StackRadar

CVE-2026-24001

High

Advisory

Published 14 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
571
of 17,787 indexed, latest versions
Container images
593
deployed by those charts
Fix available
1 of 2
affected packages

jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Carried by container images the latest versions of 571 of 17,787 indexed charts deploy, on 593 images.

Affected packageAffected versionsFixed inImages
node-diffdeb5.0.0~dfsg+~5.0.1-4no fix listed1
diffnpm1.0.0, 1.0.2, 1.3.2, 1.4.0+10 more3.5.1, 4.0.4, 5.2.2, 8.0.3593
OSV records
UBUNTU-CVE-2026-24001GHSA-73rr-hh4g-fpgx

Charts affected

571 by stars
ChartLatestAffected imagesRadar Score
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
diff@5.2.0
5.2.2

Open the chart page →

4,768
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
diff@4.0.2
4.0.4

Open the chart page →

3,129
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
diff@5.1.0
5.2.2

Open the chart page →

2,789
skoonervhdirkVerified publisher0.1.41 of 1See more

skooner vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
diff@5.1.0
5.2.2

Open the chart page →

1,341
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
diff@5.1.0
5.2.2

Open the chart page →

9,347
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
diff@5.1.0
5.2.2

Open the chart page →

3,118
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
diff@5.2.0
5.2.2

Open the chart page →

3,031
resultappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

1,263
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

8,262
resultappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

1,263
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

8,262
websitewaldo-visionVerified publisher0.33.02 of 2See more

website waldo-vision 0.33.0

2 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
diff@5.1.0
5.2.2
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
diff@5.1.0
5.2.2

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
diff@4.0.2
4.0.4

Open the chart page →

5,984
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
diff@5.0.0
5.2.2

Open the chart page →

2,559
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
diff@5.0.0
5.2.2

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
diff@5.0.0
5.2.2

Open the chart page →

28,605
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
diff@4.0.2
4.0.4

Open the chart page →

5,459
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
diff@5.2.0
5.2.2

Open the chart page →

14,100
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
diff@5.1.0
5.2.2
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
diff@4.0.2
4.0.4
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
diff@4.0.2
4.0.4
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
diff@5.1.0
5.2.2

Open the chart page →

16,083
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
diff@5.1.0
5.2.2

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
diff@5.0.0
5.2.2

Open the chart page →

3,118

Container images carrying it

593 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
litlyx/litlyx-producer:latest10407f36613f
diff@5.2.0
5.2.2
1
localstack/localstack:3.19d278167f2b7
diff@5.1.0
5.2.2
1
loftsh/jspolicy:0.2.225deb9bd2683
diff@5.1.0
5.2.2
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
diff@5.2.0
5.2.2
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
diff@5.1.0
5.2.2
1
louislam/uptime-kuma:13d632903e6af
diff@5.2.0
5.2.2
1
louislam/uptime-kuma:2.0.24c364ef96aad
diff@4.0.2
4.0.4
1
louislam/uptime-kuma:1.23.1396510915e6be
diff@5.2.0
5.2.2
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
diff@4.0.2
4.0.4
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
diff@5.0.0
5.2.2
1
louislam/uptime-kuma:1.18.5a84767d7934f
diff@5.0.0
5.2.2
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
diff@5.2.0
5.2.2
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
diff@4.0.2
4.0.4
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
diff@5.1.0
5.2.2
1
luligu/matterbridge:3.0.28f97884bebc2
diff@5.2.0
5.2.2
1
maildev/maildev:2.2.1180ef51f65ee
diff@5.2.0
5.2.2
1
maissacrement/pock8snodejs:0.0.16da0db1159da
diff@5.1.0
5.2.2
1
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
diff@5.1.0
5.2.2
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
diff@5.1.0
5.2.2
1
mauricenino/dashdot:5.9.2236997816917
diff@5.2.0
5.2.2
1
mautic/mautic:7-apacheeb8cc73d97e1
diff@7.0.0
8.0.3
1
middlewareeng/middleware:0.3.1747d880812f1
diff@5.2.0
5.2.2
1
milesmcc/shynet:v0.13.1ba54f7797a6b
diff@5.0.0
5.2.2
1
milesmcc/shynet:v0.12.0e821e31140f7
diff@5.0.0
5.2.2
1
minddocdev/hubot:0.1.96c60b11a4fa7
diff@3.5.0
3.5.1
1
mintproject/data-catalog:9be70359feabe03ed55bfdbf92c20a7e43ab928b67d2f2103085
diff@5.0.0
5.2.2
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
diff@4.0.2
4.0.4
1
mishtinetwork/operator:latestbb3fe67a5f7c
diff@5.2.0
5.2.2
1
misskey/misskey:12.110.1e08b7c478093
diff@4.0.2
4.0.4
1
mitchxxx/amazon:214e72480ec63a
diff@5.0.0
5.2.2
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
diff@4.0.2
4.0.4
1
moreillon/api-proxy:2373c1953739ef6956b5
diff@5.1.0
5.2.2
1
moreillon/api-proxy:latestd7d4a5463525
diff@4.0.2
4.0.4
1
moreillon/camera-proxy:latestce60056b50c2
diff@4.0.2
4.0.4
1
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
diff@5.0.0
5.2.2
1
moreillon/food-manager:lateste8fd856e593d
diff@5.2.0
5.2.2
1
moreillon/group-manager:latest3caa8f710ee0
diff@5.0.0
5.2.2
1
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
diff@5.1.0
5.2.2
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
diff@5.1.0
5.2.2
1
mozilla/sentencecollector:2.0.91da6ff5c4895
diff@4.0.2
4.0.4
1
mpopoola1/nodejsapp:latest061fc532de7d
diff@5.1.0
5.2.2
1
n8nio/n8n:1.86.08b39ed5a2de9
diff@5.2.0
5.2.2
1
n8nio/n8n:0.212.0a9195bc499a3
diff@5.1.0
5.2.2
1
n8nio/n8n:1.33.1dd171d45102a
diff@5.1.0
5.2.2
1
neoskop/papergirl:3.2.67f52b5949f03
diff@5.1.0
5.2.2
1
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
diff@1.4.0
3.5.1
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
diff@3.5.0
3.5.1
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
diff@5.0.0
5.2.2
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
diff@5.0.0
5.2.2
1
nocodb/nocodb:0.301.5d9516f0bf546
diff@5.2.0
5.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.