StackRadar

CVE-2024-45338

Unscored

Advisory

Published 18 Dec 2024In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,886
of 17,787 indexed, latest versions
Container images
2,333
deployed by those charts
Fix available
1 of 1
affected package

Non-linear parsing of case-insensitive content in golang.org/x/net/html

Carried by container images the latest versions of 1,886 of 17,787 indexed charts deploy, on 2,333 images.

Affected packageAffected versionsFixed inImages
golang.org/x/netgolangv0.0.0-20170114055629-f2499483f923, v0.0.0-20180301190904-22ae77b79946, v0.0.0-20180811021610-c39426892332, v0.0.0-20180906233101-161cd47e91fd+198 more0.33.02,333
OSV records
GO-2024-3333
Also known as
GHSA-w32m-9786-jp63

Charts affected

1,886 by stars
ChartLatestAffected imagesRadar Score
loadtesterflagger0.39.01 of 1See more

loadtester flagger 0.39.0

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
ghcr.io/fluxcd/flagger-loadtester:0.39.06a8546993cb5
golang.org/x/net@v0.28.0
0.33.0

Open the chart page →

1,760
flyteflyte1.16.81 of 11See more

flyte flyte 1.16.8

1 of the 11 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
kubernetesui/dashboard:v2.2.0148991563e37
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.33.0

Open the chart page →

3,282
lndfold0.3.153 of 4See more

lnd fold 0.3.15

3 of the 4 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
thesisrobot/lnd:v0.16.4-beta-c287129953689
golang.org/x/net@v0.8.0
0.33.0
thesisrobot/loop:v0.11.1-beta89ae07e787ca
golang.org/x/net@v0.0.0-20191002035440-2ec189313ef0
0.33.0
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
golang.org/x/net@v0.0.0-20191112182307-2180aed22343
0.33.0

Open the chart page →

8,834
intel-gpu-plugingeek-cookbookVerified publisher4.4.21 of 1See more

intel-gpu-plugin geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
intel/intel-gpu-plugin:0.20.0143f0a45e174
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.33.0

Open the chart page →

1,738
geonode-k8sgeonode-k8sVerified publisher2.0.01 of 10See more

geonode-k8s geonode-k8s 2.0.0

1 of the 10 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
registry.k8s.io/kubectl:v1.32.08ccae74fc039
golang.org/x/net@v0.30.0
0.33.0

Open the chart page →

14,043
hertzbeathertzbeatOfficialVerified publisher1.8.11 of 4See more

hertzbeat hertzbeat 1.8.1

1 of the 4 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
victoriametrics/victoria-metrics:v1.95.1f52723a08a44
golang.org/x/net@v0.18.0
0.33.0

Open the chart page →

14,109
permission-managerkfirfer1.0.71 of 1See more

permission-manager kfirfer 1.0.7

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/sighup/permission-manager:v1.7.1-rc1f5e6a5dcee33
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.33.0

