StackRadar

CVE-2021-29059

High

Advisory

Published 10 Dec 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.028
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
14
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

ReDOS in IS-SVG

Carried by container images the latest versions of 14 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
is-svgnpm2.1.0, 3.0.04.3.014
OSV records
GHSA-r8j5-h5cx-65gg

Charts affected

14 by stars
ChartLatestAffected imagesRadar Score
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
is-svg@2.1.0
4.3.0

Open the chart page →

5,251
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
is-svg@3.0.0
4.3.0

Open the chart page →

7,517
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
is-svg@2.1.0
4.3.0

Open the chart page →

29,901
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
is-svg@3.0.0
4.3.0

Open the chart page →

25,456
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
is-svg@3.0.0
4.3.0

Open the chart page →

12,907
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
is-svg@2.1.0
4.3.0

Open the chart page →

6,454
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
is-svg@3.0.0
4.3.0

Open the chart page →

3,651
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
is-svg@3.0.0
4.3.0

Open the chart page →

6,438
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
is-svg@3.0.0
4.3.0

Open the chart page →

6,684
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
is-svg@2.1.0
4.3.0

Open the chart page →

109,294
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
is-svg@3.0.0
4.3.0

Open the chart page →

27,465
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
is-svg@3.0.0
4.3.0

Open the chart page →

2,460
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
is-svg@2.1.0
4.3.0

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-29059.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
is-svg@2.1.0
4.3.0

Open the chart page →

22,665

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
conduction/conduction-ui-app:devd591f5e6f2a9
is-svg@3.0.0
4.3.0
1
daskdev/dask-notebook:1.1.0052630f5ca04
is-svg@2.1.0
4.3.0
1
henrywhitaker3/speedtest-tracker:latest47159a940229
is-svg@3.0.0
4.3.0
1
jayfong/yapi:1.10.2163e5d621910
is-svg@2.1.0
4.3.0
1
lavandadelpatio/frontend:latest501c3f31e0bc
is-svg@3.0.0
4.3.0
1
linuxserver/codimd:latestb801bbcf6386
is-svg@3.0.0
4.3.0
1
misskey/misskey:12.110.1e08b7c478093
is-svg@2.1.0
4.3.0
1
mozilla/sentencecollector:2.0.91da6ff5c4895
is-svg@3.0.0
4.3.0
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
is-svg@2.1.0
4.3.0
1
temporalio/web:1.14.033cfa863d8ce
is-svg@2.1.0
4.3.0
1
testhubio/testhub-frontend:on-preme86c2db53be8
is-svg@3.0.0
4.3.0
1
ubercadence/web:v3.29.58564a5b44a6d
is-svg@2.1.0
4.3.0
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
is-svg@3.0.0
4.3.0
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
is-svg@3.0.0
4.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.