StackRadar

CVE-2024-24791

High

Advisory

Published 2 Jul 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
72nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,306
of 17,828 indexed, latest versions
Container images
2,710
deployed by those charts
Fix available
1 of 2
affected packages

Denial of service due to improper 100-continue handling in net/http

Carried by container images the latest versions of 2,306 of 17,828 indexed charts deploy, on 2,710 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+132 more1.21.122,710
OSV records
DEBIAN-CVE-2024-24791GO-2024-2963
Also known as
BIT-golang-2024-24791

Charts affected

2,306 by stars
ChartLatestAffected imagesRadar Score
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
stdlib@go1.16.6
1.21.12

Open the chart page →

74,898
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.21.12

Open the chart page →

74,843
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
stdlib@go1.16.6
1.21.12

Open the chart page →

74,843
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
stdlib@go1.16.6
1.21.12

Open the chart page →

75,124
istio-ratelimitistio-ratelimitVerified publisher0.0.51 of 2See more

istio-ratelimit istio-ratelimit 0.0.5

1 of the 2 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
envoyproxy/ratelimit:4d2efd61ede09a75a84c
stdlib@go1.14.15
1.21.12

Open the chart page →

1,820
kubernetes-event-exporteritakurahVerified publisher0.2.31 of 1See more

kubernetes-event-exporter itakurah 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
ghcr.io/itakurah/kubernetes-event-exporter:v1.78abb52b66557
stdlib@go1.20.14
1.21.12

Open the chart page →

1,142
statpingitscontainedVerified publisher0.1.91 of 1See more

statping itscontained 0.1.9

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
statping/statping:v0.90.6532f26fffca46
stdlib@go1.14.8
1.21.12

Open the chart page →

3,538
traefik-forward-authitscontainedVerified publisher1.0.21 of 1See more

traefik-forward-auth itscontained 1.0.2

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
stdlib@go1.13.12
1.21.12

Open the chart page →

2,235
jetic-operatorjetic-operatorVerified publisher2.0.21 of 1See more

jetic-operator jetic-operator 2.0.2

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
apache/camel-k:1.10.43bb13d14f64a
stdlib@go1.17.13
1.21.12

Open the chart page →

9,413
jenkinsjkimVerified publisher5.5.141 of 2See more

jenkins jkim 5.5.14

1 of the 2 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
stdlib@go1.21.8
1.21.12

Open the chart page →

7,356
forecastlejmmaloney41.1.1201 of 1See more

forecastle jmmaloney4 1.1.120

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
stakater/forecastle:v1.0.13886b24cdef409
stdlib@go1.22.1
1.21.12

Open the chart page →

1,814
rclonejmmaloney42.3.211 of 1See more

rclone jmmaloney4 2.3.21

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
rclone/rclone:1.66.0a693c46a6b8b
stdlib@go1.22.1
1.21.12

Open the chart page →

1,762
hncjouveVerified publisher0.8.31 of 1See more

hnc jouve 0.8.3

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
gcr.io/k8s-staging-multitenancy/hnc-manager:v1.1.08ab8229f6a89
stdlib@go1.20.5
1.21.12

Open the chart page →

1,078
joylive-injectorjoyliveOfficialVerified publisher1.3.51 of 2See more

joylive-injector joylive 1.3.5

1 of the 2 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
otel/opentelemetry-collector:0.100.09e36620d6c2c
stdlib@go1.22.2
1.21.12

Open the chart page →

1,290
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
stdlib@go1.18.7
1.21.12

Open the chart page →

3,383
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
stdlib@go1.20.7
1.21.12

Open the chart page →

5,213
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
stdlib@go1.16.7
1.21.12

Open the chart page →

5,325
giteakeyporttech0.2.102 of 4See more

gitea keyporttech 0.2.10

2 of the 4 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
gitea/gitea:1.12.485416d6f65fe
stdlib@go1.14.8
1.21.12
library/postgres:115d2aa4a7b5f9
stdlib@go1.16.7
1.21.12

Open the chart page →

5,410
kronos-corekronos-coreVerified publisher0.4.11 of 2See more

kronos-core kronos-core 0.4.1

1 of the 2 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
kronosorg/kronos-core:v0.4.0301da21c59a5
stdlib@go1.21.10
1.21.12

Open the chart page →

544
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
stdlib@go1.20.6
1.21.12

Open the chart page →

20,466
ks-corekubeblocksVerified publisher1.1.32 of 5See more

ks-core kubeblocks 1.1.3

2 of the 5 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
kubesphere/ks-extensions-museum:latest29681958f220
stdlib@go1.20.12
1.21.12
kubesphere/kubectl:v1.27.1649b445b1b732
stdlib@go1.18.10
1.21.12

