StackRadar

CVE-2026-13676

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
105
of 17,781 indexed, latest versions
Container images
107
deployed by those charts
Fix available
1 of 2
affected packages

fast-uri vulnerable to host confusion via failed IDN canonicalization

Carried by container images the latest versions of 105 of 17,781 indexed charts deploy, on 107 images.

Affected packageAffected versionsFixed inImages
fast-urinpm2.4.0, 3.0.1, 3.0.2, 3.0.3+4 more2.4.2, 3.1.3104
node-ajvdeb6.10.2-1, 8.12.0~ds+~2.1.1-4no fix listed3
OSV records
GHSA-4c8g-83qw-93j6UBUNTU-CVE-2026-13676

Charts affected

105 by stars
ChartLatestAffected imagesRadar Score
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-13676.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
fast-uri@3.1.2
3.1.3

Open the chart page →

1,787
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-13676.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
fast-uri@3.1.0
3.1.3

Open the chart page →

2,076
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-13676.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
fast-uri@3.0.6
3.1.3

Open the chart page →

5,984
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-13676.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
fast-uri@3.1.2
3.1.3

Open the chart page →

280
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-13676.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
fast-uri@3.0.3
3.1.3

Open the chart page →

6,285

Container images carrying it

107 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
fast-uri@3.0.6
3.1.3
1
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
fast-uri@3.1.2
3.1.3
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
fast-uri@3.0.5
3.1.3
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
fast-uri@3.1.0
3.1.3
1
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
fast-uri@3.1.2
3.1.3
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
fast-uri@3.1.0
3.1.3
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
fast-uri@3.1.0
3.1.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.