StackRadar

CVE-2020-15168

Low

Advisory

Published 10 Sept 2020In the index since 8 Sept 2026
Severity
Low
worst across findings
CVSS
2.6
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,787 indexed, latest versions
Container images
16
deployed by those charts
Fix available
1 of 1
affected package

The `size` option isn't honored after following a redirect in node-fetch

Carried by container images the latest versions of 14 of 17,787 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
node-fetchnpm2.1.2, 2.2.0, 2.3.0, 2.6.02.6.116
OSV records
GHSA-w7rc-rwvf-8q5r

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
node-fetch@2.6.0
2.6.1

Open the chart page →

7,517
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
node-fetch@2.3.0
2.6.1

Open the chart page →

29,922
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
node-fetch@2.1.2
2.6.1

Open the chart page →

3,260
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
node-fetch@2.3.0
2.6.1

Open the chart page →

5,980
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
node-fetch@2.6.0
2.6.1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
node-fetch@2.6.0
2.6.1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
node-fetch@2.6.0
2.6.1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
node-fetch@2.6.0
2.6.1

Open the chart page →

89,949
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
node-fetch@2.3.0
2.6.1

Open the chart page →

7,931
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
node-fetch@2.6.0
2.6.1

Open the chart page →

3,651
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
node-fetch@2.6.0
2.6.1

Open the chart page →

68,330
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
node-fetch@2.6.0
2.6.1

Open the chart page →

7,027
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
node-fetch@2.6.0
2.6.1

Open the chart page →

6,684
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
node-fetch@2.6.0
2.6.1

Open the chart page →

1,986
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
node-fetch@2.2.0
2.6.1

Open the chart page →

5,215
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
node-fetch@2.3.0
2.6.1

Open the chart page →

3,639
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15168.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
node-fetch@2.6.0
2.6.1

Open the chart page →

3,696

Container images carrying it

16 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mesosphere/kommander:6.100.13917e82333a9
node-fetch@2.6.0
2.6.1
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
node-fetch@2.3.0
2.6.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
node-fetch@2.3.0
2.6.1
1
ethersphere/bzz-token-service:latest7624f11a72ad
node-fetch@2.1.2
2.6.1
1
gristlabs/grist:0.7.96e71b1914a7e
node-fetch@2.2.0
2.6.1
1
lavandadelpatio/frontend:latest501c3f31e0bc
node-fetch@2.6.0
2.6.1
1
mozilla/sentencecollector:2.0.91da6ff5c4895
node-fetch@2.6.0
2.6.1
1
ondrejsika/parking:latestb1fd497416c8
node-fetch@2.6.0
2.6.1
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
node-fetch@2.6.0
2.6.1
1
testhubio/testhub-frontend:on-preme86c2db53be8
node-fetch@2.6.0
2.6.1
1
wekanteam/wekan:v4.2268a51f0327df
node-fetch@2.3.0
2.6.1
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
node-fetch@2.6.0
2.6.1
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
node-fetch@2.6.0
2.6.1
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
node-fetch@2.6.0
2.6.1
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
node-fetch@2.6.0
2.6.1
1
quay.io/wekan/wekan:v5.65cb17600883a3
node-fetch@2.3.0
2.6.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.