CVE-2024-34155
MediumAdvisory
Published 6 Sept 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 4.3
- base score, highest
- EPSS
- 0.008
- 56th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,322
- of 17,797 indexed, latest versions
- Container images
- 2,781
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Stack exhaustion in all Parse functions in go/parser
Carried by container images the latest versions of 2,322 of 17,797 indexed charts deploy, on 2,781 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+134 more | 1.22.7 | 2,781 |
- OSV records
- DEBIAN-CVE-2024-34155GO-2024-3105
- Also known as
- BIT-golang-2024-34155
Charts affected
2,322 by stars
Container images carrying it
2,781 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| bitnamilegacy/ | cbf54314c401 | stdlib | 1.22.7 | 1 |
| bitnamilegacy/ | dba59d740e13 | stdlib | 1.22.7 | 1 |
| bitnami/ | 0516f987fae2 | stdlib | 1.22.7 | 1 |
| bitpoke/ | c5eed1ddf692 | stdlib | 1.22.7 | 1 |
| bitpoke/ | 21284d1df473 | stdlib | 1.22.7 | 1 |
| bitpoke/ | 7fb3aad37b5f | stdlib | 1.22.7 | 1 |
| blackducksoftware/ | 5c97f3a3f8b7 | stdlib | 1.22.7 | 1 |
| blipai/ | 737d5d19a312 | stdlib | 1.22.7 | 1 |
| bloomberg/ | 8520120f5598 | stdlib | 1.22.7 | 1 |
| breton/ | 41b1bb483aa2 | stdlib | 1.22.7 | 1 |
| bsgrigorov/ | 45ab095f09c8 | stdlib | 1.22.7 | 1 |
| btcpayserver/ | e9585b68dc6b | stdlib | 1.22.7 | 1 |
| buddyspencer/ | 6b656f19b0c1 | stdlib | 1.22.7 | 1 |
| buddyspencer/ | 9e7dbf923c12 | stdlib | 1.22.7 | 1 |
| buildkite/ | aec38cfaae0e | stdlib | 1.22.7 | 1 |
| bulich/ | 6d0b780f7c7b | stdlib | 1.22.7 | 1 |
| burganbank/ | 9259c34e4037 | stdlib | 1.22.7 | 1 |
| bytesafe/ | ee287384c005 | stdlib | 1.22.7 | 1 |
| caarlos0/ | d11dec138900 | stdlib | 1.22.7 | 1 |
| calico/ | cef0c907b8f4 | stdlib | 1.22.7 | 1 |
| calico/ | e486870cfde8 | stdlib | 1.22.7 | 1 |
| calico/ | 8f04e4772a2b | stdlib | 1.22.7 | 1 |
| calico/ | eadb3a25109a | stdlib | 1.22.7 | 1 |
| calico/ | 385bf6391fea | stdlib | 1.22.7 | 1 |
| calico/ | d8c644a8a3ee | stdlib | 1.22.7 | 1 |
| camptocamp/ | acfafc308d88 | stdlib | 1.22.7 | 1 |
| captnbp/ | 1600c5a253e0 | stdlib | 1.22.7 | 1 |
| caroga/ | f3233882b3bd | stdlib | 1.22.7 | 1 |
| casbin/ | 66f836ef778b | stdlib | 1.22.7 | 1 |
| casbin/ | 770ad9ec3190 | stdlib | 1.22.7 | 1 |
| castopod/ | 1fd37280cbb2 | stdlib | 1.22.7 | 1 |
| cbeneke/ | dc658078d7ba | stdlib | 1.22.7 | 1 |
| cfcontainerization/ | 82fa261c18a8 | stdlib | 1.22.7 | 1 |
| cfcontainerization/ | 58fb1c173a46 | stdlib | 1.22.7 | 1 |
| cgtysylr/ | aec0f8a38a77 | stdlib | 1.22.7 | 1 |
| chaerr/ | 66833deec017 | stdlib | 1.22.7 | 1 |
| chainflag/ | ac642796bcb6 | stdlib | 1.22.7 | 1 |
| chainsafe/ | 7b9fe4aa8073 | stdlib | 1.22.7 | 1 |
| chandanteekinavar/ | c96f759b6ce4 | stdlib | 1.22.7 | 1 |
| chaosnative/ | 72ee352bc333 | stdlib | 1.22.7 | 1 |
| chaosnative/ | 62cf6adc355e | stdlib | 1.22.7 | 1 |
| chaosnative/ | e7bcff4a20c0 | stdlib | 1.22.7 | 1 |
| charmcli/ | 39523c1a6ba8 | stdlib | 1.22.7 | 1 |
| chibisafe/ | 3da4fcbc1a18 | stdlib | 1.22.7 | 1 |
| chirpstack/ | e0b23dfd24d6 | stdlib | 1.22.7 | 1 |
| chirpstack/ | fb7667fe037f | stdlib | 1.22.7 | 1 |
| chirpstack/ | ce3f2cdca8a9 | stdlib | 1.22.7 | 1 |
| chirpstack/ | c0bbbb7a3f1e | stdlib | 1.22.7 | 1 |
| chirpstack/ | c98d7fe06bce | stdlib | 1.22.7 | 1 |
| chrislusf/ | 634b094b2183 | stdlib | 1.22.7 | 1 |