StackRadar

CVE-2021-27290

High

Advisory

Published 12 Mar 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.047
91st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
129
of 17,781 indexed, latest versions
Container images
128
deployed by those charts
Fix available
1 of 2
affected packages

Regular Expression Denial of Service (ReDoS)

Carried by container images the latest versions of 129 of 17,781 indexed charts deploy, on 128 images.

Affected packageAffected versionsFixed inImages
ssrinpm5.3.0, 6.0.0, 6.0.1, 7.1.0+1 more6.0.2, 7.1.1, 8.0.1128
node-ssrideb7.1.0-2no fix listed2
OSV records
GHSA-vx3p-948g-6vhqUBUNTU-CVE-2021-27290

Charts affected

129 by stars
ChartLatestAffected imagesRadar Score
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
ssri@5.3.0
6.0.2

Open the chart page →

7,210
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
ssri@7.1.0
7.1.1

Open the chart page →

9,203
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
ssri@6.0.1
6.0.2

Open the chart page →

30,326
lighthouse-cicowboysysopVerified publisher9.0.01 of 1See more

lighthouse-ci cowboysysop 9.0.0

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
patrickhulce/lhci-server:0.8.174b4b6a3954d
ssri@6.0.1
6.0.2

Open the chart page →

2,213
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
ssri@7.1.0
7.1.1

Open the chart page →

5,251
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
ssri@6.0.1
6.0.2

Open the chart page →

52,919
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
ssri@6.0.1
6.0.2

Open the chart page →

8,213
taigarc-helm-charts0.1.01 of 7See more

taiga rc-helm-charts 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
taigaio/taiga-events:6.4.00bf2d24a57d9
ssri@6.0.1
6.0.2

Open the chart page →

7,255
hubotdecayofmind1.0.21 of 3See more

hubot decayofmind 1.0.2

1 of the 3 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
decayofmind/hubot:3.3.21e18e92fe694
ssri@6.0.1
6.0.2

Open the chart page →

2,513
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
ssri@6.0.1
6.0.2

Open the chart page →

5,209
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ssri@6.0.1
6.0.2

Open the chart page →

6,868
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
ssri@6.0.1
6.0.2

Open the chart page →

2,851
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
ssri@6.0.1
6.0.2

Open the chart page →

13,635
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
ssri@8.0.0
8.0.1

Open the chart page →

10,730
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
ssri@6.0.1
6.0.2

Open the chart page →

3,509
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
koumoul/capture:17108d47be3b2
ssri@6.0.1
6.0.2

Open the chart page →

38,346
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
ssri@8.0.0
8.0.1

Open the chart page →

5,056
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
ssri@6.0.1
6.0.2

Open the chart page →

4,405
tdarrgeek-cookbookVerified publisher4.6.21 of 2See more

tdarr geek-cookbook 4.6.2

1 of the 2 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.00.101e3f9328327d
ssri@6.0.1
6.0.2

Open the chart page →

31,000
uptimerobotgeek-cookbookVerified publisher3.0.41 of 1See more

uptimerobot geek-cookbook 3.0.4

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
ssri@5.3.0
6.0.2

Open the chart page →

1,669
youtubedl-materialgeek-cookbookVerified publisher4.4.21 of 1See more

youtubedl-material geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.23720b856bd2f
ssri@6.0.1
6.0.2

Open the chart page →

4,410
pdc-portali4trustVerified publisher2.3.21 of 1See more

pdc-portal i4trust 2.3.2

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
i4trust/pdc-portal:2.0.03e77858e1219
ssri@6.0.1
6.0.2

Open the chart page →

2,723
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
ssri@7.1.0
7.1.1

Open the chart page →

5,940
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.12 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

2 of the 6 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
ssri@6.0.1
6.0.2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ssri@6.0.1
6.0.2

Open the chart page →

19,187
statsdstatsd-airflow-smd0.1.191 of 1See more

statsd statsd-airflow-smd 0.1.19

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
statsd/statsd:v0.8.6dab129e74c25
ssri@5.3.0
6.0.2

