StackRadar

CVE-2016-3956

High

Advisory

Published 2 Jul 2016In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.067
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
2 of 2
affected packages

npm Token Leak in npm

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
npmnpm1.0.1, 1.39.1-prel, 3.5.22.15.1, 3.8.38
npmdeb3.5.2-0ubuntu43.5.2-0ubuntu4.1.16.04.1~esm1, 3.5.2-0ubuntu4.1.18.04.1~esm13
OSV records
GHSA-m5h6-hr3q-22h5UBUNTU-CVE-2016-3956
Also known as
USN-4785-1

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2016-3956.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
npm@1.0.1
2.15.1

Open the chart page →

4,577
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2016-3956.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
npm@1.0.1
2.15.1

Open the chart page →

8,212
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2016-3956.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
npm@1.0.1
2.15.1

Open the chart page →

31,844
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2016-3956.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
npm@3.5.2-0ubuntu4
npm@3.5.2
3.5.2-0ubuntu4.1.18.04.1~esm1
3.8.3

Open the chart page →

12,779
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2016-3956.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
npm@3.5.2-0ubuntu4
npm@3.5.2
3.5.2-0ubuntu4.1.16.04.1~esm1
3.8.3

Open the chart page →

27,417
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2016-3956.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
npm@1.0.1
2.15.1

Open the chart page →

14,559
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2016-3956.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
npm@1.39.1-prel
2.15.1

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2016-3956.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
npm@1.39.1-prel
2.15.1

Open the chart page →

24,319
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2016-3956.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2-0ubuntu4
npm@3.5.2
3.5.2-0ubuntu4.1.18.04.1~esm1
3.8.3

Open the chart page →

36,215

Container images carrying it

8 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
governify/assets-manager:v1.4.12987672448c7
npm@1.39.1-prel
2.15.1
2
codercom/code-server:4.11.0-debian1e2cc688008e
npm@1.0.1
2.15.1
1
codercom/code-server:3.10.247605610ad8d
npm@1.0.1
2.15.1
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
npm@3.5.2-0ubuntu4
npm@3.5.2
3.5.2-0ubuntu4.1.16.04.1~esm1
3.8.3
1
linuxserver/code-server:4.10.1a5e43a05ae79
npm@1.0.1
2.15.1
1
openthread/otbr:latestf307f59f6432
npm@3.5.2-0ubuntu4
npm@3.5.2
3.5.2-0ubuntu4.1.18.04.1~esm1
3.8.3
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
npm@3.5.2-0ubuntu4
npm@3.5.2
3.5.2-0ubuntu4.1.18.04.1~esm1
3.8.3
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
npm@1.0.1
2.15.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.