CVE-2024-9506
LowAdvisory
Published 15 Oct 2024In the index since 6 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 3.7
- base score, highest
- EPSS
- 0.005
- 43rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 18
- of 17,781 indexed, latest versions
- Container images
- 22
- deployed by those charts
- Fix available
- 1 of 1
- affected package
ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 22 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| vuenpm | 2.6.10, 2.6.11, 2.6.12, 2.6.14+4 more | 3.0.0-alpha.0 | 22 |
- OSV records
- GHSA-5j4c-8p2g-v4jx
Charts affected
18 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| convertigoconvertigoOfficialVerified publisher | 8.4.3 | 1 of 5See more | 17,404 |
| mealiegeek-cookbookVerified publisher | 5.1.2 | 1 of 2See more | 7,579 |
| zwavejs2mqttgeek-cookbookVerified publisher | 5.4.2 | 1 of 1See more | 3,476 |
| n8none-acre-fundVerified publisher | 0.1.52 | 1 of 3See more | 7,776 |
| feedbacksystemthm-mni-iiVerified publisher | 0.47.1 | 1 of 10See more | 28,534 |
| data-fairdata354-helmVerified publisher | 1.1.2 | 6 of 12See more | 38,346 |
| recipesgeek-cookbookVerified publisher | 6.6.2 | 1 of 2See more | 7,801 |
| dashykrzwiatrzyk | 1.0.0 | 1 of 1See more | 3,143 |
| testhubteshubVerified publisher | 0.1.4 | 1 of 3See more | 7,517 |
| apimap-developerapimapOfficialVerified publisher | 1.4.1 | 1 of 1See more | 2,353 |
| apimap-portalapimapOfficialVerified publisher | 2.4.0 | 1 of 1See more | 2,396 |
| nas-appsawesomeVerified publisher | 2.0.0 | 1 of 8See more | 7,152 |
| townsquarehuscker-chartsVerified publisher | 1.0.4 | 1 of 2See more | 3,407 |
| frontendluiscajl | 0.1.7 | 1 of 1See more | 3,651 |
| dashynas-helm-chartsVerified publisher | 1.0.4 | 1 of 1See more | 3,269 |
| dashysergiotocaliniVerified publisher | 1.0.0 | 1 of 1See more | 3,143 |
| cadencewenerme | 0.23.0 | 1 of 5See more | 10,127 |
| temporalwenerme | 0.15.1 | 1 of 13See more | 22,665 |
Container images carrying it
22 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | acb40032ad4b | vue | 3.0.0-alpha.0 | 2 |
| apimap/ | 406d3858e20c | vue | 3.0.0-alpha.0 | 1 |
| apimap/ | 041a4790c65c | vue | 3.0.0-alpha.0 | 1 |
| baserow/ | df0c42eb67e8 | vue | 3.0.0-alpha.0 | 1 |
| hkotel/ | 3c04c0e85039 | vue | 3.0.0-alpha.0 | 1 |
| lavandadelpatio/ | 501c3f31e0bc | vue | 3.0.0-alpha.0 | 1 |
| lissy93/ | 1991f7be5ed0 | vue | 3.0.0-alpha.0 | 1 |
| ltdstudio/ | 0e76c6f4eac0 | vue | 3.0.0-alpha.0 | 1 |
| n8nio/ | a9195bc499a3 | vue | 3.0.0-alpha.0 | 1 |
| temporalio/ | 33cfa863d8ce | vue | 3.0.0-alpha.0 | 1 |
| testhubio/ | e86c2db53be8 | vue | 3.0.0-alpha.0 | 1 |
| thmmniii/ | a347f7f4d144 | vue | 3.0.0-alpha.0 | 1 |
| ubercadence/ | 8564a5b44a6d | vue | 3.0.0-alpha.0 | 1 |
| vabene1111/ | ec4e9e2905b0 | vue | 3.0.0-alpha.0 | 1 |
| zwavejs/ | 15a6040fb468 | vue | 3.0.0-alpha.0 | 1 |
| ghcr.io/ | cc9498b64b5b | vue | 3.0.0-alpha.0 | 1 |
| ghcr.io/ | a8d40779eeae | vue | 3.0.0-alpha.0 | 1 |
| ghcr.io/ | c739b74dabb0 | vue | 3.0.0-alpha.0 | 1 |
| ghcr.io/ | 8b621866ceb2 | vue | 3.0.0-alpha.0 | 1 |
| ghcr.io/ | 5a9216989707 | vue | 3.0.0-alpha.0 | 1 |
| ghcr.io/ | 38a4f32fad82 | vue | 3.0.0-alpha.0 | 1 |
| ghcr.io/ | e106681e7673 | vue | 3.0.0-alpha.0 | 1 |