StackRadar

CVE-2024-26134

High

Advisory

Published 19 Feb 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.012
66th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Potential buffer overflow in CBOR2 decoder

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
cbor2pypi5.1.0, 5.4.0, 5.4.3, 5.4.6+2 more5.6.29
OSV records
GHSA-375g-39jq-vq7mPYSEC-2024-155

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
home-assistantgeek-cookbookVerified publisher13.5.01 of 1See more

home-assistant geek-cookbook 13.5.0

1 of the 1 container images this version deploys carry CVE-2024-26134.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
cbor2@5.4.3
5.6.2

Open the chart page →

7,705
homeassistantvolker-raschekVerified publisher0.2.31 of 1See more

homeassistant volker-raschek 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-26134.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.12.48d000332b09b
cbor2@5.5.1
5.6.2

Open the chart page →

6,041
psonoankra-chartsVerified publisher1.2.01 of 2See more

psono ankra-charts 1.2.0

1 of the 2 container images this version deploys carry CVE-2024-26134.

Container imageDigestPackageFixed in
psono/psono-server:5.0.03b974b43ea03
cbor2@5.4.3
5.6.2

Open the chart page →

2,388
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2024-26134.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
cbor2@5.6.0
5.6.2

Open the chart page →

9,412
home-assistantdamounVerified publisher1.1.01 of 1See more

home-assistant damoun 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-26134.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
cbor2@5.5.1
5.6.2

Open the chart page →

6,179
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-26134.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
cbor2@5.4.6
5.6.2

Open the chart page →

14,627
jx-app-anchorejenkins-x0.0.41 of 2See more

jx-app-anchore jenkins-x 0.0.4

1 of the 2 container images this version deploys carry CVE-2024-26134.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.7.1ed9b3badd17c
cbor2@5.1.0
5.6.2

Open the chart page →

9,854
home-assistantkfirfer0.5.41 of 1See more

home-assistant kfirfer 0.5.4

1 of the 1 container images this version deploys carry CVE-2024-26134.

Container imageDigestPackageFixed in
homeassistant/home-assistant:2023.10.3021e2afc6e57
cbor2@5.4.6
5.6.2

Open the chart page →

6,447
anchore-engineopencloudcx1.13.01 of 2See more

anchore-engine opencloudcx 1.13.0

1 of the 2 container images this version deploys carry CVE-2024-26134.

Container imageDigestPackageFixed in
anchore/anchore-engine:v0.10.0bde9eedf639d
cbor2@5.4.0
5.6.2

Open the chart page →

18,023

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
anchore/anchore-engine:v0.10.0bde9eedf639d
cbor2@5.4.0
5.6.2
1
anchore/anchore-engine:v0.7.1ed9b3badd17c
cbor2@5.1.0
5.6.2
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
cbor2@5.4.6
5.6.2
1
homeassistant/home-assistant:2023.12.48d000332b09b
cbor2@5.5.1
5.6.2
1
localstack/localstack:3.19d278167f2b7
cbor2@5.6.0
5.6.2
1
psono/psono-server:5.0.03b974b43ea03
cbor2@5.4.3
5.6.2
1
ghcr.io/home-assistant/home-assistant:2022.5.4ec6d67fbedfa
cbor2@5.4.3
5.6.2
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
cbor2@5.5.1
5.6.2
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
cbor2@5.4.6
5.6.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.