StackRadar

CVE-2026-32141

High

Advisory

Published 12 Mar 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
135
of 17,781 indexed, latest versions
Container images
140
deployed by those charts
Fix available
1 of 2
affected packages

flatted vulnerable to unbounded recursion DoS in parse() revive phase

Carried by container images the latest versions of 135 of 17,781 indexed charts deploy, on 140 images.

Affected packageAffected versionsFixed inImages
flattednpm2.0.0, 2.0.1, 2.0.2, 3.1.0+11 more3.4.0140
node-flatteddeb3.2.7~ds-1no fix listed1
OSV records
GHSA-25h7-pfq9-p65fUBUNTU-CVE-2026-32141

Charts affected

135 by stars
ChartLatestAffected imagesRadar Score
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
flatted@3.3.2
3.4.0

Open the chart page →

2,529
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-32141.

Open the chart page →

4,251
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
flatted@3.1.1
3.4.0

Open the chart page →

3,744
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
flatted@3.2.5
3.4.0

Open the chart page →

3,320
exposrexposr0.12.01 of 1See more

exposr exposr 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
ghcr.io/exposr/exposrd:v0.12.0561c8f23bdb6
flatted@3.2.7
3.4.0

Open the chart page →

570
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
flatted@3.2.9
3.4.0

Open the chart page →

64,489
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
flatted@2.0.2
3.4.0

Open the chart page →

5,941
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
flatted@3.1.1
3.4.0

Open the chart page →

4,043
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
flatted@3.2.7
3.4.0

Open the chart page →

9,019
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
flatted@3.3.1
3.4.0

Open the chart page →

2,973
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
flatted@2.0.2
3.4.0

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
flatted@2.0.2
3.4.0

Open the chart page →

24,319
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
flatted@3.3.1
3.4.0

Open the chart page →

49,025
irslackdhalkeye0.1.01 of 1See more

irslackd halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
halkeye/irslackd:latest7638bfba70b0
flatted@2.0.0
3.4.0

Open the chart page →

2,064
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
flatted@2.0.2
3.4.0
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
flatted@2.0.2
3.4.0
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
flatted@2.0.2
3.4.0
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
flatted@2.0.2
3.4.0

Open the chart page →

89,959
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
flatted@3.3.2
3.4.0

Open the chart page →

5,769
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
flatted@3.2.7
3.4.0

Open the chart page →

18,813
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
flatted@3.2.5
3.4.0

Open the chart page →

25,017
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
flatted@2.0.1
3.4.0

Open the chart page →

32,915
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
flatted@3.3.1
3.4.0

Open the chart page →

11,812
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
flatted@2.0.2
3.4.0

Open the chart page →

4,944
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
flatted@3.2.7
3.4.0

Open the chart page →

5,826
docker-hub-rssjuniorjpdj0.1.311 of 1See more

docker-hub-rss juniorjpdj 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
flatted@3.3.1
3.4.0

Open the chart page →

1,966
zwave-js-uik8sonlabVerified publisher0.7.121 of 1See more

zwave-js-ui k8sonlab 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
zwavejs/zwave-js-ui:11.22.314d018bb689e
flatted@3.3.3
3.4.0

Open the chart page →

973
visual-regression-trackerkokuwa5.1.01 of 4See more

visual-regression-tracker kokuwa 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
visualregressiontracker/api:5.0.11941aeb8c8bf9
flatted@3.2.9
3.4.0

Open the chart page →

9,098
pangolinkrzwiatrzyk0.11.01 of 1See more

pangolin krzwiatrzyk 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
fosrl/pangolin:1.13.0c32ad797ab96
flatted@3.3.3
3.4.0

Open the chart page →

3,441
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
flatted@3.2.1
3.4.0

Open the chart page →

1,927
workload-operatorkubevious0.0.31 of 1See more

workload-operator kubevious 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
kubevious/workload-operator:1.0.20b0f4c507eb6
flatted@3.2.7
3.4.0

Open the chart page →

2,008
multitenantkvalitetsitVerified publisher2.2.181 of 1See more

multitenant kvalitetsit 2.2.18

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
flatted@3.1.1
3.4.0

Open the chart page →

1,614
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
flatted@3.2.9
3.4.0

Open the chart page →

2,685
lgtv2mqttleprechaun-charts0.1.11 of 1See more

lgtv2mqtt leprechaun-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
ghcr.io/leprechaun/lgtv2mqtt:latestac2e11c41ffb
flatted@2.0.2
3.4.0

Open the chart page →

1,062
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
flatted@3.1.1
3.4.0

Open the chart page →

2,247
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
flatted@2.0.2
3.4.0

Open the chart page →

5,940
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
flatted@3.3.3
3.4.0

Open the chart page →

43,341
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
flatted@3.3.3
3.4.0

Open the chart page →

2,457
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
flatted@3.3.3
3.4.0
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
flatted@3.3.3
3.4.0
mojaloop/role-assignment-service:v2.1.0def4bf273721
flatted@3.2.2
3.4.0

