StackRadar

CVE-2026-16729

Medium

Advisory

Published 29 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
222
of 17,781 indexed, latest versions
Container images
203
deployed by those charts
Fix available
1 of 2
affected packages

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

Carried by container images the latest versions of 222 of 17,781 indexed charts deploy, on 203 images.

Affected packageAffected versionsFixed inImages
node-undicideb5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4, 5.26.3+dfsg1+~cs23.10.12-2+1 moreno fix listed9
undicinpm4.15.0, 5.6.0, 5.11.0, 5.12.0+41 more6.28.0, 7.29.0, 8.9.0203
OSV records
DEBIAN-CVE-2026-16729GHSA-v3r7-h72x-cjcmUBUNTU-CVE-2026-16729

Charts affected

222 by stars
ChartLatestAffected imagesRadar Score
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
undici@6.27.0
6.28.0

Open the chart page →

1,038
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
undici@6.27.0
6.28.0

Open the chart page →

30,159
backstagebackstageOfficialVerified publisher2.10.11 of 1See more

backstage backstage 2.10.1

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/backstage/backstage:latest792e262ea504
undici@6.27.0
6.28.0

Open the chart page →

1,195
penpotpenpotOfficialVerified publisher1.9.02 of 4See more

penpot penpot 1.9.0

2 of the 4 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
penpotapp/exporter:2.17.272a8061e8806
undici@6.26.0
6.28.0
penpotapp/mcp:2.17.284f3f07ead11
undici@6.27.0
6.28.0

Open the chart page →

4,314
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
undici@6.27.0
6.28.0

Open the chart page →

22,002
actualbudgetcommunity-chartsVerified publisher1.9.41 of 1See more

actualbudget community-charts 1.9.4

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
undici@6.27.0
6.28.0

Open the chart page →

1,091
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
undici@6.26.0
6.28.0

Open the chart page →

7,210
apisix-ingress-controllerapisix1.3.11 of 2See more

apisix-ingress-controller apisix 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
undici@6.25.0
6.28.0

Open the chart page →

1,616
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
undici@6.25.0
6.28.0

Open the chart page →

9,203
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
undici@6.21.2
6.28.0

Open the chart page →

8,364
localstacklocalstack0.7.01 of 1See more

localstack localstack 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest4aef81c53168
undici@6.27.0
6.28.0

Open the chart page →

2,156
oneuptimeoneuptimeOfficialVerified publisher13.0.43 of 7See more

oneuptime oneuptime 13.0.4

3 of the 7 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
oneuptime/nginx:release6da7de4fc0f3
undici@6.27.0
6.28.0
oneuptime/probe:release6b2d98713711
undici@6.27.0
6.28.0
oneuptime/runner:release4accc516d800
undici@6.27.0
6.28.0

Open the chart page →

11,192
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
undici@8.3.0
8.9.0

Open the chart page →

5,660
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
undici@6.25.0
6.28.0

Open the chart page →

3,004
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
undici@6.21.3
6.28.0

Open the chart page →

10,775
n8nn8n0.23.01 of 1See more

n8n n8n 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
n8nio/n8n:1.33.1dd171d45102a
undici@6.9.0
6.28.0

Open the chart page →

5,639
openclawopenclawVerified publisher1.91.31 of 2See more

openclaw openclaw 1.91.3

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
undici@6.26.0
6.28.0

Open the chart page →

2,977
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
undici@6.26.0
6.28.0

Open the chart page →

2,938
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
openmined/syft-frontend:0.9.5d11524a3854a
undici@6.11.1
6.28.0

Open the chart page →

17,245
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
undici@7.28.0
7.29.0

Open the chart page →

5,564
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
undici@7.28.0
7.29.0

Open the chart page →

1,339
dialdialOfficialVerified publisher7.2.01 of 4See more

dial dial 7.2.0

1 of the 4 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
epam/ai-dial-chat:0.49.0bd6b13695cdc
undici@6.26.0
6.28.0

Open the chart page →

2,163
foundry-vttfoundry-vttVerified publisher12.343.01 of 1See more

foundry-vtt foundry-vtt 12.343.0

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
felddy/foundryvtt:12.343.06c5e3e9ffbb0
undici@6.19.7
6.28.0

Open the chart page →

723
karakeephelmforgeVerified publisher1.2.92 of 3See more

karakeep helmforge 1.2.9

2 of the 3 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
undici@6.27.0
6.28.0
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
undici@6.26.0
6.28.0

