StackRadar

CVE-2024-29041

Medium

Advisory

Published 25 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
318
of 17,781 indexed, latest versions
Container images
316
deployed by those charts
Fix available
1 of 1
affected package

Express.js Open Redirect in malformed URLs

Carried by container images the latest versions of 318 of 17,781 indexed charts deploy, on 316 images.

Affected packageAffected versionsFixed inImages
expressnpm3.4.0, 4.13.3, 4.13.4, 4.15.3+9 more4.19.2, 5.0.0-beta.3316
OSV records
GHSA-rv95-896h-c2vc

Charts affected

318 by stars
ChartLatestAffected imagesRadar Score
hubothalkeye0.0.11 of 1See more

hubot halkeye 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
halkeye/hubot:latest9764d2202130
express@4.17.1
4.19.2

Open the chart page →

2,116
matrix-appservice-gitterhalkeye0.1.01 of 1See more

matrix-appservice-gitter halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
express@4.17.1
4.19.2

Open the chart page →

3,003
theloungehalkeye4.3.11 of 1See more

thelounge halkeye 4.3.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
thelounge/thelounge:4.3.0-alpine0037aa258261
express@4.17.1
4.19.2

Open the chart page →

1,938
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
express@4.16.4
4.19.2

Open the chart page →

24,161
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
express@4.17.1
4.19.2
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
express@4.17.1
4.19.2
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
express@4.17.1
4.19.2
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
express@4.17.1
4.19.2

Open the chart page →

89,959
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
express@4.18.1
4.19.2

Open the chart page →

948
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
express@4.17.1
4.19.2

Open the chart page →

8,213
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
express@4.17.3
4.19.2

Open the chart page →

5,769
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
express@4.17.1
4.19.2

Open the chart page →

4,253
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
express@4.18.2
4.19.2

Open the chart page →

3,407
crypto-watchdoghuseyinnurbaki0.1.01 of 1See more

crypto-watchdog huseyinnurbaki 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
hhaluk/crypto-watchdog:0.4.0a6555953d941
express@4.17.1
4.19.2

Open the chart page →

2,656
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
express@4.17.1
4.19.2

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
express@4.16.3
4.19.2

Open the chart page →

39,349
ibm-microclimateibm-charts0.1.03 of 8See more

ibm-microclimate ibm-charts 0.1.0

3 of the 8 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
express@4.16.3
4.19.2
ibmcom/microclimate-portal:latested5505e5c7ec
express@4.16.3
4.19.2
ibmcom/microclimate-theia:lateste17bdccc5030
express@4.16.3
4.19.2

Open the chart page →

57,669
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
frappe/frappe-socketio:v13.4.12095767a9e82
express@4.17.1
4.19.2

Open the chart page →

6,501
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
express@4.17.1
4.19.2

Open the chart page →

4,944
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
express@4.17.1
4.19.2

Open the chart page →

10,494
interbtc-hydrainterlay0.1.153 of 4See more

interbtc-hydra interlay 0.1.15

3 of the 4 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
express@4.17.1
4.19.2
subsquid/hydra-indexer:5.0.0-alpha.37a7f8b9bad7ee
express@4.18.1
4.19.2
subsquid/hydra-indexer-status-service:5.0.0-alpha.37a4136013909c
express@4.18.1
4.19.2

Open the chart page →

6,831
interlay-firesquidinterlay0.1.112 of 4See more

interlay-firesquid interlay 0.1.11

2 of the 4 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
express@4.18.1
4.19.2
subsquid/substrate-explorer:firesquid0889a857f192
express@4.18.2
4.19.2

Open the chart page →

4,667
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
express@4.17.1
4.19.2

Open the chart page →

7,232
keyoxide-webittrident-oss0.2.31 of 1See more

keyoxide-web ittrident-oss 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
keyoxide/keyoxide:stable96f27a71269d
express@4.17.3
4.19.2

