StackRadar

CVE-2026-16728

Medium

Advisory

Published 29 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
222
of 17,781 indexed, latest versions
Container images
203
deployed by those charts
Fix available
1 of 2
affected packages

undici vulnerable to downstream response desynchronization via retry interceptor

Carried by container images the latest versions of 222 of 17,781 indexed charts deploy, on 203 images.

Affected packageAffected versionsFixed inImages
node-undicideb5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4, 5.26.3+dfsg1+~cs23.10.12-2+1 moreno fix listed9
undicinpm4.15.0, 5.6.0, 5.11.0, 5.12.0+41 more6.28.0, 7.29.0, 8.9.0203
OSV records
DEBIAN-CVE-2026-16728GHSA-8xcm-r25x-g524UBUNTU-CVE-2026-16728

Charts affected

222 by stars
ChartLatestAffected imagesRadar Score
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
undici@5.28.4
6.28.0

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
undici@5.28.4
6.28.0

Open the chart page →

11,100
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
undici@7.12.0
7.29.0

Open the chart page →

1,313
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.28.0

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.28.0

Open the chart page →

919
strapistrapi-xmv0.1.11 of 1See more

strapi strapi-xmv 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
undici@6.27.0
6.28.0

Open the chart page →

676
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
undici@5.24.0
6.28.0

Open the chart page →

13,719
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
undici@5.6.0
6.28.0

Open the chart page →

4,017
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
undici@6.26.0
6.28.0

Open the chart page →

3,972
supabaseteochenglim0.1.22 of 13See more

supabase teochenglim 0.1.2

2 of the 13 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
undici@7.28.0
7.29.0
supabase/studio:latest94a2a9d2906e
undici@6.27.0
6.28.0

Open the chart page →

9,556
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
undici@5.28.4
6.28.0

Open the chart page →

28,814
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
undici@5.29.0
6.28.0

Open the chart page →

3,576
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
undici@6.27.0
6.28.0

Open the chart page →

5,535
gtm-server-container-clustertrieb-work0.1.81 of 1See more

gtm-server-container-cluster trieb-work 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
gcr.io/cloud-tagging-10302018/gtm-cloud-image:stable688d35c6c544
undici@6.27.0
6.28.0

Open the chart page →

472
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
undici@6.27.0
6.28.0

Open the chart page →

5,550
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
undici@6.21.1
6.28.0

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.29.0

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
undici@5.29.0
6.28.0

Open the chart page →

1,787
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
undici@6.27.0
6.28.0

Open the chart page →

1,961
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
undici@6.25.0
6.28.0

Open the chart page →

1,616
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
undici@6.25.0
6.28.0

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
undici@6.19.2
6.28.0

Open the chart page →

6,285

Container images carrying it

203 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
undici@5.11.0
6.28.0
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
undici@5.29.0
6.28.0
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
undici@6.26.0
6.28.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.