StackRadar

CVE-2026-29074

High

Advisory

Published 4 Mar 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
38
of 17,781 indexed, latest versions
Container images
37
deployed by those charts
Fix available
1 of 1
affected package

SVGO DoS through entity expansion in DOCTYPE (Billion Laughs)

Carried by container images the latest versions of 38 of 17,781 indexed charts deploy, on 37 images.

Affected packageAffected versionsFixed inImages
svgonpm2.8.0, 3.1.0, 3.2.0, 3.3.2+1 more2.8.1, 3.3.3, 4.0.137
OSV records
GHSA-xpqw-6gx7-v673

Charts affected

38 by stars
ChartLatestAffected imagesRadar Score
servarrservarr1.0.21 of 10See more

servarr servarr 1.0.2

1 of the 10 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
svgo@2.8.0
2.8.1

Open the chart page →

14,238
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
svgo@2.8.0
2.8.1

Open the chart page →

5,251
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
svgo@3.1.0
3.3.3

Open the chart page →

17,404
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
svgo@3.3.2
3.3.3

Open the chart page →

3,451
overseerrpree-helm-chartsVerified publisher1.2.01 of 1See more

overseerr pree-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.35.06197516c9d7b
svgo@2.8.0
2.8.1

Open the chart page →

2,702
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
svgo@2.8.0
2.8.1

Open the chart page →

3,925
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
svgo@3.2.0
3.3.3

Open the chart page →

31,844
jellyseerrrtomik-helm-chartsVerified publisher0.0.11 of 1See more

jellyseerr rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
svgo@2.8.0
2.8.1

Open the chart page →

2,823
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
svgo@2.8.0
2.8.1

Open the chart page →

12,581
apimap-developerapimapOfficialVerified publisher1.4.11 of 1See more

apimap-developer apimap 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
apimap/developer:v1.3.1406d3858e20c
svgo@2.8.0
2.8.1

Open the chart page →

2,353
apimap-portalapimapOfficialVerified publisher2.4.01 of 1See more

apimap-portal apimap 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
apimap/portal:v2.4.0041a4790c65c
svgo@2.8.0
2.8.1

Open the chart page →

2,396
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
assistiot/open_api_frontend:1.0.1f11d82defc70
svgo@2.8.0
2.8.1

Open the chart page →

18,277
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
svgo@3.2.0
3.3.3

Open the chart page →

32,501
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
svgo@2.8.0
2.8.1

Open the chart page →

3,071
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
coldatom/containers-security-front:latest7c2fbbb41bcf
svgo@2.8.0
2.8.1

Open the chart page →

9,146
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
svgo@3.3.2
3.3.3

Open the chart page →

2,529
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
svgo@2.8.0
2.8.1

Open the chart page →

4,551
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
svgo@3.3.2
3.3.3

Open the chart page →

3,451
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
svgo@3.3.2
3.3.3

Open the chart page →

3,614
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
svgo@2.8.0
2.8.1

Open the chart page →

3,407
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
svgo@2.8.0
2.8.1

Open the chart page →

11,812
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
svgo@2.8.0
2.8.1

Open the chart page →

2,685
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
svgo@2.8.0
2.8.1

Open the chart page →

3,555
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
svgo@4.0.0
4.0.1

Open the chart page →

8,303
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
svgo@2.8.0
2.8.1

Open the chart page →

2,116
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
svgo@2.8.0
2.8.1

Open the chart page →

2,116
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
svgo@2.8.0
2.8.1

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
svgo@2.8.0
2.8.1

Open the chart page →

2,116
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
svgo@2.8.0
2.8.1

Open the chart page →

17,929
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
svgo@2.8.0
2.8.1

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
svgo@2.8.0
2.8.1

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
svgo@2.8.0
2.8.1

Open the chart page →

15,187
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
svgo@2.8.0
2.8.1

Open the chart page →

7,413
semaphoreschoenwald0.1.31 of 1See more

semaphore schoenwald 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
0hlov3/semaphore:v1.0.050f874ec096b
svgo@2.8.0
2.8.1

Open the chart page →

1,796
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
svgo@2.8.0
2.8.1

Open the chart page →

5,497
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
svgo@2.8.0
2.8.1

Open the chart page →

7,574
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
svgo@3.3.2
3.3.3

Open the chart page →

15,635
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-29074.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
svgo@3.3.2
3.3.3

Open the chart page →

5,984

Container images carrying it

37 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hoppscotch/hoppscotch:2024.8.2f1da831950b7
svgo@3.3.2
3.3.3
2
0hlov3/semaphore:v1.0.050f874ec096b
svgo@2.8.0
2.8.1
1
apimap/developer:v1.3.1406d3858e20c
svgo@2.8.0
2.8.1
1
apimap/portal:v2.4.0041a4790c65c
svgo@2.8.0
2.8.1
1
assistiot/open_api_frontend:1.0.1f11d82defc70
svgo@2.8.0
2.8.1
1
baserow/baserow:1.30.1df0c42eb67e8
svgo@3.1.0
3.3.3
1
ccjacobs14/amazon:59a9b14a6f09e
svgo@2.8.0
2.8.1
1
coldatom/containers-security-front:latest7c2fbbb41bcf
svgo@2.8.0
2.8.1
1
directus/directus:11.1.0e3c8bb975350
svgo@2.8.0
2.8.1
1
fallenbagel/jellyseerr:latest4538137bc5af
svgo@2.8.0
2.8.1
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
svgo@2.8.0
2.8.1
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
svgo@2.8.0
2.8.1
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
svgo@2.8.0
2.8.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
svgo@3.3.2
3.3.3
1
joplin/server:3.0-beta52af57880c0e
svgo@2.8.0
2.8.1
1
joplin/server:2.14.2-betab87564ef34e9
svgo@2.8.0
2.8.1
1
kyso/kyso-front:lateste52595c5c16f
svgo@2.8.0
2.8.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
svgo@2.8.0
2.8.1
1
linuxserver/overseerr:1.35.06108ed066d4a
svgo@2.8.0
2.8.1
1
mautic/mautic:7-apacheeb8cc73d97e1
svgo@4.0.0
4.0.1
1
misskey/misskey:12.110.1e08b7c478093
svgo@2.8.0
2.8.1
1
mitchxxx/amazon:214e72480ec63a
svgo@2.8.0
2.8.1
1
ooghenekaro/amazon:latest03394ba1d6d8
svgo@2.8.0
2.8.1
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
svgo@3.3.2
3.3.3
1
sigp/siren:v3.0.42c219b04758e
svgo@3.3.2
3.3.3
1
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
svgo@3.3.2
3.3.3
1
treskon/portrait-ui:DEV-lateste7970783bc8d
svgo@3.2.0
3.3.3
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
svgo@2.8.0
2.8.1
1
vlebediantsev/notes-admin-front:latest007c6670ff48
svgo@2.8.0
2.8.1
1
vlebediantsev/notes-project-front:latest945675fd2636
svgo@2.8.0
2.8.1
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
svgo@2.8.0
2.8.1
1
winfred008/amazon:910a68de5b398
svgo@2.8.0
2.8.1
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
svgo@3.2.0
3.3.3
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
svgo@2.8.0
2.8.1
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
svgo@2.8.0
2.8.1
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
svgo@2.8.0
2.8.1
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
svgo@2.8.0
2.8.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.