StackRadar

CVE-2024-27289

High

Advisory

Published 4 Mar 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.008
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
104
of 17,781 indexed, latest versions
Container images
99
deployed by those charts
Fix available
2 of 2
affected packages

pgx SQL Injection via Line Comment Creation

Carried by container images the latest versions of 104 of 17,781 indexed charts deploy, on 99 images.

Affected packageAffected versionsFixed inImages
github.com/jackc/pgx/v4golangv4.6.0, v4.7.1, v4.8.1, v4.8.2-0.20200910143026-040df1ccef85+12 more4.18.289
github.com/jackc/pgxgolangv3.1.1-0.20180608201956-39bbc98d99d7+incompatible, v3.2.0+incompatible, v3.3.0+incompatible, v3.6.0+incompatible+1 more4.18.216
OSV records
GHSA-m7wr-2xf7-cm9p
Also known as
GO-2024-2605

Charts affected

104 by stars
ChartLatestAffected imagesRadar Score
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2024-27289.

Container imageDigestPackageFixed in
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/jackc/pgx/v4@v4.16.0
4.18.2

Open the chart page →

6,132
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-27289.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/jackc/pgx@v3.6.0+incompatible
4.18.2

Open the chart page →

13,459
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2024-27289.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.18.1
4.18.2
4.18.2

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2024-27289.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/jackc/pgx/v4@v4.18.1
4.18.2

Open the chart page →

2,022

Container images carrying it

99 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
github.com/jackc/pgx/v4@v4.18.1
4.18.2
6
caddy/ingress:v0.2.118d1366fc0e9
github.com/jackc/pgx/v4@v4.18.1
4.18.2
3
oryd/hydra:v2.2.02c93beb5e5f2
github.com/jackc/pgx/v4@v4.18.1
4.18.2
3
quay.io/devtron/clair:4.3.675fb847ac045
github.com/jackc/pgx/v4@v4.13.0
4.18.2
3
crate/crate_adapter:latestb8d89fa5d19b
github.com/jackc/pgx@v3.1.1-0.20180608201956-39bbc98d99d7+incompatible
4.18.2
2
hashicorp/vault:1.8.34db614d40d0e
github.com/jackc/pgx@v3.3.0+incompatible
4.18.2
2
hashicorp/vault:1.15.26b4e5dadf082
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.18.1
4.18.2
4.18.2
2
hashicorp/vault:1.12.18de4d5f31b38
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.15.0
4.18.2
4.18.2
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
github.com/jackc/pgx/v4@v4.18.0
4.18.2
2
oryd/kratos:v1.0.0d06fc5845f63
github.com/jackc/pgx/v4@v4.17.2
4.18.2
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
github.com/jackc/pgx/v4@v4.17.2
4.18.2
2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/jackc/pgx/v4@v4.18.1
4.18.2
2
rookout/controller:latest4451a6f6b8ec
github.com/jackc/pgx/v4@v4.18.1
4.18.2
2
rookout/data-on-prem:latest51c0fce64467
github.com/jackc/pgx/v4@v4.18.1
4.18.2
2
zhenghaoz/gorse-master:0.4.12033046b432ec
github.com/jackc/pgx/v4@v4.16.1
4.18.2
2
zhenghaoz/gorse-server:0.4.1239c565685b01
github.com/jackc/pgx/v4@v4.16.1
4.18.2
2
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
github.com/jackc/pgx/v4@v4.16.1
4.18.2
2
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
github.com/jackc/pgx/v4@v4.15.0
4.18.2
2
alex6021710/ai-scale-auth:latest6c7a47e470c3
github.com/jackc/pgx/v4@v4.10.1
4.18.2
1
alex6021710/ai-scale-migrator:latest744b8a924f35
github.com/jackc/pgx/v4@v4.10.1
4.18.2
1
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
github.com/jackc/pgx@v3.6.2+incompatible
4.18.2
1
aquasec/kube-bench:v0.6.9c329d73fea58
github.com/jackc/pgx/v4@v4.16.1
4.18.2
1
artifacthub/db-migrator:v1.23.028c13565ac5c
github.com/jackc/pgx/v4@v4.7.1
4.18.2
1
artifacthub/db-migrator:v1.19.02a746b289fcd
github.com/jackc/pgx/v4@v4.7.1
4.18.2
1
baserow/baserow:1.30.1df0c42eb67e8
github.com/jackc/pgx/v4@v4.18.0
4.18.2
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/jackc/pgx/v4@v4.18.1
4.18.2
1
cockroachdb/cockroach-operator:v2.1.0983312754620
github.com/jackc/pgx@v3.6.2+incompatible
4.18.2
1
dollarshaveclub/furan2:master14a257836529
github.com/jackc/pgx/v4@v4.8.1
4.18.2
1
factly/dega-api:0.15.166fafc7b0a17
github.com/jackc/pgx/v4@v4.10.1
4.18.2
1
factly/dega-server:0.15.194d21479382e
github.com/jackc/pgx/v4@v4.10.1
4.18.2
1
factly/kavach-server:0.22.3be85ff1b9bd3
github.com/jackc/pgx/v4@v4.10.1
4.18.2
1
factly/mande-server:0.34.1384d384310ef
github.com/jackc/pgx/v4@v4.10.1
4.18.2
1
factly/vidcheck-server:0.12.087064eb0463c
github.com/jackc/pgx/v4@v4.9.0
4.18.2
1
gboxproxy/gbox:v1.0.63a9f4a711d5c
github.com/jackc/pgx/v4@v4.14.0
4.18.2
1
goharbor/harbor-core:v2.9.06412d679fdc3
github.com/jackc/pgx/v4@v4.18.1
4.18.2
1
goharbor/harbor-core:v2.5.386bf3031f4a7
github.com/jackc/pgx/v4@v4.12.0
4.18.2
1
goharbor/harbor-jobservice:v2.9.039435daedd0c
github.com/jackc/pgx/v4@v4.18.1
4.18.2
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
github.com/jackc/pgx/v4@v4.12.0
4.18.2
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
github.com/jackc/pgx/v4@v4.12.0
4.18.2
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
github.com/jackc/pgx/v4@v4.12.0
4.18.2
1
grafana/agent:v0.40.3f6cbec9409be
github.com/jackc/pgx/v4@v4.18.1
4.18.2
1
hashicorp/boundary:0.8.1fb70bd9210ff
github.com/jackc/pgx/v4@v4.14.0
4.18.2
1
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.18.1
4.18.2
4.18.2
1
hashicorp/vault:1.14.0b2177a8bfe85
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.15.0
4.18.2
4.18.2
1
hashicorp/vault:1.8.4dfc3500beb0e
github.com/jackc/pgx@v3.3.0+incompatible
4.18.2
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
github.com/jackc/pgx/v4@v4.18.0
4.18.2
1
kubevious/ui:1.2.16233e84bdd59
github.com/jackc/pgx/v4@v4.14.0
4.18.2
1
layer5/meshery-app-mesh:stable-latest77d59943b3d6
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1
layer5/meshery-kuma:stable-latest9d25f029a8a2
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
github.com/jackc/pgx/v4@v4.17.2
4.18.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.