StackRadar

CVE-2026-32286

High

Advisory

Published 16 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
160
of 17,781 indexed, latest versions
Container images
162
deployed by those charts
Fix available
None
affected package

Denial of service in github.com/jackc/pgproto3/v2

Carried by container images the latest versions of 160 of 17,781 indexed charts deploy, on 162 images.

Affected packageAffected versionsFixed inImages
github.com/jackc/pgproto3/v2golangv2.0.0, v2.0.1, v2.0.2, v2.0.4+9 moreno fix listed162
OSV records
GHSA-jqcq-xjh3-6g23
Also known as
GO-2026-4518

Charts affected

160 by stars
ChartLatestAffected imagesRadar Score
trilliansigstoreVerified publisher0.3.172 of 5See more

trillian sigstore 0.3.17

2 of the 5 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/trillian_log_serverdigest-pinned5a878e4e4f03
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
ghcr.io/sigstore/scaffolding/trillian_log_signerdigest-pinned28c5ff40963f
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed

Open the chart page →

2,808
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

1,494
harborsoftonic1.13.03 of 8See more

harbor softonic 1.13.0

3 of the 8 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
goharbor/harbor-jobservice:v2.9.039435daedd0c
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
goharbor/harbor-registryctl:v2.9.0cce272836449
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

7,672
orchestratorsubstraVerified publisher8.8.01 of 3See more

orchestrator substra 8.8.0

1 of the 3 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

2,991
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
github.com/jackc/pgproto3/v2@v2.0.1
no fix listed

Open the chart page →

3,764
tfy-cloudflaredtruefoundryVerified publisher0.5.01 of 2See more

tfy-cloudflared truefoundry 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed

Open the chart page →

2,015
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/jackc/pgproto3/v2@v2.3.0
no fix listed

Open the chart page →

6,132
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/jackc/pgproto3/v2@v2.0.7
no fix listed

Open the chart page →

13,459
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

2,022

Container images carrying it

162 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
otel/opentelemetry-collector-contrib:0.89.0995f17004231
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
reportportal/migrations:5.15.4464468240d7b
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
schemahero/schemahero-manager:0.22.11609e1a05cd3
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
scholtz2/aramid-conduit:v1.9.0-stable3a3b3d3277d2
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
scholtz2/aramid-indexer:v3.9.0-stable6770214bc881
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
sky5367/locust-plugins-timescale:latestd3150f201471
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/jackc/pgproto3/v2@v2.3.0
no fix listed
1
supabase/gotrue:v2.189.0385184459f57
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
supabase/gotrue:v2.91.07174d551d720
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
supabase/gotrue:v2.163.0ba4ddc594b0b
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
thesisrobot/lnd:v0.16.4-beta-c287129953689
github.com/jackc/pgproto3/v2@v2.1.1
no fix listed
1
thesisrobot/lnd:v0.14.1-betad94c8dbf6dac
github.com/jackc/pgproto3/v2@v2.1.1
no fix listed
1
timescale/timescaledb:latest-pg12645fd9e92d76
github.com/jackc/pgproto3/v2@v2.3.0
no fix listed
1
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
github.com/jackc/pgproto3/v2@v2.3.0
no fix listed
1
timescale/timescaledb-ha:pg14.6-ts2.9.1-p1cdb9ae118899
github.com/jackc/pgproto3/v2@v2.3.0
no fix listed
1
timescale/timescaledb-ha:pg17.2-ts2.18.2e8d0a9cc3db5
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
timescale/timescaledb-ha:pg14-ts2.6-latested719c0cd19d
github.com/jackc/pgproto3/v2@v2.0.0
no fix listed
1
timescale/timescaledb-postgis:latest-pg127758704d4a14
github.com/jackc/pgproto3/v2@v2.0.0
no fix listed
1
treeverse/lakefs:0.69.0478f37a6cffc
github.com/jackc/pgproto3/v2@v2.0.7
no fix listed
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/jackc/pgproto3/v2@v2.0.7
no fix listed
1
yugabytedb/yugabyte:2026.1.1.1-b23926eedf0ff4
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
yugabytedb/yugabyte:2026.1.1.0-b91de2e00278645
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
github.com/jackc/pgproto3/v2@v2.0.4
no fix listed
1
gcr.io/cockroachlabs-helm-charts/cockroach-self-signer-cert:1.3e225fe7eaa55
github.com/jackc/pgproto3/v2@v2.0.4
no fix listed
1
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
github.com/jackc/pgproto3/v2@v2.2.0
no fix listed
1
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
ghcr.io/cncf/clowarden/dbmigrator:v0.2.3c022fd42de45
github.com/jackc/pgproto3/v2@v2.0.2
no fix listed
1
ghcr.io/cncf/gitvote/dbmigrator:v1.5.0f1e7efe440da
github.com/jackc/pgproto3/v2@v2.0.2
no fix listed
1
ghcr.io/erpc/erpc:0.1.18bfed3d49a08
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ghcr.io/erpc/erpc:0.0.49f5654f745d4c
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ghcr.io/flatcar/nebraska:4.0.05c9e99ff7167
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
ghcr.io/glassflow/glassflow-etl-migration:v3.2.07db1a1bf3dae
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ghcr.io/justwatchcom/sql_exporter:v0.8c4b1d3d0f052
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ghcr.io/loafoe/caddy-token:v0.3.0528f2174fa2f
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
ghcr.io/netsoc/iamd:1.1.22fe6b69b20d7
github.com/jackc/pgproto3/v2@v2.0.6
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
ghcr.io/quenchworks/images/hydraffaf6629b97b
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ghcr.io/quenchworks/images/kratosc72eb6f93a26
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ghcr.io/riotkit-org/backup-repository:v4.0.0ab41ffa78f69
github.com/jackc/pgproto3/v2@v2.2.0
no fix listed
1
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
github.com/jackc/pgproto3/v2@v2.0.2
no fix listed
1
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.