StackRadar

CVE-2021-32640

Medium

Advisory

Published 28 May 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.028
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
67
of 17,781 indexed, latest versions
Container images
59
deployed by those charts
Fix available
1 of 1
affected package

ReDoS in Sec-Websocket-Protocol header

Carried by container images the latest versions of 67 of 17,781 indexed charts deploy, on 59 images.

Affected packageAffected versionsFixed inImages
wsnpm5.2.2, 6.1.3, 6.1.4, 6.2.0+8 more5.2.3, 6.2.2, 7.4.659
OSV records
GHSA-6fc8-4gx4-v693

Charts affected

67 by stars
ChartLatestAffected imagesRadar Score
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
ws@6.2.1
6.2.2

Open the chart page →

5,940
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
ws@7.3.1
7.4.6

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
ws@7.3.1
7.4.6

Open the chart page →

7,027
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
ws@6.2.1
6.2.2

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
ws@6.2.1
6.2.2

Open the chart page →

10,603
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
ws@6.2.1
6.2.2

Open the chart page →

6,438
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
ws@7.2.5
7.4.6

Open the chart page →

6,684
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
ws@6.1.4
6.2.2

Open the chart page →

27,465
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ws@5.2.2
5.2.3

Open the chart page →

19,720
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
ws@6.1.4
6.2.2

Open the chart page →

6,524
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
ws@5.2.2
5.2.3

Open the chart page →

28,484
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
ws@7.4.4
7.4.6

Open the chart page →

5,215
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
ws@6.2.1
6.2.2

Open the chart page →

2,460
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
ws@7.1.2
7.4.6

Open the chart page →

4,967
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
ws@7.2.5
7.4.6

Open the chart page →

2,838
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
ws@7.4.5
7.4.6

Open the chart page →

5,459
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
ws@6.2.1
6.2.2

Open the chart page →

5,806

Container images carrying it

59 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.