StackRadar

CVE-2024-34155

Medium

Advisory

Published 6 Sept 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.008
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,479
of 17,844 indexed, latest versions
Container images
2,905
deployed by those charts
Fix available
1 of 2
affected packages

Stack exhaustion in all Parse functions in go/parser

Carried by container images the latest versions of 2,479 of 17,844 indexed charts deploy, on 2,905 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+137 more1.22.72,905
OSV records
DEBIAN-CVE-2024-34155GO-2024-3105
Also known as
BIT-golang-2024-34155

Charts affected

2,479 by stars
ChartLatestAffected imagesRadar Score
oadaoadaVerified publisher5.0.61 of 11See more

oada oada 5.0.6

1 of the 11 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
stdlib@go1.19.3
1.22.7

Open the chart page →

13,646
transfer.shobeoneVerified publisher1.0.51 of 1See more

transfer.sh obeone 1.0.5

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
dutchcoders/transfer.sh:v1.6.1-noroot8db9ade72a0d
stdlib@go1.20.11
1.22.7

Open the chart page →

1,183
open5gs-webuiopen5gs-webuiVerified publisher2.3.11 of 2See more

open5gs-webui open5gs-webui 2.3.1

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:4.4.14fe2bd7b4036
stdlib@go1.15.1
1.22.7

Open the chart page →

5,350
kruiseopenkruise1.9.11 of 2See more

kruise openkruise 1.9.1

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
openkruise/kruise-helm-hook:v0.1.0edc7cf9428fd
stdlib@go1.20.14
1.22.7

Open the chart page →

1,652
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
stdlib@go1.20.4
1.22.7

Open the chart page →

7,258
opikopikOfficialVerified publisher2.2.802 of 13See more

opik opik 2.2.80

2 of the 13 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
library/mysql:8.4.2ac80b6e09e5b
stdlib@go1.18.2
1.22.7
library/zookeeper:3.9.4dfa9ba46d14b
stdlib@go1.18.1
1.22.7

Open the chart page →

15,395
kubernetes-dashboard-proxyosc0.7.23 of 4See more

kubernetes-dashboard-proxy osc 0.7.2

3 of the 4 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.7.02e500d29e9d5
stdlib@go1.19
1.22.7
kubernetesui/metrics-scraper:v1.0.876049887f07a
stdlib@go1.18.2
1.22.7
quay.io/oauth2-proxy/oauth2-proxy:v7.1.3ecd26b74a01f
stdlib@go1.16
1.22.7

Open the chart page →

6,014
hlf-caowkin2.1.01 of 2See more

hlf-ca owkin 2.1.0

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:1.5.1c7f3422ec1d5
stdlib@go1.15.7
1.22.7

Open the chart page →

3,428
hlf-ordowkin3.1.01 of 1See more

hlf-ord owkin 3.1.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
hyperledger/fabric-orderer:2.2.137294e05209b
stdlib@go1.14.4
1.22.7

Open the chart page →

3,360
hlf-peerowkin5.1.01 of 1See more

hlf-peer owkin 5.1.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
hyperledger/fabric-peer:2.2.1bf4995c86af6
stdlib@go1.14.4
1.22.7

Open the chart page →

3,684
prometheus-cachethqoxyno-zetaVerified publisher1.1.11 of 1See more

prometheus-cachethq oxyno-zeta 1.1.1

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
oxynozeta/prometheus-cachethq:1.1.131f11669d597
stdlib@go1.15.1
1.22.7

Open the chart page →

1,714
ngrok-operatorpaganuzzi0.0.21 of 1See more

ngrok-operator paganuzzi 0.0.2

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/paganuzzi/ngrokoperator:latest5a10cd095699
stdlib@go1.15.12
1.22.7

Open the chart page →

2,808
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
stdlib@go1.20.5
1.22.7

Open the chart page →

7,211
patch-operatorpatch-operator0.1.112 of 2See more

patch-operator patch-operator 0.1.11

2 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
quay.io/redhat-cop/kube-rbac-proxy:v0.11.0c68135620167
stdlib@go1.15.15
1.22.7
quay.io/redhat-cop/patch-operator:v0.1.11030ade9b9428
stdlib@go1.21.9
1.22.7

Open the chart page →

7,942
pdf-editor-helmpdf-editor-web1.0.02 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

2 of the 4 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-backend-rotate316e203b8bf5
stdlib@go1.18.7
1.22.7
dipugodocker/pdf-editor:1.0-backend-merge70b07544a604
stdlib@go1.18.7
1.22.7

