StackRadar

CVE-2026-24001

High

Advisory

Published 14 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
576
of 17,781 indexed, latest versions
Container images
598
deployed by those charts
Fix available
1 of 2
affected packages

jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Carried by container images the latest versions of 576 of 17,781 indexed charts deploy, on 598 images.

Affected packageAffected versionsFixed inImages
node-diffdeb5.0.0~dfsg+~5.0.1-4no fix listed1
diffnpm1.0.0, 1.0.2, 1.3.2, 1.4.0+10 more3.5.1, 4.0.4, 5.2.2, 8.0.3598
OSV records
UBUNTU-CVE-2026-24001GHSA-73rr-hh4g-fpgx

Charts affected

576 by stars
ChartLatestAffected imagesRadar Score
defactopsdefactops1.0.91 of 2See more

defactops defactops 1.0.9

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
defactops/defactops-backend:1.0.2307b663c0092a
diff@5.2.0
5.2.2

Open the chart page →

4,509
homarrdelerVerified publisher1.0.11 of 1See more

homarr deler 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
diff@5.1.0
5.2.2

Open the chart page →

1,924
demo-multiclust-chartdemo-model-chart1.0.02 of 3See more

demo-multiclust-chart demo-model-chart 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
gtato/demo-multiclus-registrator:1.0.09a744588fab3
diff@5.0.0
5.2.2
gtato/demo-multiclus-registry:1.0.02df5174f3cfd
diff@5.0.0
5.2.2

Open the chart page →

1,770
deploy-elibrarydeploy-elibrary-helm0.1.01 of 1See more

deploy-elibrary deploy-elibrary-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
psorab/elibrary:latest53b68896c4ce
diff@5.1.0
5.2.2

Open the chart page →

7,212
deploy-elibrarydeploy-elibrary-oo0.1.01 of 1See more

deploy-elibrary deploy-elibrary-oo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
jedi132000/nextapp:latestdc2a81e92f23
diff@5.1.0
5.2.2

Open the chart page →

8,106
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
diff@5.2.0
5.2.2

Open the chart page →

2,529
backend-servicedev-krishan-dhaka-charts1.0.31 of 1See more

backend-service dev-krishan-dhaka-charts 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
devkrishan001/backend:latestf1c3acadeabe
diff@5.2.0
5.2.2

Open the chart page →

1,264
apachedevops0.1.01 of 4See more

apache devops 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
diff@5.1.0
5.2.2

Open the chart page →

30,031
laraveldevops0.10.31 of 4See more

laravel devops 0.10.3

1 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/codingducksrl/laravel:8.15be52524664c
diff@5.1.0
5.2.2

Open the chart page →

29,033
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
diff@8.0.2
8.0.3

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
diff@8.0.2
8.0.3

Open the chart page →

68,240
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.009b7e8705673
diff@5.1.0
5.2.2
langgenius/dify-web:1.0.0d64914ff0d6d
diff@5.2.0
5.2.2

Open the chart page →

19,224
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
diff@5.2.0
5.2.2

Open the chart page →

4,551
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
diff@5.2.0
5.2.2

Open the chart page →

4,217
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
diff@5.2.0
5.2.2

Open the chart page →

2,862
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-24001.

Open the chart page →

4,251
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
diff@4.0.1
4.0.4

Open the chart page →

11,174
dyff-frontenddyff-frontendVerified publisher0.20.11 of 1See more

dyff-frontend dyff-frontend 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
diff@5.2.0
5.2.2

Open the chart page →

973
self-orchestratoreclipse-aeriosVerified publisher1.2.01 of 1See more

self-orchestrator eclipse-aerios 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
eclipseaerios/self-orchestrator:1.2.08b123bec5679
diff@5.2.0
5.2.2

Open the chart page →

2,385
dashboardedu1.0.01 of 1See more

dashboard edu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
diff@5.2.0
5.2.2

Open the chart page →

1,344
deploy-elibraryeducative-helm-bookapp0.5.01 of 1See more

deploy-elibrary educative-helm-bookapp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
diff@5.1.0
5.2.2

Open the chart page →

5,112
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
library/node:18-alpine8d6421d663b4
diff@5.2.0
5.2.2

