StackRadar

CVE-2026-30827

High

Advisory

Published 6 Mar 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
8
of 17,781 indexed, latest versions
Container images
8
deployed by those charts
Fix available
1 of 1
affected package

express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network

Carried by container images the latest versions of 8 of 17,781 indexed charts deploy, on 8 images.

Affected packageAffected versionsFixed inImages
express-rate-limitnpm8.1.0, 8.2.18.1.1, 8.2.28
OSV records
GHSA-46wh-pxpv-q5gq

Charts affected

8 by stars
ChartLatestAffected imagesRadar Score
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-30827.

Container imageDigestPackageFixed in
unleashorg/unleash-server:7.5.09adb37e399ba
express-rate-limit@8.2.1
8.2.2

Open the chart page →

2,059
adeptia-automate-mcpadeptia-automate-mcp1.0.01 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-30827.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
express-rate-limit@8.2.1
8.2.2

Open the chart page →

3,600
cors-proxycors-proxyVerified publisher1.2.01 of 1See more

cors-proxy cors-proxy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-30827.

Container imageDigestPackageFixed in
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
express-rate-limit@8.1.0
8.1.1

Open the chart page →

1,598
pangolinkrzwiatrzyk0.11.01 of 1See more

pangolin krzwiatrzyk 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-30827.

Container imageDigestPackageFixed in
fosrl/pangolin:1.13.0c32ad797ab96
express-rate-limit@8.2.1
8.2.2

Open the chart page →

3,441
outscale-s3-exploreroutscale-s3-explorer0.1.41 of 1See more

outscale-s3-explorer outscale-s3-explorer 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-30827.

Container imageDigestPackageFixed in
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
express-rate-limit@8.2.1
8.2.2

Open the chart page →

1,811
shopsyncshopsyncVerified publisher1.0.01 of 1See more

shopsync shopsync 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-30827.

Container imageDigestPackageFixed in
shyamkrishna21/shopsync:latest3998b83def53
express-rate-limit@8.2.1
8.2.2

Open the chart page →

1,088
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-30827.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
express-rate-limit@8.2.1
8.2.2

Open the chart page →

2,028
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-30827.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
express-rate-limit@8.2.1
8.2.2

Open the chart page →

2,620

Container images carrying it

8 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
express-rate-limit@8.2.1
8.2.2
1
fosrl/pangolin:1.13.0c32ad797ab96
express-rate-limit@8.2.1
8.2.2
1
shyamkrishna21/shopsync:latest3998b83def53
express-rate-limit@8.2.1
8.2.2
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
express-rate-limit@8.2.1
8.2.2
1
unleashorg/unleash-server:7.5.09adb37e399ba
express-rate-limit@8.2.1
8.2.2
1
zimengxiong/excalidash-backend:0.4.271273af713c91
express-rate-limit@8.2.1
8.2.2
1
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
express-rate-limit@8.1.0
8.1.1
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
express-rate-limit@8.2.1
8.2.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.