StackRadar

CVE-2026-13149

High

Advisory

Published 30 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
921
of 17,781 indexed, latest versions
Container images
964
deployed by those charts
Fix available
1 of 2
affected packages

brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups

Carried by container images the latest versions of 921 of 17,781 indexed charts deploy, on 964 images.

Affected packageAffected versionsFixed inImages
node-brace-expansiondeb1.1.8-1, 1.1.11-1, 2.0.1+~1.1.0-1, 2.0.1+~1.1.0-2no fix listed6
brace-expansionnpm1.1.1, 1.1.2, 1.1.4, 1.1.6+17 more1.1.16, 2.1.2, 5.0.7964
OSV records
DEBIAN-CVE-2026-13149UBUNTU-CVE-2026-13149GHSA-3jxr-9vmj-r5cp

Charts affected

921 by stars
ChartLatestAffected imagesRadar Score
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
brace-expansion@2.0.2
2.1.2

Open the chart page →

30,159
rocketchatrocketchat-server7.0.24 of 12See more

rocketchat rocketchat-server 7.0.2

4 of the 12 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
rocketchat/account-service:8.6.144af8ac4e711
brace-expansion@1.1.11
1.1.16
rocketchat/authorization-service:8.6.16bc18fb5d0e5
brace-expansion@2.1.0
2.1.2
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
brace-expansion@2.0.2
2.1.2
rocketchat/presence-service:8.6.1c1170bdfe797
brace-expansion@2.1.0
2.1.2

Open the chart page →

12,279
opensearch-dashboardsopensearch-project-helm-chartsVerified publisher3.8.01 of 1See more

opensearch-dashboards opensearch-project-helm-charts 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
brace-expansion@1.1.15
1.1.16

Open the chart page →

280
penpotpenpotOfficialVerified publisher1.9.02 of 4See more

penpot penpot 1.9.0

2 of the 4 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
penpotapp/exporter:2.17.272a8061e8806
brace-expansion@5.0.6
5.0.7
penpotapp/mcp:2.17.284f3f07ead11
brace-expansion@5.0.6
5.0.7

Open the chart page →

4,314
node-rednode-redVerified publisher0.40.21 of 1See more

node-red node-red 0.40.2

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
nodered/node-red:4.1.2216e7403aab9
brace-expansion@2.0.1
2.1.2

Open the chart page →

2,172
mongo-expresscowboysysopVerified publisher7.0.01 of 1See more

mongo-express cowboysysop 7.0.0

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
library/mongo-express:1.0.21b23d7976f02
brace-expansion@2.0.1
2.1.2

Open the chart page →

1,210
difydoubanVerified publisher0.10.02 of 6See more

dify douban 0.10.0

2 of the 6 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.124e65e8a351a2
brace-expansion@2.0.1
2.1.2
langgenius/dify-web:1.10.1-fix.1c306ac577912
brace-expansion@2.0.2
2.1.2

Open the chart page →

19,391
difydify-helmVerified publisher0.38.03 of 11See more

dify dify-helm 0.38.0

3 of the 11 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
brace-expansion@2.0.2
2.1.2
langgenius/dify-api:1.16.1dcefa5f7c47c
brace-expansion@2.0.2
2.1.2
langgenius/dify-web:1.16.187dd47e4e28f
brace-expansion@2.0.2
2.1.2

Open the chart page →

22,002
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
unleashorg/unleash-server:7.5.09adb37e399ba
brace-expansion@2.0.2
2.1.2

Open the chart page →

2,059
verdaccioverdaccio4.35.11 of 1See more

verdaccio verdaccio 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
brace-expansion@5.0.4
5.0.7

Open the chart page →

215
actualbudgetcommunity-chartsVerified publisher1.9.41 of 1See more

actualbudget community-charts 1.9.4

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
brace-expansion@2.0.3
2.1.2

Open the chart page →

1,091
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.01 of 5See more

openproject openproject-helm-charts 13.11.0

1 of the 5 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
openproject/hocuspocus:release-338001b288dc1359dfb5
brace-expansion@2.0.2
2.1.2

Open the chart page →

19,926
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
brace-expansion@1.1.11
1.1.16

Open the chart page →

11,384
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
brace-expansion@1.1.11
1.1.16

