StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,344
of 17,787 indexed, latest versions
Container images
1,663
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,344 of 17,787 indexed charts deploy, on 1,663 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,663
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,344 by stars
ChartLatestAffected imagesRadar Score
juicefskubesphere-stable0.16.21 of 4See more

juicefs kubesphere-stable 0.16.2

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.20.043978fc60798
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

2,489
mesherykubesphere-stable0.5.08 of 13See more

meshery kubesphere-stable 0.5.0

8 of the 13 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
layer5/meshery-app-mesh:stable-latest77d59943b3d6
google.golang.org/protobuf@v1.28.0
1.33.0
layer5/meshery-consul:stable-latest25a4cc38abcd
google.golang.org/protobuf@v1.31.0
1.33.0
layer5/meshery-istio:stable-latestfde47c141ec6
google.golang.org/protobuf@v1.31.0
1.33.0
layer5/meshery-kuma:stable-latest9d25f029a8a2
google.golang.org/protobuf@v1.30.0
1.33.0
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
google.golang.org/protobuf@v1.30.0
1.33.0
layer5/meshery-nsm:stable-latestebd6a8faf21f
google.golang.org/protobuf@v1.25.0
1.33.0
layer5/meshery-osm:stable-latestec898e5786c6
google.golang.org/protobuf@v1.28.1
1.33.0
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

24,690
kube-state-metricskubestar-state-metricsVerified publisher0.1.101 of 1See more

kube-state-metrics kubestar-state-metrics 0.1.10

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,575
kube-vault-controllerkube-vault-controller1.2.01 of 1See more

kube-vault-controller kube-vault-controller 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,550
kubemodkubmod0.5.22 of 2See more

kubemod kubmod 0.5.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.19.11f8154f7e80c
google.golang.org/protobuf@v1.23.0
1.33.0
kubemod/kubemod-crt:v1.3.0028347c9fa77
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

4,542
kubeservice-cosign-webhookkubservice-chartsVerified publisher1.1.15 of 5See more

kubeservice-cosign-webhook kubservice-charts 1.1.1

5 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
google.golang.org/protobuf@v1.30.0
1.33.0
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

7,087
kubeservice-cpupools-controllerkubservice-chartsVerified publisher0.1.12 of 2See more

kubeservice-cpupools-controller kubservice-charts 0.1.1

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dongjiang1989/cpusets-controller:v1.1.1dc5bd483874c
google.golang.org/protobuf@v1.30.0
1.33.0
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

3,122
kubeservice-custom-limitrangekubservice-chartsVerified publisher1.3.04 of 5See more

kubeservice-custom-limitrange kubservice-charts 1.3.0

4 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,941
kubeservice-ebpf-exporterkubservice-chartsVerified publisher1.2.11 of 1See more

kubeservice-ebpf-exporter kubservice-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/cloudflare/ebpf_exporter:v2.3.075370b2ec2bb
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

545
kubeservice-namespace-node-affinitykubservice-chartsVerified publisher1.1.25 of 5See more

kubeservice-namespace-node-affinity kubservice-charts 1.1.2

5 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dongjiang1989/ns-node-affinity:latest451f7823723c
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

6,872
kubeservice-scheduler-pluskubservice-chartsVerified publisher0.2.11 of 2See more

kubeservice-scheduler-plus kubservice-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,803
kube-fencingkvaps2.4.11 of 2See more

kube-fencing kvaps 2.4.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kube-fencing-controller:v2.4.0313edfec2fca
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

2,538
linstorkvaps1.14.02 of 11See more

linstor kvaps 1.14.0

2 of the 11 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
google.golang.org/protobuf@v1.24.0
1.33.0
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

15,551
lagoon-remotelagoon-chartsVerified publisher0.106.01 of 1See more

lagoon-remote lagoon-charts 0.106.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

2,113
lgtm-stacklgtm-stackVerified publisher0.1.32 of 8See more

lgtm-stack lgtm-stack 0.1.3

2 of the 8 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2024-01-16T16-06-34Z591b097ea2d4
google.golang.org/protobuf@v1.31.0
1.33.0
minio/minio:RELEASE.2024-01-18T22-51-28Z551682a57a94
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,614
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

