StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,330
of 17,781 indexed, latest versions
Container images
1,638
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,330 of 17,781 indexed charts deploy, on 1,638 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,638
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,330 by stars
ChartLatestAffected imagesRadar Score
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

14,546
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

13,874
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,030
error-pagesgeek-cookbookVerified publisher1.2.21 of 1See more

error-pages geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/error-pages:2.6.013e73da04ee4
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,110
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

7,579
smarter-device-managergeek-cookbookVerified publisher6.5.21 of 1See more

smarter-device-manager geek-cookbook 6.5.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.gitlab.com/arm-research/smarter/smarter-device-manager:v1.20.7864fc338571e
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,330
statpinggeek-cookbookVerified publisher6.2.01 of 2See more

statping geek-cookbook 6.2.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
statping/statping:v0.90.74e874da513a5c
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

3,371
syncthinggeek-cookbookVerified publisher3.5.21 of 1See more

syncthing geek-cookbook 3.5.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
syncthing/syncthing:1.18.2966433161272
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,610
health-exporterhealth-exporterVerified publisher0.3.41 of 1See more

health-exporter health-exporter 0.3.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/snapp-incubator/health-exporter:0.3.252a0d8f6278c
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,558
frpc-ingressinfinity-server0.4.11 of 1See more

frpc-ingress infinity-server 0.4.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
springhack/frpc_ingress:latest4aceb821da88
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,622
coreinstill-aiOfficialVerified publisher0.1.752 of 15See more

core instill-ai 0.1.75

2 of the 15 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:v2.0c14d7271e401
google.golang.org/protobuf@v1.28.0
1.33.0
library/influxdb:2.3.0-alpined7f5dd5f70e2
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

30,816
jenkins-operatorjenkins0.8.11 of 1See more

jenkins-operator jenkins 0.8.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/jenkins-kubernetes-operator/operator:v0.8.171cb50263c3b
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,211
kraken-cikraken-ciVerified publisher1.7.361 of 10See more

kraken-ci kraken-ci 1.7.36

1 of the 10 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-10-24T18-35-07Zf9576903f19d
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

7,273
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
neosu/kubebadges:v0.0.5256530d8e5c6
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,798
pyroscopekubeblocksVerified publisher0.2.921 of 1See more

pyroscope kubeblocks 0.2.92

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
apecloud/pyroscope:0.37.2dbca95a15bc1
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,620
kubeviouskubevious1.2.21 of 7See more

kubevious kubevious 1.2.2

1 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kubevious/ui:1.2.16233e84bdd59
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

14,204
kubeservice-lxcfs-webhookkubservice-chartsVerified publisher1.6.04 of 6See more

kubeservice-lxcfs-webhook kubservice-charts 1.6.0

4 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

11,582
karporkusionstackVerified publisher0.7.62 of 3See more

karpor kusionstack 0.7.6

2 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kusionstack/karpor:v0.6.4b707d3bf0abd
google.golang.org/protobuf@v1.30.0
1.33.0
quay.io/coreos/etcd:v3.5.11842975891182
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

3,295
loftloftVerified publisher0.0.0-ci.141 of 1See more

loft loft 0.0.0-ci.14

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

3,675
vcluster-k8sloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-k8s loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

5,570
veleromesosphere3.2.51 of 1See more

velero mesosphere 3.2.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,869
kubecostmesosphere-stable0.37.54 of 9See more

kubecost mesosphere-stable 0.37.5

4 of the 9 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:9.4.71a359d92f40e
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/kubecost1/cost-model:prod-1.108.1852f7923fad3
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.69.17bbe804260f3
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

17,693
rclonemglants2.3.41 of 1See more

rclone mglants 2.3.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
rclone/rclone:1.57.01e6eeabddc01
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,743
keycloak-operatornewsaktuell0.1.71 of 1See more

keycloak-operator newsaktuell 0.1.7

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

5,067
secrets-injectoronepassword-connect1.2.01 of 1See more

secrets-injector onepassword-connect 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
1password/kubernetes-secrets-injector:1.0.25884757f7879
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

