StackRadar

CVE-2024-24786

High

Advisory

Published 5 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,331
of 17,787 indexed, latest versions
Container images
1,642
deployed by those charts
Fix available
8 of 8
affected packages

Golang protojson.Unmarshal function infinite loop when unmarshaling certain forms of invalid JSON

Carried by container images the latest versions of 1,331 of 17,787 indexed charts deploy, on 1,642 images.

Affected packageAffected versionsFixed inImages
google.golang.org/protobufgolangv1.21.0, v1.22.0, v1.23.0, v1.24.0+14 more1.33.01,642
containers-commonrpm2:1-64.module+el8.8.0+18571+eed59fc42:1-81.module+el8.10.0+21962+8143777b1
criurpm3.15-4.module+el8.8.0+19044+f9982fd80:3.18-5.module+el8.10.0+21962+8143777b1
fuse-overlayfsrpm1.11-1.module+el8.8.0+18634+9a2682920:1.13-1.module+el8.10.0+21962+8143777b1
libslirprpm4.4.0-1.module+el8.8.0+18060+3f21f2cc0:4.4.0-2.module+el8.10.0+21962+8143777b1
runcrpm1:1.1.4-1.module+el8.8.0+18060+3f21f2cc1:1.1.12-1.module+el8.10.0+21974+acd2159c1
skopeorpm2:1.11.2-0.2.module+el8.8.0+18251+ad5b274c2:1.14.4-1.module+el8.10.0+21995+81e8507c1
slirp4netnsrpm1.2.0-2.module+el8.8.0+18060+3f21f2cc0:1.2.3-1.module+el8.10.0+21962+8143777b1
OSV records
GHSA-8r3f-844c-mc37RHSA-2024:4246
Also known as
GO-2024-2611

Charts affected

1,331 by stars
ChartLatestAffected imagesRadar Score
substreams-tier-2nodeifyVerified publisher1.1.31 of 1See more

substreams-tier-2 nodeify 1.1.3

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.14.3bf816072380e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

4,674
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

2,966
prometheusnodepulse25.0.06 of 6See more

prometheus nodepulse 25.0.0

6 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/prometheus-operator/prometheus-config-reloader:v0.67.014feefde1b80
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/prometheus/alertmanager:v0.26.0361db356b330
google.golang.org/protobuf@v1.30.0
1.33.0
quay.io/prometheus/node-exporter:v1.6.181f94e50ea37
google.golang.org/protobuf@v1.30.0
1.33.0
quay.io/prometheus/prometheus:v2.47.0c5dd35038287
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/prometheus/pushgateway:v1.6.05111de00e969
google.golang.org/protobuf@v1.30.0
1.33.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.10.0ec5d6f6be228
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

7,740
ingress-helm-chartnotesprojectchart0.1.02 of 2See more

ingress-helm-chart notesprojectchart 0.1.0

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
google.golang.org/protobuf@v1.30.0
1.33.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

2,956
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

4,547
vault-helm-chartnotesprojectchart0.1.01 of 1See more

vault-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/vault:1.13.3f98ac9dd97b0
google.golang.org/protobuf@v1.29.1
1.33.0

Open the chart page →

2,246
giteanovum-rgi-charts2.1.31 of 3See more

gitea novum-rgi-charts 2.1.3

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
gitea/gitea:1.13.0d5ab14cd29af
google.golang.org/protobuf@v1.25.0
1.33.0

Open the chart page →

4,861
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

27,465
cnaos-pvc-populatornutanix-helm-releasesVerified publisher1.1.0-174-prod1 of 2See more

cnaos-pvc-populator nutanix-helm-releases 1.1.0-174-prod

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,838
nai-knative-istio-controllernutanix-helm-releasesVerified publisher1.13.12 of 2See more

nai-knative-istio-controller nutanix-helm-releases 1.13.1

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.13.1a5b041ba3c9e
google.golang.org/protobuf@v1.32.0
1.33.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.13.1f066376eee17
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

1,552
nai-knative-servingnutanix-helm-releasesVerified publisher1.13.14 of 4See more

nai-knative-serving nutanix-helm-releases 1.13.1

4 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.13.121f8e11a44bf
google.golang.org/protobuf@v1.32.0
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.13.134796e9f760b
google.golang.org/protobuf@v1.32.0
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.13.153d9aa4d2c7a
google.golang.org/protobuf@v1.32.0
1.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.13.1700c69915dc7
google.golang.org/protobuf@v1.32.0
1.33.0

Open the chart page →

3,738
nutanix-flow-cninutanix-helm-releasesVerified publisher1.1.01 of 7See more

nutanix-flow-cni nutanix-helm-releases 1.1.0

1 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
natsio/nats-box:0.14.1a67913df95f1
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

