StackRadar

CVE-2026-32286

High

Advisory

Published 16 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
160
of 17,781 indexed, latest versions
Container images
162
deployed by those charts
Fix available
None
affected package

Denial of service in github.com/jackc/pgproto3/v2

Carried by container images the latest versions of 160 of 17,781 indexed charts deploy, on 162 images.

Affected packageAffected versionsFixed inImages
github.com/jackc/pgproto3/v2golangv2.0.0, v2.0.1, v2.0.2, v2.0.4+9 moreno fix listed162
OSV records
GHSA-jqcq-xjh3-6g23
Also known as
GO-2026-4518

Charts affected

160 by stars
ChartLatestAffected imagesRadar Score
trilliansigstoreVerified publisher0.3.172 of 5See more

trillian sigstore 0.3.17

2 of the 5 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
ghcr.io/sigstore/scaffolding/trillian_log_serverdigest-pinned5a878e4e4f03
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
ghcr.io/sigstore/scaffolding/trillian_log_signerdigest-pinned28c5ff40963f
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed

Open the chart page →

2,808
bytesafe-cesimcube1.0.41 of 3See more

bytesafe-ce simcube 1.0.4

1 of the 3 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

1,494
harborsoftonic1.13.03 of 8See more

harbor softonic 1.13.0

3 of the 8 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.9.06412d679fdc3
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
goharbor/harbor-jobservice:v2.9.039435daedd0c
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
goharbor/harbor-registryctl:v2.9.0cce272836449
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

7,672
orchestratorsubstraVerified publisher8.8.01 of 3See more

orchestrator substra 8.8.0

1 of the 3 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
ghcr.io/substra/orchestrator-server:1.0.0647e45284a80
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

2,991
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
github.com/jackc/pgproto3/v2@v2.0.1
no fix listed

Open the chart page →

3,764
tfy-cloudflaredtruefoundryVerified publisher0.5.01 of 2See more

tfy-cloudflared truefoundry 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed

Open the chart page →

2,015
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/jackc/pgproto3/v2@v2.3.0
no fix listed

Open the chart page →

6,132
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/jackc/pgproto3/v2@v2.0.7
no fix listed

Open the chart page →

13,459
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-32286.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed

Open the chart page →

2,022

Container images carrying it

162 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
6
caddy/ingress:v0.2.118d1366fc0e9
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
3
migrate/migrate:latestcc4ad8e19d66
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
3
oryd/hydra:v2.2.02c93beb5e5f2
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
3
ghcr.io/sigstore/scaffolding/trillian_log_server5a878e4e4f03
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
3
ghcr.io/sigstore/scaffolding/trillian_log_signer28c5ff40963f
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
3
quay.io/devtron/clair:4.3.675fb847ac045
github.com/jackc/pgproto3/v2@v2.1.1
no fix listed
3
grafana/alloy:v1.8.17790f6f7fbd8
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
2
grafana/alloy:v1.12.2f94b1c82957a
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
2
hashicorp/vault:1.15.26b4e5dadf082
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
2
hashicorp/vault:1.12.18de4d5f31b38
github.com/jackc/pgproto3/v2@v2.2.0
no fix listed
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
2
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
2
mesosphere/kubeaddons-catalog:v0.11.4073db43d0b8b
github.com/jackc/pgproto3/v2@v2.0.1
no fix listed
2
oryd/kratos:v1.0.0d06fc5845f63
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
2
oryd/kratos:v1.3.1fe2428f103a6
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
github.com/jackc/pgproto3/v2@v2.3.1
no fix listed
2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
2
rookout/controller:latest4451a6f6b8ec
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
2
rookout/data-on-prem:latest51c0fce64467
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
2
zhenghaoz/gorse-master:0.4.12033046b432ec
github.com/jackc/pgproto3/v2@v2.3.0
no fix listed
2
zhenghaoz/gorse-server:0.4.1239c565685b01
github.com/jackc/pgproto3/v2@v2.3.0
no fix listed
2
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
github.com/jackc/pgproto3/v2@v2.3.0
no fix listed
2
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
github.com/jackc/pgproto3/v2@v2.2.0
no fix listed
2
alex6021710/ai-scale-auth:latest6c7a47e470c3
github.com/jackc/pgproto3/v2@v2.1.1
no fix listed
1
alex6021710/ai-scale-migrator:latest744b8a924f35
github.com/jackc/pgproto3/v2@v2.0.7
no fix listed
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
aquasec/kube-bench:v0.6.9c329d73fea58
github.com/jackc/pgproto3/v2@v2.3.0
no fix listed
1
artifacthub/db-migrator:v1.23.028c13565ac5c
github.com/jackc/pgproto3/v2@v2.0.2
no fix listed
1
artifacthub/db-migrator:v1.19.02a746b289fcd
github.com/jackc/pgproto3/v2@v2.0.2
no fix listed
1
artifacthub/hub:v1.19.0111918d8c399
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
artifacthub/hub:v1.23.07d3a91c539dc
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
artifacthub/scanner:v1.23.02d8365601f0e
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
artifacthub/tracker:v1.23.05368d21a6e5c
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
bytebase/bytebase:latest9fcde38c0d5f
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/jackc/pgproto3/v2@v2.3.2
no fix listed
1
cockroachdb/cockroach-operator:v2.1.0983312754620
github.com/jackc/pgproto3/v2@v2.0.4
no fix listed
1
dollarshaveclub/furan2:master14a257836529
github.com/jackc/pgproto3/v2@v2.0.4
no fix listed
1
ethpandaops/armiarma:master1a9c3264f0a9
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
ethpandaops/dora:master2381ea793a12
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
factly/dega-api:0.15.166fafc7b0a17
github.com/jackc/pgproto3/v2@v2.0.6
no fix listed
1
factly/dega-server:0.15.194d21479382e
github.com/jackc/pgproto3/v2@v2.0.6
no fix listed
1
factly/kavach-server:0.22.3be85ff1b9bd3
github.com/jackc/pgproto3/v2@v2.0.6
no fix listed
1
factly/mande-server:0.34.1384d384310ef
github.com/jackc/pgproto3/v2@v2.0.6
no fix listed
1
factly/vidcheck-server:0.12.087064eb0463c
github.com/jackc/pgproto3/v2@v2.0.5
no fix listed
1
flanksource/batch-runner:v1.0.44689687a7cf95
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1
flashcatcloud/categraf:latest42e6ab16472e
github.com/jackc/pgproto3/v2@v2.3.3
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.