StackRadar

CVE-2020-7774

Critical

Advisory

Published 17 Nov 2020In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.694
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
122
of 17,781 indexed, latest versions
Container images
124
deployed by those charts
Fix available
2 of 3
affected packages

Prototype Pollution in y18n

Carried by container images the latest versions of 122 of 17,781 indexed charts deploy, on 124 images.

Affected packageAffected versionsFixed inImages
nodejsapk10.16.3-r0, 12.17.0-r0, 12.18.4-r0, 12.20.1-r010.24.1-r0, 12.22.1-r05
y18nnpm3.2.1, 4.0.03.2.2, 4.0.1122
node-y18ndeb4.0.0-2no fix listed2
OSV records
ALPINE-CVE-2020-7774GHSA-c4w7-xm78-47vhUBUNTU-CVE-2020-7774

Charts affected

122 by stars
ChartLatestAffected imagesRadar Score
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
y18n@3.2.1
3.2.2

Open the chart page →

11,174
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
y18n@4.0.0
4.0.1
oscarsotosanchez/weatherservice:v1.0911ec961d10b
y18n@3.2.1
3.2.2

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
y18n@4.0.0
4.0.1
oscarsotosanchez/weatherservice:v1.0911ec961d10b
y18n@3.2.1
3.2.2

Open the chart page →

27,256
ganacheethereum-helm-chartsVerified publisher0.1.31 of 2See more

ganache ethereum-helm-charts 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
trufflesuite/ganache-cli:v6.12.2c062707f17f3
y18n@4.0.0
4.0.1

Open the chart page →

1,608
testnet-faucetethereum-helm-chartsVerified publisher0.1.31 of 1See more

testnet-faucet ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
parithoshj/testnet-faucet:9859e0dcdca426fea6d
y18n@3.2.1
3.2.2

Open the chart page →

3,005
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
y18n@4.0.0
4.0.1

Open the chart page →

3,260
iotagent-ulfiware0.1.21 of 1See more

iotagent-ul fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
fiware/iotagent-ul:1.14.0fe11f55a926d
y18n@3.2.1
3.2.2

Open the chart page →

3,337
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
y18n@4.0.0
4.0.1

Open the chart page →

5,941
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
y18n@4.0.0
4.0.1

Open the chart page →

10,994
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
y18n@4.0.0
4.0.1

Open the chart page →

4,043
theloungegeek-cookbookVerified publisher3.4.21 of 1See more

thelounge geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
thelounge/thelounge:4.2.0-alpine639978459c3a
y18n@4.0.0
4.0.1

Open the chart page →

2,689
Governify-Bluejaygovernify0.1.05 of 12See more

Governify-Bluejay governify 0.1.0

5 of the 12 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
y18n@4.0.0
4.0.1
governify/director:v1.4.0608c6940bb98
y18n@4.0.0
4.0.1
governify/registry:v3.4.0d3f37f4f8168
y18n@4.0.0
4.0.1
governify/render:v2.2.0daeca1ce28e6
y18n@4.0.0
4.0.1
governify/reporter:v2.2.038595913458f
y18n@4.0.0
4.0.1

Open the chart page →

22,512
Governify-Falcongovernify0.1.05 of 10See more

Governify-Falcon governify 0.1.0

5 of the 10 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
y18n@4.0.0
4.0.1
governify/director:v1.4.0608c6940bb98
y18n@4.0.0
4.0.1
governify/registry:v3.4.0d3f37f4f8168
y18n@4.0.0
4.0.1
governify/render:v2.2.0daeca1ce28e6
y18n@4.0.0
4.0.1
governify/reporter:v2.2.038595913458f
y18n@4.0.0
4.0.1

Open the chart page →

24,319
gitter-irc-bridgehalkeye0.1.11 of 1See more

gitter-irc-bridge halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
y18n@4.0.0
4.0.1

Open the chart page →

3,642
hubothalkeye0.0.11 of 1See more

hubot halkeye 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
halkeye/hubot:latest9764d2202130
y18n@4.0.0
4.0.1

Open the chart page →

2,116
irslackdhalkeye0.1.01 of 1See more

irslackd halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
halkeye/irslackd:latest7638bfba70b0
y18n@3.2.1
3.2.2

Open the chart page →

2,064
matrix-appservice-gitterhalkeye0.1.01 of 1See more

matrix-appservice-gitter halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
y18n@3.2.1
3.2.2

Open the chart page →

3,003
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
y18n@4.0.0
4.0.1

Open the chart page →

24,161
streamsheetshelm-chartsVerified publisher0.2.35 of 8See more

streamsheets helm-charts 0.2.3

5 of the 8 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
y18n@4.0.0
4.0.1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
y18n@4.0.0
4.0.1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
y18n@4.0.0
4.0.1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
y18n@4.0.0
4.0.1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
y18n@4.0.0
4.0.1

Open the chart page →

89,959
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
y18n@4.0.0
4.0.1

Open the chart page →

8,213
http-folderhttp-folder2.0.01 of 1See more

http-folder http-folder 2.0.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
aureliengasser/http-folder:1.1.111c4318c2571
y18n@3.2.1
3.2.2

Open the chart page →

1,847
crypto-watchdoghuseyinnurbaki0.1.01 of 1See more

crypto-watchdog huseyinnurbaki 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
hhaluk/crypto-watchdog:0.4.0a6555953d941
y18n@3.2.1
3.2.2

Open the chart page →

2,656
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ibmcom/app-nav-init:1.0.1240ff499eb5b
y18n@3.2.1
3.2.2
ibmcom/app-nav-ui:1.0.1e2a86997b36b
y18n@4.0.0
4.0.1

