StackRadar

CVE-2026-24001

High

Advisory

Published 14 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
576
of 17,781 indexed, latest versions
Container images
598
deployed by those charts
Fix available
1 of 2
affected packages

jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Carried by container images the latest versions of 576 of 17,781 indexed charts deploy, on 598 images.

Affected packageAffected versionsFixed inImages
node-diffdeb5.0.0~dfsg+~5.0.1-4no fix listed1
diffnpm1.0.0, 1.0.2, 1.3.2, 1.4.0+10 more3.5.1, 4.0.4, 5.2.2, 8.0.3598
OSV records
UBUNTU-CVE-2026-24001GHSA-73rr-hh4g-fpgx

Charts affected

576 by stars
ChartLatestAffected imagesRadar Score
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
diff@5.1.0
5.2.2

Open the chart page →

9,412
shynetatrox0.1.11 of 1See more

shynet atrox 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.12.0e821e31140f7
diff@5.0.0
5.2.2

Open the chart page →

5,507
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ltdstudio/terraforming-mars:latest0e76c6f4eac0
diff@4.0.2
4.0.4

Open the chart page →

7,152
awesomeblessingappawesomeblessingapp1.1.01 of 1See more

awesomeblessingapp awesomeblessingapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
bnwokoye/nodejswebapp:latest74de7dc7ebfb
diff@5.0.0
5.2.2

Open the chart page →

1,267
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
diff@5.2.0
5.2.2

Open the chart page →

1,722
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
diff@5.2.0
5.2.2

Open the chart page →

2,136
myhelmappbelihelmapp1.1.01 of 1See more

myhelmapp belihelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
belirta/beli-docker:v1.0.0f65ad0e23b4d
diff@5.1.0
5.2.2

Open the chart page →

1,187
http-debugbicarus-labs0.1.01 of 1See more

http-debug bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
bicarus/http-https-echo:2785dd6a7e805e
diff@5.1.0
5.2.2

Open the chart page →

867
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
diff@5.0.0
5.2.2

Open the chart page →

4,455
bluerange-mosquittobluerangeOfficialVerified publisher1.0.41 of 1See more

bluerange-mosquitto bluerange 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
bluerange/bluerange-mosquitto:25f1bfbba84832
diff@8.0.2
8.0.3

Open the chart page →

1,168
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
diff@4.0.2
4.0.4
sysnet4admin/colosseum-prm:log5802bfcd7fed
diff@4.0.2
4.0.4

Open the chart page →

26,996
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
diff@5.1.0
5.2.2

Open the chart page →

3,071
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
diff@1.3.2
3.5.1

Open the chart page →

4,069
rtorrent-floodbryanalves0.5.01 of 1See more

rtorrent-flood bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
jesec/flood:4.7.03d1d0bec117a
diff@5.0.0
5.2.2

Open the chart page →

1,477
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
diff@5.2.0
5.2.2

Open the chart page →

14,352
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
diff@5.2.0
5.2.2

Open the chart page →

951
syslog-portalbryopsida0.3.11 of 1See more

syslog-portal bryopsida 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
diff@5.2.0
5.2.2

Open the chart page →

1,306
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
diff@5.2.0
5.2.2

Open the chart page →

1,338
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
diff@5.2.0
5.2.2

Open the chart page →

1,338
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
diff@4.0.2
4.0.4

Open the chart page →

7,405
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
diff@5.2.0
5.2.2

Open the chart page →

4,083
audiobookshelfcharts-derwitt-devVerified publisher1.1.01 of 1See more

audiobookshelf charts-derwitt-dev 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
diff@5.2.0
5.2.2

Open the chart page →

1,722
ddb-proxycharts-derwitt-devVerified publisher1.3.01 of 1See more

ddb-proxy charts-derwitt-dev 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/mrprimate/ddb-proxy:0.0.258dc2d7fb460f
diff@5.1.0
5.2.2

Open the chart page →

812
servicechart-serviceVerified publisher0.0.41 of 1See more

service chart-service 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
punkerside/noroot:v0.0.7be20c81d6ca1
diff@5.0.0
5.2.2

