.0
0.46.0

Open the chart page →

21,005
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2023-47108.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.0cd21e19cd8bb
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.41.0
0.46.0

Open the chart page →

9,117
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2023-47108.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.42.1-0.20230612162650-64be7e574a17
0.46.0

Open the chart page →

2,022

Container images carrying it

55 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/kubebuilder/kube-rbac-proxy:v0.16.0771a9a173e03
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.42.0
0.46.0
1
registry.k8s.io/sig-storage/csi-attacher:v4.5.19dcd469f02bb
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.44.0
0.46.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.41.0
0.46.0
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.0cd21e19cd8bb
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.41.0
0.46.0
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc@v0.44.0
0.46.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.