StackRadar

CVE-2024-41110

Critical

Advisory

Published 29 Jul 2024In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.9
base score, highest
EPSS
0.165
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
280
of 17,781 indexed, latest versions
Container images
268
deployed by those charts
Fix available
2 of 2
affected packages

Authz zero length regression

Carried by container images the latest versions of 280 of 17,781 indexed charts deploy, on 268 images.

Affected packageAffected versionsFixed inImages
github.com/docker/dockergolangv20.10.0-beta1.0.20201113105859-b6bfff2a628f+incompatible, v20.10.1+incompatible, v20.10.2+incompatible, v20.10.3-0.20211206061157-934f955e3d62+incompatible+45 more23.0.15, 25.0.6, 25.0.6+incompatible, 26.1.5+1 more266
github.com/moby/mobygolangv20.10.14+incompatible25.0.6+incompatible2
OSV records
GHSA-v23v-6jw2-98fqGO-2024-3005

Charts affected

280 by stars
ChartLatestAffected imagesRadar Score
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/devtron/kubectl:latest2ad610626658
github.com/docker/docker@v20.10.17+incompatible
23.0.15

Open the chart page →

32,902
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/docker/docker@v20.10.7+incompatible
23.0.15

Open the chart page →

2,435
harborsb-helm-charts0.3.01 of 2See more

harbor sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.11.1c017dd84ee96
github.com/docker/docker@v24.0.9+incompatible
25.0.6

Open the chart page →

1,680
opentelemetry-collectorsb-helm-charts0.3.01 of 1See more

opentelemetry-collector sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/docker/docker@v24.0.9+incompatible
25.0.6

Open the chart page →

1,721
ed-traefik2scaleway-charts0.2.01 of 1See more

ed-traefik2 scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
library/traefik:2.5.62f603f8d3abe
github.com/docker/docker@v20.10.7+incompatible
23.0.15

Open the chart page →

3,160
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/docker/docker@v24.0.7+incompatible
25.0.6

Open the chart page →

2,314
olmsikalabs0.3.01 of 2See more

olm sikalabs 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned40d0363f4aa6
github.com/docker/docker@v25.0.5+incompatible
25.0.6

Open the chart page →

1,146
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
github.com/docker/docker@v27.1.0+incompatible
27.1.1

Open the chart page →

2,429
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
github.com/docker/docker@v20.10.12+incompatible
23.0.15

Open the chart page →

9,196
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
github.com/docker/docker@v20.10.7+incompatible
23.0.15

Open the chart page →

3,462
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/docker/docker@v23.0.7-0.20230714215826-f00e7af96042+incompatible
23.0.15

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/docker/docker@v24.0.5+incompatible
25.0.6

Open the chart page →

2,505
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
github.com/docker/docker@v20.10.12+incompatible
23.0.15

Open the chart page →

30,687
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/docker/docker@v20.10.3+incompatible
23.0.15

Open the chart page →

28,165
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
github.com/docker/docker@v26.0.1+incompatible
26.1.5

Open the chart page →

20,223
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
github.com/docker/docker@v23.0.1+incompatible
23.0.15

Open the chart page →

10,134
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/docker/docker@v24.0.7+incompatible
25.0.6

Open the chart page →

1,360
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/docker/docker@v26.1.3+incompatible
26.1.5

Open the chart page →

8,518
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
github.com/docker/docker@v24.0.6+incompatible
25.0.6

Open the chart page →

4,212
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
github.com/docker/docker@v20.10.6+incompatible
23.0.15

Open the chart page →

3,764
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
github.com/docker/docker@v20.10.9+incompatible
23.0.15

Open the chart page →

21,005
mc-routerthl-chartsVerified publisher0.1.01 of 1See more

mc-router thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
itzg/mc-router:1.16.1bb552b59fb53
github.com/docker/docker@v20.10.17+incompatible
23.0.15

Open the chart page →

1,855
monitoringthl-chartsVerified publisher0.1.12 of 10See more

monitoring thl-charts 0.1.1

2 of the 10 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
grafana/promtail:2.4.2626900031c4e
github.com/docker/docker@v20.10.8+incompatible
23.0.15
quay.io/prometheus/prometheus:v2.34.0b37103e03399
github.com/docker/docker@v20.10.12+incompatible
23.0.15

Open the chart page →

18,908
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/docker/docker@v26.1.2+incompatible
26.1.5

Open the chart page →

2,477
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
github.com/docker/docker@v20.10.24+incompatible
23.0.15
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/docker/docker@v20.10.24+incompatible
23.0.15

Open the chart page →

4,815
tfy-lokitruefoundryVerified publisher0.1.61 of 2See more

tfy-loki truefoundry 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
grafana/promtail:2.9.1063a2e57a5b14
github.com/docker/docker@v23.0.8+incompatible
23.0.15

Open the chart page →

2,813
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
github.com/docker/docker@v23.0.0-rc.2+incompatible
23.0.15

Open the chart page →

6,232
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/docker/docker@v24.0.5+incompatible
25.0.6

