StackRadar

CVE-2026-33228

Critical

Advisory

Published 19 Mar 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
136
of 17,781 indexed, latest versions
Container images
142
deployed by those charts
Fix available
1 of 2
affected packages

Prototype Pollution via parse() in NodeJS flatted

Carried by container images the latest versions of 136 of 17,781 indexed charts deploy, on 142 images.

Affected packageAffected versionsFixed inImages
node-flatteddeb3.2.7~ds-1no fix listed1
flattednpm2.0.0, 2.0.1, 2.0.2, 3.1.0+12 more3.4.2142
OSV records
GHSA-rf6f-7fwh-wjghUBUNTU-CVE-2026-33228

Charts affected

136 by stars
ChartLatestAffected imagesRadar Score
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
unleashorg/unleash-server:7.5.09adb37e399ba
flatted@3.2.7
3.4.2

Open the chart page →

2,059
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
flatted@3.3.1
3.4.2

Open the chart page →

7,210
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
flatted@3.1.1
3.4.2

Open the chart page →

9,203
n8nn8n0.23.01 of 1See more

n8n n8n 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
n8nio/n8n:1.33.1dd171d45102a
flatted@3.2.7
3.4.2

Open the chart page →

5,639
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
openmined/syft-frontend:0.9.5d11524a3854a
flatted@3.2.9
3.4.2

Open the chart page →

17,245
redisinsightheywood8-helm-chartsVerified publisher0.4.51 of 1See more

redisinsight heywood8-helm-charts 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
heywood8/redisinsight:2.28.00bc9ab313d37
flatted@3.2.7
3.4.2

Open the chart page →

2,828
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
flatted@3.1.0
3.4.2

Open the chart page →

5,251
carbonetes-analyzercarbonetes-analyzerVerified publisher1.0.61 of 1See more

carbonetes-analyzer carbonetes-analyzer 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
flatted@3.2.2
3.4.2

Open the chart page →

1,829
community-solid-servercommunity-solid-server3.0.01 of 1See more

community-solid-server community-solid-server 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
solidproject/community-server:6.0.2ccc4acb7e9a1
flatted@3.1.1
3.4.2

Open the chart page →

1,613
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
flatted@3.2.7
3.4.2

Open the chart page →

28,839
nightscoutgabe565Verified publisher0.13.01 of 2See more

nightscout gabe565 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
flatted@3.2.7
3.4.2

Open the chart page →

2,521
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
flatted@3.1.1
3.4.2

Open the chart page →

22,773
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
flatted@3.1.1
3.4.2

Open the chart page →

3,476
kubeviouskubevious1.2.24 of 7See more

kubevious kubevious 1.2.2

4 of the 7 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
kubevious/backend:1.2.22d9ba6eb46b6
flatted@3.2.7
3.4.2
kubevious/collector:1.2.1f58226f9d84e
flatted@3.2.7
3.4.2
kubevious/guard:1.2.19bf567704de2
flatted@3.2.5
3.4.2
kubevious/parser:1.2.299ae7a5168c2
flatted@3.2.7
3.4.2

Open the chart page →

14,204
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
kobotoolbox/kpi:2.022.24dbcacc01bccd4
flatted@3.2.5
3.4.2

Open the chart page →

18,517
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
flatted@3.2.7
3.4.2

Open the chart page →

7,776
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
flatted@3.3.1
3.4.2

Open the chart page →

28,534
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
flatted@3.2.4
3.4.2

Open the chart page →

3,925
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
flatted@3.3.1
3.4.2

Open the chart page →

5,670
enbuildenbuildVerified publisher0.0.502 of 6See more

enbuild enbuild 0.0.50

2 of the 6 container images this version deploys carry CVE-2026-33228.

Open the chart page →

31,510
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
flatted@3.1.1
3.4.2

Open the chart page →

2,519
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
flatted@3.1.1
3.4.2

Open the chart page →

4,405
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
flatted@3.2.4
3.4.2

Open the chart page →

7,801
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
flatted@3.2.5
3.4.2

Open the chart page →

3,143
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
flatted@3.3.1
3.4.2

Open the chart page →

5,654
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
flatted@2.0.2
3.4.2

Open the chart page →

5,940
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
flatted@3.2.5
3.4.2

Open the chart page →

31,844
stornxstornxVerified publisher1.1.11 of 9See more

stornx stornx 1.1.1

1 of the 9 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
flatted@3.3.3
3.4.2

Open the chart page →

11,574
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
flatted@2.0.2
3.4.2

Open the chart page →

7,517
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
flatted@3.3.1
3.4.2

Open the chart page →

12,581
tdarrvhdirkVerified publisher5.0.51 of 2See more

tdarr vhdirk 5.0.5

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
flatted@3.2.7
3.4.2

Open the chart page →

26,657
adeptia-automate-mcpadeptia-automate-mcp1.0.01 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
flatted@3.3.3
3.4.2

Open the chart page →

3,600
admin-portaladmin-web-portal1.2.11 of 2See more

admin-portal admin-web-portal 1.2.1

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
soulou2019/node-server:latest5e6ecfcc109e
flatted@3.2.7
3.4.2

Open the chart page →

3,419
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
flatted@2.0.2
3.4.2

Open the chart page →

3,237
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:api-latest7473d77448e1
flatted@2.0.2
3.4.2

Open the chart page →

9,369
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
assistiot/open_api_frontend:1.0.1f11d82defc70
flatted@3.2.7
3.4.2

