StackRadar

CVE-2019-1010266

Medium

Advisory

Published 19 Jul 2019In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.032
87th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
2 of 2
affected packages

Regular Expression Denial of Service (ReDoS) in lodash

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
lodashnpm4.17.2, 4.17.4, 4.17.5, 4.17.104.17.1114
lodash-esnpm4.17.44.17.111
OSV records
GHSA-x5rq-j2xg-h7qm
Also known as
SNYK-JS-LODASH-73639

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
microcks/microcks-postman-runtime:latestcb72e46a1b3c
lodash@4.17.2
4.17.11

Open the chart page →

10,732
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
lodash@4.17.4
4.17.11

Open the chart page →

5,209
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
lodash@4.17.10
lodash-es@4.17.4
4.17.11
4.17.11

Open the chart page →

25,443
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
lodash@4.17.4
4.17.11

Open the chart page →

18,277
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
lodash@4.17.4
4.17.11

Open the chart page →

4,069
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
lodash@4.17.4
4.17.11

Open the chart page →

27,417
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
lodash@4.17.4
4.17.11

Open the chart page →

77,758
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
lodash@4.17.4
4.17.11

Open the chart page →

5,209
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
lodash@4.17.4
4.17.11

Open the chart page →

3,159
ibm-business-automation-insights-devibm-charts3.2.02 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

2 of the 6 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
lodash@4.17.10
4.17.11
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
lodash@4.17.10
4.17.11

Open the chart page →

39,349
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
lodash@4.17.5
4.17.11
ibmcom/microclimate-portal:latested5505e5c7ec
lodash@4.17.5
4.17.11

Open the chart page →

57,669
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
lodash@4.17.4
4.17.11

Open the chart page →

4,614
monocularmonocular1.4.151 of 5See more

monocular monocular 1.4.15

1 of the 5 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
lodash@4.17.4
4.17.11

Open the chart page →

7,048
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
lodash@4.17.4
4.17.11

Open the chart page →

3,638
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
lodash@4.17.4
4.17.11

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2019-1010266.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
lodash@4.17.4
4.17.11

Open the chart page →

12,460

Container images carrying it

14 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
pantsel/konga:latestc8172b75607d
lodash@4.17.4
4.17.11
3
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
lodash@4.17.4
4.17.11
2
migmartri/prerender:latest486aacfd5aa9
lodash@4.17.4
4.17.11
2
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
lodash@4.17.4
4.17.11
1
fiware/idm:8.3.3a1b6ed4ae84f
lodash@4.17.4
4.17.11
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
lodash@4.17.10
4.17.11
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
lodash@4.17.10
4.17.11
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
lodash@4.17.5
4.17.11
1
ibmcom/microclimate-portal:latested5505e5c7ec
lodash@4.17.5
4.17.11
1
konradkleine/docker-registry-frontend:v2181aad54ee64
lodash@4.17.4
4.17.11
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
lodash@4.17.2
4.17.11
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
lodash@4.17.4
4.17.11
1
quay.io/wekan/wekan:v5.65cb17600883a3
lodash@4.17.4
4.17.11
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
lodash@4.17.10
lodash-es@4.17.4
4.17.11
4.17.11
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.