StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,344
of 17,787 indexed, latest versions
Container images
1,663
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,344 of 17,787 indexed charts deploy, on 1,663 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,663
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,344 by stars
ChartLatestAffected imagesRadar Score
gatekeepermesosphere-stable0.6.111 of 2See more

gatekeeper mesosphere-stable 0.6.11

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

3,034
istiomesosphere-stable1.25.11 of 2See more

istio mesosphere-stable 1.25.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

4,786
kafka-operatormesosphere-stable0.25.11 of 2See more

kafka-operator mesosphere-stable 0.25.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,241
karmamesosphere-stable2.0.31 of 1See more

karma mesosphere-stable 2.0.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
lmierzwa/karma:v0.70d417abe7ddb5
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

1,966
knativemesosphere-stable1.10.87 of 7See more

knative mesosphere-stable 1.10.8

7 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.10.2c2994c2b6c2c
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.10.28319aa662b49
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpa:v1.10.2eb612b929eaa
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.10.2f66c41ad7a73
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.10.27368aaddf2be
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.10.24305209ce498
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

7,479
kommandermesosphere-stable0.39.215 of 29See more

kommander mesosphere-stable 0.39.2

15 of the 29 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
google.golang.org/protobuf@v1.23.0
1.33.0
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
google.golang.org/protobuf@v1.24.0
1.33.0
prom/prometheus:v2.19.2cd134bd4fca0
google.golang.org/protobuf@v1.24.0
1.33.0
thanosio/thanos:v0.19.088276fcd1491
google.golang.org/protobuf@v1.25.0
1.33.0
thanosio/thanos:v0.15.0b12d5c31bf5a
google.golang.org/protobuf@v1.24.0
1.33.0
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
google.golang.org/protobuf@v1.21.0
1.33.0
quay.io/thanos/thanos:v0.17.1e362f02ed304
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

68,330
kube-prometheus-stackmesosphere-stable75.9.11 of 7See more

kube-prometheus-stack mesosphere-stable 75.9.1

1 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

9,543
veleromesosphere-stable3.2.51 of 1See more

velero mesosphere-stable 3.2.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,871
cortexmetakube0.6.01 of 2See more

cortex metakube 0.6.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

4,107
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

8,940
wg-access-servermglants0.4.71 of 1See more

wg-access-server mglants 0.4.7

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,745
gogsmhio0.9.21 of 2See more

gogs mhio 0.9.2

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
gogs/gogs:0.12.1420d53bb7277
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

3,230
kube-agent-chartmiddleware-labsVerified publisher0.1.21 of 1See more

kube-agent-chart middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,799
middleware-odigosmiddleware-labsVerified publisher0.2.414 of 6See more

middleware-odigos middleware-labs 0.2.41

4 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-autoscaler:middleware-test-0.0.14aac0389614e4
google.golang.org/protobuf@v1.27.1
1.33.0
ghcr.io/middleware-labs/odigos-instrumentor:middleware-test-0.0.104ae1fc698a5
google.golang.org/protobuf@v1.27.1
1.33.0
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/middleware-labs/odigos-scheduler:middleware-test-0.0.109741c86aee7
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

8,370
middleware-visionmiddleware-labsVerified publisher0.2.654 of 6See more

middleware-vision middleware-labs 0.2.65

4 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-autoscaler:middleware-test-0.0.231f7f89bc6585
google.golang.org/protobuf@v1.27.1
1.33.0
ghcr.io/middleware-labs/vision-instrumentor:middleware-test-0.0.4dfa5907170c4
google.golang.org/protobuf@v1.27.1
1.33.0
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/middleware-labs/vision-scheduler:middleware-test-0.0.33609a075c825
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

8,361
mw-kube-agentmiddleware-labsVerified publisher0.1.21 of 1See more

mw-kube-agent middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,594
mimirmimir0.1.101 of 1See more

mimir mimir 0.1.10

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/heimops/mimir-operator:latest4e1a3ef1fe82
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

382
minio-operatorminio-operator4.3.71 of 2See more

minio-operator minio-operator 4.3.7

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

6,085
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

10,639
standard-application-stackmintel11.4.11 of 12See more

standard-application-stack mintel 11.4.1

1 of the 12 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/docker:20.10-dindaf96c680a7e1
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

10,515
jupyterhubmizzoukube0.0.1-set.by.chartpress1 of 7See more

jupyterhub mizzoukube 0.0.1-set.by.chartpress

1 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/kube-scheduler:v1.28.73ae5620a33bb
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,883
cert-manager-webhook-duckdnsmmontesVerified publisher1.2.31 of 1See more

cert-manager-webhook-duckdns mmontes 1.2.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

2,847
cockroachdb-operatormmontesVerified publisher0.1.01 of 1See more

cockroachdb-operator mmontes 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
cockroachdb/cockroach-operator:v2.1.0983312754620
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

7,775
echoperatormmontesVerified publisher0.0.21 of 1See more

echoperator mmontes 0.0.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/echoperator:v0.0.4a544a71c6e3b
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

