StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,330
of 17,787 indexed, latest versions
Container images
1,638
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,330 of 17,787 indexed charts deploy, on 1,638 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,638
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,330 by stars
ChartLatestAffected imagesRadar Score
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
wazuh/wazuh-manager:4.4.121994f40e0da
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

13,852
secrets-store-csi-driver-provider-awscustom0.2.01 of 1See more

secrets-store-csi-driver-provider-aws custom 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/aws-secrets-manager/secrets-store-csi-driver-provider-aws:1.0.r2-35-g41dc61e-2022.12.16.20.38363bd65cd707
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,232
irods-csi-drivercyverse0.12.03 of 4See more

irods-csi-driver cyverse 0.12.0

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
google.golang.org/protobuf@v1.31.0
1.33.0
registry.k8s.io/sig-storage/csi-provisioner:v3.1.0122bfb8c1eda
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,218
domain-exporterd0main-exp0rter0.1.01 of 1See more

domain-exporter d0main-exp0rter 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/caarlos0/domain_exporter:v1.18.0-arm64c852606428cf
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,832
speedtest-exporterdamounVerified publisher1.0.61 of 1See more

speedtest-exporter damoun 1.0.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/danopstech/speedtest_exporter:v0.0.599efbe55412b
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,209
grafana-agentdandydev-chartsVerified publisher0.19.21 of 1See more

grafana-agent dandydev-charts 0.19.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/agent:v0.20.0825c09373d27
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,238
adot-exporter-for-eks-on-ec2dasmeta-adot0.15.51 of 1See more

adot-exporter-for-eks-on-ec2 dasmeta-adot 0.15.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,926
datadog-csi-driverdatadogVerified publisher0.17.01 of 2See more

datadog-csi-driver datadog 0.17.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

2,040
agent-helmdatasaker0.1.85 of 6See more

agent-helm datasaker 0.1.8

5 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
datasaker/dsk-container-agent:latest08b52999f67b
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-k8s-agent:latest2542ee73be51
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-kube-state-agent:latestd6d2eb48589d
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-node-agent:latest1b95913b6729
google.golang.org/protobuf@v1.31.0
1.33.0
datasaker/dsk-process-agent:latest2f38720a637d
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

7,571
ambassador-agentdatawire1.0.221 of 1See more

ambassador-agent datawire 1.0.22

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ambassador/ambassador-agent:1.0.227a1ea0d934fb
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

956
eg-edge-stackdatawire0.0.11 of 7See more

eg-edge-stack datawire 0.0.1

1 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
envoyproxy/gateway:v0.5.02a9f99d28567
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

10,666
eg-edge-stack-crdsdatawire0.0.11 of 2See more

eg-edge-stack-crds datawire 0.0.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,404
ddns-kubernetes-controllerddns-kubernetes-controller0.1.01 of 1See more

ddns-kubernetes-controller ddns-kubernetes-controller 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/mschenck/ddns-kubernetes-controller:latest590d55aab53c
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

970
kube-better-nodedecayofmind0.0.41 of 1See more

kube-better-node decayofmind 0.0.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/decayofmind/kube-better-node:masterccd2ce03b682
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

1,583
aws-service-events-exporterdeliveryheroVerified publisher1.0.71 of 1See more

aws-service-events-exporter deliveryhero 1.0.7

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
thomasnyambati/aws-service-events-exporter:1.0.01e18a0944ceb
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

1,299
aws-service-quotas-exporterdeliveryheroVerified publisher0.1.41 of 1See more

aws-service-quotas-exporter deliveryhero 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
thoughtmachine/aws-service-quotas-exporter:v1.3.2c6065ba55c72
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

771
cortex-gatewaydeliveryheroVerified publisher0.1.91 of 1See more

cortex-gateway deliveryhero 0.1.9

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
goelankit/cortex-gateway:v1.1.00d9a82dcf026
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

2,234
prometheus-soti-mobicontrol-exporterdeliveryheroVerified publisher1.0.31 of 1See more

prometheus-soti-mobicontrol-exporter deliveryhero 1.0.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
maxrocketinternet/soti-mobicontrol-exporter:0.61a281b76efa3
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

1,644
prometheus-statsd-exporterdeliveryheroVerified publisher0.1.51 of 1See more

prometheus-statsd-exporter deliveryhero 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.18.0d23aca343b86
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

1,315
toxiproxydeliveryheroVerified publisher1.3.91 of 2See more

toxiproxy deliveryhero 1.3.9

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/shopify/toxiproxy:2.7.0fc2d40f4904c
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

598
kubeteach-coredergeberl0.2.31 of 1See more

kubeteach-core dergeberl 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,504
kubeteach-exerciseset1dergeberl0.2.31 of 2See more

kubeteach-exerciseset1 dergeberl 0.2.3

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/dergeberl/kubeteach:v0.2.3-alphacf4428a3c79e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,504
kyvernodevopstalesVerified publisher2.5.12 of 2See more

kyverno devopstales 2.5.1

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
google.golang.org/protobuf@v1.28.0
1.33.0
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

