StackRadar

CVE-2024-29041

Medium

Advisory

Published 25 Mar 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.008
54th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
318
of 17,781 indexed, latest versions
Container images
316
deployed by those charts
Fix available
1 of 1
affected package

Express.js Open Redirect in malformed URLs

Carried by container images the latest versions of 318 of 17,781 indexed charts deploy, on 316 images.

Affected packageAffected versionsFixed inImages
expressnpm3.4.0, 4.13.3, 4.13.4, 4.15.3+9 more4.19.2, 5.0.0-beta.3316
OSV records
GHSA-rv95-896h-c2vc

Charts affected

318 by stars
ChartLatestAffected imagesRadar Score
hubothalkeye0.0.11 of 1See more

hubot halkeye 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
halkeye/hubot:latest9764d2202130
express@4.17.1
4.19.2

Open the chart page →

2,116
matrix-appservice-gitterhalkeye0.1.01 of 1See more

matrix-appservice-gitter halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
express@4.17.1
4.19.2

Open the chart page →

3,003
theloungehalkeye4.3.11 of 1See more

thelounge halkeye 4.3.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
thelounge/thelounge:4.3.0-alpine0037aa258261
express@4.17.1
4.19.2

Open the chart page →

1,938
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
express@4.16.4
4.19.2

Open the chart page →

24,161
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
express@4.17.1
4.19.2
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
express@4.17.1
4.19.2
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
express@4.17.1
4.19.2
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
express@4.17.1
4.19.2

Open the chart page →

89,959
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
express@4.18.1
4.19.2

Open the chart page →

948
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
express@4.17.1
4.19.2

Open the chart page →

8,213
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
express@4.17.3
4.19.2

Open the chart page →

5,769
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
express@4.17.1
4.19.2

Open the chart page →

4,253
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
express@4.18.2
4.19.2

Open the chart page →

3,407
crypto-watchdoghuseyinnurbaki0.1.01 of 1See more

crypto-watchdog huseyinnurbaki 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
hhaluk/crypto-watchdog:0.4.0a6555953d941
express@4.17.1
4.19.2

Open the chart page →

2,656
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
express@4.17.1
4.19.2

Open the chart page →

32,915
ibm-business-automation-insights-devibm-charts3.2.01 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

1 of the 6 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
express@4.16.3
4.19.2

Open the chart page →

39,349
ibm-microclimateibm-charts0.1.03 of 8See more

ibm-microclimate ibm-charts 0.1.0

3 of the 8 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
express@4.16.3
4.19.2
ibmcom/microclimate-portal:latested5505e5c7ec
express@4.16.3
4.19.2
ibmcom/microclimate-theia:lateste17bdccc5030
express@4.16.3
4.19.2

Open the chart page →

57,669
erpnextimprowisedVerified publisher3.3.01 of 3See more

erpnext improwised 3.3.0

1 of the 3 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
frappe/frappe-socketio:v13.4.12095767a9e82
express@4.17.1
4.19.2

Open the chart page →

6,501
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
express@4.17.1
4.19.2

Open the chart page →

4,944
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
express@4.17.1
4.19.2

Open the chart page →

10,494
interbtc-hydrainterlay0.1.153 of 4See more

interbtc-hydra interlay 0.1.15

3 of the 4 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
express@4.17.1
4.19.2
subsquid/hydra-indexer:5.0.0-alpha.37a7f8b9bad7ee
express@4.18.1
4.19.2
subsquid/hydra-indexer-status-service:5.0.0-alpha.37a4136013909c
express@4.18.1
4.19.2

Open the chart page →

6,831
interlay-firesquidinterlay0.1.112 of 4See more

interlay-firesquid interlay 0.1.11

2 of the 4 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
express@4.18.1
4.19.2
subsquid/substrate-explorer:firesquid0889a857f192
express@4.18.2
4.19.2

Open the chart page →

4,667
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
express@4.17.1
4.19.2

Open the chart page →

7,232
keyoxide-webittrident-oss0.2.31 of 1See more

keyoxide-web ittrident-oss 0.2.3

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
keyoxide/keyoxide:stable96f27a71269d
express@4.17.3
4.19.2

