StackRadar

CVE-2024-32655

High

Advisory

Published 9 May 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
22
deployed by those charts
Fix available
1 of 1
affected package

Npgsql vulnerable to SQL Injection via Protocol Message Size Overflow

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 22 images.

Affected packageAffected versionsFixed inImages
Npgsqlnuget3.1.3, 4.1.3, 5.0.10, 5.0.11+4 more4.0.14, 4.1.13, 5.0.18, 6.0.11+1 more22
OSV records
GHSA-x9vc-6hfv-hg8c

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
servarrservarr1.0.23 of 10See more

servarr servarr 1.0.2

3 of the 10 container images this version deploys carry CVE-2024-32655.

Container imageDigestPackageFixed in
ghcr.io/onedr0p/prowlarr-develop:1.14.0.4286c77d84ebf7a6
Npgsql@7.0.6
7.0.7
ghcr.io/onedr0p/radarr:5.3.6.86128d299e59fce7
Npgsql@7.0.6
7.0.7
ghcr.io/onedr0p/sonarr:4.0.2.118327ffdcc8a937
Npgsql@7.0.4
7.0.7

Open the chart page →

14,238
eshoponabpabp-charts1.0.07 of 15See more

eshoponabp abp-charts 1.0.0

7 of the 15 container images this version deploys carry CVE-2024-32655.

Container imageDigestPackageFixed in
ghcr.io/volosoft/eshoponabp/app-authserver:1.0.022ce496c67d7
Npgsql@6.0.2
6.0.11
ghcr.io/volosoft/eshoponabp/service-administration:1.0.0206a9bee17a8
Npgsql@6.0.2
6.0.11
ghcr.io/volosoft/eshoponabp/service-basket:1.0.0dd5ce454072e
Npgsql@6.0.2
6.0.11
ghcr.io/volosoft/eshoponabp/service-catalog:1.0.07ecb00f53d99
Npgsql@6.0.2
6.0.11
ghcr.io/volosoft/eshoponabp/service-identity:1.0.0e53bf47b62d0
Npgsql@6.0.2
6.0.11
ghcr.io/volosoft/eshoponabp/service-ordering:1.0.15e836b17337f
Npgsql@6.0.2
6.0.11
ghcr.io/volosoft/eshoponabp/service-payment:1.0.02ca91145099c
Npgsql@6.0.2
6.0.11

Open the chart page →

19,799
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2024-32655.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
Npgsql@5.0.11
5.0.18

Open the chart page →

11,558
voice-biometricslumenvox2.0.17 of 26See more

voice-biometrics lumenvox 2.0.1

7 of the 26 container images this version deploys carry CVE-2024-32655.

Container imageDigestPackageFixed in
lumenvox/cloud-assure-identity:2.0.0147854a3c916
Npgsql@5.0.10
5.0.18
lumenvox/cloud-audit:2.0.079428add7f38
Npgsql@5.0.10
5.0.18
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
Npgsql@5.0.10
5.0.18
lumenvox/cloud-deployment:2.0.0ea8110886d38
Npgsql@5.0.10
5.0.18
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
Npgsql@5.0.10
5.0.18
lumenvox/cloud-reporting:2.0.07a9ffdc2178a
Npgsql@5.0.10
5.0.18
lumenvox/cloud-transaction:2.0.08b74f9d3ba09
Npgsql@5.0.10
5.0.18

Open the chart page →

70,741
prowlarrbeluga-cloudVerified publisher1.0.11 of 1See more

prowlarr beluga-cloud 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-32655.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/prowlarr/prowlarr:1.4.1.3258aa774b3c3425
Npgsql@5.0.11
5.0.18

Open the chart page →

169
servarrjacobcolvinVerified publisher0.1.21 of 2See more

servarr jacobcolvin 0.1.2

1 of the 2 container images this version deploys carry CVE-2024-32655.

Container imageDigestPackageFixed in
linuxserver/radarr:4.2.42f7a7b7a0ca6
Npgsql@6.0.3
6.0.11

Open the chart page →

206
bagetsimcube1.0.51 of 1See more

baget simcube 1.0.5

1 of the 1 container images this version deploys carry CVE-2024-32655.

Container imageDigestPackageFixed in
loicsharma/baget:0b46f0ec87216e1dc6839277712ee07c1c2b611aa880c78ae80b
Npgsql@4.1.3
4.1.13

Open the chart page →

1,687
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-32655.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
Npgsql@3.1.3
4.0.14

Open the chart page →

8,262
workerappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

workerapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-32655.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
Npgsql@3.1.3
4.0.14

Open the chart page →

3,329
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2024-32655.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
Npgsql@3.1.3
4.0.14

Open the chart page →

8,262
workerappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

workerapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-32655.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
Npgsql@3.1.3
4.0.14

Open the chart page →

3,329

Container images carrying it

22 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
kodekloud/examplevotingapp_worker:v1741e3aaaa812
Npgsql@3.1.3
4.0.14
4
linuxserver/radarr:4.2.42f7a7b7a0ca6
Npgsql@6.0.3
6.0.11
1
loicsharma/baget:0b46f0ec87216e1dc6839277712ee07c1c2b611aa880c78ae80b
Npgsql@4.1.3
4.1.13
1
lumenvox/cloud-assure-identity:2.0.0147854a3c916
Npgsql@5.0.10
5.0.18
1
lumenvox/cloud-audit:2.0.079428add7f38
Npgsql@5.0.10
5.0.18
1
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
Npgsql@5.0.10
5.0.18
1
lumenvox/cloud-deployment:2.0.0ea8110886d38
Npgsql@5.0.10
5.0.18
1
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
Npgsql@5.0.10
5.0.18
1
lumenvox/cloud-reporting:2.0.07a9ffdc2178a
Npgsql@5.0.10
5.0.18
1
lumenvox/cloud-transaction:2.0.08b74f9d3ba09
Npgsql@5.0.10
5.0.18
1
ghcr.io/beluga-cloud/prowlarr/prowlarr:1.4.1.3258aa774b3c3425
Npgsql@5.0.11
5.0.18
1
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
Npgsql@5.0.11
5.0.18
1
ghcr.io/onedr0p/prowlarr-develop:1.14.0.4286c77d84ebf7a6
Npgsql@7.0.6
7.0.7
1
ghcr.io/onedr0p/radarr:5.3.6.86128d299e59fce7
Npgsql@7.0.6
7.0.7
1
ghcr.io/onedr0p/sonarr:4.0.2.118327ffdcc8a937
Npgsql@7.0.4
7.0.7
1
ghcr.io/volosoft/eshoponabp/app-authserver:1.0.022ce496c67d7
Npgsql@6.0.2
6.0.11
1
ghcr.io/volosoft/eshoponabp/service-administration:1.0.0206a9bee17a8
Npgsql@6.0.2
6.0.11
1
ghcr.io/volosoft/eshoponabp/service-basket:1.0.0dd5ce454072e
Npgsql@6.0.2
6.0.11
1
ghcr.io/volosoft/eshoponabp/service-catalog:1.0.07ecb00f53d99
Npgsql@6.0.2
6.0.11
1
ghcr.io/volosoft/eshoponabp/service-identity:1.0.0e53bf47b62d0
Npgsql@6.0.2
6.0.11
1
ghcr.io/volosoft/eshoponabp/service-ordering:1.0.15e836b17337f
Npgsql@6.0.2
6.0.11
1
ghcr.io/volosoft/eshoponabp/service-payment:1.0.02ca91145099c
Npgsql@6.0.2
6.0.11
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.