Open the chart page →

4,741
kubefedkubefed0.10.01 of 2See more

kubefed kubefed 0.10.0

1 of the 2 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
quay.io/kubernetes-multicluster/kubefed:v0.10.0c4635c95730e
stdlib@go1.16.6
1.21.12

Open the chart page →

2,427
kubegems-localkubegemsOfficial1.24.101 of 2See more

kubegems-local kubegems 1.24.10

1 of the 2 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
kubegems/kubectl:latestc3b4be9a54f5
stdlib@go1.20
1.21.12

Open the chart page →

6,109
monitoringkubegems44.3.41 of 1See more

monitoring kubegems 44.3.4

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
kubegems/alertproxy:v0.4.2eaee03055329
stdlib@go1.18.10
1.21.12

Open the chart page →

742
kubernetes-stateless-chartkubernetes-stateless-chart1.0.31 of 1See more

kubernetes-stateless-chart kubernetes-stateless-chart 1.0.3

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
stdlib@go1.19.4
1.21.12

Open the chart page →

3,285
juicefskubesphere-stable0.16.21 of 4See more

juicefs kubesphere-stable 0.16.2

1 of the 4 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.20.043978fc60798
stdlib@go1.18.10
1.21.12

Open the chart page →

2,523
mesherykubesphere-stable0.5.07 of 13See more

meshery kubesphere-stable 0.5.0

7 of the 13 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
layer5/meshery-app-mesh:stable-latest77d59943b3d6
stdlib@go1.19.5
1.21.12
layer5/meshery-consul:stable-latest25a4cc38abcd
stdlib@go1.19.13
1.21.12
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
stdlib@go1.13.1
1.21.12
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
stdlib@go1.19.11
1.21.12
layer5/meshery-nsm:stable-latestebd6a8faf21f
stdlib@go1.15.12
1.21.12
layer5/meshery-osm:stable-latestec898e5786c6
stdlib@go1.19.8
1.21.12
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
stdlib@go1.19.11
1.21.12

Open the chart page →

24,964
aws-efs-csi-driverkubesphere-testVerified publisher0.1.01 of 3See more

aws-efs-csi-driver kubesphere-test 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
amazon/aws-efs-csi-driver:v0.3.0b55277652ea8
stdlib@go1.13.4
1.21.12

Open the chart page →

2,613
kube-state-metricskubestar-state-metricsVerified publisher0.1.101 of 1See more

kube-state-metrics kubestar-state-metrics 0.1.10

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.6.0bdab4e49d71d
stdlib@go1.18.5
1.21.12

Open the chart page →

1,576
kube-vault-controllerkube-vault-controller1.2.01 of 1See more

kube-vault-controller kube-vault-controller 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
stdlib@go1.21.1
1.21.12

Open the chart page →

1,550
kubemodkubmod0.5.22 of 2See more

kubemod kubmod 0.5.2

2 of the 2 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
kubemod/kubemod:v0.19.11f8154f7e80c
stdlib@go1.18
1.21.12
kubemod/kubemod-crt:v1.3.0028347c9fa77
stdlib@go1.18.1
1.21.12

Open the chart page →

4,544
kubeservice-cosign-webhookkubservice-chartsVerified publisher1.1.15 of 5See more

kubeservice-cosign-webhook kubservice-charts 1.1.1

5 of the 5 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
stdlib@go1.19.12
1.21.12
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
stdlib@go1.20.8
1.21.12
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
stdlib@go1.20.8
1.21.12
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
stdlib@go1.20.8
1.21.12
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
stdlib@go1.20.8
1.21.12

Open the chart page →

7,133
kubeservice-cpupools-controllerkubservice-chartsVerified publisher0.1.12 of 2See more

kubeservice-cpupools-controller kubservice-charts 0.1.1

2 of the 2 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
dongjiang1989/cpusets-controller:v1.1.1dc5bd483874c
stdlib@go1.19.10
1.21.12
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
stdlib@go1.19.10
1.21.12

Open the chart page →

3,129
kubeservice-custom-limitrangekubservice-chartsVerified publisher1.3.04 of 5See more

kubeservice-custom-limitrange kubservice-charts 1.3.0

4 of the 5 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
stdlib@go1.20.8
1.21.12
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
stdlib@go1.20.8
1.21.12
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
stdlib@go1.20.8
1.21.12
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
stdlib@go1.20.8
1.21.12

Open the chart page →

6,126
kubeservice-ebpf-exporterkubservice-chartsVerified publisher1.2.11 of 1See more

kubeservice-ebpf-exporter kubservice-charts 1.2.1

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
ghcr.io/cloudflare/ebpf_exporter:v2.3.075370b2ec2bb
stdlib@go1.21.5
1.21.12

