CVE-2024-28176
MediumAdvisory
Published 7 Mar 2024In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.021
- 81st percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 57
- of 17,781 indexed, latest versions
- Container images
- 53
- deployed by those charts
- Fix available
- 1 of 1
- affected package
jose vulnerable to resource exhaustion via specifically crafted JWE with compressed plaintext
Carried by container images the latest versions of 57 of 17,781 indexed charts deploy, on 53 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| josenpm | 1.26.1, 1.27.1, 2.0.4, 2.0.5+12 more | 2.0.7, 4.15.5 | 53 |
- OSV records
- GHSA-hhhv-q57g-882q
Charts affected
57 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| kubernetes-external-secretstrozz | 6.3.0 | 1 of 1See more | 2,838 |
| homarrvhdirkVerified publisher | 0.1.5 | 1 of 1See more | 2,789 |
| skoonervhdirkVerified publisher | 0.1.4 | 1 of 1See more | 1,341 |
| websitewaldo-visionVerified publisher | 0.33.0 | 1 of 2See more | 3,474 |
| temporalwenerme | 0.15.1 | 1 of 13See more | 22,665 |
| workadventureworkadventure | 1.1.0 | 1 of 9See more | 16,083 |
| skoonerxdVerified publisher | 1.1.0 | 1 of 1See more | 1,752 |
Container images carrying it
53 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 5bbc7647df07 | jose | 4.15.5 | 1 |
| quay.io/ | ce6938ff6709 | jose | 4.15.5 | 1 |
| quay.io/ | 4cd9ea9434c4 | jose | 4.15.5 | 1 |