4,722
pushproxdevopstalesVerified publisher0.1.62 of 2See more

pushprox devopstales 0.1.6

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
rancher/pushprox-client:v0.1.0-rancher2-clienta41cd716c412
google.golang.org/protobuf@v1.23.0
1.33.0
rancher/pushprox-proxy:v0.1.0-rancher2-proxy3126395b966c
google.golang.org/protobuf@v1.23.0
1.33.0

Open the chart page →

3,754
lxd8sdevplayer0Verified publisher0.5.11 of 2See more

lxd8s devplayer0 0.5.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

5,431
argocddevtron1.8.11 of 3See more

argocd devtron 1.8.1

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,466
argocd-certificate-refreshdevtron0.10.81 of 1See more

argocd-certificate-refresh devtron 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

12,949
argo-workflowdevtron0.1.61 of 1See more

argo-workflow devtron 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

1,580
calertdevtron0.0.11 of 1See more

calert devtron 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

4,648
devtron-enterprisedevtron48.0.09 of 28See more

devtron-enterprise devtron 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/nats-box:latest48cdd3054b20
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

68,240
devtron-in-clustercddevtron0.10.22 of 2See more

devtron-in-clustercd devtron 0.10.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

5,039
devtron-logs-dumpdevtron0.1.01 of 1See more

devtron-logs-dump devtron 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

4,928
dgraphdevtron0.0.201 of 1See more

dgraph devtron 0.0.20

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

11,909
jcmhproxy-ingressdevtron0.14.61 of 1See more

jcmhproxy-ingress devtron 0.14.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,379
kube-prometheus-stackdevtron19.3.03 of 6See more

kube-prometheus-stack devtron 19.3.0

3 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:8.2.500568d89c4f8
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/prometheus-operator/prometheus-operator:v0.50.0ab4f480f2cc6
google.golang.org/protobuf@v1.26.0
1.33.0
quay.io/prometheus/node-exporter:v1.2.2a990408ed288
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

8,645
securitydevtron0.2.21 of 1See more

security devtron 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,435
winter-soldierdevtron0.10.61 of 1See more

winter-soldier devtron 0.10.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/winter-soldier:abf5a822-196-14744093844c46c19
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,176
zincdevtron0.1.21 of 1See more

zinc devtron 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/zinclabs/zinc:latestfefa9ee7256a
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,507
argocddevtron-labs1.8.11 of 3See more

argocd devtron-labs 1.8.1

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,466
argocd-certificate-refreshdevtron-labs0.10.81 of 1See more

argocd-certificate-refresh devtron-labs 0.10.8

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

12,949
argo-workflowdevtron-labs0.1.61 of 1See more

argo-workflow devtron-labs 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

1,580
calertdevtron-labs0.0.11 of 1See more

calert devtron-labs 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

4,648
calicodevtron-labs0.1.13 of 4See more

calico devtron-labs 0.1.1

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,071
clairdevtron-labs0.1.141 of 2See more

clair devtron-labs 0.1.14

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

6,237
devtron-enterprisedevtron-labs48.0.09 of 28See more

devtron-enterprise devtron-labs 48.0.0

9 of the 28 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/nats-box:latest48cdd3054b20
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
quay.io/devtron/prometheus-nats-exporter:0.9.094044746cbce
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

68,240
devtron-in-clustercddevtron-labs0.10.22 of 2See more

devtron-in-clustercd devtron-labs 0.10.2

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.0.7aa4da00c5b96
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