4,988
lensoci-ai-incubations0.1.144 of 16See more

lens oci-ai-incubations 0.1.14

4 of the 16 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
alpine/k8s:1.31.106dbe6f391eda
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
google.golang.org/protobuf@v1.31.0
1.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

17,070
cluster-gateway-addon-managerocm-helm-chartsVerified publisher1.4.01 of 1See more

cluster-gateway-addon-manager ocm-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
oamdev/cluster-gateway-addon-manager:v1.4.01bcae00bd7b0
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,600
multicluster-meshocm-helm-chartsVerified publisher0.0.21 of 1See more

multicluster-mesh ocm-helm-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

2,124
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

4,219
one-green-coreone-green-coreVerified publisher0.0.72 of 8See more

one-green-core one-green-core 0.0.7

2 of the 8 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/grafana:8.5.3ecc1b80b8ca2
google.golang.org/protobuf@v1.27.1
1.33.0
library/telegraf:1.20.428e98eece020
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

9,558
opa-nginxopa-nginx0.0.31 of 2See more

opa-nginx opa-nginx 0.0.3

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
openpolicyagent/opa:0.53.16a58dea59933
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

2,167
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
google.golang.org/protobuf@v1.24.0
1.33.0

Open the chart page →

18,023
bbsimopencord4.8.111 of 1See more

bbsim opencord 4.8.11

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
voltha/bbsim:1.16.7d90403d58016
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,900
bbsim-sadis-serveropencord0.3.51 of 1See more

bbsim-sadis-server opencord 0.3.5

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
voltha/bbsim-sadis-server:0.4.0762b272d439e
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,714
volthaopencord2.14.02 of 2See more

voltha opencord 2.14.0

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
google.golang.org/protobuf@v1.27.1
1.33.0
voltha/voltha-rw-core:3.4.87a325316fe59
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

3,811
voltha-adapter-openoltopencord2.14.01 of 1See more

voltha-adapter-openolt opencord 2.14.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
voltha/voltha-openolt-adapter:4.5.16d6d79c08350a
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

891
voltha-infraopencord2.14.02 of 10See more

voltha-infra opencord 2.14.0

2 of the 10 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
opencord/onos-classic-helm-utils:0.1.00d693ba85fd6
google.golang.org/protobuf@v1.25.0
1.33.0
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

41,044
voltha-stackopencord2.14.03 of 4See more

voltha-stack opencord 2.14.0

3 of the 4 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
google.golang.org/protobuf@v1.27.1
1.33.0
voltha/voltha-openolt-adapter:4.5.16d6d79c08350a
google.golang.org/protobuf@v1.31.0
1.33.0
voltha/voltha-rw-core:3.4.87a325316fe59
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

5,539
probuilderopenfaas0.2.01 of 2See more

probuilder openfaas 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
moby/buildkit:v0.10.0c2aeafaed434
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

4,751
kruise-rolloutopenkruise0.6.21 of 1See more

kruise-rollout openkruise 0.6.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
openkruise/kruise-rollout:v0.6.2a75e6739ea7d
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,033
kruise-state-metricsopenkruise0.2.01 of 1See more

kruise-state-metrics openkruise 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
openkruise/kruise-state-metrics:v0.2.0a8108f771287
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,928
minioopenobserve5.0.72 of 2See more

minio openobserve 5.0.7

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-01-28T20-29-38Zad34abeba912
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/minio/minio:RELEASE.2023-02-10T18-48-39Za0a002cb113c
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

7,459
akeyless-api-gatewayopenshift1.41.21 of 1See more

akeyless-api-gateway openshift 1.41.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
akeyless/base-rhel:0.0.14ba8900a0061
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

11,796
exporteropenshift1.0.471 of 3See more

exporter openshift 1.0.47

1 of the 3 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

13,000
fsmopenshift0.1.8-ubi.63 of 6See more

fsm openshift 0.1.8-ubi.6

3 of the 6 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
google.golang.org/protobuf@v1.27.1
1.33.0
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

16,556
kb-cloud-installeropenshift2.1.351 of 1See more

kb-cloud-installer openshift 2.1.35

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

4,127
opscruiseopenshift0.35.1003 of 11See more

opscruise openshift 0.35.100

3 of the 11 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
grafana/loki:2.0.077e138f81a8e
google.golang.org/protobuf@v1.25.0
1.33.0
grafana/promtail:2.0.05fd12edcc694
google.golang.org/protobuf@v1.25.0
1.33.0
quay.io/prometheus/prometheus:v2.36.2df0cd5887887
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