Open the chart page →

2,363
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
express@4.13.4
4.19.2

Open the chart page →

6,454
annotation-tooljtektVerified publisher0.1.51 of 2See more

annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
express@4.17.1
4.19.2

Open the chart page →

2,315
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
express@4.18.2
4.19.2

Open the chart page →

22,589
polygonal-annotation-tooljtektVerified publisher0.1.51 of 2See more

polygonal-annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
express@4.17.1
4.19.2

Open the chart page →

2,231
shinsei-managerjtektVerified publisher0.2.02 of 8See more

shinsei-manager jtekt 0.2.0

2 of the 8 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
express@4.18.2
4.19.2
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
express@4.18.2
4.19.2

Open the chart page →

63,461
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
express@4.18.2
4.19.2

Open the chart page →

16,600
todo-appjunktext-via-aws1.2.101 of 1See more

todo-app junktext-via-aws 1.2.10

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.34d44adf5a4da2
express@4.17.1
4.19.2

Open the chart page →

1,579
k10appk10app0.2.13 of 11See more

k10app k10app 0.2.1

3 of the 11 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/k10app/basicuserservice:latest2ee057ad3bef
express@4.18.2
4.19.2
ghcr.io/k10app/catalog:latest639c980be0f1
express@4.18.2
4.19.2
ghcr.io/k10app/order:lateste1017d0dbd78
express@4.18.2
4.19.2

Open the chart page →

10,546
audiobookshelfk8s-home-lab-repo2.0.11 of 1See more

audiobookshelf k8s-home-lab-repo 2.0.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
express@4.18.2
4.19.2

Open the chart page →

2,350
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
express@4.17.1
4.19.2

Open the chart page →

4,667
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
express@4.18.2
4.19.2

Open the chart page →

9,783
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service-ui:7.0.34ebd8b4ef340
express@4.17.1
4.19.2

Open the chart page →

12,527
skoonerkfirfer0.0.61 of 1See more

skooner kfirfer 0.0.6

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
express@4.18.2
4.19.2

Open the chart page →

1,341
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.11.0d0cd3d868aca
express@4.17.1
4.19.2

Open the chart page →

5,604
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
express@4.17.1
4.19.2

Open the chart page →

3,397
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
express@4.17.2
4.19.2

Open the chart page →

4,230
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
express@4.17.3
4.19.2

Open the chart page →

5,410
component-storekubebb0.0.231 of 1See more

component-store kubebb 0.0.23

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
kubebb/component-store:latestfd8ecbd73213
express@4.18.2
4.19.2

Open the chart page →

2,178
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
kubebb/bff-server:v0.2.0-202312040fbb732379bc
express@4.18.1
4.19.2

Open the chart page →

13,819
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
express@4.17.1
4.19.2

Open the chart page →

1,927
workload-operatorkubevious0.0.31 of 1See more

workload-operator kubevious 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
kubevious/workload-operator:1.0.20b0f4c507eb6
express@4.18.2
4.19.2

Open the chart page →

2,008
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-ui-react:latestba6853e35c60
express@4.17.1
4.19.2

Open the chart page →

5,905
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
devspacecloud/ui:0.3.3deef55ff29a7
express@4.17.1
4.19.2

Open the chart page →

9,880
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
express@4.17.1
4.19.2

Open the chart page →

3,651
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
express@4.18.2
4.19.2

Open the chart page →

9,774
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
express@4.17.1
4.19.2

Open the chart page →

5,287
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
express@4.17.1
4.19.2

Open the chart page →

5,940
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
express@4.17.3
4.19.2

Open the chart page →

29,588
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
express@4.17.1
4.19.2

