StackRadar

CVE-2024-41110

Critical

Advisory

Published 29 Jul 2024In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.9
base score, highest
EPSS
0.165
97th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
280
of 17,781 indexed, latest versions
Container images
268
deployed by those charts
Fix available
2 of 2
affected packages

Authz zero length regression

Carried by container images the latest versions of 280 of 17,781 indexed charts deploy, on 268 images.

Affected packageAffected versionsFixed inImages
github.com/docker/dockergolangv20.10.0-beta1.0.20201113105859-b6bfff2a628f+incompatible, v20.10.1+incompatible, v20.10.2+incompatible, v20.10.3-0.20211206061157-934f955e3d62+incompatible+45 more23.0.15, 25.0.6, 25.0.6+incompatible, 26.1.5+1 more266
github.com/moby/mobygolangv20.10.14+incompatible25.0.6+incompatible2
OSV records
GHSA-v23v-6jw2-98fqGO-2024-3005

Charts affected

280 by stars
ChartLatestAffected imagesRadar Score
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/devtron/kubectl:latest2ad610626658
github.com/docker/docker@v20.10.17+incompatible
23.0.15

Open the chart page →

32,902
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/docker/docker@v20.10.7+incompatible
23.0.15

Open the chart page →

2,435
harborsb-helm-charts0.3.01 of 2See more

harbor sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.11.1c017dd84ee96
github.com/docker/docker@v24.0.9+incompatible
25.0.6

Open the chart page →

1,680
opentelemetry-collectorsb-helm-charts0.3.01 of 1See more

opentelemetry-collector sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/docker/docker@v24.0.9+incompatible
25.0.6

Open the chart page →

1,721
ed-traefik2scaleway-charts0.2.01 of 1See more

ed-traefik2 scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
library/traefik:2.5.62f603f8d3abe
github.com/docker/docker@v20.10.7+incompatible
23.0.15

Open the chart page →

3,160
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/docker/docker@v24.0.7+incompatible
25.0.6

Open the chart page →

2,314
olmsikalabs0.3.01 of 2See more

olm sikalabs 0.3.0

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned40d0363f4aa6
github.com/docker/docker@v25.0.5+incompatible
25.0.6

Open the chart page →

1,146
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
github.com/docker/docker@v27.1.0+incompatible
27.1.1

Open the chart page →

2,429
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
github.com/docker/docker@v20.10.12+incompatible
23.0.15

Open the chart page →

9,196
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
github.com/docker/docker@v20.10.7+incompatible
23.0.15

Open the chart page →

3,462
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/docker/docker@v23.0.7-0.20230714215826-f00e7af96042+incompatible
23.0.15

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/docker/docker@v24.0.5+incompatible
25.0.6

Open the chart page →

2,505
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
github.com/docker/docker@v20.10.12+incompatible
23.0.15

Open the chart page →

30,687
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/docker/docker@v20.10.3+incompatible
23.0.15

Open the chart page →

28,165
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
github.com/docker/docker@v26.0.1+incompatible
26.1.5

Open the chart page →

20,223
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
github.com/docker/docker@v23.0.1+incompatible
23.0.15

Open the chart page →

10,134
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/docker/docker@v24.0.7+incompatible
25.0.6

Open the chart page →

1,360
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/docker/docker@v26.1.3+incompatible
26.1.5

Open the chart page →

8,518
act-runnertektonops0.1.21 of 2See more

act-runner tektonops 0.1.2

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
library/docker:23.0.6-dindafa5d5134900
github.com/docker/docker@v24.0.6+incompatible
25.0.6

Open the chart page →

4,212
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
github.com/docker/docker@v20.10.6+incompatible
23.0.15

Open the chart page →

3,764
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
github.com/docker/docker@v20.10.9+incompatible
23.0.15

Open the chart page →

21,005
mc-routerthl-chartsVerified publisher0.1.01 of 1See more

mc-router thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
itzg/mc-router:1.16.1bb552b59fb53
github.com/docker/docker@v20.10.17+incompatible
23.0.15

Open the chart page →

1,855
monitoringthl-chartsVerified publisher0.1.12 of 10See more

monitoring thl-charts 0.1.1

2 of the 10 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
grafana/promtail:2.4.2626900031c4e
github.com/docker/docker@v20.10.8+incompatible
23.0.15
quay.io/prometheus/prometheus:v2.34.0b37103e03399
github.com/docker/docker@v20.10.12+incompatible
23.0.15

