StackRadar

CVE-2026-31808

Medium

Advisory

Published 10 Mar 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
76
of 17,781 indexed, latest versions
Container images
69
deployed by those charts
Fix available
1 of 1
affected package

file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header

Carried by container images the latest versions of 76 of 17,781 indexed charts deploy, on 69 images.

Affected packageAffected versionsFixed inImages
file-typenpm14.1.4, 14.7.1, 15.0.1, 16.2.0+12 more21.3.169
OSV records
GHSA-5v7r-6r5c-r473

Charts affected

76 by stars
ChartLatestAffected imagesRadar Score
backstagebackstageOfficialVerified publisher2.10.11 of 1See more

backstage backstage 2.10.1

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
ghcr.io/backstage/backstage:latest792e262ea504
file-type@16.5.4
21.3.1

Open the chart page →

1,195
n8nn8n0.23.01 of 1See more

n8n n8n 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
n8nio/n8n:1.33.1dd171d45102a
file-type@16.5.4
21.3.1

Open the chart page →

5,639
redisinsightheywood8-helm-chartsVerified publisher0.4.51 of 1See more

redisinsight heywood8-helm-charts 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
heywood8/redisinsight:2.28.00bc9ab313d37
file-type@16.5.4
21.3.1

Open the chart page →

2,828
redisinsightredisinsight-guiVerified publisher1.3.51 of 1See more

redisinsight redisinsight-gui 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
redis/redisinsight:3.8b5e19ee240ab
file-type@16.5.4
21.3.1

Open the chart page →

1,038
redisinsight-secureredisinsight-secureVerified publisher1.0.21 of 1See more

redisinsight-secure redisinsight-secure 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
redis/redisinsight:2.68019fcf774631
file-type@16.5.4
21.3.1

Open the chart page →

1,721
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
file-type@16.5.4
21.3.1

Open the chart page →

1,339
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
file-type@17.1.1
21.3.1

Open the chart page →

5,251
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
file-type@15.0.1
21.3.1

Open the chart page →

5,946
librechatlibrechat1.8.101 of 3See more

librechat librechat 1.8.10

1 of the 3 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
file-type@18.7.0
21.3.1

Open the chart page →

2,654
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
file-type@16.5.0
21.3.1

Open the chart page →

22,773
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
file-type@16.5.4
21.3.1

Open the chart page →

7,776
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
file-type@16.3.0
21.3.1

Open the chart page →

24,488
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
file-type@20.4.1
21.3.1

Open the chart page →

4,016
cap-captcha-serverf3k-techVerified publisher0.21.01 of 1See more

cap-captcha-server f3k-tech 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
tiago2/cap:2.159f5ae4e261e
file-type@21.0.0
21.3.1

Open the chart page →

1,664
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
file-type@21.0.0
21.3.1

Open the chart page →

15,712
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
file-type@19.0.0
21.3.1

Open the chart page →

5,654
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
file-type@16.5.4
21.3.1

Open the chart page →

2,575
patchworkpatchworkVerified publisher0.8.61 of 2See more

patchwork patchwork 0.8.6

1 of the 2 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/patchwork:mainc01e018bced4
file-type@20.4.1
21.3.1

Open the chart page →

2,083
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
file-type@16.5.4
21.3.1

Open the chart page →

31,844
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
file-type@15.0.1
21.3.1

Open the chart page →

3,833
discord-botxxczakiVerified publisher0.27.51 of 2See more

discord-bot xxczaki 0.27.5

1 of the 2 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
xxczaki/discord-bot:e9f46b6aebac02e7b96ed41a3f62b26e871cf009bb919aac45dc
file-type@16.5.4
21.3.1

Open the chart page →

474
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
file-type@18.3.0
21.3.1

Open the chart page →

9,783
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
file-type@16.5.4
21.3.1

Open the chart page →

3,820
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
file-type@16.5.4
21.3.1

Open the chart page →

4,880
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
file-type@16.5.4
21.3.1

