StackRadar

CVE-2026-14643

High

Advisory

Published 29 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
23rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
57
of 17,781 indexed, latest versions
Container images
52
deployed by those charts
Fix available
1 of 2
affected packages

undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives

Carried by container images the latest versions of 57 of 17,781 indexed charts deploy, on 52 images.

Affected packageAffected versionsFixed inImages
node-undicideb5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4, 5.26.3+dfsg1+~cs23.10.12-2+1 moreno fix listed9
undicinpm7.2.0, 7.3.0, 7.10.0, 7.11.0+14 more7.29.0, 8.9.044
OSV records
DEBIAN-CVE-2026-14643GHSA-jr45-8vmc-qm54UBUNTU-CVE-2026-14643

Charts affected

57 by stars
ChartLatestAffected imagesRadar Score
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-14643.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
undici@7.16.0
7.29.0

Open the chart page →

4,684
etherpadschoenwald0.3.01 of 1See more

etherpad schoenwald 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-14643.

Container imageDigestPackageFixed in
etherpad/etherpad:2.7.2b723fe5f2594
undici@7.25.0
7.29.0

Open the chart page →

2,133
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-14643.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
undici@8.1.0
8.9.0

Open the chart page →

1,991
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-14643.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
undici@7.12.0
7.29.0

Open the chart page →

1,313
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-14643.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
undici@7.28.0
7.29.0

Open the chart page →

9,556
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-14643.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
undici@7.28.0
7.29.0

Open the chart page →

5,550
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-14643.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.29.0

Open the chart page →

3,746

Container images carrying it

52 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
undici@8.1.0
8.9.0
3
library/ghost:6.63.0e05bc1169fb2
undici@7.28.0
7.29.0
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
undici@7.11.0
7.29.0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
undici@7.10.0
7.29.0
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
undici@7.16.0
7.29.0
2
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
undici@7.24.1
7.29.0
1
deconzcommunity/deconz:2.29.2062de2362641
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
no fix listed
1
directus/directus:12.0.29c8470ea465c
undici@7.24.5
7.29.0
1
diygod/rsshub:2025-11-097a6312cac0d5
undici@7.16.0
7.29.0
1
docmost/docmost:0.95.041c8d777cf23
undici@7.28.0
7.29.0
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
undici@7.24.7
7.29.0
1
etherpad/etherpad:2.7.2b723fe5f2594
undici@7.25.0
7.29.0
1
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.29.0
1
fallenbagel/jellyseerr:latest4538137bc5af
undici@7.3.0
7.29.0
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
undici@7.24.4
7.29.0
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-undici@5.26.3+dfsg1+~cs23.10.12-2
no fix listed
1
langgenius/dify-api:1.0.0066035f93856
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3
no fix listed
1
library/ghost:6.37.01ef2e532ca4d
undici@7.25.0
7.29.0
1
library/ghost:6.25.12654b1e90413
undici@7.24.4
7.29.0
1
library/ghost:6.41.129773d6be407
undici@7.25.0
7.29.0
1
library/ghost:6.39.0-alpine77196da4b0df
undici@7.25.0
7.29.0
1
library/ghost:6.62.0a7a268bbfb7f
undici@7.28.0
7.29.0
1
n8nio/n8n:2.25.7761374d4eb84
undici@7.24.6
7.29.0
1
nocodb/nocodb:0.301.5d9516f0bf546
undici@7.24.4
7.29.0
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
no fix listed
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
no fix listed
1
openhab/openhab:5.2.1bfd4a60e90da
node-undici@7.3.0+dfsg1+~cs24.12.11-1
undici@7.3.0
no fix listed
7.29.0
1
penpotapp/exporter:2.17.272a8061e8806
undici@8.5.0
8.9.0
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1
no fix listed
1
shieldsio/shields:nextfa194b446e42
undici@8.8.0
8.9.0
1
supabase/storage-api:v1.60.4c8eb9858eafe
undici@7.24.6
7.29.0
1
supabase/storage-api:latestf6c42a04163d
undici@7.28.0
7.29.0
1
twentycrm/twenty:v2.22.0e7d9948bf284
undici@7.28.0
7.29.0
1
xxczaki/discord-bot:e9f46b6aebac02e7b96ed41a3f62b26e871cf009bb919aac45dc
undici@8.3.0
8.9.0
1
ghcr.io/calesthio/crucix:latest67c5244b6acf
undici@7.24.4
7.29.0
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
undici@7.3.0
7.29.0
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
undici@7.3.0
7.29.0
1
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
undici@8.5.0
8.9.0
1
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
undici@7.28.0
7.29.0
1
ghcr.io/homarr-labs/homarr:v1.77.0f23ad77a681b
undici@7.28.0
7.29.0
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
no fix listed
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
undici@7.11.0
7.29.0
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
undici@7.28.0
7.29.0
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
undici@8.3.0
8.9.0
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
undici@8.5.0
8.9.0
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
undici@7.18.2
7.29.0
1
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
undici@7.28.0
7.29.0
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
undici@7.2.0
7.29.0
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
undici@8.5.0
8.9.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.