StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,330
of 17,787 indexed, latest versions
Container images
1,638
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,330 of 17,787 indexed charts deploy, on 1,638 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,638
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,330 by stars
ChartLatestAffected imagesRadar Score
kube-state-metricskubestar-state-metricsVerified publisher0.1.101 of 1See more

kube-state-metrics kubestar-state-metrics 0.1.10

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,575
kube-vault-controllerkube-vault-controller1.2.01 of 1See more

kube-vault-controller kube-vault-controller 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,550
kubemodkubmod0.5.22 of 2See more

kubemod kubmod 0.5.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.19.11f8154f7e80c
google.golang.org/protobuf@v1.23.0
1.33.0
kubemod/kubemod-crt:v1.3.0028347c9fa77
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

4,542
kubeservice-cosign-webhookkubservice-chartsVerified publisher1.1.15 of 5See more

kubeservice-cosign-webhook kubservice-charts 1.1.1

5 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
google.golang.org/protobuf@v1.30.0
1.33.0
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

7,087
kubeservice-cpupools-controllerkubservice-chartsVerified publisher0.1.12 of 2See more

kubeservice-cpupools-controller kubservice-charts 0.1.1

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dongjiang1989/cpusets-controller:v1.1.1dc5bd483874c
google.golang.org/protobuf@v1.30.0
1.33.0
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

3,118
kubeservice-custom-limitrangekubservice-chartsVerified publisher1.3.04 of 5See more

kubeservice-custom-limitrange kubservice-charts 1.3.0

4 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,941
kubeservice-ebpf-exporterkubservice-chartsVerified publisher1.2.11 of 1See more

kubeservice-ebpf-exporter kubservice-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/cloudflare/ebpf_exporter:v2.3.075370b2ec2bb
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

545
kubeservice-namespace-node-affinitykubservice-chartsVerified publisher1.1.25 of 5See more

kubeservice-namespace-node-affinity kubservice-charts 1.1.2

5 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dongjiang1989/ns-node-affinity:latest451f7823723c
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

6,872
kubeservice-scheduler-pluskubservice-chartsVerified publisher0.2.11 of 2See more

kubeservice-scheduler-plus kubservice-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,801
kube-fencingkvaps2.4.11 of 2See more

kube-fencing kvaps 2.4.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kube-fencing-controller:v2.4.0313edfec2fca
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

2,536
linstorkvaps1.14.02 of 11See more

linstor kvaps 1.14.0

2 of the 11 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
google.golang.org/protobuf@v1.24.0
1.33.0
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

15,547
lagoon-remotelagoon-chartsVerified publisher0.106.01 of 1See more

lagoon-remote lagoon-charts 0.106.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

2,113
lgtm-stacklgtm-stackVerified publisher0.1.32 of 8See more

lgtm-stack lgtm-stack 0.1.3

2 of the 8 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2024-01-16T16-06-34Z591b097ea2d4
google.golang.org/protobuf@v1.31.0
1.33.0
minio/minio:RELEASE.2024-01-18T22-51-28Z551682a57a94
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,576
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

4,418
linkerd-jaegerlinkerd2-edgeVerified publisher30.14.11-edge2 of 4See more

linkerd-jaeger linkerd2-edge 30.14.11-edge

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
google.golang.org/protobuf@v1.27.1
1.33.0
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

4,389
jspolicyloftVerified publisher0.2.21 of 1See more

jspolicy loft 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
loftsh/jspolicy:0.2.225deb9bd2683
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,309
vcluster-eksloftVerified publisher0.0.0-ci.31 of 4See more

vcluster-eks loft 0.0.0-ci.3

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,304
vcluster-k0sloftVerified publisher0.0.0-ci.31 of 2See more

vcluster-k0s loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

3,136
log2rbac-operatorlog2rbac-operator0.0.51 of 1See more

log2rbac-operator log2rbac-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jkremser/log2rbac:v0.0.5e35cf56ef183
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,938
logclilogcliVerified publisher0.1.01 of 1See more

