StackRadar

CVE-2020-15256

High

Advisory

Published 19 Oct 2020In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.015
74th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
7
of 17,781 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Prototype pollution in object-path

Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
object-pathnpm0.9.2, 0.11.40.11.59
OSV records
GHSA-cwx2-736x-mf6w

Charts affected

7 by stars
ChartLatestAffected imagesRadar Score
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2020-15256.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
object-path@0.11.4
0.11.5

Open the chart page →

8,213
graphql-gatewaygraphql-gatewayVerified publisher0.1.51 of 1See more

graphql-gateway graphql-gateway 0.1.5

1 of the 1 container images this version deploys carry CVE-2020-15256.

Container imageDigestPackageFixed in
hansehe/graphql-gateway:1.0.458e09540afbc
object-path@0.11.4
0.11.5

Open the chart page →

1,660
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2020-15256.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
object-path@0.11.4
0.11.5

Open the chart page →

25,456
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2020-15256.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
object-path@0.11.4
0.11.5
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
object-path@0.11.4
0.11.5
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
object-path@0.11.4
0.11.5
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
object-path@0.11.4
0.11.5

Open the chart page →

89,959
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2020-15256.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
object-path@0.11.4
0.11.5

Open the chart page →

8,213
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2020-15256.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
object-path@0.9.2
0.11.5

Open the chart page →

57,669
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-15256.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
object-path@0.11.4
0.11.5

Open the chart page →

3,696

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
object-path@0.11.4
0.11.5
2
hansehe/graphql-gateway:1.0.458e09540afbc
object-path@0.11.4
0.11.5
1
ibmcom/microclimate-portal:latested5505e5c7ec
object-path@0.9.2
0.11.5
1
ondrejsika/parking:latestb1fd497416c8
object-path@0.11.4
0.11.5
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
object-path@0.11.4
0.11.5
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
object-path@0.11.4
0.11.5
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
object-path@0.11.4
0.11.5
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
object-path@0.11.4
0.11.5
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
object-path@0.11.4
0.11.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.