Open the chart page →

930
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
diff@5.2.0
5.2.2

Open the chart page →

1,977
audiobookshelfchristianhuthVerified publisher2.4.01 of 1See more

audiobookshelf christianhuth 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
diff@5.2.0
5.2.2

Open the chart page →

1,722
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
diff@5.2.0
5.2.2
countly/frontend:25.05.42acbc11499b6
diff@5.2.0
5.2.2

Open the chart page →

7,295
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
diff@5.2.0
5.2.2

Open the chart page →

1,947
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
diff@5.1.0
5.2.2

Open the chart page →

2,759
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
diff@3.5.0
3.5.1

Open the chart page →

2,580
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
diff@4.0.1
4.0.4

Open the chart page →

25,456
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
diff@5.2.0
5.2.2
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
diff@4.0.2
4.0.4
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
diff@5.2.0
5.2.2

Open the chart page →

18,293
cloudvaultcloudvaultOfficialVerified publisher1.0.21 of 3See more

cloudvault cloudvault 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
shyamkrishna21/cloudvault:latestaf2785f5bb71
diff@5.2.0
5.2.2

Open the chart page →

2,184
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
diff@5.2.0
5.2.2

Open the chart page →

3,868
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
node-diff@5.0.0~dfsg+~5.0.1-4
diff@5.0.0
no fix listed
5.2.2

Open the chart page →

13,220
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
diff@5.1.0
5.2.2

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
diff@5.1.0
5.2.2

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
diff@5.1.0
5.2.2

Open the chart page →

5,141
containers-security-chartscontainers-security0.1.02 of 7See more

containers-security-charts containers-security 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
coldatom/containers-security-api:latesteae9e82da080
diff@5.1.0
5.2.2
coldatom/containers-security-front:latest7c2fbbb41bcf
diff@5.1.0
5.2.2

Open the chart page →

9,146
conversor-temperaturaconversor-temperaturaVerified publisher0.1.01 of 1See more

conversor-temperatura conversor-temperatura 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
felipecs8/conversor-temperatura:v1f945423be36d
diff@5.2.0
5.2.2

Open the chart page →

1,527
cors-proxycors-proxyVerified publisher1.2.01 of 1See more

cors-proxy cors-proxy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
diff@7.0.0
8.0.3

Open the chart page →

1,598
cortezacorteza1.0.121 of 3See more

corteza corteza 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
diff@5.2.0
5.2.2

Open the chart page →

8,368
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
diff@1.0.0
3.5.1

Open the chart page →

14,559
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
diff@3.5.0
3.5.1

Open the chart page →

5,488
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
diff@4.0.2
4.0.4

Open the chart page →

3,769
swagger-combine-uicryptexlabsVerified publisher0.2.41 of 1See more

swagger-combine-ui cryptexlabs 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
diff@5.1.0
5.2.2

Open the chart page →

1,378
myawesomeappcuriousgeekshelmfirstapp0.1.21 of 1See more

myawesomeapp curiousgeekshelmfirstapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
srini78/nodejswebappeks:latest5d1cbdc6833a
diff@5.1.0
5.2.2

Open the chart page →

1,267
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
diff@5.2.0
5.2.2

Open the chart page →

22,193
datacube-wpsdatacube-charts0.9.01 of 1See more

datacube-wps datacube-charts 0.9.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
opendatacube/wps:latest80df355a660b
diff@5.2.0
5.2.2

Open the chart page →

6,172
db-operatordb-operatorVerified publisher0.1.01 of 1See more

db-operator db-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
plumdog/db-operator:latest0c2fa2db0357
diff@5.0.0
5.2.2

