StackRadar

CVE-2026-18504

Medium

Advisory

Published 2 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.003
24th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
38
of 17,781 indexed, latest versions
Container images
39
deployed by those charts
Fix available
1 of 1
affected package

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

Carried by container images the latest versions of 38 of 17,781 indexed charts deploy, on 39 images.

Affected packageAffected versionsFixed inImages
fastifynpm3.15.1, 3.20.1, 3.28.0, 4.2.1+11 more5.12.139
OSV records
GHSA-w2qp-rph6-63g4

Charts affected

38 by stars
ChartLatestAffected imagesRadar Score
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
fastify@4.29.1
5.12.1

Open the chart page →

8,364
supabasetokens-studioVerified publisher1.0.02 of 14See more

supabase tokens-studio 1.0.0

2 of the 14 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
supabase/postgres-meta:v0.84.2d0a96973e9f1
fastify@4.26.2
5.12.1
supabase/storage-api:v1.12.0f983fb50bd95
fastify@4.28.1
5.12.1

Open the chart page →

23,123
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
fastify@5.8.5
5.12.1

Open the chart page →

5,564
foremancontane-githubOfficialVerified publisher0.6.01 of 1See more

foreman contane-github 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
contane/foreman:0.5.2efb98bdcc4e9
fastify@5.3.3
5.12.1

Open the chart page →

1,152
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
fastify@4.28.1
5.12.1

Open the chart page →

28,839
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
fastify@4.12.0
5.12.1

Open the chart page →

2,635
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
fastify@5.8.5
5.12.1

Open the chart page →

8,491
bredbandskollen-prometheus-exporteraolde0.2.31 of 1See more

bredbandskollen-prometheus-exporter aolde 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
fastify@3.15.1
5.12.1

Open the chart page →

1,972
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
fastify@3.28.0
5.12.1

Open the chart page →

15,653
gorules-brmsgorulesVerified publisher1.18.11 of 1See more

gorules-brms gorules 1.18.1

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
gorules/brms:latest3cd59e25efad
fastify@5.8.5
5.12.1

Open the chart page →

311
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
fastify@4.26.2
5.12.1

Open the chart page →

5,654
psa-restricted-patcherpsa-restricted-patcherVerified publisher0.10.11 of 1See more

psa-restricted-patcher psa-restricted-patcher 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
fastify@4.29.1
5.12.1

Open the chart page →

1,401
supabasesupabse0.8.02 of 11See more

supabase supabse 0.8.0

2 of the 11 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
supabase/postgres-meta:v0.96.6a84cc713585e
fastify@4.29.1
5.12.1
supabase/storage-api:v1.60.4c8eb9858eafe
fastify@5.8.5
5.12.1

Open the chart page →

18,075
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
fastify@5.8.5
5.12.1

Open the chart page →

2,522
trifidzazukoOfficialVerified publisher0.2.11 of 1See more

trifid zazuko 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
fastify@5.8.5
5.12.1

Open the chart page →

338
activepiecesadnoctemVerified publisher0.5.01 of 1See more

activepieces adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
activepieces/activepieces:0.90.430c10a04fe3d
fastify@5.8.5
5.12.1

Open the chart page →

1,055
lametric-nightscout-proxyaolde0.1.01 of 1See more

lametric-nightscout-proxy aolde 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/aolde/lametric-nightscout-proxy:latest7d1951b6baf5
fastify@4.8.1
5.12.1

Open the chart page →

1,186
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
fastify@5.11.2
5.12.1

Open the chart page →

951
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
fastify@3.20.1
5.12.1

Open the chart page →

3,769
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
fastify@5.8.5
5.12.1

Open the chart page →

2,033
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
fastify@5.8.5
5.12.1

Open the chart page →

839
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
fastify@5.8.5
5.12.1

Open the chart page →

2,522
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
fastify@4.28.1
5.12.1

Open the chart page →

2,973
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
fastify@5.8.5
5.12.1

Open the chart page →

3,014
k8s-jacoco-operatork8s-jacoco-operator0.4.01 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

1 of the 4 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
fastify@4.26.2
5.12.1

Open the chart page →

2,437
k8s-mutating-webhookk8s-mutating-webhook0.3.01 of 2See more

k8s-mutating-webhook k8s-mutating-webhook 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/k8s-mutating-webhook:mainaaab005242ae
fastify@4.26.2
5.12.1

Open the chart page →

2,009
k8s-validating-webhookk8s-validating-webhook0.4.01 of 2See more

k8s-validating-webhook k8s-validating-webhook 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/k8s-validating-webhook:main8344061b2f22
fastify@4.26.2
5.12.1