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/docker/docker@v24.0.2+incompatible
25.0.6

Open the chart page →

2,022
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
github.com/docker/docker@v20.10.21+incompatible
23.0.15

Open the chart page →

13,677

Container images carrying it

268 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
alpine/k8s:1.28.13e5c0b053fed7
github.com/docker/docker@v26.1.4+incompatible
26.1.5
1
alpine/k8s:1.32.3eec354133193
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
alpine/k8s:1.28.2fc059f056ad0
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
amazon/aws-otel-collector:v0.27.0d8ab0eef5074
github.com/docker/docker@v23.0.1+incompatible
23.0.15
1
amazon/cloudwatch-agent:1.300032.2b36173b79b02f03a
github.com/docker/docker@v24.0.5+incompatible
25.0.6
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/docker/docker@v26.1.2+incompatible
26.1.5
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
github.com/docker/docker@v20.10.3+incompatible
23.0.15
1
aquasec/postee:2.12.0-amd640795cba777e7
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
aquasec/trivy:0.43.1944a04445179
github.com/docker/docker@v23.0.5+incompatible
23.0.15
1
aquasec/trivy:0.32.0973d0df16189
github.com/docker/docker@v20.10.3-0.20220224222438-c78f6963a1c0+incompatible
23.0.15
1
artifacthub/hub:v1.19.0111918d8c399
github.com/docker/docker@v26.1.3+incompatible
26.1.5
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/docker/docker@v26.1.3+incompatible
26.1.5
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/docker/docker@v26.1.3+incompatible
26.1.5
1
beopenit/door-helm:v3.0.1b4d9f9bee224
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
bicarus/wg-access-server:v0.8.206cab48e9334
github.com/docker/docker@v20.10.8+incompatible
23.0.15
1
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
github.com/docker/docker@v27.0.3+incompatible
27.1.1
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
coderenvs/coder-service:1.44.61deffc4670e6
github.com/docker/docker@v20.10.20+incompatible
23.0.15
1
datasaker/dsk-container-agent:latest08b52999f67b
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
devopstales/trivy-operator:2.575136aa7a26e
github.com/docker/docker@v23.0.0-rc.1+incompatible
23.0.15
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/docker/docker@v24.0.0+incompatible
25.0.6
1
dragonflyoss/manager:v2.1.49c3ef7f10698d
github.com/docker/docker@v26.1.1+incompatible
26.1.5
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
github.com/docker/docker@v20.10.21+incompatible
23.0.15
1
emqxecp/otelcol:2.5.04c31d9bec846
github.com/docker/docker@v27.0.3+incompatible
27.1.1
1
epamedp/edp-headlamp:0.25.093417e18bb1a
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
flomesh/fsm-manager:0.2.1122f849c70b25
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
galaxy/cloudman-server:lateste5c265fe9fcd
github.com/docker/docker@v20.10.17+incompatible
23.0.15
1
gitea/act_runner:0.2.11-dind-rootless6120b1165f3a
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
gitea/act_runner:0.2.11c57233403eff
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
gocrane/craned:v0.5.1a1400909118c
github.com/docker/docker@v20.10.2+incompatible
23.0.15
1
goharbor/chartmuseum-photon:v2.5.36ab3ca28e9e5
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
goharbor/harbor-acceld:0.2.13451103a6c8d8
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
goharbor/harbor-core:v2.5.386bf3031f4a7
github.com/docker/docker@v20.10.9+incompatible
23.0.15
1
goharbor/harbor-core:v2.11.1c017dd84ee96
github.com/docker/docker@v24.0.9+incompatible
25.0.6
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
github.com/docker/docker@v20.10.9+incompatible
23.0.15
1
goharbor/trivy-adapter-photon:v2.5.3b9522c3f5056
github.com/docker/docker@v20.10.3-0.20220224222438-c78f6963a1c0+incompatible
23.0.15
1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/docker/docker@v23.0.7-0.20230714215826-f00e7af96042+incompatible
23.0.15
1
grafana/agent:v0.20.0825c09373d27
github.com/docker/docker@v20.10.7+incompatible
23.0.15
1
grafana/agent:v0.40.3f6cbec9409be
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
grafana/alloy:v1.1.1c3dac4e26471
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
grafana/phlare:0.5.1330f990cdad9
github.com/docker/docker@v20.10.22+incompatible
23.0.15
1
grafana/promtail:2.6.1072527b12cdf
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
grafana/promtail:2.9.1063a2e57a5b14
github.com/docker/docker@v23.0.8+incompatible
23.0.15
1
grafana/promtail:2.7.0c16c710f7333
github.com/docker/docker@v20.10.18+incompatible
23.0.15
1
grafana/promtail:3.0.0d3de3da9431c
github.com/docker/docker@v25.0.3+incompatible
25.0.6
1
hashicorp/boundary:0.15.3339b78b61750
github.com/docker/docker@v24.0.9+incompatible
25.0.6
1
hashicorp/boundary:0.8.1fb70bd9210ff
github.com/docker/docker@v20.10.7+incompatible
23.0.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.