StackRadar

CVE-2020-7774

Critical

Advisory

Published 17 Nov 2020In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.694
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
122
of 17,781 indexed, latest versions
Container images
124
deployed by those charts
Fix available
2 of 3
affected packages

Prototype Pollution in y18n

Carried by container images the latest versions of 122 of 17,781 indexed charts deploy, on 124 images.

Affected packageAffected versionsFixed inImages
nodejsapk10.16.3-r0, 12.17.0-r0, 12.18.4-r0, 12.20.1-r010.24.1-r0, 12.22.1-r05
y18nnpm3.2.1, 4.0.03.2.2, 4.0.1122
node-y18ndeb4.0.0-2no fix listed2
OSV records
ALPINE-CVE-2020-7774GHSA-c4w7-xm78-47vhUBUNTU-CVE-2020-7774

Charts affected

122 by stars
ChartLatestAffected imagesRadar Score
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
y18n@4.0.0
4.0.1

Open the chart page →

12,791
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
y18n@4.0.0
4.0.1

Open the chart page →

109,294
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
y18n@4.0.0
4.0.1

Open the chart page →

27,465
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
y18n@3.2.1
3.2.2

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
y18n@3.2.1
3.2.2

Open the chart page →

38,865
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
openwhisk/alarmprovider:2.2.0b695a6ceb406
y18n@3.2.1
3.2.2

Open the chart page →

36,215
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
y18n@3.2.1
3.2.2

Open the chart page →

1,986
myappp4-helm0.1.02 of 6See more

myapp p4-helm 0.1.0

2 of the 6 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
y18n@3.2.1
3.2.2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
y18n@3.2.1
3.2.2

Open the chart page →

19,720
practica-helmpractica-helm0.1.02 of 7See more

practica-helm practica-helm 0.1.0

2 of the 7 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
y18n@4.0.0
4.0.1
slagattollas/weatherservice-practica:latest68e7f56393fc
y18n@3.2.1
3.2.2

Open the chart page →

28,484
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
y18n@4.0.0
4.0.1

Open the chart page →

20,462
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
y18n@4.0.0
4.0.1

Open the chart page →

20,462
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
y18n@4.0.0
4.0.1

Open the chart page →

5,215
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
y18n@3.2.1
3.2.2

Open the chart page →

5,582
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
y18n@4.0.0
4.0.1

Open the chart page →

3,696
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
y18n@4.0.0
4.0.1

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
y18n@4.0.0
4.0.1

Open the chart page →

29,220
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
y18n@4.0.0
4.0.1

Open the chart page →

2,460
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
y18n@3.2.1
3.2.2

Open the chart page →

4,967
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-y18n@4.0.0-2
y18n@4.0.0
no fix listed
4.0.1

Open the chart page →

10,902
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
y18n@4.0.0
4.0.1

Open the chart page →

3,827
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
y18n@4.0.0
4.0.1

Open the chart page →

2,838
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
y18n@3.2.1
3.2.2

Open the chart page →

1,309

Container images carrying it

124 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
haveagitgat/tdarr_node:2.00.101e3f9328327d
y18n@4.0.0
4.0.1
1
henrywhitaker3/speedtest-tracker:latest47159a940229
y18n@4.0.0
4.0.1
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
y18n@3.2.1
3.2.2
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
y18n@3.2.1
3.2.2
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
y18n@3.2.1
3.2.2
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
y18n@3.2.1
3.2.2
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
y18n@4.0.0
4.0.1
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
y18n@3.2.1
3.2.2
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
y18n@4.0.0
4.0.1
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
y18n@4.0.0
4.0.1
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
y18n@3.2.1
3.2.2
1
ibmcom/microclimate-portal:latested5505e5c7ec
y18n@3.2.1
3.2.2
1
ibmcom/microclimate-theia:lateste17bdccc5030
y18n@3.2.1
3.2.2
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
y18n@4.0.0
4.0.1
1
istio/examples-bookinfo-ratings-v1:1.17.0b6a6b88d3578
y18n@4.0.0
4.0.1
1
jayfong/yapi:1.10.2163e5d621910
y18n@3.2.1
3.2.2
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
y18n@4.0.0
4.0.1
1
klausmeyer/docker-registry-browser:1.3.5430a440d95af
nodejs@12.18.4-r0
12.22.1-r0
1
koumoul/capture:17108d47be3b2
y18n@3.2.1
3.2.2
1
koumoul/openapi-viewer:18eeca2e8285b
y18n@3.2.1
3.2.2
1
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
y18n@3.2.1
3.2.2
1
lavandadelpatio/frontend:latest501c3f31e0bc
y18n@4.0.0
4.0.1
1
linuxserver/codimd:latestb801bbcf6386
y18n@4.0.0
4.0.1
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-y18n@4.0.0-2
y18n@4.0.0
no fix listed
4.0.1
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
y18n@3.2.1
3.2.2
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
y18n@3.2.1
3.2.2
1
minddocdev/hubot:0.1.96c60b11a4fa7
y18n@4.0.0
4.0.1
1
misskey/misskey:12.110.1e08b7c478093
y18n@4.0.0
4.0.1
1
mozilla/sentencecollector:2.0.91da6ff5c4895
y18n@4.0.0
4.0.1
1
muluder/prograncontrollermcord:0.1.843b597a93da7
y18n@3.2.1
3.2.2
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
y18n@4.0.0
4.0.1
1
nodered/node-red-docker:0.19.6-v8070643219ea2
y18n@4.0.0
4.0.1
1
omecproject/onos-progran:1.0.05715e5648aa0
y18n@3.2.1
3.2.2
1
ondrejsika/parking:latestb1fd497416c8
y18n@4.0.0
4.0.1
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
y18n@3.2.1
3.2.2
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
y18n@3.2.1
3.2.2
1
pachyderm/grpc-proxy:0.4.92b27f41d4d02
y18n@3.2.1
3.2.2
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
y18n@3.2.1
3.2.2
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
y18n@3.2.1
3.2.2
1
slagattollas/server-practica:latest6dd8ead8e2b1
y18n@4.0.0
4.0.1
1
slagattollas/weatherservice-practica:latest68e7f56393fc
y18n@3.2.1
3.2.2
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
y18n@4.0.0
4.0.1
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-y18n@4.0.0-2
y18n@4.0.0
no fix listed
4.0.1
1
swaggerapi/swagger-ui:v3.24.3d434cac93813
nodejs@10.16.3-r0
10.24.1-r0
1
testhubio/testhub-frontend:on-preme86c2db53be8
nodejs@12.20.1-r0
y18n@4.0.0
12.22.1-r0
4.0.1
1
thelounge/thelounge:4.2.0-alpine639978459c3a
y18n@4.0.0
4.0.1
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
y18n@3.2.1
3.2.2
1
trufflesuite/ganache-cli:v6.12.2c062707f17f3
y18n@4.0.0
4.0.1
1
tzahi12345/youtubedl-material:4.23720b856bd2f
nodejs@12.20.1-r0
y18n@4.0.0
12.22.1-r0
4.0.1
1
wekanteam/wekan:v4.2268a51f0327df
y18n@4.0.0
4.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.