Open the chart page →

4,185
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
ssri@6.0.1
6.0.2

Open the chart page →

7,517
restreamerutkuozdemirVerified publisher1.1.01 of 1See more

restreamer utkuozdemir 1.1.0

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
datarhei/restreamer:0.6.4655e12f9eeed
ssri@6.0.1
6.0.2

Open the chart page →

2,598
scrapoxywiremindVerified publisher0.3.41 of 1See more

scrapoxy wiremind 0.3.4

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
wiremind/scrapoxy:lateste7048929a676
ssri@6.0.1
6.0.2

Open the chart page →

2,154
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
ssri@6.0.1
6.0.2

Open the chart page →

25,443
allure-docker-helm-chartallure-service-chartVerified publisher0.1.01 of 2See more

allure-docker-helm-chart allure-service-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service-ui:latest4ebd8b4ef340
ssri@6.0.1
6.0.2

Open the chart page →

3,647
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
ssri@5.3.0
6.0.2

Open the chart page →

3,237
angular-node-chartangular-webapp2.0.01 of 1See more

angular-node-chart angular-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
rakii8585/angular-node-webapp:latest026082a515ac
ssri@6.0.1
6.0.2

Open the chart page →

2,616
d.vazquezm.2021_helmapphelmVerified publisher1.0.02 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

2 of the 6 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
davidvmar/urjc-davidvmar-external-service:1.0.02a68e9ac7f09
ssri@6.0.1
6.0.2
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
ssri@6.0.1
6.0.2

Open the chart page →

19,745
trifidappuio2.0.21 of 1See more

trifid appuio 2.0.2

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
zazuko/trifid:2.3.7054be137de70
ssri@6.0.1
6.0.2

Open the chart page →

2,783
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
ssri@6.0.1
6.0.2

Open the chart page →

18,277
bookinfobasictechno0.1.01 of 6See more

bookinfo basictechno 0.1.0

1 of the 6 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.17.0b6a6b88d3578
ssri@6.0.1
6.0.2

Open the chart page →

20,671
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
ssri@8.0.0
8.0.1

Open the chart page →

5,806
istio-bookinfobookinfo1.2.21 of 6See more

istio-bookinfo bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.15.009b9d6958a13
ssri@6.0.1
6.0.2

Open the chart page →

18,980
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
ssri@5.3.0
6.0.2

Open the chart page →

29,901
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
ssri@5.3.0
6.0.2

Open the chart page →

2,580
kube-slackcloudnativeapp1.0.01 of 1See more

kube-slack cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
willwill/kube-slack:v4.1.1d443017aae98
ssri@6.0.0
6.0.2

Open the chart page →

1,937
node-redcloudnativeapp1.2.21 of 1See more

node-red cloudnativeapp 1.2.2

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
nodered/node-red-docker:0.19.6-v8070643219ea2
ssri@5.3.0
6.0.2

Open the chart page →

4,790
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
ssri@6.0.1
6.0.2

Open the chart page →

25,456
setup-jobcloud-native-toolkit0.3.01 of 2See more

setup-job cloud-native-toolkit 0.3.0

1 of the 2 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
ssri@6.0.1
6.0.2

Open the chart page →

2,792
slack-notificationscloud-native-toolkit0.1.71 of 1See more

slack-notifications cloud-native-toolkit 0.1.7

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/slack-notifications:latest041df93e2bac
ssri@6.0.1
6.0.2

Open the chart page →

1,545
maildevcnieg1.1.11 of 1See more

maildev cnieg 1.1.1

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
cnieg/maildev:v1.1.998ee05668915
ssri@6.0.1
6.0.2

Open the chart page →

2,449
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
ssri@6.0.1
6.0.2

Open the chart page →

12,907
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
ssri@6.0.1
6.0.2

Open the chart page →

5,209
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.02 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
ssri@6.0.1
6.0.2
oscarsotosanchez/weatherservice:v1.0911ec961d10b
ssri@6.0.1
6.0.2

Open the chart page →

27,550
mergeabledoubanVerified publisher0.2.21 of 1See more

mergeable douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2021-27290.