logcli logcli 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/logcli:main-c90366d-amd643d85bb66e39b
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,947
voice-biometricslumenvox2.0.17 of 26See more

voice-biometrics lumenvox 2.0.1

7 of the 26 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
google.golang.org/protobuf@v1.23.0
1.33.0
library/traefik:v2.57d5a6ae66572
google.golang.org/protobuf@v1.27.1
1.33.0
lumenvox/cloud-license:2.0.09a69862e1248
google.golang.org/protobuf@v1.27.1
1.33.0
prom/pushgateway:v1.3.18305a33fb80a
google.golang.org/protobuf@v1.23.0
1.33.0
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
google.golang.org/protobuf@v1.21.0
1.33.0
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
google.golang.org/protobuf@v1.23.0
1.33.0
quay.io/prometheus/prometheus:v2.26.038d40a760569
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

70,741
goblackholemainVerified publisher0.0.41 of 1See more

goblackhole main 0.0.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bedag/goblackhole:0.2.0447a88598f4c
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,972
traefik-forward-authmesosphere0.3.101 of 2See more

traefik-forward-auth mesosphere 0.3.10

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

5,308
chartmuseummike75151.2.01 of 1See more

chartmuseum mike7515 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

3,168
miniomilvus8.0.171 of 1See more

minio milvus 8.0.17

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

6,915
maddymyaVerified publisher22.4.121 of 2See more

maddy mya 22.4.12

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
foxcpp/maddy:0.7.16ab538e2f28b
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

1,412
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.230b60b6565ab2
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

37,373
ngrok-operatorngrok-operator1.1.01 of 2See more

ngrok-operator ngrok-operator 1.1.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
zufardhiyaulhaq/ngrok-operator:v1.3.07cf2ae3fb1fb
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,896
node-exporternode-exporterVerified publisher0.1.101 of 1See more

node-exporter node-exporter 0.1.10

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
prom/node-exporter:v1.6.0d2e48098c364
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,229
oadaoadaVerified publisher5.0.51 of 11See more

oada oada 5.0.5

1 of the 11 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

13,317
transfer.shobeoneVerified publisher1.0.51 of 1See more

transfer.sh obeone 1.0.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dutchcoders/transfer.sh:v1.6.1-noroot8db9ade72a0d
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,171
opsopsVerified publisher1.2.02 of 2See more

ops ops 1.2.0

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
shaowenchen/ops-controller-manager:latest26da43bb5b66
google.golang.org/protobuf@v1.31.0
1.33.0
shaowenchen/ops-server:latest315444f703f4
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

8,939
kubernetes-dashboard-proxyosc0.7.23 of 4See more

kubernetes-dashboard-proxy osc 0.7.2

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.7.02e500d29e9d5
google.golang.org/protobuf@v1.28.0
1.33.0
kubernetesui/metrics-scraper:v1.0.876049887f07a
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

6,005
hlf-caowkin2.1.01 of 2See more

hlf-ca owkin 2.1.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

3,424
patch-operatorpatch-operator0.1.112 of 2See more

patch-operator patch-operator 0.1.11

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
google.golang.org/protobuf@v1.24.0
1.33.0
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

7,807
pdf-editor-helmpdf-editor-web1.0.02 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-backend-rotate316e203b8bf5
google.golang.org/protobuf@v1.28.1
1.33.0
dipugodocker/pdf-editor:1.0-backend-merge70b07544a604
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

4,206
spirephilips-labsVerified publisher0.12.25 of 6See more

spire philips-labs 0.12.2

5 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

7,236
chartmuseumphntom4.0.201 of 1See more

chartmuseum phntom 4.0.20

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
phntom/chartmuseum:v0.16.053883b65d9b7
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

2,939
pipelinewise-operatorpipelinewise-operatorVerified publisher0.5.11 of 1See more

pipelinewise-operator pipelinewise-operator 0.5.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,121
secrets-store-csi-driver-provider-awsportefaix-hub0.4.01 of 1See more

secrets-store-csi-driver-provider-aws portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-2021.08.13.20.34-linux-amd6402aed3370fce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,206
postgres-backuppostgres-backup0.3.01 of 2See more

postgres-backup postgres-backup 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
nerzhul/mc-arm64:2020.10.034215df511f31
google.golang.org/protobuf@v1.22.0
1.33.0

