StackRadar

CVE-2023-26112

Medium

Advisory

Published 3 Apr 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.013
68th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
84
of 17,781 indexed, latest versions
Container images
77
deployed by those charts
Fix available
2 of 2
affected packages

configobj ReDoS exploitable by developer using values in a server-side configuration file

Carried by container images the latest versions of 84 of 17,781 indexed charts deploy, on 77 images.

Affected packageAffected versionsFixed inImages
configobjdeb5.0.6-45.0.6-4ubuntu0.11
configobjpypi5.0.6, 5.0.85.0.977
OSV records
UBUNTU-CVE-2023-26112GHSA-c33w-24p9-8m24
Also known as
PYSEC-2026-1270, USN-7040-1

Charts affected

84 by stars
ChartLatestAffected imagesRadar Score
gitter-irc-bridgehalkeye0.1.11 of 1See more

gitter-irc-bridge halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
configobj@5.0.6
5.0.9

Open the chart page →

3,642
resurrectbothalkeye0.1.51 of 1See more

resurrectbot halkeye 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
halkeye/slack-resurrect:v0.1.477b05e95fdb5
configobj@5.0.6
5.0.9

Open the chart page →

3,809
prometheus-aws-costs-exporterhelm-charts-nr0.1.51 of 1See more

prometheus-aws-costs-exporter helm-charts-nr 0.1.5

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
nachomillangarcia/prometheus_aws_cost_exporter:lateste4ce056f2d6d
configobj@5.0.6
5.0.9

Open the chart page →

3,553
jenkinsjenkins-x0.10.381 of 2See more

jenkins jenkins-x 0.10.38

1 of the 2 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
jenkinsci/jenkins:2.67a1f33f004659
configobj@5.0.6
5.0.9

Open the chart page →

10,682
oauth2-proxyjenkins-x0.2.31 of 1See more

oauth2-proxy jenkins-x 0.2.3

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
a5huynh/oauth2_proxy:2.20c7307d31ca8
configobj@5.0.6
5.0.9

Open the chart page →

2,392
annotation-tooljtektVerified publisher0.1.51 of 2See more

annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
configobj@5.0.6
5.0.9

Open the chart page →

2,315
polygonal-annotation-tooljtektVerified publisher0.1.51 of 2See more

polygonal-annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
configobj@5.0.6
5.0.9

Open the chart page →

2,231
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
configobj@5.0.6
5.0.9

Open the chart page →

16,417
statsdkeyporttech0.1.191 of 1See more

statsd keyporttech 0.1.19

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
statsd/statsd:v0.8.6dab129e74c25
configobj@5.0.6
5.0.9

Open the chart page →

4,185
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
configobj@5.0.6
5.0.9

Open the chart page →

5,287
buildkite-exporterminaVerified publisher0.1.41 of 1See more

buildkite-exporter mina 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
codaprotocol/buildkite-exporter:0.2.137c68e67a401
configobj@5.0.6
5.0.9

Open the chart page →

2,599
o1-botminaVerified publisher0.0.31 of 1See more

o1-bot mina 0.0.3

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
codaprotocol/coda-user-agent:0.1.54ba4dd3a041f
configobj@5.0.6
5.0.9

Open the chart page →

2,655
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
configobj@5.0.6
5.0.9

Open the chart page →

8,556
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
openwhisk/alarmprovider:2.2.0b695a6ceb406
configobj@5.0.6
5.0.9

Open the chart page →

36,215
myappp4-helm0.1.02 of 6See more

myapp p4-helm 0.1.0

2 of the 6 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
configobj@5.0.6
5.0.9
fjvela/urjc-fjvela-server:1.0.53c840aebce22
configobj@5.0.6
5.0.9

Open the chart page →

19,720
plausiblepascaliskeVerified publisher2.0.01 of 1See more

plausible pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
configobj@5.0.8
5.0.9

Open the chart page →

960
plausibleplausible0.1.21 of 2See more

plausible plausible 0.1.2

1 of the 2 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
configobj@5.0.8
5.0.9

Open the chart page →

1,338
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
configobj@5.0.6
5.0.9

Open the chart page →

28,484
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
configobj@5.0.8
5.0.9

Open the chart page →

4,616
classificationsignalen4.24.01 of 1See more

classification signalen 4.24.0

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
configobj@5.0.6
5.0.9

Open the chart page →

1,553
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
configobj@5.0.6
5.0.9