Open the chart page →

2,266
kubeflowkubeflow1.6.225 of 45See more

kubeflow kubeflow 1.6.2

25 of the 45 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
golang.org/x/net@v0.0.0-20201224014010-6772e930b67b
0.33.0
istio/proxyv2:1.14.1df69c1a7af7c
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.33.0
kserve/kserve-controller:v0.8.0f0692a9ea09f
golang.org/x/net@v0.0.0-20211205041911-012df41ee64c
0.33.0
kubeflow/training-operator:v1-e1434f6ff847e2b6af0
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
0.33.0
kubeflownotebookswg/kfam:v1.6.1f226fb44db57
golang.org/x/net@v0.0.0-20200602114024-627f9648deb9
0.33.0
kubeflownotebookswg/notebook-controller:v1.6.185e2e685abd6
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.33.0
kubeflownotebookswg/poddefaults-webhook:v1.6.17d42600e1524
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.33.0
kubeflownotebookswg/profile-controller:v1.6.19f01767a460f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.33.0
kubeflownotebookswg/tensorboard-controller:v1.6.182ffdd2da285
golang.org/x/net@v0.0.0-20210825183410-e898025ed96a
0.33.0
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
golang.org/x/net@v0.0.0-20210428140749-89ef3d95e781
0.33.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/controller:v1.2.0f253b82941c2
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.33.0
gcr.io/knative-releases/knative.dev/net-istio/cmd/webhook:v1.2.0a705c1ea8e9e
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/activator:v1.2.593ff6e693577
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/autoscaler:v1.2.5007820fdb75b
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/controller:v1.2.575cfdcfa050a
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping:v1.2.523baa1932232
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/domain-mapping-webhook:v1.2.5847bb97e3844
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.33.0
gcr.io/knative-releases/knative.dev/serving/cmd/webhook:v1.2.59084ea8498ea
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.33.0
gcr.io/ml-pipeline/api-server:2.0.0-alpha.5dc6ca05bb94f
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.33.0
gcr.io/ml-pipeline/cache-server:2.0.0-alpha.583e79c709df3
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.33.0
gcr.io/ml-pipeline/persistenceagent:2.0.0-alpha.500db9796a37b
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.33.0
gcr.io/ml-pipeline/scheduledworkflow:2.0.0-alpha.5795a0c8a0e13
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.33.0
gcr.io/ml-pipeline/viewer-crd-controller:2.0.0-alpha.534403f9f94be
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.33.0
gcr.io/ml-pipeline/workflow-controller:v3.3.8-license-compliance6c8e4e2a6443
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.33.0
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.33.0

Open the chart page →

97,040
openelbkubesphere-stable0.5.02 of 2See more

openelb kubesphere-stable 0.5.0

2 of the 2 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
kubesphere/openelb:v0.5.0b5b665c4672c
golang.org/x/net@v0.0.0-20200528225125-3c3fba18258b
0.33.0
kubespheredev/kube-webhook-certgen:v1.1.123a03c9c381f
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.33.0

Open the chart page →

4,329
operatorkube-starrocksVerified publisher1.11.71 of 1See more

operator kube-starrocks 1.11.7

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
starrocks/operator:v1.11.78c20435a7579
golang.org/x/net@v0.17.0
0.33.0

Open the chart page →

556
vclustermainVerified publisher0.17.06 of 10See more

vcluster main 0.17.0

6 of the 10 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
golang.org/x/net@v0.8.0
0.33.0
quay.io/kubermatic/operating-system-manager:v1.3.010081473da43
golang.org/x/net@v0.9.0
0.33.0
registry.k8s.io/kas-network-proxy/proxy-server:v0.0.37c2f596cae3c6
golang.org/x/net@v0.7.0
0.33.0
registry.k8s.io/kube-apiserver:v1.25.0f6902791fb9a
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.33.0
registry.k8s.io/kube-controller-manager:v1.25.066ce7d460e53
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.33.0
registry.k8s.io/kube-scheduler:v1.25.09330c53feca7
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.33.0

Open the chart page →

11,556
netris-operatornetrisai3.0.21 of 2See more

netris-operator netrisai 3.0.2

1 of the 2 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
netrisai/netris-operator:v4.0.244f60aa0d898
golang.org/x/net@v0.0.0-20220225172249-27dd8689420f
0.33.0

Open the chart page →

1,588
node-local-dnsnode-local-dns2.4.01 of 1See more

node-local-dns node-local-dns 2.4.0

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
registry.k8s.io/dns/k8s-dns-node-cache:1.23.081a13703d6b8
golang.org/x/net@v0.17.0
0.33.0

Open the chart page →

2,601
goldpingerokgoloveVerified publisher6.2.01 of 1See more

goldpinger okgolove 6.2.0

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
bloomberg/goldpinger:3.10.08520120f5598
golang.org/x/net@v0.17.0
0.33.0

Open the chart page →

715
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
golang.org/x/net@v0.17.0
0.33.0

Open the chart page →

8,767
capsuleprojectcapsuleOfficialVerified publisher0.14.51 of 2See more

capsule projectcapsule 0.14.5

1 of the 2 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
clastix/kubectl:v1.3122918a06c253
golang.org/x/net@v0.26.0
0.33.0

Open the chart page →

1,231
prometheus-consul-exporterprometheus-communityVerified publisher1.1.11 of 1See more

prometheus-consul-exporter prometheus-community 1.1.1

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
prom/consul-exporter:v0.13.04e4cfd809e96
golang.org/x/net@v0.29.0
0.33.0

