StackRadar

CVE-2026-24001

High

Advisory

Published 14 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
576
of 17,781 indexed, latest versions
Container images
598
deployed by those charts
Fix available
1 of 2
affected packages

jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Carried by container images the latest versions of 576 of 17,781 indexed charts deploy, on 598 images.

Affected packageAffected versionsFixed inImages
node-diffdeb5.0.0~dfsg+~5.0.1-4no fix listed1
diffnpm1.0.0, 1.0.2, 1.3.2, 1.4.0+10 more3.5.1, 4.0.4, 5.2.2, 8.0.3598
OSV records
UBUNTU-CVE-2026-24001GHSA-73rr-hh4g-fpgx

Charts affected

576 by stars
ChartLatestAffected imagesRadar Score
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
diff@5.1.0
5.2.2

Open the chart page →

9,412
shynetatrox0.1.11 of 1See more

shynet atrox 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.12.0e821e31140f7
diff@5.0.0
5.2.2

Open the chart page →

5,507
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ltdstudio/terraforming-mars:latest0e76c6f4eac0
diff@4.0.2
4.0.4

Open the chart page →

7,152
awesomeblessingappawesomeblessingapp1.1.01 of 1See more

awesomeblessingapp awesomeblessingapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
bnwokoye/nodejswebapp:latest74de7dc7ebfb
diff@5.0.0
5.2.2

Open the chart page →

1,267
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
diff@5.2.0
5.2.2

Open the chart page →

1,722
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
diff@5.2.0
5.2.2

Open the chart page →

2,136
myhelmappbelihelmapp1.1.01 of 1See more

myhelmapp belihelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
belirta/beli-docker:v1.0.0f65ad0e23b4d
diff@5.1.0
5.2.2

Open the chart page →

1,187
http-debugbicarus-labs0.1.01 of 1See more

http-debug bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
bicarus/http-https-echo:2785dd6a7e805e
diff@5.1.0
5.2.2

Open the chart page →

867
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
diff@5.0.0
5.2.2

Open the chart page →

4,455
bluerange-mosquittobluerangeOfficialVerified publisher1.0.41 of 1See more

bluerange-mosquitto bluerange 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
bluerange/bluerange-mosquitto:25f1bfbba84832
diff@8.0.2
8.0.3

Open the chart page →

1,168
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
diff@4.0.2
4.0.4
sysnet4admin/colosseum-prm:log5802bfcd7fed
diff@4.0.2
4.0.4

Open the chart page →

26,996
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
diff@5.1.0
5.2.2

Open the chart page →

3,071
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
diff@1.3.2
3.5.1

Open the chart page →

4,069
rtorrent-floodbryanalves0.5.01 of 1See more

rtorrent-flood bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
jesec/flood:4.7.03d1d0bec117a
diff@5.0.0
5.2.2

Open the chart page →

1,477
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
diff@5.2.0
5.2.2

Open the chart page →

14,352
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
diff@5.2.0
5.2.2

Open the chart page →

951
syslog-portalbryopsida0.3.11 of 1See more

syslog-portal bryopsida 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
diff@5.2.0
5.2.2

Open the chart page →

1,306
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
diff@5.2.0
5.2.2

Open the chart page →

1,338
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
diff@5.2.0
5.2.2

Open the chart page →

1,338
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
diff@4.0.2
4.0.4

Open the chart page →

7,405
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
diff@5.2.0
5.2.2

Open the chart page →

4,083
audiobookshelfcharts-derwitt-devVerified publisher1.1.01 of 1See more

audiobookshelf charts-derwitt-dev 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
diff@5.2.0
5.2.2

Open the chart page →

1,722
ddb-proxycharts-derwitt-devVerified publisher1.3.01 of 1See more

ddb-proxy charts-derwitt-dev 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/mrprimate/ddb-proxy:0.0.258dc2d7fb460f
diff@5.1.0
5.2.2

