StackRadar

CVE-2026-16732

Medium

Advisory

Published 2 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
19
of 17,781 indexed, latest versions
Container images
18
deployed by those charts
Fix available
1 of 1
affected package

fastify vulnerable to X-Forwarded-* spoofing under trustProxy hop-count

Carried by container images the latest versions of 19 of 17,781 indexed charts deploy, on 18 images.

Affected packageAffected versionsFixed inImages
fastifynpm5.8.4, 5.8.5, 5.11.25.12.118
OSV records
GHSA-3m5p-2c4r-xxw2

Charts affected

19 by stars
ChartLatestAffected imagesRadar Score
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
fastify@5.8.5
5.12.1

Open the chart page →

5,564
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
fastify@5.8.5
5.12.1

Open the chart page →

8,491
gorules-brmsgorulesVerified publisher1.18.11 of 1See more

gorules-brms gorules 1.18.1

1 of the 1 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
gorules/brms:latest3cd59e25efad
fastify@5.8.5
5.12.1

Open the chart page →

311
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
supabase/storage-api:v1.60.4c8eb9858eafe
fastify@5.8.5
5.12.1

Open the chart page →

18,075
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
fastify@5.8.5
5.12.1

Open the chart page →

2,522
trifidzazukoOfficialVerified publisher0.2.11 of 1See more

trifid zazuko 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
fastify@5.8.5
5.12.1

Open the chart page →

338
activepiecesadnoctemVerified publisher0.5.01 of 1See more

activepieces adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
activepieces/activepieces:0.90.430c10a04fe3d
fastify@5.8.5
5.12.1

Open the chart page →

1,055
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
fastify@5.11.2
5.12.1

Open the chart page →

951
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
fastify@5.8.5
5.12.1

Open the chart page →

2,033
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
fastify@5.8.5
5.12.1

Open the chart page →

839
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
fastify@5.8.5
5.12.1

Open the chart page →

2,522
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
fastify@5.8.5
5.12.1

Open the chart page →

3,014
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
fastify@5.8.5
5.12.1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
fastify@5.8.5
5.12.1

Open the chart page →

2,774
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
fastify@5.8.5
5.12.1

Open the chart page →

2,396
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
fastify@5.8.5
5.12.1

Open the chart page →

1,166
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
fastify@5.8.5
5.12.1

Open the chart page →

5,819
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
fastify@5.8.5
5.12.1

Open the chart page →

3,014
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
fastify@5.11.2
5.12.1

Open the chart page →

9,556
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-16732.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
fastify@5.8.4
5.12.1

Open the chart page →

2,076

Container images carrying it

18 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
epamedp/krci-portal:0.8.0687acf641097
fastify@5.8.5
5.12.1
2
infisical/infisical:latest:v0.165.602082bf13163
fastify@5.8.5
5.12.1
2
activepieces/activepieces:0.90.430c10a04fe3d
fastify@5.8.5
5.12.1
1
chainsafe/lodestar:latest5593f6e97912
fastify@5.8.5
5.12.1
1
docmost/docmost:0.95.041c8d777cf23
fastify@5.8.5
5.12.1
1
gorules/brms:latest3cd59e25efad
fastify@5.8.5
5.12.1
1
haohanyang/compass-web:0.5.054f2112602ee
fastify@5.8.5
5.12.1
1
journeyapps/powersync-service:latestbf46f66e5dcc
fastify@5.8.5
5.12.1
1
neoskop/ixy:2.1.125152b474f54
fastify@5.8.5
5.12.1
1
supabase/storage-api:v1.60.4c8eb9858eafe
fastify@5.8.5
5.12.1
1
supabase/storage-api:latestf6c42a04163d
fastify@5.11.2
5.12.1
1
tenureai/tenure:v1.0.285f5b222df9a5
fastify@5.8.5
5.12.1
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
fastify@5.11.2
5.12.1
1
ghcr.io/colanode/server:latest7006cac874fd
fastify@5.8.4
5.12.1
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
fastify@5.8.5
5.12.1
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
fastify@5.8.5
5.12.1
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
fastify@5.8.5
5.12.1
1
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
fastify@5.8.5
5.12.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.