StackRadar

CVE-2026-15603

Medium

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
85
of 17,781 indexed, latest versions
Container images
84
deployed by those charts
Fix available
1 of 1
affected package

morgan vulnerable to Log Forging via unescaped Unicode line separators

Carried by container images the latest versions of 85 of 17,781 indexed charts deploy, on 84 images.

Affected packageAffected versionsFixed inImages
morgannpm1.6.1, 1.7.0, 1.9.0, 1.9.1+3 more1.12.084
OSV records
GHSA-jxfw-x594-9x9m

Charts affected

85 by stars
ChartLatestAffected imagesRadar Score
hoppscotchhelmforgeVerified publisher1.1.111 of 2See more

hoppscotch helmforge 1.1.11

1 of the 2 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2026.8.0d50725df661f
morgan@1.11.0
1.12.0

Open the chart page →

2,046
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
morgan@1.10.1
1.12.0

Open the chart page →

6,012
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
morgan@1.10.0
1.12.0

Open the chart page →

4,944
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
morgan@1.9.1
1.12.0

Open the chart page →

10,494
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
morgan@1.10.0
1.12.0

Open the chart page →

7,232
hello-kubernetes-chartjhidalgo3-githubVerified publisher3.0.01 of 1See more

hello-kubernetes-chart jhidalgo3-github 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
morgan@1.10.0
1.12.0

Open the chart page →

914
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
morgan@1.6.1
1.12.0

Open the chart page →

6,454
zwave-js-uik8sonlabVerified publisher0.7.121 of 1See more

zwave-js-ui k8sonlab 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
zwavejs/zwave-js-ui:11.22.314d018bb689e
morgan@1.10.1
1.12.0

Open the chart page →

973
keycloak-multi-client-notifierkeycloak-multi-client-notifier2.1.21 of 2See more

keycloak-multi-client-notifier keycloak-multi-client-notifier 2.1.2

1 of the 2 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
morgan@1.10.1
1.12.0

Open the chart page →

1,473
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
morgan@1.10.0
1.12.0

Open the chart page →

1,927
workload-operatorkubevious0.0.31 of 1See more

workload-operator kubevious 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
kubevious/workload-operator:1.0.20b0f4c507eb6
morgan@1.10.0
1.12.0

Open the chart page →

2,008
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
morgan@1.10.0
1.12.0

Open the chart page →

9,668
littlelink-servermhamzahkhanVerified publisher1.0.01 of 1See more

littlelink-server mhamzahkhan 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
ghcr.io/techno-tim/littlelink-server:latest735a1fcd078b
morgan@1.10.0
1.12.0

Open the chart page →

887
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
library/mongo-express:latest1b23d7976f02
morgan@1.10.0
1.12.0

Open the chart page →

5,179
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
morgan@1.10.0
1.12.0

Open the chart page →

4,560
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
morgan@1.10.0
1.12.0

Open the chart page →

3,128
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
morgan@1.7.0
1.12.0
socialmediamacroscope/smile_server:0.3.31a528c794270
morgan@1.9.1
1.12.0

Open the chart page →

109,294
node-hostnamenode-hostnameVerified publisher1.0.11 of 1See more

node-hostname node-hostname 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
christianhuth/node-hostname:1.0.1c07f414a3e4b
morgan@1.9.1
1.12.0

Open the chart page →

884
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
morgan@1.10.0
1.12.0

Open the chart page →

27,465
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
morgan@1.10.0
1.12.0

Open the chart page →

838
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
morgan@1.9.1
1.12.0

Open the chart page →

6,524
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
morgan@1.10.1
1.12.0

Open the chart page →

4,600
jsonplaceholderrgnu1.0.01 of 1See more

jsonplaceholder rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
svenwal/jsonplaceholder:latestba2f285af432
morgan@1.10.0
1.12.0

Open the chart page →

1,547
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
morgan@1.9.1
1.12.0

Open the chart page →

5,215
samplesample0.1.01 of 2See more

sample sample 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
library/mongo-express:1.0.2-20-alpine3.191aae00775251
morgan@1.10.0
1.12.0

Open the chart page →

2,309
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
morgan@1.10.0
1.12.0

Open the chart page →

3,118
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
morgan@1.6.1
1.12.0

Open the chart page →

3,638
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
morgan@1.11.0
1.12.0

Open the chart page →

2,638
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
morgan@1.10.0
1.12.0

Open the chart page →

3,881
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
morgan@1.10.1
1.12.0

Open the chart page →

3,972
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
morgan@1.10.0
1.12.0

Open the chart page →

3,576
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
morgan@1.10.1
1.12.0

Open the chart page →

4,768
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
morgan@1.10.0
1.12.0

Open the chart page →

3,129
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
morgan@1.10.0
1.12.0

Open the chart page →

3,118
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-15603.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
morgan@1.10.0
1.12.0

