StackRadar

CVE-2026-30838

Medium

Advisory

Published 6 Mar 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
20
deployed by those charts
Fix available
1 of 1
affected package

CommonMark has DisallowedRawHtml extension bypass via whitespace in HTML tag names

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 20 images.

Affected packageAffected versionsFixed inImages
league/commonmarkcomposer2.2.1, 2.3.0, 2.3.3, 2.3.4+6 more2.8.120
OSV records
GHSA-4v6x-c7xx-hw9f

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
league/commonmark@2.3.4
2.8.1

Open the chart page →

18,509
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
league/commonmark@2.7.1
2.8.1

Open the chart page →

5,634
bookstackgabe565Verified publisher0.20.01 of 1See more

bookstack gabe565 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
league/commonmark@2.6.1
2.8.1

Open the chart page →

2,811
invoiceninjainvoiceninjaVerified publisher0.10.21 of 5See more

invoiceninja invoiceninja 0.10.2

1 of the 5 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
invoiceninja/invoiceninja:5.6.241437916dee01
league/commonmark@2.4.0
2.8.1

Open the chart page →

2,709
akauntingf3k-techVerified publisher1.3121.01 of 4See more

akaunting f3k-tech 1.3121.0

1 of the 4 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
akaunting/akaunting:3.1.21-fpm-alpine-nginxe7d5c245b1a0
league/commonmark@2.8.0
2.8.1

Open the chart page →

4,333
firefly-iiigeek-cookbookVerified publisher0.3.01 of 1See more

firefly-iii geek-cookbook 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
fireflyiii/core:version-5.6.142f4283bd0cf7
league/commonmark@2.2.1
2.8.1

Open the chart page →

2,076
monicageek-cookbookVerified publisher8.2.01 of 1See more

monica geek-cookbook 8.2.0

1 of the 1 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
library/monica:3.7.0-apacheceb1ba4196ab
league/commonmark@2.2.1
2.8.1

Open the chart page →

2,096
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
leantime/leantime:3.3.3ad4bfb0699d3
league/commonmark@2.5.3
2.8.1

Open the chart page →

6,416
castopodh2mVerified publisher1.12.101 of 3See more

castopod h2m 1.12.10

1 of the 3 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
castopod/castopod:1.12.101fd37280cbb2
league/commonmark@2.5.3
2.8.1

Open the chart page →

10,072
linkstackadnoctemVerified publisher0.4.01 of 1See more

linkstack adnoctem 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
linkstackorg/linkstack:latest1c8b05399ee4
league/commonmark@2.8.0
2.8.1

Open the chart page →

2,092
heimdallegebackVerified publisher2.0.41 of 1See more

heimdall egeback 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
linuxserver/heimdall:2.6.371597f4461e4
league/commonmark@2.4.2
2.8.1

Open the chart page →

1,664
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
league/commonmark@2.3.0
2.8.1

Open the chart page →

20,933
monicagabe565Verified publisher0.10.01 of 2See more

monica gabe565 0.10.0

1 of the 2 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
library/monica:4.1.2-fpm-alpine6d1b2bd0947e
league/commonmark@2.4.2
2.8.1

Open the chart page →

1,173
anonaddygeek-cookbookVerified publisher6.0.01 of 1See more

anonaddy geek-cookbook 6.0.0

1 of the 1 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
anonaddy/anonaddy:0.12.3957a95565166
league/commonmark@2.3.3
2.8.1

Open the chart page →

4,788
castopodhelmforgeVerified publisher1.2.71 of 3See more

castopod helmforge 1.2.7

1 of the 3 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
castopod/castopod:1.15.54e4f0440520f
league/commonmark@2.8.0
2.8.1

Open the chart page →

9,342
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
league/commonmark@2.4.0
2.8.1

Open the chart page →

12,813
librenmsnimbolus0.5.11 of 3See more

librenms nimbolus 0.5.1

1 of the 3 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
librenms/librenms:24.11.00920bc9117a8
league/commonmark@2.5.3
2.8.1

Open the chart page →

2,293
firefly-iiiphntom0.2.101 of 2See more

firefly-iii phntom 0.2.10

1 of the 2 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
phntom/fireflyiii:version-5.7.5f881ea5fbbf1
league/commonmark@2.3.0
2.8.1

Open the chart page →

1,813
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
league/commonmark@2.7.1
2.8.1

Open the chart page →

6,094
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2026-30838.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
league/commonmark@2.3.3
2.8.1

Open the chart page →

2,019

Container images carrying it

20 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
akaunting/akaunting:3.0.1552811b36ec3a
league/commonmark@2.4.0
2.8.1
1
akaunting/akaunting:3.1.21-fpm-alpine-nginxe7d5c245b1a0
league/commonmark@2.8.0
2.8.1
1
anonaddy/anonaddy:0.12.3957a95565166
league/commonmark@2.3.3
2.8.1
1
castopod/castopod:1.12.101fd37280cbb2
league/commonmark@2.5.3
2.8.1
1
castopod/castopod:1.15.54e4f0440520f
league/commonmark@2.8.0
2.8.1
1
fireflyiii/core:version-5.6.142f4283bd0cf7
league/commonmark@2.2.1
2.8.1
1
invoiceninja/invoiceninja:5.6.241437916dee01
league/commonmark@2.4.0
2.8.1
1
leantime/leantime:3.3.3ad4bfb0699d3
league/commonmark@2.5.3
2.8.1
1
library/monica:4.1.2-fpm-alpine6d1b2bd0947e
league/commonmark@2.4.2
2.8.1
1
library/monica:3.7.0-apacheceb1ba4196ab
league/commonmark@2.2.1
2.8.1
1
librenms/librenms:24.11.00920bc9117a8
league/commonmark@2.5.3
2.8.1
1
linkstackorg/linkstack:latest1c8b05399ee4
league/commonmark@2.8.0
2.8.1
1
linuxserver/heimdall:2.6.371597f4461e4
league/commonmark@2.4.2
2.8.1
1
phntom/fireflyiii:version-5.7.5f881ea5fbbf1
league/commonmark@2.3.0
2.8.1
1
snipe/snipe-it:v8.3.1141ebf2386fe
league/commonmark@2.7.1
2.8.1
1
snipe/snipe-it:v6.0.1455fb7636a98c
league/commonmark@2.3.4
2.8.1
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
league/commonmark@2.6.1
2.8.1
1
ghcr.io/monicahq/monica-next:main8be69156acbb
league/commonmark@2.7.1
2.8.1
1
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
league/commonmark@2.3.3
2.8.1
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
league/commonmark@2.3.0
2.8.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.