StackRadar

CVE-2026-33013

High

Advisory

Published 17 Mar 2026In the index since 8 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
29
deployed by those charts
Fix available
1 of 1
affected package

Micronaut vulnerable to DoS via crafted form-urlencoded body binding with descending array indices

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 29 images.

Affected packageAffected versionsFixed inImages
micronaut-json-coremaven3.8.6, 3.9.1, 3.10.3, 3.10.4+5 more3.8.13, 3.10.5, 4.10.1629
OSV records
GHSA-43w5-mmxv-cpvh

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
airbyte-api-serverairbyteVerified publisher0.293.41 of 1See more

airbyte-api-server airbyte 0.293.4

1 of the 1 container images this version deploys carry CVE-2026-33013.

Container imageDigestPackageFixed in
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
micronaut-json-core@4.5.3
4.10.16

Open the chart page →

854
connector-rollout-workerairbyteVerified publisher1.9.21 of 1See more

connector-rollout-worker airbyte 1.9.2

1 of the 1 container images this version deploys carry CVE-2026-33013.

Container imageDigestPackageFixed in
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
micronaut-json-core@4.9.10
4.10.16

Open the chart page →

829
consent-facadefiware0.1.11 of 1See more

consent-facade fiware 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33013.

Container imageDigestPackageFixed in
quay.io/seamware/consent-facade:0.0.14be844c750c7e
micronaut-json-core@4.7.6
4.10.16

Open the chart page →

2,475
contract-managementfiware3.5.361 of 1See more

contract-management fiware 3.5.36

1 of the 1 container images this version deploys carry CVE-2026-33013.

Container imageDigestPackageFixed in
quay.io/fiware/contract-management:3.3.122bcfcf874451
micronaut-json-core@4.7.6
4.10.16

Open the chart page →

2,411
credentials-config-servicefiware2.6.41 of 1See more

credentials-config-service fiware 2.6.4

1 of the 1 container images this version deploys carry CVE-2026-33013.

Container imageDigestPackageFixed in
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
micronaut-json-core@4.10.12
4.10.16

Open the chart page →

2,293
dss-validation-servicefiware0.0.191 of 1See more

dss-validation-service fiware 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-33013.

Container imageDigestPackageFixed in
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
micronaut-json-core@4.7.6
4.10.16

Open the chart page →

4,536
tm-forum-apifiware0.17.1519 of 19See more

tm-forum-api fiware 0.17.15

19 of the 19 container images this version deploys carry CVE-2026-33013.

Container imageDigestPackageFixed in
quay.io/fiware/tmforum-account:1.18.06b25aac03414
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-service-order-management:1.18.0d2091785d544
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-software-management:1.18.01b74a2f7ba67
micronaut-json-core@3.9.1
3.10.5
quay.io/fiware/tmforum-usage-management:1.18.042f190c42926
micronaut-json-core@3.9.1
3.10.5

Open the chart page →

35,112
trusted-issuers-listfiware0.18.71 of 1See more

trusted-issuers-list fiware 0.18.7

1 of the 1 container images this version deploys carry CVE-2026-33013.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
micronaut-json-core@4.10.11
4.10.16

Open the chart page →

1,701
trusted-issuers-registryfiware0.13.01 of 1See more

trusted-issuers-registry fiware 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-33013.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
micronaut-json-core@3.10.3
3.10.5

Open the chart page →

7,087
gridgain9gridgainVerified publisher1.1.101 of 2See more

gridgain9 gridgain 1.1.10

1 of the 2 container images this version deploys carry CVE-2026-33013.

Container imageDigestPackageFixed in
gridgain/gridgain9:9.1.1895018390077b
micronaut-json-core@3.10.4
3.10.5

Open the chart page →

3,199
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-33013.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
micronaut-json-core@3.8.6
3.8.13

Open the chart page →

18,756

Container images carrying it

29 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
airbyte/airbyte-api-server:0.63.8e1c5e7cfec8a
micronaut-json-core@4.5.3
4.10.16
1
airbyte/connector-rollout-worker:2.0.2-alpha-c905e75d42813fcc191
micronaut-json-core@4.9.10
4.10.16
1
gridgain/gridgain9:9.1.1895018390077b
micronaut-json-core@3.10.4
3.10.5
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
micronaut-json-core@3.8.6
3.8.13
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
micronaut-json-core@4.7.6
4.10.16
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
micronaut-json-core@4.10.12
4.10.16
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-product-inventory:1.18.03a5d6dd30f1d
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-product-ordering-management:1.18.042c81c291f6f
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-quote:1.18.0d9ca3a334352
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-resource-catalog:1.18.0b0d853627c59
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-resource-function-activation:1.18.062a5acb63fd1
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-resource-inventory:1.18.0553b4a47730b
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-resource-order-management:1.18.0dd1778ad6203
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-service-catalog:1.18.074b0fad9e155
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-service-inventory:1.18.04be54e8cb5c0
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-service-order-management:1.18.0d2091785d544
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-software-management:1.18.01b74a2f7ba67
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/tmforum-usage-management:1.18.042f190c42926
micronaut-json-core@3.9.1
3.10.5
1
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
micronaut-json-core@4.10.11
4.10.16
1
quay.io/fiware/trusted-issuers-registry:0.11.1a8a9ec461034
micronaut-json-core@3.10.3
3.10.5
1
quay.io/seamware/consent-facade:0.0.14be844c750c7e
micronaut-json-core@4.7.6
4.10.16
1
quay.io/wi_stefan/dss-validation-service:0.0.18e928db29ee1
micronaut-json-core@4.7.6
4.10.16
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.