StackRadar

CVE-2021-33502

High

Advisory

Published 24 May 2021In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
23
of 17,781 indexed, latest versions
Container images
21
deployed by those charts
Fix available
1 of 2
affected packages

ReDoS in normalize-url

Carried by container images the latest versions of 23 of 17,781 indexed charts deploy, on 21 images.

Affected packageAffected versionsFixed inImages
normalize-urlnpm4.5.0, 5.0.0, 6.0.04.5.1, 5.3.1, 6.0.118
node-gotdeb7.1.0-1, 11.8.5+~cs58.13.36-3no fix listed3
OSV records
GHSA-px4h-xg32-q955UBUNTU-CVE-2021-33502

Charts affected

23 by stars
ChartLatestAffected imagesRadar Score
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
normalize-url@4.5.0
4.5.1

Open the chart page →

8,213
bredbandskollen-prometheus-exporteraolde0.2.31 of 1See more

bredbandskollen-prometheus-exporter aolde 0.2.3

1 of the 1 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
normalize-url@6.0.0
6.0.1

Open the chart page →

1,972
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
normalize-url@4.5.0
4.5.1

Open the chart page →

4,405
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
normalize-url@4.5.0
4.5.1

Open the chart page →

25,456
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
node-got@11.8.5+~cs58.13.36-3
no fix listed

Open the chart page →

13,220
mergeabledoubanVerified publisher0.2.21 of 1See more

mergeable douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
ghcr.io/leoquote/mergeable:latest451706815103
normalize-url@4.5.0
4.5.1

Open the chart page →

4,223
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
normalize-url@4.5.0
4.5.1

Open the chart page →

3,260
flaresolverrgeek-cookbookVerified publisher5.4.21 of 1See more

flaresolverr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v1.2.896f8c08c0c1b
normalize-url@4.5.0
4.5.1

Open the chart page →

1,870
theloungegeek-cookbookVerified publisher3.4.21 of 1See more

thelounge geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
thelounge/thelounge:4.2.0-alpine639978459c3a
normalize-url@4.5.0
4.5.1

Open the chart page →

2,689
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
governify/registry:v3.4.0d3f37f4f8168
normalize-url@4.5.0
4.5.1

Open the chart page →

22,512
Governify-Falcongovernify0.1.02 of 10See more

Governify-Falcon governify 0.1.0

2 of the 10 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
governify/collector-dynamic:v1.3.06d3d1a5b46a9
normalize-url@4.5.0
4.5.1
governify/registry:v3.4.0d3f37f4f8168
normalize-url@4.5.0
4.5.1

Open the chart page →

24,319
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
normalize-url@4.5.0
4.5.1

Open the chart page →

8,213
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
normalize-url@4.5.0
4.5.1

Open the chart page →

7,232
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-got@7.1.0-1
no fix listed

Open the chart page →

17,779
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
normalize-url@4.5.0
4.5.1

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
normalize-url@4.5.0
4.5.1

Open the chart page →

7,027
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
normalize-url@5.0.0
5.3.1

Open the chart page →

6,684
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
normalize-url@4.5.0
4.5.1

Open the chart page →

29,227
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
normalize-url@4.5.0
4.5.1

Open the chart page →

5,215
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-got@7.1.0-1
no fix listed

Open the chart page →

10,902
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
normalize-url@4.5.0
4.5.1

Open the chart page →

6,881
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
normalize-url@4.5.0
4.5.1

Open the chart page →

2,838
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-33502.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
normalize-url@4.5.0
4.5.1

Open the chart page →

22,665

Container images carrying it

21 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
governify/registry:v3.4.0d3f37f4f8168
normalize-url@4.5.0
4.5.1
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
normalize-url@4.5.0
4.5.1
2
mesosphere/kommander:6.100.13917e82333a9
normalize-url@4.5.0
4.5.1
2
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
normalize-url@6.0.0
6.0.1
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
normalize-url@4.5.0
4.5.1
1
denisshav/backend:latest4cc8dc5a4499
normalize-url@4.5.0
4.5.1
1
ethersphere/bzz-token-service:latest7624f11a72ad
normalize-url@4.5.0
4.5.1
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
normalize-url@4.5.0
4.5.1
1
gristlabs/grist:0.7.96e71b1914a7e
normalize-url@4.5.0
4.5.1
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-got@11.8.5+~cs58.13.36-3
no fix listed
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-got@7.1.0-1
no fix listed
1
mozilla/sentencecollector:2.0.91da6ff5c4895
normalize-url@5.0.0
5.3.1
1
roadiehq/community-backstage-image:latestef355bf5b639
normalize-url@4.5.0
4.5.1
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-got@7.1.0-1
no fix listed
1
temporalio/web:1.14.033cfa863d8ce
normalize-url@4.5.0
4.5.1
1
thelounge/thelounge:4.2.0-alpine639978459c3a
normalize-url@4.5.0
4.5.1
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
normalize-url@4.5.0
4.5.1
1
ghcr.io/flaresolverr/flaresolverr:v1.2.896f8c08c0c1b
normalize-url@4.5.0
4.5.1
1
ghcr.io/leoquote/mergeable:latest451706815103
normalize-url@4.5.0
4.5.1
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
normalize-url@4.5.0
4.5.1
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
normalize-url@4.5.0
4.5.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.