Open the chart page →

782
prometheus-statsd-exporterprometheus-communityVerified publisher1.0.01 of 1See more

prometheus-statsd-exporter prometheus-community 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
prom/statsd-exporter:v0.28.04e7a1f00b9b2
golang.org/x/net@v0.29.0
0.33.0

Open the chart page →

782
rke2-multusrke2-charts3.7.1-build20210416011 of 2See more

rke2-multus rke2-charts 3.7.1-build2021041601

1 of the 2 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
rancher/hardened-multus-cni:v3.7.1-build202104168eb8092f0728
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.33.0

Open the chart page →

4,519
uffizzi-appuffizzi-app1.3.08 of 14See more

uffizzi-app uffizzi-app 1.3.0

8 of the 14 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
golang.org/x/net@v0.12.0
0.33.0
uffizzi/uffizzi-cluster-operator:v1.4.514e528bbd926
golang.org/x/net@v0.8.0
0.33.0
quay.io/jetstack/cert-manager-cainjector:v1.13.2858fee0c4af0
golang.org/x/net@v0.17.0
0.33.0
quay.io/jetstack/cert-manager-controller:v1.13.29c67cf8c92d8
golang.org/x/net@v0.17.0
0.33.0
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
golang.org/x/net@v0.17.0
0.33.0
quay.io/jetstack/cert-manager-webhook:v1.13.20a9470447ebf
golang.org/x/net@v0.17.0
0.33.0
registry.k8s.io/ingress-nginx/controller:v1.9.45b161f051d01
golang.org/x/net@v0.17.0
0.33.0
registry.k8s.io/ingress-nginx/kube-webhook-certgen:v20231011-8b53cabe0a7943503b45d
golang.org/x/net@v0.16.0
0.33.0

Open the chart page →

19,363
dexwiremindVerified publisher2.15.71 of 2See more

dex wiremind 2.15.7

1 of the 2 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/dexidp/dex:v2.24.0c9b7f6d0d953
golang.org/x/net@v0.0.0-20190813141303-74dc4d7220e7
0.33.0

Open the chart page →

13,567
pod-gatewayangelnu7.1.11 of 2See more

pod-gateway angelnu 7.1.1

1 of the 2 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
ghcr.io/angelnu/gateway-admision-controller:v3.12.06f6ab596afd5
golang.org/x/net@v0.30.0
0.33.0

Open the chart page →

1,133
aperture-controlleraperture2.34.02 of 5See more

aperture-controller aperture 2.34.0

2 of the 5 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
fluxninja/aperture-operator:2.34.0356d7aa86632
golang.org/x/net@v0.19.0
0.33.0
quay.io/prometheus/prometheus:v2.33.591100b06e86d
golang.org/x/net@v0.0.0-20220105145211-5b0dc2dfae98
0.33.0

Open the chart page →

4,663
k8upappuio2.0.51 of 1See more

k8up appuio 2.0.5

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.33.0

Open the chart page →

3,300
openshift-consoleav1o-chartsVerified publisher0.3.61 of 1See more

openshift-console av1o-charts 0.3.6

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.33.0

Open the chart page →

9,052
prometheusaveshaVerified publisher19.3.03 of 4See more

prometheus avesha 19.3.0

3 of the 4 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/prometheus/node-exporter:v1.5.039c642b2b337
golang.org/x/net@v0.2.0
0.33.0
quay.io/prometheus/prometheus:v2.41.01a3e9a878e50
golang.org/x/net@v0.4.0
0.33.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.7.0a15ca437f230
golang.org/x/net@v0.0.0-20221014081412-f15817d10f9b
0.33.0

Open the chart page →

5,484
aws-calicoaws0.3.111 of 1See more

aws-calico aws 0.3.11

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/tigera/operator:v1.20.1379efe0c2541
golang.org/x/net@v0.0.0-20201110031124-69a78807bb2b
0.33.0

Open the chart page →

2,250
yataibentomlVerified publisher1.1.131 of 1See more

yatai bentoml 1.1.13

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
golang.org/x/net@v0.7.0
0.33.0

Open the chart page →

1,917
yatai-deploymentbentomlVerified publisher1.1.211 of 2See more

yatai-deployment bentoml 1.1.21

1 of the 2 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/bentoml/yatai-deployment:1.1.212342cfe8c2a9
golang.org/x/net@v0.17.0
0.33.0