Open the chart page →

4,240
spirephilips-labsVerified publisher0.12.25 of 6See more

spire philips-labs 0.12.2

5 of the 6 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/spiffe/spiffe-csi-driver:0.2.34144101005b2
stdlib@go1.20.1
1.22.7
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
stdlib@go1.20.1
1.22.7
ghcr.io/spiffe/spire-controller-manager:0.2.25e90b2d092df
stdlib@go1.20.1
1.22.7
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
stdlib@go1.20.1
1.22.7
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
stdlib@go1.19
1.22.7

Open the chart page →

7,282
chadbotphntom0.2.31 of 1See more

chadbot phntom 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
phntom/chadbot:0.2.397c28e4178ad
stdlib@go1.21.5
1.22.7

Open the chart page →

1,099
chartmuseumphntom4.0.201 of 1See more

chartmuseum phntom 4.0.20

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
phntom/chartmuseum:v0.16.053883b65d9b7
stdlib@go1.19.3
1.22.7

Open the chart page →

2,937
phonebook-chartphonebook-chart0.1.01 of 3See more

phonebook-chart phonebook-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.22.7

Open the chart page →

3,046
phpipamphpipam-helmVerified publisher1.0.121 of 3See more

phpipam phpipam-helm 1.0.12

1 of the 3 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
library/mysql:8.0.40d58ac93387f6
stdlib@go1.18.2
1.22.7

Open the chart page →

3,884
pipelinewise-operatorpipelinewise-operatorVerified publisher0.5.11 of 1See more

pipelinewise-operator pipelinewise-operator 0.5.1

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
dirathea/pipelinewise-operator:v0.5.08d4c9f773ae1
stdlib@go1.15.8
1.22.7

Open the chart page →

2,117
secrets-store-csi-driver-provider-awsportefaix-hub0.4.01 of 1See more

secrets-store-csi-driver-provider-aws portefaix-hub 0.4.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Open the chart page →

2,214
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
stdlib@go1.14.4
1.22.7

Open the chart page →

33,368
postgres-backuppostgres-backup0.3.02 of 2See more

postgres-backup postgres-backup 0.3.0

2 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
library/postgres:14.13162a6ead070
stdlib@go1.16.7
1.22.7
nerzhul/mc-arm64:2020.10.034215df511f31
stdlib@go1.15.2
1.22.7

Open the chart page →

5,471
rethinkdbpozetron1.1.91 of 1See more

rethinkdb pozetron 1.1.9

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
pozetroninc/rethinkdb-cluster:v2.4.16b06a098f994
stdlib@go1.16.9
1.22.7

Open the chart page →

2,909
privacyideaprivacyidea1.0.61 of 2See more

privacyidea privacyidea 1.0.6

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
library/mariadb:11.7.2fcc7fcd7114a
stdlib@go1.18.2
1.22.7

Open the chart page →

5,795
prometheus-druid-exporterprometheus-communityVerified publisher1.2.01 of 1See more

prometheus-druid-exporter prometheus-community 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
quay.io/opstree/druid-exporter:v0.119f01c9c5c2e3
stdlib@go1.15.15
1.22.7

Open the chart page →

1,180
prometheusprometheus-worawutchan13.0.05 of 6See more

prometheus prometheus-worawutchan 13.0.0

5 of the 6 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
jimmidyson/configmap-reload:v0.4.017d34fd73f9e
stdlib@go1.14.4
1.22.7
prom/pushgateway:v1.3.0c0d39b8d4cfe
stdlib@go1.15.2
1.22.7
quay.io/prometheus/alertmanager:v0.21.024a5204b418e
stdlib@go1.14.4
1.22.7
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.22.7
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
stdlib@go1.15.3
1.22.7

Open the chart page →

9,931
operatorpunchplatform8.1.131 of 1See more

operator punchplatform 8.1.13

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/punchplatform/operator:8.1-dev2a9536c8cee2
stdlib@go1.22.0
1.22.7

Open the chart page →

722
kubernetes-dashboardpyalive-cdmswebappVerified publisher5.8.01 of 1See more

kubernetes-dashboard pyalive-cdmswebapp 5.8.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.6.1290bebc3cd96
stdlib@go1.19
1.22.7

Open the chart page →

1,659
phpqonstruktVerified publisher0.2.01 of 1See more

php qonstrukt 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
qonstrukt/php:8.4-v8-apache089af7925aa1
stdlib@go1.14.2
1.22.7

Open the chart page →

59,090
minecraft-serverqumine0.1.15001 of 1See more

minecraft-server qumine 0.1.1500

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
qumine/minecraft-server:v0.1.15c0b650d51132
stdlib@go1.19.4
1.22.7

