StackRadar

CVE-2026-33228

Critical

Advisory

Published 19 Mar 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
136
of 17,781 indexed, latest versions
Container images
142
deployed by those charts
Fix available
1 of 2
affected packages

Prototype Pollution via parse() in NodeJS flatted

Carried by container images the latest versions of 136 of 17,781 indexed charts deploy, on 142 images.

Affected packageAffected versionsFixed inImages
node-flatteddeb3.2.7~ds-1no fix listed1
flattednpm2.0.0, 2.0.1, 2.0.2, 3.1.0+12 more3.4.2142
OSV records
GHSA-rf6f-7fwh-wjghUBUNTU-CVE-2026-33228

Charts affected

136 by stars
ChartLatestAffected imagesRadar Score
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
flatted@3.2.5
3.4.2

Open the chart page →

3,269
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
flatted@3.2.7
3.4.2

Open the chart page →

2,919
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
flatted@3.2.7
3.4.2

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
flatted@3.2.7
3.4.2

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
flatted@3.2.7
3.4.2

Open the chart page →

15,187
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
flatted@2.0.2
3.4.2

Open the chart page →

27,465
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
flatted@2.0.1
3.4.2

Open the chart page →

6,524
recipe-apprecipe-app0.1.01 of 2See more

recipe-app recipe-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
flatted@3.3.1
3.4.2

Open the chart page →

3,271
helm-redchefredchef0.1.01 of 3See more

helm-redchef redchef 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
sharanalwar/redchef-frontend:latest5e82950b16b7
flatted@3.3.3
3.4.2

Open the chart page →

4,763
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
flatted@3.2.9
3.4.2

Open the chart page →

6,282
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
flatted@3.3.1
3.4.2

Open the chart page →

7,084
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
flatted@3.3.3
3.4.2

Open the chart page →

4,600
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
flatted@3.3.2
3.4.2

Open the chart page →

15,591
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
flatted@3.2.4
3.4.2

Open the chart page →

7,413
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
flatted@3.3.1
3.4.2

Open the chart page →

5,497
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
flatted@3.2.5
3.4.2

Open the chart page →

3,143
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
flatted@3.2.7
3.4.2

Open the chart page →

7,574
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
flatted@3.2.2
3.4.2

Open the chart page →

3,228
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
flatted@3.3.3
3.4.2

Open the chart page →

1,313
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
flatted@3.1.1
3.4.2

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
flatted@3.1.1
3.4.2

Open the chart page →

11,554
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
flatted@2.0.2
3.4.2

Open the chart page →

3,881
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
flatted@2.0.2
3.4.2

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
flatted@2.0.2
3.4.2

Open the chart page →

919
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
flatted@3.3.1
3.4.2

Open the chart page →

28,814
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
flatted@3.2.7
3.4.2

Open the chart page →

20,270
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
pysga1996/python-redis-web:latestfdeec30ad482
flatted@3.1.1
3.4.2

Open the chart page →

4,661
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
flatted@3.2.9
3.4.2

Open the chart page →

17,323
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
flatted@3.3.4
3.4.2

Open the chart page →

2,028
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
flatted@3.3.3
3.4.2

Open the chart page →

3,746
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
flatted@3.2.2
3.4.2

Open the chart page →

3,129
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
flatted@3.3.3
3.4.2

Open the chart page →

4,305
websitewaldo-visionVerified publisher0.33.01 of 2See more

website waldo-vision 0.33.0

1 of the 2 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
flatted@3.2.7
3.4.2

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
flatted@3.3.3
3.4.2

Open the chart page →

5,984
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
flatted@3.1.1
3.4.2

Open the chart page →

10,127
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2026-33228.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
flatted@3.2.7
3.4.2
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
flatted@2.0.2
3.4.2

