StackRadar

CVE-2024-41110

Critical

Advisory

Published 29 Jul 2024In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.9
base score, highest
EPSS
0.165
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
280
of 17,781 indexed, latest versions
Container images
268
deployed by those charts
Fix available
2 of 2
affected packages

Authz zero length regression

Carried by container images the latest versions of 280 of 17,781 indexed charts deploy, on 268 images.

Affected packageAffected versionsFixed inImages
github.com/docker/dockergolangv20.10.0-beta1.0.20201113105859-b6bfff2a628f+incompatible, v20.10.1+incompatible, v20.10.2+incompatible, v20.10.3-0.20211206061157-934f955e3d62+incompatible+45 more23.0.15, 25.0.6, 25.0.6+incompatible, 26.1.5+1 more266
github.com/moby/mobygolangv20.10.14+incompatible25.0.6+incompatible2
OSV records
GHSA-v23v-6jw2-98fqGO-2024-3005

Charts affected

280 by stars
ChartLatestAffected imagesRadar Score
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/devtron/kubectl:latest2ad610626658
github.com/docker/docker@v20.10.17+incompatible
23.0.15

Open the chart page →

32,902
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/docker/docker@v20.10.7+incompatible
23.0.15

Open the chart page →

2,435
harborsb-helm-charts0.3.01 of 2See more

harbor sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.11.1c017dd84ee96
github.com/docker/docker@v24.0.9+incompatible
25.0.6

Open the chart page →

1,680
opentelemetry-collectorsb-helm-charts0.3.01 of 1See more

opentelemetry-collector sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/docker/docker@v24.0.9+incompatible
25.0.6

Open the chart page →

1,721
ed-traefik2scaleway-charts0.2.01 of 1See more

ed-traefik2 scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
library/traefik:2.5.62f603f8d3abe
github.com/docker/docker@v20.10.7+incompatible
23.0.15

Open the chart page →

3,160
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/docker/docker@v24.0.7+incompatible
25.0.6

Open the chart page →

2,314
olmsikalabs0.3.01 of 2See more

olm sikalabs 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned40d0363f4aa6
github.com/docker/docker@v25.0.5+incompatible
25.0.6

Open the chart page →

1,146
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
github.com/docker/docker@v27.1.0+incompatible
27.1.1

Open the chart page →

2,429
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
github.com/docker/docker@v20.10.12+incompatible
23.0.15

Open the chart page →

9,196
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
github.com/docker/docker@v20.10.7+incompatible
23.0.15

Open the chart page →

3,462
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/docker/docker@v23.0.7-0.20230714215826-f00e7af96042+incompatible
23.0.15

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/docker/docker@v24.0.5+incompatible
25.0.6

Open the chart page →

2,505
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
github.com/docker/docker@v20.10.12+incompatible
23.0.15

Open the chart page →

30,687
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/docker/docker@v20.10.3+incompatible
23.0.15

Open the chart page →

28,165
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
github.com/docker/docker@v26.0.1+incompatible
26.1.5

Open the chart page →

20,223
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
github.com/docker/docker@v23.0.1+incompatible
23.0.15

Open the chart page →

10,134
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/docker/docker@v24.0.7+incompatible
25.0.6

Open the chart page →

1,360
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/docker/docker@v26.1.3+incompatible
26.1.5

Open the chart page →

8,518
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
github.com/docker/docker@v24.0.6+incompatible
25.0.6

Open the chart page →

4,212
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
github.com/docker/docker@v20.10.6+incompatible
23.0.15

Open the chart page →

3,764
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
github.com/docker/docker@v20.10.9+incompatible
23.0.15

Open the chart page →

21,005
mc-routerthl-chartsVerified publisher0.1.01 of 1See more

mc-router thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
itzg/mc-router:1.16.1bb552b59fb53
github.com/docker/docker@v20.10.17+incompatible
23.0.15

Open the chart page →

1,855
monitoringthl-chartsVerified publisher0.1.12 of 10See more

monitoring thl-charts 0.1.1

2 of the 10 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
grafana/promtail:2.4.2626900031c4e
github.com/docker/docker@v20.10.8+incompatible
23.0.15
quay.io/prometheus/prometheus:v2.34.0b37103e03399
github.com/docker/docker@v20.10.12+incompatible
23.0.15

Open the chart page →

18,908
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/docker/docker@v26.1.2+incompatible
26.1.5

Open the chart page →

2,477
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
github.com/docker/docker@v20.10.24+incompatible
23.0.15
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/docker/docker@v20.10.24+incompatible
23.0.15

Open the chart page →

4,815
tfy-lokitruefoundryVerified publisher0.1.61 of 2See more

tfy-loki truefoundry 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
grafana/promtail:2.9.1063a2e57a5b14
github.com/docker/docker@v23.0.8+incompatible
23.0.15

Open the chart page →

2,813
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
github.com/docker/docker@v23.0.0-rc.2+incompatible
23.0.15

Open the chart page →

6,232
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/docker/docker@v24.0.5+incompatible
25.0.6

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/docker/docker@v24.0.2+incompatible
25.0.6