Open the chart page →

3,042

Container images carrying it

598 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
nodered/node-red:4.1.2216e7403aab9
diff@5.2.0
5.2.2
1
nodered/node-red:4.1.10-minimald73ae167cb9b
diff@5.2.0
5.2.2
1
nodered/node-red:3.0.2-18e2632a7a35dd
diff@5.1.0
5.2.2
1
nonkronk/tristian-id:latest0a3694d70647
diff@5.0.0
5.2.2
1
nottiey/mynodejswebapp:latest9c35a24c9eb3
diff@5.1.0
5.2.2
1
oada/auth:4.0.0c0d077e79ef4
diff@5.2.0
5.2.2
1
oada/http-handler:4.0.0d87efe8ba4b0
diff@5.2.0
5.2.2
1
oada/rev-graph-update:4.0.0ebc8343f05ff
diff@5.2.0
5.2.2
1
oada/shares:4.0.0c6ffb4e8ed63
diff@5.2.0
5.2.2
1
oada/startup:4.0.0fc09495e2f3c
diff@5.2.0
5.2.2
1
oada/sync-handler:4.0.0b7a2cfc137cf
diff@5.2.0
5.2.2
1
oada/users:4.0.0b6c562fa5b1b
diff@5.2.0
5.2.2
1
oada/webhooks:4.0.06590c60de347
diff@5.2.0
5.2.2
1
oada/well-known:4.0.07943fde43b19
diff@5.2.0
5.2.2
1
oada/write-handler:4.0.08464c7f48aae
diff@5.2.0
5.2.2
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
diff@4.0.2
4.0.4
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
diff@5.0.0
5.2.2
1
okaforuchena/uo-docker:V1.0.0004e81250f48
diff@5.1.0
5.2.2
1
ondrejsika/parking:latestb1fd497416c8
diff@5.0.0
5.2.2
1
ooghenekaro/amazon:latest03394ba1d6d8
diff@5.1.0
5.2.2
1
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
diff@5.0.0
5.2.2
1
ooghenekaro/nodejswebapp:latestea5b71588a76
diff@5.0.0
5.2.2
1
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
diff@5.0.0
5.2.2
1
opea/codegen-ui:1.02bee4eb66f3e
diff@5.1.0
5.2.2
1
opea/codetrans-ui:1.03ef121f34610
diff@5.1.0
5.2.2
1
opea/docsum-ui:1.07f854e9bffaf
diff@5.1.0
5.2.2
1
openbas/caldera-server:5.1.0a277796d9724
diff@5.2.0
5.2.2
1
opendatacube/wps:latest80df355a660b
diff@5.2.0
5.2.2
1
openemr/openemr:6.1.089eaa6d9a4e3
diff@5.0.0
5.2.2
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
diff@5.0.0
5.2.2
1
openproject/hocuspocus:release-338001b288dc1359dfb5
diff@5.2.0
5.2.2
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
diff@4.0.1
4.0.4
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
diff@5.2.0
5.2.2
1
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
diff@5.1.0
5.2.2
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
diff@5.1.0
5.2.2
1
outlinewiki/outline:0.82.0494dfb9249a6
diff@5.2.0
5.2.2
1
patdada/bella-docker:v1.0.075127147a624
diff@5.0.0
5.2.2
1
pawelmalak/flame:2.1.193e7b0abb603
diff@5.0.0
5.2.2
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
diff@5.0.0
5.2.2
1
penpotapp/exporter:2.2.15c835ffd87ab
diff@5.1.0
5.2.2
1
phntom/codimd:2.4.31b9aafbb62e6
diff@3.5.0
3.5.1
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
diff@8.0.2
8.0.3
1
plumdog/db-operator:latest0c2fa2db0357
diff@5.0.0
5.2.2
1
polonel/trudesk:1.2.60cf6513f6fe3
diff@5.0.0
5.2.2
1
promasu/cryptpad:v4.14.1-nginx51d1142b9f95
diff@5.1.0
5.2.2
1
prowlercloud/prowler-ui:5.31.179ee83c8e702
diff@8.0.2
8.0.3
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
diff@5.2.0
5.2.2
1
psorab/elibrary:latest53b68896c4ce
diff@5.1.0
5.2.2
1
pumejlab/nodejs-webapp:latestf563eabcb819
diff@5.0.0
5.2.2
1
punkerside/noroot:v0.0.7be20c81d6ca1
diff@5.0.0
5.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.