8,201
osm-edgeopenshift1.2.1-ubi84 of 7See more

osm-edge openshift 1.2.1-ubi8

4 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
google.golang.org/protobuf@v1.28.1
1.33.0
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

19,455
redhat-trusted-application-pipelineopenshift1.0.21 of 2See more

redhat-trusted-application-pipeline openshift 1.0.2

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
google.golang.org/protobuf@v1.28.0
1.33.0

Open the chart page →

8,599
openvscode-serveropenvscode-server-helmVerified publisher2.7.371 of 2See more

openvscode-server openvscode-server-helm 2.7.37

1 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/docker:23.0.1-dindd9a0fd8bdd15
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

4,237
gitlab-proxyopslevelVerified publisher0.0.81 of 1See more

gitlab-proxy opslevel 0.0.8

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
library/caddy:2.660fb54d36b4b
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

1,872
opslevelopslevelVerified publisher2025.1.221 of 10See more

opslevel opslevel 2025.1.22

1 of the 10 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
minio/mc:RELEASE.2023-02-28T00-12-59Zc631532a394e
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

5,554
agentoptimizely-agentVerified publisher1.4.01 of 1See more

agent optimizely-agent 1.4.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
optimizely/agent:4.0.09d0096cabd63
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,213
prometheusosc0.26.22 of 12See more

prometheus osc 0.26.2

2 of the 12 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/prometheus/blackbox-exporter:v0.24.03af31f8bd1ad
google.golang.org/protobuf@v1.30.0
1.33.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.8.2ec5732e28f15
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

3,374
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
registry.k8s.io/e2e-test-images/agnhost:2.40af7e3857d877
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

71,208
osm-edgeosm-edgeVerified publisher1.3.94 of 7See more

osm-edge osm-edge 1.3.9

4 of the 7 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
flomesh/osm-edge-bootstrap:1.3.9b188e128cbfe
google.golang.org/protobuf@v1.28.1
1.33.0
flomesh/osm-edge-controller:1.3.9add7a4da4622
google.golang.org/protobuf@v1.28.1
1.33.0
flomesh/osm-edge-injector:1.3.947287e3ad324
google.golang.org/protobuf@v1.28.1
1.33.0
flomesh/osm-edge-preinstall:1.3.9bd224d55ed0f
google.golang.org/protobuf@v1.28.1
1.33.0

Open the chart page →

5,589
logging-operatorot-container-kit0.4.01 of 1See more

logging-operator ot-container-kit 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/opstree/logging-operator:v0.4.0fd8bb57ef3cf
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,801
lokiot-container-kit1.0.11 of 5See more

loki ot-container-kit 1.0.1

1 of the 5 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
prom/memcached-exporter:v0.14.2d8a61419b841
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

4,831
mongodb-operatorot-container-kit0.3.11 of 1See more

mongodb-operator ot-container-kit 0.3.1

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
quay.io/opstree/mongodb-operator:v0.3.0879b9bead838
google.golang.org/protobuf@v1.26.0
1.33.0

Open the chart page →

1,873
kubernetes-taggeroxyno-zetaVerified publisher1.1.21 of 1See more

kubernetes-tagger oxyno-zeta 1.1.2

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
google.golang.org/protobuf@v1.27.1
1.33.0

Open the chart page →

1,826
Parpar0.1.01 of 1See more

Par par 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/jmcgrath207/par:v0.1.09977511cb142
google.golang.org/protobuf@v1.30.0
1.33.0

Open the chart page →

889
parcaparca4.19.02 of 2See more

parca parca 4.19.0

2 of the 2 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
google.golang.org/protobuf@v1.31.0
1.33.0
ghcr.io/parca-dev/parca-agent:v0.28.06d6794f45f3e
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

3,350
parcaparca-chart0.1.01 of 1See more

parca parca-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24786.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
google.golang.org/protobuf@v1.31.0
1.33.0

Open the chart page →

1,978

Container images carrying it

1,642 by charts deploying them

A fixed version is listed for 8 of the 8 affected packages.

