StackRadar

CVE-2024-34158

High

Advisory

Published 6 Sept 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.010
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,431
of 17,828 indexed, latest versions
Container images
2,874
deployed by those charts
Fix available
1 of 2
affected packages

Stack exhaustion in Parse in go/build/constraint

Carried by container images the latest versions of 2,431 of 17,828 indexed charts deploy, on 2,874 images.

Affected packageAffected versionsFixed inImages
golang-1.19deb1.19.8-2no fix listed1
stdlibgolanggo1.13, go1.13.1, go1.13.3, go1.13.4+137 more1.22.72,874
OSV records
DEBIAN-CVE-2024-34158GO-2024-3107
Also known as
BIT-golang-2024-34158

Charts affected

2,431 by stars
ChartLatestAffected imagesRadar Score
grafanatnh5.3.01 of 1See more

grafana tnh 5.3.0

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
grafana/grafana:7.0.3d72946c8e5d5
stdlib@go1.14.3
1.22.7

Open the chart page →

3,200
prometheustnh11.6.04 of 6See more

prometheus tnh 11.6.0

4 of the 6 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
prom/alertmanager:v0.20.07e4e9f7a0954
stdlib@go1.13.5
1.22.7
prom/prometheus:v2.19.0bfad037f95e5
stdlib@go1.14.4
1.22.7
prom/pushgateway:v1.2.00a9031142481
stdlib@go1.13.8
1.22.7
quay.io/prometheus/node-exporter:v1.0.1cf66a6bbd573
stdlib@go1.14.4
1.22.7

Open the chart page →

8,495
traefik-jwt-decodetraefik-jwt-decode0.1.01 of 1See more

traefik-jwt-decode traefik-jwt-decode 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
simonschneider/traefik-jwt-decode:latestd674ac370f80
stdlib@go1.17.13
1.22.7

Open the chart page →

1,311
nfs-servertranhailongVerified publisher0.1.21 of 1See more

nfs-server tranhailong 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
tranhailong/nfs-server:4.2-2-gcsfuse028662749be2
stdlib@go1.18.4
1.22.7

Open the chart page →

2,331
treenitytreenityVerified publisher0.1.31 of 4See more

treenity treenity 0.1.3

1 of the 4 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
library/nats:2.9.6-alpine3.16f576cdc17cc3
stdlib@go1.19.3
1.22.7

Open the chart page →

2,782
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
stdlib@go1.22.3
1.22.7

Open the chart page →

2,490
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
stdlib@go1.18.10
1.22.7
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
stdlib@go1.18.10
1.22.7

Open the chart page →

4,817
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
stdlib@go1.13.10
1.22.7

Open the chart page →

7,518
monitorortrozz0.0.11 of 1See more

monitoror trozz 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
monitoror/monitoror:44b88edcf51ff
stdlib@go1.14.6
1.22.7

Open the chart page →

3,111
clickhouse-operatortruefoundryVerified publisher0.1.12 of 3See more

clickhouse-operator truefoundry 0.1.1

2 of the 3 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.23.34baec90b20cd
stdlib@go1.20.14
1.22.7
altinity/metrics-exporter:0.23.32912a6c15b44
stdlib@go1.20.14
1.22.7

Open the chart page →

1,433
tfy-cloudflaredtruefoundryVerified publisher0.6.01 of 2See more

tfy-cloudflared truefoundry 0.6.0

1 of the 2 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
stdlib@go1.20
1.22.7

Open the chart page →

2,035
tfy-distributortruefoundryVerified publisher0.0.13 of 4See more

tfy-distributor truefoundry 0.0.1

3 of the 4 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
library/nats:2.10.7-alpine1bcddab51b80
stdlib@go1.21.5
1.22.7
natsio/nats-server-config-reloader:0.14.08c28b75bc416
stdlib@go1.20.5
1.22.7
natsio/prometheus-nats-exporter:0.13.02adf791d9f9f
stdlib@go1.21.3
1.22.7

