StackRadar

CVE-2026-31808

Medium

Advisory

Published 10 Mar 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
25th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
76
of 17,781 indexed, latest versions
Container images
69
deployed by those charts
Fix available
1 of 1
affected package

file-type affected by infinite loop in ASF parser on malformed input with zero-size sub-header

Carried by container images the latest versions of 76 of 17,781 indexed charts deploy, on 69 images.

Affected packageAffected versionsFixed inImages
file-typenpm14.1.4, 14.7.1, 15.0.1, 16.2.0+12 more21.3.169
OSV records
GHSA-5v7r-6r5c-r473

Charts affected

76 by stars
ChartLatestAffected imagesRadar Score
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
file-type@16.5.4
21.3.1

Open the chart page →

2,383
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
file-type@16.5.4
21.3.1

Open the chart page →

71,208
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
file-type@16.5.4
21.3.1

Open the chart page →

6,583
redisinsightredisinsightVerified publisher0.1.01 of 1See more

redisinsight redisinsight 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
file-type@16.5.4
21.3.1

Open the chart page →

1,038
redisinsightredisinsight-helmVerified publisher0.1.11 of 1See more

redisinsight redisinsight-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
redis/redisinsight:2.46699d341bd329
file-type@16.5.4
21.3.1

Open the chart page →

1,884
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
file-type@14.1.4
21.3.1

Open the chart page →

5,215
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
file-type@17.1.2
21.3.1

Open the chart page →

3,118
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
file-type@16.5.4
21.3.1

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
file-type@16.5.4
21.3.1

Open the chart page →

16,400
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.17.14-branch.testing.72707.921a5f884fc39bca0c8
file-type@16.5.4
21.3.1

Open the chart page →

14,679
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
file-type@16.5.4
21.3.1

Open the chart page →

16,400
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4691 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

1 of the 5 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d4694bd113093583
file-type@16.5.4
21.3.1

Open the chart page →

14,221
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.18.12-branch.testing3.88744-f55b3414bd113093583
file-type@16.5.4
21.3.1

Open the chart page →

14,221
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
file-type@16.5.4
21.3.1

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
file-type@16.5.4
21.3.1

Open the chart page →

15,635
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
file-type@21.0.0
21.3.1

Open the chart page →

1,313
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
file-type@16.5.4
21.3.1

Open the chart page →

39,090
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
file-type@16.5.4
21.3.1

Open the chart page →

5,604
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
file-type@16.5.4
21.3.1

Open the chart page →

4,661
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
file-type@18.7.0
21.3.1

Open the chart page →

3,576
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
file-type@16.5.4
21.3.1

Open the chart page →

5,535
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
file-type@16.5.4
21.3.1

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
file-type@16.5.4
21.3.1

Open the chart page →

1,787
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
file-type@17.1.2
21.3.1

Open the chart page →

3,118
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
file-type@21.0.0
21.3.1

Open the chart page →

5,984
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-31808.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
file-type@15.0.1
21.3.1

Open the chart page →

5,459

Container images carrying it

69 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
tiago2/cap:2.159f5ae4e261e
file-type@21.0.0
21.3.1
1
treskon/portrait-ui:DEV-lateste7970783bc8d
file-type@16.5.4
21.3.1
1
veecode/devportalc443520aebf7
file-type@16.5.4
21.3.1
1
xxczaki/discord-bot:e9f46b6aebac02e7b96ed41a3f62b26e871cf009bb919aac45dc
file-type@16.5.4
21.3.1
1
ghcr.io/backstage/backstage:latest792e262ea504
file-type@16.5.4
21.3.1
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
file-type@16.5.4
21.3.1
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
file-type@16.5.4
21.3.1
1
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
file-type@16.5.4
21.3.1
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
file-type@20.4.1
21.3.1
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
file-type@16.5.4
21.3.1
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
file-type@18.7.0
21.3.1
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
file-type@21.0.0
21.3.1
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
file-type@16.5.4
21.3.1
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
file-type@15.0.1
21.3.1
1
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
file-type@17.1.6
21.3.1
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
file-type@16.5.4
21.3.1
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
file-type@21.0.0
21.3.1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
file-type@16.5.4
21.3.1
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
file-type@16.5.4
21.3.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.