Container imageDigestPackageFixed in
ghcr.io/leoquote/mergeable:latest451706815103
ssri@6.0.1
6.0.2

Open the chart page →

4,223

Container images carrying it

128 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
ssri@6.0.1
6.0.2
5
oscarsotosanchez/server:v1.06e2e1279126b
ssri@6.0.1
6.0.2
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
ssri@6.0.1
6.0.2
4
frankescobar/allure-docker-service-ui:7.0.3:latest4ebd8b4ef340
ssri@6.0.1
6.0.2
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
ssri@6.0.1
6.0.2
3
pantsel/konga:latestc8172b75607d
ssri@6.0.1
6.0.2
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
ssri@8.0.0
8.0.1
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
ssri@7.1.0
7.1.1
2
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
ssri@6.0.1
6.0.2
2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ssri@6.0.1
6.0.2
2
governify/assets-manager:v1.4.12987672448c7
ssri@6.0.1
6.0.2
2
governify/director:v1.4.0608c6940bb98
ssri@6.0.1
6.0.2
2
governify/registry:v3.4.0d3f37f4f8168
ssri@6.0.1
6.0.2
2
governify/render:v2.2.0daeca1ce28e6
ssri@6.0.1
6.0.2
2
governify/reporter:v2.2.038595913458f
ssri@6.0.1
6.0.2
2
istio/examples-bookinfo-ratings-v1:1.15.009b9d6958a13
ssri@6.0.1
6.0.2
2
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
ssri@6.0.1
6.0.2
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
ssri@6.0.1
6.0.2
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
ssri@6.0.1
6.0.2
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
ssri@6.0.1
6.0.2
2
statsd/statsd:v0.8.6dab129e74c25
ssri@5.3.0
6.0.2
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
ssri@6.0.1
6.0.2
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
ssri@6.0.1
6.0.2
2
a5hut0sh/helloworld:1.02ae77620e616
ssri@5.3.0
6.0.2
1
adrianberger/fluxcd-webui:latest76848c0d2780
ssri@6.0.1
6.0.2
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
ssri@6.0.1
6.0.2
1
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
ssri@6.0.1
6.0.2
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
ssri@6.0.1
6.0.2
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
ssri@8.0.0
8.0.1
1
aureliengasser/http-folder:1.1.111c4318c2571
ssri@6.0.1
6.0.2
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
ssri@6.0.1
6.0.2
1
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
ssri@5.3.0
6.0.2
1
chatwoot/chatwoot:v4.15.167ebc751c171
ssri@7.1.0
7.1.1
1
cnieg/maildev:v1.1.998ee05668915
ssri@6.0.1
6.0.2
1
conduction/conduction-ui-app:devd591f5e6f2a9
ssri@6.0.1
6.0.2
1
daskdev/dask-notebook:1.1.0052630f5ca04
ssri@5.3.0
6.0.2
1
datarhei/restreamer:0.6.4655e12f9eeed
ssri@6.0.1
6.0.2
1
davidvmar/urjc-davidvmar-external-service:1.0.02a68e9ac7f09
ssri@6.0.1
6.0.2
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
ssri@6.0.1
6.0.2
1
decayofmind/hubot:3.3.21e18e92fe694
ssri@6.0.1
6.0.2
1
denisshav/backend:latest4cc8dc5a4499
ssri@6.0.1
6.0.2
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
ssri@5.3.0
6.0.2
1
devspacecloud/ui:0.3.3deef55ff29a7
ssri@6.0.1
6.0.2
1
eameti/node-app:latestf36642affa86
ssri@6.0.1
6.0.2
1
fiware/iotagent-ul:1.14.0fe11f55a926d
ssri@6.0.1
6.0.2
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ssri@6.0.1
6.0.2
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
ssri@6.0.1
6.0.2
1
gristlabs/grist:0.7.96e71b1914a7e
ssri@6.0.1
6.0.2
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
ssri@6.0.1
6.0.2
1
halkeye/hubot:latest9764d2202130
ssri@6.0.1
6.0.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.