StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,344
of 17,787 indexed, latest versions
Container images
1,663
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,344 of 17,787 indexed charts deploy, on 1,663 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,663
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,344 by stars
ChartLatestAffected imagesRadar Score
electric-mailcryptexlabsVerified publisher0.0.12 of 5See more

electric-mail cryptexlabs 0.0.1

2 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/protobuf@v1.25.0
1.33.0
hashicorp/vault-k8s:0.13.1bebb03e8e800
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,973
purple-piecryptexlabsVerified publisher0.0.12 of 4See more

purple-pie cryptexlabs 0.0.1

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.34db614d40d0e
google.golang.org/protobuf@v1.25.0
1.33.0
hashicorp/vault-k8s:0.13.1bebb03e8e800
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,973
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

14,206
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

13,937
secrets-store-csi-driver-provider-awscustom0.2.01 of 1See more

secrets-store-csi-driver-provider-aws custom 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,232
irods-csi-drivercyverse0.12.03 of 4See more

irods-csi-driver cyverse 0.12.0

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
google.golang.org/protobuf@v1.31.0
1.33.0
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,257
domain-exporterd0main-exp0rter0.1.01 of 1See more

domain-exporter d0main-exp0rter 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,832
speedtest-exporterdamounVerified publisher1.0.61 of 1See more

speedtest-exporter damoun 1.0.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,209
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,238
adot-exporter-for-eks-on-ec2dasmeta-adot0.15.51 of 1See more

adot-exporter-for-eks-on-ec2 dasmeta-adot 0.15.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,926
datadog-csi-driverdatadogVerified publisher0.17.01 of 2See more

datadog-csi-driver datadog 0.17.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

2,041
agent-helmdatasaker0.1.85 of 6See more

agent-helm datasaker 0.1.8

5 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
datasaker/dsk-container-agent:latest08b52999f67b
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-k8s-agent:latest2542ee73be51
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-node-agent:latest1b95913b6729
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-process-agent:latest2f38720a637d
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

7,571
ambassador-agentdatawire1.0.221 of 1See more

ambassador-agent datawire 1.0.22

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ambassador/ambassador-agent:1.0.227a1ea0d934fb
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

958
eg-edge-stackdatawire0.0.14 of 7See more

eg-edge-stack datawire 0.0.1

4 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ambassador/aes-authsvc:v4.0.0-preview.12a4598b03a6a
google.golang.org/protobuf@v1.31.0
1.33.0
ambassador/aes-eg-ext:v4.0.0-preview.1b7eb1be3345d
google.golang.org/protobuf@v1.31.0
1.33.0
ambassador/aes-wafsvc:v4.0.0-preview.15fc571509b8c
google.golang.org/protobuf@v1.31.0
1.33.0
envoyproxy/gateway:v0.5.02a9f99d28567
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

15,781
eg-edge-stack-crdsdatawire0.0.11 of 2See more

eg-edge-stack-crds datawire 0.0.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,404
ddns-kubernetes-controllerddns-kubernetes-controller0.1.01 of 1See more

ddns-kubernetes-controller ddns-kubernetes-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

970
kube-better-nodedecayofmind0.0.41 of 1See more

kube-better-node decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

1,583
aws-service-events-exporterdeliveryheroVerified publisher1.0.71 of 1See more

aws-service-events-exporter deliveryhero 1.0.7

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
thomasnyambati/aws-service-events-exporter:1.0.01e18a0944ceb
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

1,299
aws-service-quotas-exporterdeliveryheroVerified publisher0.1.41 of 1See more

aws-service-quotas-exporter deliveryhero 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
thoughtmachine/aws-service-quotas-exporter:v1.3.2c6065ba55c72
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

771
cortex-gatewaydeliveryheroVerified publisher0.1.91 of 1See more

cortex-gateway deliveryhero 0.1.9

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

2,234
prometheus-soti-mobicontrol-exporterdeliveryheroVerified publisher1.0.31 of 1See more

prometheus-soti-mobicontrol-exporter deliveryhero 1.0.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

1,644
prometheus-statsd-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-statsd-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.18.0d23aca343b86
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

