StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,330
of 17,787 indexed, latest versions
Container images
1,638
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,330 of 17,787 indexed charts deploy, on 1,638 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,638
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,330 by stars
ChartLatestAffected imagesRadar Score
vcluster-pro-eksloftVerified publisher0.0.0-ci-run.102 of 4See more

vcluster-pro-eks loft 0.0.0-ci-run.10

2 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
google.golang.org/protobuf@v1.30.0
1.33.0
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

5,936
vcluster-pro-k0sloftVerified publisher0.0.0-ci-run.102 of 2See more

vcluster-pro-k0s loft 0.0.0-ci-run.10

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

5,768
vcluster-pro-k8sloftVerified publisher0.0.0-ci-run.104 of 4See more

vcluster-pro-k8s loft 0.0.0-ci-run.10

4 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
google.golang.org/protobuf@v1.30.0
1.33.0
registry.k8s.io/etcd:3.5.6-0dd75ec974b0a
google.golang.org/protobuf@v1.27.1
1.33.0
registry.k8s.io/kube-apiserver:v1.26.199e1ed9fbc8a
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/kube-controller-manager:v1.26.140adecbe3a40
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

8,202
virtualclusterloftVerified publisher0.0.281 of 2See more

virtualcluster loft 0.0.28

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
loftsh/virtual-cluster:0.0.28023b13bf5898
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,986
apica-ascentlogiqai2.0.45 of 19See more

apica-ascent logiqai 2.0.4

5 of the 19 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
logiqai/flash-discovery:v2.0.3f5b551bca98e
google.golang.org/protobuf@v1.25.0
1.33.0
logiqai/logiqctl:2.0.4798306811f2d
google.golang.org/protobuf@v1.25.0
1.33.0
logiqai/tracing:v1.35.2-lq1-c3e149f6781b8
google.golang.org/protobuf@v1.28.0
1.33.0
logiqai/tracing:v1.35.2-lq1-q4a746ff04d6a
google.golang.org/protobuf@v1.28.0
1.33.0
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
google.golang.org/protobuf@v1.22.0
1.33.0

Open the chart page →

23,613
lsdisklsdiskVerified publisher2.0.71 of 4See more

lsdisk lsdisk 2.0.7

1 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/csi-resizer:v1.9.0f1f352df9787
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

5,025
chronograflsst-sqre1.3.51 of 1See more

chronograf lsst-sqre 1.3.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/influxdb/chronograf:1.9.4bb0a980bc2bf
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,342
sasquatchlsst-sqre0.1.132 of 6See more

sasquatch lsst-sqre 0.1.13

2 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/kapacitor:1.6.37232f6388a4d
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/influxdb/chronograf:1.9.3c2ed16080689
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

9,332
squash-apilsst-sqre0.1.61 of 3See more

squash-api lsst-sqre 0.1.6

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
gcr.io/cloudsql-docker/gce-proxy:1.17a85176b8e7cc
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

6,611
telegraf-dslsst-sqre1.0.231 of 1See more

telegraf-ds lsst-sqre 1.0.23

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/telegraf:1.19-alpineaddb86c0c520
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

3,764
m9sweeperm9sweeperVerified publisher1.6.02 of 6See more

m9sweeper m9sweeper 1.6.0

2 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
kubesec/kubesec:v2.13.0c0f3b0673578
google.golang.org/protobuf@v1.28.1
1.33.0
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

9,774
magistralamagistrala-devopsVerified publisher0.16.23 of 42See more

magistrala magistrala-devops 0.16.2

3 of the 42 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
google.golang.org/protobuf@v1.32.0
1.33.0
jaegertracing/jaeger-collector:1.53.07f1269222903
google.golang.org/protobuf@v1.32.0
1.33.0
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

24,400
matrix-sliding-syncmatrix-sliding-sync0.2.31 of 1See more

matrix-sliding-sync matrix-sliding-sync 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/matrix-org/sliding-sync:v0.99.19b940cab56435
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,592
focalboardmattermostVerified publisher0.5.01 of 1See more

focalboard mattermost 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mattermost/focalboard:0.6.7f2f987dada52
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

