StackRadar

CVE-2024-46982

High

Advisory

Published 17 Sept 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.592
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
15
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 1
affected package

Next.js Cache Poisoning

Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
nextnpm13.5.2, 13.5.3, 13.5.6, 14.1.0+8 more13.5.7, 14.2.1015
OSV records
GHSA-gp8f-8m3g-qvj9

Charts affected

15 by stars
ChartLatestAffected imagesRadar Score
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
langgenius/dify-web:0.6.11a2a294743634
next@14.1.0
14.2.10

Open the chart page →

20,403
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
next@14.1.3
14.2.10

Open the chart page →

31,844
kyoorubxkubeVerified publisher0.1.101 of 9See more

kyoo rubxkube 0.1.10

1 of the 9 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
next@14.2.5
14.2.10

Open the chart page →

30,234
katalogalpineworks0.1.21 of 5See more

katalog alpineworks 0.1.2

1 of the 5 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
next@14.1.4
14.2.10

Open the chart page →

4,497
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
next@14.1.1
14.2.10

Open the chart page →

1,977
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
next@14.2.6
14.2.10

Open the chart page →

2,862
dashboardedu1.0.01 of 1See more

dashboard edu 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
next@14.2.3
14.2.10

Open the chart page →

1,344
mandefactlyVerified publisher0.5.161 of 3See more

mande factly 0.5.16

1 of the 3 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
factly/mande-web:0.34.1742355964b0e
next@13.5.3
13.5.7

Open the chart page →

4,777
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
next@14.2.2
14.2.10

Open the chart page →

4,650
opentelemetry-demogpg-dev0.33.82 of 27See more

opentelemetry-demo gpg-dev 0.33.8

2 of the 27 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
next@14.2.5
14.2.10
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
next@14.2.5
14.2.10

Open the chart page →

49,025
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
next@13.5.2
13.5.7

Open the chart page →

2,685
dashboardleechistest1.0.01 of 1See more

dashboard leechistest 1.0.0

1 of the 1 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
next@14.2.3
14.2.10

Open the chart page →

1,344
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
next@13.5.6
13.5.7

Open the chart page →

4,647
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit:1.24.02434560e8f0e
next@14.2.4
14.2.10

Open the chart page →

5,017
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2024-46982.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
next@13.5.3
13.5.7

Open the chart page →

2,969

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
sysnet4admin/dashboard:bluec5bd3bb1b5a6
next@14.2.3
14.2.10
2
documenso/documenso:v1.8.17f16a9449f18
next@14.2.6
14.2.10
1
factly/mande-web:0.34.1742355964b0e
next@13.5.3
13.5.7
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
next@14.2.2
14.2.10
1
kyso/kyso-front:lateste52595c5c16f
next@13.5.2
13.5.7
1
langgenius/dify-web:0.6.11a2a294743634
next@14.1.0
14.2.10
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
next@13.5.3
13.5.7
1
treskon/portrait-ui:DEV-lateste7970783bc8d
next@14.1.3
14.2.10
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
next@14.1.1
14.2.10
1
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
next@14.1.4
14.2.10
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
next@13.5.6
13.5.7
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
next@14.2.4
14.2.10
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
next@14.2.5
14.2.10
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
next@14.2.5
14.2.10
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
next@14.2.5
14.2.10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.