StackRadar

CVE-2026-101907

High

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
59
of 17,966 indexed, latest versions
Container images
51
deployed by those charts
Fix available
1 of 1
affected package

Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF

Carried by container images the latest versions of 59 of 17,966 indexed charts deploy, on 51 images.

Affected packageAffected versionsFixed inImages
axiosnpm1.17.0, 1.18.0, 1.18.1, 1.19.01.20.051
OSV records
GHSA-r4gj-5m52-g5wh

Charts affected

59 by stars
ChartLatestAffected imagesRadar Score
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-101907.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
axios@1.19.0
1.20.0

Open the chart page →

3,322
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-101907.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
axios@1.18.1
1.20.0

Open the chart page →

3,871
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-101907.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
axios@1.17.0
1.20.0

Open the chart page →

6,179
evershopunifieVerified publisher1.0.01 of 1See more

evershop unifie 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-101907.

Container imageDigestPackageFixed in
evershop/evershop:latestd0823576f91b
axios@1.19.0
1.20.0

Open the chart page →

1,215
devportalveecode-platform-nextVerified publisher0.1.261 of 1See more

devportal veecode-platform-next 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-101907.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinned28d1bafed0cf
axios@1.19.0
1.20.0

Open the chart page →

2,041
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-101907.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
axios@1.19.0
1.20.0

Open the chart page →

73,602
opensearch-dashboardswener3.9.01 of 1See more

opensearch-dashboards wener 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101907.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
axios@1.18.1
1.20.0

Open the chart page →

250
opensearch-dashboardswenerme3.9.01 of 1See more

opensearch-dashboards wenerme 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-101907.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
axios@1.18.1
1.20.0

Open the chart page →

250
kibanawiremindVerified publisher8.5.241 of 2See more

kibana wiremind 8.5.24

1 of the 2 container images this version deploys carry CVE-2026-101907.

Container imageDigestPackageFixed in
library/kibana:8.19.2235544f1ff28a
axios@1.19.0
1.20.0

Open the chart page →

1,611

Container images carrying it

51 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
decisionrules/server:latest6a8f32aa11bc
axios@1.19.0
1.20.0
4
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
axios@1.18.1
1.20.0
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
axios@1.19.0
1.20.0
3
actualbudget/actual-server:26.9.0552beab3dec8
axios@1.18.1
1.20.0
2
library/ghost:6.65.090592b712b6b
axios@1.18.1
1.20.0
2
n8nio/n8n:2.36.714c4285bc303
axios@1.18.0
1.20.0
2
nodered/node-red:5.0.7:latesta649dd711d55
axios@1.19.0
1.20.0
2
activepieces/activepieces:0.91.058414dfc94c4
axios@1.18.0
1.20.0
1
baserow/web-frontend:2.3.3566d24c7d9f5
axios@1.18.0
1.20.0
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
axios@1.19.0
1.20.0
1
cyfershepard/jellystat:1.1.12e61c759ec706
axios@1.17.0
1.20.0
1
dbgate/dbgate:7.2.0-alpine287077002446
axios@1.17.0
1.20.0
1
dbgate/dbgate:7.2.3f2dc7423ea88
axios@1.18.1
1.20.0
1
docmost/docmost:0.96.0b56947fcfd08
axios@1.18.1
1.20.0
1
evershop/evershop:latestd0823576f91b
axios@1.19.0
1.20.0
1
flanksource/incident-manager-ui:v1.4.320d952c2a774a2
axios@1.18.1
1.20.0
1
growthbook/growthbook:5.1.0c8a124f55dca
axios@1.18.1
1.20.0
1
growthbook/growthbook:latestcbf1bc59e9a9
axios@1.18.1
1.20.0
1
helmforge/strapi-base:5.52.270e9143d6d92
axios@1.19.0
1.20.0
1
infisical/infisical:latest:v0.165.602082bf13163
axios@1.18.1
1.20.0
1
infisical/infisical:latest3365445909be
axios@1.18.1
1.20.0
1
kitware/cdash:v5.4.0da5abe941506
axios@1.19.0
1.20.0
1
library/ghost:6.64.0586821cfebac
axios@1.18.1
1.20.0
1
library/ghost:6.65.0-alpine3.23fea3264f902e
axios@1.18.1
1.20.0
1
library/kibana:8.19.2235544f1ff28a
axios@1.19.0
1.20.0
1
makeplane/live-commercial:v3.3.0488a6684637c
axios@1.18.1
1.20.0
1
makeplane/silo-commercial:v3.3.027bf6bbf59bd
axios@1.18.1
1.20.0
1
makeplane/space-commercial:v3.3.03dba6a659fb9
axios@1.18.1
1.20.0
1
mitre/heimdall2:release-latest06f6e72d416a
axios@1.19.0
1.20.0
1
n8nio/n8n:2.40.59f693fd55655
axios@1.18.0
1.20.0
1
n8nio/n8n:2.36.8cfe2704ff858
axios@1.18.0
1.20.0
1
n8nio/n8n:2.41.3fdce8f852ac7
axios@1.18.0
1.20.0
1
n8nio/runners:2.41.31522f8179b76
axios@1.18.0
1.20.0
1
nodered/node-red:5.0.410f40d0a83e7
axios@1.19.0
1.20.0
1
otwld/velero-ui:0.10.31c228d9ef71b
axios@1.18.1
1.20.0
1
outlinewiki/outline:1.10.1832051f039b4
axios@1.18.1
1.20.0
1
twentycrm/twenty:latest:v2.41.047bcefe4e497
axios@1.19.0
1.20.0
1
twentycrm/twenty:v2.43.0b2b662b1bef1
axios@1.19.0
1.20.0
1
twentycrm/twenty:v2.22.0e7d9948bf284
axios@1.17.0
1.20.0
1
veecode/devportal28d1bafed0cf
axios@1.19.0
1.20.0
1
ghcr.io/cameri/nostream:mainc134ac2fa289
axios@1.18.0
1.20.0
1
ghcr.io/data-fair/portals:18b621866ceb2
axios@1.18.1
1.20.0
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
axios@1.18.0
1.20.0
1
ghcr.io/mkutlak/alluredeck-api:0.41.0fa429df90c68
axios@1.18.1
1.20.0
1
ghcr.io/platform-mesh/portal:v0.27.16a7ecd5a0dc2
axios@1.18.0
1.20.0
1
ghcr.io/sredevopsorg/ghost-on-kubernetes:main06adb21bfdfc
axios@1.18.1
1.20.0
1
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
axios@1.19.0
1.20.0
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
axios@1.18.1
1.20.0
1
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
axios@1.19.0
1.20.0
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
axios@1.19.0
1.20.0
1

syft 1.42.1 · advisories as of 1 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.