Open the chart page →

7,210
apisix-ingress-controllerapisix1.3.11 of 2See more

apisix-ingress-controller apisix 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
brace-expansion@5.0.5
5.0.7

Open the chart page →

1,616
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
brace-expansion@5.0.5
5.0.7

Open the chart page →

9,203
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
brace-expansion@2.0.2
2.1.2

Open the chart page →

8,364
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
brace-expansion@5.0.6
5.0.7

Open the chart page →

5,660
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
brace-expansion@1.1.11
1.1.16

Open the chart page →

4,431
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
brace-expansion@1.1.11
1.1.16

Open the chart page →

5,352
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
brace-expansion@5.0.4
5.0.7

Open the chart page →

3,004
velero-uiotwldVerified publisher0.15.01 of 1See more

velero-ui otwld 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
otwld/velero-ui:0.10.2d1954b759e47
brace-expansion@2.0.2
2.1.2

Open the chart page →

1,332
supabasetokens-studioVerified publisher1.0.03 of 14See more

supabase tokens-studio 1.0.0

3 of the 14 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
supabase/postgres-meta:v0.84.2d0a96973e9f1
brace-expansion@1.1.11
1.1.16
supabase/storage-api:v1.12.0f983fb50bd95
brace-expansion@2.0.1
2.1.2
supabase/studio:20241021-9f9b08326d8070c55e9
brace-expansion@2.0.1
2.1.2

Open the chart page →

23,123
budibasebudibase0.0.0-master3 of 7See more

budibase budibase 0.0.0-master

3 of the 7 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
brace-expansion@2.0.2
2.1.2
budibase/database:2.1.0d90f656261c9
brace-expansion@5.0.4
5.0.7
budibase/worker:3.41.3de5e2e560ce8
brace-expansion@2.0.2
2.1.2

Open the chart page →

10,775
krokicowboysysopVerified publisher6.1.04 of 5See more

kroki cowboysysop 6.1.0

4 of the 5 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.29.1444805c4b917
brace-expansion@2.0.2
2.1.2
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
brace-expansion@2.0.2
2.1.2
yuzutech/kroki-excalidraw:0.29.157917319ea70
brace-expansion@2.0.2
2.1.2
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
brace-expansion@2.0.2
2.1.2

Open the chart page →

6,743
n8nn8n0.23.01 of 1See more

n8n n8n 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
n8nio/n8n:1.33.1dd171d45102a
brace-expansion@2.0.1
2.1.2

Open the chart page →

5,639
openclawopenclawVerified publisher1.91.31 of 2See more

openclaw openclaw 1.91.3

1 of the 2 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
brace-expansion@5.0.6
5.0.7

Open the chart page →

2,977
sorry-cypresssorry-cypressVerified publisher1.20.02 of 4See more

sorry-cypress sorry-cypress 1.20.0

2 of the 4 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-api:2.5.11afaa5a84051d
brace-expansion@1.1.11
1.1.16
agoldis/sorry-cypress-director:2.5.1110228ecd353b
brace-expansion@2.0.1
2.1.2

Open the chart page →

4,285
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
brace-expansion@5.0.6
5.0.7

Open the chart page →

2,938
umamichristianhuthVerified publisher7.13.01 of 2See more

umami christianhuth 7.13.0

1 of the 2 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
brace-expansion@2.0.2
2.1.2

Open the chart page →

2,367
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
brace-expansion@1.1.11
1.1.16

Open the chart page →

4,577
echo-serverealenn0.5.01 of 1See more

echo-server ealenn 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
ealen/echo-server:0.6.0359761caae37
brace-expansion@1.1.11
1.1.16

Open the chart page →

766
ilumilumOfficialVerified publisher6.7.31 of 19See more

ilum ilum 6.7.3

1 of the 19 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
ilum/ui:6.7.3998937726679
brace-expansion@2.0.2
2.1.2

Open the chart page →

23,228
homepagem0nsterrr-homepageVerified publisher5.3.01 of 1See more

homepage m0nsterrr-homepage 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v2.3.0f82027665453
brace-expansion@2.0.2
2.1.2

