StackRadar

CVE-2024-43800

Medium

Advisory

Published 10 Sept 2024In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.0
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
354
of 17,781 indexed, latest versions
Container images
355
deployed by those charts
Fix available
1 of 1
affected package

serve-static vulnerable to template injection that can lead to XSS

Carried by container images the latest versions of 354 of 17,781 indexed charts deploy, on 355 images.

Affected packageAffected versionsFixed inImages
serve-staticnpm1.10.0, 1.10.2, 1.10.3, 1.12.2+6 more1.16.0355
OSV records
GHSA-cm22-4g7w-348p

Charts affected

354 by stars
ChartLatestAffected imagesRadar Score
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
serve-static@1.15.0
1.16.0

Open the chart page →

4,455
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
serve-static@1.15.0
1.16.0

Open the chart page →

3,071
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
serve-static@1.10.3
1.16.0

Open the chart page →

4,069
audiobookshelfcharts-derwitt-devVerified publisher1.1.01 of 1See more

audiobookshelf charts-derwitt-dev 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
serve-static@1.15.0
1.16.0

Open the chart page →

1,722
ddb-proxycharts-derwitt-devVerified publisher1.3.01 of 1See more

ddb-proxy charts-derwitt-dev 1.3.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
ghcr.io/mrprimate/ddb-proxy:0.0.258dc2d7fb460f
serve-static@1.15.0
1.16.0

Open the chart page →

812
servicechart-serviceVerified publisher0.0.41 of 1See more

service chart-service 0.0.4

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
punkerside/noroot:v0.0.7be20c81d6ca1
serve-static@1.15.0
1.16.0

Open the chart page →

930
audiobookshelfchristianhuthVerified publisher2.4.01 of 1See more

audiobookshelf christianhuth 2.4.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
serve-static@1.15.0
1.16.0

Open the chart page →

1,722
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
serve-static@1.15.0
1.16.0
countly/frontend:25.05.42acbc11499b6
serve-static@1.15.0
1.16.0

Open the chart page →

7,295
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
serve-static@1.13.1
1.16.0

Open the chart page →

27,417
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
serve-static@1.13.2
1.16.0

Open the chart page →

2,580
node-redcloudnativeapp1.2.21 of 1See more

node-red cloudnativeapp 1.2.2

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
nodered/node-red-docker:0.19.6-v8070643219ea2
serve-static@1.13.2
1.16.0

Open the chart page →

4,790
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
serve-static@1.13.2
1.16.0

Open the chart page →

25,456
robot-shopcloud-native-toolkit1.1.13 of 12See more

robot-shop cloud-native-toolkit 1.1.1

3 of the 12 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
robotshop/rs-cart:latest388349d5cb3c
serve-static@1.14.1
1.16.0
robotshop/rs-catalogue:latestd545747c1b97
serve-static@1.14.1
1.16.0
robotshop/rs-user:latestea509182c180
serve-static@1.14.1
1.16.0

Open the chart page →

29,555
slack-notificationscloud-native-toolkit0.1.71 of 1See more

slack-notifications cloud-native-toolkit 0.1.7

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/slack-notifications:latest041df93e2bac
serve-static@1.14.1
1.16.0

Open the chart page →

1,545
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
serve-static@1.15.0
1.16.0

Open the chart page →

3,868
maildevcnieg1.1.11 of 1See more

maildev cnieg 1.1.1

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
cnieg/maildev:v1.1.998ee05668915
serve-static@1.14.1
1.16.0

Open the chart page →

2,449
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
serve-static@1.15.0
1.16.0

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
serve-static@1.15.0
1.16.0

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
serve-static@1.15.0
1.16.0

Open the chart page →

5,141
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
serve-static@1.14.1
1.16.0

Open the chart page →

12,907
containers-security-chartscontainers-security0.1.02 of 7See more

containers-security-charts containers-security 0.1.0

2 of the 7 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
coldatom/containers-security-api:latesteae9e82da080
serve-static@1.15.0
1.16.0
coldatom/containers-security-front:latest7c2fbbb41bcf
serve-static@1.15.0
1.16.0

