StackRadar

CVE-2026-104849

Critical

Advisory

Published 5 Oct 2026In the index since 6 Oct 2026
Severity
Critical
worst across findings
CVSS
9.5
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 18,035 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 1
affected package

Tinypool: Prototype Pollution Gadget to RCE in run() options

Carried by container images the latest versions of 9 of 18,035 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
tinypoolnpm0.3.1, 0.4.0, 0.6.0, 0.8.1+3 more2.1.215
OSV records
GHSA-85c8-ppgw-ccpr

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-104849.

Container imageDigestPackageFixed in
openmined/syft-frontend:0.9.5d11524a3854a
tinypool@0.6.0
2.1.2

Open the chart page →

20,741
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-104849.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
tinypool@1.1.1
2.1.2

Open the chart page →

5,239
plane-enterprisemakeplaneOfficialVerified publisher3.10.33 of 13See more

plane-enterprise makeplane 3.10.3

3 of the 13 container images this version deploys carry CVE-2026-104849.

Container imageDigestPackageFixed in
makeplane/live-commercial:v3.3.1d68fab8f6a3e
tinypool@2.1.0
2.1.2
makeplane/silo-commercial:v3.3.1f0825c6b22d1
tinypool@2.1.0
2.1.2
makeplane/space-commercial:v3.3.19360e65bf273
tinypool@2.1.0
2.1.2

Open the chart page →

6,159
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-104849.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
tinypool@0.3.1
2.1.2

Open the chart page →

5,787
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-104849.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
tinypool@0.8.1
2.1.2

Open the chart page →

5,288
rybbitrybbit-helm1.3.21 of 7See more

rybbit rybbit-helm 1.3.2

1 of the 7 container images this version deploys carry CVE-2026-104849.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
tinypool@1.1.1
2.1.2

Open the chart page →

8,342
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-104849.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
tinypool@1.0.0
2.1.2

Open the chart page →

4,940
workadventure-adminwork-adventure1.0.0-21-33 of 14See more

workadventure-admin work-adventure 1.0.0-21-3

3 of the 14 container images this version deploys carry CVE-2026-104849.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:helm-chart53a30c962ce9
tinypool@0.4.0
2.1.2
thecodingmachine/workadventure-map-storage:helm-chart519c31c6e7ec
tinypool@0.4.0
2.1.2
thecodingmachine/workadventure-play:helm-chartdf31006cc4ce
tinypool@0.4.0
2.1.2

Open the chart page →

19,828
workadventureworkadventure1.1.03 of 9See more

workadventure workadventure 1.1.0

3 of the 9 container images this version deploys carry CVE-2026-104849.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
tinypool@0.4.0
2.1.2
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
tinypool@0.4.0
2.1.2
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
tinypool@0.4.0
2.1.2

Open the chart page →

20,446

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
chainsafe/lodestar:v1.27.07b9fe4aa8073
tinypool@1.0.0
2.1.2
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
tinypool@0.3.1
2.1.2
1
makeplane/live-commercial:v3.3.1d68fab8f6a3e
tinypool@2.1.0
2.1.2
1
makeplane/silo-commercial:v3.3.1f0825c6b22d1
tinypool@2.1.0
2.1.2
1
makeplane/space-commercial:v3.3.19360e65bf273
tinypool@2.1.0
2.1.2
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
tinypool@0.8.1
2.1.2
1
nocodb/nocodb:0.301.5d9516f0bf546
tinypool@1.1.1
2.1.2
1
openmined/syft-frontend:0.9.5d11524a3854a
tinypool@0.6.0
2.1.2
1
thecodingmachine/workadventure-back:helm-chart53a30c962ce9
tinypool@0.4.0
2.1.2
1
thecodingmachine/workadventure-back:v1.17.764001369dad5
tinypool@0.4.0
2.1.2
1
thecodingmachine/workadventure-map-storage:helm-chart519c31c6e7ec
tinypool@0.4.0
2.1.2
1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
tinypool@0.4.0
2.1.2
1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
tinypool@0.4.0
2.1.2
1
thecodingmachine/workadventure-play:helm-chartdf31006cc4ce
tinypool@0.4.0
2.1.2
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
tinypool@1.1.1
2.1.2
1

syft 1.42.1 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.