StackRadar

CVE-2026-12590

Low

Advisory

Published 20 Jul 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
515
of 17,781 indexed, latest versions
Container images
522
deployed by those charts
Fix available
1 of 1
affected package

body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement

Carried by container images the latest versions of 515 of 17,781 indexed charts deploy, on 522 images.

Affected packageAffected versionsFixed inImages
body-parsernpm1.13.3, 1.14.2, 1.16.1, 1.17.2+15 more1.20.6, 2.3.0522
OSV records
GHSA-v422-hmwv-36x6

Charts affected

515 by stars
ChartLatestAffected imagesRadar Score
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
body-parser@1.19.0
1.20.6

Open the chart page →

27,465
firecrawlobeoneVerified publisher3.0.11 of 5See more

firecrawl obeone 3.0.1

1 of the 5 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
body-parser@2.2.2
2.3.0

Open the chart page →

9,995
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
body-parser@1.20.3
1.20.6

Open the chart page →

4,219
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
body-parser@2.2.0
2.3.0

Open the chart page →

2,421
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
body-parser@1.19.0
1.20.6

Open the chart page →

9,968
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
openwhisk/alarmprovider:2.2.0b695a6ceb406
body-parser@1.19.0
1.20.6

Open the chart page →

36,215
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
body-parser@1.20.3
1.20.6

Open the chart page →

838
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
body-parser@1.19.0
1.20.6

Open the chart page →

1,986
outscale-s3-exploreroutscale-s3-explorer0.1.41 of 1See more

outscale-s3-explorer outscale-s3-explorer 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
body-parser@1.20.3
1.20.6

Open the chart page →

1,811
mishtip2p-avs0.1.01 of 2See more

mishti p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
mishtinetwork/operator:latestbb3fe67a5f7c
body-parser@1.20.0
1.20.6

Open the chart page →

3,999
ungatep2p-avs0.1.02 of 3See more

ungate p2p-avs 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
body-parser@1.20.0
1.20.6
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
body-parser@1.20.2
1.20.6

Open the chart page →

27,373
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-server:1.0.53c840aebce22
body-parser@1.19.0
1.20.6

Open the chart page →

19,720
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
ghcr.io/michaelhaigh/pacman:latestb0931b1f085d
body-parser@1.20.4
1.20.6

Open the chart page →

3,562
pairdroppascaliskeVerified publisher2.0.01 of 1See more

pairdrop pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/pairdrop:version-v1.11.23279d2d986c0
body-parser@1.20.3
1.20.6

Open the chart page →

663
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
body-parser@1.19.0
1.20.6

Open the chart page →

6,524
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
body-parser@1.19.0
1.20.6

Open the chart page →

28,484
prismeai-coreprismeai1.12.12 of 7See more

prismeai-core prismeai 1.12.1

2 of the 7 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod470da8f8730c
body-parser@2.2.1
2.3.0
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbce6d452ad08
body-parser@2.2.1
2.3.0

Open the chart page →

3,270
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
body-parser@1.20.1
1.20.6

Open the chart page →

2,969
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
body-parser@2.2.2
2.3.0

Open the chart page →

1,858
recipe-apprecipe-app0.1.01 of 2See more

recipe-app recipe-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
body-parser@1.20.3
1.20.6

Open the chart page →

3,271
redisinsightredisinsightVerified publisher0.1.01 of 1See more

redisinsight redisinsight 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
body-parser@2.2.1
2.3.0

Open the chart page →

1,038
redisinsightredisinsight-helmVerified publisher0.1.11 of 1See more

redisinsight redisinsight-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
redis/redisinsight:2.46699d341bd329
body-parser@1.20.2
1.20.6

Open the chart page →

1,884
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
body-parser@1.20.2
1.20.6

Open the chart page →

6,282
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
body-parser@1.20.3
1.20.6

Open the chart page →

4,600
jsonplaceholderrgnu1.0.01 of 1See more

jsonplaceholder rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
svenwal/jsonplaceholder:latestba2f285af432
body-parser@1.19.1
1.20.6