Open the chart page →

9,146
conversor-temperaturaconversor-temperaturaVerified publisher0.1.01 of 1See more

conversor-temperatura conversor-temperatura 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
felipecs8/conversor-temperatura:v1f945423be36d
serve-static@1.15.0
1.16.0

Open the chart page →

1,527
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
serve-static@1.15.0
1.16.0

Open the chart page →

5,488
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
serve-static@1.10.2
1.16.0

Open the chart page →

5,209
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
serve-static@1.15.0
1.16.0

Open the chart page →

3,769
myawesomeappcuriousgeekshelmfirstapp0.1.21 of 1See more

myawesomeapp curiousgeekshelmfirstapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
srini78/nodejswebappeks:latest5d1cbdc6833a
serve-static@1.15.0
1.16.0

Open the chart page →

1,267
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
defactops/defactops-backend:1.0.2307b663c0092a
serve-static@1.15.0
1.16.0

Open the chart page →

4,509
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
serve-static@1.14.1
1.16.0

Open the chart page →

27,550
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
serve-static@1.15.0
1.16.0

Open the chart page →

4,551
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
serve-static@1.15.0
1.16.0

Open the chart page →

4,217
mergeabledoubanVerified publisher0.2.21 of 1See more

mergeable douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
ghcr.io/leoquote/mergeable:latest451706815103
serve-static@1.14.1
1.16.0

Open the chart page →

4,223
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
serve-static@1.14.1
1.16.0

Open the chart page →

24,656
backend-charteks-3-tier-app-chart0.1.01 of 1See more

backend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
arfath29/3-tier-app-backend:latestee0750b18406
serve-static@1.14.1
1.16.0

Open the chart page →

1,693
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
serve-static@1.14.1
1.16.0

Open the chart page →

3,744
reddarkemmas-chartsVerified publisher0.0.21 of 1See more

reddark emmas-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
ghcr.io/0xemma/reddark:main2a115e991894
serve-static@1.15.0
1.16.0

Open the chart page →

1,998
eolicplantseolicplantsVerified publisher0.1.01 of 7See more

eolicplants eolicplants 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
serve-static@1.14.1
1.16.0

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.01 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
serve-static@1.14.1
1.16.0

Open the chart page →

27,256
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
serve-static@1.14.2
1.16.0

Open the chart page →

27,096
ethstatsethereum-helm-chartsVerified publisher0.1.41 of 1See more

ethstats ethereum-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
skylenet/ethstats-server:pow-latestd757cc016198
serve-static@1.15.0
1.16.0

Open the chart page →

1,109
testnet-faucetethereum-helm-chartsVerified publisher0.1.31 of 1See more

testnet-faucet ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
parithoshj/testnet-faucet:9859e0dcdca426fea6d
serve-static@1.13.2
1.16.0

Open the chart page →

3,005
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
serve-static@1.14.1
1.16.0

Open the chart page →

3,260
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
serve-static@1.15.0
1.16.0

Open the chart page →

3,320
my-chartexpress-server0.1.01 of 1See more

my-chart express-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
tawfiq58/express-server:latestc707555f6853
serve-static@1.15.0
1.16.0

Open the chart page →

1,113
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
serve-static@1.15.0
1.16.0

Open the chart page →

3,311
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
serve-static@1.15.0
1.16.0

Open the chart page →

64,489
iotagent-jsonfiware0.1.21 of 1See more

iotagent-json fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
fiware/iotagent-json:3.1.0879b21a0d36d
serve-static@1.15.0
1.16.0

Open the chart page →

937
iotagent-ulfiware0.1.21 of 1See more

iotagent-ul fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
fiware/iotagent-ul:1.14.0fe11f55a926d
serve-static@1.13.2
1.16.0

Open the chart page →

3,337
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
serve-static@1.15.0
1.16.0

Open the chart page →

3,159
flamegabe565Verified publisher0.6.01 of 1See more

flame gabe565 0.6.0

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
pawelmalak/flame:multiarch2.3.19f88b17692a0
serve-static@1.15.0
1.16.0

Open the chart page →

2,172
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2024-43800.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
serve-static@1.15.0
1.16.0