Open the chart page →

14,809
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
flatted@3.3.3
3.4.0

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
flatted@3.3.3
3.4.0

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
flatted@3.2.2
3.4.0

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
flatted@3.3.3
3.4.0

Open the chart page →

2,457
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
flatted@2.0.2
3.4.0

Open the chart page →

6,438
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
flatted@2.0.1
3.4.0

Open the chart page →

6,684
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
flatted@3.2.7
3.4.0

Open the chart page →

6,608
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
flatted@3.2.7
3.4.0

Open the chart page →

3,128
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
flatted@3.2.7
3.4.0

Open the chart page →

2,116
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
flatted@3.2.7
3.4.0

Open the chart page →

2,116
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
flatted@3.2.7
3.4.0

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
flatted@3.2.7
3.4.0

Open the chart page →

2,116
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
flatted@3.2.7
3.4.0

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-32141.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
flatted@3.2.5
3.4.0

Open the chart page →

3,269

Container images carrying it

140 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
chatwoot/chatwoot:v3.1.0d530ab8c1753
flatted@2.0.2
3.4.0
2
governify/assets-manager:v1.4.12987672448c7
flatted@2.0.2
3.4.0
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
flatted@3.3.3
3.4.0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
flatted@3.3.3
3.4.0
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
flatted@3.2.2
3.4.0
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
flatted@3.3.3
3.4.0
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
flatted@2.0.2
3.4.0
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
flatted@3.1.1
3.4.0
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
flatted@3.2.5
3.4.0
2
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
flatted@3.3.3
3.4.0
1
alazidis/stornx:1.1.1602d4f7f090c
flatted@3.3.3
3.4.0
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
flatted@3.3.1
3.4.0
1
arfath29/3-tier-app-frontend:latest384b3e377f47
flatted@3.1.1
3.4.0
1
assistiot/fl_orchestrator:api-latest7473d77448e1
flatted@2.0.2
3.4.0
1
assistiot/open_api_frontend:1.0.1f11d82defc70
flatted@3.2.7
3.4.0
1
automatischio/automatisch:0.15.03bace7a12d5f
flatted@3.3.2
3.4.0
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
flatted@3.1.1
3.4.0
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
flatted@3.2.7
3.4.0
1
bnjbvr/kresus:0.22.137e216b182c8
flatted@3.3.2
3.4.0
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
flatted@3.2.2
3.4.0
1
ccjacobs14/amazon:59a9b14a6f09e
flatted@3.2.7
3.4.0
1
chatwoot/chatwoot:v4.15.167ebc751c171
flatted@3.1.1
3.4.0
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
flatted@3.3.1
3.4.0
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
flatted@3.2.7
3.4.0
1
coldatom/containers-security-front:latest7c2fbbb41bcf
flatted@3.2.7
3.4.0
1
conduction/conduction-ui-app:devd591f5e6f2a9
flatted@3.1.1
3.4.0
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
flatted@3.3.3
3.4.0
1
countly/api:25.05.4f4cc7447c4f5
flatted@3.2.7
3.4.0
1
countly/countly-server:25.05.4e3c238248f99
flatted@3.2.7
3.4.0
1
countly/frontend:25.05.42acbc11499b6
flatted@3.2.7
3.4.0
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
flatted@3.3.1
3.4.0
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
flatted@2.0.2
3.4.0
1
ethersphere/onboarding-faucet:0.3.0513154aab230
flatted@3.2.5
3.4.0
1
evoapicloud/evolution-api:latest966625532d90
flatted@3.3.3
3.4.0
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
flatted@3.2.9
3.4.0
1
fosrl/pangolin:1.13.0c32ad797ab96
flatted@3.3.3
3.4.0
1
halkeye/irslackd:latest7638bfba70b0
flatted@2.0.0
3.4.0
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
flatted@3.2.7
3.4.0
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
flatted@3.2.7
3.4.0
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
flatted@3.2.7
3.4.0
1
heywood8/redisinsight:2.28.00bc9ab313d37
flatted@3.2.7
3.4.0
1
ianw/quickchart:v1.7.1dc49dd460c37
flatted@2.0.2
3.4.0
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
flatted@2.0.2
3.4.0
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
flatted@2.0.1
3.4.0
1
joplin/server:3.0-beta52af57880c0e
flatted@3.2.4
3.4.0
1
joplin/server:2.14.2-betab87564ef34e9
flatted@3.2.4
3.4.0
1
jupyterhub/jupyterhub:5.4.63974ba945e65
flatted@3.2.7
node-flatted@3.2.7~ds-1
3.4.0
no fix listed
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
flatted@3.2.5
3.4.0
1
kubevious/backend:1.2.22d9ba6eb46b6
flatted@3.2.7
3.4.0
1
kubevious/collector:1.2.1f58226f9d84e
flatted@3.2.7
3.4.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.