CVE-2024-34155
MediumAdvisory
Published 6 Sept 2024In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 4.3
- base score, highest
- EPSS
- 0.008
- 56th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,322
- of 17,797 indexed, latest versions
- Container images
- 2,781
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Stack exhaustion in all Parse functions in go/parser
Carried by container images the latest versions of 2,322 of 17,797 indexed charts deploy, on 2,781 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| golang-1.19deb | 1.19.8-2 | no fix listed | 1 |
| stdlibgolang | go1.13, go1.13.1, go1.13.3, go1.13.4+134 more | 1.22.7 | 2,781 |
- OSV records
- DEBIAN-CVE-2024-34155GO-2024-3105
- Also known as
- BIT-golang-2024-34155
Charts affected
2,322 by stars
Container images carrying it
2,781 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| chrislusf/ | ed80f00fde46 | stdlib | 1.22.7 | 1 |
| chriswells0/ | f3918ec8471c | stdlib | 1.22.7 | 1 |
| circleci/ | 4d8d0ae5efc3 | stdlib | 1.22.7 | 1 |
| circleci/ | 9bdc62f02162 | stdlib | 1.22.7 | 1 |
| ciscolabs/ | 36d02faad958 | stdlib | 1.22.7 | 1 |
| ckan/ | ef8e5d3e6be1 | stdlib | 1.22.7 | 1 |
| clastix/ | 43d301afbca8 | stdlib | 1.22.7 | 1 |
| clickhouse/ | 512bb8a21483 | stdlib | 1.22.7 | 1 |
| clickhouse/ | dc5658853ce1 | stdlib | 1.22.7 | 1 |
| cloudbees/ | 1d44fb4f799b | stdlib | 1.22.7 | 1 |
| cloudbees/ | 8f102ef0383a | stdlib | 1.22.7 | 1 |
| cloudecho/ | f76ede067ab9 | stdlib | 1.22.7 | 1 |
| cloudentity/ | 9402ec4b5016 | stdlib | 1.22.7 | 1 |
| cloudentity/ | 8a1890eb8265 | stdlib | 1.22.7 | 1 |
| cloudentity/ | ee83cdd45b7b | stdlib | 1.22.7 | 1 |
| cloudentity/ | 5728654cecb7 | stdlib | 1.22.7 | 1 |
| cloudentity/ | 8ca94ae6acf4 | stdlib | 1.22.7 | 1 |
| cloudentity/ | c04eb10c77b7 | stdlib | 1.22.7 | 1 |
| cloudflare/ | 14d9c6b01b29 | stdlib | 1.22.7 | 1 |
| cloudflare/ | 5d5f70a59d5e | stdlib | 1.22.7 | 1 |
| cloudflare/ | c18744ae1767 | stdlib | 1.22.7 | 1 |
| cloudnativelabs/ | 0ec7cd73f43f | stdlib | 1.22.7 | 1 |
| cloudposse/ | 0d9507e8a760 | stdlib | 1.22.7 | 1 |
| cmacrae/ | fc5fecba436e | stdlib | 1.22.7 | 1 |
| cmacrae/ | dec8d490fe40 | stdlib | 1.22.7 | 1 |
| cockroachdb/ | 983312754620 | stdlib | 1.22.7 | 1 |
| codecov/ | de483faad6e5 | stdlib | 1.22.7 | 1 |
| codenotary/ | 7c85d7cc4f22 | stdlib | 1.22.7 | 1 |
| codercom/ | 1e2cc688008e | stdlib | 1.22.7 | 1 |
| codercom/ | 47605610ad8d | stdlib | 1.22.7 | 1 |
| coderenvs/ | 1deffc4670e6 | stdlib | 1.22.7 | 1 |
| codeskyblue/ | caa862590e34 | stdlib | 1.22.7 | 1 |
| conduction/ | 9cfeeb6c7c20 | stdlib | 1.22.7 | 1 |
| conduction/ | c36094a41369 | stdlib | 1.22.7 | 1 |
| conduction/ | ece1ab544c57 | stdlib | 1.22.7 | 1 |
| conduction/ | 25415534d245 | stdlib | 1.22.7 | 1 |
| conduction/ | 3423845692c1 | stdlib | 1.22.7 | 1 |
| conduction/ | 2744565516e8 | stdlib | 1.22.7 | 1 |
| conduction/ | e1d4ad1e22a8 | stdlib | 1.22.7 | 1 |
| conduction/ | b6f95c8ead7d | stdlib | 1.22.7 | 1 |
| conduction/ | 8f177f9f8a7b | stdlib | 1.22.7 | 1 |
| conduction/ | 24f03c57568f | stdlib | 1.22.7 | 1 |
| containous/ | 587162516502 | stdlib | 1.22.7 | 1 |
| coredns/ | 73ca82b4ce82 | stdlib | 1.22.7 | 1 |
| coredns/ | a0ead06651cf | stdlib | 1.22.7 | 1 |
| cortezaproject/ | 8eb7a26605c9 | stdlib | 1.22.7 | 1 |
| countly/ | f4cc7447c4f5 | stdlib | 1.22.7 | 1 |
| countly/ | e3c238248f99 | stdlib | 1.22.7 | 1 |
| countly/ | 2acbc11499b6 | stdlib | 1.22.7 | 1 |
| craftypath/ | 402a0024c732 | stdlib | 1.22.7 | 1 |