StackRadar

CVE-2024-7254

High

Advisory

Published 19 Sept 2024In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.028
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
256
of 17,781 indexed, latest versions
Container images
260
deployed by those charts
Fix available
5 of 5
affected packages

protobuf-java has potential Denial of Service issue

Carried by container images the latest versions of 256 of 17,781 indexed charts deploy, on 260 images.

Affected packageAffected versionsFixed inImages
protobuf-javamaven2.4.1, 2.5.0, 2.6.0, 2.6.1+56 more3.25.5, 4.27.5238
protobufdeb2.6.1-1.3, 3.0.0-9.1ubuntu1, 3.0.0-9.1ubuntu1.1, 3.6.1.3-2ubuntu5+2 more2.6.1-1.3ubuntu0.1~esm4, 3.0.0-9.1ubuntu1.1+esm3, 3.6.1.3-2ubuntu5.2+esm2, 3.21.12-3+deb12u114
google-protobufgem3.8.0, 3.22.3, 3.24.23.25.56
protobuf-javalitemaven3.11.4, 3.18.0, 3.19.4, 3.21.12+1 more3.25.56
protobuf-kotlinmaven3.19.43.25.53
OSV records
DEBIAN-CVE-2024-7254GHSA-735f-pc8j-v9w8UBUNTU-CVE-2024-7254
Also known as
USN-7629-2

Charts affected

256 by stars
ChartLatestAffected imagesRadar Score
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2024-7254.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
protobuf-java@3.8.0
3.25.5

Open the chart page →

5,460
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2024-7254.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
protobuf-java@3.12.2
3.25.5

Open the chart page →

28,605
hazelcastwenerme5.10.22 of 2See more

hazelcast wenerme 5.10.2

2 of the 2 container images this version deploys carry CVE-2024-7254.

Container imageDigestPackageFixed in
hazelcast/hazelcast:5.5.05dd5d31c7a06
protobuf-java@3.21.12
3.25.5
hazelcast/management-center:5.5.2991ddb27c251
protobuf-java@3.25.3
3.25.5

Open the chart page →

2,634
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-7254.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
protobuf-java@3.13.0
3.25.5

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2024-7254.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
protobuf-java@3.11.0
3.25.5

Open the chart page →

5,806
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2024-7254.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
protobuf-java@3.21.7
3.25.5

Open the chart page →

5,846

Container images carrying it

260 by charts deploying them

A fixed version is listed for 5 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
marcelmay/hadoop-hdfs-fsimage-exporter:1.26292c0a41ffa
protobuf-java@2.5.0
3.25.5
8
gradiant/hdfs:2.7.73b28784ba41f
protobuf-java@2.5.0
3.25.5
7
bde2020/hive:2.3.2-postgresql-metastore620267768985
protobuf-java@2.5.0
3.25.5
4
gradiant/hbase-base:2.0.1a1ee6de94c04
protobuf-java@2.5.0
3.25.5
4
mastercloudapps/planner:v1.2340a950b311b2
protobuf-java@3.10.0
3.25.5
4
apache/shenyu-admin:2.4.2e8b7c4ddd069
protobuf-java@3.8.0
3.25.5
3
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
protobuf-java@3.8.0
3.25.5
3
codeurjc/planner:v1.0800cf520c245
protobuf-java@3.10.0
3.25.5
3
gchq/hdfs:3.3.35ec58edbb2db
protobuf-java@2.5.0
3.25.5
3
library/solr:8.11.18c5f7881cebb
protobuf-java@3.11.0
3.25.5
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
protobuf@2.6.1-1.3
2.6.1-1.3ubuntu0.1~esm4
3
provectuslabs/kafka-ui:latest8f2ff02d64b0
protobuf-java@3.23.3
3.25.5
3
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
protobuf-java@3.11.0
3.25.5
2
apache/druid:37.0.00116fb802786
protobuf-java@3.7.1
3.25.5
2
apache/nifi-registry:1.26.07cdfd8deec92
protobuf-java@3.24.3
3.25.5
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
protobuf-java@2.4.1
3.25.5
2
apache/rocketmq:5.4.0319cd8a81ed1
protobuf-java@3.20.1
3.25.5
2
apacherocketmq/rocketmq-dashboard:2.1.0ce78506bd6fe
protobuf-java@3.20.1
3.25.5
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
google-protobuf@3.22.3
3.25.5
2
danisla/hadoop:2.9.0255ba2dd739b
protobuf-java@2.5.0
3.25.5
2
dependencytrack/apiserver:4.6.3485ac0952c02
protobuf-java@3.19.4
3.25.5
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
protobuf-java@2.5.0
3.25.5
2
gradiant/opentsdb:2.4.0c33d53913869
protobuf-java@2.5.0
3.25.5
2
gradiant/spark:2.4.4-python-alpine97657d56e927
protobuf-java@2.5.0
3.25.5
2
hazelcast/hazelcast:5.5.05dd5d31c7a06
protobuf-java@3.21.12
3.25.5
2
hazelcast/management-center:5.5.2991ddb27c251
protobuf-java@3.25.3
3.25.5
2
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
protobuf-java@3.19.4
3.25.5
2
inaccel/coral:2.18c53744ed70b
protobuf-java@3.25.3
3.25.5
2
library/elasticsearch:7.17.35e6ac15bf6a5
protobuf-java@3.16.1
3.25.5
2
library/neo4j:5.20.052d3dec8d455
protobuf-java@3.25.2
3.25.5
2
metabase/metabase:v0.45.21fb334ce4820
protobuf-java@3.17.3
3.25.5
2
nacos/nacos-server:v2.1.0dcf04549c6d7
protobuf-java@3.16.1
3.25.5
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
protobuf-java@3.19.1
3.25.5
2
opensearchproject/opensearch:2.1.04254021a8c71
protobuf-java@3.19.2
3.25.5
2
opensearchproject/opensearch:1.1.0967d7f57f72f
protobuf-java@3.11.0
3.25.5
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
protobuf-java@3.19.2
3.25.5
2
5200710/hadoop:3.2.3-java8092d3088a5fb
protobuf-java@3.7.1
3.25.5
1
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
protobuf-java@2.5.0
3.25.5
1
adagber/planner:v1.0e5c1ed097752
protobuf-java@3.10.0
3.25.5
1
adityaprasadpathak/myapp:3.07e3b9777362c
protobuf-java@3.25.3
3.25.5
1
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
protobuf-java@3.25.3
3.25.5
1
airbyte/cron:0.40.17caf4f551c546
protobuf-java@3.21.6
3.25.5
1
aktosecurity/akto-api-protection:localbcd7382c9c1b
protobuf-java@3.21.5
3.25.5
1
aktosecurity/source-code-analyser:a-1703-merge274042ed7a53
protobuf-java@3.21.5
3.25.5
1
amartinm82/planner:v2.01184353ff57b
protobuf-java@3.10.0
3.25.5
1
anguda/ant-media:2.5c435285fc241
protobuf-java@3.12.4
3.25.5
1
apache/bookkeeper:4.14.5a7d9970c148f
protobuf-java@3.14.0
3.25.5
1
apache/drill:1.21.11f96558fd292
protobuf-java@2.5.0
3.25.5
1
apache/druid:29.0.10cef139b6bf1
protobuf-java@3.7.1
3.25.5
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
protobuf-java@3.7.1
3.25.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.