StackRadar

CVE-2021-3918

Critical

Advisory

Published 13 Nov 2021In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.038
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
220
of 17,781 indexed, latest versions
Container images
220
deployed by those charts
Fix available
2 of 2
affected packages

json-schema is vulnerable to Prototype Pollution

Carried by container images the latest versions of 220 of 17,781 indexed charts deploy, on 220 images.

Affected packageAffected versionsFixed inImages
json-schemanpm0.2.2, 0.2.3, 0.3.00.4.0220
node-json-schemadeb0.2.3-10.2.3-1+deb10u1build0.20.04.11
OSV records
GHSA-896r-f27r-55mwUBUNTU-CVE-2021-3918
Also known as
USN-6103-1

Charts affected

220 by stars
ChartLatestAffected imagesRadar Score
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
json-schema@0.2.3
0.4.0

Open the chart page →

3,228
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
json-schema@0.2.3
0.4.0

Open the chart page →

2,121
alert-mappersomeblackmagic0.2.01 of 1See more

alert-mapper someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
someblackmagic/alert-mapper:v0.1.088351d85c04c
json-schema@0.2.3
0.4.0

Open the chart page →

1,890
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
json-schema@0.2.3
0.4.0

Open the chart page →

3,881
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
json-schema@0.2.3
0.4.0

Open the chart page →

4,967
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
json-schema@0.2.3
0.4.0

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
json-schema@0.2.3
0.4.0

Open the chart page →

12,460
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
json-schema@0.2.3
0.4.0

Open the chart page →

10,902
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
json-schema@0.2.3
0.4.0

Open the chart page →

3,827
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
json-schema@0.2.3
0.4.0

Open the chart page →

4,017
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
json-schema@0.2.3
0.4.0

Open the chart page →

3,576
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
json-schema@0.2.3
0.4.0

Open the chart page →

6,881
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
json-schema@0.2.3
0.4.0

Open the chart page →

2,838
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
json-schema@0.2.3
0.4.0

Open the chart page →

3,129
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
json-schema@0.2.3
0.4.0

Open the chart page →

2,559
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
json-schema@0.2.3
0.4.0

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
json-schema@0.2.3
0.4.0

Open the chart page →

22,665
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
json-schema@0.2.3
0.4.0

Open the chart page →

5,806
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
json-schema@0.2.3
0.4.0

Open the chart page →

1,309
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
json-schema@0.2.3
0.4.0

Open the chart page →

3,118

Container images carrying it

220 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
robotshop/rs-cart:latest388349d5cb3c
json-schema@0.2.3
0.4.0
1
robotshop/rs-catalogue:latestd545747c1b97
json-schema@0.2.3
0.4.0
1
robotshop/rs-user:latestea509182c180
json-schema@0.2.3
0.4.0
1
shahanafarooqui/rtl:0.11.0d0cd3d868aca
json-schema@0.2.3
0.4.0
1
shinobisystems/shinobi:dev3ca746937856
json-schema@0.2.3
0.4.0
1
shinobisystems/shinobi:latestc2f5ce2e1067
json-schema@0.2.3
0.4.0
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
json-schema@0.2.3
0.4.0
1
slagattollas/server-practica:latest6dd8ead8e2b1
json-schema@0.2.3
0.4.0
1
slagattollas/weatherservice-practica:latest68e7f56393fc
json-schema@0.2.3
0.4.0
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
json-schema@0.2.3
0.4.0
1
socialmediamacroscope/smile_server:0.3.31a528c794270
json-schema@0.2.3
0.4.0
1
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
json-schema@0.2.3
0.4.0
1
someblackmagic/alert-mapper:v0.1.088351d85c04c
json-schema@0.2.3
0.4.0
1
sqlpad/sqlpad:6.7d3d2f430dffd
json-schema@0.2.3
0.4.0
1
stanfordoval/almond-server:latest1a63cdccedaf
json-schema@0.2.3
0.4.0
1
svenwal/jsonplaceholder:latestba2f285af432
json-schema@0.2.3
0.4.0
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
json-schema@0.2.3
0.4.0
1
taigaio/taiga-events:6.4.00bf2d24a57d9
json-schema@0.2.3
0.4.0
1
temporalio/web:1.14.033cfa863d8ce
json-schema@0.2.3
0.4.0
1
testhubio/testhub-frontend:on-preme86c2db53be8
json-schema@0.2.3
0.4.0
1
thelounge/thelounge:4.2.0-alpine639978459c3a
json-schema@0.2.3
0.4.0
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
json-schema@0.2.3
0.4.0
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
json-schema@0.2.3
0.4.0
1
trufflesuite/ganache-cli:v6.12.2c062707f17f3
json-schema@0.2.3
0.4.0
1
tvanro/prerender-alpine:6.4.06909015f0328
json-schema@0.2.3
0.4.0
1
tzahi12345/youtubedl-material:4.23720b856bd2f
json-schema@0.2.3
0.4.0
1
ubercadence/web:v3.29.58564a5b44a6d
json-schema@0.2.3
0.4.0
1
wekanteam/wekan:v4.2268a51f0327df
json-schema@0.2.3
0.4.0
1
willwill/kube-slack:v4.1.1d443017aae98
json-schema@0.2.3
0.4.0
1
wiremind/scrapoxy:lateste7048929a676
json-schema@0.2.3
0.4.0
1
zazuko/trifid:2.3.7054be137de70
json-schema@0.2.3
0.4.0
1
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
json-schema@0.2.3
0.4.0
1
zooz/predator:1.6f491d1f7a865
json-schema@0.2.3
0.4.0
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
json-schema@0.2.3
0.4.0
1
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
json-schema@0.2.3
0.4.0
1
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
json-schema@0.2.3
0.4.0
1
ghcr.io/aolde/lametric-nightscout-proxy:latest7d1951b6baf5
json-schema@0.2.3
0.4.0
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
json-schema@0.2.3
0.4.0
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
json-schema@0.2.3
0.4.0
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
json-schema@0.2.3
0.4.0
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
json-schema@0.2.3
0.4.0
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
json-schema@0.2.3
0.4.0
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
json-schema@0.2.3
0.4.0
1
ghcr.io/flaresolverr/flaresolverr:v1.2.896f8c08c0c1b
json-schema@0.2.3
0.4.0
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
json-schema@0.2.3
0.4.0
1
ghcr.io/leoquote/mergeable:latest451706815103
json-schema@0.2.3
0.4.0
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
json-schema@0.2.3
0.4.0
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
json-schema@0.2.3
0.4.0
1
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
json-schema@0.2.3
0.4.0
1
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
json-schema@0.2.3
0.4.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.