4,456
linkerd-jaegerlinkerd2-edgeVerified publisher30.14.11-edge2 of 4See more

linkerd-jaeger linkerd2-edge 30.14.11-edge

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
google.golang.org/protobuf@v1.27.1
1.33.0
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

4,389
jspolicyloftVerified publisher0.2.21 of 1See more

jspolicy loft 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
loftsh/jspolicy:0.2.225deb9bd2683
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,309
vcluster-eksloftVerified publisher0.0.0-ci.31 of 4See more

vcluster-eks loft 0.0.0-ci.3

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,304
vcluster-k0sloftVerified publisher0.0.0-ci.31 of 2See more

vcluster-k0s loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

3,138
log2rbac-operatorlog2rbac-operator0.0.51 of 1See more

log2rbac-operator log2rbac-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jkremser/log2rbac:v0.0.5e35cf56ef183
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,938
logclilogcliVerified publisher0.1.01 of 1See more

logcli logcli 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/logcli:main-c90366d-amd643d85bb66e39b
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,947
voice-biometricslumenvox2.0.17 of 26See more

voice-biometrics lumenvox 2.0.1

7 of the 26 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
google.golang.org/protobuf@v1.23.0
1.33.0
library/traefik:v2.57d5a6ae66572
google.golang.org/protobuf@v1.27.1
1.33.0
lumenvox/cloud-license:2.0.09a69862e1248
google.golang.org/protobuf@v1.27.1
1.33.0
prom/pushgateway:v1.3.18305a33fb80a
google.golang.org/protobuf@v1.23.0
1.33.0
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
google.golang.org/protobuf@v1.21.0
1.33.0
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
google.golang.org/protobuf@v1.23.0
1.33.0
quay.io/prometheus/prometheus:v2.26.038d40a760569
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

71,216
mcp-orchestratormagertronVerified publisher3.8.231 of 6See more

mcp-orchestrator magertron 3.8.23

1 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
curtismager20/mcp-sync:3.8.23b5a057bc3cee
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,704
goblackholemainVerified publisher0.0.41 of 1See more

goblackhole main 0.0.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bedag/goblackhole:0.2.0447a88598f4c
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,972
traefik-forward-authmesosphere0.3.101 of 2See more

traefik-forward-auth mesosphere 0.3.10

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

5,308
chartmuseummike75151.2.01 of 1See more

chartmuseum mike7515 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

3,168
miniomilvus8.0.171 of 1See more

minio milvus 8.0.17

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

6,915
maddymyaVerified publisher22.4.121 of 2See more

maddy mya 22.4.12

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
foxcpp/maddy:0.7.16ab538e2f28b
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

1,412
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.230b60b6565ab2
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

37,441
ngrok-operatorngrok-operator1.1.01 of 2See more

ngrok-operator ngrok-operator 1.1.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
zufardhiyaulhaq/ngrok-operator:v1.3.07cf2ae3fb1fb
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,896
node-exporternode-exporterVerified publisher0.1.101 of 1See more

node-exporter node-exporter 0.1.10

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
prom/node-exporter:v1.6.0d2e48098c364
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,229
oadaoadaVerified publisher5.0.51 of 11See more

oada oada 5.0.5

1 of the 11 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

13,319
transfer.shobeoneVerified publisher1.0.51 of 1See more

transfer.sh obeone 1.0.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dutchcoders/transfer.sh:v1.6.1-noroot8db9ade72a0d
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,171
opsopsVerified publisher1.2.02 of 2See more

ops ops 1.2.0

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
shaowenchen/ops-controller-manager:latest26da43bb5b66
google.golang.org/protobuf@v1.31.0
1.33.0
shaowenchen/ops-server:latest315444f703f4
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

9,049
kubernetes-dashboard-proxyosc0.7.23 of 4See more

kubernetes-dashboard-proxy osc 0.7.2

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.7.02e500d29e9d5
google.golang.org/protobuf@v1.28.0
1.33.0
kubernetesui/metrics-scraper:v1.0.876049887f07a
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

