StackRadar

CVE-2024-7254

High

Advisory

Published 19 Sept 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.028
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
256
of 17,781 indexed, latest versions
Container images
260
deployed by those charts
Fix available
5 of 5
affected packages

protobuf-java has potential Denial of Service issue

Carried by container images the latest versions of 256 of 17,781 indexed charts deploy, on 260 images.

Affected packageAffected versionsFixed inImages
protobuf-javamaven2.4.1, 2.5.0, 2.6.0, 2.6.1+56 more3.25.5, 4.27.5238
protobufdeb2.6.1-1.3, 3.0.0-9.1ubuntu1, 3.0.0-9.1ubuntu1.1, 3.6.1.3-2ubuntu5+2 more2.6.1-1.3ubuntu0.1~esm4, 3.0.0-9.1ubuntu1.1+esm3, 3.6.1.3-2ubuntu5.2+esm2, 3.21.12-3+deb12u114
google-protobufgem3.8.0, 3.22.3, 3.24.23.25.56
protobuf-javalitemaven3.11.4, 3.18.0, 3.19.4, 3.21.12+1 more3.25.56
protobuf-kotlinmaven3.19.43.25.53
OSV records
DEBIAN-CVE-2024-7254GHSA-735f-pc8j-v9w8UBUNTU-CVE-2024-7254
Also known as
USN-7629-2

Charts affected

256 by stars
ChartLatestAffected imagesRadar Score
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2024-7254.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
protobuf-java@3.8.0
3.25.5

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2024-7254.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
protobuf-java@3.12.2
3.25.5

Open the chart page →

28,605
hazelcastwenerme5.10.22 of 2See more

hazelcast wenerme 5.10.2

2 of the 2 container images this version deploys carry CVE-2024-7254.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
protobuf-java@3.21.12
3.25.5
hazelcast/management-center:5.5.2991ddb27c251
protobuf-java@3.25.3
3.25.5

Open the chart page →

2,634
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-7254.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
protobuf-java@3.13.0
3.25.5

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2024-7254.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
protobuf-java@3.11.0
3.25.5

Open the chart page →

5,806
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-7254.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
protobuf-java@3.21.7
3.25.5

Open the chart page →

5,846

Container images carrying it

260 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
emeraldpay/dshackle:0.14.0126f0ae0b388
protobuf-java@3.17.2
3.25.5
1
emeraldpay/dshackle:0.12ac2a4bc66ab6
protobuf-java@3.12.0
3.25.5
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
protobuf-java@3.16.1
3.25.5
1
expediagroup/pitchfork:1.314f2cf61e7de9
protobuf-java@3.18.0
3.25.5
1
farberg/apache-knox-docker:1.6.14b4a22487394
protobuf-java@3.14.0
3.25.5
1
featurehub/dacha2:1.9.1c8d5551b5e40
protobuf-java@3.25.3
3.25.5
1
featurehub/edge:1.9.198ad426737f6
protobuf-java@3.25.3
3.25.5
1
featurehub/mr:1.9.1477d8bf771a9
protobuf-java@3.25.3
3.25.5
1
fimperato/sparkvid-api:1.0.5-RELEASE604012b77841
protobuf-java@2.5.0
3.25.5
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
protobuf@3.6.1.3-2ubuntu5.2
3.6.1.3-2ubuntu5.2+esm2
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
protobuf-java@2.5.0
3.25.5
1
fjvela/urjc-fjvela-worker:1.0.170cebf67bd66
protobuf-java@3.10.0
3.25.5
1
flyway/flyway:9.1545b5d7cdc75a
protobuf-java@3.21.7
3.25.5
1
flyway/flyway:9.14.1-alpine80f12c80502b
protobuf-java@3.21.7
3.25.5
1
folioci/mod-marccat:latest1b57d690d568
protobuf-java@2.6.0
3.25.5
1
fonoster/routr:1.0.0-rc52ca65af17cbc
protobuf-java@3.6.1
3.25.5
1
fonoster/routr-edgeport:2.13.6d08a8a574a50
protobuf-java@3.21.7
3.25.5
1
fonoster/routr-requester:2.13.6e0c823506eb2
protobuf-java@3.21.7
3.25.5
1
franrobles8/planner:v3.099985392d63c
protobuf-java@3.10.0
3.25.5
1
fthomas/scala-steward:latest367afe974b7a
protobuf-java@3.19.6
3.25.5
1
gchq/accumulo:2.0.1c460bb587d6d
protobuf-java@3.7.1
3.25.5
1
gradiant/hdfs:3.2.2e3bf364fe713
protobuf-java@2.5.0
3.25.5
1
graylog2/server:2.4.3-38ff28c66e6c1
protobuf-java@3.4.0
3.25.5
1
gridgain/community:8.9.11d32d182a0e6a
protobuf-java@3.5.0
3.25.5
1
gurolakman/oam:4.0.0ed8fd2062548
protobuf-java@2.5.0
3.25.5
1
hazelcast/hazelcast:5.3.18fe26efde8e1
protobuf-java@3.7.1
3.25.5
1
hazelcast/hazelcast-jet:4.5.3a825ecbe9fda
protobuf-java@3.13.0
3.25.5
1
hazelcast/management-center:5.3.2f9d34300d330
protobuf-java@3.23.3
3.25.5
1
hmediade/printserver:latest481a552c8e1c
protobuf-java@2.5.0
3.25.5
1
huertaslopez/i.huertas.2021-v.martinp.2021-planner:2.0.0e2c18bd65472
protobuf-java@3.10.0
3.25.5
1
hugohg34/planner:0.0.2171f61e8d7e2
protobuf-java@3.10.0
3.25.5
1
ibmcom/app-nav-api:1.0.1ce9d2a564273
protobuf-java@3.4.0
3.25.5
1
ibmcom/app-nav-was-controller:1.0.1a6748792da26
protobuf-java@3.4.0
3.25.5
1
ibmcom/bai-flink-dev:19.0.2e31ff09e8aad
protobuf-java@2.6.1
3.25.5
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
protobuf-java@3.17.3
3.25.5
1
intel/trusted-certificate-issuer:0.5.0591a9db4a427
protobuf@3.6.1.3-2ubuntu5
3.6.1.3-2ubuntu5.2+esm2
1
jacobalberty/unifi:v7.1.664a3616625dda
protobuf-java@3.6.0
3.25.5
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
protobuf-java@3.6.0
3.25.5
1
jacobalberty/unifi:5.10.19c409924e2463
protobuf-java@3.6.1
3.25.5
1
jingking/geonetwork-hnap:4.2.843e74ab234e1
protobuf-java@3.19.4
3.25.5
1
jordan/icinga2:latestf75025fe8ea8
protobuf@3.21.12-3
3.21.12-3+deb12u1
1
just1not2/streama:1.10.48a2305192dec
protobuf-java@2.5.0
3.25.5
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
protobuf-java@3.23.4
3.25.5
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
protobuf-java@3.23.4
3.25.5
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
protobuf-java@3.23.4
3.25.5
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
protobuf-java@3.23.4
3.25.5
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
protobuf-java@3.12.0
3.25.5
1
ladeit/ladeit:latest962b665ffe82
protobuf-java@3.4.0
3.25.5
1
library/crate:4.7.0c7984a05e15b
protobuf-java@2.5.0
3.25.5
1
library/elasticsearch:8.15.0310b9fc03b06
protobuf-java@3.21.9
3.25.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.