Open the chart page →

812
servicechart-serviceVerified publisher0.0.41 of 1See more

service chart-service 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
punkerside/noroot:v0.0.7be20c81d6ca1
diff@5.0.0
5.2.2

Open the chart page →

930
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
diff@5.2.0
5.2.2

Open the chart page →

1,977
audiobookshelfchristianhuthVerified publisher2.4.01 of 1See more

audiobookshelf christianhuth 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
diff@5.2.0
5.2.2

Open the chart page →

1,722
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
diff@5.2.0
5.2.2
countly/frontend:25.05.42acbc11499b6
diff@5.2.0
5.2.2

Open the chart page →

7,295
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
diff@5.2.0
5.2.2

Open the chart page →

1,947
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
diff@5.1.0
5.2.2

Open the chart page →

2,759
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
diff@3.5.0
3.5.1

Open the chart page →

2,580
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
diff@4.0.1
4.0.4

Open the chart page →

25,456
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
diff@5.2.0
5.2.2
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
diff@4.0.2
4.0.4
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
diff@5.2.0
5.2.2

Open the chart page →

18,293
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
shyamkrishna21/cloudvault:latestaf2785f5bb71
diff@5.2.0
5.2.2

Open the chart page →

2,184
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
diff@5.2.0
5.2.2

Open the chart page →

3,868
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
node-diff@5.0.0~dfsg+~5.0.1-4
diff@5.0.0
no fix listed
5.2.2

Open the chart page →

13,220
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
diff@5.1.0
5.2.2

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
diff@5.1.0
5.2.2

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
diff@5.1.0
5.2.2

Open the chart page →

5,141
containers-security-chartscontainers-security0.1.02 of 7See more

containers-security-charts containers-security 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
coldatom/containers-security-api:latesteae9e82da080
diff@5.1.0
5.2.2
coldatom/containers-security-front:latest7c2fbbb41bcf
diff@5.1.0
5.2.2

Open the chart page →

9,146
conversor-temperaturaconversor-temperaturaVerified publisher0.1.01 of 1See more

conversor-temperatura conversor-temperatura 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
felipecs8/conversor-temperatura:v1f945423be36d
diff@5.2.0
5.2.2

Open the chart page →

1,527
cors-proxycors-proxyVerified publisher1.2.01 of 1See more

cors-proxy cors-proxy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
diff@7.0.0
8.0.3

Open the chart page →

1,598
cortezacorteza1.0.121 of 3See more

corteza corteza 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
diff@5.2.0
5.2.2

Open the chart page →

8,368
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
diff@1.0.0
3.5.1

Open the chart page →

14,559
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
diff@3.5.0
3.5.1

Open the chart page →

5,488
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
diff@4.0.2
4.0.4

Open the chart page →

3,769
swagger-combine-uicryptexlabsVerified publisher0.2.41 of 1See more

swagger-combine-ui cryptexlabs 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
diff@5.1.0
5.2.2

Open the chart page →

1,378
myawesomeappcuriousgeekshelmfirstapp0.1.21 of 1See more

myawesomeapp curiousgeekshelmfirstapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
srini78/nodejswebappeks:latest5d1cbdc6833a
diff@5.1.0
5.2.2

Open the chart page →

1,267
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
diff@5.2.0
5.2.2

Open the chart page →

22,193
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
diff@5.2.0
5.2.2

Open the chart page →

6,172
db-operatordb-operatorVerified publisher0.1.01 of 1See more

db-operator db-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
plumdog/db-operator:latest0c2fa2db0357
diff@5.0.0
5.2.2

