StackRadar

CVE-2024-51744

Low

Advisory

Published 4 Nov 2024In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.1
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
384
of 17,781 indexed, latest versions
Container images
407
deployed by those charts
Fix available
1 of 1
affected package

Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations

Carried by container images the latest versions of 384 of 17,781 indexed charts deploy, on 407 images.

Affected packageAffected versionsFixed inImages
github.com/golang-jwt/jwt/v4golangv4.0.0, v4.1.0, v4.2.0, v4.3.0+4 more4.5.1407
OSV records
GHSA-29wx-vh33-7x7r
Also known as
GO-2024-3250

Charts affected

384 by stars
ChartLatestAffected imagesRadar Score
hermitcrabseal-ioVerified publisher0.1.41 of 2See more

hermitcrab seal-io 0.1.4

1 of the 2 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1

Open the chart page →

4,881
miniosergiotocaliniVerified publisher1.0.01 of 1See more

minio sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
quay.io/minio/minio:RELEASE.2023-07-21T21-12-44Z8e5e9490cd50
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

4,203
keycloak-configuratorsikalabs0.2.01 of 1See more

keycloak-configurator sikalabs 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
hashicorp/terraform:1.44dcb45513699
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1

Open the chart page →

2,863
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

2,314
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

1,494
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

2,429
mimirskyloud-helm-chartsVerified publisher5.5.12 of 5See more

mimir skyloud-helm-charts 5.5.1

2 of the 5 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
quay.io/minio/mc:RELEASE.2023-09-29T16-41-22Za784ce6e3b1b
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
quay.io/minio/minio:RELEASE.2023-09-30T07-02-29Z6262bc9a2730
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

10,651
harborsoftonic1.13.03 of 8See more

harbor softonic 1.13.0

3 of the 8 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
goharbor/harbor-registryctl:v2.9.0cce272836449
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

7,672
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

2,505
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.1

Open the chart page →

30,687
ambassador-manifestssqream-chartsVerified publisher0.6.31 of 1See more

ambassador-manifests sqream-charts 0.6.3

1 of the 1 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
datawire/aes:3.11.195ec30b3c732
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

2,416
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2022.12.12-debian-11-r90f7c8ac484ac
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1

Open the chart page →

66,266
prestashopstack-prestahop22.0.01 of 4See more

prestashop stack-prestahop 22.0.0

1 of the 4 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
filebrowser/filebrowser:v2.23.086e8449ff8ff
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.1

Open the chart page →

3,073
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

2,938
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

6,779
sn-platform-slimstreamnative1.11.442 of 6See more

sn-platform-slim streamnative 1.11.44

2 of the 6 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.1
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

10,134
orchestratorsubstraVerified publisher8.8.01 of 3See more

orchestrator substra 8.8.0

1 of the 3 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1

Open the chart page →

2,991
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.1

Open the chart page →

10,902
agentssynapse0.1.301 of 9See more

agents synapse 0.1.30

1 of the 9 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.1

Open the chart page →

7,244
cctpsynapse0.3.01 of 4See more

cctp synapse 0.3.0

1 of the 4 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.1

Open the chart page →

1,815
promexportersynapse0.1.11 of 1See more

promexporter synapse 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.1

Open the chart page →

1,704
temporaltemporal0.28.93 of 13See more

temporal temporal 0.28.9

3 of the 13 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.22.0836af062af30
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.1
temporalio/server:1.22.0ddeebf8bad8f
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.1

Open the chart page →

21,005
monitoringthl-chartsVerified publisher0.1.14 of 10See more

monitoring thl-charts 0.1.1

4 of the 10 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
grafana/grafana:8.5.042d3e6bc1865
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
grafana/loki:2.5.0f9ef133793af
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
grafana/promtail:2.4.2626900031c4e
github.com/golang-jwt/jwt/v4@v4.0.0
4.5.1
quay.io/prometheus/prometheus:v2.34.0b37103e03399
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1