1,826
corednsmoikot1.13.31 of 1See more

coredns moikot 1.13.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
coredns/coredns:1.7.073ca82b4ce82
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

2,547
smartthings-metricsmoikot0.1.01 of 1See more

smartthings-metrics moikot 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:0.1.08625f53aa9b7
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

1,744
smartthings-metrics-feat-log-detailsmoikot0.0.921 of 1See more

smartthings-metrics-feat-log-details moikot 0.0.92

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
moikot/smartthings-metrics:feat-log-detailsfb8565140106
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

1,732
pritunl-vpnmoinologics0.0.11 of 1See more

pritunl-vpn moinologics 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
goofball222/pritunl:1.32.3602.807bf26032dfce
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

2,470
backendmojaloop0.1.02 of 6See more

backend mojaloop 0.1.0

2 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kafka-exporter-archived:1.3.2e527fbf75dce
google.golang.org/protobuf@v1.27.1
1.33.0
bitnamilegacy/mysqld-exporter:0.13.0a7e14cc919cb
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

16,111
mongodb-query-exportermongodb-query-exporterVerified publisher5.1.01 of 1See more

mongodb-query-exporter mongodb-query-exporter 5.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/raffis/mongodb-query-exporter:v5.1.0ca6ac8a5b329
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

989
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/influxdb:2.6.1-debian-11-r18d17df1f9d745
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

10,998
backupmorremeyer4.0.01 of 1See more

backup morremeyer 4.0.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
restic/restic:0.15.2579e4e6a4931
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

2,295
hcloud-ccm-networksmorremeyer2.0.01 of 1See more

hcloud-ccm-networks morremeyer 2.0.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,739
hcloud-csi-drivermorremeyer3.0.06 of 6See more

hcloud-csi-driver morremeyer 3.0.0

6 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hetznercloud/hcloud-csi-driver:v2.3.2b7ed90d5fab2
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-attacher:v4.1.008721106b949
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

7,145
chirpstackmosquitto-helm-chart0.5.03 of 8See more

chirpstack mosquitto-helm-chart 0.5.0

3 of the 8 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
chirpstack/chirpstack-application-server:3fb7667fe037f
google.golang.org/protobuf@v1.28.1
1.33.0
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
google.golang.org/protobuf@v1.28.1
1.33.0
oliver006/redis_exporter:v1.14.0d55e056987af
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

25,989
chirpstack-event-forwardmosquitto-helm-chart0.1.21 of 1See more

chirpstack-event-forward mosquitto-helm-chart 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/chirpstack-event-forward:v0.1.223dc6274cc4b
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,854
replacermosquitto-helm-chart0.2.01 of 3See more

replacer mosquitto-helm-chart 0.2.0

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/waitfor:v1.0.0ca5a98cbed32
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,931
configmapsecretsmozilla0.0.11 of 1See more

configmapsecrets mozilla 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mzinc/configmapsecret-controller:v0.5.1eebbcbf2d1f7
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,109
approuvezmvisonneau0.1.11 of 1See more

approuvez mvisonneau 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/mvisonneau/approuvez:v0.1.0441da62e6cb3
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

1,971
unpollermvisonneau0.1.01 of 1See more

unpoller mvisonneau 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
golift/unifi-poller:v2.9.2585a29a06d05
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,190
cognativemyaVerified publisher0.2403.32 of 3See more

cognative mya 0.2403.3

2 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:10.4.0f9811e4e687f
google.golang.org/protobuf@v1.32.0
1.33.0
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

7,348
giteamyaVerified publisher23.12.51 of 1See more

gitea mya 23.12.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
gitea/gitea:1.21.6ac73e0da341f
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

3,429
redismyaVerified publisher22.4.101 of 2See more

redis mya 22.4.10

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,050
redis-queuemyaVerified publisher22.4.61 of 2See more

redis-queue mya 22.4.6

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,050
redis-raftmyaVerified publisher22.5.41 of 2See more

redis-raft mya 22.5.4

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/oliver006/redis_exporter:v1.35.1908dbee5c546
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,050
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,359
fargate-sidecar-injectormziyaboVerified publisher0.1.51 of 1See more

fargate-sidecar-injector mziyabo 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mziyabo/fargate-eks-sidecar-injector:latest3067dce17983
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,393
nats-kafkanatsVerified publisher0.15.41 of 1See more

nats-kafka nats 0.15.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
natsio/nats-kafka:1.4.2bb241956b0dc
google.golang.org/protobuf@v1.25.1-0.20200805231151-a709e31e5d12
1.33.0

Open the chart page →

1,731
nats-operatornatsVerified publisher0.8.31 of 1See more

nats-operator nats 0.8.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
natsio/nats-operator:0.8.31261dae38389
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,353
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2022-05-09T04-08-26Z4b415310d8d0
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

