StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,330
of 17,781 indexed, latest versions
Container images
1,638
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,330 of 17,781 indexed charts deploy, on 1,638 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,638
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,330 by stars
ChartLatestAffected imagesRadar Score
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

14,546
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

13,874
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,030
error-pagesgeek-cookbookVerified publisher1.2.21 of 1See more

error-pages geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,110
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

7,579
smarter-device-managergeek-cookbookVerified publisher6.5.21 of 1See more

smarter-device-manager geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,330
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

3,371
syncthinggeek-cookbookVerified publisher3.5.21 of 1See more

syncthing geek-cookbook 3.5.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
syncthing/syncthing:1.18.2966433161272
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,610
health-exporterhealth-exporterVerified publisher0.3.41 of 1See more

health-exporter health-exporter 0.3.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,558
frpc-ingressinfinity-server0.4.11 of 1See more

frpc-ingress infinity-server 0.4.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
springhack/frpc_ingress:latest4aceb821da88
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,622
coreinstill-aiOfficialVerified publisher0.1.752 of 15See more

core instill-ai 0.1.75

2 of the 15 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
google.golang.org/protobuf@v1.28.0
1.33.0
library/influxdb:2.3.0-alpined7f5dd5f70e2
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

30,816
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,211
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

7,273
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
neosu/kubebadges:v0.0.5256530d8e5c6
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,798
pyroscopekubeblocksVerified publisher0.2.921 of 1See more

pyroscope kubeblocks 0.2.92

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
apecloud/pyroscope:0.37.2dbca95a15bc1
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,620
kubeviouskubevious1.2.21 of 7See more

kubevious kubevious 1.2.2

1 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kubevious/ui:1.2.16233e84bdd59
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

14,204
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.04 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

4 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

11,582
karporkusionstackVerified publisher0.7.62 of 3See more

karpor kusionstack 0.7.6

2 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kusionstack/karpor:v0.6.4b707d3bf0abd
google.golang.org/protobuf@v1.30.0
1.33.0
quay.io/coreos/etcd:v3.5.11842975891182
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

3,295
loftloftVerified publisher0.0.0-ci.141 of 1See more

loft loft 0.0.0-ci.14

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

3,675
vcluster-k8sloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-k8s loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

5,570
veleromesosphere3.2.51 of 1See more

velero mesosphere 3.2.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,869
kubecostmesosphere-stable0.37.54 of 9See more

kubecost mesosphere-stable 0.37.5

4 of the 9 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:9.4.71a359d92f40e
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.69.17bbe804260f3
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

17,693
rclonemglants2.3.41 of 1See more

rclone mglants 2.3.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
rclone/rclone:1.57.01e6eeabddc01
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,743
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

5,067
secrets-injectoronepassword-connect1.2.01 of 1See more

secrets-injector onepassword-connect 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
1password/kubernetes-secrets-injector:1.0.25884757f7879
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

890
opentelemetry-ebpfopentelemetry-helmVerified publisher0.1.71 of 4See more

opentelemetry-ebpf opentelemetry-helm 0.1.7

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
otel/opentelemetry-ebpf-k8s-watcher:v0.10.263a0d1dd2cac
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

2,573
oesopsmxVerified publisher4.0.324 of 25See more

oes opsmx 4.0.32

4 of the 25 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
google.golang.org/protobuf@v1.22.0
1.33.0
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
google.golang.org/protobuf@v1.22.0
1.33.0
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

107,811
ipfs-clusterparadeum-teamVerified publisher0.0.192 of 2See more

ipfs-cluster paradeum-team 0.0.19

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.13.117259397f587
google.golang.org/protobuf@v1.28.0
1.33.0
ipfs/ipfs-cluster:1.0.21511f6d57994
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

3,757
ipmi-exporterpnnl-miscscripts0.1.151 of 1See more

ipmi-exporter pnnl-miscscripts 0.1.15

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

2,995
pomeriumpomerium34.0.11 of 1See more

pomerium pomerium 34.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
pomerium/pomerium:v0.22.19c69b10a2126
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,942
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
google.golang.org/protobuf@v1.25.0
1.33.0
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
google.golang.org/protobuf@v1.24.0
1.33.0
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
google.golang.org/protobuf@v1.22.0
1.33.0

Open the chart page →

12,125
seaweedfs-csi-driverseaweedfs-csi-driver0.2.385 of 7See more

seaweedfs-csi-driver seaweedfs-csi-driver 0.2.38

5 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
google.golang.org/protobuf@v1.30.0
1.33.0
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

5,270
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,663
sn-platformstreamnative1.11.446 of 9See more

sn-platform streamnative 1.11.44

6 of the 9 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
google.golang.org/protobuf@v1.28.1
1.33.0
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
google.golang.org/protobuf@v1.28.1
1.33.0
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
google.golang.org/protobuf@v1.29.0
1.33.0

Open the chart page →

15,477
feedbacksystemthm-mni-iiVerified publisher0.47.13 of 10See more

feedbacksystem thm-mni-ii 0.47.1

3 of the 10 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
google.golang.org/protobuf@v1.31.0
1.33.0
library/docker:20.10.21-dind3153fa63f546
google.golang.org/protobuf@v1.28.0
1.33.0
thmmniii/fbs-runner:v1.27.186105349c1a3
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

28,534
traefik-meshtraefikOfficialVerified publisher4.1.12 of 7See more

traefik-mesh traefik 4.1.1

2 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/traefik:v2.57d5a6ae66572
google.golang.org/protobuf@v1.27.1
1.33.0
traefik/mesh:v1.4.8cf071f3e165c
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

