StackRadar

CVE-2021-32640

Medium

Advisory

Published 28 May 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.028
86th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
67
of 17,781 indexed, latest versions
Container images
59
deployed by those charts
Fix available
1 of 1
affected package

ReDoS in Sec-Websocket-Protocol header

Carried by container images the latest versions of 67 of 17,781 indexed charts deploy, on 59 images.

Affected packageAffected versionsFixed inImages
wsnpm5.2.2, 6.1.3, 6.1.4, 6.2.0+8 more5.2.3, 6.2.2, 7.4.659
OSV records
GHSA-6fc8-4gx4-v693

Charts affected

67 by stars
ChartLatestAffected imagesRadar Score
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
ws@6.2.1
6.2.2

Open the chart page →

5,940
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
ws@7.3.1
7.4.6

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
ws@7.3.1
7.4.6

Open the chart page →

7,027
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
ws@6.2.1
6.2.2

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
ws@6.2.1
6.2.2

Open the chart page →

10,603
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
ws@6.2.1
6.2.2

Open the chart page →

6,438
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
ws@7.2.5
7.4.6

Open the chart page →

6,684
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
ws@6.1.4
6.2.2

Open the chart page →

27,465
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ws@5.2.2
5.2.3

Open the chart page →

19,720
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
ws@6.1.4
6.2.2

Open the chart page →

6,524
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
ws@5.2.2
5.2.3

Open the chart page →

28,484
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
ws@7.4.4
7.4.6

Open the chart page →

5,215
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
ws@6.2.1
6.2.2

Open the chart page →

2,460
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
ws@7.1.2
7.4.6

Open the chart page →

4,967
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
ws@7.2.5
7.4.6

Open the chart page →

2,838
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
ws@7.4.5
7.4.6

Open the chart page →

5,459
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-32640.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
ws@6.2.1
6.2.2

Open the chart page →

5,806

Container images carrying it

59 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
oscarsotosanchez/server:v1.06e2e1279126b
ws@5.2.2
5.2.3
4
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
ws@6.2.1
6.2.2
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
ws@6.2.1
6.2.2
2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ws@5.2.2
5.2.3
2
governify/assets-manager:v1.4.12987672448c7
ws@6.2.0
6.2.2
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
ws@7.4.5
7.4.6
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
ws@6.2.1
6.2.2
2
mesosphere/kommander:6.100.13917e82333a9
ws@7.3.1
7.4.6
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
ws@6.2.1
6.2.2
2
requarks/wiki:2:latest68f0d1848261
ws@7.4.5
7.4.6
2
amundsendev/amundsen-frontend:2.1.169e7915e61c1
ws@5.2.2
5.2.3
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
ws@7.3.1
7.4.6
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
ws@7.3.1
7.4.6
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
ws@7.4.3
7.4.6
1
chatwoot/chatwoot:v4.15.167ebc751c171
ws@6.2.1
6.2.2
1
cnieg/maildev:v1.1.998ee05668915
ws@6.1.4
6.2.2
1
codercom/code-server:3.10.247605610ad8d
ws@7.4.5
7.4.6
1
conduction/conduction-ui-app:devd591f5e6f2a9
ws@6.2.1
6.2.2
1
datarhei/restreamer:0.6.4655e12f9eeed
ws@7.2.3
7.4.6
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
ws@5.2.2
5.2.3
1
electerious/ackee:3.2.05e7173fa321c
ws@7.4.5
7.4.6
1
ethersphere/bzz-token-service:latest7624f11a72ad
ws@5.2.2
5.2.3
1
fiware/iotagent-ul:1.14.0fe11f55a926d
ws@6.2.1
6.2.2
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ws@6.2.1
6.2.2
1
gristlabs/grist:0.7.96e71b1914a7e
ws@7.4.4
7.4.6
1
halkeye/hubot:latest9764d2202130
ws@6.2.1
6.2.2
1
halkeye/irslackd:latest7638bfba70b0
ws@5.2.2
5.2.3
1
hansehe/graphql-gateway:1.0.458e09540afbc
ws@6.2.1
6.2.2
1
henrywhitaker3/speedtest-tracker:latest47159a940229
ws@6.2.1
6.2.2
1
inseefrlab/shelly:cloudshell31f04ca7436b
ws@6.1.4
6.2.2
1
koumoul/capture:17108d47be3b2
ws@6.2.1
6.2.2
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
ws@6.2.1
6.2.2
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
ws@6.2.1
6.2.2
1
langgenius/dify-api:1.0.0066035f93856
ws@7.3.1
7.4.6
1
langgenius/dify-api:0.6.11fca918260dd6
ws@7.3.1
7.4.6
1
lavandadelpatio/frontend:latest501c3f31e0bc
ws@6.2.1
6.2.2
1
linuxserver/codimd:latestb801bbcf6386
ws@6.1.4
6.2.2
1
misskey/misskey:12.110.1e08b7c478093
ws@6.2.1
6.2.2
1
mozilla/sentencecollector:2.0.91da6ff5c4895
ws@7.2.5
7.4.6
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
ws@7.4.3
7.4.6
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
ws@7.4.4
7.4.6
1
pachyderm/grpc-proxy:0.4.92b27f41d4d02
ws@7.1.2
7.4.6
1
phntom/codimd:2.4.31b9aafbb62e6
ws@6.1.4
6.2.2
1
requarks/wiki:canary-2.5.2438b5865a7386c
ws@7.4.5
7.4.6
1
slagattollas/server-practica:latest6dd8ead8e2b1
ws@5.2.2
5.2.3
1
testhubio/testhub-frontend:on-preme86c2db53be8
ws@6.2.1
6.2.2
1
thelounge/thelounge:4.2.0-alpine639978459c3a
ws@7.3.1
7.4.6
1
willwill/kube-slack:v4.1.1d443017aae98
ws@6.1.3
6.2.2
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
ws@7.4.5
7.4.6
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
ws@6.2.1
6.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.