StackRadar

CVE-2026-54345

Medium

Advisory

Published 28 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)

Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
github.com/gopacket/gopacketgolangv1.3.1, v1.3.2-0.20250721223119-be3fffa73cab, v1.4.0, v1.5.01.6.19
OSV records
GHSA-6r28-9ppf-4hj5
Also known as
GO-2026-6121

Charts affected

5 by stars
ChartLatestAffected imagesRadar Score
kubesharkkubeshark-helm-chartsOfficialVerified publisher53.4.01 of 3See more

kubeshark kubeshark-helm-charts 53.4.0

1 of the 3 container images this version deploys carry CVE-2026-54345.

Container imageDigestPackageFixed in
kubeshark/hub:v53.46d3f22525a0e
github.com/gopacket/gopacket@v1.3.1
1.6.1

Open the chart page →

825
netbird-reverse-proxychristianhuthVerified publisher0.1.01 of 1See more

netbird-reverse-proxy christianhuth 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-54345.

Container imageDigestPackageFixed in
netbirdio/reverse-proxy:0.72.43104d5ca3a76
github.com/gopacket/gopacket@v1.4.0
1.6.1

Open the chart page →

912
ciliumnicklasfrahm-ciliumVerified publisher0.7.44 of 6See more

cilium nicklasfrahm-cilium 0.7.4

4 of the 6 container images this version deploys carry CVE-2026-54345.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.18.2858f807ea4e2
github.com/gopacket/gopacket@v1.3.2-0.20250721223119-be3fffa73cab
1.6.1
quay.io/cilium/hubble-relay:v1.18.26079308ee15e
github.com/gopacket/gopacket@v1.3.2-0.20250721223119-be3fffa73cab
1.6.1
quay.io/cilium/hubble-ui-backend:v0.13.3db1454e45dc3
github.com/gopacket/gopacket@v1.3.1
1.6.1
quay.io/cilium/operator-generic:v1.18.2cb4e4ffc5789
github.com/gopacket/gopacket@v1.3.2-0.20250721223119-be3fffa73cab
1.6.1

Open the chart page →

7,092
ciliumvks-helm-chartsVerified publisher1.17.142 of 3See more

cilium vks-helm-charts 1.17.14

2 of the 3 container images this version deploys carry CVE-2026-54345.

Container imageDigestPackageFixed in
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
github.com/gopacket/gopacket@v1.3.1
1.6.1
quay.io/cilium/operator-generic:v1.17.14773886ec9337
github.com/gopacket/gopacket@v1.3.1
1.6.1

Open the chart page →

4,046
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-54345.

Container imageDigestPackageFixed in
wallarm/node-native-processing:0.23.07db2da8fce0b
github.com/gopacket/gopacket@v1.5.0
1.6.1

Open the chart page →

2,824

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
kubeshark/hub:v53.46d3f22525a0e
github.com/gopacket/gopacket@v1.3.1
1.6.1
1
netbirdio/reverse-proxy:0.72.43104d5ca3a76
github.com/gopacket/gopacket@v1.4.0
1.6.1
1
wallarm/node-native-processing:0.23.07db2da8fce0b
github.com/gopacket/gopacket@v1.5.0
1.6.1
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
github.com/gopacket/gopacket@v1.3.2-0.20250721223119-be3fffa73cab
1.6.1
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
github.com/gopacket/gopacket@v1.3.1
1.6.1
1
quay.io/cilium/hubble-relay:v1.18.26079308ee15e
github.com/gopacket/gopacket@v1.3.2-0.20250721223119-be3fffa73cab
1.6.1
1
quay.io/cilium/hubble-ui-backend:v0.13.3db1454e45dc3
github.com/gopacket/gopacket@v1.3.1
1.6.1
1
quay.io/cilium/operator-generic:v1.17.14773886ec9337
github.com/gopacket/gopacket@v1.3.1
1.6.1
1
quay.io/cilium/operator-generic:v1.18.2cb4e4ffc5789
github.com/gopacket/gopacket@v1.3.2-0.20250721223119-be3fffa73cab
1.6.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.