StackRadar

CVE-2026-13676

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
105
of 17,781 indexed, latest versions
Container images
107
deployed by those charts
Fix available
1 of 2
affected packages

fast-uri vulnerable to host confusion via failed IDN canonicalization

Carried by container images the latest versions of 105 of 17,781 indexed charts deploy, on 107 images.

Affected packageAffected versionsFixed inImages
fast-urinpm2.4.0, 3.0.1, 3.0.2, 3.0.3+4 more2.4.2, 3.1.3104
node-ajvdeb6.10.2-1, 8.12.0~ds+~2.1.1-4no fix listed3
OSV records
GHSA-4c8g-83qw-93j6UBUNTU-CVE-2026-13676

Charts affected

105 by stars
ChartLatestAffected imagesRadar Score
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-13676.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
fast-uri@3.1.2
3.1.3

Open the chart page →

1,787
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-13676.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
fast-uri@3.1.0
3.1.3

Open the chart page →

2,076
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-13676.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
fast-uri@3.0.6
3.1.3

Open the chart page →

5,984
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-13676.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
fast-uri@3.1.2
3.1.3

Open the chart page →

280
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-13676.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
fast-uri@3.0.3
3.1.3

Open the chart page →

6,285

Container images carrying it

107 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
obolnetwork/charon-dkg-sidecar:maine263be0a7440
fast-uri@3.1.0
3.1.3
1
penpotapp/mcp:2.17.284f3f07ead11
fast-uri@3.1.2
3.1.3
1
qxip/qryn:3.2.3977acc9c7a9fd
fast-uri@3.0.1
3.1.3
1
rocketadmin/rocketadmin:1.17.710955ef540b9
fast-uri@3.1.0
3.1.3
1
rocketchat/account-service:8.6.144af8ac4e711
fast-uri@3.1.2
3.1.3
1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
fast-uri@3.1.2
3.1.3
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
fast-uri@3.1.2
3.1.3
1
rocketchat/presence-service:8.6.1c1170bdfe797
fast-uri@3.1.2
3.1.3
1
sigp/siren:v3.0.42c219b04758e
fast-uri@3.0.6
3.1.3
1
supabase/postgres-meta:v0.96.6a84cc713585e
fast-uri@3.0.6
3.1.3
1
supabase/storage-api:v1.60.4c8eb9858eafe
fast-uri@3.1.0
3.1.3
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-ajv@6.10.2-1
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
fast-uri@3.0.6
3.1.3
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
fast-uri@3.0.6
3.1.3
1
tensorzero/ui:2026.6.0f2563d54724e
fast-uri@3.1.2
3.1.3
1
tenureai/tenure:v1.0.285f5b222df9a5
fast-uri@3.1.2
3.1.3
1
th0th/node-red:4.0.3-debiand06fa39f7406
fast-uri@3.0.1
3.1.3
1
tiago2/cap:2.159f5ae4e261e
fast-uri@3.1.0
3.1.3
1
treskon/portrait-ui:DEV-lateste7970783bc8d
fast-uri@3.0.3
3.1.3
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
fast-uri@3.0.1
3.1.3
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
fast-uri@3.1.0
3.1.3
1
unleashorg/unleash-proxy:v1.4.82538f89e2685
fast-uri@3.0.2
3.1.3
1
unleashorg/unleash-server:7.5.09adb37e399ba
fast-uri@3.0.1
3.1.3
1
veecode/devportalc443520aebf7
fast-uri@3.1.2
3.1.3
1
wsjbr/duplistatus:1.4.25e594f5f09f6
fast-uri@3.1.2
3.1.3
1
yooooomi/your_spotify_client:1.20.0e4da90a0634c
fast-uri@3.1.2
3.1.3
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
fast-uri@3.1.0
3.1.3
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
fast-uri@3.1.2
3.1.3
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
fast-uri@3.0.1
3.1.3
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
fast-uri@3.0.1
3.1.3
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
fast-uri@3.0.6
3.1.3
1
ghcr.io/colanode/server:latest7006cac874fd
fast-uri@3.1.0
3.1.3
1
ghcr.io/data-fair/notify:3c739b74dabb0
fast-uri@3.0.6
3.1.3
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
fast-uri@3.1.2
3.1.3
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
fast-uri@3.1.0
3.1.3
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
fast-uri@3.1.0
3.1.3
1
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
fast-uri@3.0.6
3.1.3
1
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
fast-uri@3.1.2
3.1.3
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
fast-uri@3.0.6
3.1.3
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
fast-uri@3.0.6
3.1.3
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
fast-uri@3.1.2
3.1.3
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
fast-uri@3.1.2
3.1.3
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
fast-uri@3.1.2
3.1.3
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
fast-uri@3.1.2
3.1.3
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
fast-uri@3.0.1
3.1.3
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
fast-uri@3.0.1
3.1.3
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
fast-uri@3.1.0
3.1.3
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
fast-uri@3.0.1
3.1.3
1
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
fast-uri@3.1.2
3.1.3
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
fast-uri@3.1.0
3.1.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.