StackRadar

CVE-2024-49364

Critical

Advisory

Published 30 Jun 2025In the index since 9 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4
of 18,053 indexed, latest versions
Container images
4
deployed by those charts
Fix available
1 of 1
affected package

tiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environment

Carried by container images the latest versions of 4 of 18,053 indexed charts deploy, on 4 images.

Affected packageAffected versionsFixed inImages
tiny-secp256k1npm1.1.61.1.74
OSV records
GHSA-7mc2-6phr-23xc

Charts affected

4 by stars
ChartLatestAffected imagesRadar Score
interbtc-hydrainterlay0.1.151 of 4See more

interbtc-hydra interlay 0.1.15

1 of the 4 container images this version deploys carry CVE-2024-49364.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
tiny-secp256k1@1.1.6
1.1.7

Open the chart page →

7,786
interlay-firesquidinterlay0.1.111 of 4See more

interlay-firesquid interlay 0.1.11

1 of the 4 container images this version deploys carry CVE-2024-49364.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
tiny-secp256k1@1.1.6
1.1.7

Open the chart page →

5,207
console-webovrclk-20.1.11 of 1See more

console-web ovrclk-2 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-49364.

Container imageDigestPackageFixed in
ghcr.io/akash-network/deploy-web:2.46.0ac540172c120
tiny-secp256k1@1.1.6
1.1.7

Open the chart page →

3,176
provider-consoleovrclk-20.1.01 of 1See more

provider-console ovrclk-2 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-49364.

Container imageDigestPackageFixed in
ghcr.io/akash-network/provider-console:1.0.04d4c19a8d3ff
tiny-secp256k1@1.1.6
1.1.7

Open the chart page →

2,659

Container images carrying it

4 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
tiny-secp256k1@1.1.6
1.1.7
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
tiny-secp256k1@1.1.6
1.1.7
1
ghcr.io/akash-network/deploy-web:2.46.0ac540172c120
tiny-secp256k1@1.1.6
1.1.7
1
ghcr.io/akash-network/provider-console:1.0.04d4c19a8d3ff
tiny-secp256k1@1.1.6
1.1.7
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.