StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,342
of 17,790 indexed, latest versions
Container images
1,661
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,342 of 17,790 indexed charts deploy, on 1,661 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,661
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,342 by stars
ChartLatestAffected imagesRadar Score
kafka-operatormesosphere-stable0.25.11 of 2See more

kafka-operator mesosphere-stable 0.25.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,241
karmamesosphere-stable2.0.31 of 1See more

karma mesosphere-stable 2.0.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
lmierzwa/karma:v0.70d417abe7ddb5
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

1,966
knativemesosphere-stable1.10.87 of 7See more

knative mesosphere-stable 1.10.8

7 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.10.2c2994c2b6c2c
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.10.28319aa662b49
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpa:v1.10.2eb612b929eaa
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.10.2f66c41ad7a73
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.10.27368aaddf2be
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.10.24305209ce498
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

7,479
kommandermesosphere-stable0.39.215 of 29See more

kommander mesosphere-stable 0.39.2

15 of the 29 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
google.golang.org/protobuf@v1.23.0
1.33.0
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
google.golang.org/protobuf@v1.24.0
1.33.0
prom/prometheus:v2.19.2cd134bd4fca0
google.golang.org/protobuf@v1.24.0
1.33.0
thanosio/thanos:v0.19.088276fcd1491
google.golang.org/protobuf@v1.25.0
1.33.0
thanosio/thanos:v0.15.0b12d5c31bf5a
google.golang.org/protobuf@v1.24.0
1.33.0
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
google.golang.org/protobuf@v1.21.0
1.33.0
quay.io/thanos/thanos:v0.17.1e362f02ed304
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

68,330
kube-prometheus-stackmesosphere-stable75.9.11 of 7See more

kube-prometheus-stack mesosphere-stable 75.9.1

1 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

9,543
veleromesosphere-stable3.2.51 of 1See more

velero mesosphere-stable 3.2.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,871
cortexmetakube0.6.01 of 2See more

cortex metakube 0.6.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

4,107
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

8,940
wg-access-servermglants0.4.71 of 1See more

wg-access-server mglants 0.4.7

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,745
gogsmhio0.9.21 of 2See more

gogs mhio 0.9.2

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
gogs/gogs:0.12.1420d53bb7277
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

3,230
kube-agent-chartmiddleware-labsVerified publisher0.1.21 of 1See more

kube-agent-chart middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,799
middleware-odigosmiddleware-labsVerified publisher0.2.414 of 6See more

middleware-odigos middleware-labs 0.2.41

4 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
google.golang.org/protobuf@v1.27.1
1.33.0
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
google.golang.org/protobuf@v1.27.1
1.33.0
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

8,370
middleware-visionmiddleware-labsVerified publisher0.2.654 of 6See more

middleware-vision middleware-labs 0.2.65

4 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
google.golang.org/protobuf@v1.27.1
1.33.0
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
google.golang.org/protobuf@v1.27.1
1.33.0
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

8,361
mw-kube-agentmiddleware-labsVerified publisher0.1.21 of 1See more

mw-kube-agent middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,594
mimirmimir0.1.101 of 1See more

mimir mimir 0.1.10

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/heimops/mimir-operator:latest4e1a3ef1fe82
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

382
minio-operatorminio-operator4.3.71 of 2See more

minio-operator minio-operator 4.3.7

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

6,085
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

10,639
standard-application-stackmintel11.4.11 of 12See more

standard-application-stack mintel 11.4.1

1 of the 12 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

10,515
jupyterhubmizzoukube0.0.1-set.by.chartpress1 of 7See more

jupyterhub mizzoukube 0.0.1-set.by.chartpress

1 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,883
cert-manager-webhook-duckdnsmmontesVerified publisher1.2.31 of 1See more

cert-manager-webhook-duckdns mmontes 1.2.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

2,847
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

7,775
echoperatormmontesVerified publisher0.0.21 of 1See more

echoperator mmontes 0.0.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

1,826
corednsmoikot1.13.31 of 1See more

coredns moikot 1.13.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
coredns/coredns:1.7.073ca82b4ce82
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

2,547
smartthings-metricsmoikot0.1.01 of 1See more

smartthings-metrics moikot 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:0.1.08625f53aa9b7
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

1,744
smartthings-metrics-feat-log-detailsmoikot0.0.921 of 1See more

smartthings-metrics-feat-log-details moikot 0.0.92

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:feat-log-detailsfb8565140106
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

1,732
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

2,470
backendmojaloop0.1.02 of 6See more

backend mojaloop 0.1.0

2 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
google.golang.org/protobuf@v1.27.1
1.33.0
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