890
opentelemetry-ebpfopentelemetry-helmVerified publisher0.1.71 of 4See more

opentelemetry-ebpf opentelemetry-helm 0.1.7

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
otel/opentelemetry-ebpf-k8s-watcher:v0.10.263a0d1dd2cac
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

2,573
oesopsmxVerified publisher4.0.324 of 25See more

oes opsmx 4.0.32

4 of the 25 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
google.golang.org/protobuf@v1.22.0
1.33.0
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
google.golang.org/protobuf@v1.22.0
1.33.0
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

107,811
ipfs-clusterparadeum-teamVerified publisher0.0.192 of 2See more

ipfs-cluster paradeum-team 0.0.19

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ipfs/go-ipfs:v0.13.117259397f587
google.golang.org/protobuf@v1.28.0
1.33.0
ipfs/ipfs-cluster:1.0.21511f6d57994
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

3,757
ipmi-exporterpnnl-miscscripts0.1.151 of 1See more

ipmi-exporter pnnl-miscscripts 0.1.15

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
pnnlmiscscripts/ipmi-exporter:1.2.0-181e18992d8e3
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

2,995
pomeriumpomerium34.0.11 of 1See more

pomerium pomerium 34.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
pomerium/pomerium:v0.22.19c69b10a2126
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,942
kube-prometheus-stackprometheus-worawutchan12.8.04 of 6See more

kube-prometheus-stack prometheus-worawutchan 12.8.0

4 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:7.2.1733842cca5bd
google.golang.org/protobuf@v1.25.0
1.33.0
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
google.golang.org/protobuf@v1.24.0
1.33.0
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
google.golang.org/protobuf@v1.22.0
1.33.0

Open the chart page →

12,125
seaweedfs-csi-driverseaweedfs-csi-driver0.2.385 of 7See more

seaweedfs-csi-driver seaweedfs-csi-driver 0.2.38

5 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-attacher:v4.3.04eb73137b663
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0f6717ce72a26
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
google.golang.org/protobuf@v1.30.0
1.33.0
registry.k8s.io/sig-storage/csi-resizer:v1.8.02e2b44393539
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/livenessprobe:v2.10.04dc0b87ccd69
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

5,270
corednssoftizyVerified publisher0.2.01 of 1See more

coredns softizy 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
coredns/coredns:1.10.1a0ead06651cf
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,663
sn-platformstreamnative1.11.446 of 9See more

sn-platform streamnative 1.11.44

6 of the 9 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.8.05af9d3041d12
google.golang.org/protobuf@v1.28.1
1.33.0
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
google.golang.org/protobuf@v1.28.1
1.33.0
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
google.golang.org/protobuf@v1.29.0
1.33.0

Open the chart page →

15,477
feedbacksystemthm-mni-iiVerified publisher0.47.13 of 10See more

feedbacksystem thm-mni-ii 0.47.1

3 of the 10 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2023.12.23-debian-11-r25bb0aa825d16
google.golang.org/protobuf@v1.31.0
1.33.0
library/docker:20.10.21-dind3153fa63f546
google.golang.org/protobuf@v1.28.0
1.33.0
thmmniii/fbs-runner:v1.27.186105349c1a3
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

28,534
traefik-meshtraefikOfficialVerified publisher4.1.12 of 7See more

traefik-mesh traefik 4.1.1

2 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/traefik:v2.57d5a6ae66572
google.golang.org/protobuf@v1.27.1
1.33.0
traefik/mesh:v1.4.8cf071f3e165c
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

9,257
argocdtwomartensVerified publisher0.1.12 of 3See more

argocd twomartens 0.1.1

2 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/argoproj/argocd:v2.8.6acaf37352569
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

10,315
vsphere-cpivsphere-tmm1.6.01 of 1See more

vsphere-cpi vsphere-tmm 1.6.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/cloud-pv-vsphere/cloud-provider-vsphere:v1.28.0026f63d9ed42
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,344
gethvulcanlink1.10.231 of 1See more

geth vulcanlink 1.10.23

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ethereum/client-go:v1.10.23cce21b423165
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,245
minio-operatorwenerme4.3.71 of 2See more

minio-operator wenerme 4.3.7

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/operator:v4.3.754393e03f3b2
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

