StackRadar

CVE-2021-3918

Critical

Advisory

Published 13 Nov 2021In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.038
89th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
220
of 17,781 indexed, latest versions
Container images
220
deployed by those charts
Fix available
2 of 2
affected packages

json-schema is vulnerable to Prototype Pollution

Carried by container images the latest versions of 220 of 17,781 indexed charts deploy, on 220 images.

Affected packageAffected versionsFixed inImages
json-schemanpm0.2.2, 0.2.3, 0.3.00.4.0220
node-json-schemadeb0.2.3-10.2.3-1+deb10u1build0.20.04.11
OSV records
GHSA-896r-f27r-55mwUBUNTU-CVE-2021-3918
Also known as
USN-6103-1

Charts affected

220 by stars
ChartLatestAffected imagesRadar Score
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
json-schema@0.2.3
0.4.0

Open the chart page →

3,228
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
json-schema@0.2.3
0.4.0

Open the chart page →

2,121
alert-mappersomeblackmagic0.2.01 of 1See more

alert-mapper someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
someblackmagic/alert-mapper:v0.1.088351d85c04c
json-schema@0.2.3
0.4.0

Open the chart page →

1,890
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
json-schema@0.2.3
0.4.0

Open the chart page →

3,881
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
json-schema@0.2.3
0.4.0

Open the chart page →

4,967
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
json-schema@0.2.3
0.4.0

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
json-schema@0.2.3
0.4.0

Open the chart page →

12,460
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
json-schema@0.2.3
0.4.0

Open the chart page →

10,902
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
json-schema@0.2.3
0.4.0

Open the chart page →

3,827
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
json-schema@0.2.3
0.4.0

Open the chart page →

4,017
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
json-schema@0.2.3
0.4.0

Open the chart page →

3,576
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
json-schema@0.2.3
0.4.0

Open the chart page →

6,881
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
json-schema@0.2.3
0.4.0

Open the chart page →

2,838
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
json-schema@0.2.3
0.4.0

Open the chart page →

3,129
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
json-schema@0.2.3
0.4.0

Open the chart page →

2,559
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
json-schema@0.2.3
0.4.0

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
json-schema@0.2.3
0.4.0

Open the chart page →

22,665
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
json-schema@0.2.3
0.4.0

Open the chart page →

5,806
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
json-schema@0.2.3
0.4.0

Open the chart page →

1,309
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2021-3918.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
json-schema@0.2.3
0.4.0

Open the chart page →

3,118

Container images carrying it

220 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
json-schema@0.2.3
0.4.0
5
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
json-schema@0.2.3
0.4.0
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
json-schema@0.2.3
0.4.0
4
oscarsotosanchez/server:v1.06e2e1279126b
json-schema@0.2.3
0.4.0
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
json-schema@0.2.3
0.4.0
4
dgraph/dgraph:v21.12.03b55ea83fffe
json-schema@0.2.3
0.4.0
3
frankescobar/allure-docker-service-ui:7.0.3:latest4ebd8b4ef340
json-schema@0.2.3
0.4.0
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
json-schema@0.2.3
0.4.0
3
pantsel/konga:latestc8172b75607d
json-schema@0.2.3
0.4.0
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
json-schema@0.2.3
0.4.0
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
json-schema@0.2.3
0.4.0
2
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
json-schema@0.2.3
0.4.0
2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
json-schema@0.2.3
0.4.0
2
governify/assets-manager:v1.4.12987672448c7
json-schema@0.2.3
0.4.0
2
governify/director:v1.4.0608c6940bb98
json-schema@0.2.3
0.4.0
2
governify/registry:v3.4.0d3f37f4f8168
json-schema@0.2.3
0.4.0
2
governify/render:v2.2.0daeca1ce28e6
json-schema@0.2.3
0.4.0
2
governify/reporter:v2.2.038595913458f
json-schema@0.2.3
0.4.0
2
htmlprogrammer2001/simple-db-app:1.0a7e0a233a9bc
json-schema@0.2.3
0.4.0
2
istio/examples-bookinfo-ratings-v1:1.15.009b9d6958a13
json-schema@0.2.3
0.4.0
2
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
json-schema@0.2.3
0.4.0
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
json-schema@0.2.3
0.4.0
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
json-schema@0.2.3
0.4.0
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
json-schema@0.2.3
0.4.0
2
mesosphere/kommander:6.100.13917e82333a9
json-schema@0.2.3
0.4.0
2
migmartri/prerender:latest486aacfd5aa9
json-schema@0.2.3
0.4.0
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
json-schema@0.2.3
0.4.0
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
json-schema@0.2.3
0.4.0
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
json-schema@0.2.3
0.4.0
2
statsd/statsd:v0.8.6dab129e74c25
json-schema@0.2.3
0.4.0
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
json-schema@0.2.3
0.4.0
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
json-schema@0.2.3
0.4.0
2
a5hut0sh/helloworld:1.02ae77620e616
json-schema@0.2.3
0.4.0
1
adrianberger/fluxcd-webui:latest76848c0d2780
json-schema@0.2.3
0.4.0
1
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
json-schema@0.2.3
0.4.0
1
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
json-schema@0.2.3
0.4.0
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
json-schema@0.2.3
0.4.0
1
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
json-schema@0.2.3
0.4.0
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
json-schema@0.2.3
0.4.0
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
json-schema@0.2.3
0.4.0
1
aureliengasser/http-folder:1.1.111c4318c2571
json-schema@0.2.3
0.4.0
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
json-schema@0.2.3
0.4.0
1
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
json-schema@0.2.3
0.4.0
1
bluerange/bluerange-mosquitto:25f1bfbba84832
json-schema@0.2.3
0.4.0
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
json-schema@0.2.3
0.4.0
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
json-schema@0.2.3
0.4.0
1
catalysm/csmm:latestf003b35f54d9
json-schema@0.2.3
0.4.0
1
chatwoot/chatwoot:v4.15.167ebc751c171
json-schema@0.2.3
0.4.0
1
cnieg/maildev:v1.1.998ee05668915
json-schema@0.2.3
0.4.0
1
conduction/conduction-ui-app:devd591f5e6f2a9
json-schema@0.2.3
0.4.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.