Open the chart page →

2,022
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
github.com/docker/docker@v20.10.21+incompatible
23.0.15

Open the chart page →

13,677

Container images carrying it

268 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
moby/buildkit:v0.10.0c2aeafaed434
github.com/docker/docker@v20.10.3-0.20220224222438-c78f6963a1c0+incompatible
23.0.15
1
moul/sshportal:v1.19.3332b603727c3
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
murtazashah46/helmfile:latest4d11726cf803
github.com/docker/docker@v20.10.21+incompatible
23.0.15
1
oryd/kratos:v1.1.08f15006a080d
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
otel/opentelemetry-collector:0.100.09e36620d6c2c
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
otel/opentelemetry-collector:0.59.0ee9da0b08d83
github.com/docker/docker@v20.10.17+incompatible
23.0.15
1
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
github.com/docker/docker@v24.0.5+incompatible
25.0.6
1
otel/opentelemetry-collector-contrib:0.89.0995f17004231
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
otel/opentelemetry-collector-contrib:0.46.0ba173aa85f3f
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/docker/docker@v24.0.2+incompatible
25.0.6
1
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
github.com/docker/docker@v20.10.20+incompatible
23.0.15
1
phntom/chartmuseum:v0.16.053883b65d9b7
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
phntom/chartmuseum:v0.15.29242b4df9e65
github.com/docker/docker@v20.10.17+incompatible
23.0.15
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
github.com/docker/docker@v23.0.3+incompatible
23.0.15
1
prom/prometheus:v2.51.24f6c47e39a90
github.com/docker/docker@v25.0.3+incompatible
25.0.6
1
prom/prometheus:v2.48.0b440bc0e8aa5
github.com/docker/docker@v24.0.6+incompatible
25.0.6
1
rancher/k3s:v1.28.2-k3s18c2599ecfca8
github.com/docker/docker@v24.0.0-rc.2.0.20230801142700-69c9adb7d386+incompatible
25.0.6+incompatible
1
rancher/k3s:v1.25.3-k3s1eaa270df79cc
github.com/docker/docker@v20.10.7+incompatible
23.0.15
1
sikalabs/slu:v0.72.07bd267f30247
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
simpleidserver/faasprometheus:0.0.425e378d57d78
github.com/docker/docker@v20.10.8+incompatible
23.0.15
1
sirrend/helmup-engine:0.1.13699e79e3d4e2
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
github.com/docker/docker@v20.10.10+incompatible
23.0.15
1
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
github.com/docker/docker@v20.10.7+incompatible
23.0.15
1
gcr.io/cadvisor/cadvisor:v0.47.2e6c562b5e983
github.com/docker/docker@v20.10.21+incompatible
23.0.15
1
gcr.io/cadvisor/cadvisor:v0.52.1f40e65878e25
github.com/docker/docker@v26.1.4+incompatible
26.1.5
1
gcr.io/istio-testing/operator:latest8d4576f7b98f
github.com/docker/docker@v26.0.2+incompatible
26.1.5
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.13.153d9aa4d2c7a
github.com/docker/docker@v20.10.20+incompatible
23.0.15
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.10.298a2cc7fd62e
github.com/docker/docker@v20.10.20+incompatible
23.0.15
1
gcr.io/projectsigstore/cosigned784518ff3ee7
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
gcr.io/projectsigstore/policy-webhook82940e8c3e0d
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
ghcr.io/appscode/trivydb:0.0.367ffb0309acb
github.com/docker/docker@v20.10.17+incompatible
23.0.15
1
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/docker/docker@v24.0.5+incompatible
25.0.6
1
ghcr.io/arpa-network/node-client:latest657a2c9f6e6d
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
ghcr.io/beluga-cloud/helm-dashboard/dashboard:1.3.39ab9a675c405
github.com/docker/docker@v24.0.5+incompatible
25.0.6
1
ghcr.io/chaos-mesh/chaos-daemon:v2.7.29608d9b51452
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
ghcr.io/chaos-mesh/chaos-daemon:v2.5.1cf78fdf7403a
github.com/docker/docker@v20.10.17+incompatible
23.0.15
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.7.211cdbbc479b3
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
ghcr.io/chaos-mesh/chaos-dashboard:v2.5.1448cb346b12c
github.com/docker/docker@v20.10.17+incompatible
23.0.15
1
ghcr.io/chaos-mesh/chaos-mesh:v2.5.1700bb42ac21d
github.com/docker/docker@v20.10.17+incompatible
23.0.15
1
ghcr.io/chaos-mesh/chaos-mesh:v2.7.28bc853c7414c
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
ghcr.io/clusternet/clusternet-controller-manager:v1.0.02ce077d3d02d
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
ghcr.io/clusternet/clusternet-hub:v1.0.059f75504c5d4
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
ghcr.io/clusternet/clusternet-scheduler:v1.0.0a6ae5aff81ce
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
github.com/docker/docker@v20.10.14+incompatible
23.0.15
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
github.com/docker/docker@v20.10.17+incompatible
23.0.15
1
ghcr.io/kubedb/kubedb-autoscaler:v0.25.0df6b11907d33
github.com/docker/docker@v20.10.20+incompatible
23.0.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.