Open the chart page →

16,083

Container images carrying it

142 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kubevious/guard:1.2.19bf567704de2
flatted@3.2.5
3.4.2
1
kubevious/parser:1.0.151acf1a1f0b47
flatted@3.2.1
3.4.2
1
kubevious/parser:1.2.299ae7a5168c2
flatted@3.2.7
3.4.2
1
kubevious/workload-operator:1.0.20b0f4c507eb6
flatted@3.2.7
3.4.2
1
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
flatted@3.1.1
3.4.2
1
kyso/kyso-front:lateste52595c5c16f
flatted@3.2.9
3.4.2
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
flatted@3.3.1
3.4.2
1
library/ghost:5.79.083f7bf209844
flatted@3.2.7
3.4.2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
flatted@3.1.1
3.4.2
1
linuxserver/codimd:latestb801bbcf6386
flatted@2.0.2
3.4.2
1
lissy93/dashy:2.0.51991f7be5ed0
flatted@3.2.5
3.4.2
1
lsstsqre/squareone:0.4.09ded78e7fe03
flatted@3.1.1
3.4.2
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
flatted@2.0.2
3.4.2
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
flatted@3.3.3
3.4.2
1
misskey/misskey:12.110.1e08b7c478093
flatted@3.1.0
3.4.2
1
mitchxxx/amazon:214e72480ec63a
flatted@3.2.7
3.4.2
1
mozilla/sentencecollector:2.0.91da6ff5c4895
flatted@2.0.1
3.4.2
1
n8nio/n8n:1.86.08b39ed5a2de9
flatted@3.2.7
3.4.2
1
n8nio/n8n:0.212.0a9195bc499a3
flatted@3.2.7
3.4.2
1
n8nio/n8n:1.33.1dd171d45102a
flatted@3.2.7
3.4.2
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
flatted@3.1.1
3.4.2
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
flatted@3.2.7
3.4.2
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
flatted@3.2.7
3.4.2
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
flatted@3.3.3
3.4.2
1
ooghenekaro/amazon:latest03394ba1d6d8
flatted@3.2.7
3.4.2
1
opea/codegen-ui:1.02bee4eb66f3e
flatted@3.3.1
3.4.2
1
openbas/caldera-server:5.1.0a277796d9724
flatted@3.2.5
3.4.2
1
openmined/syft-frontend:0.9.5d11524a3854a
flatted@3.2.9
3.4.2
1
phntom/codimd:2.4.31b9aafbb62e6
flatted@2.0.1
3.4.2
1
pysga1996/python-redis-web:latestfdeec30ad482
flatted@3.1.1
3.4.2
1
qxip/qryn:3.2.3977acc9c7a9fd
flatted@3.3.1
3.4.2
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
flatted@3.3.2
3.4.2
1
samajh/alprfrontend:latest05ef4fddbb75
flatted@3.2.7
3.4.2
1
sharanalwar/redchef-frontend:latest5e82950b16b7
flatted@3.3.3
3.4.2
1
sigp/siren:v3.0.42c219b04758e
flatted@3.3.3
3.4.2
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
flatted@2.0.2
3.4.2
1
solidproject/community-server:6.0.2ccc4acb7e9a1
flatted@3.1.1
3.4.2
1
soulou2019/node-server:latest5e6ecfcc109e
flatted@3.2.7
3.4.2
1
stanfordoval/almond-server:latest1a63cdccedaf
flatted@3.2.2
3.4.2
1
sysnet4admin/colosseum-cms:loge74b43c7f492
flatted@3.3.3
3.4.2
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
flatted@3.3.3
3.4.2
1
testhubio/testhub-frontend:on-preme86c2db53be8
flatted@2.0.2
3.4.2
1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
flatted@3.2.7
3.4.2
1
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
flatted@2.0.2
3.4.2
1
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
flatted@3.3.1
3.4.2
1
treskon/portrait-ui:DEV-lateste7970783bc8d
flatted@3.2.5
3.4.2
1
ubercadence/web:v3.29.58564a5b44a6d
flatted@3.1.1
3.4.2
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
flatted@3.3.1
3.4.2
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
flatted@3.3.4
3.4.2
1
unleashorg/unleash-server:7.5.09adb37e399ba
flatted@3.2.7
3.4.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.