StackRadar

CVE-2026-24001

High

Advisory

Published 14 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
571
of 17,787 indexed, latest versions
Container images
593
deployed by those charts
Fix available
1 of 2
affected packages

jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Carried by container images the latest versions of 571 of 17,787 indexed charts deploy, on 593 images.

Affected packageAffected versionsFixed inImages
node-diffdeb5.0.0~dfsg+~5.0.1-4no fix listed1
diffnpm1.0.0, 1.0.2, 1.3.2, 1.4.0+10 more3.5.1, 4.0.4, 5.2.2, 8.0.3593
OSV records
UBUNTU-CVE-2026-24001GHSA-73rr-hh4g-fpgx

Charts affected

571 by stars
ChartLatestAffected imagesRadar Score
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
diff@5.2.0
5.2.2

Open the chart page →

4,768
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
diff@4.0.2
4.0.4

Open the chart page →

3,129
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
diff@5.1.0
5.2.2

Open the chart page →

2,789
skoonervhdirkVerified publisher0.1.41 of 1See more

skooner vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
diff@5.1.0
5.2.2

Open the chart page →

1,341
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
diff@5.1.0
5.2.2

Open the chart page →

9,347
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
diff@5.1.0
5.2.2

Open the chart page →

3,118
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
diff@5.2.0
5.2.2

Open the chart page →

3,031
resultappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

1,263
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

8,262
resultappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

1,263
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

8,262
websitewaldo-visionVerified publisher0.33.02 of 2See more

website waldo-vision 0.33.0

2 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
diff@5.1.0
5.2.2
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
diff@5.1.0
5.2.2

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
diff@4.0.2
4.0.4

Open the chart page →

5,984
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
diff@5.0.0
5.2.2

Open the chart page →

2,559
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
diff@5.0.0
5.2.2

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
diff@5.0.0
5.2.2

Open the chart page →

28,605
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
diff@4.0.2
4.0.4

Open the chart page →

5,459
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
diff@5.2.0
5.2.2

Open the chart page →

14,100
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
diff@5.1.0
5.2.2
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
diff@4.0.2
4.0.4
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
diff@4.0.2
4.0.4
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
diff@5.1.0
5.2.2

Open the chart page →

16,083
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
diff@5.1.0
5.2.2

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
diff@5.0.0
5.2.2

Open the chart page →

3,118

Container images carrying it

593 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
qxip/qryn:3.2.3977acc9c7a9fd
diff@5.2.0
5.2.2
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
diff@5.2.0
5.2.2
1
redis/redisinsight:2.68019fcf774631
diff@4.0.2
4.0.4
1
redis/redisinsight:3.2.055542a762210
diff@4.0.2
4.0.4
1
redis/redisinsight:2.46699d341bd329
diff@5.1.0
5.2.2
1
redis/redisinsight:3.485562d67a912
diff@4.0.2
4.0.4
1
requarks/wiki:canary-2.5.2438b5865a7386c
diff@4.0.2
4.0.4
1
roadiehq/community-backstage-image:latestef355bf5b639
diff@1.4.0
3.5.1
1
safeglobal/safe-client-gateway-nest:v1.51.012ccfd93fcaf
diff@5.2.0
5.2.2
1
samajh/alprbackend:latestea742b4372ad
diff@5.0.0
5.2.2
1
samajh/alprfrontend:latest05ef4fddbb75
diff@5.0.0
5.2.2
1
sharanalwar/redchef-frontend:latest5e82950b16b7
diff@5.2.0
5.2.2
1
shinobisystems/shinobi:dev3ca746937856
diff@5.0.0
5.2.2
1
shinobisystems/shinobi:latestc2f5ce2e1067
diff@5.0.0
5.2.2
1
shyamkrishna21/cloudvault:latestaf2785f5bb71
diff@5.2.0
5.2.2
1
shyamkrishna21/shopsync:latest3998b83def53
diff@5.2.0
5.2.2
1
sigp/siren:v3.0.42c219b04758e
diff@4.0.2
4.0.4
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
diff@3.5.0
3.5.1
1
sissbruecker/linkding:1.41.0-plusa222fb777e1f
diff@5.2.0
5.2.2
1
skylenet/ethstats-server:pow-latestd757cc016198
diff@5.0.0
5.2.2
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
diff@5.0.0
5.2.2
1
socialmediamacroscope/smile_server:0.3.31a528c794270
diff@5.0.0
5.2.2
1
solidproject/community-server:6.0.2ccc4acb7e9a1
diff@5.1.0
5.2.2
1
soulou2019/node-server:latest5e6ecfcc109e
diff@5.0.0
5.2.2
1
soulteary/cronicle:0.9.80ac2512fa6e39
diff@5.2.0
5.2.2
1
speckle/speckle-preview-service:2.26.3092384dba45d
diff@5.2.0
5.2.2
1
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
diff@5.2.0
5.2.2
1
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
diff@5.2.0
5.2.2
1
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
diff@5.2.0
5.2.2
1
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
diff@5.2.0
5.2.2
1
speckle/speckle-preview-service:2.17.14-branch.testing.72707.921a5f884fc39bca0c8
diff@5.1.0
5.2.2
1
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
diff@5.2.0
5.2.2
1
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
diff@5.2.0
5.2.2
1
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
diff@5.2.0
5.2.2
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
diff@5.1.0
5.2.2
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
diff@5.2.0
5.2.2
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
diff@5.2.0
5.2.2
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
diff@5.2.0
5.2.2
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
diff@5.1.0
5.2.2
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
diff@5.1.0
5.2.2
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
diff@5.2.0
5.2.2
1
srini78/nodejswebappeks:latest5d1cbdc6833a
diff@5.1.0
5.2.2
1
stakater/workshop-exercise:0.0.26076926b7159d3
diff@5.0.0
5.2.2
1
stanfordoval/almond-server:latest1a63cdccedaf
diff@4.0.2
4.0.4
1
subsquid/substrate-explorer:firesquid0889a857f192
diff@5.1.0
5.2.2
1
subsquid/substrate-ingest:firesquidfa549779e9b1
diff@5.1.0
5.2.2
1
supabase/postgres-meta:v0.96.6a84cc713585e
diff@5.2.0
5.2.2
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
diff@5.2.0
5.2.2
1
supabase/storage-api:v1.12.0f983fb50bd95
diff@5.2.0
5.2.2
1
supabase/studio:20241021-9f9b08326d8070c55e9
diff@5.2.0
5.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.