Open the chart page →

17,408
tfy-inferentia-operatortruefoundryVerified publisher0.2.82 of 3See more

tfy-inferentia-operator truefoundry 0.2.8

2 of the 3 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
public.ecr.aws/neuron/neuron-device-plugin:2.23.30.075a6d5ce3bd3
stdlib@go1.20.4
1.22.7
public.ecr.aws/neuron/neuron-scheduler:2.23.30.04cd274463e6b
stdlib@go1.20.4
1.22.7

Open the chart page →

2,925
tfy-kservetruefoundryVerified publisher0.1.11 of 2See more

tfy-kserve truefoundry 0.1.1

1 of the 2 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
kserve/kserve-controller:v0.10.022ff858b57c1
stdlib@go1.18.10
1.22.7

Open the chart page →

1,178
tfy-llm-gateway-infratruefoundryVerified publisher0.2.102 of 3See more

tfy-llm-gateway-infra truefoundry 0.2.10

2 of the 3 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.23.774315beb57db
stdlib@go1.21.13
1.22.7
altinity/metrics-exporter:0.23.7a4d7ff0c727e
stdlib@go1.21.13
1.22.7

Open the chart page →

1,210
tfy-lokitruefoundryVerified publisher0.1.62 of 2See more

tfy-loki truefoundry 0.1.6

2 of the 2 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
grafana/loki:2.9.1035b02acc6765
stdlib@go1.22.5
1.22.7
grafana/promtail:2.9.1063a2e57a5b14
stdlib@go1.22.5
1.22.7

Open the chart page →

2,829
aws-eks-asg-rolling-update-handlertwin1.5.01 of 1See more

aws-eks-asg-rolling-update-handler twin 1.5.0

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
twinproduction/aws-eks-asg-rolling-update-handler:v1.7.08f38c206972e
stdlib@go1.19.3
1.22.7

Open the chart page →

1,119
lighthousetwin1.0.21 of 1See more

lighthouse twin 1.0.2

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
ghcr.io/twin/lighthouse:v0.0.45aeda2ea2ba2
stdlib@go1.22.3
1.22.7

Open the chart page →

544
twitter-apptwitter-helm0.1.124 of 8See more

twitter-app twitter-helm 0.1.12

4 of the 8 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
stakkato95/twitter-service-analytics:0.1.05d48906d66b3
stdlib@go1.18.3
1.22.7
stakkato95/twitter-service-graphql:0.1.13cbe857234f2
stdlib@go1.18.3
1.22.7
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
stdlib@go1.18.3
1.22.7
stakkato95/twitter-service-users:0.1.1456049efee9a
stdlib@go1.18.3
1.22.7

Open the chart page →

6,150
kafkatwomartensVerified publisher0.2.11 of 2See more

kafka twomartens 0.2.1

1 of the 2 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
danielqsj/kafka-exporter:v1.7.0e90b7ba06d97
stdlib@go1.20.4
1.22.7

Open the chart page →

1,252
simple-mongodbtyk-helm0.1.11 of 1See more

simple-mongodb tyk-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
stdlib@go1.21.12
1.22.7

Open the chart page →

4,167
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
stdlib@go1.19.2
1.22.7

Open the chart page →

4,998
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
stdlib@go1.20.7
1.22.7

Open the chart page →

5,283
phonebook-chartusuladams2Verified publisher0.2.11 of 3See more

phonebook-chart usuladams2 0.2.1

1 of the 3 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
library/mysql:5.74bc6bc963e6d
stdlib@go1.18.2
1.22.7

Open the chart page →

3,179
kiamuswitch6.1.21 of 1See more

kiam uswitch 6.1.2

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
quay.io/uswitch/kiam:v4.0be3a5846922d
stdlib@go1.13.8
1.22.7

Open the chart page →

2,973
gohttpserverutkuozdemirVerified publisher0.2.01 of 1See more

gohttpserver utkuozdemir 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
codeskyblue/gohttpserver:latestcaa862590e34
stdlib@go1.16.3
1.22.7

Open the chart page →

1,899
transmission-exporterutkuozdemirVerified publisher1.1.01 of 1See more

transmission-exporter utkuozdemir 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
metalmatze/transmission-exporter:0.3.090d6acb6d47d
stdlib@go1.13
1.22.7