Open the chart page →

2,363
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
express@4.13.4
4.19.2

Open the chart page →

6,454
annotation-tooljtektVerified publisher0.1.51 of 2See more

annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
express@4.17.1
4.19.2

Open the chart page →

2,315
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
express@4.18.2
4.19.2

Open the chart page →

22,589
polygonal-annotation-tooljtektVerified publisher0.1.51 of 2See more

polygonal-annotation-tool jtekt 0.1.5

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
moreillon/api-proxy:a3e8b41e9e578c9653b6
express@4.17.1
4.19.2

Open the chart page →

2,231
shinsei-managerjtektVerified publisher0.2.02 of 8See more

shinsei-manager jtekt 0.2.0

2 of the 8 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
express@4.18.2
4.19.2
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
express@4.18.2
4.19.2

Open the chart page →

63,461
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
express@4.18.2
4.19.2

Open the chart page →

16,600
todo-appjunktext-via-aws1.2.101 of 1See more

todo-app junktext-via-aws 1.2.10

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.34d44adf5a4da2
express@4.17.1
4.19.2

Open the chart page →

1,579
k10appk10app0.2.13 of 11See more

k10app k10app 0.2.1

3 of the 11 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/k10app/basicuserservice:latest2ee057ad3bef
express@4.18.2
4.19.2
ghcr.io/k10app/catalog:latest639c980be0f1
express@4.18.2
4.19.2
ghcr.io/k10app/order:lateste1017d0dbd78
express@4.18.2
4.19.2

Open the chart page →

10,546
audiobookshelfk8s-home-lab-repo2.0.11 of 1See more

audiobookshelf k8s-home-lab-repo 2.0.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
express@4.18.2
4.19.2

Open the chart page →

2,350
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
express@4.17.1
4.19.2

Open the chart page →

4,667
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
express@4.18.2
4.19.2

Open the chart page →

9,783
allurekfirfer0.1.81 of 2See more

allure kfirfer 0.1.8

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service-ui:7.0.34ebd8b4ef340
express@4.17.1
4.19.2

Open the chart page →

12,527
skoonerkfirfer0.0.61 of 1See more

skooner kfirfer 0.0.6

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
express@4.18.2
4.19.2

Open the chart page →

1,341
rtlkronkltdVerified publisher0.1.01 of 2See more

rtl kronkltd 0.1.0

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.11.0d0cd3d868aca
express@4.17.1
4.19.2

Open the chart page →

5,604
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
express@4.17.1
4.19.2

Open the chart page →

3,397
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
express@4.17.2
4.19.2

Open the chart page →

4,230
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
express@4.17.3
4.19.2

Open the chart page →

5,410
component-storekubebb0.0.231 of 1See more

component-store kubebb 0.0.23

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
kubebb/component-store:latestfd8ecbd73213
express@4.18.2
4.19.2

Open the chart page →

2,178
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
kubebb/bff-server:v0.2.0-202312040fbb732379bc
express@4.18.1
4.19.2

Open the chart page →

13,819
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
express@4.17.1
4.19.2

Open the chart page →

1,927
workload-operatorkubevious0.0.31 of 1See more

workload-operator kubevious 0.0.3

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
kubevious/workload-operator:1.0.20b0f4c507eb6
express@4.18.2
4.19.2

Open the chart page →

2,008
weather-app-chartlocal-weatherapp0.1.01 of 4See more

weather-app-chart local-weatherapp 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
youssef11gaber10/deployment-ui-react:latestba6853e35c60
express@4.17.1
4.19.2

Open the chart page →

5,905
devspace-cloudloftVerified publisher0.3.31 of 8See more

devspace-cloud loft 0.3.3

1 of the 8 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
devspacecloud/ui:0.3.3deef55ff29a7
express@4.17.1
4.19.2

Open the chart page →

9,880
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
express@4.17.1
4.19.2

Open the chart page →

3,651
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
express@4.18.2
4.19.2

Open the chart page →

9,774
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
express@4.17.1
4.19.2

Open the chart page →

5,287
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
express@4.17.1
4.19.2