6,005
hlf-caowkin2.1.01 of 2See more

hlf-ca owkin 2.1.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

3,424
patch-operatorpatch-operator0.1.112 of 2See more

patch-operator patch-operator 0.1.11

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
google.golang.org/protobuf@v1.24.0
1.33.0
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

7,833
pdf-editor-helmpdf-editor-web1.0.02 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-backend-rotate316e203b8bf5
google.golang.org/protobuf@v1.28.1
1.33.0
dipugodocker/pdf-editor:1.0-backend-merge70b07544a604
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

4,206
spirephilips-labsVerified publisher0.12.25 of 6See more

spire philips-labs 0.12.2

5 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

7,236
chartmuseumphntom4.0.201 of 1See more

chartmuseum phntom 4.0.20

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
phntom/chartmuseum:v0.16.053883b65d9b7
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

2,939
pipelinewise-operatorpipelinewise-operatorVerified publisher0.5.11 of 1See more

pipelinewise-operator pipelinewise-operator 0.5.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,121
secrets-store-csi-driver-provider-awsportefaix-hub0.4.01 of 1See more

secrets-store-csi-driver-provider-aws portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-2021.08.13.20.34-linux-amd6402aed3370fce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,206
postgres-backuppostgres-backup0.3.01 of 2See more

postgres-backup postgres-backup 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
nerzhul/mc-arm64:2020.10.034215df511f31
google.golang.org/protobuf@v1.22.0
1.33.0

Open the chart page →

5,462
prometheusprometheus-worawutchan13.0.05 of 6See more

prometheus prometheus-worawutchan 13.0.0

5 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
google.golang.org/protobuf@v1.23.0
1.33.0
prom/pushgateway:v1.3.0c0d39b8d4cfe
google.golang.org/protobuf@v1.23.0
1.33.0
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
google.golang.org/protobuf@v1.21.0
1.33.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
google.golang.org/protobuf@v1.22.0
1.33.0
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

9,939
operatorpunchplatform8.1.131 of 1See more

operator punchplatform 8.1.13

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/operator:8.1-dev2a9536c8cee2
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

718
kubernetes-dashboardpyalive-cdmswebappVerified publisher5.8.01 of 1See more

kubernetes-dashboard pyalive-cdmswebapp 5.8.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.6.1290bebc3cd96
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,662
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

6,835
velero-s3-deploymentradar-baseVerified publisher0.4.22 of 4See more

velero-s3-deployment radar-base 0.4.2

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
velero/velero:v1.9.0277fbfaf8dcf
google.golang.org/protobuf@v1.26.0
1.33.0
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