6,085
wharf-helmwharf-helmOfficialVerified publisher3.2.64 of 5See more

wharf-helm wharf-helm 3.2.6

4 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/iver-wharf/wharf-provider-azuredevops:v3.0.12fe7e4dcffdf
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/iver-wharf/wharf-provider-github:v3.0.177a22cb45c2a
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/iver-wharf/wharf-provider-gitlab:v2.0.1d7079e0890da
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

10,032
keycloak-operatorwiremindVerified publisher0.0.141 of 1See more

keycloak-operator wiremind 0.0.14

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

4,714
yataiyataiVerified publisher0.4.61 of 2See more

yatai yatai 0.4.6

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:0.4.614b482c1f1b8
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

4,039
clearml-servingallegroaiVerified publisher1.6.24 of 9See more

clearml-serving allegroai 1.6.2

4 of the 9 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:9.4.376dcf36e7d2a
google.golang.org/protobuf@v1.28.1
1.33.0
jimmidyson/configmap-reload:v0.8.05af9d3041d12
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

17,877
pact-brokeralmorgvVerified publisher0.1.01 of 1See more

pact-broker almorgv 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
pactfoundation/pact-broker:2.79.1.112861b0bd4d9
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

4,995
upcloud-csiankra-chartsVerified publisher0.4.07 of 8See more

upcloud-csi ankra-charts 0.4.0

7 of the 8 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
alpine/k8s:1.31.137a319b15cfc9
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
google.golang.org/protobuf@v1.26.0
1.33.0
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

14,917
annotations-exporterannotations-exporter0.5.01 of 1See more

annotations-exporter annotations-exporter 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/alex123012/annotations-exporter:v0.5.04c2b8dbc798e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,149
anteonanteonVerified publisher2.6.42 of 13See more

anteon anteon 2.6.4

2 of the 13 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/influxdb:2.6.1-alpine44a366dd7724
google.golang.org/protobuf@v1.28.1
1.33.0
prom/prometheus:v2.37.98176adea328e
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

22,202
gateway-helmappscodeVerified publisher0.0.0-latest1 of 2See more

gateway-helm appscode 0.0.0-latest

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/voyagermesh/gateway:v0.0.1a8a144f14889
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

1,057
scannerappscodeVerified publisher2026.1.151 of 3See more

scanner appscode 2026.1.15

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
rancher/kine:v0.11.412889bbcd1e8
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