Open the chart page →

1,160
caddy-ingress-controllercaddy-ingress1.3.01 of 1See more

caddy-ingress-controller caddy-ingress 1.3.0

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
caddy/ingress:v0.2.118d1366fc0e9
golang.org/x/net@v0.17.0
0.33.0

Open the chart page →

1,884
cert-managerchoerodon1.8.24 of 4See more

cert-manager choerodon 1.8.2

4 of the 4 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/jetstack/cert-manager-cainjector:v1.8.2c010246124c2
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.33.0
quay.io/jetstack/cert-manager-controller:v1.8.2a20c44021a5d
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.33.0
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.33.0
quay.io/jetstack/cert-manager-webhook:v1.8.2ada7edd90bec
golang.org/x/net@v0.0.0-20210224082022-3d97a244fca7
0.33.0

Open the chart page →

7,775
cloudflare-exportercloudflare-exporter0.2.31 of 1See more

cloudflare-exporter cloudflare-exporter 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
ghcr.io/lablabs/cloudflare_exporter:0.0.1670d74ec46602
golang.org/x/net@v0.25.0
0.33.0

Open the chart page →

791
cluster-registrycluster-registry-controller0.2.121 of 1See more

cluster-registry cluster-registry-controller 0.2.12

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
ghcr.io/cisco-open/cluster-registry-controller:v0.2.12937eff91df1e
golang.org/x/net@v0.7.0
0.33.0

Open the chart page →

1,707
coder-observabilitycoder-observabilityVerified publisher0.7.311 of 21See more

coder-observability coder-observability 0.7.3

11 of the 21 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
grafana/agent:v0.40.3f6cbec9409be
golang.org/x/net@v0.20.0
0.33.0
grafana/loki:3.1.0d947e68a84d9
golang.org/x/net@v0.23.0
0.33.0
grafana/loki-canary:3.1.039baf6d67f85
golang.org/x/net@v0.23.0
0.33.0
prom/memcached-exporter:v0.14.2d8a61419b841
golang.org/x/net@v0.17.0
0.33.0
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
golang.org/x/net@v0.0.0-20220722155237-a158d28d115b
0.33.0
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
golang.org/x/net@v0.0.0-20220909164309-bea034e7d591
0.33.0
quay.io/prometheus-operator/prometheus-config-reloader:v0.74.0d55631c7a740
golang.org/x/net@v0.25.0
0.33.0
quay.io/prometheus/alertmanager:v0.27.0e13b6ed5cb92
golang.org/x/net@v0.20.0
0.33.0
quay.io/prometheus/node-exporter:v1.8.1fa7fa12a57ef
golang.org/x/net@v0.23.0
0.33.0
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
golang.org/x/net@v0.26.0
0.33.0
registry.k8s.io/kube-state-metrics/kube-state-metrics:v2.12.0b401fae262a5
golang.org/x/net@v0.22.0
0.33.0

Open the chart page →

24,698
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
golang.org/x/net@v0.17.0
0.33.0

Open the chart page →

17,475
core-dump-handlercore-dump-handler9.0.01 of 1See more

core-dump-handler core-dump-handler 9.0.0

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
golang.org/x/net@v0.0.0-20210520170846-37e1c6afe023
0.33.0

Open the chart page →

3,081
cosmocosmo-platformOfficialVerified publisher0.20.02 of 10See more

cosmo cosmo-platform 0.20.0

2 of the 10 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
golang.org/x/net@v0.25.0
0.33.0
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
golang.org/x/net@v0.26.0
0.33.0

Open the chart page →

27,984
dapr-dashboarddapr0.15.01 of 1See more

dapr-dashboard dapr 0.15.0

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
daprio/dashboard:0.15.04be696707bd1
golang.org/x/net@v0.25.0
0.33.0

Open the chart page →

1,301
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
golang.org/x/net@v0.17.0
0.33.0

Open the chart page →

3,451
kube-benchdeliveryheroVerified publisher0.1.171 of 1See more

kube-bench deliveryhero 0.1.17

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
golang.org/x/net@v0.19.0
0.33.0

Open the chart page →

1,623
listmonkdeliveryheroVerified publisher0.1.121 of 1See more

listmonk deliveryhero 0.1.12

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
listmonk/listmonk:v2.1.0d2eac77ddfad
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.33.0