Open the chart page →

9,460
openhabhelmforgeVerified publisher1.2.01 of 1See more

openhab helmforge 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
openhab/openhab:5.2.1bfd4a60e90da
node-undici@7.3.0+dfsg1+~cs24.12.11-1
undici@7.3.0
no fix listed
7.29.0

Open the chart page →

3,641
libredb-studiolibredb-studioVerified publisher0.1.631 of 1See more

libredb-studio libredb-studio 0.1.63

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/libredb/libredb-studio:0.15.04b696f960ac1
undici@6.27.0
6.28.0

Open the chart page →

1,222
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/tale/headplane:0.5.50dbc52cffc19
undici@6.21.0
6.28.0

Open the chart page →

7,949
wg-easywg-easyVerified publisher0.1.61 of 1See more

wg-easy wg-easy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:150e7bc9d34e86
undici@6.26.0
6.28.0

Open the chart page →

725
ghostcloudpirates-ghostVerified publisher0.20.221 of 3See more

ghost cloudpirates-ghost 0.20.22

1 of the 3 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
undici@6.27.0
6.28.0

Open the chart page →

7,146
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
undici@5.28.4
6.28.0

Open the chart page →

28,839
duplistatusduplistatusVerified publisher1.2.01 of 2See more

duplistatus duplistatus 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
wsjbr/duplistatus:1.4.25e594f5f09f6
undici@6.26.0
6.28.0

Open the chart page →

1,870
rsshubgabe565Verified publisher0.8.01 of 3See more

rsshub gabe565 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
diygod/rsshub:latest1d4b508b6357
undici@6.27.0
6.28.0

Open the chart page →

1,717
ghost-on-kubernetesghost-on-kubernetes-helmVerified publisher1.1.21 of 3See more

ghost-on-kubernetes ghost-on-kubernetes-helm 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
undici@6.27.0
6.28.0

Open the chart page →

1,447
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
undici@5.12.0
6.28.0

Open the chart page →

10,311
dynamodbkeyporttech0.1.271 of 2See more

dynamodb keyporttech 0.1.27

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
aaronshaf/dynamodb-admin:latestac41724cd997
undici@6.25.0
6.28.0

Open the chart page →

1,304
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
shieldsio/shields:nextfa194b446e42
undici@6.26.0
6.28.0

Open the chart page →

1,798
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
undici@6.25.0
6.28.0

Open the chart page →

5,218
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
undici@6.26.0
6.28.0

Open the chart page →

977
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
undici@6.26.0
6.28.0

Open the chart page →

8,491
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
undici@7.24.4
7.29.0

Open the chart page →

4,016
aapbaapbVerified publisher0.1.31 of 1See more

aapb aapb 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
undici@6.26.0
6.28.0

Open the chart page →

1,044
hermes-agentankra-chartsVerified publisher0.3.11 of 1See more

hermes-agent ankra-charts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
undici@6.26.0
6.28.0

Open the chart page →

5,880
kinesisaws-kinesis-local0.8.01 of 1See more

kinesis aws-kinesis-local 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
saidsef/aws-kinesis-local:v2026.0667025e3a163e
undici@6.26.0
6.28.0

Open the chart page →

360
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
undici@6.25.0
6.28.0

Open the chart page →

1,991
home-assistant-matter-servercharts-derwitt-devVerified publisher4.2.11 of 2See more

home-assistant-matter-server charts-derwitt-dev 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
undici@6.26.0
6.28.0

Open the chart page →

2,360
node-redcharts-derwitt-devVerified publisher2.1.21 of 1See more

node-red charts-derwitt-dev 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
nodered/node-red:5.0.7a649dd711d55
undici@6.27.0
6.28.0

Open the chart page →

101
claude-code-hubclaude-code-hub0.1.01 of 4See more

claude-code-hub claude-code-hub 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/ding113/claude-code-hub:latest87f9e8a92bd7
undici@6.27.0
6.28.0

Open the chart page →

2,173
kubedashdevopstalesOfficialVerified publisher4.0.01 of 8See more

kubedash devopstales 4.0.0

1 of the 8 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
patrikx3/p3x-redis-ui:latestf19eb45b0694
undici@6.27.0
6.28.0

Open the chart page →

9,205
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
undici@7.24.5
7.29.0

Open the chart page →

7,473
jellystatdjjudas21Verified publisher0.1.121 of 1See more

jellystat djjudas21 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
undici@6.26.0
6.28.0

