StackRadar

CVE-2026-101901

High

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
107
of 17,966 indexed, latest versions
Container images
91
deployed by those charts
Fix available
1 of 1
affected package

Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization

Carried by container images the latest versions of 107 of 17,966 indexed charts deploy, on 91 images.

Affected packageAffected versionsFixed inImages
axiosnpm1.13.0, 1.13.2, 1.13.3, 1.13.5+10 more1.20.091
OSV records
GHSA-542g-h47m-68v8

Charts affected

107 by stars
ChartLatestAffected imagesRadar Score
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-101901.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
axios@1.13.2
1.20.0

Open the chart page →

4,166
devportalveecode-platform-nextVerified publisher0.1.261 of 1See more

devportal veecode-platform-next 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-101901.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinned28d1bafed0cf
axios@1.19.0
1.20.0

Open the chart page →

2,041
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101901.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
axios@1.19.0
1.20.0

Open the chart page →

73,602
opensearch-dashboardswener3.9.01 of 1See more

opensearch-dashboards wener 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101901.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
axios@1.18.1
1.20.0

Open the chart page →

250
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-101901.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
axios@1.15.2
1.20.0

Open the chart page →

4,240
opensearch-dashboardswenerme3.9.01 of 1See more

opensearch-dashboards wenerme 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101901.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
axios@1.18.1
1.20.0

Open the chart page →

250
kibanawiremindVerified publisher8.5.241 of 2See more

kibana wiremind 8.5.24

1 of the 2 container images this version deploys carry CVE-2026-101901.

Container imageDigestPackageFixed in
library/kibana:8.19.2235544f1ff28a
axios@1.19.0
1.20.0

Open the chart page →

1,611

Container images carrying it

91 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
n8nio/n8n:2.40.59f693fd55655
axios@1.18.0
1.20.0
1
n8nio/n8n:2.36.8cfe2704ff858
axios@1.18.0
1.20.0
1
n8nio/n8n:2.41.3fdce8f852ac7
axios@1.18.0
1.20.0
1
n8nio/runners:2.41.31522f8179b76
axios@1.18.0
1.20.0
1
nocodb/nocodb:0.301.5d9516f0bf546
axios@1.13.6
1.20.0
1
nodered/node-red:5.0.410f40d0a83e7
axios@1.19.0
1.20.0
1
nodered/node-red:4.1.10-minimald73ae167cb9b
axios@1.16.0
1.20.0
1
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
axios@1.13.6
1.20.0
1
otwld/velero-ui:0.10.31c228d9ef71b
axios@1.18.1
1.20.0
1
outlinewiki/outline:1.10.1832051f039b4
axios@1.18.1
1.20.0
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
axios@1.13.2
1.20.0
1
redis/redisinsight:3.485562d67a912
axios@1.15.0
1.20.0
1
rocketadmin/rocketadmin:1.17.710955ef540b9
axios@1.15.1
1.20.0
1
shyamkrishna21/shopsync:latest3998b83def53
axios@1.13.5
1.20.0
1
treskon/portrait-ui:DEV-lateste7970783bc8d
axios@1.15.2
1.20.0
1
twentycrm/twenty:latest:v2.41.047bcefe4e497
axios@1.19.0
1.20.0
1
twentycrm/twenty:v2.43.0b2b662b1bef1
axios@1.19.0
1.20.0
1
twentycrm/twenty:v2.22.0e7d9948bf284
axios@1.17.0
1.20.0
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
axios@1.13.6
1.20.0
1
unleashorg/unleash-server:7.5.09adb37e399ba
axios@1.13.5
1.20.0
1
veecode/devportal28d1bafed0cf
axios@1.19.0
1.20.0
1
ghcr.io/appscode/platform-ui:2.5.0c27cafe398c2
axios@1.15.0
1.20.0
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
axios@1.13.5
1.20.0
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
axios@1.13.2
1.20.0
1
ghcr.io/cameri/nostream:mainc134ac2fa289
axios@1.18.0
1.20.0
1
ghcr.io/data-fair/portals:18b621866ceb2
axios@1.18.1
1.20.0
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
axios@1.18.0
1.20.0
1
ghcr.io/mkutlak/alluredeck-api:0.41.0fa429df90c68
axios@1.18.1
1.20.0
1
ghcr.io/platform-mesh/portal:v0.27.16a7ecd5a0dc2
axios@1.18.0
1.20.0
1
ghcr.io/seerr-team/seerr:v3.5.027602401178d
axios@1.15.0
1.20.0
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
axios@1.15.0
1.20.0
1
ghcr.io/sredevopsorg/ghost-on-kubernetes:main06adb21bfdfc
axios@1.18.1
1.20.0
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
axios@1.16.0
1.20.0
1
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
axios@1.19.0
1.20.0
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
axios@1.18.1
1.20.0
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
axios@1.15.0
1.20.0
1
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
axios@1.19.0
1.20.0
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
axios@1.19.0
1.20.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
axios@1.13.6
1.20.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
axios@1.13.6
1.20.0
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
axios@1.19.0
1.20.0
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.