Open the chart page →

1,647
openldap-havcnngrVerified publisher1.0.01 of 3See more

openldap-ha vcnngr 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
osixia/openldap:1.5.018742e9c449c
stdlib@go1.15.5
1.22.7

Open the chart page →

5,517
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
stdlib@go1.13.10
1.22.7

Open the chart page →

7,518
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
stdlib@go1.13.10
1.22.7

Open the chart page →

7,536
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
stdlib@go1.13.10
1.22.7

Open the chart page →

7,439
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
stdlib@go1.13.10
1.22.7

Open the chart page →

7,439
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
stdlib@go1.22.5
1.22.7

Open the chart page →

2,805
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
stdlib@go1.20.14
1.22.7

Open the chart page →

4,433
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
stdlib@go1.21.7
1.22.7

Open the chart page →

67,865
kube-monitoring-telegram-botviento-repository1.0.01 of 1See more

kube-monitoring-telegram-bot viento-repository 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
stdlib@go1.16.4
1.22.7

Open the chart page →

7,928
vineyard-operatorvineyardVerified publisher0.24.22 of 2See more

vineyard-operator vineyard 0.24.2

2 of the 2 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
stdlib@go1.19.13
1.22.7
ghcr.io/v6d-io/v6d/kube-rbac-proxy:v0.13.0a2523c532c0c
stdlib@go1.18.3
1.22.7

Open the chart page →

4,573
calibre-webvista0.1.31 of 1See more

calibre-web vista 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
linuxserver/calibre-web:0.6.24241009026e6f
stdlib@go1.17.8
1.22.7

Open the chart page →

7,892
vm-console-proxyvm-console-proxyVerified publisher0.2.01 of 1See more

vm-console-proxy vm-console-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
quay.io/kubevirt/vm-console-proxy:v0.8.08d6b4b6e99bd
stdlib@go1.22.4
1.22.7

Open the chart page →

646
go-devvoid-xmh1.0.11 of 1See more

go-dev void-xmh 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
voidxmh/golang:1.19-alpine-dev423c6195fab2
stdlib@go1.19
1.22.7

Open the chart page →

1,155
volantmqvolantmq0.1.21 of 1See more

volantmq volantmq 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
volantmq/volantmq:v0.4.0-rc.69bfe7857ebc3
stdlib@go1.13.6
1.22.7

Open the chart page →

2,551
cert-manager-webhook-vultrvultrVerified publisher1.0.01 of 1See more

cert-manager-webhook-vultr vultr 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
stdlib@go1.16.3
1.22.7

Open the chart page →

2,508
vultr-csivultrVerified publisher2.0.01 of 4See more

vultr-csi vultr 2.0.0

1 of the 4 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
vultr/vultr-csi:v0.3.041d26735d437
stdlib@go1.16.8
1.22.7

Open the chart page →

2,355
websitewaldo-visionVerified publisher0.33.01 of 2See more

website waldo-vision 0.33.0

1 of the 2 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
stdlib@go1.20.2
1.22.7

Open the chart page →

3,480
kongwallarmVerified publisher4.6.33 of 7See more

kong wallarm 4.6.3

3 of the 7 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
wallarm/ingress-python:4.6.0-15cb2ae08b40f
stdlib@go1.18.2
1.22.7
wallarm/ingress-ruby:4.6.0-1aecdb35c4def
stdlib@go1.18.3
1.22.7
wallarm/kong-kubernetes-ingress-controller:2.8b55ff6cecbd5
stdlib@go1.19.4
1.22.7

Open the chart page →

72,415
kong-previewwallarmVerified publisher4.2.32 of 5See more

kong-preview wallarm 4.2.3

2 of the 5 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
kong/kubernetes-ingress-controller:2.1.160e4102ab2da
stdlib@go1.17.5
1.22.7
wallarm/ingress-ruby:4.2.1-195ea2632326c
stdlib@go1.18.3
1.22.7

Open the chart page →

2,907
wallarm-ingress-rcwallarmVerified publisher4.8.42 of 2See more

wallarm-ingress-rc wallarm 4.8.4

2 of the 2 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
wallarm/ingress-controller:4.8.0-1a591b9c91570
stdlib@go1.20.5
1.22.7
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20230407543c40fd0939
stdlib@go1.20.1
1.22.7