6,982

Container images carrying it

1,663 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
google.golang.org/protobuf@v1.27.1
1.33.0
1
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
google.golang.org/protobuf@v1.31.0
1.33.0
1
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
google.golang.org/protobuf@v1.28.1
1.33.0
1
otel/opentelemetry-ebpf-k8s-watcher:v0.10.263a0d1dd2cac
google.golang.org/protobuf@v1.28.1
1.33.0
1
owncloud/ocis:1.7.0d2efcae92c84
google.golang.org/protobuf@v1.26.0
1.33.0
1
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
google.golang.org/protobuf@v1.27.1
1.33.0
1
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
google.golang.org/protobuf@v1.21.0
1.33.0
1
pactfoundation/pact-broker:2.101.0.0a3021fc42834
google.golang.org/protobuf@v1.21.0
1.33.0
1
pannoi/kollektor:1.0.59559617788fc
google.golang.org/protobuf@v1.30.0
1.33.0
1
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
google.golang.org/protobuf@v1.21.0
1.33.0
1
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
google.golang.org/protobuf@v1.32.0
1.33.0
1
phntom/chartmuseum:v0.16.053883b65d9b7
google.golang.org/protobuf@v1.30.0
1.33.0
1
phntom/chartmuseum:v0.15.29242b4df9e65
google.golang.org/protobuf@v1.28.1
1.33.0
1
phntom/external-dns-host-network:0.0.123adadbac8443
google.golang.org/protobuf@v1.28.0
1.33.0
1
phntom/goalert:0.0.298ca4df55499b
google.golang.org/protobuf@v1.31.0
1.33.0
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
google.golang.org/protobuf@v1.31.0
1.33.0
1
phntom/mindav:0.1.7-kix35695f546abbb
google.golang.org/protobuf@v1.25.0
1.33.0
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
photoprism/photoprism:231128-ce284de9cc4f9c
google.golang.org/protobuf@v1.31.0
1.33.0
1
photoprism/photoprism:220629-jammy2954334adbda
google.golang.org/protobuf@v1.28.0
1.33.0
1
piblokto/backlokto-operator:v0.0.20963cda71e393
google.golang.org/protobuf@v1.30.0
1.33.0
1
pinclr/v2ray-proxy:latestf37f250b7091
google.golang.org/protobuf@v1.28.2-0.20220831092852-f930b1dc76e8
1.33.0
1
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
google.golang.org/protobuf@v1.21.0
1.33.0
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
google.golang.org/protobuf@v1.29.1
1.33.0
1
polyaxon/training-operator:2.1.0b5b29deaec9a
google.golang.org/protobuf@v1.30.0
1.33.0
1
pomerium/pomerium:v0.22.19c69b10a2126
google.golang.org/protobuf@v1.30.0
1.33.0
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
google.golang.org/protobuf@v1.28.1
1.33.0
1
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
google.golang.org/protobuf@v1.21.0
1.33.0
1
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
google.golang.org/protobuf@v1.28.0
1.33.0
1
prom/blackbox-exporter:v0.22.0608acee5704a
google.golang.org/protobuf@v1.27.1
1.33.0
1
prom/blackbox-exporter:v0.23.0ca04aa9d9093
google.golang.org/protobuf@v1.28.1
1.33.0
1
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
prom/influxdb-exporter:v0.11.427e33e18634a
google.golang.org/protobuf@v1.30.0
1.33.0
1
prom/influxdb-exporter:v0.9.0f63fd77c05ee
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
prom/memcached-exporter:v0.9.001267317c95d
google.golang.org/protobuf@v1.23.0
1.33.0
1
prom/node-exporter:v1.6.0d2e48098c364
google.golang.org/protobuf@v1.30.0
1.33.0
1
prom/prometheus:v2.51.24f6c47e39a90
google.golang.org/protobuf@v1.32.0
1.33.0
1
prom/prometheus:v2.18.15880ec936055
google.golang.org/protobuf@v1.21.0
1.33.0
1
prom/prometheus:v2.48.0b440bc0e8aa5
google.golang.org/protobuf@v1.31.0
1.33.0
1
prom/prometheus:v2.19.2cd134bd4fca0
google.golang.org/protobuf@v1.24.0
1.33.0
1
prom/prometheus:v2.22.2f7ffebdd428b
google.golang.org/protobuf@v1.24.0
1.33.0
1
prom/pushgateway:v1.5.128fe26c8b8b1
google.golang.org/protobuf@v1.28.1
1.33.0
1
prom/pushgateway:v1.4.33496e0f85943
google.golang.org/protobuf@v1.26.0
1.33.0
1
prom/snmp-exporter:v0.20.09d226d7de223
google.golang.org/protobuf@v1.23.0
1.33.0
1
prom/statsd-exporter:v0.24.061d866e93b56
google.golang.org/protobuf@v1.30.0
1.33.0
1
prom/statsd-exporter:v0.22.48be660470961
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
qoveryrd/digital-mobius:0.1.4b30a9398a83c
google.golang.org/protobuf@v1.25.0
1.33.0
1
qumine/ingress-controller:v0.8.5f2c8a2148381
google.golang.org/protobuf@v1.28.1
1.33.0
1
qumine/minecraft-server:v0.1.15c0b650d51132
google.golang.org/protobuf@v1.28.1
1.33.0
1
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
google.golang.org/protobuf@v1.26.0
1.33.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.