StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,344
of 17,787 indexed, latest versions
Container images
1,663
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,344 of 17,787 indexed charts deploy, on 1,663 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,663
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,344 by stars
ChartLatestAffected imagesRadar Score
juicefskubesphere-stable0.16.21 of 4See more

juicefs kubesphere-stable 0.16.2

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.20.043978fc60798
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

2,489
mesherykubesphere-stable0.5.08 of 13See more

meshery kubesphere-stable 0.5.0

8 of the 13 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
layer5/meshery-app-mesh:stable-latest77d59943b3d6
google.golang.org/protobuf@v1.28.0
1.33.0
layer5/meshery-consul:stable-latest25a4cc38abcd
google.golang.org/protobuf@v1.31.0
1.33.0
layer5/meshery-istio:stable-latestfde47c141ec6
google.golang.org/protobuf@v1.31.0
1.33.0
layer5/meshery-kuma:stable-latest9d25f029a8a2
google.golang.org/protobuf@v1.30.0
1.33.0
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
google.golang.org/protobuf@v1.30.0
1.33.0
layer5/meshery-nsm:stable-latestebd6a8faf21f
google.golang.org/protobuf@v1.25.0
1.33.0
layer5/meshery-osm:stable-latestec898e5786c6
google.golang.org/protobuf@v1.28.1
1.33.0
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

24,690
kube-state-metricskubestar-state-metricsVerified publisher0.1.101 of 1See more

kube-state-metrics kubestar-state-metrics 0.1.10

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,575
kube-vault-controllerkube-vault-controller1.2.01 of 1See more

kube-vault-controller kube-vault-controller 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,550
kubemodkubmod0.5.22 of 2See more

kubemod kubmod 0.5.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.19.11f8154f7e80c
google.golang.org/protobuf@v1.23.0
1.33.0
kubemod/kubemod-crt:v1.3.0028347c9fa77
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

4,542
kubeservice-cosign-webhookkubservice-chartsVerified publisher1.1.15 of 5See more

kubeservice-cosign-webhook kubservice-charts 1.1.1

5 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
google.golang.org/protobuf@v1.30.0
1.33.0
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

7,087
kubeservice-cpupools-controllerkubservice-chartsVerified publisher0.1.12 of 2See more

kubeservice-cpupools-controller kubservice-charts 0.1.1

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dongjiang1989/cpusets-controller:v1.1.1dc5bd483874c
google.golang.org/protobuf@v1.30.0
1.33.0
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

3,122
kubeservice-custom-limitrangekubservice-chartsVerified publisher1.3.04 of 5See more

kubeservice-custom-limitrange kubservice-charts 1.3.0

4 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,941
kubeservice-ebpf-exporterkubservice-chartsVerified publisher1.2.11 of 1See more

kubeservice-ebpf-exporter kubservice-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/cloudflare/ebpf_exporter:v2.3.075370b2ec2bb
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

545
kubeservice-namespace-node-affinitykubservice-chartsVerified publisher1.1.25 of 5See more

kubeservice-namespace-node-affinity kubservice-charts 1.1.2

5 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dongjiang1989/ns-node-affinity:latest451f7823723c
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

6,872
kubeservice-scheduler-pluskubservice-chartsVerified publisher0.2.11 of 2See more

kubeservice-scheduler-plus kubservice-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,803
kube-fencingkvaps2.4.11 of 2See more

kube-fencing kvaps 2.4.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kube-fencing-controller:v2.4.0313edfec2fca
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

2,538
linstorkvaps1.14.02 of 11See more

linstor kvaps 1.14.0

2 of the 11 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
google.golang.org/protobuf@v1.24.0
1.33.0
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

15,551
lagoon-remotelagoon-chartsVerified publisher0.106.01 of 1See more

lagoon-remote lagoon-charts 0.106.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

2,113
lgtm-stacklgtm-stackVerified publisher0.1.32 of 8See more

lgtm-stack lgtm-stack 0.1.3

2 of the 8 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2024-01-16T16-06-34Z591b097ea2d4
google.golang.org/protobuf@v1.31.0
1.33.0
minio/minio:RELEASE.2024-01-18T22-51-28Z551682a57a94
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,614
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

4,456
linkerd-jaegerlinkerd2-edgeVerified publisher30.14.11-edge2 of 4See more

linkerd-jaeger linkerd2-edge 30.14.11-edge

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
google.golang.org/protobuf@v1.27.1
1.33.0
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