Open the chart page →

13,241

Container images carrying it

355 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ethersphere/bzz-token-service:latest7624f11a72ad
serve-static@1.14.1
1.16.0
1
ethersphere/onboarding-faucet:0.3.0513154aab230
serve-static@1.15.0
1.16.0
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
serve-static@1.15.0
1.16.0
1
felipecs8/conversor-temperatura:v1f945423be36d
serve-static@1.15.0
1.16.0
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
serve-static@1.15.0
1.16.0
1
fiware/idm:8.3.3a1b6ed4ae84f
serve-static@1.15.0
1.16.0
1
fiware/iotagent-json:3.1.0879b21a0d36d
serve-static@1.15.0
1.16.0
1
fiware/iotagent-ul:1.14.0fe11f55a926d
serve-static@1.13.2
1.16.0
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
serve-static@1.13.2
1.16.0
1
frappe/frappe-socketio:v13.4.12095767a9e82
serve-static@1.14.1
1.16.0
1
getferdi/ferdi-server:1.3.26e620b85afaa
serve-static@1.14.1
1.16.0
1
glenndehaan/api-mapper:latest6ff6310683bf
serve-static@1.15.0
1.16.0
1
glenndehaan/contentbridge:latest99b9e4f73848
serve-static@1.15.0
1.16.0
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
serve-static@1.14.1
1.16.0
1
gristlabs/grist:0.7.96e71b1914a7e
serve-static@1.13.2
1.16.0
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
serve-static@1.14.1
1.16.0
1
halkeye/hubot:latest9764d2202130
serve-static@1.14.1
1.16.0
1
hamid2021/nodejs-dockercli:latest429d99890c3c
serve-static@1.15.0
1.16.0
1
hansehe/graphql-gateway:1.0.458e09540afbc
serve-static@1.14.1
1.16.0
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
serve-static@1.15.0
1.16.0
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
serve-static@1.15.0
1.16.0
1
henrywhitaker3/speedtest-tracker:latest47159a940229
serve-static@1.14.1
1.16.0
1
heywood8/redisinsight:2.28.00bc9ab313d37
serve-static@1.15.0
1.16.0
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
serve-static@1.14.1
1.16.0
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
serve-static@1.14.2
1.16.0
1
hugohg34/server:0.0.2503e5d8960ff
serve-static@1.14.2
1.16.0
1
i4trust/pdc-portal:2.0.03e77858e1219
serve-static@1.14.1
1.16.0
1
ianw/quickchart:v1.7.1dc49dd460c37
serve-static@1.15.0
1.16.0
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
serve-static@1.15.0
1.16.0
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
serve-static@1.14.1
1.16.0
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
serve-static@1.13.2
1.16.0
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
serve-static@1.13.2
1.16.0
1
ibmcom/microclimate-portal:latested5505e5c7ec
serve-static@1.12.2
1.16.0
1
ibmcom/microclimate-theia:lateste17bdccc5030
serve-static@1.13.2
1.16.0
1
inseefrlab/shelly:cloudshell31f04ca7436b
serve-static@1.14.1
1.16.0
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
serve-static@1.14.1
1.16.0
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
serve-static@1.15.0
1.16.0
1
jakowenko/double-take:1.6.0b858bac9e32a
serve-static@1.14.1
1.16.0
1
jayfong/yapi:1.10.2163e5d621910
serve-static@1.10.3
1.16.0
1
joplin/server:3.0-beta52af57880c0e
serve-static@1.15.0
1.16.0
1
joplin/server:2.14.2-betab87564ef34e9
serve-static@1.15.0
1.16.0
1
josepht05/nodejs-feb24:latest36cb0c618c94
serve-static@1.15.0
1.16.0
1
josepht05/titajo-docker:v1.0.0d94024965d78
serve-static@1.15.0
1.16.0
1
junktext/getting-started:1.0.5a70936c04aed
serve-static@1.14.1
1.16.0
1
junktext/getting-started:1.0.34d44adf5a4da2
serve-static@1.14.1
1.16.0
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
serve-static@1.15.0
1.16.0
1
keyoxide/keyoxide:stable96f27a71269d
serve-static@1.14.2
1.16.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
serve-static@1.14.2
1.16.0
1
konradkleine/docker-registry-frontend:v2181aad54ee64
serve-static@1.10.3
1.16.0
1
koumoul/capture:17108d47be3b2
serve-static@1.13.2
1.16.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.