Open the chart page →

1,547
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
body-parser@1.20.1
1.20.6

Open the chart page →

6,026
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
body-parser@1.18.3
1.20.6

Open the chart page →

5,215
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
body-parser@1.20.3
1.20.6

Open the chart page →

15,591
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
body-parser@1.20.4
1.20.6

Open the chart page →

68,240
routr-connectroutr0.4.31 of 10See more

routr-connect routr 0.4.3

1 of the 10 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
fonoster/routr-registry:2.13.6e27001f2813c
body-parser@1.20.3
1.20.6

Open the chart page →

11,021
audiobookshelfrubxkubeVerified publisher0.1.31 of 1See more

audiobookshelf rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
body-parser@1.20.1
1.20.6

Open the chart page →

1,722
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
body-parser@1.20.1
1.20.6

Open the chart page →

7,413
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
body-parser@1.20.5
1.20.6

Open the chart page →

30,219
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
safeglobal/safe-client-gateway-nest:v1.51.012ccfd93fcaf
body-parser@1.20.2
1.20.6

Open the chart page →

19,560
samplesample0.1.01 of 2See more

sample sample 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
library/mongo-express:1.0.2-20-alpine3.191aae00775251
body-parser@1.20.1
1.20.6

Open the chart page →

2,309
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
body-parser@1.19.2
1.20.6

Open the chart page →

4,744
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
body-parser@1.20.1
1.20.6

Open the chart page →

5,582
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
body-parser@1.20.0
1.20.6

Open the chart page →

3,118
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
body-parser@1.13.3
1.20.6

Open the chart page →

3,638
etherpadschoenwald0.3.01 of 1See more

etherpad schoenwald 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
etherpad/etherpad:2.7.2b723fe5f2594
body-parser@2.2.2
2.3.0

Open the chart page →

2,133
semaphoreschoenwald0.1.31 of 1See more

semaphore schoenwald 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
0hlov3/semaphore:v1.0.050f874ec096b
body-parser@1.20.1
1.20.6

Open the chart page →

1,796
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
body-parser@1.20.3
1.20.6

Open the chart page →

5,497
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
body-parser@2.2.2
2.3.0

Open the chart page →

1,991
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
body-parser@1.19.2
1.20.6

Open the chart page →

3,143
shopsyncshopsyncVerified publisher1.0.01 of 1See more

shopsync shopsync 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
shyamkrishna21/shopsync:latest3998b83def53
body-parser@1.20.4
1.20.6

Open the chart page →

1,088
simple-db-app-chartsimple-db-app0.1.01 of 2See more

simple-db-app-chart simple-db-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
htmlprogrammer2001/simple-db-app:1.0a7e0a233a9bc
body-parser@1.19.1
1.20.6

Open the chart page →

1,925
simple-db-app-chart-with-dependencysimple-db-app0.1.01 of 3See more

simple-db-app-chart-with-dependency simple-db-app 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
htmlprogrammer2001/simple-db-app:1.0a7e0a233a9bc
body-parser@1.19.1
1.20.6

Open the chart page →

1,925
first-appsimple-helm-chart0.1.01 of 1See more

first-app simple-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
leeyoongti/first-app:1.0.021d66cb76352
body-parser@1.19.0
1.20.6

Open the chart page →

2,154
simple-node-expresssimple-node-express1.0.01 of 1See more

simple-node-express simple-node-express 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
devravinder/node-express-app:1.0.05325a96967b5
body-parser@1.20.3
1.20.6

Open the chart page →

752
skoonerskooner0.2.21 of 1See more

skooner skooner 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-12590.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
body-parser@1.20.1
1.20.6

