StackRadar

CVE-2026-104182

Medium

Advisory

Published 5 Oct 2026In the index since 6 Oct 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
27
of 18,026 indexed, latest versions
Container images
23
deployed by those charts
Fix available
1 of 1
affected package

stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk

Carried by container images the latest versions of 27 of 18,026 indexed charts deploy, on 23 images.

Affected packageAffected versionsFixed inImages
stream-jsonnpm1.8.0, 1.9.0, 1.9.1, 2.1.03.6.023
OSV records
GHSA-hqr4-qq8f-hg3x

Charts affected

27 by stars
ChartLatestAffected imagesRadar Score
n8ncommunity-chartsVerified publisher1.24.431 of 1See more

n8n community-charts 1.24.43

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
n8nio/n8n:2.41.687e0bab2c931
stream-json@1.9.1
3.6.0

Open the chart page →

1,398
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
stream-json@1.9.1
3.6.0

Open the chart page →

2,259
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
stream-json@1.9.1
3.6.0

Open the chart page →

3,948
n8nhelmforgeVerified publisher2.1.22 of 2See more

n8n helmforge 2.1.2

2 of the 2 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
n8nio/n8n:2.41.3fdce8f852ac7
stream-json@1.9.1
3.6.0
n8nio/runners:2.41.31522f8179b76
stream-json@1.9.1
3.6.0

Open the chart page →

1,744
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
stream-json@1.8.0
3.6.0

Open the chart page →

34,276
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
stream-json@1.9.1
3.6.0

Open the chart page →

1,450
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
stream-json@1.9.1
3.6.0

Open the chart page →

5,210
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
stream-json@1.9.1
3.6.0

Open the chart page →

9,353
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
stream-json@1.9.1
3.6.0

Open the chart page →

2,103
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
stream-json@1.9.1
3.6.0

Open the chart page →

3,835
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
stream-json@1.8.0
3.6.0

Open the chart page →

5,761
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
stream-json@1.8.0
3.6.0

Open the chart page →

5,761
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
stream-json@1.8.0
3.6.0

Open the chart page →

5,761
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
stream-json@1.8.0
3.6.0

Open the chart page →

5,437
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
stream-json@1.9.1
3.6.0

Open the chart page →

2,147
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
stream-json@1.8.0
3.6.0

Open the chart page →

3,456
strapihelmforgeVerified publisher2.3.151 of 3See more

strapi helmforge 2.3.15

1 of the 3 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
helmforge/strapi-base:5.52.270e9143d6d92
stream-json@1.9.1
3.6.0

Open the chart page →

2,680
nocodbinseefrlab0.2.01 of 1See more

nocodb inseefrlab 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
nocodb/nocodb:latest4ccfc5114506
stream-json@1.9.1
3.6.0

Open the chart page →

873
mongo-compassmongo-compass-webVerified publisher1.1.41 of 1See more

mongo-compass mongo-compass-web 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.1f4f8fe4e21f1
stream-json@1.9.1
3.6.0

Open the chart page →

2,189
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
stream-json@1.9.1
3.6.0

Open the chart page →

2,859
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
stream-json@1.9.1
3.6.0

Open the chart page →

2,259
nostreamnostream0.1.01 of 1See more

nostream nostream 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
ghcr.io/cameri/nostream:mainc134ac2fa289
stream-json@2.1.0
3.6.0

Open the chart page →

786
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
stream-json@1.9.0
3.6.0

Open the chart page →

4,917
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
stream-json@1.9.1
3.6.0

Open the chart page →

2,259
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
stream-json@1.9.1
3.6.0

Open the chart page →

3,645
strapistrapi-xmv0.1.21 of 1See more

strapi strapi-xmv 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latest978cda40de67
stream-json@1.8.0
3.6.0

Open the chart page →

923
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-104182.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
stream-json@1.9.1
3.6.0

Open the chart page →

4,536

Container images carrying it

23 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
rcdelacruz/my-strapi-app:js-amd6438007f358355
stream-json@1.8.0
3.6.0
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
stream-json@1.9.1
3.6.0
3
n8nio/n8n:2.36.714c4285bc303
stream-json@1.9.1
3.6.0
2
directus/directus:12.0.29c8470ea465c
stream-json@1.9.1
3.6.0
1
directus/directus:11.1.0e3c8bb975350
stream-json@1.8.0
3.6.0
1
ethpandaops/ethereumjs:masterfb84b718500f
stream-json@1.9.1
3.6.0
1
evoapicloud/evolution-api:latest966625532d90
stream-json@1.9.1
3.6.0
1
haohanyang/compass-web:0.5.054f2112602ee
stream-json@1.9.1
3.6.0
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
stream-json@1.9.1
3.6.0
1
helmforge/strapi-base:5.52.270e9143d6d92
stream-json@1.9.1
3.6.0
1
n8nio/n8n:2.25.7761374d4eb84
stream-json@1.9.1
3.6.0
1
n8nio/n8n:2.41.687e0bab2c931
stream-json@1.9.1
3.6.0
1
n8nio/n8n:2.36.8cfe2704ff858
stream-json@1.9.1
3.6.0
1
n8nio/n8n:2.41.3fdce8f852ac7
stream-json@1.9.1
3.6.0
1
n8nio/runners:2.41.31522f8179b76
stream-json@1.9.1
3.6.0
1
nocodb/nocodb:latest4ccfc5114506
stream-json@1.9.1
3.6.0
1
nocodb/nocodb:0.258.06779a4ddedf2
stream-json@1.9.0
3.6.0
1
nocodb/nocodb:0.301.5d9516f0bf546
stream-json@1.9.1
3.6.0
1
qxip/qryn:3.2.3977acc9c7a9fd
stream-json@1.8.0
3.6.0
1
ghcr.io/cameri/nostream:mainc134ac2fa289
stream-json@2.1.0
3.6.0
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
stream-json@1.8.0
3.6.0
1
ghcr.io/xmv-solutions-gmbh/strapi:latest978cda40de67
stream-json@1.8.0
3.6.0
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
stream-json@1.9.1
3.6.0
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.