Open the chart page →

5,462
prometheusprometheus-worawutchan13.0.05 of 6See more

prometheus prometheus-worawutchan 13.0.0

5 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
google.golang.org/protobuf@v1.23.0
1.33.0
prom/pushgateway:v1.3.0c0d39b8d4cfe
google.golang.org/protobuf@v1.23.0
1.33.0
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
google.golang.org/protobuf@v1.21.0
1.33.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
google.golang.org/protobuf@v1.22.0
1.33.0
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

9,939
operatorpunchplatform8.1.131 of 1See more

operator punchplatform 8.1.13

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/operator:8.1-dev2a9536c8cee2
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

718
kubernetes-dashboardpyalive-cdmswebappVerified publisher5.8.01 of 1See more

kubernetes-dashboard pyalive-cdmswebapp 5.8.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.6.1290bebc3cd96
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,662
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

6,796
velero-s3-deploymentradar-baseVerified publisher0.4.22 of 4See more

velero-s3-deployment radar-base 0.4.2

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
velero/velero:v1.9.0277fbfaf8dcf
google.golang.org/protobuf@v1.26.0
1.33.0
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

4,798
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

7,432
backup-repository-serverriotkit-org4.0.01 of 1See more

backup-repository-server riotkit-org 4.0.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

2,049
cloudflare-tunnelrlex0.8.01 of 1See more

cloudflare-tunnel rlex 0.8.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2023.10.0c18744ae1767
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,684
grafanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

grafana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:8.3.4cf81d2c753c8
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,835