16,111
mongodb-query-exportermongodb-query-exporterVerified publisher5.1.01 of 1See more

mongodb-query-exporter mongodb-query-exporter 5.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/raffis/mongodb-query-exporter:v5.1.0ca6ac8a5b329
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

989
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

10,998
backupmorremeyer4.0.01 of 1See more

backup morremeyer 4.0.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
restic/restic:0.15.2579e4e6a4931
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

2,295
hcloud-ccm-networksmorremeyer2.0.01 of 1See more

hcloud-ccm-networks morremeyer 2.0.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,739
hcloud-csi-drivermorremeyer3.0.06 of 6See more

hcloud-csi-driver morremeyer 3.0.0

6 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

7,145
chirpstackmosquitto-helm-chart0.5.03 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

3 of the 8 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3fb7667fe037f
google.golang.org/protobuf@v1.28.1
1.33.0
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
google.golang.org/protobuf@v1.28.1
1.33.0
oliver006/redis_exporter:v1.14.0d55e056987af
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

25,989
chirpstack-event-forwardmosquitto-helm-chart0.1.21 of 1See more

chirpstack-event-forward mosquitto-helm-chart 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,854
replacermosquitto-helm-chart0.2.01 of 3See more

replacer mosquitto-helm-chart 0.2.0

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,931
configmapsecretsmozilla0.0.11 of 1See more

configmapsecrets mozilla 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,109
approuvezmvisonneau0.1.11 of 1See more

approuvez mvisonneau 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

1,971
unpollermvisonneau0.1.01 of 1See more

unpoller mvisonneau 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
golift/unifi-poller:v2.9.2585a29a06d05
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,190
cognativemyaVerified publisher0.2403.32 of 3See more

cognative mya 0.2403.3

2 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:10.4.0f9811e4e687f
google.golang.org/protobuf@v1.32.0
1.33.0
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

7,348
giteamyaVerified publisher23.12.51 of 1See more

gitea mya 23.12.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
gitea/gitea:1.21.6ac73e0da341f
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

3,429
redismyaVerified publisher22.4.101 of 2See more

redis mya 22.4.10

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,050
redis-queuemyaVerified publisher22.4.61 of 2See more

redis-queue mya 22.4.6

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,050
redis-raftmyaVerified publisher22.5.41 of 2See more

redis-raft mya 22.5.4

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,050
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,359
fargate-sidecar-injectormziyaboVerified publisher0.1.51 of 1See more

fargate-sidecar-injector mziyabo 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mziyabo/fargate-eks-sidecar-injector:latest3067dce17983
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,393
nats-kafkanatsVerified publisher0.15.41 of 1See more

nats-kafka nats 0.15.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
natsio/nats-kafka:1.4.2bb241956b0dc
google.golang.org/protobuf@v1.25.1-0.20200805231151-a709e31e5d12
1.33.0

Open the chart page →

1,731
nats-operatornatsVerified publisher0.8.31 of 1See more

nats-operator nats 0.8.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
natsio/nats-operator:0.8.31261dae38389
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,353
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

6,982
webspacednetsocVerified publisher0.2.82 of 2See more

webspaced netsoc 0.2.8

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
google.golang.org/protobuf@v1.26.0
1.33.0
ghcr.io/netsoc/webspaced:0.5.1edc238a538a0
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,193
node-upgrade-channelnimbolus0.1.11 of 1See more

node-upgrade-channel nimbolus 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/nimbolus/k8s-openstack-node-upgrade-agent:0.1.0e0c7cf2415f0
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,062

