StackRadar

CVE-2026-33228

Critical

Advisory

Published 19 Mar 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
136
of 17,781 indexed, latest versions
Container images
142
deployed by those charts
Fix available
1 of 2
affected packages

Prototype Pollution via parse() in NodeJS flatted

Carried by container images the latest versions of 136 of 17,781 indexed charts deploy, on 142 images.

Affected packageAffected versionsFixed inImages
node-flatteddeb3.2.7~ds-1no fix listed1
flattednpm2.0.0, 2.0.1, 2.0.2, 3.1.0+12 more3.4.2142
OSV records
GHSA-rf6f-7fwh-wjghUBUNTU-CVE-2026-33228

Charts affected

136 by stars
ChartLatestAffected imagesRadar Score
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
unleashorg/unleash-server:7.5.09adb37e399ba
flatted@3.2.7
3.4.2

Open the chart page →

2,059
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
flatted@3.3.1
3.4.2

Open the chart page →

7,210
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
flatted@3.1.1
3.4.2

Open the chart page →

9,203
n8nn8n0.23.01 of 1See more

n8n n8n 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
n8nio/n8n:1.33.1dd171d45102a
flatted@3.2.7
3.4.2

Open the chart page →

5,639
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
openmined/syft-frontend:0.9.5d11524a3854a
flatted@3.2.9
3.4.2

Open the chart page →

17,245
redisinsightheywood8-helm-chartsVerified publisher0.4.51 of 1See more

redisinsight heywood8-helm-charts 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
heywood8/redisinsight:2.28.00bc9ab313d37
flatted@3.2.7
3.4.2

Open the chart page →

2,828
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
flatted@3.1.0
3.4.2

Open the chart page →

5,251
carbonetes-analyzercarbonetes-analyzerVerified publisher1.0.61 of 1See more

carbonetes-analyzer carbonetes-analyzer 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
flatted@3.2.2
3.4.2

Open the chart page →

1,829
community-solid-servercommunity-solid-server3.0.01 of 1See more

community-solid-server community-solid-server 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
solidproject/community-server:6.0.2ccc4acb7e9a1
flatted@3.1.1
3.4.2

Open the chart page →

1,613
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
flatted@3.2.7
3.4.2

Open the chart page →

28,839
nightscoutgabe565Verified publisher0.13.01 of 2See more

nightscout gabe565 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
flatted@3.2.7
3.4.2

Open the chart page →

2,521
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
flatted@3.1.1
3.4.2

Open the chart page →

22,773
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
flatted@3.1.1
3.4.2

Open the chart page →

3,476
kubeviouskubevious1.2.24 of 7See more

kubevious kubevious 1.2.2

4 of the 7 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
kubevious/backend:1.2.22d9ba6eb46b6
flatted@3.2.7
3.4.2
kubevious/collector:1.2.1f58226f9d84e
flatted@3.2.7
3.4.2
kubevious/guard:1.2.19bf567704de2
flatted@3.2.5
3.4.2
kubevious/parser:1.2.299ae7a5168c2
flatted@3.2.7
3.4.2

Open the chart page →

14,204
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
kobotoolbox/kpi:2.022.24dbcacc01bccd4
flatted@3.2.5
3.4.2

Open the chart page →

18,517
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
flatted@3.2.7
3.4.2

Open the chart page →

7,776
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
flatted@3.3.1
3.4.2

Open the chart page →

28,534
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
flatted@3.2.4
3.4.2

Open the chart page →

3,925
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
flatted@3.3.1
3.4.2

Open the chart page →

5,670
enbuildenbuildVerified publisher0.0.502 of 6See more

enbuild enbuild 0.0.50

2 of the 6 container images this version deploys carry CVE-2026-33228.

Open the chart page →

31,510
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
flatted@3.1.1
3.4.2

Open the chart page →

2,519
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
flatted@3.1.1
3.4.2

Open the chart page →

4,405
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
flatted@3.2.4
3.4.2

Open the chart page →

7,801
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
flatted@3.2.5
3.4.2

Open the chart page →

3,143
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
flatted@3.3.1
3.4.2

Open the chart page →

5,654
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
flatted@2.0.2
3.4.2

Open the chart page →

5,940
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
flatted@3.2.5
3.4.2

Open the chart page →

31,844
stornxstornxVerified publisher1.1.11 of 9See more

stornx stornx 1.1.1

1 of the 9 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
flatted@3.3.3
3.4.2

Open the chart page →

11,574
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
flatted@2.0.2
3.4.2

Open the chart page →

7,517
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
flatted@3.3.1
3.4.2

Open the chart page →

12,581
tdarrvhdirkVerified publisher5.0.51 of 2See more

tdarr vhdirk 5.0.5

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
flatted@3.2.7
3.4.2

Open the chart page →

26,657
adeptia-automate-mcpadeptia-automate-mcp1.0.01 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
flatted@3.3.3
3.4.2

Open the chart page →

3,600
admin-portaladmin-web-portal1.2.11 of 2See more

admin-portal admin-web-portal 1.2.1

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
soulou2019/node-server:latest5e6ecfcc109e
flatted@3.2.7
3.4.2

Open the chart page →

3,419
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
flatted@2.0.2
3.4.2

Open the chart page →

3,237
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:api-latest7473d77448e1
flatted@2.0.2
3.4.2

Open the chart page →

9,369
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
assistiot/open_api_frontend:1.0.1f11d82defc70
flatted@3.2.7
3.4.2

Open the chart page →

18,277
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
flatted@3.3.1
3.4.2

Open the chart page →

32,501
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ltdstudio/terraforming-mars:latest0e76c6f4eac0
flatted@2.0.2
3.4.2