Open the chart page →

352
microcksmicrocksOfficialVerified publisher0.8.0-helm-3.kube-1.171 of 5See more

microcks microcks 0.8.0-helm-3.kube-1.17

1 of the 5 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
microcks/microcks-postman-runtime:latestcb72e46a1b3c
brace-expansion@1.1.6
1.1.16

Open the chart page →

10,732
netris-controllernetrisai2.8.22 of 14See more

netris-controller netrisai 2.8.2

2 of the 14 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
brace-expansion@1.1.11
1.1.16
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
brace-expansion@2.0.2
2.1.2

Open the chart page →

30,326
homarroben01Verified publisher1.4.01 of 1See more

homarr oben01 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
brace-expansion@2.0.1
2.1.2

Open the chart page →

2,581
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
openmined/syft-frontend:0.9.5d11524a3854a
brace-expansion@2.0.1
2.1.2

Open the chart page →

17,245
umamiwaldo-visionVerified publisher0.0.11 of 1See more

umami waldo-vision 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v1.39.560fa8875aff8
brace-expansion@2.0.1
2.1.2

Open the chart page →

1,255
lighthouse-cicowboysysopVerified publisher9.0.01 of 1See more

lighthouse-ci cowboysysop 9.0.0

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
patrickhulce/lhci-server:0.8.174b4b6a3954d
brace-expansion@1.1.11
1.1.16

Open the chart page →

2,213
uptime-kumaduyet0.1.71 of 1See more

uptime-kuma duyet 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.18.5a84767d7934f
brace-expansion@2.0.1
2.1.2

Open the chart page →

4,515
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
brace-expansion@2.0.2
2.1.2

Open the chart page →

5,564
redisinsightheywood8-helm-chartsVerified publisher0.4.51 of 1See more

redisinsight heywood8-helm-charts 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
heywood8/redisinsight:2.28.00bc9ab313d37
brace-expansion@2.0.1
2.1.2

Open the chart page →

2,828
redisinsightredisinsight-guiVerified publisher1.3.51 of 1See more

redisinsight redisinsight-gui 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
redis/redisinsight:3.8b5e19ee240ab
brace-expansion@2.0.2
2.1.2

Open the chart page →

1,038
redisinsight-secureredisinsight-secureVerified publisher1.0.21 of 1See more

redisinsight-secure redisinsight-secure 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
redis/redisinsight:2.68019fcf774631
brace-expansion@2.0.1
2.1.2

Open the chart page →

1,721
servarrservarr1.0.21 of 10See more

servarr servarr 1.0.2

1 of the 10 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
brace-expansion@1.1.11
1.1.16

Open the chart page →

14,238
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
brace-expansion@1.1.11
1.1.16

Open the chart page →

6,168
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
brace-expansion@1.1.11
1.1.16

Open the chart page →

5,251
carbonetes-analyzercarbonetes-analyzerVerified publisher1.0.61 of 1See more

carbonetes-analyzer carbonetes-analyzer 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
brace-expansion@1.1.11
1.1.16

Open the chart page →

1,829
fadicetic0.3.11 of 25See more

fadi cetic 0.3.1

1 of the 25 container images this version deploys carry CVE-2026-13149.

Container imageDigestPackageFixed in
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
brace-expansion@1.1.11
1.1.16

