StackRadar

CVE-2026-101903

High

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
61
of 17,966 indexed, latest versions
Container images
53
deployed by those charts
Fix available
1 of 1
affected package

Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)

Carried by container images the latest versions of 61 of 17,966 indexed charts deploy, on 53 images.

Affected packageAffected versionsFixed inImages
axiosnpm1.16.1, 1.17.0, 1.18.0, 1.18.1+1 more1.20.053
OSV records
GHSA-c29m-xwm3-cm6r

Charts affected

61 by stars
ChartLatestAffected imagesRadar Score
portalplatform-mesh-portal0.21.11 of 1See more

portal platform-mesh-portal 0.21.1

1 of the 1 container images this version deploys carry CVE-2026-101903.

Container imageDigestPackageFixed in
ghcr.io/platform-mesh/portal:v0.27.16a7ecd5a0dc2
axios@1.18.0
1.20.0

Open the chart page →

330
prismeai-coreprismeai1.12.31 of 7See more

prismeai-core prismeai 1.12.3

1 of the 7 container images this version deploys carry CVE-2026-101903.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
axios@1.19.0
1.20.0

Open the chart page →

4,859
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-101903.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
axios@1.19.0
1.20.0

Open the chart page →

3,322
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-101903.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
axios@1.18.1
1.20.0

Open the chart page →

3,871
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-101903.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
axios@1.17.0
1.20.0

Open the chart page →

6,179
evershopunifieVerified publisher1.0.01 of 1See more

evershop unifie 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101903.

Container imageDigestPackageFixed in
evershop/evershop:latestd0823576f91b
axios@1.19.0
1.20.0

Open the chart page →

1,215
devportalveecode-platform-nextVerified publisher0.1.261 of 1See more

devportal veecode-platform-next 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-101903.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinned28d1bafed0cf
axios@1.19.0
1.20.0

Open the chart page →

2,041
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101903.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
axios@1.19.0
1.20.0

Open the chart page →

73,602
opensearch-dashboardswener3.9.01 of 1See more

opensearch-dashboards wener 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101903.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
axios@1.18.1
1.20.0

Open the chart page →

250
opensearch-dashboardswenerme3.9.01 of 1See more

opensearch-dashboards wenerme 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101903.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
axios@1.18.1
1.20.0

Open the chart page →

250
kibanawiremindVerified publisher8.5.241 of 2See more

kibana wiremind 8.5.24

1 of the 2 container images this version deploys carry CVE-2026-101903.

Container imageDigestPackageFixed in
library/kibana:8.19.2235544f1ff28a
axios@1.19.0
1.20.0

Open the chart page →

1,611

Container images carrying it

53 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
axios@1.19.0
1.20.0
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
axios@1.19.0
1.20.0
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
axios@1.19.0
1.20.0
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.