StackRadar

CVE-2026-24001

High

Advisory

Published 14 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
576
of 17,781 indexed, latest versions
Container images
598
deployed by those charts
Fix available
1 of 2
affected packages

jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Carried by container images the latest versions of 576 of 17,781 indexed charts deploy, on 598 images.

Affected packageAffected versionsFixed inImages
node-diffdeb5.0.0~dfsg+~5.0.1-4no fix listed1
diffnpm1.0.0, 1.0.2, 1.3.2, 1.4.0+10 more3.5.1, 4.0.4, 5.2.2, 8.0.3598
OSV records
UBUNTU-CVE-2026-24001GHSA-73rr-hh4g-fpgx

Charts affected

576 by stars
ChartLatestAffected imagesRadar Score
altinnendata-apptumogroup0.1.141 of 1See more

altinnendata-app tumogroup 0.1.14

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
sondresjo/altinnendata-app:v1.8.011ead455b492
diff@5.2.0
5.2.2

Open the chart page →

1,833
nstuning-apptumogroup0.1.171 of 1See more

nstuning-app tumogroup 0.1.17

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
sondresjo/nstuning-app:v1.6.10ffca294f10ba
diff@5.2.0
5.2.2

Open the chart page →

1,842
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
diff@5.2.0
5.2.2

Open the chart page →

2,620
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
diff@5.2.0
5.2.2

Open the chart page →

5,228
uoappuoapp1.1.01 of 1See more

uoapp uoapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
okaforuchena/uo-docker:V1.0.0004e81250f48
diff@5.1.0
5.2.2

Open the chart page →

1,187
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
diff@5.2.0
5.2.2

Open the chart page →

4,768
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
diff@4.0.2
4.0.4

Open the chart page →

3,129
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
diff@5.1.0
5.2.2

Open the chart page →

2,789
skoonervhdirkVerified publisher0.1.41 of 1See more

skooner vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
diff@5.1.0
5.2.2

Open the chart page →

1,341
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
diff@5.1.0
5.2.2

Open the chart page →

9,347
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
diff@5.1.0
5.2.2

Open the chart page →

3,118
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
diff@5.2.0
5.2.2

Open the chart page →

3,031
resultappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

1,263
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

8,262
resultappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

1,263
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2

Open the chart page →

8,262
websitewaldo-visionVerified publisher0.33.02 of 2See more

website waldo-vision 0.33.0

2 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
diff@5.1.0
5.2.2
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
diff@5.1.0
5.2.2

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
diff@4.0.2
4.0.4

Open the chart page →

5,984
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
diff@5.0.0
5.2.2

Open the chart page →

2,559
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
diff@5.0.0
5.2.2

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
diff@5.0.0
5.2.2

Open the chart page →

28,605
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
diff@4.0.2
4.0.4

Open the chart page →

5,459
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
diff@5.2.0
5.2.2

Open the chart page →

14,100
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
diff@5.1.0
5.2.2
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
diff@4.0.2
4.0.4
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
diff@4.0.2
4.0.4
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
diff@5.1.0
5.2.2

Open the chart page →

16,083
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
diff@5.1.0
5.2.2

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
diff@5.0.0
5.2.2

Open the chart page →

3,118

Container images carrying it

598 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
diff@4.0.2
4.0.4
5
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2
4
redis/redisinsight:3.8:latestb5e19ee240ab
diff@5.2.0
5.2.2
4
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
diff@5.2.0
5.2.2
4
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
diff@5.1.0
5.2.2
4
assistiot/dlt_api:2.0.0e36a8922fa0c
diff@5.1.0
5.2.2
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
diff@4.0.2
4.0.4
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/emails:59b64c36c866b3555c135c70de76a884e63f86197d2d6d7c099a
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/schema:59b64c36c866b3555c135c70de76a884e63f8619931d1f6e5ad4
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/server:59b64c36c866b3555c135c70de76a884e63f86196d3899d281cc
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/storage:59b64c36c866b3555c135c70de76a884e63f86199808dac13353
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/tokens:59b64c36c866b3555c135c70de76a884e63f86190f3416d940b4
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/usage:59b64c36c866b3555c135c70de76a884e63f861953619ee7614e
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/usage-ingestor:59b64c36c866b3555c135c70de76a884e63f861947b87c071af4
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/webhooks:59b64c36c866b3555c135c70de76a884e63f861918a5c5b5b671
diff@5.1.0
5.2.2
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
diff@8.0.2
8.0.3
3
agoldis/sorry-cypress-api:2.5.11afaa5a84051d
diff@5.1.0
5.2.2
2
agoldis/sorry-cypress-director:2.5.1110228ecd353b
diff@5.1.0
5.2.2
2
epamedp/krci-portal:0.8.0687acf641097
diff@5.2.0
5.2.2
2
ethersphere/bee-localchain:latest0558799ca992
diff@5.1.0
5.2.2
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
diff@4.0.2
4.0.4
2
governify/assets-manager:v1.4.12987672448c7
diff@5.0.0
5.2.2
2
governify/director:v1.4.0608c6940bb98
diff@5.0.0
5.2.2
2
governify/registry:v3.4.0d3f37f4f8168
diff@4.0.2
4.0.4
2
governify/render:v2.2.0daeca1ce28e6
diff@4.0.2
4.0.4
2
governify/reporter:v2.2.038595913458f
diff@4.0.2
4.0.4
2
gradiant/open5gs-webui:2.7.5fbd10c017541
diff@5.1.0
5.2.2
2
hookiesolutions/webhookie:latest0629694246ba
diff@5.0.0
5.2.2
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
diff@5.2.0
5.2.2
2
ilum/ui:6.7.3998937726679
diff@8.0.2
8.0.3
2
infisical/infisical:latest:v0.165.602082bf13163
diff@5.2.0
5.2.2
2
krtk6160/galoy-nostrcc82a694f818
diff@5.1.0
5.2.2
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
diff@5.1.0
5.2.2
2
langgenius/dify-sandbox:0.2.009b7e8705673
diff@5.1.0
5.2.2
2
library/mongo-express:1.0.2:latest1b23d7976f02
diff@5.2.0
5.2.2
2
migmartri/prerender:latest486aacfd5aa9
diff@3.2.0
3.5.1
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
diff@4.0.2
4.0.4
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
diff@4.0.2
4.0.4
2
mojaloop/reporting:v12.1.0d480a62103d6
diff@5.2.0
5.2.2
2
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
diff@5.2.0
5.2.2
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
diff@5.2.0
5.2.2
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
diff@5.0.0
5.2.2
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
diff@5.2.0
5.2.2
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
diff@4.0.2
4.0.4
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
diff@8.0.2
8.0.3
2
moreillon/api-proxy:a3e8b41e9e578c9653b6
diff@5.0.0
5.2.2
2
moreillon/group-manager:v4.9.0d5a0ec8394c0
diff@4.0.2
4.0.4
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
diff@5.1.0
5.2.2
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.