Open the chart page →

52,919

Container images carrying it

964 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
brace-expansion@1.1.11
1.1.16
5
decisionrules/server:latestf38d8571fa06
brace-expansion@2.0.2
2.1.2
4
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
brace-expansion@1.1.8
1.1.16
4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
brace-expansion@1.1.8
1.1.16
4
kodekloud/examplevotingapp_result:v1e510023fdf38
brace-expansion@1.1.11
1.1.16
4
oscarsotosanchez/server:v1.06e2e1279126b
brace-expansion@1.1.11
1.1.16
4
oscarsotosanchez/weatherservice:v1.0911ec961d10b
brace-expansion@1.1.11
1.1.16
4
redis/redisinsight:3.8:latestb5e19ee240ab
brace-expansion@2.0.2
2.1.2
4
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
brace-expansion@2.0.1
2.1.2
4
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
brace-expansion@1.1.11
1.1.16
4
assistiot/dlt_api:2.0.0e36a8922fa0c
brace-expansion@1.1.11
1.1.16
3
dgraph/dgraph:v21.12.03b55ea83fffe
brace-expansion@1.1.11
1.1.16
3
frankescobar/allure-docker-service-ui:7.0.3:latest4ebd8b4ef340
brace-expansion@1.1.11
1.1.16
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
brace-expansion@1.1.11
1.1.16
3
pantsel/konga:latestc8172b75607d
brace-expansion@1.1.8
1.1.16
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
brace-expansion@2.0.1
2.1.2
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
brace-expansion@1.1.11
1.1.16
3
ghcr.io/kamilkisiela/graphql-hive/emails:59b64c36c866b3555c135c70de76a884e63f86197d2d6d7c099a
brace-expansion@2.0.1
2.1.2
3
ghcr.io/kamilkisiela/graphql-hive/schema:59b64c36c866b3555c135c70de76a884e63f8619931d1f6e5ad4
brace-expansion@1.1.11
1.1.16
3
ghcr.io/kamilkisiela/graphql-hive/server:59b64c36c866b3555c135c70de76a884e63f86196d3899d281cc
brace-expansion@1.1.11
1.1.16
3
ghcr.io/kamilkisiela/graphql-hive/storage:59b64c36c866b3555c135c70de76a884e63f86199808dac13353
brace-expansion@1.1.11
1.1.16
3
ghcr.io/kamilkisiela/graphql-hive/tokens:59b64c36c866b3555c135c70de76a884e63f86190f3416d940b4
brace-expansion@2.0.1
2.1.2
3
ghcr.io/kamilkisiela/graphql-hive/usage:59b64c36c866b3555c135c70de76a884e63f861953619ee7614e
brace-expansion@1.1.11
1.1.16
3
ghcr.io/kamilkisiela/graphql-hive/usage-ingestor:59b64c36c866b3555c135c70de76a884e63f861947b87c071af4
brace-expansion@1.1.11
1.1.16
3
ghcr.io/kamilkisiela/graphql-hive/webhooks:59b64c36c866b3555c135c70de76a884e63f861918a5c5b5b671
brace-expansion@2.0.1
2.1.2
3
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
brace-expansion@2.0.2
2.1.2
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
brace-expansion@5.0.4
5.0.7
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
brace-expansion@1.1.12
1.1.16
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
brace-expansion@5.0.6
5.0.7
3
actualbudget/actual-server:26.9.0552beab3dec8
brace-expansion@2.0.3
2.1.2
2
agoldis/sorry-cypress-api:2.5.11afaa5a84051d
brace-expansion@1.1.11
1.1.16
2
agoldis/sorry-cypress-director:2.5.1110228ecd353b
brace-expansion@2.0.1
2.1.2
2
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
brace-expansion@1.1.11
1.1.16
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
brace-expansion@1.1.11
1.1.16
2
epamedp/krci-portal:0.8.0687acf641097
brace-expansion@5.0.6
5.0.7
2
ethersphere/bee-localchain:latest0558799ca992
brace-expansion@2.0.1
2.1.2
2
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
brace-expansion@1.1.11
1.1.16
2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
brace-expansion@1.1.11
1.1.16
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
brace-expansion@1.1.11
1.1.16
2
governify/assets-manager:v1.4.12987672448c7
brace-expansion@1.1.11
1.1.16
2
governify/director:v1.4.0608c6940bb98
brace-expansion@1.1.11
1.1.16
2
governify/registry:v3.4.0d3f37f4f8168
brace-expansion@1.1.11
1.1.16
2
governify/render:v2.2.0daeca1ce28e6
brace-expansion@1.1.11
1.1.16
2
governify/reporter:v2.2.038595913458f
brace-expansion@1.1.11
1.1.16
2
gradiant/open5gs-webui:2.7.5fbd10c017541
brace-expansion@1.1.11
1.1.16
2
hookiesolutions/webhookie:latest0629694246ba
brace-expansion@1.1.11
1.1.16
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
brace-expansion@2.0.1
2.1.2
2
htmlprogrammer2001/simple-db-app:1.0a7e0a233a9bc
brace-expansion@1.1.11
1.1.16
2
ilum/ui:6.7.3998937726679
brace-expansion@2.0.2
2.1.2
2
infisical/infisical:latest:v0.165.602082bf13163
brace-expansion@2.0.1
2.1.2
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.