4,389
jspolicyloftVerified publisher0.2.21 of 1See more

jspolicy loft 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
loftsh/jspolicy:0.2.225deb9bd2683
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,309
vcluster-eksloftVerified publisher0.0.0-ci.31 of 4See more

vcluster-eks loft 0.0.0-ci.3

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,304
vcluster-k0sloftVerified publisher0.0.0-ci.31 of 2See more

vcluster-k0s loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

3,138
log2rbac-operatorlog2rbac-operator0.0.51 of 1See more

log2rbac-operator log2rbac-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jkremser/log2rbac:v0.0.5e35cf56ef183
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,938
logclilogcliVerified publisher0.1.01 of 1See more

logcli logcli 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/logcli:main-c90366d-amd643d85bb66e39b
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,947
voice-biometricslumenvox2.0.17 of 26See more

voice-biometrics lumenvox 2.0.1

7 of the 26 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
google.golang.org/protobuf@v1.23.0
1.33.0
library/traefik:v2.57d5a6ae66572
google.golang.org/protobuf@v1.27.1
1.33.0
lumenvox/cloud-license:2.0.09a69862e1248
google.golang.org/protobuf@v1.27.1
1.33.0
prom/pushgateway:v1.3.18305a33fb80a
google.golang.org/protobuf@v1.23.0
1.33.0
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
google.golang.org/protobuf@v1.21.0
1.33.0
quay.io/prometheus/node-exporter:v1.1.222fbde17ab64
google.golang.org/protobuf@v1.23.0
1.33.0
quay.io/prometheus/prometheus:v2.26.038d40a760569
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

71,216
mcp-orchestratormagertronVerified publisher3.8.231 of 6See more

mcp-orchestrator magertron 3.8.23

1 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
curtismager20/mcp-sync:3.8.23b5a057bc3cee
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,704
goblackholemainVerified publisher0.0.41 of 1See more

goblackhole main 0.0.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bedag/goblackhole:0.2.0447a88598f4c
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,972
traefik-forward-authmesosphere0.3.101 of 2See more

traefik-forward-auth mesosphere 0.3.10

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-addon-initializer:v0.5.15efa21defcbc
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

5,308
chartmuseummike75151.2.01 of 1See more

chartmuseum mike7515 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

3,168
miniomilvus8.0.171 of 1See more

minio milvus 8.0.17

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

6,915
maddymyaVerified publisher22.4.121 of 2See more

maddy mya 22.4.12

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
foxcpp/maddy:0.7.16ab538e2f28b
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

1,412
clowder2ncsaVerified publisher1.9.71 of 12See more

clowder2 ncsa 1.9.7

1 of the 12 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.230b60b6565ab2
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

37,441
ngrok-operatorngrok-operator1.1.01 of 2See more

ngrok-operator ngrok-operator 1.1.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
zufardhiyaulhaq/ngrok-operator:v1.3.07cf2ae3fb1fb
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,896
node-exporternode-exporterVerified publisher0.1.101 of 1See more

node-exporter node-exporter 0.1.10

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
prom/node-exporter:v1.6.0d2e48098c364
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,229
oadaoadaVerified publisher5.0.51 of 11See more

oada oada 5.0.5

1 of the 11 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

13,319
transfer.shobeoneVerified publisher1.0.51 of 1See more

transfer.sh obeone 1.0.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dutchcoders/transfer.sh:v1.6.1-noroot8db9ade72a0d
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,171
opsopsVerified publisher1.2.02 of 2See more

ops ops 1.2.0

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
shaowenchen/ops-controller-manager:latest26da43bb5b66
google.golang.org/protobuf@v1.31.0
1.33.0
shaowenchen/ops-server:latest315444f703f4
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

9,049
kubernetes-dashboard-proxyosc0.7.23 of 4See more

kubernetes-dashboard-proxy osc 0.7.2

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.7.02e500d29e9d5
google.golang.org/protobuf@v1.28.0
1.33.0
kubernetesui/metrics-scraper:v1.0.876049887f07a
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

6,005
hlf-caowkin2.1.01 of 2See more

hlf-ca owkin 2.1.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

3,424
patch-operatorpatch-operator0.1.112 of 2See more

patch-operator patch-operator 0.1.11

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
google.golang.org/protobuf@v1.24.0
1.33.0
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