Open the chart page →

7,152
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
flatted@3.2.7
3.4.2

Open the chart page →

4,455
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
flatted@3.3.3
3.4.2
sysnet4admin/colosseum-prm:log5802bfcd7fed
flatted@3.3.3
3.4.2

Open the chart page →

26,996
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
flatted@3.2.7
3.4.2

Open the chart page →

951
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
flatted@3.3.3
3.4.2

Open the chart page →

7,405
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
flatted@3.2.7
3.4.2
countly/frontend:25.05.42acbc11499b6
flatted@3.2.7
3.4.2

Open the chart page →

7,295
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
flatted@2.0.1
3.4.2

Open the chart page →

25,456
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
flatted@3.3.2
3.4.2
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
flatted@3.3.3
3.4.2
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
flatted@3.3.3
3.4.2

Open the chart page →

18,293
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
node-flatted@3.2.7~ds-1
flatted@3.2.7
no fix listed
3.4.2

Open the chart page →

13,220
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
flatted@3.1.1
3.4.2

Open the chart page →

12,907
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
coldatom/containers-security-front:latest7c2fbbb41bcf
flatted@3.2.7
3.4.2

Open the chart page →

9,146
cortezacorteza1.0.121 of 3See more

corteza corteza 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
flatted@3.3.3
3.4.2

Open the chart page →

8,368
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
flatted@2.0.2
3.4.2

Open the chart page →

5,488

Container images carrying it

142 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kubevious/guard:1.2.19bf567704de2
flatted@3.2.5
3.4.2
1
kubevious/parser:1.0.151acf1a1f0b47
flatted@3.2.1
3.4.2
1
kubevious/parser:1.2.299ae7a5168c2
flatted@3.2.7
3.4.2
1
kubevious/workload-operator:1.0.20b0f4c507eb6
flatted@3.2.7
3.4.2
1
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
flatted@3.1.1
3.4.2
1
kyso/kyso-front:lateste52595c5c16f
flatted@3.2.9
3.4.2
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
flatted@3.3.1
3.4.2
1
library/ghost:5.79.083f7bf209844
flatted@3.2.7
3.4.2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
flatted@3.1.1
3.4.2
1
linuxserver/codimd:latestb801bbcf6386
flatted@2.0.2
3.4.2
1
lissy93/dashy:2.0.51991f7be5ed0
flatted@3.2.5
3.4.2
1
lsstsqre/squareone:0.4.09ded78e7fe03
flatted@3.1.1
3.4.2
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
flatted@2.0.2
3.4.2
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
flatted@3.3.3
3.4.2
1
misskey/misskey:12.110.1e08b7c478093
flatted@3.1.0
3.4.2
1
mitchxxx/amazon:214e72480ec63a
flatted@3.2.7
3.4.2
1
mozilla/sentencecollector:2.0.91da6ff5c4895
flatted@2.0.1
3.4.2
1
n8nio/n8n:1.86.08b39ed5a2de9
flatted@3.2.7
3.4.2
1
n8nio/n8n:0.212.0a9195bc499a3
flatted@3.2.7
3.4.2
1
n8nio/n8n:1.33.1dd171d45102a
flatted@3.2.7
3.4.2
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
flatted@3.1.1
3.4.2
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
flatted@3.2.7
3.4.2
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
flatted@3.2.7
3.4.2
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
flatted@3.3.3
3.4.2
1
ooghenekaro/amazon:latest03394ba1d6d8
flatted@3.2.7
3.4.2
1
opea/codegen-ui:1.02bee4eb66f3e
flatted@3.3.1
3.4.2
1
openbas/caldera-server:5.1.0a277796d9724
flatted@3.2.5
3.4.2
1
openmined/syft-frontend:0.9.5d11524a3854a
flatted@3.2.9
3.4.2
1
phntom/codimd:2.4.31b9aafbb62e6
flatted@2.0.1
3.4.2
1
pysga1996/python-redis-web:latestfdeec30ad482
flatted@3.1.1
3.4.2
1
qxip/qryn:3.2.3977acc9c7a9fd
flatted@3.3.1
3.4.2
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
flatted@3.3.2
3.4.2
1
samajh/alprfrontend:latest05ef4fddbb75
flatted@3.2.7
3.4.2
1
sharanalwar/redchef-frontend:latest5e82950b16b7
flatted@3.3.3
3.4.2
1
sigp/siren:v3.0.42c219b04758e
flatted@3.3.3
3.4.2
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
flatted@2.0.2
3.4.2
1
solidproject/community-server:6.0.2ccc4acb7e9a1
flatted@3.1.1
3.4.2
1
soulou2019/node-server:latest5e6ecfcc109e
flatted@3.2.7
3.4.2
1
stanfordoval/almond-server:latest1a63cdccedaf
flatted@3.2.2
3.4.2
1
sysnet4admin/colosseum-cms:loge74b43c7f492
flatted@3.3.3
3.4.2
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
flatted@3.3.3
3.4.2
1
testhubio/testhub-frontend:on-preme86c2db53be8
flatted@2.0.2
3.4.2
1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
flatted@3.2.7
3.4.2
1
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
flatted@2.0.2
3.4.2
1
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
flatted@3.3.1
3.4.2
1
treskon/portrait-ui:DEV-lateste7970783bc8d
flatted@3.2.5
3.4.2
1
ubercadence/web:v3.29.58564a5b44a6d
flatted@3.1.1
3.4.2
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
flatted@3.3.1
3.4.2
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
flatted@3.3.4
3.4.2
1
unleashorg/unleash-server:7.5.09adb37e399ba
flatted@3.2.7
3.4.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.