Container images carrying it

1,638 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
ethpandaops/dugtrio:1.0.0e261d1734e9f
google.golang.org/protobuf@v1.31.0
1.33.0
1
ethpandaops/ethereum-metrics-exporter:0.21.0d1780db2e286
google.golang.org/protobuf@v1.28.1
1.33.0
1
ethpandaops/ethereum-validator-metrics-exporter:latest38448e9d4aef
google.golang.org/protobuf@v1.30.0
1.33.0
1
ethpandaops/stubbies:latest9f1d6aec0d04
google.golang.org/protobuf@v1.28.1
1.33.0
1
everpcpc/channels:latestb378d137ae8b
google.golang.org/protobuf@v1.26.0
1.33.0
1
expediagroup/kubernetes-sidecar-injector:1.0.1193a00ec8dd4
google.golang.org/protobuf@v1.27.1
1.33.0
1
factly/dega-api:0.15.166fafc7b0a17
google.golang.org/protobuf@v1.26.0
1.33.0
1
factly/dega-server:0.15.194d21479382e
google.golang.org/protobuf@v1.26.0
1.33.0
1
factly/kavach-server:0.22.3be85ff1b9bd3
google.golang.org/protobuf@v1.26.0
1.33.0
1
factly/mande-server:0.34.1384d384310ef
google.golang.org/protobuf@v1.28.1
1.33.0
1
falcosecurity/falcosidekick:2.27.0828ee36cb13a
google.golang.org/protobuf@v1.28.1
1.33.0
1
fission/fission-bundle:1.14.13fcfd8a0fa5d
google.golang.org/protobuf@v1.26.0
1.33.0
1
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
google.golang.org/protobuf@v1.26.0
1.33.0
1
flanksource/apm-hub:v0.0.471dacc3195bf9
google.golang.org/protobuf@v1.30.0
1.33.0
1
flanksource/batch-runner:v1.0.44689687a7cf95
google.golang.org/protobuf@v1.28.0
1.33.0
1
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
google.golang.org/protobuf@v1.27.1
1.33.0
1
flomesh/fsm-ingress-pipy:0.2.11cc39c96711c4
google.golang.org/protobuf@v1.30.0
1.33.0
1
flomesh/fsm-manager:0.2.1122f849c70b25
google.golang.org/protobuf@v1.30.0
1.33.0
1
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
google.golang.org/protobuf@v1.28.1
1.33.0
1
flomesh/osm-edge-controller:1.3.9add7a4da4622
google.golang.org/protobuf@v1.28.1
1.33.0
1
flomesh/osm-edge-injector:1.3.947287e3ad324
google.golang.org/protobuf@v1.28.1
1.33.0
1
flomesh/osm-edge-preinstall:1.3.9bd224d55ed0f
google.golang.org/protobuf@v1.28.1
1.33.0
1
fluxcd/helm-controller:v0.9.092b891e495d8
google.golang.org/protobuf@v1.25.0
1.33.0
1
fluxcd/source-controller:v0.10.031a8c79a6803
google.golang.org/protobuf@v1.25.0
1.33.0
1
fluxninja/aperture-operator:2.34.0356d7aa86632
google.golang.org/protobuf@v1.32.0
1.33.0
1
foomo/csp-reporter:1.3.0e436da524785
google.golang.org/protobuf@v1.26.0
1.33.0
1
foxcpp/maddy:0.7.16ab538e2f28b
google.golang.org/protobuf@v1.32.0
1.33.0
1
foxcpp/maddy:v0.5.28fa2bd8f6830
google.golang.org/protobuf@v1.27.1
1.33.0
1
galaxy/cloudman-server:lateste5c265fe9fcd
google.golang.org/protobuf@v1.27.1
1.33.0
1
garugaru/presto-exporter:cb666560e9e82d5ae36aef1e663c3d7f51cca9fc5201314c28f3
google.golang.org/protobuf@v1.24.0
1.33.0
1
gboxproxy/gbox:v1.0.63a9f4a711d5c
google.golang.org/protobuf@v1.28.0
1.33.0
1
gitea/gitea:1.12.485416d6f65fe
google.golang.org/protobuf@v1.22.0
1.33.0
1
gitea/gitea:1.21.6ac73e0da341f
google.golang.org/protobuf@v1.31.0
1.33.0
1
gitea/gitea:1.13.0d5ab14cd29af
google.golang.org/protobuf@v1.25.0
1.33.0
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
google.golang.org/protobuf@v1.27.1
1.33.0
1
gkarthics/container-resource-exporter:latest6799af333e8a
google.golang.org/protobuf@v1.23.0
1.33.0
1
goalert/goalert:v0.32.008d57388b0cb
google.golang.org/protobuf@v1.32.0
1.33.0
1
gocrane/craned:v0.5.1a1400909118c
google.golang.org/protobuf@v1.27.1
1.33.0
1
gocrane/crane-scheduler:0.0.239ba6d11b2079
google.golang.org/protobuf@v1.27.1
1.33.0
1
gocrane/crane-scheduler-controller:0.1.23a2d7e60576f9
google.golang.org/protobuf@v1.27.1
1.33.0
1
gogs/gogs:0.12.30195b095d0b2
google.golang.org/protobuf@v1.21.0
1.33.0
1
gogs/gogs:0.12.1420d53bb7277
google.golang.org/protobuf@v1.21.0
1.33.0
1
goharbor/chartmuseum-photon:v2.5.36ab3ca28e9e5
google.golang.org/protobuf@v1.27.1
1.33.0
1
goharbor/harbor-acceld:0.2.13451103a6c8d8
google.golang.org/protobuf@v1.31.0
1.33.0
1
goharbor/harbor-core:v2.9.06412d679fdc3
google.golang.org/protobuf@v1.28.1
1.33.0
1
goharbor/harbor-core:v2.5.386bf3031f4a7
google.golang.org/protobuf@v1.27.1
1.33.0
1
goharbor/harbor-jobservice:v2.9.039435daedd0c
google.golang.org/protobuf@v1.28.1
1.33.0
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
google.golang.org/protobuf@v1.27.1
1.33.0
1
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
google.golang.org/protobuf@v1.27.1
1.33.0
1
goharbor/harbor-registryctl:v2.9.0cce272836449
google.golang.org/protobuf@v1.28.1
1.33.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.