StackRadar

CVE-2026-1527

Medium

Advisory

Published 12 Mar 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.6
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
82
of 17,781 indexed, latest versions
Container images
76
deployed by those charts
Fix available
1 of 2
affected packages

Undici has CRLF Injection in undici via `upgrade` option

Carried by container images the latest versions of 82 of 17,781 indexed charts deploy, on 76 images.

Affected packageAffected versionsFixed inImages
undicinpm4.15.0, 5.6.0, 5.11.0, 5.12.0+29 more6.24.0, 7.24.076
node-undicideb5.26.3+dfsg1+~cs23.10.12-2, 7.3.0+dfsg1+~cs24.12.11-1no fix listed2
OSV records
DEBIAN-CVE-2026-1527GHSA-4992-7rv2-5pvqUBUNTU-CVE-2026-1527

Charts affected

82 by stars
ChartLatestAffected imagesRadar Score
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
undici@7.3.0
7.24.0

Open the chart page →

3,555
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
undici@7.16.0
7.24.0

Open the chart page →

2,457
finance-portalmojaloop5.1.42 of 11See more

finance-portal mojaloop 5.1.4

2 of the 11 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
undici@7.11.0
7.24.0
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
undici@7.10.0
7.24.0

Open the chart page →

14,809
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
undici@7.11.0
7.24.0

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
undici@7.10.0
7.24.0

Open the chart page →

2,318
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
undici@7.16.0
7.24.0

Open the chart page →

2,457
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
undici@5.22.1
6.24.0

Open the chart page →

4,960
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
undici@6.23.0
6.24.0

Open the chart page →

2,383
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
undici@5.28.2
6.24.0

Open the chart page →

6,282
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
undici@6.21.3
6.24.0

Open the chart page →

5,338
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
undici@5.28.4
6.24.0

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
undici@5.28.4
6.24.0

Open the chart page →

16,620
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
undici@6.22.0
6.24.0

Open the chart page →

4,684
k8soketisoketi1.0.11 of 1See more

k8soketi soketi 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
undici@5.11.0
6.24.0

Open the chart page →

2,267
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
undici@5.28.4
6.24.0

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
undici@5.28.4
6.24.0

Open the chart page →

16,400
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
undici@5.26.3
6.24.0

Open the chart page →

14,679
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
undici@5.28.4
6.24.0

Open the chart page →

16,400
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4691 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

1 of the 5 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
undici@5.28.3
6.24.0

Open the chart page →

14,221
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
undici@5.28.3
6.24.0

Open the chart page →

14,221
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
undici@5.28.4
6.24.0

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
undici@5.28.4
6.24.0

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
undici@5.28.4
6.24.0

Open the chart page →

11,100
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
undici@7.12.0
7.24.0

Open the chart page →

1,313
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
undici@5.24.0
6.24.0

Open the chart page →

13,719
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
undici@5.6.0
6.24.0

Open the chart page →

4,017
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
undici@5.28.4
6.24.0

Open the chart page →

28,814
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
undici@5.29.0
6.24.0

Open the chart page →

3,576
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
undici@6.21.1
6.24.0

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.24.0

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
undici@5.29.0
6.24.0

Open the chart page →

1,787
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-1527.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
undici@6.19.2
6.24.0

Open the chart page →

6,285

Container images carrying it

76 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
undici@5.12.0
6.24.0
3
ethersphere/bee-localchain:latest0558799ca992
undici@5.28.3
6.24.0
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
undici@5.28.4
6.24.0
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
undici@7.11.0
7.24.0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
undici@7.10.0
7.24.0
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
undici@7.16.0
7.24.0
2
rajnandan1/kener:3.2.1930407afca731
undici@6.21.1
6.24.0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
undici@5.22.0
6.24.0
2
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
undici@5.28.3
6.24.0
1
budibase/apps:3.41.344fe6feab985
undici@6.21.3
6.24.0
1
catalysm/csmm:latestf003b35f54d9
undici@5.29.0
6.24.0
1
cryptexlabs/authf:0.12.11189c07411d7c
undici@6.19.8
6.24.0
1
cspconsole/report-processor:1.0.279a2d8840bfdf
undici@5.29.0
6.24.0
1
deconzcommunity/deconz:2.29.2062de2362641
undici@5.15.0
6.24.0
1
directus/directus:11.1.0e3c8bb975350
undici@6.19.5
6.24.0
1
diygod/rsshub:2025-11-097a6312cac0d5
undici@6.22.0
6.24.0
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
undici@4.15.0
6.24.0
1
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.24.0
1
fallenbagel/jellyseerr:latest4538137bc5af
undici@7.3.0
7.24.0
1
felddy/foundryvtt:12.343.06c5e3e9ffbb0
undici@6.19.7
6.24.0
1
globalping/globalping-probe:latest8acbd23009fd
undici@5.29.0
6.24.0
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
undici@6.21.2
6.24.0
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-undici@5.26.3+dfsg1+~cs23.10.12-2
undici@5.26.3
no fix listed
6.24.0
1
kubebb/component-store:latestfd8ecbd73213
undici@5.22.1
6.24.0
1
langgenius/dify-api:1.0.0066035f93856
undici@5.15.0
6.24.0
1
langgenius/dify-api:0.6.11fca918260dd6
undici@5.15.0
6.24.0
1
library/ghost:6.25.12654b1e90413
undici@5.22.1
6.24.0
1
library/ghost:5.79.083f7bf209844
undici@5.22.1
6.24.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
undici@5.22.1
6.24.0
1
library/kibana:8.18.004c0fc150f3a
undici@6.19.2
6.24.0
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
undici@6.23.0
6.24.0
1
louislam/uptime-kuma:2.0.24c364ef96aad
undici@6.22.0
6.24.0
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
undici@6.22.0
6.24.0
1
n8nio/n8n:1.86.08b39ed5a2de9
undici@5.28.5
6.24.0
1
n8nio/n8n:1.33.1dd171d45102a
undici@6.9.0
6.24.0
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
undici@5.15.0
6.24.0
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
undici@5.15.0
6.24.0
1
opea/codegen-ui:1.02bee4eb66f3e
undici@5.28.4
6.24.0
1
openhab/openhab:5.2.1bfd4a60e90da
node-undici@7.3.0+dfsg1+~cs24.12.11-1
undici@7.3.0
no fix listed
7.24.0
1
openmined/syft-frontend:0.9.5d11524a3854a
undici@6.11.1
6.24.0
1
polonel/trudesk:1.2.60cf6513f6fe3
undici@5.6.0
6.24.0
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
undici@5.15.0
6.24.0
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
undici@5.26.3
6.24.0
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
undici@5.28.4
6.24.0
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
undici@5.28.4
6.24.0
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
undici@5.28.4
6.24.0
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
undici@5.28.4
6.24.0
1
speckle/speckle-server:2.26.379f14a2bf931
undici@5.29.0
6.24.0
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
undici@5.28.3
6.24.0
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
undici@5.28.4
6.24.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.