5,039
devtron-logs-dumpdevtron-labs0.1.01 of 1See more

devtron-logs-dump devtron-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

4,928
devtron-operatordevtron-labs0.23.35 of 11See more

devtron-operator devtron-labs 0.23.3

5 of the 11 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0

Open the chart page →

32,902
dgraphdevtron-labs0.0.201 of 1See more

dgraph devtron-labs 0.0.20

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

11,909
jcmhproxy-ingressdevtron-labs0.14.61 of 1See more

jcmhproxy-ingress devtron-labs 0.14.6

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,379

Container images carrying it

1,638 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
alpine/k8s:1.18.16a41efe02a041
google.golang.org/protobuf@v1.25.0
1.33.0
1
alpine/k8s:1.30.0bd01dae02676
google.golang.org/protobuf@v1.31.0
1.33.0
1
alpine/k8s:1.30.2cd560fce90f7
google.golang.org/protobuf@v1.28.1
1.33.0
1
alpine/k8s:1.28.13e5c0b053fed7
google.golang.org/protobuf@v1.28.1
1.33.0
1
alpine/k8s:1.32.3eec354133193
google.golang.org/protobuf@v1.28.1
1.33.0
1
alpine/k8s:1.28.2fc059f056ad0
google.golang.org/protobuf@v1.31.0
1.33.0
1
altinity/clickhouse-operator:0.23.34baec90b20cd
google.golang.org/protobuf@v1.31.0
1.33.0
1
altinity/clickhouse-operator:0.19.07a85f522c5bc
google.golang.org/protobuf@v1.26.0
1.33.0
1
altinity/clickhouse-operator:0.20.08f0f582d41f0
google.golang.org/protobuf@v1.26.0
1.33.0
1
altinity/clickhouse-operator:0.16.1db7dde971407
google.golang.org/protobuf@v1.26.0
1.33.0
1
altinity/metrics-exporter:0.20.01a46d104406d
google.golang.org/protobuf@v1.26.0
1.33.0
1
altinity/metrics-exporter:0.23.32912a6c15b44
google.golang.org/protobuf@v1.31.0
1.33.0
1
altinity/metrics-exporter:0.16.185b4fdbae053
google.golang.org/protobuf@v1.26.0
1.33.0
1
amazon/aws-fsx-csi-driver:latestc9b14856fd22
google.golang.org/protobuf@v1.26.0
1.33.0
1
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
google.golang.org/protobuf@v1.28.1
1.33.0
1
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
google.golang.org/protobuf@v1.31.0
1.33.0
1
ambassador/ambassador-agent:1.0.227a1ea0d934fb
google.golang.org/protobuf@v1.31.0
1.33.0
1
anchore/anchore-engine:v0.10.0bde9eedf639d
google.golang.org/protobuf@v1.24.0
1.33.0
1
anchore/kai:v0.5.08aad6d0912dd
google.golang.org/protobuf@v1.28.1
1.33.0
1
andreacioni/kube-workload-restarter:0.0.242938b310090a
google.golang.org/protobuf@v1.28.1
1.33.0
1
apache/apisix-dashboard:2.9.0c010ea7d1694
google.golang.org/protobuf@v1.26.0
1.33.0
1
apache/apisix-ingress-controller:1.3.0412f92cde0b3
google.golang.org/protobuf@v1.25.0
1.33.0
1
apache/camel-k:1.10.43bb13d14f64a
google.golang.org/protobuf@v1.28.1
1.33.0
1
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
google.golang.org/protobuf@v1.30.0
1.33.0
1
apache/skywalking-oap-server:9.2.0133d35d2c263
google.golang.org/protobuf@v1.27.1
1.33.0
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
google.golang.org/protobuf@v1.27.1
1.33.0
1
apecloud/dt-platform:0.1.1d48bcbd38066
google.golang.org/protobuf@v1.30.0
1.33.0
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
google.golang.org/protobuf@v1.31.0
1.33.0
1
apecloud/kubeblocks-csi-driver:0.1.3c93655ccb2d7
google.golang.org/protobuf@v1.27.1
1.33.0
1
apecloud/kubetran-platform:latest32bd92c7f7fa
google.golang.org/protobuf@v1.31.0
1.33.0
1
apecloud/pyroscope:0.37.2dbca95a15bc1
google.golang.org/protobuf@v1.28.0
1.33.0
1
apecloud/smartfs-csi-driver:0.1.1ff2858eab9cc
google.golang.org/protobuf@v1.28.1
1.33.0
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
google.golang.org/protobuf@v1.25.0
1.33.0
1
aquasec/postee:2.12.0-amd640795cba777e7
google.golang.org/protobuf@v1.28.1
1.33.0
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
google.golang.org/protobuf@v1.28.1
1.33.0
1
aquasec/starboard-operator:0.15.4be34f709e1ce
google.golang.org/protobuf@v1.28.0
1.33.0
1
aquasec/trivy:0.43.1944a04445179
google.golang.org/protobuf@v1.31.0
1.33.0
1
aquasec/trivy:0.32.0973d0df16189
google.golang.org/protobuf@v1.28.1
1.33.0
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
google.golang.org/protobuf@v1.23.0
1.33.0
1
assistiot/data_integrity_verification:1.0.0eb7f5d765ab6
google.golang.org/protobuf@v1.26.0
1.33.0
1
assistiot/distributed_broker:1.0.033e02dad168f
google.golang.org/protobuf@v1.26.0
1.33.0
1
assistiot/dlt_based_fl:1.1.04bc3d92788ed
google.golang.org/protobuf@v1.26.0
1.33.0
1
assistiot/logging_auditing:1.0.0790dbb198e86
google.golang.org/protobuf@v1.26.0
1.33.0
1
baserow/baserow:1.30.1df0c42eb67e8
google.golang.org/protobuf@v1.31.0
1.33.0
1
bedag/goblackhole:0.2.0447a88598f4c
google.golang.org/protobuf@v1.26.0
1.33.0
1
beopenit/door-cd-operator:v3.0.4d3999cb8d026
google.golang.org/protobuf@v1.31.0
1.33.0
1
beopenit/door-helm:v3.0.1b4d9f9bee224
google.golang.org/protobuf@v1.29.1
1.33.0
1
beopenit/onboarding-operator-kubernetes:v3.0.275a48144e682
google.golang.org/protobuf@v1.26.0
1.33.0
1
bicarus/elrond-rosetta:v1.3.50.0b1dab0721e1c
google.golang.org/protobuf@v1.28.0
1.33.0
1
bicarus/mx-notifier:1.1.8bed688d16762
google.golang.org/protobuf@v1.28.0
1.33.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.