StackRadar

CVE-2024-34155

Medium

Advisory

Published 6 Sept 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.008
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,479
of 17,844 indexed, latest versions
Container images
2,905
deployed by those charts
Fix available
1 of 2
affected packages

Stack exhaustion in all Parse functions in go/parser

Carried by container images the latest versions of 2,479 of 17,844 indexed charts deploy, on 2,905 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+137 more1.22.72,905
OSV records
DEBIAN-CVE-2024-34155GO-2024-3105
Also known as
BIT-golang-2024-34155

Charts affected

2,479 by stars
ChartLatestAffected imagesRadar Score
lokiot-container-kit1.0.13 of 5See more

loki ot-container-kit 1.0.1

3 of the 5 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
grafana/loki:3.1.0d947e68a84d9
stdlib@go1.22.2
1.22.7
grafana/promtail:3.0.0d3de3da9431c
stdlib@go1.21.9
1.22.7
prom/memcached-exporter:v0.14.2d8a61419b841
stdlib@go1.21.5
1.22.7

Open the chart page →

4,837
mongodb-operatorot-container-kit0.3.11 of 1See more

mongodb-operator ot-container-kit 0.3.1

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
quay.io/opstree/mongodb-operator:v0.3.0879b9bead838
stdlib@go1.17.8
1.22.7

Open the chart page →

1,869
pgaot-container-kit1.0.34 of 6See more

pga ot-container-kit 1.0.3

4 of the 6 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
grafana/grafana:11.1.0079600c9517b
stdlib@go1.22.4
1.22.7
quay.io/prometheus-operator/prometheus-operator:v0.75.1a7cc63108511
stdlib@go1.22.4
1.22.7
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
stdlib@go1.22.3
1.22.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
stdlib@go1.21.8
1.22.7

Open the chart page →

5,176
vmot-container-kit0.0.34 of 7See more

vm ot-container-kit 0.0.3

4 of the 7 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
grafana/grafana:11.1.4886b56d5534e
stdlib@go1.22.4
1.22.7
victoriametrics/operator:v0.47.271be93cfafb6
stdlib@go1.23.0
1.22.7
quay.io/prometheus/node-exporter:v1.8.24032c6d5bfd7
stdlib@go1.22.5
1.22.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.13.0639a1e2da549
stdlib@go1.22.5
1.22.7

Open the chart page →

5,475
akash-nodeovrclk-211.1.31 of 1See more

akash-node ovrclk-2 11.1.3

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/akash-network/node:0.36.08763983b31f1
stdlib@go1.21.10
1.22.7

Open the chart page →

1,339
console-apiovrclk-20.1.11 of 1See more

console-api ovrclk-2 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/akash-network/console-api:2.64.0ba359097329d
stdlib@go1.21.13
1.22.7

Open the chart page →

3,732
kubernetes-taggeroxyno-zetaVerified publisher1.1.21 of 1See more

kubernetes-tagger oxyno-zeta 1.1.2

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
oxynozeta/kubernetes-tagger:1.3.0a153c386f5af
stdlib@go1.17
1.22.7

Open the chart page →

1,829
arpap2p-avs0.1.31 of 2See more

arpa p2p-avs 0.1.3

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
stdlib@go1.22.5
1.22.7

Open the chart page →

1,990
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/automata-network/multi-prover-avs/operator:v0.6.0752f1aa02438
stdlib@go1.22.1
1.22.7

Open the chart page →

3,847
avap2p-avs0.1.01 of 1See more

ava p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
avaprotocol/ap-avs:1.2.0c430ea5c37d6
stdlib@go1.22.5
1.22.7

Open the chart page →

3,462
eigendap2p-avs0.1.12 of 3See more

eigenda p2p-avs 0.1.1

2 of the 3 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/layr-labs/eigenda/opr-node:0.8.46650119a385f
stdlib@go1.21.1
1.22.7
ghcr.io/layr-labs/eigenda/opr-nodeplugin:0.8.4e459ad3ae758
stdlib@go1.21.1
1.22.7

Open the chart page →

2,342
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
codeurjc/toposervice:v1.239fb4c11e6a49
stdlib@go1.18.10
1.22.7

Open the chart page →

28,753
alistpanghuli0.1.51 of 2See more

alist panghuli 0.1.5

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
xhofe/alist:v3.24.033f15a31be6c
stdlib@go1.20.5
1.22.7

Open the chart page →

1,998
cloudrevepanghuli0.1.01 of 1See more

cloudreve panghuli 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
cloudreve/cloudreve:3.8.009093aec5a20
stdlib@go1.20
1.22.7

Open the chart page →

2,320
Parpar0.1.01 of 1See more

Par par 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/jmcgrath207/par:v0.1.09977511cb142
stdlib@go1.19.10
1.22.7