Open the chart page →

545
kubeservice-namespace-node-affinitykubservice-chartsVerified publisher1.1.25 of 5See more

kubeservice-namespace-node-affinity kubservice-charts 1.1.2

5 of the 5 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
dongjiang1989/ns-node-affinity:latest451f7823723c
stdlib@go1.18.5
1.21.12
quay.io/jetstack/cert-manager-cainjector:v1.13.172072d492b43
stdlib@go1.20.8
1.21.12
quay.io/jetstack/cert-manager-controller:v1.13.16b83f55bd99e
stdlib@go1.20.8
1.21.12
quay.io/jetstack/cert-manager-ctl:v1.13.1c10bde7ff9ad
stdlib@go1.20.8
1.21.12
quay.io/jetstack/cert-manager-webhook:v1.13.148ea4a77dfa7
stdlib@go1.20.8
1.21.12

Open the chart page →

6,911
kubeservice-scheduler-pluskubservice-chartsVerified publisher0.2.11 of 2See more

kubeservice-scheduler-plus kubservice-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
stdlib@go1.19.9
1.21.12

Open the chart page →

1,804
kube-fencingkvaps2.4.12 of 2See more

kube-fencing kvaps 2.4.1

2 of the 2 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kube-fencing-controller:v2.4.0313edfec2fca
stdlib@go1.18.8
1.21.12
ghcr.io/kvaps/kube-fencing-switcher:v2.4.0f8c378e63b78
stdlib@go1.18.8
1.21.12

Open the chart page →

2,539
linstorkvaps1.14.04 of 11See more

linstor kvaps 1.14.0

4 of the 11 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
ghcr.io/kvaps/linstor-controller:v1.14.000ce11c31087
stdlib@go1.15.14
1.21.12
ghcr.io/kvaps/linstor-csi:v1.14.0087618d16b83
stdlib@go1.15.14
1.21.12
ghcr.io/kvaps/linstor-ha-controller:v1.14.08e7b44bbd123
stdlib@go1.15.14
1.21.12
ghcr.io/kvaps/linstor-stork:v1.14.05e409a6332b4
stdlib@go1.15.14
1.21.12

Open the chart page →

15,579
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
stdlib@go1.20.12
1.21.12

Open the chart page →

5,076
lagoon-remotelagoon-chartsVerified publisher0.106.01 of 1See more

lagoon-remote lagoon-charts 0.106.0

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
stdlib@go1.21.3
1.21.12

Open the chart page →

2,281
landelijketabellencataloguslandelijketabellencatalogus1.0.01 of 3See more

landelijketabellencatalogus landelijketabellencatalogus 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
stdlib@go1.13.10
1.21.12

Open the chart page →

7,521
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
stdlib@go1.13.8
1.21.12

Open the chart page →

4,481
linkerd-jaegerlinkerd2-edgeVerified publisher30.14.11-edge2 of 4See more

linkerd-jaeger linkerd2-edge 30.14.11-edge

2 of the 4 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
jaegertracing/all-in-one:1.3104d224a9999b
stdlib@go1.17.6
1.21.12
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
stdlib@go1.20.7
1.21.12

Open the chart page →

4,410
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
stdlib@go1.18.2
1.21.12

Open the chart page →

8,115
jspolicyloftVerified publisher0.2.21 of 1See more

jspolicy loft 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
loftsh/jspolicy:0.2.225deb9bd2683
stdlib@go1.17.13
1.21.12

Open the chart page →

2,313
vcluster-eksloftVerified publisher0.0.0-ci.33 of 4See more

vcluster-eks loft 0.0.0-ci.3

3 of the 4 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
public.ecr.aws/eks-distro/etcd-io/etcd:v3.5.6-eks-1-24-7efa6dee17ed2
stdlib@go1.16.15
1.21.12
public.ecr.aws/eks-distro/kubernetes/kube-apiserver:v1.24.9-eks-1-24-772e06b605692
stdlib@go1.18.9
1.21.12
public.ecr.aws/eks-distro/kubernetes/kube-controller-manager:v1.24.9-eks-1-24-7eaea8c230432
stdlib@go1.18.9
1.21.12

Open the chart page →

3,314
vcluster-k0sloftVerified publisher0.0.0-ci.31 of 2See more

vcluster-k0s loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
stdlib@go1.19.4
1.21.12

Open the chart page →

3,154
log2rbac-operatorlog2rbac-operator0.0.51 of 1See more

log2rbac-operator log2rbac-operator 0.0.5

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
jkremser/log2rbac:v0.0.5e35cf56ef183
stdlib@go1.17.6
1.21.12

Open the chart page →

1,953
logclilogcliVerified publisher0.1.01 of 1See more

logcli logcli 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-24791.

Container imageDigestPackageFixed in
grafana/logcli:main-c90366d-amd643d85bb66e39b
stdlib@go1.16.2
1.21.12

Open the chart page →

2,955

Container images carrying it

2,710 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.21.12
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.21.12
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.21.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.21.12
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.21.12
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.21.12
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.21.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.21.12
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.21.12
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.21.12
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.