Open the chart page →

2,537
imagepullsecret-patcherempathyco1.0.01 of 1See more

imagepullsecret-patcher empathyco 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/titansoft/imagepullsecret-patcher:v0.1421e6d6a155dc
golang.org/x/net@v0.0.0-20191004110552-13f9640d40b9
0.33.0

Open the chart page →

2,271
openshift-secured-appeximiaitVerified publisher0.5.01 of 1See more

openshift-secured-app eximiait 0.5.0

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
0.33.0

Open the chart page →

12,042
openshift-secured-pgadmineximiaitVerified publisher0.2.01 of 2See more

openshift-secured-pgadmin eximiait 0.2.0

1 of the 2 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
0.33.0

Open the chart page →

14,545
openshift-secured-redisInsighteximiaitVerified publisher0.9.21 of 2See more

openshift-secured-redisInsight eximiait 0.9.2

1 of the 2 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
quay.io/openshift/origin-oauth-proxy:4.14a7dff785d821
golang.org/x/net@v0.17.0
0.33.0

Open the chart page →

13,874
frp-operatorfrp-operator1.9.01 of 1See more

frp-operator frp-operator 1.9.0

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
ghcr.io/zufardhiyaulhaq/frp-operator:v0.11.0cd25ee354df2
golang.org/x/net@v0.23.0
0.33.0

Open the chart page →

528
blockygeek-cookbookVerified publisher10.5.21 of 1See more

blocky geek-cookbook 10.5.2

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
golang.org/x/net@v0.0.0-20211209124913-491a49abca63
0.33.0

Open the chart page →

3,030
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
0.33.0

Open the chart page →

7,579
multusgeek-cookbookVerified publisher3.5.21 of 3See more

multus geek-cookbook 3.5.2

1 of the 3 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
ghcr.io/k8snetworkplumbingwg/multus-cni:v3.7.1e72aa733faf2
golang.org/x/net@v0.0.0-20201021035429-f5854403a974
0.33.0

Open the chart page →

4,908
signal-cli-rest-apigeek-cookbookVerified publisher1.2.21 of 1See more

signal-cli-rest-api geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-45338.

Container imageDigestPackageFixed in
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
golang.org/x/net@v0.0.0-20200625001655-4c5254603344
0.33.0