Container imageDigestPackageFixed inUsed by
jimmidyson/configmap-reload:v0.5.0904d08e9f701
google.golang.org/protobuf@v1.23.0
1.33.0
14
prom/pushgateway:v1.4.2a684e7c830a4
google.golang.org/protobuf@v1.26.0
1.33.0
8
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
google.golang.org/protobuf@v1.32.0
1.33.0
8
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
google.golang.org/protobuf@v1.22.0
1.33.0
8
wurstmeister/kafka:latest2d4bbf9cc83d
google.golang.org/protobuf@v1.27.1
1.33.0
7
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
google.golang.org/protobuf@v1.27.1
1.33.0
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
google.golang.org/protobuf@v1.25.0
1.33.0
6
quay.io/devtron/kubectl:latest2ad610626658
google.golang.org/protobuf@v1.28.0
1.33.0
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
google.golang.org/protobuf@v1.28.1
1.33.0
6
quay.io/devtron/postgres_exporter:v0.10.13ea136843b2e
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
6
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
google.golang.org/protobuf@v1.21.0
1.33.0
6
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.8.0:v2.8.1f6717ce72a26
google.golang.org/protobuf@v1.28.1
1.33.0
6
bitnamilegacy/kubectl:1.29.2c74b703deed2
google.golang.org/protobuf@v1.31.0
1.33.0
5
natsio/nats-box:0.14.1a67913df95f1
google.golang.org/protobuf@v1.31.0
1.33.0
5
ghcr.io/jimmidyson/configmap-reload:v0.12.0a7c754986900
google.golang.org/protobuf@v1.28.1
1.33.0
5
quay.io/prometheus/alertmanager:v0.23.09ab73a421b65
google.golang.org/protobuf@v1.26.0-rc.1
1.33.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
google.golang.org/protobuf@v1.26.0
1.33.0
5
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
google.golang.org/protobuf@v1.31.0
1.33.0
5
registry.k8s.io/sig-storage/csi-provisioner:v2.2.204c55b93a032
google.golang.org/protobuf@v1.26.0
1.33.0
5
registry.k8s.io/sig-storage/csi-provisioner:v3.5.0d078dc174323
google.golang.org/protobuf@v1.30.0
1.33.0
5
csiplugin/csi-attacher:v3.2.160ab9b3e6a03
google.golang.org/protobuf@v1.26.0
1.33.0
4
csiplugin/csi-node-driver-registrar:v2.2.02dee3fe5fe86
google.golang.org/protobuf@v1.26.0
1.33.0
4
grafana/loki:2.6.11ee60f980950
google.golang.org/protobuf@v1.27.1
1.33.0
4
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
google.golang.org/protobuf@v1.32.0
1.33.0
4
jaegertracing/jaeger-collector:1.53.07f1269222903
google.golang.org/protobuf@v1.32.0
1.33.0
4
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
google.golang.org/protobuf@v1.32.0
1.33.0
4
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
google.golang.org/protobuf@v1.23.0
1.33.0
4
jimmidyson/configmap-reload:v0.8.05af9d3041d12
google.golang.org/protobuf@v1.28.1
1.33.0
4
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
google.golang.org/protobuf@v1.27.1
1.33.0
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
google.golang.org/protobuf@v1.30.0
1.33.0
4
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
google.golang.org/protobuf@v1.31.0
1.33.0
4
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
google.golang.org/protobuf@v1.31.0
1.33.0
4
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
google.golang.org/protobuf@v1.31.0
1.33.0
4
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
google.golang.org/protobuf@v1.31.0
1.33.0
4
quay.io/prometheus/alertmanager:v0.25.0fd4d9a3dd1fd
google.golang.org/protobuf@v1.28.1
1.33.0
4
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
google.golang.org/protobuf@v1.28.1
1.33.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
google.golang.org/protobuf@v1.26.0
1.33.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20221220-controller-v1.5.1-58-g787ea74b64d99688e5573
google.golang.org/protobuf@v1.26.0
1.33.0
4
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.1.164d8c73dca98
google.golang.org/protobuf@v1.26.0
1.33.0
4
argoproj/argocd:v1.8.1830e86cacefd
google.golang.org/protobuf@v1.25.0
1.33.0
3
caddy/ingress:v0.2.118d1366fc0e9
google.golang.org/protobuf@v1.31.0
1.33.0
3
ciscolabs/rtsp-server:latestb59fc10bb821
google.golang.org/protobuf@v1.28.0
1.33.0
3
csiplugin/csi-resizer:v1.2.036c31f7e1f43
google.golang.org/protobuf@v1.26.0
1.33.0
3
csiplugin/csi-snapshotter:v4.0.051f2dfde5bcc
google.golang.org/protobuf@v1.25.0
1.33.0
3
dgraph/dgraph:v21.12.03b55ea83fffe
google.golang.org/protobuf@v1.26.0
1.33.0
3
grafana/grafana:8.2.500568d89c4f8
google.golang.org/protobuf@v1.27.1
1.33.0
3
grafana/promtail:2.4.2626900031c4e
google.golang.org/protobuf@v1.27.1
1.33.0
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
google.golang.org/protobuf@v1.28.0
1.33.0
3
library/docker:20.10-dind:20-dindaf96c680a7e1
google.golang.org/protobuf@v1.28.1
1.33.0
3
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
google.golang.org/protobuf@v1.23.0
1.33.0
3

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.