Open the chart page →

7,089
rabbitmqrabbitmq-magefleet1.2.01 of 1See more

rabbitmq rabbitmq-magefleet 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
library/rabbitmq:4.1.0-management935b3f84c1e4
stdlib@go1.22.2
1.22.7

Open the chart page →

3,023
velero-s3-deploymentradar-baseVerified publisher0.4.32 of 4See more

velero-s3-deployment radar-base 0.4.3

2 of the 4 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
velero/velero:v1.9.0277fbfaf8dcf
stdlib@go1.18
1.22.7
velero/velero-plugin-for-aws:v1.5.03d2ea7aab32d
stdlib@go1.17.11
1.22.7

Open the chart page →

4,839
redis-enterprise-operatorredis-enterprise-operatorVerified publisher7.13.4-121 of 1See more

redis-enterprise-operator redis-enterprise-operator 7.13.4-12

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
redislabs/operator:7.4.2-2ecb101af0506
stdlib@go1.21.5
1.22.7

Open the chart page →

2,674
redis-sentinel-gatewayredis-sentinel-gatewayVerified publisher1.0.21 of 1See more

redis-sentinel-gateway redis-sentinel-gateway 1.0.2

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
promzeus/redis-sentinel-gateway:v182f6d56e280b
stdlib@go1.22.6
1.22.7

Open the chart page →

2,810
docker-registry-mirrorregistry-mirror1.0.11 of 1See more

docker-registry-mirror registry-mirror 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
library/registry:2.8.3a3d8aaa63ed8
stdlib@go1.20.8
1.22.7

Open the chart page →

551
reportportalreportportal-ioOfficialVerified publisher26.8.121 of 15See more

reportportal reportportal-io 26.8.12

1 of the 15 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.4-managementeb5295d08332
stdlib@go1.22.2
1.22.7

Open the chart page →

12,900
reservation-appreservation-app1.0.91 of 4See more

reservation-app reservation-app 1.0.9

1 of the 4 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
library/postgres:9.6caddd35b05cd
stdlib@go1.16.7
1.22.7

Open the chart page →

6,740
resurfaceresurfaceioVerified publisher3.9.02 of 3See more

resurface resurfaceio 3.9.0

2 of the 3 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
stdlib@go1.22.2
1.22.7
resurfaceio/resurface:3.7.84d5cda2f64109
stdlib@go1.23.0
1.22.7

Open the chart page →

7,625
backup-repository-serverriotkit-org4.0.01 of 1See more

backup-repository-server riotkit-org 4.0.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
stdlib@go1.17.13
1.22.7

Open the chart page →

2,062
cloudflare-tunnelrlex0.8.01 of 1See more

cloudflare-tunnel rlex 0.8.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
cloudflare/cloudflared:2023.10.0c18744ae1767
stdlib@go1.20.6
1.22.7

Open the chart page →

1,730
hcloud-fip-controllerrlex0.2.51 of 1See more

hcloud-fip-controller rlex 0.2.5

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
stdlib@go1.15.3
1.22.7

Open the chart page →

2,959
prometheus-webhook-dingtalkrlex0.0.31 of 1See more

prometheus-webhook-dingtalk rlex 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
timonwong/prometheus-webhook-dingtalk:v1.4.0a0fcc028bd8d
stdlib@go1.13.5
1.22.7

Open the chart page →

1,845
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
stdlib@go1.22.6
1.22.7

Open the chart page →

10,139
kimai2robjuz5.0.141 of 2See more

kimai2 robjuz 5.0.14

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:10.6.12-debian-11-r1678847062532a
stdlib@go1.19.7
1.22.7

Open the chart page →

4,882
grafanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

grafana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
grafana/grafana:8.3.4cf81d2c753c8
stdlib@go1.17.6
1.22.7

Open the chart page →

2,847
jaeger-collectorromanow-helm-chartsVerified publisher1.5.01 of 1See more

jaeger-collector romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
stdlib@go1.19.4
1.22.7

Open the chart page →

1,866
jaeger-queryromanow-helm-chartsVerified publisher1.5.01 of 1See more

jaeger-query romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
jaegertracing/jaeger-query:1.41.0b636f0f464bc
stdlib@go1.19.4
1.22.7

Open the chart page →

1,809
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
stdlib@go1.19.3
1.22.7

Open the chart page →

7,780

Container images carrying it

2,905 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.22.7
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.22.7
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.22.7
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.22.7
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.22.7
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.