4,014
mattermost-calls-offloadermattermostVerified publisher0.2.11 of 1See more

mattermost-calls-offloader mattermost 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mattermost/calls-offloader:v0.9.0b440b282599e
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,414
mattermost-chaos-enginemattermostVerified publisher0.2.01 of 1See more

mattermost-chaos-engine mattermost 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mattermost/mattermost-app-chaosengine:c153e436268954edd67
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

4,067
mayastormayastorVerified publisher2.12.11 of 31See more

mayastor mayastor 2.12.1

1 of the 31 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
natsio/prometheus-nats-exporter:0.11.031c02aac089a
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

21,064
sabnzbdmedia-servarrVerified publisher1.6.21 of 3See more

sabnzbd media-servarr 1.6.2

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/onedr0p/exportarr:v1.6.160cf3d44aa0b
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

700
cameramedia-streaming-meshVerified publisher0.2.51 of 3See more

camera media-streaming-mesh 0.2.5

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ciscolabs/rtsp-server:latestb59fc10bb821
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

18,608
crdsmedia-streaming-meshVerified publisher0.0.11 of 2See more

crds media-streaming-mesh 0.0.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ciscolabs/msm-nc:0710202336d02faad958
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

3,668
ingressmedia-streaming-meshVerified publisher0.1.82 of 2See more

ingress media-streaming-mesh 0.1.8

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
google.golang.org/protobuf@v1.28.1
1.33.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230312-helm-chart-4.5.2-28-g66a76079401d181618f27
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

3,301
msmmedia-streaming-meshVerified publisher0.1.171 of 6See more

msm media-streaming-mesh 0.1.17

1 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

11,286
msm-rtspmedia-streaming-meshVerified publisher0.0.21 of 2See more

msm-rtsp media-streaming-mesh 0.0.2

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ciscolabs/rtsp-server:latestb59fc10bb821
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

18,608
rtspmedia-streaming-meshVerified publisher0.0.141 of 2See more

rtsp media-streaming-mesh 0.0.14

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ciscolabs/rtsp-server:latestb59fc10bb821
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

18,608
mediawiki-backupmediawiki-backupVerified publisher0.2.11 of 1See more

mediawiki-backup mediawiki-backup 0.2.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

1,917
gatekeepermesosphere0.6.111 of 2See more

gatekeeper mesosphere 0.6.11

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

3,034
istiomesosphere1.25.11 of 2See more

istio mesosphere 1.25.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,422
kafka-operatormesosphere0.20.21 of 2See more

kafka-operator mesosphere 0.20.2

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/kafka-operator:v0.20.2e341aefa9a90
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,884
kubeaddons-catalogmesosphere0.1.161 of 2See more

kubeaddons-catalog mesosphere 0.1.16

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

12,010
kubefedmesosphere0.5.21 of 1See more

kubefed mesosphere 0.5.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mesosphere/kubefed:proxyurl4fd8889195fe
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

3,144
kube-prometheus-stackmesosphere87.16.01 of 7See more

kube-prometheus-stack mesosphere 87.16.0

1 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

7,398
nvidiamesosphere0.4.41 of 2See more

nvidia mesosphere 0.4.4

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
nvidia/dcgm-exporter:2.2.9-2.4.1-ubuntu20.0491b20b66d1cd
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

10,436
prometheus-operatormesosphere12.11.133 of 8See more

prometheus-operator mesosphere 12.11.13

3 of the 8 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jettech/kube-webhook-certgen:v1.5.0fb7c2cd46ccf
google.golang.org/protobuf@v1.24.0
1.33.0
quay.io/prometheus-operator/prometheus-operator:v0.44.0983627001c89
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
google.golang.org/protobuf@v1.22.0
1.33.0

Open the chart page →

11,689
traefik2mesosphere9.18.01 of 1See more

traefik2 mesosphere 9.18.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/traefik:2.4.8eda951fd29a8
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

