StackRadar

CVE-2026-16728

Medium

Advisory

Published 29 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.002
7th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
222
of 17,781 indexed, latest versions
Container images
203
deployed by those charts
Fix available
1 of 2
affected packages

undici vulnerable to downstream response desynchronization via retry interceptor

Carried by container images the latest versions of 222 of 17,781 indexed charts deploy, on 203 images.

Affected packageAffected versionsFixed inImages
node-undicideb5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4, 5.26.3+dfsg1+~cs23.10.12-2+1 moreno fix listed9
undicinpm4.15.0, 5.6.0, 5.11.0, 5.12.0+41 more6.28.0, 7.29.0, 8.9.0203
OSV records
DEBIAN-CVE-2026-16728GHSA-8xcm-r25x-g524UBUNTU-CVE-2026-16728

Charts affected

222 by stars
ChartLatestAffected imagesRadar Score
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
undici@5.28.4
6.28.0

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
undici@5.28.4
6.28.0

Open the chart page →

11,100
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
undici@7.12.0
7.29.0

Open the chart page →

1,313
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.28.0

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.28.0

Open the chart page →

919
strapistrapi-xmv0.1.11 of 1See more

strapi strapi-xmv 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
undici@6.27.0
6.28.0

Open the chart page →

676
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
undici@5.24.0
6.28.0

Open the chart page →

13,719
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
undici@5.6.0
6.28.0

Open the chart page →

4,017
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
undici@6.26.0
6.28.0

Open the chart page →

3,972
supabaseteochenglim0.1.22 of 13See more

supabase teochenglim 0.1.2

2 of the 13 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
undici@7.28.0
7.29.0
supabase/studio:latest94a2a9d2906e
undici@6.27.0
6.28.0

Open the chart page →

9,556
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
undici@5.28.4
6.28.0

Open the chart page →

28,814
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
undici@5.29.0
6.28.0

Open the chart page →

3,576
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
undici@6.27.0
6.28.0

Open the chart page →

5,535
gtm-server-container-clustertrieb-work0.1.81 of 1See more

gtm-server-container-cluster trieb-work 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
gcr.io/cloud-tagging-10302018/gtm-cloud-image:stable688d35c6c544
undici@6.27.0
6.28.0

Open the chart page →

472
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
undici@6.27.0
6.28.0

Open the chart page →

5,550
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
undici@6.21.1
6.28.0

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.29.0

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
undici@5.29.0
6.28.0

Open the chart page →

1,787
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
undici@6.27.0
6.28.0

Open the chart page →

1,961
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
undici@6.25.0
6.28.0

Open the chart page →

1,616
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
undici@6.25.0
6.28.0

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-16728.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
undici@6.19.2
6.28.0

Open the chart page →

6,285

Container images carrying it

203 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/node:ltsbe23f54a88d3
undici@6.27.0
6.28.0
3
localstack/localstack-pro:latest4aef81c53168
undici@6.27.0
6.28.0
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
undici@5.12.0
6.28.0
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
undici@6.25.0
6.28.0
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
undici@6.26.0
6.28.0
3
actualbudget/actual-server:26.9.0552beab3dec8
undici@6.27.0
6.28.0
2
ethersphere/bee-localchain:latest0558799ca992
undici@5.28.3
6.28.0
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
undici@5.28.4
6.28.0
2
homebridge/homebridge:latest77c685a40911
undici@6.27.0
6.28.0
2
library/ghost:6.63.0e05bc1169fb2
undici@6.27.0
6.28.0
2
library/node:24.21.0-alpine3.23159fe6464903
undici@6.27.0
6.28.0
2
library/node:24.21.0-alpinebe80f76cf40e
undici@6.27.0
6.28.0
2
louislam/uptime-kuma:2.3.29aeb4e51d038
undici@6.25.0
6.28.0
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
undici@6.27.0
6.28.0
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
undici@7.11.0
7.29.0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
undici@7.10.0
7.29.0
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
undici@7.16.0
7.29.0
2
n8nio/n8n:2.36.714c4285bc303
undici@6.27.0
6.28.0
2
patrikx3/p3x-redis-ui:latestf19eb45b0694
undici@6.27.0
6.28.0
2
rajnandan1/kener:3.2.1930407afca731
undici@6.21.1
6.28.0
2
requarks/wiki:2:latest68f0d1848261
undici@6.25.0
6.28.0
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.28.0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
undici@5.22.0
6.28.0
2
gcr.io/cloud-tagging-10302018/gtm-cloud-image:stable688d35c6c544
undici@6.27.0
6.28.0
2
ghcr.io/api7/adc:0.27.1f65f53dd9668
undici@6.25.0
6.28.0
2
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
undici@6.27.0
6.28.0
2
ghcr.io/wg-easy/wg-easy:15:15.4.00e7bc9d34e86
undici@6.26.0
6.28.0
2
aaronshaf/dynamodb-admin:latestac41724cd997
undici@6.25.0
6.28.0
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
undici@7.24.1
7.29.0
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
undici@5.28.3
6.28.0
1
archivebox/archivebox:0.7.41a5a37331091
undici@6.25.0
6.28.0
1
budibase/apps:3.41.344fe6feab985
undici@6.21.3
6.28.0
1
catalysm/csmm:latestf003b35f54d9
undici@5.29.0
6.28.0
1
chainsafe/lodestar:latest5593f6e97912
undici@6.27.0
6.28.0
1
chatwoot/chatwoot:v4.15.167ebc751c171
undici@6.25.0
6.28.0
1
chocobozzz/peertube:v8.1.5052712130691
undici@6.24.1
6.28.0
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
undici@6.26.0
6.28.0
1
cryptexlabs/authf:0.12.11189c07411d7c
undici@6.19.8
6.28.0
1
cspconsole/report-processor:1.0.279a2d8840bfdf
undici@5.29.0
6.28.0
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
undici@6.26.0
6.28.0
1
deconzcommunity/deconz:2.29.2062de2362641
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
6.28.0
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
undici@6.26.0
6.28.0
1
directus/directus:12.0.29c8470ea465c
undici@7.24.5
7.29.0
1
directus/directus:11.1.0e3c8bb975350
undici@6.19.5
6.28.0
1
diygod/rsshub:latest1d4b508b6357
undici@6.27.0
6.28.0
1
diygod/rsshub:2025-11-097a6312cac0d5
undici@6.22.0
6.28.0
1
docmost/docmost:0.95.041c8d777cf23
undici@7.28.0
7.29.0
1
drumsergio/lynxprompt:2.0.75c6afb6679301
undici@6.25.0
6.28.0
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
undici@6.27.0
6.28.0
1
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
undici@6.26.0
6.28.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.