StackRadar

CVE-2026-15074

High

Advisory

Published 24 Jul 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
1 of 1
affected package

@fastify/static vulnerable to route guard bypass via path traversal

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
@fastify/staticnpm6.12.0, 7.0.3, 7.0.4, 8.0.1+4 more10.1.118
OSV records
GHSA-83w8-p2f5-377r

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
supabasetokens-studioVerified publisher1.0.01 of 14See more

supabase tokens-studio 1.0.0

1 of the 14 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
supabase/storage-api:v1.12.0f983fb50bd95
@fastify/static@7.0.4
10.1.1

Open the chart page →

23,123
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
@fastify/static@9.1.3
10.1.1

Open the chart page →

5,564
foremancontane-githubOfficialVerified publisher0.6.01 of 1See more

foreman contane-github 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
contane/foreman:0.5.2efb98bdcc4e9
@fastify/static@8.2.0
10.1.1

Open the chart page →

1,152
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
@fastify/static@6.12.0
10.1.1

Open the chart page →

2,635
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
@fastify/static@7.0.3
10.1.1

Open the chart page →

5,654
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
supabase/storage-api:v1.60.4c8eb9858eafe
@fastify/static@9.1.3
10.1.1

Open the chart page →

18,075
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
@fastify/static@9.1.3
10.1.1

Open the chart page →

2,522
trifidzazukoOfficialVerified publisher0.2.11 of 1See more

trifid zazuko 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
@fastify/static@9.1.3
10.1.1

Open the chart page →

338
activepiecesadnoctemVerified publisher0.5.01 of 1See more

activepieces adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
activepieces/activepieces:0.90.430c10a04fe3d
@fastify/static@8.3.0
10.1.1

Open the chart page →

1,055
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
@fastify/static@9.1.3
10.1.1

Open the chart page →

2,033
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
@fastify/static@9.1.3
10.1.1

Open the chart page →

839
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
@fastify/static@8.0.1
10.1.1

Open the chart page →

2,522
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
@fastify/static@6.12.0
10.1.1

Open the chart page →

2,973
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
@fastify/static@9.1.3
10.1.1

Open the chart page →

3,014
mongo-compassmongo-compass-webVerified publisher1.1.41 of 1See more

mongo-compass mongo-compass-web 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.1f4f8fe4e21f1
@fastify/static@8.3.0
10.1.1

Open the chart page →

1,759
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
@fastify/static@8.3.0
10.1.1

Open the chart page →

2,396
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
@fastify/static@9.0.0
10.1.1

Open the chart page →

1,166
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
@fastify/static@9.1.3
10.1.1

Open the chart page →

5,819
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
@fastify/static@9.1.3
10.1.1

Open the chart page →

3,014
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-15074.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
@fastify/static@8.0.1
10.1.1

Open the chart page →

4,052

Container images carrying it

18 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
epamedp/krci-portal:0.8.0687acf641097
@fastify/static@9.1.3
10.1.1
2
infisical/infisical:latest:v0.165.602082bf13163
@fastify/static@9.1.3
10.1.1
2
activepieces/activepieces:0.90.430c10a04fe3d
@fastify/static@8.3.0
10.1.1
1
activepieces/activepieces:0.23.0c26188b44e62
@fastify/static@6.12.0
10.1.1
1
chainsafe/lodestar:latest5593f6e97912
@fastify/static@8.0.1
10.1.1
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
@fastify/static@8.0.1
10.1.1
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
@fastify/static@7.0.3
10.1.1
1
contane/foreman:0.5.2efb98bdcc4e9
@fastify/static@8.2.0
10.1.1
1
docmost/docmost:0.95.041c8d777cf23
@fastify/static@9.1.3
10.1.1
1
haohanyang/compass-web:0.5.054f2112602ee
@fastify/static@8.3.0
10.1.1
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
@fastify/static@8.3.0
10.1.1
1
neoskop/ixy:2.1.125152b474f54
@fastify/static@9.0.0
10.1.1
1
qxip/qryn:3.2.3977acc9c7a9fd
@fastify/static@6.12.0
10.1.1
1
supabase/storage-api:v1.60.4c8eb9858eafe
@fastify/static@9.1.3
10.1.1
1
supabase/storage-api:v1.12.0f983fb50bd95
@fastify/static@7.0.4
10.1.1
1
tenureai/tenure:v1.0.285f5b222df9a5
@fastify/static@9.1.3
10.1.1
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
@fastify/static@9.1.3
10.1.1
1
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
@fastify/static@9.1.3
10.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.