1,315
toxiproxydeliveryheroVerified publisher1.3.91 of 2See more

toxiproxy deliveryhero 1.3.9

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/shopify/toxiproxy:2.7.0fc2d40f4904c
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

598
kubeteach-coredergeberl0.2.31 of 1See more

kubeteach-core dergeberl 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,504
kubeteach-exerciseset1dergeberl0.2.31 of 2See more

kubeteach-exerciseset1 dergeberl 0.2.3

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,504
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
google.golang.org/protobuf@v1.28.0
1.33.0
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

4,722
pushproxdevopstalesVerified publisher0.1.62 of 2See more

pushprox devopstales 0.1.6

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
google.golang.org/protobuf@v1.23.0
1.33.0
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

3,754
lxd8sdevplayer0Verified publisher0.5.11 of 2See more

lxd8s devplayer0 0.5.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,431
argocddevtron1.8.11 of 3See more

argocd devtron 1.8.1

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,468
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

12,999
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

1,580
calertdevtron0.0.11 of 1See more

calert devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

4,688
devtron-enterprisedevtron48.0.09 of 28See more

devtron-enterprise devtron 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/nats-box:latest48cdd3054b20
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

66,542
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

5,041
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

4,969
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

11,957
jcmhproxy-ingressdevtron0.14.61 of 1See more

jcmhproxy-ingress devtron 0.14.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,379
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/protobuf@v1.26.0
1.33.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

8,645
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,435
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,176
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,507
argocddevtron-labs1.8.11 of 3See more

argocd devtron-labs 1.8.1

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,468
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

12,999
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

1,580
calertdevtron-labs0.0.11 of 1See more

calert devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

4,688
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,073
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.09 of 28See more

devtron-enterprise devtron-labs 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/nats-box:latest48cdd3054b20
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

