StackRadar

CVE-2023-26115

Medium

Advisory

Published 22 Jun 2023In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.017
76th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
120
of 17,781 indexed, latest versions
Container images
120
deployed by those charts
Fix available
1 of 1
affected package

word-wrap vulnerable to Regular Expression Denial of Service

Carried by container images the latest versions of 120 of 17,781 indexed charts deploy, on 120 images.

Affected packageAffected versionsFixed inImages
word-wrapnpm1.2.31.2.4120
OSV records
GHSA-j8xg-fqg3-53r7

Charts affected

120 by stars
ChartLatestAffected imagesRadar Score
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
word-wrap@1.2.3
1.2.4

Open the chart page →

3,269
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
word-wrap@1.2.3
1.2.4

Open the chart page →

2,919
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
word-wrap@1.2.3
1.2.4

Open the chart page →

15,187
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
word-wrap@1.2.3
1.2.4

Open the chart page →

27,465
powerdnspuckpuck2.0.01 of 4See more

powerdns puckpuck 2.0.0

1 of the 4 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
pschiffe/pdns-admin:0.4.137ebba8c2b8f
word-wrap@1.2.3
1.2.4

Open the chart page →

4,616
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
word-wrap@1.2.3
1.2.4

Open the chart page →

6,026
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
word-wrap@1.2.3
1.2.4

Open the chart page →

7,413
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
word-wrap@1.2.3
1.2.4

Open the chart page →

4,431
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
word-wrap@1.2.3
1.2.4

Open the chart page →

3,143
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
word-wrap@1.2.3
1.2.4

Open the chart page →

7,574
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
word-wrap@1.2.3
1.2.4

Open the chart page →

3,228
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
word-wrap@1.2.3
1.2.4

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
word-wrap@1.2.3
1.2.4

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
word-wrap@1.2.3
1.2.4

Open the chart page →

3,881
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
word-wrap@1.2.3
1.2.4

Open the chart page →

20,270
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
word-wrap@1.2.3
1.2.4

Open the chart page →

3,576
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
word-wrap@1.2.3
1.2.4

Open the chart page →

2,838
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
word-wrap@1.2.3
1.2.4

Open the chart page →

3,129
websitewaldo-visionVerified publisher0.33.01 of 2See more

website waldo-vision 0.33.0

1 of the 2 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
word-wrap@1.2.3
1.2.4

Open the chart page →

3,474
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2023-26115.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
word-wrap@1.2.3
1.2.4

Open the chart page →

5,806

Container images carrying it

120 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
word-wrap@1.2.3
1.2.4
5
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
word-wrap@1.2.3
1.2.4
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
word-wrap@1.2.3
1.2.4
2
governify/assets-manager:v1.4.12987672448c7
word-wrap@1.2.3
1.2.4
2
governify/director:v1.4.0608c6940bb98
word-wrap@1.2.3
1.2.4
2
governify/registry:v3.4.0d3f37f4f8168
word-wrap@1.2.3
1.2.4
2
governify/render:v2.2.0daeca1ce28e6
word-wrap@1.2.3
1.2.4
2
governify/reporter:v2.2.038595913458f
word-wrap@1.2.3
1.2.4
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
word-wrap@1.2.3
1.2.4
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
word-wrap@1.2.3
1.2.4
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
word-wrap@1.2.3
1.2.4
2
outlinewiki/outline:0.69.1d060dcd8f9aa
word-wrap@1.2.3
1.2.4
2
shahanafarooqui/rtl:0.13.3e2195188a451
word-wrap@1.2.3
1.2.4
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
word-wrap@1.2.3
1.2.4
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
word-wrap@1.2.3
1.2.4
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
word-wrap@1.2.3
1.2.4
2
arfath29/3-tier-app-frontend:latest384b3e377f47
word-wrap@1.2.3
1.2.4
1
arturisimo/server-urjc:v1.0d8dc4430531e
word-wrap@1.2.3
1.2.4
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
word-wrap@1.2.3
1.2.4
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
word-wrap@1.2.3
1.2.4
1
assistiot/open_api_frontend:1.0.1f11d82defc70
word-wrap@1.2.3
1.2.4
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
word-wrap@1.2.3
1.2.4
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
word-wrap@1.2.3
1.2.4
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
word-wrap@1.2.3
1.2.4
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
word-wrap@1.2.3
1.2.4
1
catalysm/csmm:latestf003b35f54d9
word-wrap@1.2.3
1.2.4
1
ccjacobs14/amazon:59a9b14a6f09e
word-wrap@1.2.3
1.2.4
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
word-wrap@1.2.3
1.2.4
1
codercom/code-server:4.11.0-debian1e2cc688008e
word-wrap@1.2.3
1.2.4
1
codercom/code-server:3.10.247605610ad8d
word-wrap@1.2.3
1.2.4
1
coldatom/containers-security-front:latest7c2fbbb41bcf
word-wrap@1.2.3
1.2.4
1
conduction/conduction-ui-app:devd591f5e6f2a9
word-wrap@1.2.3
1.2.4
1
enketo/enketo-express:3.0.4dcad9c2273f6
word-wrap@1.2.3
1.2.4
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
word-wrap@1.2.3
1.2.4
1
ethersphere/onboarding-faucet:0.3.0513154aab230
word-wrap@1.2.3
1.2.4
1
fiware/idm:8.3.3a1b6ed4ae84f
word-wrap@1.2.3
1.2.4
1
fiware/iotagent-ul:1.14.0fe11f55a926d
word-wrap@1.2.3
1.2.4
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
word-wrap@1.2.3
1.2.4
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
word-wrap@1.2.3
1.2.4
1
heywood8/redisinsight:2.28.00bc9ab313d37
word-wrap@1.2.3
1.2.4
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
word-wrap@1.2.3
1.2.4
1
hugohg34/server:0.0.2503e5d8960ff
word-wrap@1.2.3
1.2.4
1
ianw/quickchart:v1.7.1dc49dd460c37
word-wrap@1.2.3
1.2.4
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
word-wrap@1.2.3
1.2.4
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
word-wrap@1.2.3
1.2.4
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
word-wrap@1.2.3
1.2.4
1
jayfong/yapi:1.10.2163e5d621910
word-wrap@1.2.3
1.2.4
1
joplin/server:3.0-beta52af57880c0e
word-wrap@1.2.3
1.2.4
1
joplin/server:2.14.2-betab87564ef34e9
word-wrap@1.2.3
1.2.4
1
junktext/getting-started:1.0.5a70936c04aed
word-wrap@1.2.3
1.2.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.