StackRadar

CVE-2026-24001

High

Advisory

Published 14 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
572
of 17,787 indexed, latest versions
Container images
594
deployed by those charts
Fix available
1 of 2
affected packages

jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Carried by container images the latest versions of 572 of 17,787 indexed charts deploy, on 594 images.

Affected packageAffected versionsFixed inImages
node-diffdeb5.0.0~dfsg+~5.0.1-4no fix listed1
diffnpm1.0.0, 1.0.2, 1.3.2, 1.4.0+10 more3.5.1, 4.0.4, 5.2.2, 8.0.3594
OSV records
UBUNTU-CVE-2026-24001GHSA-73rr-hh4g-fpgx

Charts affected

572 by stars
ChartLatestAffected imagesRadar Score
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
diff@5.2.0
5.2.2

Open the chart page →

4,768
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
diff@4.0.2
4.0.4

Open the chart page →

3,129
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
diff@5.1.0
5.2.2

Open the chart page →

2,789
skoonervhdirkVerified publisher0.1.41 of 1See more

skooner vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
diff@5.1.0
5.2.2

Open the chart page →

1,341
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
diff@5.1.0
5.2.2

Open the chart page →

9,347
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
diff@5.2.0
5.2.2

Open the chart page →

hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
diff@5.1.0
5.2.2

Open the chart page →

3,118
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
diff@5.2.0
5.2.2

Open the chart page →

3,031
resultappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

1,263
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

8,262
resultappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

1,263
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

8,262
websitewaldo-visionVerified publisher0.33.02 of 2See more

website waldo-vision 0.33.0

2 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
diff@5.1.0
5.2.2
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
diff@5.1.0
5.2.2

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
diff@4.0.2
4.0.4

Open the chart page →

5,984
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
diff@5.0.0
5.2.2

Open the chart page →

2,559
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
diff@5.0.0
5.2.2

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
diff@5.0.0
5.2.2

Open the chart page →

28,605
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
diff@4.0.2
4.0.4

Open the chart page →

5,459
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
diff@5.2.0
5.2.2

Open the chart page →

14,100
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
diff@5.1.0
5.2.2
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
diff@4.0.2
4.0.4
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
diff@4.0.2
4.0.4
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
diff@5.1.0
5.2.2

Open the chart page →

16,083
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
diff@5.1.0
5.2.2

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
diff@5.0.0
5.2.2

Open the chart page →

3,118

Container images carrying it

594 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
supabase/studio:20241021-9f9b08326d8070c55e9
diff@5.2.0
5.2.2
1
sysnet4admin/colosseum-cms:loge74b43c7f492
diff@4.0.2
4.0.4
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
diff@4.0.2
4.0.4
1
tawfiq58/express-server:latestc707555f6853
diff@5.1.0
5.2.2
1
tensorzero/ui:2026.6.0f2563d54724e
diff@8.0.2
8.0.3
1
th0th/node-red:4.0.3-debiand06fa39f7406
diff@5.2.0
5.2.2
1
thecloudspark/app-result:1.09a5302cb8312
diff@5.2.0
5.2.2
1
thecodingmachine/workadventure-back:v1.17.764001369dad5
diff@5.1.0
5.2.2
1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
diff@4.0.2
4.0.4
1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
diff@4.0.2
4.0.4
1
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
diff@5.1.0
5.2.2
1
thelounge/thelounge:4.3.0-alpine0037aa258261
diff@5.0.0
5.2.2
1
thingsboard/tb-js-executor:3.4.113e1eadf8ace
diff@5.0.0
5.2.2
1
thingsboard/tb-web-ui:3.4.157f98ed53b3d
diff@5.0.0
5.2.2
1
thingsboard/tb-web-ui:3.6.0d388378062cc
diff@5.0.0
5.2.2
1
thmmniii/fbs-collab:v1.27.15d389e3c5ce6
diff@5.2.0
5.2.2
1
thmmniii/fbs-qcm-backend:v1.27.1afbe511e5c24
diff@5.2.0
5.2.2
1
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
diff@5.2.0
5.2.2
1
tobirachel/node-project3:v17d9f37154994
diff@5.1.0
5.2.2
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
diff@4.0.2
4.0.4
1
treskon/portrait-ui:DEV-lateste7970783bc8d
diff@4.0.2
4.0.4
1
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
diff@5.0.0
5.2.2
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
diff@5.2.0
5.2.2
1
vabene1111/recipes:2.3.50f8d061895e9
diff@7.0.0
8.0.3
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
diff@4.0.2
4.0.4
1
vcnngr/pnbackend:latesteaf44ad0ad1f
diff@5.2.0
5.2.2
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
diff@5.2.0
5.2.2
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
diff@5.1.0
5.2.2
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
diff@4.0.2
4.0.4
1
visualregressiontracker/migration:5.0.1f983a1d4306e
diff@4.0.2
4.0.4
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
diff@5.1.0
5.2.2
1
vlebediantsev/notes-admin-front:latest007c6670ff48
diff@5.1.0
5.2.2
1
vlebediantsev/notes-project-front:latest945675fd2636
diff@5.1.0
5.2.2
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
diff@5.1.0
5.2.2
1
winfred008/amazon:910a68de5b398
diff@5.0.0
5.2.2
1
wiremind/scrapoxy:lateste7048929a676
diff@3.2.0
3.5.1
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
diff@5.2.0
5.2.2
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
diff@5.2.0
5.2.2
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
diff@5.2.0
5.2.2
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
diff@5.2.0
5.2.2
1
youssef11gaber10/deployment-ui-react:latestba6853e35c60
diff@5.0.0
5.2.2
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
diff@5.2.0
5.2.2
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
diff@5.2.0
5.2.2
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
diff@5.2.0
5.2.2
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
diff@5.2.0
5.2.2
1
zimengxiong/excalidash-backend:0.4.271273af713c91
diff@5.2.0
5.2.2
1
zimengxiong/excalidash-backend:0.6.0cbdab75f31b2
diff@5.2.0
5.2.2
1
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
diff@5.0.0
5.2.2
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
diff@5.0.0
5.2.2
1
zwavejs/zwave-js-ui:11.22.314d018bb689e
diff@5.2.0
5.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.