StackRadar

CVE-2026-16729

Medium

Advisory

Published 29 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
222
of 17,781 indexed, latest versions
Container images
203
deployed by those charts
Fix available
1 of 2
affected packages

undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields

Carried by container images the latest versions of 222 of 17,781 indexed charts deploy, on 203 images.

Affected packageAffected versionsFixed inImages
node-undicideb5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u3, 5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4, 5.26.3+dfsg1+~cs23.10.12-2+1 moreno fix listed9
undicinpm4.15.0, 5.6.0, 5.11.0, 5.12.0+41 more6.28.0, 7.29.0, 8.9.0203
OSV records
DEBIAN-CVE-2026-16729GHSA-v3r7-h72x-cjcmUBUNTU-CVE-2026-16729

Charts affected

222 by stars
ChartLatestAffected imagesRadar Score
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
undici@5.28.4
6.28.0

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
undici@5.28.4
6.28.0

Open the chart page →

11,100
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
undici@7.12.0
7.29.0

Open the chart page →

1,313
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.28.0

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.28.0

Open the chart page →

919
strapistrapi-xmv0.1.11 of 1See more

strapi strapi-xmv 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
undici@6.27.0
6.28.0

Open the chart page →

676
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
undici@5.24.0
6.28.0

Open the chart page →

13,719
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
undici@5.6.0
6.28.0

Open the chart page →

4,017
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
undici@6.26.0
6.28.0

Open the chart page →

3,972
supabaseteochenglim0.1.22 of 13See more

supabase teochenglim 0.1.2

2 of the 13 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
undici@7.28.0
7.29.0
supabase/studio:latest94a2a9d2906e
undici@6.27.0
6.28.0

Open the chart page →

9,556
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
undici@5.28.4
6.28.0

Open the chart page →

28,814
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
undici@5.29.0
6.28.0

Open the chart page →

3,576
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
undici@6.27.0
6.28.0

Open the chart page →

5,535
gtm-server-container-clustertrieb-work0.1.81 of 1See more

gtm-server-container-cluster trieb-work 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
gcr.io/cloud-tagging-10302018/gtm-cloud-image:stable688d35c6c544
undici@6.27.0
6.28.0

Open the chart page →

472
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
undici@6.27.0
6.28.0

Open the chart page →

5,550
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
undici@6.21.1
6.28.0

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.29.0

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
undici@5.29.0
6.28.0

Open the chart page →

1,787
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
undici@6.27.0
6.28.0

Open the chart page →

1,961
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
undici@6.25.0
6.28.0

Open the chart page →

1,616
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
undici@6.25.0
6.28.0

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-16729.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
undici@6.19.2
6.28.0

Open the chart page →

6,285

Container images carrying it

203 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
nodered/node-red:5.0.7a649dd711d55
undici@6.27.0
6.28.0
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
undici@6.26.0
6.28.0
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
6.28.0
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u4
undici@5.15.0
no fix listed
6.28.0
1
oneuptime/nginx:release6da7de4fc0f3
undici@6.27.0
6.28.0
1
oneuptime/probe:release6b2d98713711
undici@6.27.0
6.28.0
1
oneuptime/runner:release4accc516d800
undici@6.27.0
6.28.0
1
opea/codegen-ui:1.02bee4eb66f3e
undici@5.28.4
6.28.0
1
openhab/openhab:5.2.1bfd4a60e90da
node-undici@7.3.0+dfsg1+~cs24.12.11-1
undici@7.3.0
no fix listed
7.29.0
1
openmined/syft-frontend:0.9.5d11524a3854a
undici@6.11.1
6.28.0
1
outlinewiki/outline:1.10.1832051f039b4
undici@6.26.0
6.28.0
1
penpotapp/exporter:2.17.272a8061e8806
undici@6.26.0
6.28.0
1
penpotapp/mcp:2.17.284f3f07ead11
undici@6.27.0
6.28.0
1
polonel/trudesk:1.2.60cf6513f6fe3
undici@5.6.0
6.28.0
1
rocketadmin/rocketadmin:1.17.710955ef540b9
undici@6.25.0
6.28.0
1
saidsef/aws-kinesis-local:v2026.0667025e3a163e
undici@6.26.0
6.28.0
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
node-undici@5.15.0+dfsg1+~cs20.10.9.3-1+deb12u1
undici@5.15.0
no fix listed
6.28.0
1
shieldsio/shields:nextfa194b446e42
undici@6.26.0
6.28.0
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
undici@5.26.3
6.28.0
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
undici@5.28.4
6.28.0
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
undici@5.28.4
6.28.0
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
undici@5.28.4
6.28.0
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
undici@5.28.4
6.28.0
1
speckle/speckle-server:2.26.379f14a2bf931
undici@5.29.0
6.28.0
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
undici@5.28.3
6.28.0
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
undici@5.28.4
6.28.0
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
undici@5.28.3
6.28.0
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
undici@5.28.4
6.28.0
1
supabase/storage-api:v1.60.4c8eb9858eafe
undici@7.24.6
7.29.0
1
supabase/storage-api:latestf6c42a04163d
undici@7.28.0
7.29.0
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
undici@6.27.0
6.28.0
1
supabase/studio:latest94a2a9d2906e
undici@6.27.0
6.28.0
1
tensorzero/ui:2026.6.0f2563d54724e
undici@6.26.0
6.28.0
1
tenureai/tenure:v1.0.285f5b222df9a5
undici@6.26.0
6.28.0
1
trackerforce/switcher-api:latest28ee0c4e0b88
undici@6.27.0
6.28.0
1
trackerforce/switcher-resolver-node:latest67e2c261f7b4
undici@6.27.0
6.28.0
1
treskon/portrait-ui:DEV-lateste7970783bc8d
undici@6.27.0
6.28.0
1
twentycrm/twenty:v2.22.0e7d9948bf284
undici@6.27.0
6.28.0
1
veecode/devportalc443520aebf7
undici@5.29.0
6.28.0
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
undici@5.24.0
6.28.0
1
wsjbr/duplistatus:1.4.25e594f5f09f6
undici@6.26.0
6.28.0
1
xxczaki/discord-bot:e9f46b6aebac02e7b96ed41a3f62b26e871cf009bb919aac45dc
undici@6.27.0
6.28.0
1
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
undici@6.27.0
6.28.0
1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
undici@6.27.0
6.28.0
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
undici@5.28.3
6.28.0
1
ghcr.io/backstage/backstage:latest792e262ea504
undici@6.27.0
6.28.0
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
undici@6.23.0
6.28.0
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
undici@6.23.0
6.28.0
1
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
undici@6.26.0
6.28.0
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
undici@6.27.0
6.28.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.