StackRadar

CVE-2026-13697

Critical

Advisory

Published 29 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
57
of 17,781 indexed, latest versions
Container images
52
deployed by those charts
Fix available
1 of 2
affected packages

undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives

Carried by container images the latest versions of 57 of 17,781 indexed charts deploy, on 52 images.

Affected packageAffected versionsFixed inImages
node-undicideb5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4, 5.26.3+dfsg1+~cs23.10.12-2+1 moreno fix listed9
undicinpm7.2.0, 7.3.0, 7.10.0, 7.11.0+14 more7.29.0, 8.9.044
OSV records
DEBIAN-CVE-2026-13697GHSA-4cwx-7wf7-3272UBUNTU-CVE-2026-13697

Charts affected

57 by stars
ChartLatestAffected imagesRadar Score
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-13697.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
undici@7.16.0
7.29.0

Open the chart page →

4,684
etherpadschoenwald0.3.01 of 1See more

etherpad schoenwald 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-13697.

Container imageDigestPackageFixed in
etherpad/etherpad:2.7.2b723fe5f2594
undici@7.25.0
7.29.0

Open the chart page →

2,133
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-13697.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
undici@8.1.0
8.9.0

Open the chart page →

1,991
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-13697.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
undici@7.12.0
7.29.0

Open the chart page →

1,313
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-13697.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
undici@7.28.0
7.29.0

Open the chart page →

9,556
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-13697.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
undici@7.28.0
7.29.0

Open the chart page →

5,550
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-13697.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.29.0

Open the chart page →

3,746

Container images carrying it

52 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
undici@7.12.0
7.29.0
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
undici@7.28.0
7.29.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.