66,542
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

5,041
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

4,969

Container images carrying it

1,663 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
moby/buildkit:v0.10.0c2aeafaed434
google.golang.org/protobuf@v1.26.0
1.33.0
1
moikot/smartthings-metrics:0.1.08625f53aa9b7
google.golang.org/protobuf@v1.23.0
1.33.0
1
moikot/smartthings-metrics:feat-log-detailsfb8565140106
google.golang.org/protobuf@v1.23.0
1.33.0
1
mpioperator/mpi-operator:0.3.03ccfa8d8b7bf
google.golang.org/protobuf@v1.24.0
1.33.0
1
murtazashah46/helmfile:latest4d11726cf803
google.golang.org/protobuf@v1.28.1
1.33.0
1
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
google.golang.org/protobuf@v1.25.0
1.33.0
1
mziyabo/fargate-eks-sidecar-injector:latest3067dce17983
google.golang.org/protobuf@v1.28.1
1.33.0
1
natsio/nats-box:0.13.559cf2e949181
google.golang.org/protobuf@v1.28.1
1.33.0
1
natsio/nats-box:0.13.3c507bd7e3831
google.golang.org/protobuf@v1.28.1
1.33.0
1
natsio/nats-box:0.14.2e808e0644ce1
google.golang.org/protobuf@v1.31.0
1.33.0
1
natsio/nats-kafka:1.4.2bb241956b0dc
google.golang.org/protobuf@v1.25.1-0.20200805231151-a709e31e5d12
1.33.0
1
natsio/nats-operator:0.8.31261dae38389
google.golang.org/protobuf@v1.26.0
1.33.0
1
natsio/prometheus-nats-exporter:0.13.02adf791d9f9f
google.golang.org/protobuf@v1.30.0
1.33.0
1
natsio/prometheus-nats-exporter:0.10.1bce728062c4f
google.golang.org/protobuf@v1.28.1
1.33.0
1
neosu/kubebadges:v0.0.5256530d8e5c6
google.golang.org/protobuf@v1.31.0
1.33.0
1
nerzhul/mc-arm64:2020.10.034215df511f31
google.golang.org/protobuf@v1.22.0
1.33.0
1
netapp/trident-operator:21.10.049cfe552d9c2
google.golang.org/protobuf@v1.26.0
1.33.0
1
netrisai/controller-grpc:4.6.0.00753178bf173c2
google.golang.org/protobuf@v1.30.0
1.33.0
1
netrisai/netris-operator:v4.0.244f60aa0d898
google.golang.org/protobuf@v1.26.0
1.33.0
1
nginx/nginx-ingress:1.11.1eb5b4fd73325
google.golang.org/protobuf@v1.25.0
1.33.0
1
nineinfra/hdfs-operator:v0.7.0debb1e3410e2
google.golang.org/protobuf@v1.30.0
1.33.0
1
nineinfra/kyuubi-operator:v0.7.08d8ed87ef77c
google.golang.org/protobuf@v1.30.0
1.33.0
1
nineinfra/metastore-operator:v0.7.011259032fb04
google.golang.org/protobuf@v1.30.0
1.33.0
1
nineinfra/nineinfra:v0.7.0d4aad414eccd
google.golang.org/protobuf@v1.31.0
1.33.0
1
nineinfra/zookeeper-operator:v0.7.0af6eb2f37bfc
google.golang.org/protobuf@v1.30.0
1.33.0
1
nocodb/nocodb:0.258.06779a4ddedf2
google.golang.org/protobuf@v1.31.0
1.33.0
1
nocodb/nocodb:0.100.2b0b91ec2a2dd
google.golang.org/protobuf@v1.28.1
1.33.0
1
nocodb/nocodb:0.84.15f9b799933aa8
google.golang.org/protobuf@v1.27.1
1.33.0
1
ntakashi/cole:1.2.3f7b68bee2a68
google.golang.org/protobuf@v1.30.0
1.33.0
1
ntakashi/gitana:1.4.04171ec641120
google.golang.org/protobuf@v1.27.1
1.33.0
1
nvidia/dcgm-exporter:2.2.9-2.4.1-ubuntu20.0491b20b66d1cd
google.golang.org/protobuf@v1.25.0
1.33.0
1
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
google.golang.org/protobuf@v1.27.1
1.33.0
1
ofekmeister/csi-gcs:v0.9.030d70fa9211b
google.golang.org/protobuf@v1.28.0
1.33.0
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
google.golang.org/protobuf@v1.30.0
1.33.0
1
okteto/civo-webhook:0.5.357cd51176538
google.golang.org/protobuf@v1.31.0
1.33.0
1
oliver006/redis_exporter:v1.11.104d958d209ab
google.golang.org/protobuf@v1.23.0
1.33.0
1
oliver006/redis_exporter:v1.14.0d55e056987af
google.golang.org/protobuf@v1.23.0
1.33.0
1
ondrejsika/counter:latestd95eaeee2172
google.golang.org/protobuf@v1.31.0
1.33.0
1
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
google.golang.org/protobuf@v1.25.0
1.33.0
1
openebs/provisioner-nfs:0.11.04f41dd782761
google.golang.org/protobuf@v1.25.0
1.33.0
1
openenergyprojects/modbus_exporter:20230617_a14455158990f24fb25
google.golang.org/protobuf@v1.28.1
1.33.0
1
openkruise/kruise-rollout:v0.6.2a75e6739ea7d
google.golang.org/protobuf@v1.28.1
1.33.0
1
openkruise/kruise-state-metrics:v0.2.0a8108f771287
google.golang.org/protobuf@v1.28.1
1.33.0
1
openpolicyagent/opa:0.53.16a58dea59933
google.golang.org/protobuf@v1.30.0
1.33.0
1
opsgenie/kubernetes-event-exporter:0.9ecb246e4d260
google.golang.org/protobuf@v1.25.0
1.33.0
1
optimizely/agent:4.0.09d0096cabd63
google.golang.org/protobuf@v1.31.0
1.33.0
1
oryd/kratos:v1.1.08f15006a080d
google.golang.org/protobuf@v1.31.0
1.33.0
1
otel/opentelemetry-collector:0.59.0ee9da0b08d83
google.golang.org/protobuf@v1.28.1
1.33.0
1
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
google.golang.org/protobuf@v1.31.0
1.33.0
1
otel/opentelemetry-collector-contrib:0.89.0995f17004231
google.golang.org/protobuf@v1.31.0
1.33.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.