StackRadar

CVE-2021-3795

High

Advisory

Published 20 Sept 2021In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.015
72nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 1
affected package

semver-regex Regular Expression Denial of Service (ReDOS)

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
semver-regexnpm1.0.0, 2.0.0, 3.1.23.1.311
OSV records
GHSA-44c6-4v22-4mhx

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2021-3795.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
semver-regex@2.0.0
3.1.3

Open the chart page →

8,213
hubotdecayofmind1.0.21 of 3See more

hubot decayofmind 1.0.2

1 of the 3 container images this version deploys carry CVE-2021-3795.

Container imageDigestPackageFixed in
decayofmind/hubot:3.3.21e18e92fe694
semver-regex@1.0.0
3.1.3

Open the chart page →

2,513
bredbandskollen-prometheus-exporteraolde0.2.31 of 1See more

bredbandskollen-prometheus-exporter aolde 0.2.3

1 of the 1 container images this version deploys carry CVE-2021-3795.

Container imageDigestPackageFixed in
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
semver-regex@3.1.2
3.1.3

Open the chart page →

1,972
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3795.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
semver-regex@1.0.0
3.1.3

Open the chart page →

4,069
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2021-3795.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
semver-regex@1.0.0
3.1.3

Open the chart page →

2,580
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2021-3795.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
semver-regex@2.0.0
3.1.3

Open the chart page →

3,769
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2021-3795.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
semver-regex@2.0.0
3.1.3

Open the chart page →

8,213
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2021-3795.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
semver-regex@1.0.0
3.1.3

Open the chart page →

57,669
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2021-3795.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
semver-regex@2.0.0
3.1.3

Open the chart page →

4,230
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2021-3795.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
semver-regex@3.1.2
3.1.3

Open the chart page →

5,287
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2021-3795.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
semver-regex@2.0.0
3.1.3

Open the chart page →

6,684
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2021-3795.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
semver-regex@3.1.2
3.1.3

Open the chart page →

3,881

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
semver-regex@2.0.0
3.1.3
2
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
semver-regex@3.1.2
3.1.3
1
cryptexlabs/authf:0.12.11189c07411d7c
semver-regex@2.0.0
3.1.3
1
decayofmind/hubot:3.3.21e18e92fe694
semver-regex@1.0.0
3.1.3
1
ibmcom/microclimate-portal:latested5505e5c7ec
semver-regex@1.0.0
3.1.3
1
konradkleine/docker-registry-frontend:v2181aad54ee64
semver-regex@1.0.0
3.1.3
1
minddocdev/hubot:0.1.96c60b11a4fa7
semver-regex@1.0.0
3.1.3
1
mozilla/sentencecollector:2.0.91da6ff5c4895
semver-regex@2.0.0
3.1.3
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
semver-regex@2.0.0
3.1.3
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
semver-regex@3.1.2
3.1.3
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
semver-regex@3.1.2
3.1.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.