Open the chart page →

2,942
reddarkemmas-chartsVerified publisher0.0.21 of 1See more

reddark emmas-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/0xemma/reddark:main2a115e991894
diff@5.1.0
5.2.2

Open the chart page →

1,998
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
diff@5.0.0
5.2.2

Open the chart page →

27,096
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
diff@5.2.0
5.2.2

Open the chart page →

2,033
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
diff@5.2.0
5.2.2

Open the chart page →

839
blobscanethereum-helm-chartsVerified publisher0.1.11 of 1See more

blobscan ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ethpandaops/blobscan:latest7a9ab6370657
diff@5.0.0
5.2.2

Open the chart page →

1,329
blockscoutethereum-helm-chartsVerified publisher0.2.31 of 2See more

blockscout ethereum-helm-charts 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
blockscout/blockscout:5.1.5c365a8f2dc12
diff@5.0.0
5.2.2

Open the chart page →

1,928
ethstatsethereum-helm-chartsVerified publisher0.1.41 of 1See more

ethstats ethereum-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
skylenet/ethstats-server:pow-latestd757cc016198
diff@5.0.0
5.2.2

Open the chart page →

1,109
bee-localchainethersphereVerified publisher0.2.01 of 1See more

bee-localchain ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
diff@5.1.0
5.2.2

Open the chart page →

2,266
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
diff@3.5.0
3.5.1

Open the chart page →

3,260
etherproxyethersphereVerified publisher0.2.01 of 1See more

etherproxy ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ethersphere/etherproxy:1.0.056029b0985f4
diff@5.1.0
5.2.2

Open the chart page →

745
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
diff@5.1.0
5.2.2

Open the chart page →

4,756
multichain-proxyethersphereVerified publisher0.1.01 of 1See more

multichain-proxy ethersphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ethersphere/multichain-proxy:0.0.261f5419afbcd
diff@5.2.0
5.2.2

Open the chart page →

795
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
diff@5.0.0
5.2.2

Open the chart page →

3,320
evobotevobotVerified publisher0.1.11 of 1See more

evobot evobot 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
diff@5.1.0
5.2.2

Open the chart page →

2,987
my-chartexpress-server0.1.01 of 1See more

my-chart express-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
tawfiq58/express-server:latestc707555f6853
diff@5.1.0
5.2.2

Open the chart page →

1,113
mandefactlyVerified publisher0.5.161 of 3See more

mande factly 0.5.16

1 of the 3 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
factly/mande-web:0.34.1742355964b0e
diff@5.1.0
5.2.2

Open the chart page →

4,777
smeejasfanzynoodle0.0.11 of 1See more

smeejas fanzynoodle 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
fanzynoodle/smeejas:0.0.15f9916c1a287
diff@5.0.0
5.2.2

Open the chart page →

4,127
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
diff@5.0.0
5.2.2

Open the chart page →

3,311
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-user-service:1.049e164a9a439
diff@5.1.0
5.2.2

Open the chart page →

7,691
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
diff@5.2.0
5.2.2

Open the chart page →

64,489
fdsc-dashboardfiware0.6.81 of 1See more

fdsc-dashboard fiware 0.6.8

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
diff@5.2.0
5.2.2

Open the chart page →

705
iotagent-jsonfiware0.1.21 of 1See more

iotagent-json fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
fiware/iotagent-json:3.1.0879b21a0d36d
diff@5.1.0
5.2.2

Open the chart page →

937
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
diff@4.0.2
4.0.4

Open the chart page →

1,489
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
diff@5.2.0
5.2.2

Open the chart page →

4,650
flanksource-uiflanksourceVerified publisher1.4.3181 of 1See more

flanksource-ui flanksource 1.4.318

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.318891f21df54fb
diff@5.2.0
5.2.2

Open the chart page →

2,558
mission-controlflanksourceVerified publisher0.1.3361 of 8See more

mission-control flanksource 0.1.336

1 of the 8 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
diff@5.2.0
5.2.2

Open the chart page →

8,902
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
louislam/uptime-kuma:13d632903e6af
diff@5.2.0
5.2.2

Open the chart page →

3,474
mod-graphqlfolio-org0.1.301 of 1See more

mod-graphql folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-24001.