Open the chart page →

10,202

Container images carrying it

2,333 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
streamnative/pulsar_vault_init:v1.0.731533fa9fab7
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.33.0
1
su541/cert-manager-desec-webhook:latest371ee33f83c1
golang.org/x/net@v0.7.0
0.33.0
1
subspacecommunity/subspace:1.5.0e2042b63fb35
golang.org/x/net@v0.0.0-20200519113804-d87ec0cfa476
0.33.0
1
summerwind/actions-runner-controller:v0.27.62128f81dbede
golang.org/x/net@v0.12.0
0.33.0
1
supabase/gotrue:v2.91.07174d551d720
golang.org/x/net@v0.10.0
0.33.0
1
supabase/gotrue:v2.163.0ba4ddc594b0b
golang.org/x/net@v0.23.0
0.33.0
1
superorbital/cludod:0.0.2-alphad59732f61d6e
golang.org/x/net@v0.0.0-20220111093109-d55c255bac03
0.33.0
1
surajwarbhe/grafana:v185248611e9f1
golang.org/x/net@v0.0.0-20200202094626-16171245cfb2
0.33.0
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
golang.org/x/net@v0.8.0
0.33.0
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
golang.org/x/net@v0.8.0
0.33.0
1
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
golang.org/x/net@v0.19.0
0.33.0
1
syncthing/syncthing:1.18.2966433161272
golang.org/x/net@v0.0.0-20210716203947-853a461950ff
0.33.0
1
sysintelligent/hello-app:2.0.177fb30df847d
golang.org/x/net@v0.19.0
0.33.0
1
tailscale/k8s-operator:v1.70.08edd06cf5bac
golang.org/x/net@v0.26.0
0.33.0
1
tailwarden/komiser:3.1.103f68c8ae7993
golang.org/x/net@v0.17.0
0.33.0
1
tdengine/tdengine:3.0.2.24140a4021ddb
golang.org/x/net@v0.0.0-20220607020251-c690dde0001d
0.33.0
1
tdeutsch/podsync:v2.4.2b67186f4c9a5
golang.org/x/net@v0.0.0-20210405180319-a5a99cb37ef4
0.33.0
1
temporalio/admin-tools:1.22.4258958fe2ff2
golang.org/x/net@v0.8.0
0.33.0
1
temporalio/admin-tools:1.15.135034611d981
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.33.0
1
temporalio/admin-tools:1.26.237e2e33dbd7b
golang.org/x/net@v0.31.0
0.33.0
1
temporalio/admin-tools:1.22.0836af062af30
golang.org/x/net@v0.14.0
0.33.0
1
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
golang.org/x/net@v0.27.0
0.33.0
1
temporalio/server:1.26.21e2626efcbc1
golang.org/x/net@v0.31.0
0.33.0
1
temporalio/server:1.25.08a5798191dea
golang.org/x/net@v0.28.0
0.33.0
1
temporalio/server:1.22.0ddeebf8bad8f
golang.org/x/net@v0.14.0
0.33.0
1
temporalio/server:1.15.1e26758f5a1bf
golang.org/x/net@v0.0.0-20220127200216-cd36cc0744dd
0.33.0
1
temporalio/ui:2.30.25c2a3645d09c
golang.org/x/net@v0.28.0
0.33.0
1
temporalio/ui:2.33.05c586a3c8ec5
golang.org/x/net@v0.17.0
0.33.0
1
thanosio/thanos:v0.19.088276fcd1491
golang.org/x/net@v0.0.0-20210119194325-5f4716e94777
0.33.0
1
thanosio/thanos:v0.15.0b12d5c31bf5a
golang.org/x/net@v0.0.0-20200707034311-ab3426394381
0.33.0
1
thesisrobot/lnd:v0.16.4-beta-c287129953689
golang.org/x/net@v0.8.0
0.33.0
1
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
golang.org/x/net@v0.0.0-20210913180222-943fd674d43e
0.33.0
1
thmmniii/fbs-runner:v1.27.186105349c1a3
golang.org/x/net@v0.17.0
0.33.0
1
thomseddon/traefik-forward-auth:269a2c985d2c5
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.33.0
1
thomseddon/traefik-forward-auth:latestb364aa6a4117
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.33.0
1
thomseddon/traefik-forward-auth:2.2.0e875194d67e2
golang.org/x/net@v0.0.0-20190930134127-c5a3c61f89f3
0.33.0
1
tile38/tile38:1.33.4afb7e82f9485
golang.org/x/net@v0.23.0
0.33.0
1
timescale/timescaledb-ha:pg16d7db8f1085a3
golang.org/x/net@v0.26.0
0.33.0
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
golang.org/x/net@v0.24.0
0.33.0
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
golang.org/x/net@v0.21.0
0.33.0
1
tksky1/cubeuniverse:0.1alphaec7b889f380f
golang.org/x/net@v0.3.1-0.20221206200815-1e63c2f08a10
0.33.0
1
tobiasbp/db-backup:0.0.314bee6e33a26
golang.org/x/net@v0.0.0-20191109021931-daa7c04131f5
0.33.0
1
tobirachel/node-project3:v17d9f37154994
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.33.0
1
toucansoftware/spa-reloader:latestc187b1fba501
golang.org/x/net@v0.0.0-20200520004742-59133d7f0dd7
0.33.0
1
traefik/mesh:v1.4.8cf071f3e165c
golang.org/x/net@v0.0.0-20220624214902-1bab6f366d9e
0.33.0
1
traefik/whoami:v1.10.21474027c3166
golang.org/x/net@v0.25.0
0.33.0
1
tranhailong/nfs-server:4.2-2-gcsfuse028662749be2
golang.org/x/net@v0.4.0
0.33.0
1
treeverse/lakefs:0.69.0478f37a6cffc
golang.org/x/net@v0.0.0-20220412020605-290c469a71a5
0.33.0
1
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
golang.org/x/net@v0.0.0-20210614182718-04defd469f4e
0.33.0
1
turt2live/matrix-media-repo:v1.2.8bfbd459f89a5
golang.org/x/net@v0.0.0-20210226172049-e18ecbb05110
0.33.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.