StackRadar

CVE-2024-27289

High

Advisory

Published 4 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.008
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
104
of 17,781 indexed, latest versions
Container images
99
deployed by those charts
Fix available
2 of 2
affected packages

pgx SQL Injection via Line Comment Creation

Carried by container images the latest versions of 104 of 17,781 indexed charts deploy, on 99 images.

Affected packageAffected versionsFixed inImages
github.com/jackc/pgx/v4golangv4.6.0, v4.7.1, v4.8.1, v4.8.2-0.20200910143026-040df1ccef85+12 more4.18.289
github.com/jackc/pgxgolangv3.1.1-0.20180608201956-39bbc98d99d7+incompatible, v3.2.0+incompatible, v3.3.0+incompatible, v3.6.0+incompatible+1 more4.18.216
OSV records
GHSA-m7wr-2xf7-cm9p
Also known as
GO-2024-2605

Charts affected

104 by stars
ChartLatestAffected imagesRadar Score
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2024-27289.

Container imageDigestPackageFixed in
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/jackc/pgx/v4@v4.16.0
4.18.2

Open the chart page →

6,132
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-27289.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/jackc/pgx@v3.6.0+incompatible
4.18.2

Open the chart page →

13,459
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2024-27289.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.18.1
4.18.2
4.18.2

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2024-27289.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/jackc/pgx/v4@v4.18.1
4.18.2

Open the chart page →

2,022

Container images carrying it

99 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
layer5/meshery-osm:stable-latestec898e5786c6
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1
library/caddy:2.660fb54d36b4b
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1
library/telegraf:1.20.428e98eece020
github.com/jackc/pgx/v4@v4.6.0
4.18.2
1
library/telegraf:1.27507a3eecf809
github.com/jackc/pgx/v4@v4.18.1
4.18.2
1
library/telegraf:1.19.0-alpine794079a7f241
github.com/jackc/pgx/v4@v4.6.0
4.18.2
1
library/telegraf:1.19-alpineaddb86c0c520
github.com/jackc/pgx/v4@v4.6.0
4.18.2
1
library/vault:1.13.3f98ac9dd97b0
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.15.0
4.18.2
4.18.2
1
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1
moul/sshportal:v1.19.3332b603727c3
github.com/jackc/pgx/v4@v4.14.0
4.18.2
1
oryd/kratos:v1.1.08f15006a080d
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
github.com/jackc/pgx/v4@v4.18.1
4.18.2
1
otel/opentelemetry-collector-contrib:0.89.0995f17004231
github.com/jackc/pgx/v4@v4.18.1
4.18.2
1
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/jackc/pgx/v4@v4.18.1
4.18.2
1
reportportal/migrations:5.7.0da5d8e1395fe
github.com/jackc/pgx@v3.2.0+incompatible
4.18.2
1
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/jackc/pgx/v4@v4.16.0
4.18.2
1
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
github.com/jackc/pgx@v3.3.0+incompatible
4.18.2
1
supabase/gotrue:v2.91.07174d551d720
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1
thesisrobot/lnd:v0.16.4-beta-c287129953689
github.com/jackc/pgx/v4@v4.13.0
4.18.2
1
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
github.com/jackc/pgx/v4@v4.13.0
4.18.2
1
timescale/timescaledb:latest-pg12645fd9e92d76
github.com/jackc/pgx/v4@v4.16.1
4.18.2
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
github.com/jackc/pgx/v4@v4.16.1
4.18.2
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
github.com/jackc/pgx/v4@v4.16.1
4.18.2
1
treeverse/lakefs:0.69.0478f37a6cffc
github.com/jackc/pgx/v4@v4.10.1
4.18.2
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/jackc/pgx@v3.6.0+incompatible
4.18.2
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
github.com/jackc/pgx/v4@v4.8.2-0.20200910143026-040df1ccef85
4.18.2
1
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
github.com/jackc/pgx@v3.6.2+incompatible
4.18.2
1
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
github.com/jackc/pgx/v4@v4.14.0
4.18.2
1
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
github.com/jackc/pgx/v4@v4.17.1
4.18.2
1
ghcr.io/cncf/clowarden/dbmigrator:v0.2.3c022fd42de45
github.com/jackc/pgx/v4@v4.7.1
4.18.2
1
ghcr.io/cncf/gitvote/dbmigrator:v1.5.0f1e7efe440da
github.com/jackc/pgx/v4@v4.7.1
4.18.2
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
github.com/jackc/pgx/v4@v4.18.0
4.18.2
1
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
github.com/jackc/pgx/v4@v4.10.1
4.18.2
1
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1
ghcr.io/openfaasltd/postgres-connector:0.2.3379e583a0a75
github.com/jackc/pgx@v3.6.2+incompatible
4.18.2
1
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
github.com/jackc/pgx/v4@v4.15.0
4.18.2
1
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
github.com/jackc/pgx/v4@v4.8.1
4.18.2
1
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
github.com/jackc/pgx/v4@v4.18.1
4.18.2
1
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
github.com/jackc/pgx/v4@v4.14.0
4.18.2
1
quay.io/argoproj/argocli:v3.5.591b9825f09a8
github.com/jackc/pgx/v4@v4.18.1
4.18.2
1
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
github.com/jackc/pgx/v4@v4.18.1
4.18.2
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
github.com/jackc/pgx/v4@v4.13.0
4.18.2
1
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
github.com/jackc/pgx/v4@v4.13.0
4.18.2
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.18.1
4.18.2
4.18.2
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
github.com/jackc/pgx/v4@v4.18.1
4.18.2
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
github.com/jackc/pgx/v4@v4.18.0
4.18.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.