Open the chart page →

68,284

Container images carrying it

316 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
glenndehaan/api-mapper:latest6ff6310683bf
express@4.18.2
4.19.2
1
glenndehaan/contentbridge:latest99b9e4f73848
express@4.18.2
4.19.2
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
express@4.17.1
4.19.2
1
gristlabs/grist:0.7.96e71b1914a7e
express@4.16.4
4.19.2
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
express@4.17.1
4.19.2
1
halkeye/hubot:latest9764d2202130
express@4.17.1
4.19.2
1
hamid2021/nodejs-dockercli:latest429d99890c3c
express@4.18.2
4.19.2
1
hansehe/graphql-gateway:1.0.458e09540afbc
express@4.17.1
4.19.2
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
express@4.18.2
4.19.2
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
express@4.18.2
4.19.2
1
henrywhitaker3/speedtest-tracker:latest47159a940229
express@4.17.1
4.19.2
1
heywood8/redisinsight:2.28.00bc9ab313d37
express@4.18.2
4.19.2
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
express@4.17.1
4.19.2
1
hugohg34/server:0.0.2503e5d8960ff
express@4.17.3
4.19.2
1
i4trust/pdc-portal:2.0.03e77858e1219
express@4.17.1
4.19.2
1
ianw/quickchart:v1.7.1dc49dd460c37
express@4.18.2
4.19.2
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
express@4.18.1
4.19.2
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
express@4.17.1
4.19.2
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
express@4.16.3
4.19.2
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
express@4.16.3
4.19.2
1
ibmcom/microclimate-portal:latested5505e5c7ec
express@4.16.3
4.19.2
1
ibmcom/microclimate-theia:lateste17bdccc5030
express@4.16.3
4.19.2
1
inseefrlab/shelly:cloudshell31f04ca7436b
express@4.17.1
4.19.2
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
express@4.17.1
4.19.2
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
express@4.18.1
4.19.2
1
jakowenko/double-take:1.6.0b858bac9e32a
express@4.17.1
4.19.2
1
jayfong/yapi:1.10.2163e5d621910
express@4.13.4
4.19.2
1
joplin/server:3.0-beta52af57880c0e
express@4.18.2
4.19.2
1
joplin/server:2.14.2-betab87564ef34e9
express@4.18.2
4.19.2
1
josepht05/titajo-docker:v1.0.0d94024965d78
express@4.18.2
4.19.2
1
junktext/getting-started:1.0.5a70936c04aed
express@4.17.1
4.19.2
1
junktext/getting-started:1.0.34d44adf5a4da2
express@4.17.1
4.19.2
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
express@4.18.1
4.19.2
1
keyoxide/keyoxide:stable96f27a71269d
express@4.17.3
4.19.2
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
express@4.17.3
4.19.2
1
koumoul/capture:17108d47be3b2
express@4.16.4
4.19.2
1
koumoul/openapi-viewer:18eeca2e8285b
express@4.16.3
4.19.2
1
ktitilayo2/nodejswebapp:latest8bac28058688
express@4.18.2
4.19.2
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
express@4.18.1
4.19.2
1
kubebb/component-store:latestfd8ecbd73213
express@4.18.2
4.19.2
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
express@4.17.1
4.19.2
1
kubevious/backend:1.2.22d9ba6eb46b6
express@4.18.2
4.19.2
1
kubevious/collector:1.2.1f58226f9d84e
express@4.18.2
4.19.2
1
kubevious/guard:1.2.19bf567704de2
express@4.17.3
4.19.2
1
kubevious/parser:1.0.151acf1a1f0b47
express@4.17.1
4.19.2
1
kubevious/parser:1.2.299ae7a5168c2
express@4.18.2
4.19.2
1
kubevious/workload-operator:1.0.20b0f4c507eb6
express@4.18.2
4.19.2
1
kyleslugg/klusterview:latestba8c36dfdfbd
express@4.18.2
4.19.2
1
laly9999/node-app-dockerized:latest75ae77a20c6c
express@4.18.2
4.19.2
1
lavandadelpatio/frontend:latest501c3f31e0bc
express@4.17.1
4.19.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.