Open the chart page →

1,722

Container images carrying it

203 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
epam/ai-dial-admin-frontend:0.20.021d91ad74755
undici@6.26.0
6.28.0
1
epam/ai-dial-chat:0.49.0bd6b13695cdc
undici@6.26.0
6.28.0
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
undici@4.15.0
6.28.0
1
etherpad/etherpad:latest6020e7b57f4b
undici@6.27.0
6.28.0
1
etherpad/etherpad:2.7.2b723fe5f2594
undici@7.25.0
7.29.0
1
ethpandaops/assertoor:latest1efa2fba6711
undici@6.26.0
6.28.0
1
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.29.0
1
fallenbagel/jellyseerr:latest4538137bc5af
undici@7.3.0
7.29.0
1
felddy/foundryvtt:12.343.06c5e3e9ffbb0
undici@6.19.7
6.28.0
1
foggbh/stocky:latest8b7a2e5ecf4e
undici@6.27.0
6.28.0
1
fosrl/pangolin:latest83a55f933b4d
undici@6.26.0
6.28.0
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
undici@7.24.4
7.29.0
1
globalping/globalping-probe:latest8acbd23009fd
undici@5.29.0
6.28.0
1
haohanyang/compass-web:0.5.054f2112602ee
undici@6.25.0
6.28.0
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
undici@6.27.0
6.28.0
1
helmforge/opencut:v0.3.0bf11156e0ab5
undici@6.26.0
6.28.0
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
undici@6.21.2
6.28.0
1
joplin/server:latest3f7b852959aa
undici@6.27.0
6.28.0
1
journeyapps/powersync-service:latestbf46f66e5dcc
undici@6.26.0
6.28.0
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-undici@5.26.3+dfsg1+~cs23.10.12-2
undici@5.26.3
no fix listed
6.28.0
1
kitware/cdash:v5.3.0d7767d9b9da4
undici@6.26.0
6.28.0
1
kubebb/component-store:latestfd8ecbd73213
undici@5.22.1
6.28.0
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
undici@6.27.0
6.28.0
1
langgenius/dify-api:1.0.0066035f93856
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
6.28.0
1
langgenius/dify-api:0.6.11fca918260dd6
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3
undici@5.15.0
no fix listed
6.28.0
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
undici@6.26.0
6.28.0
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
undici@6.26.0
6.28.0
1
library/ghost:6.37.01ef2e532ca4d
undici@7.25.0
7.29.0
1
library/ghost:6.25.12654b1e90413
undici@5.22.1
6.28.0
1
library/ghost:6.41.129773d6be407
undici@6.25.0
6.28.0
1
library/ghost:6.39.0-alpine77196da4b0df
undici@6.25.0
6.28.0
1
library/ghost:5.79.083f7bf209844
undici@5.22.1
6.28.0
1
library/ghost:6.62.0a7a268bbfb7f
undici@6.27.0
6.28.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
undici@5.22.1
6.28.0
1
library/kibana:8.18.004c0fc150f3a
undici@6.19.2
6.28.0
1
library/node:lts-alpinee67514e5d0f6
undici@6.27.0
6.28.0
1
library/node:latestf5d1cc40abc1
undici@6.27.0
6.28.0
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
undici@6.23.0
6.28.0
1
louislam/uptime-kuma:2.0.24c364ef96aad
undici@6.22.0
6.28.0
1
louislam/uptime-kuma:2.4.091e963bfda56
undici@6.26.0
6.28.0
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
undici@6.22.0
6.28.0
1
luligu/matterbridge:3.10.81ec50ecd0694
undici@6.27.0
6.28.0
1
mautic/mautic:7-apacheeb8cc73d97e1
undici@6.26.0
6.28.0
1
n8nio/n8n:2.25.7761374d4eb84
undici@7.24.6
7.29.0
1
n8nio/n8n:1.86.08b39ed5a2de9
undici@5.28.5
6.28.0
1
n8nio/n8n:2.36.8cfe2704ff858
undici@6.27.0
6.28.0
1
n8nio/n8n:1.33.1dd171d45102a
undici@6.9.0
6.28.0
1
neoskop/ixy:2.1.125152b474f54
undici@6.27.0
6.28.0
1
nocodb/nocodb:0.301.5d9516f0bf546
undici@7.24.4
7.29.0
1
nodered/node-red:5.0.410f40d0a83e7
undici@6.27.0
6.28.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.