Open the chart page →

2,136
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
file-type@19.6.0
21.3.1
sysnet4admin/colosseum-prm:log5802bfcd7fed
file-type@19.6.0
21.3.1

Open the chart page →

26,996
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
file-type@16.5.4
21.3.1

Open the chart page →

4,083
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
file-type@16.5.4
21.3.1
countly/frontend:25.05.42acbc11499b6
file-type@16.5.4
21.3.1

Open the chart page →

7,295
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
file-type@16.5.4
21.3.1

Open the chart page →

22,193
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
file-type@16.5.4
21.3.1

Open the chart page →

3,159
theloungegeek-cookbookVerified publisher3.4.21 of 1See more

thelounge geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
thelounge/thelounge:4.2.0-alpine639978459c3a
file-type@14.7.1
21.3.1

Open the chart page →

2,689
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
file-type@16.5.4
21.3.1

Open the chart page →

9,019
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
file-type@16.5.4
21.3.1

Open the chart page →

2,950
theloungehalkeye4.3.11 of 1See more

thelounge halkeye 4.3.1

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
thelounge/thelounge:4.3.0-alpine0037aa258261
file-type@16.2.0
21.3.1

Open the chart page →

1,938
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
file-type@16.5.4
21.3.1

Open the chart page →

18,813
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
file-type@15.0.1
21.3.1

Open the chart page →

4,253
bluesky-pdsijmacd1.0.01 of 2See more

bluesky-pds ijmacd 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
file-type@16.5.4
21.3.1

Open the chart page →

8,967
nocodbinseefrlab0.2.01 of 1See more

nocodb inseefrlab 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
nocodb/nocodb:latest4b760f0d2547
file-type@20.4.1
21.3.1

Open the chart page →

781
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
file-type@16.5.4
21.3.1

Open the chart page →

3,436
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
file-type@16.5.4
21.3.1

Open the chart page →

5,826
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
file-type@16.5.4
21.3.1

Open the chart page →

22,589
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
file-type@16.5.4
21.3.1

Open the chart page →

3,092
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
file-type@18.3.0
21.3.1

Open the chart page →

9,783
redisinsightklicktippVerified publisher0.5.01 of 1See more

redisinsight klicktipp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
redis/redisinsight:3.2.055542a762210
file-type@20.4.1
21.3.1

Open the chart page →

1,290
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
file-type@16.5.4
21.3.1

Open the chart page →

2,756
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
file-type@16.5.4
21.3.1

Open the chart page →

1,490
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
file-type@17.1.6
21.3.1

Open the chart page →

9,774
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
file-type@16.5.4
21.3.1

Open the chart page →

9,668
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
file-type@16.5.4
21.3.1

Open the chart page →

4,960
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
file-type@16.5.4
21.3.1

Open the chart page →

3,128

Container images carrying it

69 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
tiago2/cap:2.159f5ae4e261e
file-type@21.0.0
21.3.1
1
treskon/portrait-ui:DEV-lateste7970783bc8d
file-type@16.5.4
21.3.1
1
veecode/devportalc443520aebf7
file-type@16.5.4
21.3.1
1
xxczaki/discord-bot:e9f46b6aebac02e7b96ed41a3f62b26e871cf009bb919aac45dc
file-type@16.5.4
21.3.1
1
ghcr.io/backstage/backstage:latest792e262ea504
file-type@16.5.4
21.3.1
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
file-type@16.5.4
21.3.1
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
file-type@16.5.4
21.3.1
1
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
file-type@16.5.4
21.3.1
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
file-type@20.4.1
21.3.1
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
file-type@16.5.4
21.3.1
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
file-type@18.7.0
21.3.1
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
file-type@21.0.0
21.3.1
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
file-type@16.5.4
21.3.1
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
file-type@15.0.1
21.3.1
1
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
file-type@17.1.6
21.3.1
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
file-type@16.5.4
21.3.1
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
file-type@21.0.0
21.3.1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
file-type@16.5.4
21.3.1
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
file-type@16.5.4
21.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.