Open the chart page →

893
parcaparca4.19.02 of 2See more

parca parca 4.19.0

2 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
stdlib@go1.21.1
1.22.7
ghcr.io/parca-dev/parca-agent:v0.28.06d6794f45f3e
stdlib@go1.21.4
1.22.7

Open the chart page →

3,368
parcaparca-chart0.1.01 of 1See more

parca parca-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/parca-dev/parca:v0.20.00d1df8f436f7
stdlib@go1.21.1
1.22.7

Open the chart page →

1,988
istio-operatorparticuleio1.7.01 of 1See more

istio-operator particuleio 1.7.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
gcr.io/istio-testing/operator:latest8d4576f7b98f
stdlib@go1.22.5
1.22.7

Open the chart page →

4,318
scaleway-webhookparticuleio0.0.11 of 1See more

scaleway-webhook particuleio 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
stdlib@go1.15.2
1.22.7

Open the chart page →

2,356
hammondpascaliskeVerified publisher2.0.01 of 2See more

hammond pascaliske 2.0.0

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
alfhou/hammond:v0.0.24c85dc0293aa1
stdlib@go1.20.6
1.22.7

Open the chart page →

1,802
plausible-exporterpascaliskeVerified publisher1.0.01 of 1See more

plausible-exporter pascaliske 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/riesinger/plausible-exporter:1.1.061112cda1be5
stdlib@go1.19.7
1.22.7

Open the chart page →

701
minecraftpaul1365972-mc3.0.11 of 1See more

minecraft paul1365972-mc 3.0.1

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
itzg/minecraft-server:latest77280d10744f
stdlib@go1.22.2
1.22.7

Open the chart page →

4,462
pax-prometheuspaxtecnologia0.7.21 of 8See more

pax-prometheus paxtecnologia 0.7.2

1 of the 8 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
registry.k8s.io/prometheus-adapter/prometheus-adapter:v0.12.0932eae60e2bc
stdlib@go1.22.2
1.22.7

Open the chart page →

1,840
permission-managerpermission-manager1.0.0-seal1 of 1See more

permission-manager permission-manager 1.0.0-seal

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
stdlib@go1.16.8
1.22.7

Open the chart page →

2,263
pet-battle-infrapetbattle1.0.321 of 2See more

pet-battle-infra petbattle 1.0.32

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
stdlib@go1.16.12
1.22.7

Open the chart page →

15,586
pet-battle-tournamentpetbattle1.0.401 of 3See more

pet-battle-tournament petbattle 1.0.40

1 of the 3 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.8bb5e052770e5
stdlib@go1.16.12
1.22.7

Open the chart page →

15,586
whoamiphilippwaller1.0.31 of 1See more

whoami philippwaller 1.0.3

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
traefik/whoami:v1.8.08d0f943abdbf
stdlib@go1.17.7
1.22.7

Open the chart page →

1,008
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
stdlib@go1.16
1.22.7

Open the chart page →

6,593
container-agentphntom100.0.11 of 1See more

container-agent phntom 100.0.1

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
circleci/container-agent:34d8d0ae5efc3
stdlib@go1.19.7
1.22.7

Open the chart page →

1,975
external-dns-host-networkphntom0.0.121 of 1See more

external-dns-host-network phntom 0.0.12

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
phntom/external-dns-host-network:0.0.123adadbac8443
stdlib@go1.19.2
1.22.7

Open the chart page →

5,089
goalertphntom0.0.291 of 1See more

goalert phntom 0.0.29

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
phntom/goalert:0.0.298ca4df55499b
stdlib@go1.21.5
1.22.7

Open the chart page →

1,048
kochiphntom1.1.41 of 1See more

kochi phntom 1.1.4

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
phntom/kochi:1.1.33b82358bd56e
stdlib@go1.15.5
1.22.7

Open the chart page →

2,960
loki-stackphntom2.10.22 of 2See more

loki-stack phntom 2.10.2

2 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
grafana/loki:2.4.2b3af8ead67d7
stdlib@go1.17.2
1.22.7
grafana/promtail:2.4.2626900031c4e
stdlib@go1.17.2
1.22.7

Open the chart page →

5,723
mindavphntom0.1.61 of 2See more

mindav phntom 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
phntom/mindav:0.1.7-kix35695f546abbb
stdlib@go1.16.2
1.22.7