Open the chart page →

18,277
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
flatted@3.3.1
3.4.2

Open the chart page →

32,501
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ltdstudio/terraforming-mars:latest0e76c6f4eac0
flatted@2.0.2
3.4.2

Open the chart page →

7,152
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
flatted@3.2.7
3.4.2

Open the chart page →

4,455
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
flatted@3.3.3
3.4.2
sysnet4admin/colosseum-prm:log5802bfcd7fed
flatted@3.3.3
3.4.2

Open the chart page →

26,996
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
flatted@3.2.7
3.4.2

Open the chart page →

951
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
flatted@3.3.3
3.4.2

Open the chart page →

7,405
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
flatted@3.2.7
3.4.2
countly/frontend:25.05.42acbc11499b6
flatted@3.2.7
3.4.2

Open the chart page →

7,295
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
flatted@2.0.1
3.4.2

Open the chart page →

25,456
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
flatted@3.3.2
3.4.2
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
flatted@3.3.3
3.4.2
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
flatted@3.3.3
3.4.2

Open the chart page →

18,293
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
node-flatted@3.2.7~ds-1
flatted@3.2.7
no fix listed
3.4.2

Open the chart page →

13,220
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
flatted@3.1.1
3.4.2

Open the chart page →

12,907
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
coldatom/containers-security-front:latest7c2fbbb41bcf
flatted@3.2.7
3.4.2

Open the chart page →

9,146
cortezacorteza1.0.121 of 3See more

corteza corteza 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
flatted@3.3.3
3.4.2

Open the chart page →

8,368
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
flatted@2.0.2
3.4.2

Open the chart page →

5,488

Container images carrying it

142 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
chatwoot/chatwoot:v3.1.0d530ab8c1753
flatted@2.0.2
3.4.2
2
governify/assets-manager:v1.4.12987672448c7
flatted@2.0.2
3.4.2
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
flatted@3.3.3
3.4.2
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
flatted@3.3.3
3.4.2
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
flatted@3.2.2
3.4.2
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
flatted@3.3.3
3.4.2
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
flatted@2.0.2
3.4.2
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
flatted@3.1.1
3.4.2
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
flatted@3.2.5
3.4.2
2
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
flatted@3.3.3
3.4.2
1
alazidis/stornx:1.1.1602d4f7f090c
flatted@3.3.3
3.4.2
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
flatted@3.3.1
3.4.2
1
arfath29/3-tier-app-frontend:latest384b3e377f47
flatted@3.1.1
3.4.2
1
assistiot/fl_orchestrator:api-latest7473d77448e1
flatted@2.0.2
3.4.2
1
assistiot/open_api_frontend:1.0.1f11d82defc70
flatted@3.2.7
3.4.2
1
automatischio/automatisch:0.15.03bace7a12d5f
flatted@3.3.2
3.4.2
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
flatted@3.1.1
3.4.2
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
flatted@3.2.7
3.4.2
1
bnjbvr/kresus:0.22.137e216b182c8
flatted@3.3.2
3.4.2
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
flatted@3.2.2
3.4.2
1
ccjacobs14/amazon:59a9b14a6f09e
flatted@3.2.7
3.4.2
1
chatwoot/chatwoot:v4.15.167ebc751c171
flatted@3.1.1
3.4.2
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
flatted@3.3.1
3.4.2
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
flatted@3.2.7
3.4.2
1
coldatom/containers-security-front:latest7c2fbbb41bcf
flatted@3.2.7
3.4.2
1
conduction/conduction-ui-app:devd591f5e6f2a9
flatted@3.1.1
3.4.2
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
flatted@3.3.3
3.4.2
1
countly/api:25.05.4f4cc7447c4f5
flatted@3.2.7
3.4.2
1
countly/countly-server:25.05.4e3c238248f99
flatted@3.2.7
3.4.2
1
countly/frontend:25.05.42acbc11499b6
flatted@3.2.7
3.4.2
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
flatted@3.3.1
3.4.2
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
flatted@2.0.2
3.4.2
1
ethersphere/onboarding-faucet:0.3.0513154aab230
flatted@3.2.5
3.4.2
1
evoapicloud/evolution-api:latest966625532d90
flatted@3.3.3
3.4.2
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
flatted@3.2.9
3.4.2
1
fosrl/pangolin:1.13.0c32ad797ab96
flatted@3.3.3
3.4.2
1
halkeye/irslackd:latest7638bfba70b0
flatted@2.0.0
3.4.2
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
flatted@3.2.7
3.4.2
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
flatted@3.2.7
3.4.2
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
flatted@3.2.7
3.4.2
1
heywood8/redisinsight:2.28.00bc9ab313d37
flatted@3.2.7
3.4.2
1
ianw/quickchart:v1.7.1dc49dd460c37
flatted@2.0.2
3.4.2
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
flatted@2.0.2
3.4.2
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
flatted@2.0.1
3.4.2
1
joplin/server:3.0-beta52af57880c0e
flatted@3.2.4
3.4.2
1
joplin/server:2.14.2-betab87564ef34e9
flatted@3.2.4
3.4.2
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-flatted@3.2.7~ds-1
flatted@3.2.7
no fix listed
3.4.2
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
flatted@3.2.5
3.4.2
1
kubevious/backend:1.2.22d9ba6eb46b6
flatted@3.2.7
3.4.2
1
kubevious/collector:1.2.1f58226f9d84e
flatted@3.2.7
3.4.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.