Container imageDigestPackageFixed in
folioci/mod-graphql:latestf0655a6a08fd
diff@5.2.0
5.2.2

Open the chart page →

1,091

Container images carrying it

598 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
diff@4.0.2
4.0.4
5
kodekloud/examplevotingapp_result:v1e510023fdf38
diff@5.1.0
5.2.2
4
redis/redisinsight:3.8:latestb5e19ee240ab
diff@5.2.0
5.2.2
4
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
diff@5.2.0
5.2.2
4
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
diff@5.1.0
5.2.2
4
assistiot/dlt_api:2.0.0e36a8922fa0c
diff@5.1.0
5.2.2
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
diff@4.0.2
4.0.4
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/emails:59b64c36c866b3555c135c70de76a884e63f86197d2d6d7c099a
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/schema:59b64c36c866b3555c135c70de76a884e63f8619931d1f6e5ad4
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/server:59b64c36c866b3555c135c70de76a884e63f86196d3899d281cc
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/storage:59b64c36c866b3555c135c70de76a884e63f86199808dac13353
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/tokens:59b64c36c866b3555c135c70de76a884e63f86190f3416d940b4
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/usage:59b64c36c866b3555c135c70de76a884e63f861953619ee7614e
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/usage-ingestor:59b64c36c866b3555c135c70de76a884e63f861947b87c071af4
diff@5.1.0
5.2.2
3
ghcr.io/kamilkisiela/graphql-hive/webhooks:59b64c36c866b3555c135c70de76a884e63f861918a5c5b5b671
diff@5.1.0
5.2.2
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
diff@8.0.2
8.0.3
3
agoldis/sorry-cypress-api:2.5.11afaa5a84051d
diff@5.1.0
5.2.2
2
agoldis/sorry-cypress-director:2.5.1110228ecd353b
diff@5.1.0
5.2.2
2
epamedp/krci-portal:0.8.0687acf641097
diff@5.2.0
5.2.2
2
ethersphere/bee-localchain:latest0558799ca992
diff@5.1.0
5.2.2
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
diff@4.0.2
4.0.4
2
governify/assets-manager:v1.4.12987672448c7
diff@5.0.0
5.2.2
2
governify/director:v1.4.0608c6940bb98
diff@5.0.0
5.2.2
2
governify/registry:v3.4.0d3f37f4f8168
diff@4.0.2
4.0.4
2
governify/render:v2.2.0daeca1ce28e6
diff@4.0.2
4.0.4
2
governify/reporter:v2.2.038595913458f
diff@4.0.2
4.0.4
2
gradiant/open5gs-webui:2.7.5fbd10c017541
diff@5.1.0
5.2.2
2
hookiesolutions/webhookie:latest0629694246ba
diff@5.0.0
5.2.2
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
diff@5.2.0
5.2.2
2
ilum/ui:6.7.3998937726679
diff@8.0.2
8.0.3
2
infisical/infisical:latest:v0.165.602082bf13163
diff@5.2.0
5.2.2
2
krtk6160/galoy-nostrcc82a694f818
diff@5.1.0
5.2.2
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
diff@5.1.0
5.2.2
2
langgenius/dify-sandbox:0.2.009b7e8705673
diff@5.1.0
5.2.2
2
library/mongo-express:1.0.2:latest1b23d7976f02
diff@5.2.0
5.2.2
2
migmartri/prerender:latest486aacfd5aa9
diff@3.2.0
3.5.1
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
diff@4.0.2
4.0.4
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
diff@4.0.2
4.0.4
2
mojaloop/reporting:v12.1.0d480a62103d6
diff@5.2.0
5.2.2
2
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
diff@5.2.0
5.2.2
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
diff@5.2.0
5.2.2
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
diff@5.0.0
5.2.2
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
diff@5.2.0
5.2.2
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
diff@4.0.2
4.0.4
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
diff@8.0.2
8.0.3
2
moreillon/api-proxy:a3e8b41e9e578c9653b6
diff@5.0.0
5.2.2
2
moreillon/group-manager:v4.9.0d5a0ec8394c0
diff@4.0.2
4.0.4
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
diff@5.1.0
5.2.2
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.