7,833
pdf-editor-helmpdf-editor-web1.0.02 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-backend-rotate316e203b8bf5
google.golang.org/protobuf@v1.28.1
1.33.0
dipugodocker/pdf-editor:1.0-backend-merge70b07544a604
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

4,206
spirephilips-labsVerified publisher0.12.25 of 6See more

spire philips-labs 0.12.2

5 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

7,236
chartmuseumphntom4.0.201 of 1See more

chartmuseum phntom 4.0.20

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
phntom/chartmuseum:v0.16.053883b65d9b7
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

2,939
pipelinewise-operatorpipelinewise-operatorVerified publisher0.5.11 of 1See more

pipelinewise-operator pipelinewise-operator 0.5.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,121
secrets-store-csi-driver-provider-awsportefaix-hub0.4.01 of 1See more

secrets-store-csi-driver-provider-aws portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-2021.08.13.20.34-linux-amd6402aed3370fce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,206
postgres-backuppostgres-backup0.3.01 of 2See more

postgres-backup postgres-backup 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
nerzhul/mc-arm64:2020.10.034215df511f31
google.golang.org/protobuf@v1.22.0
1.33.0

Open the chart page →

5,462
prometheusprometheus-worawutchan13.0.05 of 6See more

prometheus prometheus-worawutchan 13.0.0

5 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
google.golang.org/protobuf@v1.23.0
1.33.0
prom/pushgateway:v1.3.0c0d39b8d4cfe
google.golang.org/protobuf@v1.23.0
1.33.0
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
google.golang.org/protobuf@v1.21.0
1.33.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
google.golang.org/protobuf@v1.22.0
1.33.0
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

9,939
operatorpunchplatform8.1.131 of 1See more

operator punchplatform 8.1.13

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/operator:8.1-dev2a9536c8cee2
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

718
kubernetes-dashboardpyalive-cdmswebappVerified publisher5.8.01 of 1See more

kubernetes-dashboard pyalive-cdmswebapp 5.8.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.6.1290bebc3cd96
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,662
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

6,835
velero-s3-deploymentradar-baseVerified publisher0.4.22 of 4See more

velero-s3-deployment radar-base 0.4.2

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
velero/velero:v1.9.0277fbfaf8dcf
google.golang.org/protobuf@v1.26.0
1.33.0
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