Open the chart page →

18,908
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

2,477
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1

Open the chart page →

4,815
tfy-lokitruefoundryVerified publisher0.1.62 of 2See more

tfy-loki truefoundry 0.1.6

2 of the 2 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
grafana/loki:2.9.1035b02acc6765
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
grafana/promtail:2.9.1063a2e57a5b14
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

2,813
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1

Open the chart page →

4,960
consulwarjiang1.3.01 of 2See more

consul warjiang 1.3.0

1 of the 2 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
hashicorp/consul:1.17.0712fe02d2f84
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1

Open the chart page →

4,060
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
github.com/golang-jwt/jwt/v4@v4.1.0
4.5.1

Open the chart page →

6,138
openebswenerme3.10.01 of 3See more

openebs wenerme 3.10.0

1 of the 3 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
openebs/node-disk-operator:2.1.06afe2123c457
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1

Open the chart page →

10,489
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
temporalio/server:1.15.1e26758f5a1bf
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1

Open the chart page →

22,665
wexa-studiowexa-studio1.2.02 of 15See more

wexa-studio wexa-studio 1.2.0

2 of the 15 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
minio/minio:RELEASE.2024-01-16T16-07-38Z4c4a4876193f
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

2,022
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2024-51744.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
lishimeng/owl-messager:v0.11.23d00485e64dc
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1

Open the chart page →

3,880

Container images carrying it

407 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.1
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.1
1
ghcr.io/k10app/businit:latest94c9a3e799c2
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
1
ghcr.io/kalgurn/grl-exporter:v3.2.0bd109b2bda38
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/kgma74/dockyard:0.4.0b40439329191
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/kore3lab/kore-board.terminal:v0.5.5f52e66eff50b
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
1
ghcr.io/kubedb/kubedb-autoscaler:v0.25.0df6b11907d33
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/kubedb/kubedb-dashboard:v0.16.07bfe1c07bd9b
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/kubedb/kubedb-ops-manager:v0.27.1ec36422b09af
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/kubedb/kubedb-provisioner:v0.40.242574f512837
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/kubedb/kubedb-schema-manager:v0.16.09518de37eed5
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/kubedb/kubedb-webhook-server:v0.16.2e24894e32cbc
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/kubedb/provider-aws:v0.27.049b1c312e342
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
1
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
1
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
1
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
1
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
1
ghcr.io/kubeshop/botkube:v1.0.0669e27a5d1af
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/kvaps/kube-fencing-controller:v2.4.0313edfec2fca
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
1
ghcr.io/kyverno/background-controller:v1.12.506ed5db6cd33
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/kyverno/cleanup-controller:v1.12.5b914032ef9ad
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
github.com/golang-jwt/jwt/v4@v4.3.0
4.5.1
1
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
github.com/golang-jwt/jwt/v4@v4.3.0
4.5.1
1
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
1
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
github.com/golang-jwt/jwt/v4@v4.2.0
4.5.1
1
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/openfaasltd/federated-gateway:0.2.39066d7b3e6a1
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/openfaasltd/jetstream-queue-worker:0.3.37d96366e208b1
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/openfaasltd/sns-connector:0.2.0e9ab76a4ec77
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
github.com/golang-jwt/jwt/v4@v4.4.1
4.5.1
1
ghcr.io/runatlantis/atlantis:v0.47.1511231955463
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
github.com/golang-jwt/jwt/v4@v4.5.0
4.5.1
1
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/spiffe/spire-server:1.6.0635b9024cad2
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/stashed/stash-enterprise:v0.32.0e9bde36e34b7
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
github.com/golang-jwt/jwt/v4@v4.4.2
4.5.1
1
ghcr.io/synapsecns/sanguine/agents:6e3887fc2a05aff0d159453cedbfbe5024b910bf81a9ebc899a4
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.1
1
ghcr.io/synapsecns/sanguine/cctp-relayer:b5a1dd5288f1a18eb05994e130d626fed45a56fc2f1408c94168
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.1
1
ghcr.io/synapsecns/sanguine/promexporter:4a9aad096c2bd1160e56e5472ddac77fa0cde2e9416c1c5aeb86
github.com/golang-jwt/jwt/v4@v4.4.3
4.5.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.