Open the chart page →

3,042

Container images carrying it

598 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
diff@5.2.0
5.2.2
1
jkroepke/github_exporter:1.8.03d850992786d
diff@8.0.2
8.0.3
1
joplin/server:3.0-beta52af57880c0e
diff@4.0.2
4.0.4
1
joplin/server:2.14.2-betab87564ef34e9
diff@5.1.0
5.2.2
1
josepht05/nodejs-feb24:latest36cb0c618c94
diff@5.1.0
5.2.2
1
josepht05/titajo-docker:v1.0.0d94024965d78
diff@5.0.0
5.2.2
1
josh5/unmanic:0.2.64d49c4816260
diff@5.1.0
5.2.2
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-diff@5.0.0~dfsg+~5.0.1-4
diff@5.0.0
no fix listed
5.2.2
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
diff@5.2.0
5.2.2
1
keyoxide/keyoxide:stable96f27a71269d
diff@5.0.0
5.2.2
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
diff@3.5.0
3.5.1
1
konradkleine/docker-registry-frontend:v2181aad54ee64
diff@1.3.2
3.5.1
1
ktitilayo2/nodejswebapp:latest8bac28058688
diff@5.0.0
5.2.2
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
diff@5.1.0
5.2.2
1
kubebb/component-store:latestfd8ecbd73213
diff@5.1.0
5.2.2
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
diff@5.1.0
5.2.2
1
kubevious/backend:1.2.22d9ba6eb46b6
diff@5.1.0
5.2.2
1
kubevious/collector:1.2.1f58226f9d84e
diff@5.0.0
5.2.2
1
kubevious/guard:1.2.19bf567704de2
diff@5.0.0
5.2.2
1
kubevious/parser:1.0.151acf1a1f0b47
diff@5.0.0
5.2.2
1
kubevious/parser:1.2.299ae7a5168c2
diff@5.0.0
5.2.2
1
kubevious/workload-operator:1.0.20b0f4c507eb6
diff@5.0.0
5.2.2
1
kyleslugg/klusterview:latestba8c36dfdfbd
diff@4.0.2
4.0.4
1
kyso/kyso-front:lateste52595c5c16f
diff@4.0.2
4.0.4
1
laly9999/node-app:1dd0e503913e1
diff@5.2.0
5.2.2
1
laly9999/node-app-dockerized:latest75ae77a20c6c
diff@5.0.0
5.2.2
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
diff@5.2.0
5.2.2
1
langgenius/dify-api:1.16.1dcefa5f7c47c
diff@5.2.0
5.2.2
1
langgenius/dify-sandbox:0.2.124e65e8a351a2
diff@5.1.0
5.2.2
1
langgenius/dify-web:1.16.187dd47e4e28f
diff@5.2.0
5.2.2
1
langgenius/dify-web:0.6.11a2a294743634
diff@5.1.0
5.2.2
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
diff@5.2.0
5.2.2
1
langgenius/dify-web:1.0.0d64914ff0d6d
diff@5.2.0
5.2.2
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
diff@5.2.0
5.2.2
1
library/ghost:5.79.083f7bf209844
diff@5.1.0
5.2.2
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
diff@5.2.0
5.2.2
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
diff@5.2.0
5.2.2
1
library/node:16.13.0-alpine60ef0bed1dc2
diff@5.0.0
5.2.2
1
library/node:18-alpine8d6421d663b4
diff@5.2.0
5.2.2
1
library/node:208f693eaa7e0a
diff@5.2.0
5.2.2
1
library/node:16.20f77a1aef2da8
diff@5.1.0
5.2.2
1
linuxserver/cloud9:latest45c5fe102ff3
diff@1.0.2
3.5.1
1
linuxserver/code-server:4.10.1a5e43a05ae79
diff@1.0.0
3.5.1
1
linuxserver/codimd:latestb801bbcf6386
diff@3.5.0
3.5.1
1
linuxserver/overseerr:1.35.06108ed066d4a
diff@5.1.0
5.2.2
1
lissy93/dashy:2.0.51991f7be5ed0
diff@5.0.0
5.2.2
1
lissy93/domain-locker:latestd3c95edc0a8b
diff@5.2.0
5.2.2
1
lissy93/networking-toolbox:latest700862839553
diff@5.2.0
5.2.2
1
litlyx/litlyx-consumer:latest02225e77d316
diff@4.0.2
4.0.4
1
litlyx/litlyx-dashboard:lateste64ff2d52385
diff@5.2.0
5.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.