Open the chart page →

2,009
kube-admission-controller-starterk8s-validating-webhook0.2.01 of 2See more

kube-admission-controller-starter k8s-validating-webhook 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/kube-admission-controller-starter:maine9716966f30b
fastify@4.5.3
5.12.1

Open the chart page →

2,166
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
fastify@5.8.5
5.12.1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
fastify@5.8.5
5.12.1

Open the chart page →

2,774
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
fastify@5.3.3
5.12.1

Open the chart page →

10,897
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
fastify@5.8.5
5.12.1

Open the chart page →

2,396
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
fastify@5.8.5
5.12.1

Open the chart page →

1,166
walletconnect-relayparadeum-teamVerified publisher0.1.21 of 1See more

walletconnect-relay paradeum-team 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
quay.io/netwarps/walletconnect-relay:v2.1.3-rc.15d90b9c193e0
fastify@4.2.1
5.12.1

Open the chart page →

1,243
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
fastify@5.8.5
5.12.1

Open the chart page →

5,819
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
fastify@5.8.5
5.12.1

Open the chart page →

3,014
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
fastify@5.0.0
5.12.1

Open the chart page →

4,052
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
fastify@5.11.2
5.12.1

Open the chart page →

9,556
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-18504.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
fastify@5.8.4
5.12.1

Open the chart page →

2,076

Container images carrying it

39 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
epamedp/krci-portal:0.8.0687acf641097
fastify@5.8.5
5.12.1
2
infisical/infisical:latest:v0.165.602082bf13163
fastify@5.8.5
5.12.1
2
activepieces/activepieces:0.90.430c10a04fe3d
fastify@5.8.5
5.12.1
1
activepieces/activepieces:0.23.0c26188b44e62
fastify@4.12.0
5.12.1
1
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
fastify@3.15.1
5.12.1
1
chainsafe/lodestar:latest5593f6e97912
fastify@5.8.5
5.12.1
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
fastify@5.0.0
5.12.1
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
fastify@4.26.2
5.12.1
1
contane/foreman:0.5.2efb98bdcc4e9
fastify@5.3.3
5.12.1
1
cryptexlabs/authf:0.12.11189c07411d7c
fastify@3.20.1
5.12.1
1
docmost/docmost:0.95.041c8d777cf23
fastify@5.8.5
5.12.1
1
gorules/brms:latest3cd59e25efad
fastify@5.8.5
5.12.1
1
haohanyang/compass-web:0.5.054f2112602ee
fastify@5.8.5
5.12.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
fastify@4.29.1
5.12.1
1
journeyapps/powersync-service:latestbf46f66e5dcc
fastify@5.8.5
5.12.1
1
neoskop/ixy:2.1.125152b474f54
fastify@5.8.5
5.12.1
1
qxip/qryn:3.2.3977acc9c7a9fd
fastify@4.28.1
5.12.1
1
supabase/postgres-meta:v0.96.6a84cc713585e
fastify@4.29.1
5.12.1
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
fastify@4.26.2
5.12.1
1
supabase/storage-api:v1.60.4c8eb9858eafe
fastify@5.8.5
5.12.1
1
supabase/storage-api:latestf6c42a04163d
fastify@5.11.2
5.12.1
1
supabase/storage-api:v1.12.0f983fb50bd95
fastify@4.28.1
5.12.1
1
tenureai/tenure:v1.0.285f5b222df9a5
fastify@5.8.5
5.12.1
1
ghcr.io/aolde/lametric-nightscout-proxy:latest7d1951b6baf5
fastify@4.8.1
5.12.1
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
fastify@5.11.2
5.12.1
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
fastify@4.29.1
5.12.1
1
ghcr.io/colanode/server:latest7006cac874fd
fastify@5.8.4
5.12.1
1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
fastify@4.26.2
5.12.1
1
ghcr.io/curium-rocks/k8s-mutating-webhook:mainaaab005242ae
fastify@4.26.2
5.12.1
1
ghcr.io/curium-rocks/k8s-validating-webhook:main8344061b2f22
fastify@4.26.2
5.12.1
1
ghcr.io/curium-rocks/kube-admission-controller-starter:maine9716966f30b
fastify@4.5.3
5.12.1
1
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
fastify@5.3.3
5.12.1
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
fastify@5.8.5
5.12.1
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
fastify@5.8.5
5.12.1
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
fastify@3.28.0
5.12.1
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
fastify@5.8.5
5.12.1
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
fastify@4.28.1
5.12.1
1
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
fastify@5.8.5
5.12.1
1
quay.io/netwarps/walletconnect-relay:v2.1.3-rc.15d90b9c193e0
fastify@4.2.1
5.12.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.