4,798
resurfaceresurfaceioVerified publisher3.9.01 of 3See more

resurface resurfaceio 3.9.0

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

7,487

Container images carrying it

1,663 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/pingcap-public/deadmansswitch:1.04861d81aa528
google.golang.org/protobuf@v1.23.0
1.33.0
1
gcr.io/press-labs-public/dashboard:1.8.19b88f88070fb0
google.golang.org/protobuf@v1.30.0
1.33.0
1
gcr.io/projectsigstore/cosigned784518ff3ee7
google.golang.org/protobuf@v1.28.0
1.33.0
1
gcr.io/projectsigstore/policy-webhook82940e8c3e0d
google.golang.org/protobuf@v1.28.0
1.33.0
1
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
google.golang.org/protobuf@v1.27.1
1.33.0
1
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
google.golang.org/protobuf@v1.32.0
1.33.0
1
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
google.golang.org/protobuf@v1.27.1
1.33.0
1
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
google.golang.org/protobuf@v1.28.1
1.33.0
1
ghcr.io/alexellis/registry-creds:0.3.2-rc1f5c72501e559
google.golang.org/protobuf@v1.28.1
1.33.0
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
google.golang.org/protobuf@v1.27.1
1.33.0
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
google.golang.org/protobuf@v1.31.0
1.33.0
1
ghcr.io/aplulu/hakoniwa:0.1.0accf0b921388
google.golang.org/protobuf@v1.30.0
1.33.0
1
ghcr.io/appscode/auditor:v0.0.1c62c89ee706d
google.golang.org/protobuf@v1.27.1
1.33.0
1
ghcr.io/appscode/capa-vpc-peering-operator:v0.0.4b1557553a2b3
google.golang.org/protobuf@v1.31.0
1.33.0
1
ghcr.io/appscode/docker-machine-operator:v0.0.481f6007abb4e
google.golang.org/protobuf@v1.31.0
1.33.0
1
ghcr.io/appscode/grafana:v2025.2.367d18880448c
google.golang.org/protobuf@v1.25.0
1.33.0
1
ghcr.io/appscode/kube-rbac-proxy:v0.15.0d8cc6ffb9819
google.golang.org/protobuf@v1.28.0
1.33.0
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
google.golang.org/protobuf@v1.31.0
1.33.0
1
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
google.golang.org/protobuf@v1.28.1
1.33.0
1
ghcr.io/banzaicloud/kafka-operator:v0.20.2e341aefa9a90
google.golang.org/protobuf@v1.27.1
1.33.0
1
ghcr.io/banzaicloud/logging-operator:3.17.101b530cf7c07f
google.golang.org/protobuf@v1.27.1
1.33.0
1
ghcr.io/banzaicloud/logging-operator:3.17.623c2d4d54a64
google.golang.org/protobuf@v1.27.1
1.33.0
1
ghcr.io/banzaicloud/log-socket:latesta514736d2d4d
google.golang.org/protobuf@v1.27.1
1.33.0
1
ghcr.io/beezlabs-org/cloudflare-tunnel-operator:v0.1.09afcd070940f
google.golang.org/protobuf@v1.28.0
1.33.0
1
ghcr.io/behappy-project/behappy-tencentcloud-exporter:0.1.3a0ba56e1501b
google.golang.org/protobuf@v1.28.0
1.33.0
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
google.golang.org/protobuf@v1.30.0
1.33.0
1
ghcr.io/benc-uk/kubeview:0.1.31f8e7cd7325a3
google.golang.org/protobuf@v1.26.0
1.33.0
1
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
google.golang.org/protobuf@v1.32.0
1.33.0
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
google.golang.org/protobuf@v1.28.1
1.33.0
1
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
google.golang.org/protobuf@v1.28.1
1.33.0
1
ghcr.io/camptocamp/terraboard:v2.3.0df53e2c8998c
google.golang.org/protobuf@v1.31.0
1.33.0
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
google.golang.org/protobuf@v1.31.0
1.33.0
1
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
google.golang.org/protobuf@v1.28.0
1.33.0
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
google.golang.org/protobuf@v1.31.0
1.33.0
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
google.golang.org/protobuf@v1.28.0
1.33.0
1
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
google.golang.org/protobuf@v1.28.0
1.33.0
1
ghcr.io/chaos-mesh/chaos-mesh:v2.7.28bc853c7414c
google.golang.org/protobuf@v1.31.0
1.33.0
1
ghcr.io/chronicleprotocol/oracles-updates-exporter:0.0.4992d0e793af6
google.golang.org/protobuf@v1.31.0
1.33.0
1
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
google.golang.org/protobuf@v1.26.0
1.33.0
1
ghcr.io/ckotzbauer/chekrf299baf467b5
google.golang.org/protobuf@v1.27.1
1.33.0
1
ghcr.io/cloudflare/ebpf_exporter:v2.3.075370b2ec2bb
google.golang.org/protobuf@v1.31.0
1.33.0
1
ghcr.io/cloudfoundry-incubator/quarks-job:v1.0.213760eee87f839
google.golang.org/protobuf@v1.23.0
1.33.0
1
ghcr.io/cloudfoundry-incubator/quarks-operator:v7.0.1-0.g5396b116a1432b0d503
google.golang.org/protobuf@v1.23.0
1.33.0
1
ghcr.io/cloudfoundry-incubator/quarks-secret:v1.0.754f059af4de8ed
google.golang.org/protobuf@v1.23.0
1.33.0
1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1304-g4b4f2ac5c7c70b527255
google.golang.org/protobuf@v1.23.0
1.33.0
1
ghcr.io/cloudfoundry-incubator/quarks-statefulset:v0.0.1308-g6a8b2220e24a9e0a21b6
google.golang.org/protobuf@v1.23.0
1.33.0
1
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
google.golang.org/protobuf@v1.28.1
1.33.0
1
ghcr.io/cloudnative-pg/cloudnative-pg:1.21.19f707d91de1c
google.golang.org/protobuf@v1.31.0
1.33.0
1
ghcr.io/cloudtty/cloudshell-operator:v0.8.9e43ad91f0684
google.golang.org/protobuf@v1.31.0
1.33.0
1
ghcr.io/cmacrae/kove:v0.2.0185bfaae750c
google.golang.org/protobuf@v1.25.0
1.33.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.