StackRadar

CVE-2021-3765

Medium

Advisory

Published 3 Nov 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
48
of 17,781 indexed, latest versions
Container images
47
deployed by those charts
Fix available
1 of 1
affected package

Inefficient Regular Expression Complexity in validator.js

Carried by container images the latest versions of 48 of 17,781 indexed charts deploy, on 47 images.

Affected packageAffected versionsFixed inImages
validatornpm1.5.1, 2.1.0, 3.2.1, 4.4.0+12 more13.7.047
OSV records
GHSA-qgmg-gppg-76g5

Charts affected

48 by stars
ChartLatestAffected imagesRadar Score
lighthouse-cicowboysysopVerified publisher9.0.01 of 1See more

lighthouse-ci cowboysysop 9.0.0

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
patrickhulce/lhci-server:0.8.174b4b6a3954d
validator@10.11.0
13.7.0

Open the chart page →

2,213
redisinsightheywood8-helm-chartsVerified publisher0.4.51 of 1See more

redisinsight heywood8-helm-charts 0.4.5

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
heywood8/redisinsight:2.28.00bc9ab313d37
validator@13.0.0
13.7.0

Open the chart page →

2,828
ghost-on-kubernetesghost-on-kubernetes-helmVerified publisher1.1.21 of 3See more

ghost-on-kubernetes ghost-on-kubernetes-helm 1.1.2

1 of the 3 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
validator@7.2.0
13.7.0

Open the chart page →

1,447
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
validator@4.4.0
13.7.0

Open the chart page →

5,209
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
validator@10.11.0
13.7.0

Open the chart page →

2,851
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
validator@13.5.2
13.7.0

Open the chart page →

2,519
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
validator@7.2.0
13.7.0

Open the chart page →

4,260
openhab-cloudandibraeuVerified publisher1.2.61 of 1See more

openhab-cloud andibraeu 1.2.6

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
openhab/openhab-cloud:a8138a329dd2bac8c4b
validator@2.1.0
13.7.0

Open the chart page →

3,437
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
validator@4.4.0
13.7.0

Open the chart page →

18,277
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
validator@7.2.0
13.7.0

Open the chart page →

4,083
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
validator@4.4.0
13.7.0

Open the chart page →

5,209
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
validator@12.0.0
13.7.0

Open the chart page →

3,769
swagger-combine-uicryptexlabsVerified publisher0.2.41 of 1See more

swagger-combine-ui cryptexlabs 0.2.4

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
validator@10.11.0
13.7.0

Open the chart page →

1,378
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
validator@10.11.0
13.7.0

Open the chart page →

27,550
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
validator@10.11.0
13.7.0

Open the chart page →

24,656
eolicplantseolicplantsVerified publisher0.1.01 of 7See more

eolicplants eolicplants 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
validator@10.11.0
13.7.0

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.01 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
validator@10.11.0
13.7.0

Open the chart page →

27,256
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
validator@13.6.0
13.7.0

Open the chart page →

12,222
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
validator@12.2.0
13.7.0

Open the chart page →

9,019
Governify-Bluejaygovernify0.1.03 of 12See more

Governify-Bluejay governify 0.1.0

3 of the 12 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
governify/director:v1.4.0608c6940bb98
validator@13.6.0
13.7.0
governify/registry:v3.4.0d3f37f4f8168
validator@13.5.2
13.7.0
governify/reporter:v2.2.038595913458f
validator@10.11.0
13.7.0

Open the chart page →

22,512
Governify-Falcongovernify0.1.04 of 10See more

Governify-Falcon governify 0.1.0

4 of the 10 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
governify/collector-dynamic:v1.3.06d3d1a5b46a9
validator@13.5.2
13.7.0
governify/director:v1.4.0608c6940bb98
validator@13.6.0
13.7.0
governify/registry:v3.4.0d3f37f4f8168
validator@13.5.2
13.7.0
governify/reporter:v2.2.038595913458f
validator@10.11.0
13.7.0

Open the chart page →

24,319
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
validator@10.11.0
13.7.0

Open the chart page →

24,161
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
validator@12.2.0
13.7.0
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
validator@10.11.0
13.7.0
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
validator@12.2.0
13.7.0
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
validator@10.11.0
13.7.0

Open the chart page →

89,959
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
validator@10.9.0
13.7.0

Open the chart page →

39,349
ibm-microclimateibm-charts0.1.02 of 8See more

ibm-microclimate ibm-charts 0.1.0

2 of the 8 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
validator@6.2.1
13.7.0
ibmcom/microclimate-portal:latested5505e5c7ec
validator@9.4.1
13.7.0

Open the chart page →

57,669
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
validator@12.2.0
13.7.0

Open the chart page →

10,494
interbtc-hydrainterlay0.1.151 of 4See more

interbtc-hydra interlay 0.1.15

1 of the 4 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
validator@13.6.0
13.7.0

Open the chart page →

6,831
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
validator@8.2.0
13.7.0

Open the chart page →

7,232
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
validator@7.2.0
13.7.0