3,341
azuredisk-csi-drivermesosphere-stable0.8.14 of 6See more

azuredisk-csi-driver mesosphere-stable 0.8.1

4 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
mcr.microsoft.com/k8s/csi/azuredisk-csi:v1.1.1ec1803037ed9
google.golang.org/protobuf@v1.25.0
1.33.0
mcr.microsoft.com/oss/kubernetes-csi/csi-node-driver-registrar:v2.0.1fc5d14e9f26f
google.golang.org/protobuf@v1.24.0
1.33.0
mcr.microsoft.com/oss/kubernetes-csi/csi-resizer:v1.1.07997e0f236bc
google.golang.org/protobuf@v1.25.0
1.33.0
mcr.microsoft.com/oss/kubernetes-csi/livenessprobe:v2.2.0b7d82802cca8
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

14,065
cert-manager-setupmesosphere-stable0.2.104 of 5See more

cert-manager-setup mesosphere-stable 0.2.10

4 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.11.05c3eb25b0854
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/jetstack/cert-manager-controller:v1.11.0d429b6d696e0
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/jetstack/cert-manager-ctl:v1.11.074611761f052
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.11.06730d96fc382
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

7,179
dexmesosphere-stable2.14.12 of 5See more

dex mesosphere-stable 2.14.1

2 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
google.golang.org/protobuf@v1.31.0
1.33.0
mesosphere/dex:v2.37.0-d2iq.1b093d78a21ed
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

19,214
gatekeepermesosphere-stable0.6.111 of 2See more

gatekeeper mesosphere-stable 0.6.11

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
openpolicyagent/gatekeeper:v3.4.0-rc.1825370bdb3c3
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

3,034
istiomesosphere-stable1.25.11 of 2See more

istio mesosphere-stable 1.25.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

5,422
kafka-operatormesosphere-stable0.25.11 of 2See more

kafka-operator mesosphere-stable 0.25.1

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/banzaicloud/kafka-operator:v0.25.113dcbc7ebfc6
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,241
karmamesosphere-stable2.0.31 of 1See more

karma mesosphere-stable 2.0.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
lmierzwa/karma:v0.70d417abe7ddb5
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

1,966
knativemesosphere-stable1.10.87 of 7See more

knative mesosphere-stable 1.10.8

7 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.10.2c2994c2b6c2c
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.10.28319aa662b49
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler-hpa:v1.10.2eb612b929eaa
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.10.2f66c41ad7a73
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.10.27368aaddf2be
google.golang.org/protobuf@v1.28.1
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.10.24305209ce498
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

7,479
kommandermesosphere-stable0.39.215 of 29See more

kommander mesosphere-stable 0.39.2

15 of the 29 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.5.0904d08e9f701
google.golang.org/protobuf@v1.23.0
1.33.0
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-federation-utility-apiserver:v0.21.2f9b769c65e24
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-licensing-controller-manager:v0.21.28e18bbe407f7
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kommander-licensing-webhook:v0.21.2265edcd2a1ca
google.golang.org/protobuf@v1.25.0
1.33.0
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
google.golang.org/protobuf@v1.24.0
1.33.0
prom/prometheus:v2.19.2cd134bd4fca0
google.golang.org/protobuf@v1.24.0
1.33.0
thanosio/thanos:v0.19.088276fcd1491
google.golang.org/protobuf@v1.25.0
1.33.0
thanosio/thanos:v0.15.0b12d5c31bf5a
google.golang.org/protobuf@v1.24.0
1.33.0
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/kubernetes-multicluster/kubefed:v0.7.06d56f69b15a3
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
google.golang.org/protobuf@v1.21.0
1.33.0
quay.io/thanos/thanos:v0.17.1e362f02ed304
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

68,284
kube-prometheus-stackmesosphere-stable75.9.11 of 7See more

kube-prometheus-stack mesosphere-stable 75.9.1

1 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.2c74b703deed2
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

10,180
veleromesosphere-stable3.2.51 of 1See more

velero mesosphere-stable 3.2.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.26.4a0a972324d93
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,869
cortexmetakube0.6.01 of 2See more

cortex metakube 0.6.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

4,107
istio-operatormetakube1.12.01 of 1See more

istio-operator metakube 1.12.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
istio/operator:1.12.06cfce8a071b9
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