Open the chart page →

4,195
npre-essentialsphntom0.1.6013 of 22See more

npre-essentials phntom 0.1.60

13 of the 22 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.22.7
grafana/loki:2.6.11ee60f980950
stdlib@go1.17.9
1.22.7
grafana/promtail:2.7.0c16c710f7333
stdlib@go1.19.2
1.22.7
phntom/chartmuseum:v0.15.29242b4df9e65
stdlib@go1.18.5
1.22.7
phntom/kochi:1.1.33b82358bd56e
stdlib@go1.15.5
1.22.7
phntom/oauth2-proxy:v7.3.48ea656a2a895
stdlib@go1.19.2
1.22.7
quay.io/groundcover/grafana:9.3.18c65b333a3d3
stdlib@go1.19.3
1.22.7
quay.io/prometheus-operator/prometheus-operator:v0.61.1cd7d1a82ef00
stdlib@go1.19.3
1.22.7
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
stdlib@go1.19.3
1.22.7
quay.io/prometheuscommunity/elasticsearch-exporter:v1.5.013a41e8ac836
stdlib@go1.18.4
1.22.7
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
stdlib@go1.19.2
1.22.7
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20220916-gd32f8c34339c5b2e3310d
stdlib@go1.19.1
1.22.7
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
stdlib@go1.19.3
1.22.7

Open the chart page →

26,965
prometheus-elasticsearch-exporterphntom4.5.11 of 2See more

prometheus-elasticsearch-exporter phntom 4.5.1

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
abutaha/aws-es-proxy:v1.1190ed2d1dfc8
stdlib@go1.14.1
1.22.7

Open the chart page →

2,031
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
stdlib@go1.19
1.22.7

Open the chart page →

93,123
blockmeta-servicepinaxVerified publisher0.0.31 of 1See more

blockmeta-service pinax 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/blockmeta-service:2f971e04f0a86e490b6
stdlib@go1.22.1
1.22.7

Open the chart page →

1,720
firehose-corepinaxVerified publisher0.1.11 of 2See more

firehose-core pinax 0.1.1

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-core:v1.10.222f84e3615c8
stdlib@go1.18.5
1.22.7

Open the chart page →

3,675
firehose-ethereumpinaxVerified publisher0.3.21 of 2See more

firehose-ethereum pinax 0.3.2

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.4-gethd7bdfa7b41da
stdlib@go1.18.5
1.22.7

Open the chart page →

7,575
substreams-tier-2pinaxVerified publisher0.0.81 of 1See more

substreams-tier-2 pinax 0.0.8

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
ghcr.io/streamingfast/firehose-ethereum:v2.12.489969b78fb07
stdlib@go1.18.5
1.22.7

Open the chart page →

5,223
pixie-operator-chartpixie0.1.71 of 3See more

pixie-operator-chart pixie 0.1.7

1 of the 3 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned1b6002156f56
stdlib@go1.21.7
1.22.7

Open the chart page →

1,907
pixie-operator-helm2-chartpixie0.1.21 of 2See more

pixie-operator-helm2-chart pixie 0.1.2

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinnedf9ea8cef95ac
stdlib@go1.19.6
1.22.7

Open the chart page →

1,762
planectlplanectlVerified publisher0.7.03 of 10See more

planectl planectl 0.7.0

3 of the 10 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
alpine/k8s:1.30.2cd560fce90f7
stdlib@go1.22.3
1.22.7
library/redis:7.4.2-alpine02419de7eddf
stdlib@go1.18.2
1.22.7
quay.io/argoproj/argocd:v2.14.115fc69e31c755
stdlib@go1.22.2
1.22.7

Open the chart page →

27,418
gitlab-runner-operatorpnnl-miscscripts0.1.61 of 1See more

gitlab-runner-operator pnnl-miscscripts 0.1.6

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
pnnlmiscscripts/gitlab-runner-operator:0.1.3-1155131891741
stdlib@go1.13.12
1.22.7

Open the chart page →

11,224
tenant-namespacepnnl-miscscripts0.6.231 of 1See more

tenant-namespace pnnl-miscscripts 0.6.23

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
stdlib@go1.18.2
1.22.7

Open the chart page →

2,590
tenant-namespace-operatorpnnl-miscscripts0.1.281 of 1See more

tenant-namespace-operator pnnl-miscscripts 0.1.28

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
pnnlmiscscripts/tenant-namespace-operator:0.1.24-18af4b7551d40
stdlib@go1.19.13
1.22.7

Open the chart page →

13,288
podnat-controllerpodnat-controller0.5.21 of 1See more

podnat-controller podnat-controller 0.5.2

1 of the 1 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
gutmensch/podnat-controller:0.5.2566979793fc4
stdlib@go1.22.3
1.22.7

Open the chart page →

987
libretimepodzone-chartsVerified publisher0.4.11 of 9See more

libretime podzone-charts 0.4.1

1 of the 9 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
library/postgres:16.24aea012537ed
stdlib@go1.18.2
1.22.7

Open the chart page →

11,545
static-sitepodzone-chartsVerified publisher0.1.11 of 2See more

static-site podzone-charts 0.1.1

1 of the 2 container images this version deploys carry CVE-2024-34155.

Container imageDigestPackageFixed in
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
stdlib@go1.20.10
1.22.7

Open the chart page →

5,977

Container images carrying it

2,905 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.22.7
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.22.7
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.22.7
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.22.7
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.22.7
1

syft 1.42.1 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.