Container images carrying it

1,661 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
google.golang.org/protobuf@v1.28.0
1.33.0
1
gutmensch/podnat-controller:0.5.2566979793fc4
google.golang.org/protobuf@v1.28.1
1.33.0
1
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
google.golang.org/protobuf@v1.32.0
1.33.0
1
hashicorp/boundary:0.8.1fb70bd9210ff
google.golang.org/protobuf@v1.27.1
1.33.0
1
hashicorp/consul:1.17.0712fe02d2f84
google.golang.org/protobuf@v1.30.0
1.33.0
1
hashicorp/consul:1.15.3ddff34041c5c
google.golang.org/protobuf@v1.28.1
1.33.0
1
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
google.golang.org/protobuf@v1.30.0
1.33.0
1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
google.golang.org/protobuf@v1.28.1
1.33.0
1
hashicorp/terraform:1.44dcb45513699
google.golang.org/protobuf@v1.28.1
1.33.0
1
hashicorp/terraform-k8s:1.1.2b19857bab620
google.golang.org/protobuf@v1.26.0
1.33.0
1
hashicorp/vault:1.15.40b01ed3924e6
google.golang.org/protobuf@v1.31.0
1.33.0
1
hashicorp/vault:1.14.0b2177a8bfe85
google.golang.org/protobuf@v1.30.0
1.33.0
1
hashicorp/vault:1.8.4dfc3500beb0e
google.golang.org/protobuf@v1.25.0
1.33.0
1
hashicorp/vault-k8s:1.2.14500e988b7ce
google.golang.org/protobuf@v1.28.1
1.33.0
1
hashicorp/vault-k8s:0.6.05697b85bc69a
google.golang.org/protobuf@v1.23.0
1.33.0
1
hashicorp/vault-k8s:0.14.0aff47b5ba39c
google.golang.org/protobuf@v1.26.0
1.33.0
1
hashicorp/waypoint:0.11.397d521a27498
google.golang.org/protobuf@v1.28.1
1.33.0
1
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
google.golang.org/protobuf@v1.24.0
1.33.0
1
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
google.golang.org/protobuf@v1.30.0
1.33.0
1
hetznercloud/hcloud-cloud-controller-manager:v1.13.0ed5ee5f83973
google.golang.org/protobuf@v1.28.1
1.33.0
1
hetznercloud/hcloud-csi-driver:1.6.01475d525f9a4
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
hetznercloud/hcloud-csi-driver:1.5.141dce5b33644
google.golang.org/protobuf@v1.25.0
1.33.0
1
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
google.golang.org/protobuf@v1.28.1
1.33.0
1
hibiken/asynqmon:latestac80bcffd2f9
google.golang.org/protobuf@v1.30.0
1.33.0
1
hipages/php-fpm_exporter:2.2.09b5be9d3d955
google.golang.org/protobuf@v1.28.0
1.33.0
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
google.golang.org/protobuf@v1.27.1
1.33.0
1
holiman/nodemonitor:latest5cd609761065
google.golang.org/protobuf@v1.28.1
1.33.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
google.golang.org/protobuf@v1.31.0
1.33.0
1
huacnlee/gobackup:v3.1.1560be93229a5
google.golang.org/protobuf@v1.31.0
1.33.0
1
huangchengwu6904/hi-app:cac-16910478061b932f8221a9
google.golang.org/protobuf@v1.28.1
1.33.0
1
huseyinbabal/demory:0.0.0-rc.20ae8eb4053c60
google.golang.org/protobuf@v1.27.1
1.33.0
1
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
google.golang.org/protobuf@v1.23.0
1.33.0
1
hyperledger/fabric-ca:1.5.0f270dfeee91d
google.golang.org/protobuf@v1.23.0
1.33.0
1
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
google.golang.org/protobuf@v1.28.1
1.33.0
1
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
google.golang.org/protobuf@v1.28.1
1.33.0
1
hyperledgerk8s/fabric-operator:7776e7129a8af8be270
google.golang.org/protobuf@v1.27.1
1.33.0
1
hyperledgerk8s/minio-mc:RELEASE.2023-01-28T20-29-38Z729b3d128487
google.golang.org/protobuf@v1.28.1
1.33.0
1
hyperledgerk8s/minio-minio:RELEASE.2023-02-10T18-48-39Zed0b0c56f1ea
google.golang.org/protobuf@v1.28.1
1.33.0
1
hyperledgerk8s/tektoncd-operator:v0.64.0d0a3a35a138d
google.golang.org/protobuf@v1.28.1
1.33.0
1
hyperledgerk8s/tekton-operator-webhook:v0.64.02237cb80f52b
google.golang.org/protobuf@v1.28.1
1.33.0
1
inaccel/cloud-init:latesta5d3d0af05c1
google.golang.org/protobuf@v1.32.0
1.33.0
1
inaccel/device-selector:latest44b4f274f40b
google.golang.org/protobuf@v1.31.0
1.33.0
1
inaccel/kubevirt-hack:latestbdfd61803a70
google.golang.org/protobuf@v1.32.0
1.33.0
1
inseefrlab/shelly:cloudshell31f04ca7436b
google.golang.org/protobuf@v1.25.0
1.33.0
1
intel/intel-gpu-plugin:0.20.0143f0a45e174
google.golang.org/protobuf@v1.25.0
1.33.0
1
intel/multimodal-data-visualization:3.03426deb77337
google.golang.org/protobuf@v1.27.1
1.33.0
1
intel/trusted-certificate-issuer:0.5.0591a9db4a427
google.golang.org/protobuf@v1.28.1
1.33.0
1
invisibl/gravity-init:v1.0.91a970f84178b
google.golang.org/protobuf@v1.27.1
1.33.0
1
invisibl/identity-manager:1.0.01029f4fe20eb
google.golang.org/protobuf@v1.27.1
1.33.0
1
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
google.golang.org/protobuf@v1.28.1
1.33.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.