9,257
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/argoproj/argocd:v2.8.6acaf37352569
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

10,315
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,344
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,245
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

6,085
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

10,032
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

4,714
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

4,039
clearml-servingallegroaiVerified publisher1.6.24 of 9See more

clearml-serving allegroai 1.6.2

4 of the 9 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:9.4.376dcf36e7d2a
google.golang.org/protobuf@v1.28.1
1.33.0
jimmidyson/configmap-reload:v0.8.05af9d3041d12
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

17,877
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

4,995
upcloud-csiankra-chartsVerified publisher0.4.07 of 8See more

upcloud-csi ankra-charts 0.4.0

7 of the 8 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
google.golang.org/protobuf@v1.26.0
1.33.0
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

14,917
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,149
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/influxdb:2.6.1-alpine44a366dd7724
google.golang.org/protobuf@v1.28.1
1.33.0
prom/prometheus:v2.37.98176adea328e
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

22,202
gateway-helmappscodeVerified publisher0.0.0-latest1 of 2See more

gateway-helm appscode 0.0.0-latest

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,057
scannerappscodeVerified publisher2026.1.151 of 3See more

scanner appscode 2026.1.15

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

5,299

Container images carrying it

1,638 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
oryd/hydra:v2.2.02c93beb5e5f2
google.golang.org/protobuf@v1.31.0
1.33.0
3
prom/prometheus:v2.19.0bfad037f95e5
google.golang.org/protobuf@v1.24.0
1.33.0
3
prom/pushgateway:v1.3.18305a33fb80a
google.golang.org/protobuf@v1.23.0
1.33.0
3
prom/statsd-exporter:v0.18.0d23aca343b86
google.golang.org/protobuf@v1.24.0
1.33.0
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
google.golang.org/protobuf@v1.31.0
1.33.0
3
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
google.golang.org/protobuf@v1.26.0
1.33.0
3
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
google.golang.org/protobuf@v1.28.1
1.33.0
3
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/protobuf@v1.25.0
1.33.0
3
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/protobuf@v1.29.1
1.33.0
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/protobuf@v1.28.0
1.33.0
3
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
google.golang.org/protobuf@v1.25.0
1.33.0
3
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
google.golang.org/protobuf@v1.25.0
1.33.0
3
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
google.golang.org/protobuf@v1.25.0
1.33.0
3
quay.io/devtron/clair:4.3.675fb847ac045
google.golang.org/protobuf@v1.26.0
1.33.0
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
3
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
google.golang.org/protobuf@v1.27.1
1.33.0
3
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/protobuf@v1.31.0
1.33.0
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/protobuf@v1.25.0
1.33.0
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
google.golang.org/protobuf@v1.31.0
1.33.0
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
google.golang.org/protobuf@v1.28.1
1.33.0
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/protobuf@v1.29.1
1.33.0
3
quay.io/devtron/nats-box:latest48cdd3054b20
google.golang.org/protobuf@v1.28.1
1.33.0
3
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
google.golang.org/protobuf@v1.25.0
1.33.0
3
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
google.golang.org/protobuf@v1.27.1
1.33.0
3
quay.io/metallb/controller:v0.13.101b33357b3595
google.golang.org/protobuf@v1.30.0
1.33.0
3
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
google.golang.org/protobuf@v1.26.0
1.33.0
3
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
google.golang.org/protobuf@v1.28.1
1.33.0
3
quay.io/prometheus/alertmanager:v0.26.0361db356b330
google.golang.org/protobuf@v1.30.0
1.33.0
3
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
google.golang.org/protobuf@v1.23.0
1.33.0
3
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
google.golang.org/protobuf@v1.30.0
1.33.0
3
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
3
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/protobuf@v1.26.0
1.33.0
3
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
google.golang.org/protobuf@v1.28.1
1.33.0
3
quay.io/prometheus/prometheus:v2.26.038d40a760569
google.golang.org/protobuf@v1.25.0
1.33.0
3
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
google.golang.org/protobuf@v1.27.1
1.33.0
3
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
google.golang.org/protobuf@v1.29.0
1.33.0
3
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
google.golang.org/protobuf@v1.24.0
1.33.0
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
google.golang.org/protobuf@v1.28.1
1.33.0
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
google.golang.org/protobuf@v1.30.0
1.33.0
3
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
google.golang.org/protobuf@v1.28.1
1.33.0
3
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
google.golang.org/protobuf@v1.28.1
1.33.0
3
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
google.golang.org/protobuf@v1.28.1
1.33.0
3
1password/scim:v2.3.129d0c6cb67eb
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
2
altinity/clickhouse-operator:0.21.2cd9252644ce0
google.golang.org/protobuf@v1.26.0
1.33.0
2
altinity/metrics-exporter:0.21.2df3d57215356
google.golang.org/protobuf@v1.26.0
1.33.0
2
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
google.golang.org/protobuf@v1.31.0
1.33.0
2
ayushsobti/kube-monkey:v0.5.24c94e8f8924e
google.golang.org/protobuf@v1.28.0
1.33.0
2
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
google.golang.org/protobuf@v1.27.1
1.33.0
2
bitnamilegacy/kubectl:1.26.4a0a972324d93
google.golang.org/protobuf@v1.28.1
1.33.0
2
bitpoke/mysql-operator:v0.6.3f44fa86ab27e
google.golang.org/protobuf@v1.26.0
1.33.0
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.