4,798
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

7,487

Container images carrying it

1,663 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
google.golang.org/protobuf@v1.27.1
1.33.0
1
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
google.golang.org/protobuf@v1.31.0
1.33.0
1
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
google.golang.org/protobuf@v1.28.1
1.33.0
1
otel/opentelemetry-ebpf-k8s-watcher:v0.10.263a0d1dd2cac
google.golang.org/protobuf@v1.28.1
1.33.0
1
owncloud/ocis:1.7.0d2efcae92c84
google.golang.org/protobuf@v1.26.0
1.33.0
1
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
google.golang.org/protobuf@v1.27.1
1.33.0
1
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
google.golang.org/protobuf@v1.21.0
1.33.0
1
pactfoundation/pact-broker:2.101.0.0a3021fc42834
google.golang.org/protobuf@v1.21.0
1.33.0
1
pannoi/kollektor:1.0.59559617788fc
google.golang.org/protobuf@v1.30.0
1.33.0
1
passbolt/passbolt:3.9.0-2-ce-non-rootec046e112d5c
google.golang.org/protobuf@v1.21.0
1.33.0
1
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
google.golang.org/protobuf@v1.32.0
1.33.0
1
phntom/chartmuseum:v0.16.053883b65d9b7
google.golang.org/protobuf@v1.30.0
1.33.0
1
phntom/chartmuseum:v0.15.29242b4df9e65
google.golang.org/protobuf@v1.28.1
1.33.0
1
phntom/external-dns-host-network:0.0.123adadbac8443
google.golang.org/protobuf@v1.28.0
1.33.0
1
phntom/goalert:0.0.298ca4df55499b
google.golang.org/protobuf@v1.31.0
1.33.0
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
google.golang.org/protobuf@v1.31.0
1.33.0
1
phntom/mindav:0.1.7-kix35695f546abbb
google.golang.org/protobuf@v1.25.0
1.33.0
1
phntom/oauth2-proxy:v7.3.48ea656a2a895
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
photoprism/photoprism:231128-ce284de9cc4f9c
google.golang.org/protobuf@v1.31.0
1.33.0
1
photoprism/photoprism:220629-jammy2954334adbda
google.golang.org/protobuf@v1.28.0
1.33.0
1
piblokto/backlokto-operator:v0.0.20963cda71e393
google.golang.org/protobuf@v1.30.0
1.33.0
1
pinclr/v2ray-proxy:latestf37f250b7091
google.golang.org/protobuf@v1.28.2-0.20220831092852-f930b1dc76e8
1.33.0
1
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
google.golang.org/protobuf@v1.21.0
1.33.0
1
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
google.golang.org/protobuf@v1.29.1
1.33.0
1
polyaxon/training-operator:2.1.0b5b29deaec9a
google.golang.org/protobuf@v1.30.0
1.33.0
1
pomerium/pomerium:v0.22.19c69b10a2126
google.golang.org/protobuf@v1.30.0
1.33.0
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
google.golang.org/protobuf@v1.28.1
1.33.0
1
pozetroninc/liftbridge:v1.1.079fd6b9d93e6
google.golang.org/protobuf@v1.21.0
1.33.0
1
pravega/zookeeper-operator:0.2.15b2bc4042fdd8
google.golang.org/protobuf@v1.28.0
1.33.0
1
prom/blackbox-exporter:v0.22.0608acee5704a
google.golang.org/protobuf@v1.27.1
1.33.0
1
prom/blackbox-exporter:v0.23.0ca04aa9d9093
google.golang.org/protobuf@v1.28.1
1.33.0
1
prometheuscommunity/elasticsearch-exporter:v1.3.0fe735268fbdc
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
prom/influxdb-exporter:v0.11.427e33e18634a
google.golang.org/protobuf@v1.30.0
1.33.0
1
prom/influxdb-exporter:v0.9.0f63fd77c05ee
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
prom/memcached-exporter:v0.9.001267317c95d
google.golang.org/protobuf@v1.23.0
1.33.0
1
prom/node-exporter:v1.6.0d2e48098c364
google.golang.org/protobuf@v1.30.0
1.33.0
1
prom/prometheus:v2.51.24f6c47e39a90
google.golang.org/protobuf@v1.32.0
1.33.0
1
prom/prometheus:v2.18.15880ec936055
google.golang.org/protobuf@v1.21.0
1.33.0
1
prom/prometheus:v2.48.0b440bc0e8aa5
google.golang.org/protobuf@v1.31.0
1.33.0
1
prom/prometheus:v2.19.2cd134bd4fca0
google.golang.org/protobuf@v1.24.0
1.33.0
1
prom/prometheus:v2.22.2f7ffebdd428b
google.golang.org/protobuf@v1.24.0
1.33.0
1
prom/pushgateway:v1.5.128fe26c8b8b1
google.golang.org/protobuf@v1.28.1
1.33.0
1
prom/pushgateway:v1.4.33496e0f85943
google.golang.org/protobuf@v1.26.0
1.33.0
1
prom/snmp-exporter:v0.20.09d226d7de223
google.golang.org/protobuf@v1.23.0
1.33.0
1
prom/statsd-exporter:v0.24.061d866e93b56
google.golang.org/protobuf@v1.30.0
1.33.0
1
prom/statsd-exporter:v0.22.48be660470961
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
1
qoveryrd/digital-mobius:0.1.4b30a9398a83c
google.golang.org/protobuf@v1.25.0
1.33.0
1
qumine/ingress-controller:v0.8.5f2c8a2148381
google.golang.org/protobuf@v1.28.1
1.33.0
1
qumine/minecraft-server:v0.1.15c0b650d51132
google.golang.org/protobuf@v1.28.1
1.33.0
1
rabbitmqoperator/cluster-operator:1.8.3231e7ce0e905
google.golang.org/protobuf@v1.26.0
1.33.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.