StackRadar

CVE-2026-32286

High

Advisory

Published 16 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
160
of 17,781 indexed, latest versions
Container images
162
deployed by those charts
Fix available
None
affected package

Denial of service in github.com/jackc/pgproto3/v2

Carried by container images the latest versions of 160 of 17,781 indexed charts deploy, on 162 images.

Affected packageAffected versionsFixed inImages
github.com/jackc/pgproto3/v2golangv2.0.0, v2.0.1, v2.0.2, v2.0.4+9 moreno fix listed162
OSV records
GHSA-jqcq-xjh3-6g23
Also known as
GO-2026-4518

Charts affected

160 by stars
ChartLatestAffected imagesRadar Score
trilliansigstoreVerified publisher0.3.172 of 5See more

trillian sigstore 0.3.17

2 of the 5 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/trillian_log_serverdigest-pinned5a878e4e4f03
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
ghcr.io/sigstore/scaffolding/trillian_log_signerdigest-pinned28c5ff40963f
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed

Open the chart page →

2,808
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

1,494
harborsoftonic1.13.03 of 8See more

harbor softonic 1.13.0

3 of the 8 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
goharbor/harbor-jobservice:v2.9.039435daedd0c
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
goharbor/harbor-registryctl:v2.9.0cce272836449
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

7,672
orchestratorsubstraVerified publisher8.8.01 of 3See more

orchestrator substra 8.8.0

1 of the 3 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

2,991
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
github.com/jackc/pgproto3/v2@v2.0.1
no fix listed

Open the chart page →

3,764
tfy-cloudflaredtruefoundryVerified publisher0.5.01 of 2See more

tfy-cloudflared truefoundry 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed

Open the chart page →

2,015
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/jackc/pgproto3/v2@v2.3.0
no fix listed

Open the chart page →

6,132
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/jackc/pgproto3/v2@v2.0.7
no fix listed

Open the chart page →

13,459
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

2,022

Container images carrying it

162 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gboxproxy/gbox:v1.0.63a9f4a711d5c
github.com/jackc/pgproto3/v2@v2.2.0
no fix listed
1
goharbor/harbor-core:v2.9.06412d679fdc3
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
goharbor/harbor-core:v2.5.386bf3031f4a7
github.com/jackc/pgproto3/v2@v2.1.1
no fix listed
1
goharbor/harbor-core:v2.14.3a30e5a8be3d9
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
goharbor/harbor-core:v2.11.1c017dd84ee96
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
goharbor/harbor-jobservice:v2.9.039435daedd0c
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
github.com/jackc/pgproto3/v2@v2.1.1
no fix listed
1
goharbor/harbor-jobservice:v2.14.3e2b0298e894d
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
goharbor/harbor-registryctl:v2.5.37f82ed1e2635
github.com/jackc/pgproto3/v2@v2.1.1
no fix listed
1
goharbor/harbor-registryctl:v2.9.0cce272836449
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
goharbor/harbor-registryctl:v2.14.3ddf6bb429eb6
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
github.com/jackc/pgproto3/v2@v2.0.1
no fix listed
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
github.com/jackc/pgproto3/v2@v2.1.1
no fix listed
1
grafana/agent:v0.44.23364714a2f64
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
grafana/agent:v0.40.3f6cbec9409be
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
grafana/alloy:v1.5.101a63f4e032c
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
grafana/alloy:v1.4.306bdcbb51fc2
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
grafana/alloy:v1.16.384b76d56c594
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
grafana/alloy:v1.11.38c7256f412fe
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
grafana/alloy:v1.1.1c3dac4e26471
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
grafana/alloy:v1.14.0f50931848bd8
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
hashicorp/boundary:0.15.3339b78b61750
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
hashicorp/boundary:0.21.037bf86488b74
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
hashicorp/boundary:0.8.1fb70bd9210ff
github.com/jackc/pgproto3/v2@v2.2.0
no fix listed
1
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
hashicorp/vault:1.14.0b2177a8bfe85
github.com/jackc/pgproto3/v2@v2.2.0
no fix listed
1
hashicorp/vault:1.19.0bbb7f98dc67d
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
ispras/svacer:11-2-042aa9fa9f189
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
kubevious/ui:1.2.16233e84bdd59
github.com/jackc/pgproto3/v2@v2.2.0
no fix listed
1
layer5/meshery-app-mesh:stable-latest77d59943b3d6
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
layer5/meshery-kuma:stable-latest9d25f029a8a2
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
layer5/meshery-nginx-sm:stable-latestb3864dfd47ad
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
layer5/meshery-osm:stable-latestec898e5786c6
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
layer5/meshery-traefik-mesh:stable-latest797fa7a03570
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
library/caddy:2.660fb54d36b4b
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
library/telegraf:1.20.428e98eece020
github.com/jackc/pgproto3/v2@v2.0.1
no fix listed
1
library/telegraf:1.27507a3eecf809
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
library/telegraf:1.19.0-alpine794079a7f241
github.com/jackc/pgproto3/v2@v2.0.1
no fix listed
1
library/telegraf:1.19-alpineaddb86c0c520
github.com/jackc/pgproto3/v2@v2.0.1
no fix listed
1
library/vault:1.13.3f98ac9dd97b0
github.com/jackc/pgproto3/v2@v2.2.0
no fix listed
1
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
migrate/migrate:latest76cc2074cb66
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
moul/sshportal:v1.19.3332b603727c3
github.com/jackc/pgproto3/v2@v2.2.0
no fix listed
1
oryd/hydra:v2.3.0b94007e19a1f
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
oryd/hydra:v26.2.0ff67c7fb5f95
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
oryd/keto:v26.2.0bfdb8b9e283a
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
oryd/kratos:v26.2.02a13bb8d362c
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
oryd/kratos:v1.1.08f15006a080d
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
otel/opentelemetry-collector-contrib:0.83.071fcef33ae71
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.