StackRadar

CVE-2016-10539

High

Advisory

Published 9 Oct 2018In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 1
affected package

Regular Expression Denial of Service in negotiator

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
negotiatornpm0.3.0, 0.5.30.6.18
OSV records
GHSA-7mc5-chhp-fmc3

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2016-10539.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
negotiator@0.5.3
0.6.1

Open the chart page →

5,209
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2016-10539.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
negotiator@0.5.3
0.6.1

Open the chart page →

18,277
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2016-10539.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
negotiator@0.5.3
0.6.1

Open the chart page →

4,069
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2016-10539.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
negotiator@0.5.3
0.6.1

Open the chart page →

27,417
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2016-10539.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
negotiator@0.5.3
0.6.1

Open the chart page →

5,209
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2016-10539.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
negotiator@0.5.3
0.6.1

Open the chart page →

5,941
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2016-10539.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
negotiator@0.5.3
0.6.1

Open the chart page →

6,454
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2016-10539.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
negotiator@0.3.0
0.6.1

Open the chart page →

27,465
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2016-10539.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
negotiator@0.5.3
0.6.1

Open the chart page →

3,638
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2016-10539.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
negotiator@0.5.3
0.6.1

Open the chart page →

3,827

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
pantsel/konga:latestc8172b75607d
negotiator@0.5.3
0.6.1
3
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
negotiator@0.5.3
0.6.1
1
jayfong/yapi:1.10.2163e5d621910
negotiator@0.5.3
0.6.1
1
konradkleine/docker-registry-frontend:v2181aad54ee64
negotiator@0.5.3
0.6.1
1
linuxserver/cloud9:latest45c5fe102ff3
negotiator@0.3.0
0.6.1
1
wekanteam/wekan:v4.2268a51f0327df
negotiator@0.5.3
0.6.1
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
negotiator@0.5.3
0.6.1
1
quay.io/wekan/wekan:v5.65cb17600883a3
negotiator@0.5.3
0.6.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.