Open the chart page →

3,696
simple-db-app-chartsimple-db-app0.1.01 of 2See more

simple-db-app-chart simple-db-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
htmlprogrammer2001/simple-db-app:1.0a7e0a233a9bc
configobj@5.0.6
5.0.9

Open the chart page →

1,925
simple-db-app-chart-with-dependencysimple-db-app0.1.01 of 3See more

simple-db-app-chart-with-dependency simple-db-app 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
htmlprogrammer2001/simple-db-app:1.0a7e0a233a9bc
configobj@5.0.6
5.0.9

Open the chart page →

1,925
first-appsimple-helm-chart0.1.01 of 1See more

first-app simple-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
leeyoongti/first-app:1.0.021d66cb76352
configobj@5.0.6
5.0.9

Open the chart page →

2,154
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
configobj@5.0.6-4
configobj@5.0.6
5.0.6-4ubuntu0.1
5.0.9

Open the chart page →

30,687
restful-distributed-lock-managerstakaterVerified publisher1.0.41 of 1See more

restful-distributed-lock-manager stakater 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
configobj@5.0.6
5.0.9

Open the chart page →

3,116
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
configobj@5.0.6
5.0.9

Open the chart page →

11,841
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
configobj@5.0.6
5.0.9

Open the chart page →

4,967
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
configobj@5.0.6
5.0.9

Open the chart page →

8,262
workerappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

workerapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
configobj@5.0.6
5.0.9

Open the chart page →

3,329
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
configobj@5.0.6
5.0.9

Open the chart page →

8,262
workerappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

workerapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_worker:v1741e3aaaa812
configobj@5.0.6
5.0.9

Open the chart page →

3,329
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
configobj@5.0.6
5.0.9

Open the chart page →

2,559
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2023-26112.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
configobj@5.0.6
5.0.9

Open the chart page →

2,643

Container images carrying it

77 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
netbirdio/dashboard:v2.90.2332cc31f5f35
configobj@5.0.6
5.0.9
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
configobj@5.0.6
5.0.9
1
ngoduykhanh/powerdns-admin:latest9898a7cf37d2
configobj@5.0.6
5.0.9
1
nodered/node-red-docker:0.19.6-v8070643219ea2
configobj@5.0.6
5.0.9
1
ondrejsika/parking:latestb1fd497416c8
configobj@5.0.6
5.0.9
1
openemr/openemr:6.1.089eaa6d9a4e3
configobj@5.0.6
5.0.9
1
openspeedtest/latest:v2.0.0d4d62f4b7d85
configobj@5.0.6
5.0.9
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
configobj@5.0.6
5.0.9
1
pachyderm/grpc-proxy:0.4.92b27f41d4d02
configobj@5.0.6
5.0.9
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
configobj@5.0.8
5.0.9
1
rakii8585/angular-node-webapp:latest026082a515ac
configobj@5.0.6
5.0.9
1
raykrueger/riemann:0.2.14c8baf3de57bb
configobj@5.0.6
5.0.9
1
robotshop/rs-cart:latest388349d5cb3c
configobj@5.0.6
5.0.9
1
robotshop/rs-catalogue:latestd545747c1b97
configobj@5.0.6
5.0.9
1
robotshop/rs-user:latestea509182c180
configobj@5.0.6
5.0.9
1
royalwang/sentinel-dashboard:1.8.4df99e2499f91
configobj@5.0.6
5.0.9
1
signalen/classification:ad60447d1733473e30ab0a3ba53d58141cc1d2509496ae672877
configobj@5.0.6
5.0.9
1
slagattollas/server-practica:latest6dd8ead8e2b1
configobj@5.0.6
5.0.9
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
configobj@5.0.6-4
configobj@5.0.6
5.0.6-4ubuntu0.1
5.0.9
1
stakater/restful-distributed-lock-manager:0.5.34f8e409f30c2
configobj@5.0.6
5.0.9
1
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
configobj@5.0.6
5.0.9
1
ghcr.io/kubedb/mongo-gui:latestee0354b7a57a
configobj@5.0.6
5.0.9
1
ghcr.io/leoquote/mergeable:latest451706815103
configobj@5.0.6
5.0.9
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
configobj@5.0.6
5.0.9
1
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
configobj@5.0.8
5.0.9
1
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
configobj@5.0.8
5.0.9
1
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
configobj@5.0.6
5.0.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.