StackRadar

CVE-2023-26159

Medium

Advisory

Published 2 Jan 2024In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
210
of 17,781 indexed, latest versions
Container images
208
deployed by those charts
Fix available
1 of 1
affected package

Follow Redirects improperly handles URLs in the url.parse() function

Carried by container images the latest versions of 210 of 17,781 indexed charts deploy, on 208 images.

Affected packageAffected versionsFixed inImages
follow-redirectsnpm1.0.0, 1.2.5, 1.5.10, 1.6.1+20 more1.15.4208
OSV records
GHSA-jchw-25xp-jwwc

Charts affected

210 by stars
ChartLatestAffected imagesRadar Score
vehicle-dashboardtest-vehi-dash0.1.02 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

2 of the 7 container images this version deploys carry CVE-2023-26159.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
follow-redirects@1.15.2
1.15.4
samajh/alprfrontend:latest05ef4fddbb75
follow-redirects@1.15.2
1.15.4

Open the chart page →

20,270
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2023-26159.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
follow-redirects@1.14.5
1.15.4

Open the chart page →

3,576
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2023-26159.

Container imageDigestPackageFixed in
thingsboard/tb-web-ui:3.4.157f98ed53b3d
follow-redirects@1.15.1
1.15.4

Open the chart page →

25,394
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2023-26159.

Container imageDigestPackageFixed in
jupyterhub/configurable-http-proxy:4.5.39e2c0107c7a3
follow-redirects@1.14.8
1.15.4

Open the chart page →

8,607
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2023-26159.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
follow-redirects@1.14.6
1.15.4

Open the chart page →

3,129
skoonervhdirkVerified publisher0.1.41 of 1See more

skooner vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2023-26159.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
follow-redirects@1.15.2
1.15.4

Open the chart page →

1,341
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2023-26159.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
follow-redirects@1.15.1
1.15.4

Open the chart page →

3,118
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2023-26159.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
follow-redirects@1.9.0
1.15.4

Open the chart page →

2,559
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2023-26159.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
follow-redirects@1.15.2
1.15.4
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
follow-redirects@1.15.2
1.15.4
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
follow-redirects@1.15.2
1.15.4
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
follow-redirects@1.15.2
1.15.4

Open the chart page →

16,083
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2023-26159.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
follow-redirects@1.14.8
1.15.4

Open the chart page →

1,752

Container images carrying it

208 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
follow-redirects@1.15.2
1.15.4
4
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
follow-redirects@1.14.3
1.15.4
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
follow-redirects@1.15.3
1.15.4
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
follow-redirects@1.15.2
1.15.4
3
quay.io/jupyterhub/configurable-http-proxy:4.6.1fd916f75415f
follow-redirects@1.14.8
1.15.4
3
agoldis/sorry-cypress-director:2.5.1110228ecd353b
follow-redirects@1.15.0
1.15.4
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
follow-redirects@1.14.0
1.15.4
2
governify/assets-manager:v1.4.12987672448c7
follow-redirects@1.14.4
1.15.4
2
governify/director:v1.4.0608c6940bb98
follow-redirects@1.14.4
1.15.4
2
governify/registry:v3.4.0d3f37f4f8168
follow-redirects@1.14.4
1.15.4
2
governify/render:v2.2.0daeca1ce28e6
follow-redirects@1.14.4
1.15.4
2
governify/reporter:v2.2.038595913458f
follow-redirects@1.14.4
1.15.4
2
gradiant/open5gs-webui:2.7.5fbd10c017541
follow-redirects@1.15.2
1.15.4
2
jupyterhub/configurable-http-proxy:4.5.08ced0a2f8073
follow-redirects@1.13.2
1.15.4
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
follow-redirects@1.14.1
1.15.4
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
follow-redirects@1.13.0
1.15.4
2
mesosphere/kommander:6.100.13917e82333a9
follow-redirects@1.13.1
1.15.4
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
follow-redirects@1.14.4
1.15.4
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
follow-redirects@1.13.1
1.15.4
2
moreillon/api-proxy:a3e8b41e9e578c9653b6
follow-redirects@1.13.0
1.15.4
2
moreillon/group-manager:v4.9.0d5a0ec8394c0
follow-redirects@1.15.3
1.15.4
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
follow-redirects@1.15.2
1.15.4
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
follow-redirects@1.14.1
1.15.4
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
follow-redirects@1.14.8
1.15.4
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
follow-redirects@1.15.3
1.15.4
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
follow-redirects@1.15.1
1.15.4
2
amundsendev/amundsen-frontend:2.1.169e7915e61c1
follow-redirects@1.5.10
1.15.4
1
apimap/developer:v1.3.1406d3858e20c
follow-redirects@1.15.1
1.15.4
1
apimap/portal:v2.4.0041a4790c65c
follow-redirects@1.14.9
1.15.4
1
arfath29/3-tier-app-frontend:latest384b3e377f47
follow-redirects@1.14.1
1.15.4
1
arturisimo/server-urjc:v1.0d8dc4430531e
follow-redirects@1.14.9
1.15.4
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
follow-redirects@1.14.5
1.15.4
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
follow-redirects@1.13.0
1.15.4
1
assistiot/fl_orchestrator:api-latest7473d77448e1
follow-redirects@1.5.10
1.15.4
1
assistiot/multi-link_client:latestcf048365d042
follow-redirects@1.15.2
1.15.4
1
assistiot/open_api_frontend:1.0.1f11d82defc70
follow-redirects@1.14.9
1.15.4
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
follow-redirects@1.15.0
1.15.4
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
follow-redirects@1.15.0
1.15.4
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
follow-redirects@1.15.0
1.15.4
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
follow-redirects@1.15.2
1.15.4
1
blockscout/blockscout:5.1.5c365a8f2dc12
follow-redirects@1.14.8
1.15.4
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
follow-redirects@1.14.3
1.15.4
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
follow-redirects@1.14.4
1.15.4
1
catalysm/csmm:latestf003b35f54d9
follow-redirects@1.14.5
1.15.4
1
ccjacobs14/amazon:59a9b14a6f09e
follow-redirects@1.15.2
1.15.4
1
chatwoot/chatwoot:v4.15.167ebc751c171
follow-redirects@1.14.0
1.15.4
1
codercom/code-server:4.11.0-debian1e2cc688008e
follow-redirects@1.14.8
1.15.4
1
codercom/code-server:3.10.247605610ad8d
follow-redirects@1.13.0
1.15.4
1
coldatom/containers-security-front:latest7c2fbbb41bcf
follow-redirects@1.15.2
1.15.4
1
conduction/conduction-ui-app:devd591f5e6f2a9
follow-redirects@1.13.2
1.15.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.