StackRadar

CVE-2026-32286

High

Advisory

Published 16 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
160
of 17,781 indexed, latest versions
Container images
162
deployed by those charts
Fix available
None
affected package

Denial of service in github.com/jackc/pgproto3/v2

Carried by container images the latest versions of 160 of 17,781 indexed charts deploy, on 162 images.

Affected packageAffected versionsFixed inImages
github.com/jackc/pgproto3/v2golangv2.0.0, v2.0.1, v2.0.2, v2.0.4+9 moreno fix listed162
OSV records
GHSA-jqcq-xjh3-6g23
Also known as
GO-2026-4518

Charts affected

160 by stars
ChartLatestAffected imagesRadar Score
trilliansigstoreVerified publisher0.3.172 of 5See more

trillian sigstore 0.3.17

2 of the 5 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/trillian_log_serverdigest-pinned5a878e4e4f03
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
ghcr.io/sigstore/scaffolding/trillian_log_signerdigest-pinned28c5ff40963f
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed

Open the chart page →

2,808
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

1,494
harborsoftonic1.13.03 of 8See more

harbor softonic 1.13.0

3 of the 8 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
goharbor/harbor-jobservice:v2.9.039435daedd0c
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
goharbor/harbor-registryctl:v2.9.0cce272836449
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

7,672
orchestratorsubstraVerified publisher8.8.01 of 3See more

orchestrator substra 8.8.0

1 of the 3 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

2,991
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
github.com/jackc/pgproto3/v2@v2.0.1
no fix listed

Open the chart page →

3,764
tfy-cloudflaredtruefoundryVerified publisher0.5.01 of 2See more

tfy-cloudflared truefoundry 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed

Open the chart page →

2,015
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/jackc/pgproto3/v2@v2.3.0
no fix listed

Open the chart page →

6,132
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/jackc/pgproto3/v2@v2.0.7
no fix listed

Open the chart page →

13,459
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

2,022

Container images carrying it

162 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
github.com/jackc/pgproto3/v2@v2.2.0
no fix listed
1
quay.io/argoproj/argocli:v3.5.591b9825f09a8
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
github.com/jackc/pgproto3/v2@v2.1.1
no fix listed
1
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
github.com/jackc/pgproto3/v2@v2.1.1
no fix listed
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.