StackRadar

CVE-2026-23897

High

Advisory

Published 4 Feb 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
49th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
22
of 17,781 indexed, latest versions
Container images
16
deployed by those charts
Fix available
1 of 2
affected packages

Apollo Serve vulnerable to Denial of Service with `startStandaloneServer`

Carried by container images the latest versions of 22 of 17,781 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
@apollo/servernpm4.6.0, 4.7.4, 4.9.5, 4.11.0+1 more4.13.08
apollo-servernpm2.16.1, 2.18.2, 2.19.2, 2.21.0+2 moreno fix listed8
OSV records
GHSA-mp6q-xf9x-fwf7

Charts affected

22 by stars
ChartLatestAffected imagesRadar Score
sorry-cypresssorry-cypressVerified publisher1.20.01 of 4See more

sorry-cypress sorry-cypress 1.20.0

1 of the 4 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-api:2.5.11afaa5a84051d
apollo-server@3.9.0
no fix listed

Open the chart page →

4,285
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
apollo-server@2.16.1
no fix listed

Open the chart page →

8,213
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
apollo-server@2.18.2
no fix listed

Open the chart page →

5,946
graphql-gatewaygraphql-gatewayVerified publisher0.1.51 of 1See more

graphql-gateway graphql-gateway 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
hansehe/graphql-gateway:1.0.458e09540afbc
apollo-server@2.18.2
no fix listed

Open the chart page →

1,660
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
@apollo/server@4.9.5
4.13.0

Open the chart page →

3,451
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
speckle/speckle-server:2.26.379f14a2bf931
@apollo/server@4.11.0
4.13.0

Open the chart page →

10,380
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
apollo-server@2.25.2
no fix listed

Open the chart page →

3,833
mod-graphqlfolio-org0.1.301 of 1See more

mod-graphql folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
folioci/mod-graphql:latestf0655a6a08fd
@apollo/server@4.12.2
4.13.0

Open the chart page →

1,091
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
apollo-server@2.16.1
no fix listed

Open the chart page →

8,213
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
@apollo/server@4.9.5
4.13.0

Open the chart page →

3,451
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
apollo-server@2.18.2
no fix listed

Open the chart page →

4,253
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
@apollo/server@4.11.0
4.13.0

Open the chart page →

3,614
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
apollo-server@2.21.0
no fix listed

Open the chart page →

7,232
component-storekubebb0.0.231 of 1See more

component-store kubebb 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
kubebb/component-store:latestfd8ecbd73213
@apollo/server@4.7.4
4.13.0

Open the chart page →

2,178
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
apollo-server@2.19.2
no fix listed

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
apollo-server@2.19.2
no fix listed

Open the chart page →

7,027
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
@apollo/server@4.6.0
4.13.0

Open the chart page →

14,809
reporting-hub-bop-api-svcmojaloop4.1.31 of 1See more

reporting-hub-bop-api-svc mojaloop 4.1.3

1 of the 1 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
@apollo/server@4.6.0
4.13.0

Open the chart page →

1,661
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-api:2.5.11afaa5a84051d
apollo-server@3.9.0
no fix listed

Open the chart page →

4,285
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
@apollo/server@4.11.0
4.13.0

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
@apollo/server@4.11.0
4.13.0

Open the chart page →

11,100
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-23897.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
apollo-server@2.25.2
no fix listed

Open the chart page →

5,459

Container images carrying it

16 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
agoldis/sorry-cypress-api:2.5.11afaa5a84051d
apollo-server@3.9.0
no fix listed
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
@apollo/server@4.9.5
4.13.0
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
apollo-server@2.16.1
no fix listed
2
mesosphere/kommander:6.100.13917e82333a9
apollo-server@2.19.2
no fix listed
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
@apollo/server@4.6.0
4.13.0
2
requarks/wiki:2:latest68f0d1848261
apollo-server@2.25.2
no fix listed
2
folioci/mod-graphql:latestf0655a6a08fd
@apollo/server@4.12.2
4.13.0
1
hansehe/graphql-gateway:1.0.458e09540afbc
apollo-server@2.18.2
no fix listed
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
@apollo/server@4.11.0
4.13.0
1
kubebb/component-store:latestfd8ecbd73213
@apollo/server@4.7.4
4.13.0
1
requarks/wiki:canary-2.5.2438b5865a7386c
apollo-server@2.18.2
no fix listed
1
roadiehq/community-backstage-image:latestef355bf5b639
apollo-server@2.21.0
no fix listed
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
@apollo/server@4.11.0
4.13.0
1
speckle/speckle-server:2.26.379f14a2bf931
@apollo/server@4.11.0
4.13.0
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
@apollo/server@4.11.0
4.13.0
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
apollo-server@2.18.2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.