StackRadar

CVE-2026-101900

Medium

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.005
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
114
of 17,966 indexed, latest versions
Container images
99
deployed by those charts
Fix available
1 of 1
affected package

Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders

Carried by container images the latest versions of 114 of 17,966 indexed charts deploy, on 99 images.

Affected packageAffected versionsFixed inImages
axiosnpm1.12.0, 1.12.2, 1.13.0, 1.13.2+12 more1.20.099
OSV records
GHSA-4hqw-qxg8-jxx2

Charts affected

114 by stars
ChartLatestAffected imagesRadar Score
strapistrapi-xmv0.1.21 of 1See more

strapi strapi-xmv 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
axios@1.16.0
1.20.0

Open the chart page →

1,011
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
axios@1.16.0
1.20.0

Open the chart page →

5,022
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
axios@1.17.0
1.20.0

Open the chart page →

6,179
evershopunifieVerified publisher1.0.01 of 1See more

evershop unifie 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
evershop/evershop:latestd0823576f91b
axios@1.19.0
1.20.0

Open the chart page →

1,215
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
axios@1.13.6
1.20.0

Open the chart page →

2,408
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
axios@1.13.2
1.20.0

Open the chart page →

4,166
devportalveecode-platform-nextVerified publisher0.1.261 of 1See more

devportal veecode-platform-next 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinned28d1bafed0cf
axios@1.19.0
1.20.0

Open the chart page →

2,041
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
axios@1.12.0
1.20.0

Open the chart page →

7,081
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
axios@1.19.0
1.20.0

Open the chart page →

73,602
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
axios@1.12.2
1.20.0

Open the chart page →

6,084
opensearch-dashboardswener3.9.01 of 1See more

opensearch-dashboards wener 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
axios@1.18.1
1.20.0

Open the chart page →

250
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
axios@1.15.2
1.20.0

Open the chart page →

4,240
opensearch-dashboardswenerme3.9.01 of 1See more

opensearch-dashboards wenerme 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
axios@1.18.1
1.20.0

Open the chart page →

250
kibanawiremindVerified publisher8.5.241 of 2See more

kibana wiremind 8.5.24

1 of the 2 container images this version deploys carry CVE-2026-101900.

Container imageDigestPackageFixed in
library/kibana:8.19.2235544f1ff28a
axios@1.19.0
1.20.0

Open the chart page →

1,611

Container images carrying it

99 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
decisionrules/server:latest6a8f32aa11bc
axios@1.19.0
1.20.0
4
redis/redisinsight:3.8:latestb5e19ee240ab
axios@1.16.0
1.20.0
4
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
axios@1.18.1
1.20.0
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
axios@1.13.6
1.20.0
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
axios@1.19.0
1.20.0
3
actualbudget/actual-server:26.9.0552beab3dec8
axios@1.18.1
1.20.0
2
library/ghost:6.65.090592b712b6b
axios@1.18.1
1.20.0
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
axios@1.13.0
1.20.0
2
n8nio/n8n:2.36.714c4285bc303
axios@1.18.0
1.20.0
2
nodered/node-red:5.0.7:latesta649dd711d55
axios@1.19.0
1.20.0
2
requarks/wiki:2:latest68f0d1848261
axios@1.15.2
1.20.0
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
axios@1.16.0
1.20.0
2
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
axios@1.15.0
1.20.0
2
activepieces/activepieces:0.91.058414dfc94c4
axios@1.18.0
1.20.0
1
baserow/web-frontend:2.3.3566d24c7d9f5
axios@1.18.0
1.20.0
1
budibase/apps:3.41.344fe6feab985
axios@1.15.2
1.20.0
1
chainsafe/lodestar:latestd717e4193699
axios@1.13.3
1.20.0
1
codiacimages/codiac-cluster-agent:1.0.380cd44ca7a7ee
axios@1.13.2
1.20.0
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
axios@1.19.0
1.20.0
1
cyfershepard/jellystat:1.1.12e61c759ec706
axios@1.17.0
1.20.0
1
dbgate/dbgate:7.2.0-alpine287077002446
axios@1.17.0
1.20.0
1
dbgate/dbgate:7.2.3f2dc7423ea88
axios@1.18.1
1.20.0
1
directus/directus:12.0.29c8470ea465c
axios@1.16.1
1.20.0
1
docmost/docmost:0.96.0b56947fcfd08
axios@1.18.1
1.20.0
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
axios@1.13.2
1.20.0
1
evershop/evershop:latestd0823576f91b
axios@1.19.0
1.20.0
1
evoapicloud/evolution-api:latest966625532d90
axios@1.13.2
1.20.0
1
f3ktech/recaptcha-v3-verifier:1.1.048e78987cf91
axios@1.13.2
1.20.0
1
flanksource/incident-manager-ui:v1.4.320d952c2a774a2
axios@1.18.1
1.20.0
1
fosrl/pangolin:1.13.0c32ad797ab96
axios@1.13.2
1.20.0
1
growthbook/growthbook:5.1.0c8a124f55dca
axios@1.18.1
1.20.0
1
growthbook/growthbook:latestcbf1bc59e9a9
axios@1.18.1
1.20.0
1
helmforge/strapi-base:5.52.270e9143d6d92
axios@1.19.0
1.20.0
1
infisical/infisical:latest:v0.165.602082bf13163
axios@1.18.1
1.20.0
1
infisical/infisical:latest3365445909be
axios@1.18.1
1.20.0
1
kitware/cdash:v5.4.0da5abe941506
axios@1.19.0
1.20.0
1
library/ghost:6.37.01ef2e532ca4d
axios@1.16.0
1.20.0
1
library/ghost:6.25.12654b1e90413
axios@1.13.2
1.20.0
1
library/ghost:6.41.129773d6be407
axios@1.16.0
1.20.0
1
library/ghost:6.64.0586821cfebac
axios@1.18.1
1.20.0
1
library/ghost:6.39.0-alpine77196da4b0df
axios@1.16.0
1.20.0
1
library/ghost:6.65.0-alpine3.23fea3264f902e
axios@1.18.1
1.20.0
1
library/kibana:8.19.2235544f1ff28a
axios@1.19.0
1.20.0
1
litlyx/litlyx-consumer:latest02225e77d316
axios@1.13.2
1.20.0
1
makeplane/live-commercial:v3.3.0488a6684637c
axios@1.18.1
1.20.0
1
makeplane/silo-commercial:v3.3.027bf6bbf59bd
axios@1.18.1
1.20.0
1
makeplane/space-commercial:v3.3.03dba6a659fb9
axios@1.18.1
1.20.0
1
mitre/heimdall2:release-latest06f6e72d416a
axios@1.19.0
1.20.0
1
moreillon/group-manager:latest3caa8f710ee0
axios@1.15.0
1.20.0
1
n8nio/n8n:2.25.7761374d4eb84
axios@1.16.1
1.20.0
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.