8,902
wg-access-servermglants0.4.71 of 1See more

wg-access-server mglants 0.4.7

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

2,745
gogsmhio0.9.21 of 2See more

gogs mhio 0.9.2

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
gogs/gogs:0.12.1420d53bb7277
google.golang.org/protobuf@v1.21.0
1.33.0

Open the chart page →

3,230
kube-agent-chartmiddleware-labsVerified publisher0.1.21 of 1See more

kube-agent-chart middleware-labs 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,799

Container images carrying it

1,638 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
jimmidyson/configmap-reload:v0.5.0904d08e9f701
google.golang.org/protobuf@v1.23.0
1.33.0
14
prom/pushgateway:v1.4.2a684e7c830a4
google.golang.org/protobuf@v1.26.0
1.33.0
8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
google.golang.org/protobuf@v1.32.0
1.33.0
8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
google.golang.org/protobuf@v1.22.0
1.33.0
8
wurstmeister/kafka:latest2d4bbf9cc83d
google.golang.org/protobuf@v1.27.1
1.33.0
7
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
6
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
6
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
google.golang.org/protobuf@v1.21.0
1.33.0
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0:v2.8.1f6717ce72a26
google.golang.org/protobuf@v1.28.1
1.33.0
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
google.golang.org/protobuf@v1.31.0
1.33.0
5
natsio/nats-box:0.14.1a67913df95f1
google.golang.org/protobuf@v1.31.0
1.33.0
5
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
google.golang.org/protobuf@v1.28.1
1.33.0
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
google.golang.org/protobuf@v1.26.0
1.33.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
google.golang.org/protobuf@v1.31.0
1.33.0
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
google.golang.org/protobuf@v1.26.0
1.33.0
5
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
google.golang.org/protobuf@v1.30.0
1.33.0
5
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
google.golang.org/protobuf@v1.26.0
1.33.0
4
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
google.golang.org/protobuf@v1.26.0
1.33.0
4
grafana/loki:2.6.11ee60f980950
google.golang.org/protobuf@v1.27.1
1.33.0
4
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
google.golang.org/protobuf@v1.32.0
1.33.0
4
jaegertracing/jaeger-collector:1.53.07f1269222903
google.golang.org/protobuf@v1.32.0
1.33.0
4
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
google.golang.org/protobuf@v1.32.0
1.33.0
4
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
google.golang.org/protobuf@v1.23.0
1.33.0
4
jimmidyson/configmap-reload:v0.8.05af9d3041d12
google.golang.org/protobuf@v1.28.1
1.33.0
4
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
google.golang.org/protobuf@v1.27.1
1.33.0
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
google.golang.org/protobuf@v1.30.0
1.33.0
4
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
4
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
google.golang.org/protobuf@v1.28.1
1.33.0
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
google.golang.org/protobuf@v1.28.1
1.33.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
google.golang.org/protobuf@v1.26.0
1.33.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
google.golang.org/protobuf@v1.26.0
1.33.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
google.golang.org/protobuf@v1.26.0
1.33.0
4
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/protobuf@v1.25.0
1.33.0
3
caddy/ingress:v0.2.118d1366fc0e9
google.golang.org/protobuf@v1.31.0
1.33.0
3
ciscolabs/rtsp-server:latestb59fc10bb821
google.golang.org/protobuf@v1.28.0
1.33.0
3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
google.golang.org/protobuf@v1.26.0
1.33.0
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
google.golang.org/protobuf@v1.25.0
1.33.0
3
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/protobuf@v1.26.0
1.33.0
3
grafana/grafana:8.2.500568d89c4f8
google.golang.org/protobuf@v1.27.1
1.33.0
3
grafana/promtail:2.4.2626900031c4e
google.golang.org/protobuf@v1.27.1
1.33.0
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
google.golang.org/protobuf@v1.28.0
1.33.0
3
library/docker:20.10-dind:20-dindaf96c680a7e1
google.golang.org/protobuf@v1.28.1
1.33.0
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
google.golang.org/protobuf@v1.23.0
1.33.0
3

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.