Open the chart page →

5,940
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
express@4.17.3
4.19.2

Open the chart page →

29,588
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2024-29041.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
express@4.17.1
4.19.2

Open the chart page →

68,284

Container images carrying it

316 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
kodekloud/examplevotingapp_result:v1e510023fdf38
express@4.18.2
4.19.2
4
oscarsotosanchez/server:v1.06e2e1279126b
express@4.17.1
4.19.2
4
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
express@4.18.2
4.19.2
4
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
express@4.18.2
4.19.2
4
assistiot/dlt_api:2.0.0e36a8922fa0c
express@4.18.2
4.19.2
3
frankescobar/allure-docker-service-ui:7.0.3:latest4ebd8b4ef340
express@4.17.1
4.19.2
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
express@4.17.1
4.19.2
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
express@4.18.2
4.19.2
3
agoldis/sorry-cypress-api:2.5.11afaa5a84051d
express@4.18.1
4.19.2
2
agoldis/sorry-cypress-director:2.5.1110228ecd353b
express@4.18.1
4.19.2
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
express@4.17.1
4.19.2
2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
express@4.17.1
4.19.2
2
governify/assets-manager:v1.4.12987672448c7
express@4.17.1
4.19.2
2
governify/director:v1.4.0608c6940bb98
express@4.17.1
4.19.2
2
governify/registry:v3.4.0d3f37f4f8168
express@4.17.1
4.19.2
2
governify/render:v2.2.0daeca1ce28e6
express@4.17.1
4.19.2
2
governify/reporter:v2.2.038595913458f
express@4.17.1
4.19.2
2
gradiant/open5gs-webui:2.7.5fbd10c017541
express@4.18.2
4.19.2
2
hookiesolutions/webhookie:latest0629694246ba
express@4.17.1
4.19.2
2
htmlprogrammer2001/simple-db-app:1.0a7e0a233a9bc
express@4.17.2
4.19.2
2
krtk6160/galoy-nostrcc82a694f818
express@4.18.2
4.19.2
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
express@4.18.2
4.19.2
2
library/mongo-express:1.0.2:latest1b23d7976f02
express@4.18.2
4.19.2
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
express@4.17.1
4.19.2
2
mesosphere/kommander:6.100.13917e82333a9
express@4.17.1
4.19.2
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
express@4.17.1
4.19.2
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
express@4.17.1
4.19.2
2
mojaloop/reporting:v12.1.0d480a62103d6
express@3.4.0
4.19.2
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
express@4.18.2
4.19.2
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
express@4.18.2
4.19.2
2
moreillon/api-proxy:a3e8b41e9e578c9653b6
express@4.17.1
4.19.2
2
moreillon/group-manager:v4.9.0d5a0ec8394c0
express@4.18.2
4.19.2
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
express@4.18.2
4.19.2
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
express@4.18.2
4.19.2
2
requarks/wiki:2:latest68f0d1848261
express@4.18.2
4.19.2
2
shahanafarooqui/rtl:0.13.3e2195188a451
express@4.18.2
4.19.2
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
express@4.17.3
4.19.2
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
express@4.17.1
4.19.2
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
express@4.18.2
4.19.2
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
express@4.18.1
4.19.2
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
express@4.18.1
4.19.2
2
0hlov3/semaphore:v1.0.050f874ec096b
express@4.18.2
4.19.2
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
express@4.18.3
4.19.2
1
anoopnair/lifecycle-jira-integration:latestd80c73a6089d
express@4.17.3
4.19.2
1
apimap/developer:v1.3.1406d3858e20c
express@4.18.1
4.19.2
1
apimap/portal:v2.4.0041a4790c65c
express@4.18.1
4.19.2
1
arfath29/3-tier-app-backend:latestee0750b18406
express@4.17.1
4.19.2
1
arfath29/3-tier-app-frontend:latest384b3e377f47
express@4.17.1
4.19.2
1
arturisimo/server-urjc:v1.0d8dc4430531e
express@4.17.3
4.19.2
1
assistiot/dlt_api:2.1.0c8a170683be7
express@4.18.2
4.19.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.