StackRadar

CVE-2026-32630

Medium

Advisory

Published 13 Mar 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

file-type: ZIP Decompression Bomb DoS via [Content_Types].xml entry

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
file-typenpm20.4.1, 21.0.0, 21.1.1, 21.3.121.3.214
OSV records
GHSA-j47w-4g3g-c36v

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
redisinsightredisinsight-guiVerified publisher1.3.51 of 1See more

redisinsight redisinsight-gui 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
redis/redisinsight:3.8b5e19ee240ab
file-type@20.4.1
21.3.2

Open the chart page →

1,038
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
file-type@20.4.1
21.3.2

Open the chart page →

4,016
cap-captcha-serverf3k-techVerified publisher0.21.01 of 1See more

cap-captcha-server f3k-tech 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
tiago2/cap:2.159f5ae4e261e
file-type@21.0.0
21.3.2

Open the chart page →

1,664
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
file-type@21.0.0
21.3.2

Open the chart page →

15,712
patchworkpatchworkVerified publisher0.8.61 of 2See more

patchwork patchwork 0.8.6

1 of the 2 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/patchwork:mainc01e018bced4
file-type@20.4.1
21.3.2

Open the chart page →

2,083
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
file-type@20.4.1
21.3.2
sysnet4admin/colosseum-prm:log5802bfcd7fed
file-type@20.4.1
21.3.2

Open the chart page →

26,996
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
file-type@20.4.1
21.3.2

Open the chart page →

22,193
nocodbinseefrlab0.2.01 of 1See more

nocodb inseefrlab 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
nocodb/nocodb:latest4b760f0d2547
file-type@20.4.1
21.3.2

Open the chart page →

781
redisinsightklicktippVerified publisher0.5.01 of 1See more

redisinsight klicktipp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
redis/redisinsight:3.2.055542a762210
file-type@20.4.1
21.3.2

Open the chart page →

1,290
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
file-type@20.4.1
21.3.2

Open the chart page →

1,490
redisinsightredisinsightVerified publisher0.1.01 of 1See more

redisinsight redisinsight 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
file-type@20.4.1
21.3.2

Open the chart page →

1,038
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
file-type@21.0.0
21.3.2

Open the chart page →

1,313
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
file-type@20.4.1
21.3.2

Open the chart page →

4,661
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
file-type@21.1.1
21.3.2

Open the chart page →

3,746
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
file-type@21.3.1
21.3.2

Open the chart page →

4,305
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-32630.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
file-type@21.0.0
21.3.2

Open the chart page →

5,984

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
redis/redisinsight:3.8:latestb5e19ee240ab
file-type@20.4.1
21.3.2
4
evoapicloud/evolution-api:latest966625532d90
file-type@21.1.1
21.3.2
1
nocodb/nocodb:latest4b760f0d2547
file-type@20.4.1
21.3.2
1
nocodb/nocodb:0.301.5d9516f0bf546
file-type@20.4.1
21.3.2
1
redis/redisinsight:3.2.055542a762210
file-type@20.4.1
21.3.2
1
redis/redisinsight:3.485562d67a912
file-type@20.4.1
21.3.2
1
sigp/siren:v3.0.42c219b04758e
file-type@21.0.0
21.3.2
1
sysnet4admin/colosseum-cms:loge74b43c7f492
file-type@20.4.1
21.3.2
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
file-type@20.4.1
21.3.2
1
tiago2/cap:2.159f5ae4e261e
file-type@21.0.0
21.3.2
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
file-type@21.3.1
21.3.2
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
file-type@20.4.1
21.3.2
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
file-type@21.0.0
21.3.2
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
file-type@21.0.0
21.3.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.