StackRadar

CVE-2026-21714

Medium

Advisory

Published 30 Mar 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
59
of 17,781 indexed, latest versions
Container images
52
deployed by those charts
Fix available
2 of 3
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 59 of 17,781 indexed charts deploy, on 52 images.

Affected packageAffected versionsFixed inImages
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+32 more18.20.4+dfsg-1~deb12u2, 20.19.2+dfsg-1+deb13u247
nodejsapk22.16.0-r2, 22.22.0-r0, 24.11.1-r022.22.2-r0, 24.14.1-r04
nodejs-18apk18.20.8-r9no fix listed1
OSV records
ALPINE-CVE-2026-21714CGA-53pv-33c7-vj6fDEBIAN-CVE-2026-21714UBUNTU-CVE-2026-21714
Also known as
CGA-6chm-fxfm-7j4j

Charts affected

59 by stars
ChartLatestAffected imagesRadar Score
coolify-realtimequench-coolify-realtimeVerified publisher0.0.71 of 1See more

coolify-realtime quench-coolify-realtime 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-21714.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/coolify-realtimedigest-pinnedf128e512c9c0
nodejs-18@18.20.8-r9
no fix listed

Open the chart page →

306
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-21714.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
nodejs@14.17.5-deb-1nodesource1
no fix listed

Open the chart page →

11,909
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-21714.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
nodejs@22.16.0-r2
22.22.2-r0

Open the chart page →

4,499
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-21714.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
nodejs@10.19.0~dfsg-3ubuntu1.3
no fix listed

Open the chart page →

10,902
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-21714.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
nodejs@20.20.2-1nodesource1
no fix listed

Open the chart page →

7,248
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-21714.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
nodejs@20.11.1-1nodesource1
no fix listed

Open the chart page →

9,347
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-21714.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nodejs@14.18.1-deb-1nodesource1
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-21714.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nodejs@14.18.1-deb-1nodesource1
no fix listed

Open the chart page →

28,605
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-21714.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
no fix listed

Open the chart page →

14,100

Container images carrying it

52 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
dgraph/dgraph:v21.12.03b55ea83fffe
nodejs@14.17.5-deb-1nodesource1
no fix listed
3
hookiesolutions/webhookie:latest0629694246ba
nodejs@14.18.1-deb-1nodesource1
no fix listed
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
nodejs@16.14.2-deb-1nodesource1
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
nodejs@22.16.0-1nodesource1
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
nodejs@16.18.0-deb-1nodesource1
no fix listed
2
ghcr.io/quenchworks/images/coolify-realtimef128e512c9c0
nodejs-18@18.20.8-r9
no fix listed
2
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
nodejs@16.7.0-deb-1nodesource1
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
nodejs@18.20.4-1nodesource1
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
nodejs@18.19.0+dfsg-6~deb12u2
18.20.4+dfsg-1~deb12u2
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
nodejs@4.2.6~dfsg-1ubuntu4.1
no fix listed
1
galaxy/galaxy-init:v18.010267bad550e6
nodejs@9.11.1-1nodesource1
no fix listed
1
gethue/hue:4.11.011b649636e68
nodejs@14.21.2-deb-1nodesource1
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
nodejs@14.17.0-1nodesource1
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
nodejs@24.13.1-1nodesource1
no fix listed
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
nodejs@14.15.3-deb-1nodesource1
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
nodejs@18.17.1-deb-1nodesource1
no fix listed
1
ibmcom/microclimate-theia:lateste17bdccc5030
nodejs@4.2.6~dfsg-1ubuntu4.1
no fix listed
1
instructure/kinesalite:latest34400d82f28f
nodejs@16.20.2-1nodesource1
no fix listed
1
jakowenko/double-take:1.6.0b858bac9e32a
nodejs@16.13.0-deb-1nodesource1
no fix listed
1
jedi132000/nextapp:latestdc2a81e92f23
nodejs@16.18.0-deb-1nodesource1
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
nodejs@20.11.1-1nodesource1
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
nodejs@18.19.1+dfsg-6ubuntu5
no fix listed
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
nodejs@24.11.1-r0
24.14.1-r0
1
langgenius/dify-api:1.0.0066035f93856
nodejs@18.19.0+dfsg-6~deb12u2
18.20.4+dfsg-1~deb12u2
1
langgenius/dify-api:0.6.11fca918260dd6
nodejs@18.19.0+dfsg-6~deb12u1
18.20.4+dfsg-1~deb12u2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
nodejs@14.17.0-1nodesource1
no fix listed
1
linuxserver/codimd:latestb801bbcf6386
nodejs@10.23.0-1nodesource1
no fix listed
1
linuxserver/overseerr:1.35.06108ed066d4a
nodejs@22.22.0-r0
22.22.2-r0
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
nodejs@10.19.0~dfsg-3ubuntu1
no fix listed
1
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
nodejs@16.20.2-1nodesource1
no fix listed
1
muluder/prograncontrollermcord:0.1.843b597a93da7
nodejs@8.9.4-1nodesource1
no fix listed
1
octoboxio/octobox:latestd909041c46eb
nodejs@24.11.1-r0
24.14.1-r0
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
nodejs@18.20.4+dfsg-1~deb12u1
18.20.4+dfsg-1~deb12u2
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
nodejs@18.19.0+dfsg-6~deb12u2
18.20.4+dfsg-1~deb12u2
1
omecproject/onos-progran:1.0.05715e5648aa0
nodejs@8.9.4-1nodesource1
no fix listed
1
openthread/otbr:latestf307f59f6432
nodejs@8.10.0~dfsg-2ubuntu0.4
no fix listed
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
nodejs@8.10.0~dfsg-2ubuntu0.4
no fix listed
1
psorab/elibrary:latest53b68896c4ce
nodejs@16.20.0-deb-1nodesource1
no fix listed
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
nodejs@18.13.0+dfsg1-1
18.20.4+dfsg-1~deb12u2
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
nodejs@10.19.0~dfsg-3ubuntu1.3
no fix listed
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
nodejs@7.10.1-2nodesource1~xenial1
no fix listed
1
vabene1111/recipes:2.3.50f8d061895e9
nodejs@22.16.0-r2
22.22.2-r0
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
nodejs@16.19.1-deb-1nodesource1
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
no fix listed
1
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
nodejs@20.20.2-1nodesource1
no fix listed
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
nodejs@20.20.0-1nodesource1
no fix listed
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
nodejs@16.19.1-deb-1nodesource1
no fix listed
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
nodejs@18.20.4-1nodesource1
18.20.4+dfsg-1~deb12u2
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nodejs@18.20.4+dfsg-1~deb12u1
18.20.4+dfsg-1~deb12u2
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
nodejs@17.5.0-deb-1nodesource1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.