Open the chart page →

2,636
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
wallarm/ebpf-agent:0.11.0-rc0c8920e60c726
stdlib@go1.22.1
1.22.7

Open the chart page →

2,842
consulwarjiang1.3.02 of 2See more

consul warjiang 1.3.0

2 of the 2 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
stdlib@go1.20.10
1.22.7
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
stdlib@go1.20.10
1.22.7

Open the chart page →

4,102
prometheus-storage-adapterwavefront0.1.61 of 2See more

prometheus-storage-adapter wavefront 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-34158.

Container imageDigestPackageFixed in
wavefronthq/prometheus-storage-adapter:latestded77b38c7c6
stdlib@go1.18
1.22.7

Open the chart page →

1,285

Container images carrying it

2,874 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.9.12cddcc716c19
stdlib@go1.20.5
1.22.7
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.7.04a4cae5118c4
stdlib@go1.19
1.22.7
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.6.2a13bff2ed69a
stdlib@go1.19
1.22.7
1
registry.k8s.io/sig-storage/csi-node-driver-registrar:v2.0.1e07f914c32f0
stdlib@go1.15
1.22.7
1
registry.k8s.io/sig-storage/csi-provisioner:v5.0.27b9cdb5830d0
stdlib@go1.22.5
1.22.7
1
registry.k8s.io/sig-storage/csi-provisioner:v3.4.0e468dddcd275
stdlib@go1.19
1.22.7
1
registry.k8s.io/sig-storage/csi-provisioner:v3.3.0ee3b525d5b89
stdlib@go1.18
1.22.7
1
registry.k8s.io/sig-storage/csi-resizer:v1.7.03a7bdf5d1057
stdlib@go1.19
1.22.7
1
registry.k8s.io/sig-storage/csi-resizer:v1.6.0425d8f1b7693
stdlib@go1.18
1.22.7
1
registry.k8s.io/sig-storage/csi-resizer:v1.10.14ecda2818f6d
stdlib@go1.21.5
1.22.7
1
registry.k8s.io/sig-storage/csi-resizer:v1.3.06e0546563b18
stdlib@go1.16.2
1.22.7
1
registry.k8s.io/sig-storage/csi-resizer:v1.12.0ab774734705a
stdlib@go1.22.5
1.22.7
1
registry.k8s.io/sig-storage/csi-snapshotter:v6.1.0291334908ddf
stdlib@go1.18
1.22.7
1
registry.k8s.io/sig-storage/csi-snapshotter:v8.0.25f051159c95f
stdlib@go1.22.5
1.22.7
1
registry.k8s.io/sig-storage/csi-snapshotter:v4.2.1818f35653f2e
stdlib@go1.16.2
1.22.7
1
registry.k8s.io/sig-storage/csi-snapshotter:v5.0.189e900a160a9
stdlib@go1.17.3
1.22.7
1
registry.k8s.io/sig-storage/hostpathplugin:v1.9.092257881c1d6
stdlib@go1.18
1.22.7
1
registry.k8s.io/sig-storage/livenessprobe:v2.9.02b10b24dafdc
stdlib@go1.19
1.22.7
1
registry.k8s.io/sig-storage/livenessprobe:v2.11.082adbebdf5d5
stdlib@go1.20.5
1.22.7
1
registry.k8s.io/sig-storage/nfs-subdir-external-provisioner:v4.0.03ce0fdba4d8e
stdlib@go1.15
1.22.7
1
registry.k8s.io/sig-storage/snapshot-controller:v4.2.195587f8777d7
stdlib@go1.16.2
1.22.7
1
registry.k8s.io/sig-storage/snapshot-controller:v6.2.198bab4eaf23c
stdlib@go1.19
1.22.7
1
registry.k8s.io/sig-storage/snapshot-controller:v6.3.1ce6ca3c0e30b
stdlib@go1.20.5
1.22.7
1
registry.k8s.io/sig-storage/volume-data-source-validator:v1.0.0d35884236461
stdlib@go1.17.3
1.22.7
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.