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.02 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

2 of the 6 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
y18n@3.2.1
3.2.2
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
y18n@4.0.0
4.0.1

Open the chart page →

39,349
ibm-kerify-devibm-charts1.0.01 of 1See more

ibm-kerify-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
y18n@4.0.0
4.0.1

Open the chart page →

8,221
ibm-microclimateibm-charts0.1.03 of 8See more

ibm-microclimate ibm-charts 0.1.0

3 of the 8 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
y18n@3.2.1
3.2.2
ibmcom/microclimate-portal:latested5505e5c7ec
y18n@3.2.1
3.2.2
ibmcom/microclimate-theia:lateste17bdccc5030
y18n@3.2.1
3.2.2

Open the chart page →

57,669
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
y18n@4.0.0
4.0.1

Open the chart page →

4,505
indexer-chartindexer-application0.1.01 of 1See more

indexer-chart indexer-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ibarreche/cloud-indexer-ci:latestb7a08274e69f
y18n@3.2.1
3.2.2

Open the chart page →

3,289
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
y18n@4.0.0
4.0.1

Open the chart page →

4,944
istio-bookinfoistio-bookinfo1.2.21 of 6See more

istio-bookinfo istio-bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.15.009b9d6958a13
y18n@3.2.1
3.2.2

Open the chart page →

18,980
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
y18n@3.2.1
3.2.2

Open the chart page →

6,454
statsdkeyporttech0.1.191 of 1See more

statsd keyporttech 0.1.19

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
statsd/statsd:v0.8.6dab129e74c25
y18n@4.0.0
4.0.1

Open the chart page →

4,185
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service-ui:7.0.34ebd8b4ef340
y18n@3.2.1
3.2.2

Open the chart page →

12,527
online-boutiquekubesphere-testVerified publisher0.1.02 of 11See more

online-boutique kubesphere-test 0.1.0

2 of the 11 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
y18n@4.0.0
4.0.1
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
y18n@4.0.0
4.0.1

Open the chart page →

26,018
sample-bookinfokubesphere-testVerified publisher1.0.01 of 4See more

sample-bookinfo kubesphere-test 1.0.0

1 of the 4 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
y18n@3.2.1
3.2.2

Open the chart page →

9,378
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
devspacecloud/ui:0.3.3deef55ff29a7
y18n@4.0.0
4.0.1

Open the chart page →

9,880
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-y18n@4.0.0-2
y18n@4.0.0
no fix listed
4.0.1

Open the chart page →

17,779
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
y18n@3.2.1
3.2.2

Open the chart page →

7,929
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
y18n@4.0.0
4.0.1

Open the chart page →

3,651
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
y18n@3.2.1
3.2.2

Open the chart page →

5,287
alluremidokura-communityVerified publisher0.1.31 of 2See more

allure midokura-community 0.1.3

1 of the 2 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service-ui:7.0.34ebd8b4ef340
y18n@3.2.1
3.2.2

Open the chart page →

12,847
iotmmontesVerified publisher0.3.24 of 7See more

iot mmontes 0.3.2

4 of the 7 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
y18n@4.0.0
4.0.1
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
y18n@4.0.0
4.0.1
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
y18n@4.0.0
4.0.1
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
y18n@4.0.0
4.0.1

Open the chart page →

10,608
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
y18n@4.0.0
4.0.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
y18n@3.2.1
3.2.2

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
y18n@4.0.0
4.0.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
y18n@3.2.1
3.2.2

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
y18n@4.0.0
4.0.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
y18n@3.2.1
3.2.2

Open the chart page →

12,108
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
y18n@3.2.1
3.2.2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
y18n@3.2.1
3.2.2

Open the chart page →

11,479
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
y18n@4.0.0
4.0.1
mojaloop/central-ledger:v13.14.01abc8a7aa71c
y18n@4.0.0
4.0.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
y18n@3.2.1
3.2.2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
y18n@3.2.1
3.2.2

Open the chart page →

19,226
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
y18n@4.0.0
4.0.1

Open the chart page →

6,438
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
y18n@4.0.0
4.0.1

Open the chart page →

6,684
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2020-7774.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
y18n@4.0.0
4.0.1

Open the chart page →

12,791

Container images carrying it

124 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
willwill/kube-slack:v4.1.1d443017aae98
y18n@4.0.0
4.0.1
1
wiremind/scrapoxy:lateste7048929a676
y18n@3.2.1
3.2.2
1
zooz/predator:1.6f491d1f7a865
y18n@4.0.0
4.0.1
1
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
y18n@4.0.0
4.0.1
1
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
y18n@4.0.0
4.0.1
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
y18n@4.0.0
4.0.1
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
y18n@4.0.0
4.0.1
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
y18n@4.0.0
4.0.1
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
y18n@4.0.0
4.0.1
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
y18n@4.0.0
4.0.1
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
y18n@4.0.0
4.0.1
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
y18n@4.0.0
4.0.1
1
ghcr.io/leoquote/mergeable:latest451706815103
y18n@3.2.1
3.2.2
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
y18n@3.2.1
3.2.2
1
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
y18n@4.0.0
4.0.1
1
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
y18n@4.0.0
4.0.1
1
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
y18n@4.0.0
4.0.1
1
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
y18n@4.0.0
4.0.1
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
y18n@4.0.0
4.0.1
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
y18n@4.0.0
4.0.1
1
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
y18n@4.0.0
4.0.1
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
y18n@4.0.0
4.0.1
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
y18n@4.0.0
4.0.1
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
y18n@3.2.1
3.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.