CVE-2026-34165
MediumAdvisory
Published 30 Mar 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.0
- base score, highest
- EPSS
- 0.001
- 4th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 154
- of 17,781 indexed, latest versions
- Container images
- 160
- deployed by those charts
- Fix available
- 1 of 1
- affected package
go-git: Maliciously crafted idx file can cause asymmetric memory consumption
Carried by container images the latest versions of 154 of 17,781 indexed charts deploy, on 160 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v5.0.0, v5.1.0, v5.2.0, v5.3.0+18 more | 5.17.1 | 160 |
- OSV records
- GHSA-jhf3-xxhw-2wpp
- Also known as
- GO-2026-4910
Charts affected
154 by stars
Container images carrying it
160 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | d6fd2a9e3273 | github.com/ | 5.17.1 | 1 |
| quay.io/ | 13aaae779248 | github.com/ | 5.17.1 | 1 |
| quay.io/ | d7d93debf1f4 | github.com/ | 5.17.1 | 1 |
| quay.io/ | ec6ab507c5da | github.com/ | 5.17.1 | 1 |
| quay.io/ | ebba936046ab | github.com/ | 5.17.1 | 1 |
| quay.io/ | c241c971aef8 | github.com/ | 5.17.1 | 1 |
| quay.io/ | 6ff40fa6257f | github.com/ | 5.17.1 | 1 |
| quay.io/ | bca5dfcc67ca | github.com/ | 5.17.1 | 1 |
| quay.io/ | 7b4202c25b67 | github.com/ | 5.17.1 | 1 |
| registry.gitlab.com/ | 9b9d1ed86b6a | github.com/ | 5.17.1 | 1 |