StackRadar

CVE-2026-104861

High

Advisory

Published 2 Oct 2026In the index since 3 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
17
of 18,026 indexed, latest versions
Container images
16
deployed by those charts
Fix available
1 of 1
affected package

probe-image-size: Quadratic-time Denial of Service in the SVG Parser

Carried by container images the latest versions of 17 of 18,026 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
probe-image-sizenpm5.0.0, 7.2.1, 7.2.3, 7.3.07.4.016
OSV records
GHSA-gjj5-9665-rwrc

Charts affected

17 by stars
ChartLatestAffected imagesRadar Score
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
probe-image-size@7.2.3
7.4.0

Open the chart page →

5,610
ghostcloudpirates-ghostVerified publisher0.20.281 of 3See more

ghost cloudpirates-ghost 0.20.28

1 of the 3 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
library/ghost:6.67.0428ce627d581
probe-image-size@7.3.0
7.4.0

Open the chart page →

8,355
ghost-on-kubernetesghost-on-kubernetes-helmVerified publisher2.0.21 of 3See more

ghost-on-kubernetes ghost-on-kubernetes-helm 2.0.2

1 of the 3 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
ghcr.io/sredevopsorg/ghost-on-kubernetes:main8da4c9948421
probe-image-size@7.3.0
7.4.0

Open the chart page →

1,513
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
probe-image-size@5.0.0
7.4.0

Open the chart page →

4,975
ghostgroundhog2k0.212.151 of 1See more

ghost groundhog2k 0.212.15

1 of the 1 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
library/ghost:6.67.0428ce627d581
probe-image-size@7.3.0
7.4.0

Open the chart page →

2,130
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
probe-image-size@7.3.0
7.4.0

Open the chart page →

36,111
ghostchart-ghost0.1.61 of 2See more

ghost chart-ghost 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
library/ghost:6.65.0-alpine3.23fea3264f902e
probe-image-size@7.3.0
7.4.0

Open the chart page →

1,762
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
probe-image-size@7.2.3
7.4.0

Open the chart page →

2,970
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
probe-image-size@7.2.1
7.4.0

Open the chart page →

88,566
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
probe-image-size@7.2.3
7.4.0

Open the chart page →

10,598
ghosthelmforgeVerified publisher1.2.101 of 3See more

ghost helmforge 1.2.10

1 of the 3 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
library/ghost:6.65.090592b712b6b
probe-image-size@7.3.0
7.4.0

Open the chart page →

3,528
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
probe-image-size@7.2.3
7.4.0

Open the chart page →

3,683
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
probe-image-size@7.2.3
7.4.0

Open the chart page →

4,551
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
probe-image-size@7.2.3
7.4.0

Open the chart page →

4,062
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
probe-image-size@7.2.3
7.4.0

Open the chart page →

3,846
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
probe-image-size@7.2.3
7.4.0

Open the chart page →

2,883
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-104861.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
probe-image-size@7.2.3
7.4.0

Open the chart page →

6,165

Container images carrying it

16 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/ghost:6.67.0428ce627d581
probe-image-size@7.3.0
7.4.0
2
jakowenko/double-take:1.6.0b858bac9e32a
probe-image-size@7.2.1
7.4.0
1
kyso/kyso-front:lateste52595c5c16f
probe-image-size@7.2.3
7.4.0
1
library/ghost:6.37.01ef2e532ca4d
probe-image-size@7.2.3
7.4.0
1
library/ghost:6.25.12654b1e90413
probe-image-size@7.2.3
7.4.0
1
library/ghost:6.41.129773d6be407
probe-image-size@7.2.3
7.4.0
1
library/ghost:4.37.0767230c0f263
probe-image-size@5.0.0
7.4.0
1
library/ghost:6.39.0-alpine77196da4b0df
probe-image-size@7.2.3
7.4.0
1
library/ghost:5.79.083f7bf209844
probe-image-size@7.2.3
7.4.0
1
library/ghost:6.65.090592b712b6b
probe-image-size@7.3.0
7.4.0
1
library/ghost:6.65.0-alpine3.23fea3264f902e
probe-image-size@7.3.0
7.4.0
1
misskey/misskey:12.110.1e08b7c478093
probe-image-size@7.2.3
7.4.0
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
probe-image-size@7.2.3
7.4.0
1
treskon/portrait-ui:DEV-lateste7970783bc8d
probe-image-size@7.3.0
7.4.0
1
ghcr.io/sredevopsorg/ghost-on-kubernetes:main8da4c9948421
probe-image-size@7.3.0
7.4.0
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
probe-image-size@7.2.3
7.4.0
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.