StackRadar

CVE-2026-102281

High

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
6
of 17,992 indexed, latest versions
Container images
6
deployed by those charts
Fix available
1 of 1
affected package

Nest: Remote process termination via a deeply nested microservice message pattern

Carried by container images the latest versions of 6 of 17,992 indexed charts deploy, on 6 images.

Affected packageAffected versionsFixed inImages
@nestjs/microservicesnpm8.0.0, 9.2.0, 10.4.19, 11.1.11+1 more11.2.46
OSV records
GHSA-m8vh-jmq9-5rjg

Charts affected

6 by stars
ChartLatestAffected imagesRadar Score
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2026-102281.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
@nestjs/microservices@11.1.17
11.2.4

Open the chart page →

35,822
patchworkpatchworkVerified publisher0.8.61 of 2See more

patchwork patchwork 0.8.6

1 of the 2 container images this version deploys carry CVE-2026-102281.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/patchwork:mainc01e018bced4
@nestjs/microservices@10.4.19
11.2.4

Open the chart page →

2,264
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-102281.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
@nestjs/microservices@9.2.0
11.2.4

Open the chart page →

5,377
codiac-cluster-agent-chartcodiac-cluster-agent1.0.381 of 1See more

codiac-cluster-agent-chart codiac-cluster-agent 1.0.38

1 of the 1 container images this version deploys carry CVE-2026-102281.

Container imageDigestPackageFixed in
codiacimages/codiac-cluster-agent:1.0.380cd44ca7a7ee
@nestjs/microservices@11.1.11
11.2.4

Open the chart page →

1,855
mishtip2p-avs0.1.01 of 2See more

mishti p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-102281.

Container imageDigestPackageFixed in
mishtinetwork/operator:latestbb3fe67a5f7c
@nestjs/microservices@8.0.0
11.2.4

Open the chart page →

4,549
ungatep2p-avs0.1.01 of 3See more

ungate p2p-avs 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-102281.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
@nestjs/microservices@8.0.0
11.2.4

Open the chart page →

29,544

Container images carrying it

6 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
@nestjs/microservices@9.2.0
11.2.4
1
codiacimages/codiac-cluster-agent:1.0.380cd44ca7a7ee
@nestjs/microservices@11.1.11
11.2.4
1
mishtinetwork/operator:latestbb3fe67a5f7c
@nestjs/microservices@8.0.0
11.2.4
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
@nestjs/microservices@8.0.0
11.2.4
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
@nestjs/microservices@10.4.19
11.2.4
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
@nestjs/microservices@11.1.17
11.2.4
1

syft 1.42.1 · advisories as of 4 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.