5,299

Container images carrying it

1,638 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
google.golang.org/protobuf@v1.30.0
1.33.0
2
quay.io/prometheus/node-exporter:v1.3.023ff46c728b9
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
2
quay.io/prometheus/node-exporter:v1.0.08a3a33cad0bd
google.golang.org/protobuf@v1.22.0
1.33.0
2
quay.io/prometheus/node-exporter:v1.3.1f2269e73124d
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
2
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
google.golang.org/protobuf@v1.31.0
1.33.0
2
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
google.golang.org/protobuf@v1.25.0
1.33.0
2
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
google.golang.org/protobuf@v1.24.0
1.33.0
2
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
google.golang.org/protobuf@v1.31.0
1.33.0
2
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
google.golang.org/protobuf@v1.28.0
1.33.0
2
quay.io/prometheus/pushgateway:v1.6.2979a69ab4a40
google.golang.org/protobuf@v1.31.0
1.33.0
2
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
google.golang.org/protobuf@v1.27.1
1.33.0
2
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
google.golang.org/protobuf@v1.31.0
1.33.0
2
registry.k8s.io/ingress-nginx/controller:v1.9.5b3aba22b1da8
google.golang.org/protobuf@v1.31.0
1.33.0
2
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
google.golang.org/protobuf@v1.26.0
1.33.0
2
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
google.golang.org/protobuf@v1.28.1
1.33.0
2
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
google.golang.org/protobuf@v1.28.1
1.33.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.5.009a36e2be1db
google.golang.org/protobuf@v1.28.0
1.33.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
google.golang.org/protobuf@v1.28.1
1.33.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.1af8220f53493
google.golang.org/protobuf@v1.30.0
1.33.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
google.golang.org/protobuf@v1.28.1
1.33.0
2
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
google.golang.org/protobuf@v1.30.0
1.33.0
2
registry.k8s.io/sig-storage/csi-attacher:v3.4.08b9c313c05f5
google.golang.org/protobuf@v1.27.1
1.33.0
2
registry.k8s.io/sig-storage/csi-attacher:v4.0.09a685020911e
google.golang.org/protobuf@v1.28.0
1.33.0
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.10103eee7c35e
google.golang.org/protobuf@v1.27.1
1.33.0
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.5.04fd21f36075b
google.golang.org/protobuf@v1.27.1
1.33.0
2
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.0f1c25991bac2
google.golang.org/protobuf@v1.28.0
1.33.0
2
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
google.golang.org/protobuf@v1.27.1
1.33.0
2
registry.k8s.io/sig-storage/csi-resizer:v1.5.08f7520bd957e
google.golang.org/protobuf@v1.27.1
1.33.0
2
registry.k8s.io/sig-storage/csi-resizer:v1.4.09ebbf9f023e7
google.golang.org/protobuf@v1.27.1
1.33.0
2
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
google.golang.org/protobuf@v1.30.0
1.33.0
2
registry.k8s.io/sig-storage/csi-snapshotter:v6.0.1ad16874e2140
google.golang.org/protobuf@v1.27.1
1.33.0
2
registry.k8s.io/sig-storage/livenessprobe:v2.8.0cacee2b5c36d
google.golang.org/protobuf@v1.28.1
1.33.0
2
0xpolygon/heimdall:1.0.134ddf259993c
google.golang.org/protobuf@v1.28.1
1.33.0
1
1password/connect-api:1.7.26aa94cf713f9
google.golang.org/protobuf@v1.31.0
1.33.0
1
1password/kubernetes-secrets-injector:1.0.25884757f7879
google.golang.org/protobuf@v1.30.0
1.33.0
1
abohatyrenko/bucket-backup-restore:latestfa98af15a13e
google.golang.org/protobuf@v1.31.0
1.33.0
1
absaoss/terraform-controller:v0.0.20ad538a1285a0
google.golang.org/protobuf@v1.25.0
1.33.0
1
adrianberger/fluxcd-webui:latest76848c0d2780
google.golang.org/protobuf@v1.25.0
1.33.0
1
akeyless/base-rhel:0.0.14ba8900a0061
google.golang.org/protobuf@v1.30.0
1.33.0
1
alex6021710/ai-scale-auth:latest6c7a47e470c3
google.golang.org/protobuf@v1.27.1
1.33.0
1
alex6021710/ai-scale-doer:latest31e533cf7cd3
google.golang.org/protobuf@v1.27.1
1.33.0
1
alex6021710/ai-scale-migrator:latest744b8a924f35
google.golang.org/protobuf@v1.27.1
1.33.0
1
alex6021710/ai-scale-provider:latest5837d9b30cc7
google.golang.org/protobuf@v1.27.1
1.33.0
1
alex6021710/ai-scale-saver:latestf73e8d60fd03
google.golang.org/protobuf@v1.27.1
1.33.0
1
alpine/k8s:1.22.600ac10bcb759
google.golang.org/protobuf@v1.27.1
1.33.0
1
alpine/k8s:1.27.321b24e6bf801
google.golang.org/protobuf@v1.30.0
1.33.0
1
alpine/k8s:1.31.106dbe6f391eda
google.golang.org/protobuf@v1.28.1
1.33.0
1
alpine/k8s:1.31.137a319b15cfc9
google.golang.org/protobuf@v1.28.1
1.33.0
1
alpine/k8s:1.32.47e1e7d5b7a96
google.golang.org/protobuf@v1.28.1
1.33.0
1
alpine/k8s:1.31.49c4976d47656
google.golang.org/protobuf@v1.28.1
1.33.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.