Open the chart page →

18,908
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/docker/docker@v26.1.2+incompatible
26.1.5

Open the chart page →

2,477
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
github.com/docker/docker@v20.10.24+incompatible
23.0.15
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/docker/docker@v20.10.24+incompatible
23.0.15

Open the chart page →

4,815
tfy-lokitruefoundryVerified publisher0.1.61 of 2See more

tfy-loki truefoundry 0.1.6

1 of the 2 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
grafana/promtail:2.9.1063a2e57a5b14
github.com/docker/docker@v23.0.8+incompatible
23.0.15

Open the chart page →

2,813
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
github.com/docker/docker@v23.0.0-rc.2+incompatible
23.0.15

Open the chart page →

6,232
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/docker/docker@v24.0.5+incompatible
25.0.6

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/docker/docker@v24.0.2+incompatible
25.0.6

Open the chart page →

2,022
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2024-41110.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
github.com/docker/docker@v20.10.21+incompatible
23.0.15

Open the chart page →

13,677

Container images carrying it

268 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kubedb/kubedb-dashboard:v0.16.07bfe1c07bd9b
github.com/docker/docker@v20.10.20+incompatible
23.0.15
1
ghcr.io/kubedb/kubedb-ops-manager:v0.27.1ec36422b09af
github.com/docker/docker@v20.10.20+incompatible
23.0.15
1
ghcr.io/kubedb/kubedb-provisioner:v0.40.242574f512837
github.com/docker/docker@v20.10.20+incompatible
23.0.15
1
ghcr.io/kubedb/kubedb-schema-manager:v0.16.09518de37eed5
github.com/docker/docker@v20.10.20+incompatible
23.0.15
1
ghcr.io/kubedb/kubedb-webhook-server:v0.16.2e24894e32cbc
github.com/docker/docker@v20.10.20+incompatible
23.0.15
1
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
ghcr.io/loft-sh/agent:3.2.45c109914ff73
github.com/docker/docker@v20.10.21+incompatible
23.0.15
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
github.com/docker/docker@v20.10.21+incompatible
23.0.15
1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
github.com/docker/docker@v23.0.0-rc.1+incompatible
23.0.15
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
github.com/docker/docker@v20.10.22+incompatible
23.0.15
1
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
github.com/docker/docker@v24.0.5+incompatible
25.0.6
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
github.com/docker/docker@v25.0.5+incompatible
25.0.6
1
ghcr.io/openclarity/grype-server:v0.6.079412399f301
github.com/docker/docker@v24.0.5+incompatible
25.0.6
1
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
ghcr.io/parca-dev/parca-agent:v0.28.06d6794f45f3e
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
github.com/docker/docker@v23.0.1+incompatible
23.0.15
1
ghcr.io/substra/fabric-peer:0.2.4f681e0343a31
github.com/docker/docker@v20.10.0-beta1.0.20201113105859-b6bfff2a628f+incompatible
23.0.15
1
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
github.com/docker/docker@v20.10.0-beta1.0.20201113105859-b6bfff2a628f+incompatible
23.0.15
1
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/docker/docker@v26.1.3+incompatible
26.1.5
1
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
github.com/docker/docker@v20.10.21+incompatible
23.0.15
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
github.com/docker/docker@v26.1.3+incompatible
26.1.5
1
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/docker/docker@v24.0.7+incompatible
25.0.6
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
github.com/docker/docker@v24.0.0+incompatible
25.0.6
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
github.com/docker/docker@v20.10.14+incompatible
23.0.15
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/docker/docker@v20.10.3+incompatible
23.0.15
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/docker/docker@v20.10.3+incompatible
23.0.15
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/docker/docker@v20.10.3+incompatible
23.0.15
1
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
github.com/docker/docker@v20.10.2+incompatible
23.0.15
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
github.com/docker/docker@v24.0.2+incompatible
25.0.6
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
github.com/docker/docker@v20.10.8+incompatible
23.0.15
1
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
github.com/docker/docker@v23.0.3+incompatible
23.0.15
1
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
github.com/docker/docker@v20.10.12+incompatible
23.0.15
1
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/docker/docker@v23.0.3+incompatible
23.0.15
1
quay.io/kube-ops/promtail:2.2.134de6387233b
github.com/docker/docker@v20.10.1+incompatible
23.0.15
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
github.com/docker/docker@v20.10.24+incompatible
23.0.15
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.