Open the chart page →

3,436
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
validator@10.11.0
13.7.0

Open the chart page →

6,454
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
validator@7.2.0
13.7.0

Open the chart page →

3,092
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
validator@10.11.0
13.7.0

Open the chart page →

3,397
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
validator@7.2.0
13.7.0

Open the chart page →

2,756
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
validator@10.11.0
13.7.0

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
validator@10.11.0
13.7.0

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
validator@10.11.0
13.7.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
validator@10.11.0
13.7.0

Open the chart page →

12,108
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
validator@10.11.0
13.7.0
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
validator@10.11.0
13.7.0

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
validator@10.11.0
13.7.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
validator@10.11.0
13.7.0
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
validator@10.11.0
13.7.0

Open the chart page →

19,226
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
validator@10.11.0
13.7.0

Open the chart page →

6,684
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
validator@7.2.0
13.7.0

Open the chart page →

4,960
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
validator@1.5.1
13.7.0
linuxserver/codimd:latestb801bbcf6386
validator@10.11.0
13.7.0

Open the chart page →

27,465
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
validator@10.11.0
13.7.0

Open the chart page →

9,968
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
validator@10.11.0
13.7.0

Open the chart page →

6,524
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
validator@10.11.0
13.7.0

Open the chart page →

28,484
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
validator@3.2.1
13.7.0

Open the chart page →

3,827
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
validator@5.7.0
13.7.0

Open the chart page →

3,576
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
validator@13.6.0
13.7.0

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2021-3765.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
validator@13.6.0
13.7.0

Open the chart page →

28,605

Container images carrying it

47 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
validator@10.11.0
13.7.0
5
oscarsotosanchez/server:v1.06e2e1279126b
validator@10.11.0
13.7.0
4
pantsel/konga:latestc8172b75607d
validator@4.4.0
13.7.0
3
governify/director:v1.4.0608c6940bb98
validator@13.6.0
13.7.0
2
governify/registry:v3.4.0d3f37f4f8168
validator@13.5.2
13.7.0
2
governify/reporter:v2.2.038595913458f
validator@10.11.0
13.7.0
2
hookiesolutions/webhookie:latest0629694246ba
validator@13.6.0
13.7.0
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
validator@10.11.0
13.7.0
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
validator@10.11.0
13.7.0
2
catalysm/csmm:latestf003b35f54d9
validator@5.7.0
13.7.0
1
cryptexlabs/authf:0.12.11189c07411d7c
validator@12.0.0
13.7.0
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
validator@10.11.0
13.7.0
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
validator@13.5.2
13.7.0
1
heywood8/redisinsight:2.28.00bc9ab313d37
validator@13.0.0
13.7.0
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
validator@10.9.0
13.7.0
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
validator@6.2.1
13.7.0
1
ibmcom/microclimate-portal:latested5505e5c7ec
validator@9.4.1
13.7.0
1
inseefrlab/shelly:cloudshell31f04ca7436b
validator@12.2.0
13.7.0
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
validator@13.6.0
13.7.0
1
jakowenko/double-take:1.6.0b858bac9e32a
validator@13.6.0
13.7.0
1
jayfong/yapi:1.10.2163e5d621910
validator@10.11.0
13.7.0
1
library/ghost:6.37.01ef2e532ca4d
validator@7.2.0
13.7.0
1
library/ghost:6.25.12654b1e90413
validator@7.2.0
13.7.0
1
library/ghost:6.41.129773d6be407
validator@7.2.0
13.7.0
1
library/ghost:4.37.0767230c0f263
validator@7.2.0
13.7.0
1
library/ghost:6.39.0-alpine77196da4b0df
validator@7.2.0
13.7.0
1
library/ghost:5.79.083f7bf209844
validator@12.2.0
13.7.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
validator@7.2.0
13.7.0
1
linuxserver/cloud9:latest45c5fe102ff3
validator@1.5.1
13.7.0
1
linuxserver/codimd:latestb801bbcf6386
validator@10.11.0
13.7.0
1
mozilla/sentencecollector:2.0.91da6ff5c4895
validator@10.11.0
13.7.0
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
validator@2.1.0
13.7.0
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
validator@10.11.0
13.7.0
1
phntom/codimd:2.4.31b9aafbb62e6
validator@10.11.0
13.7.0
1
roadiehq/community-backstage-image:latestef355bf5b639
validator@8.2.0
13.7.0
1
slagattollas/server-practica:latest6dd8ead8e2b1
validator@10.11.0
13.7.0
1
sqlpad/sqlpad:6.7d3d2f430dffd
validator@10.11.0
13.7.0
1
zooz/predator:1.6f491d1f7a865
validator@10.11.0
13.7.0
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
validator@12.2.0
13.7.0
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
validator@10.11.0
13.7.0
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
validator@12.2.0
13.7.0
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
validator@10.11.0
13.7.0
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
validator@13.5.2
13.7.0
1
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
validator@7.2.0
13.7.0
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
validator@10.11.0
13.7.0
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
validator@10.11.0
13.7.0
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
validator@3.2.1
13.7.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.