Open the chart page →

16,083

Container images carrying it

84 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
pantsel/konga:latestc8172b75607d
morgan@1.6.1
1.12.0
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
morgan@1.11.0
1.12.0
3
gradiant/open5gs-webui:2.7.5fbd10c017541
morgan@1.10.0
1.12.0
2
krtk6160/galoy-nostrcc82a694f818
morgan@1.10.0
1.12.0
2
library/mongo-express:1.0.2:latest1b23d7976f02
morgan@1.10.0
1.12.0
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
morgan@1.10.0
1.12.0
2
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
morgan@1.10.0
1.12.0
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
morgan@1.10.0
1.12.0
2
anoopnair/lifecycle-jira-integration:latestd80c73a6089d
morgan@1.10.0
1.12.0
1
automatischio/automatisch:0.15.03bace7a12d5f
morgan@1.10.0
1.12.0
1
bicarus/http-https-echo:2785dd6a7e805e
morgan@1.10.0
1.12.0
1
catalysm/csmm:latestf003b35f54d9
morgan@1.10.0
1.12.0
1
chocobozzz/peertube:v8.1.5052712130691
morgan@1.10.1
1.12.0
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
morgan@1.9.1
1.12.0
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
morgan@1.10.0
1.12.0
1
dacinfomotion/h2p:latest68fa393b472c
morgan@1.10.0
1.12.0
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
morgan@1.10.0
1.12.0
1
enketo/enketo-express:3.0.4dcad9c2273f6
morgan@1.10.0
1.12.0
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
morgan@1.10.0
1.12.0
1
fanzynoodle/smeejas:0.0.15f9916c1a287
morgan@1.10.0
1.12.0
1
fiware/idm:8.3.3a1b6ed4ae84f
morgan@1.10.0
1.12.0
1
foggbh/stocky:latest8b7a2e5ecf4e
morgan@1.10.1
1.12.0
1
gristlabs/grist:0.7.96e71b1914a7e
morgan@1.9.1
1.12.0
1
hoppscotch/hoppscotch:2026.8.0d50725df661f
morgan@1.11.0
1.12.0
1
inseefrlab/shelly:cloudshell31f04ca7436b
morgan@1.9.1
1.12.0
1
jayfong/yapi:1.10.2163e5d621910
morgan@1.6.1
1.12.0
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
morgan@1.10.0
1.12.0
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
morgan@1.10.0
1.12.0
1
konradkleine/docker-registry-frontend:v2181aad54ee64
morgan@1.6.1
1.12.0
1
kubevious/backend:1.2.22d9ba6eb46b6
morgan@1.10.0
1.12.0
1
kubevious/collector:1.2.1f58226f9d84e
morgan@1.10.0
1.12.0
1
kubevious/guard:1.2.19bf567704de2
morgan@1.10.0
1.12.0
1
kubevious/parser:1.0.151acf1a1f0b47
morgan@1.10.0
1.12.0
1
kubevious/parser:1.2.299ae7a5168c2
morgan@1.10.0
1.12.0
1
kubevious/workload-operator:1.0.20b0f4c507eb6
morgan@1.10.0
1.12.0
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
morgan@1.10.0
1.12.0
1
linuxserver/codimd:latestb801bbcf6386
morgan@1.10.0
1.12.0
1
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
morgan@1.10.0
1.12.0
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
morgan@1.10.0
1.12.0
1
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
morgan@1.10.1
1.12.0
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
morgan@1.10.0
1.12.0
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
morgan@1.10.0
1.12.0
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
morgan@1.10.0
1.12.0
1
phntom/codimd:2.4.31b9aafbb62e6
morgan@1.9.1
1.12.0
1
roadiehq/community-backstage-image:latestef355bf5b639
morgan@1.10.0
1.12.0
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
morgan@1.10.0
1.12.0
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
morgan@1.7.0
1.12.0
1
socialmediamacroscope/smile_server:0.3.31a528c794270
morgan@1.9.1
1.12.0
1
soulou2019/node-server:latest5e6ecfcc109e
morgan@1.10.0
1.12.0
1
stanfordoval/almond-server:latest1a63cdccedaf
morgan@1.10.0
1.12.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.