Open the chart page →

1,341

Container images carrying it

522 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ktitilayo2/nodejswebapp:latest8bac28058688
body-parser@1.20.1
1.20.6
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
body-parser@1.20.0
1.20.6
1
kubebb/component-store:latestfd8ecbd73213
body-parser@1.20.1
1.20.6
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
body-parser@1.19.0
1.20.6
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
body-parser@1.20.2
1.20.6
1
kubevious/backend:1.2.22d9ba6eb46b6
body-parser@1.20.1
1.20.6
1
kubevious/collector:1.2.1f58226f9d84e
body-parser@1.20.1
1.20.6
1
kubevious/guard:1.2.19bf567704de2
body-parser@1.19.2
1.20.6
1
kubevious/parser:1.0.151acf1a1f0b47
body-parser@1.19.0
1.20.6
1
kubevious/parser:1.2.299ae7a5168c2
body-parser@1.20.1
1.20.6
1
kubevious/workload-operator:1.0.20b0f4c507eb6
body-parser@1.20.1
1.20.6
1
kyleslugg/klusterview:latestba8c36dfdfbd
body-parser@1.20.1
1.20.6
1
laly9999/node-app:1dd0e503913e1
body-parser@1.20.3
1.20.6
1
laly9999/node-app-dockerized:latest75ae77a20c6c
body-parser@1.20.1
1.20.6
1
lavandadelpatio/frontend:latest501c3f31e0bc
body-parser@1.19.0
1.20.6
1
lbenicio/stremio-web:latest732f9003de33
body-parser@1.20.5
1.20.6
1
leeyoongti/first-app:1.0.021d66cb76352
body-parser@1.19.0
1.20.6
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
body-parser@1.20.3
1.20.6
1
library/ghost:6.37.01ef2e532ca4d
body-parser@1.20.4
1.20.6
1
library/ghost:6.25.12654b1e90413
body-parser@1.20.3
1.20.6
1
library/ghost:6.41.129773d6be407
body-parser@2.2.2
2.3.0
1
library/ghost:4.37.0767230c0f263
body-parser@1.19.1
1.20.6
1
library/ghost:6.39.0-alpine77196da4b0df
body-parser@2.2.2
2.3.0
1
library/ghost:5.79.083f7bf209844
body-parser@1.20.2
1.20.6
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
body-parser@2.2.2
2.3.0
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
body-parser@1.20.1
1.20.6
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
body-parser@1.19.0
1.20.6
1
linuxserver/code-server:4.10.1a5e43a05ae79
body-parser@1.19.0
1.20.6
1
linuxserver/codimd:latestb801bbcf6386
body-parser@1.19.0
1.20.6
1
linuxserver/overseerr:1.35.06108ed066d4a
body-parser@1.20.1
1.20.6
1
lissy93/dashy:2.0.51991f7be5ed0
body-parser@1.19.1
1.20.6
1
litlyx/litlyx-consumer:latest02225e77d316
body-parser@1.20.3
1.20.6
1
litlyx/litlyx-producer:latest10407f36613f
body-parser@1.20.3
1.20.6
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
body-parser@1.20.4
1.20.6
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
body-parser@1.19.2
1.20.6
1
louislam/uptime-kuma:13d632903e6af
body-parser@1.20.3
1.20.6
1
louislam/uptime-kuma:2.0.24c364ef96aad
body-parser@1.20.3
1.20.6
1
louislam/uptime-kuma:2.4.091e963bfda56
body-parser@1.20.5
1.20.6
1
louislam/uptime-kuma:1.23.1396510915e6be
body-parser@1.20.2
1.20.6
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
body-parser@1.20.3
1.20.6
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
body-parser@1.19.2
1.20.6
1
louislam/uptime-kuma:1.18.5a84767d7934f
body-parser@1.19.2
1.20.6
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
body-parser@1.20.2
1.20.6
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
body-parser@1.20.1
1.20.6
1
luligu/matterbridge:3.0.28f97884bebc2
body-parser@2.2.0
2.3.0
1
maildev/maildev:2.2.1180ef51f65ee
body-parser@1.20.3
1.20.6
1
maissacrement/pock8snodejs:0.0.16da0db1159da
body-parser@1.20.1
1.20.6
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
body-parser@1.20.1
1.20.6
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
body-parser@1.19.0
1.20.6
1
microcks/microcks-postman-runtime:latestcb72e46a1b3c
body-parser@1.17.2
1.20.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.