StackRadar

CVE-2026-33532

Medium

Advisory

Published 25 Mar 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
187
of 17,787 indexed, latest versions
Container images
180
deployed by those charts
Fix available
1 of 2
affected packages

yaml is vulnerable to Stack Overflow via deeply nested YAML collections

Carried by container images the latest versions of 187 of 17,787 indexed charts deploy, on 180 images.

Affected packageAffected versionsFixed inImages
yamlnpm1.0.0, 1.8.2, 1.9.2, 1.10.0+18 more1.10.3, 2.8.3180
node-yamldeb2.3.4+~cs0.4.0-1no fix listed1
OSV records
DEBIAN-CVE-2026-33532GHSA-48c2-rrv3-qjmp

Charts affected

187 by stars
ChartLatestAffected imagesRadar Score
prismeai-coreprismeai1.12.12 of 7See more

prismeai-core prismeai 1.12.1

2 of the 7 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod470da8f8730c
yaml@2.8.2
2.8.3
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbce6d452ad08
yaml@2.8.2
2.8.3

Open the chart page →

3,271
recipe-apprecipe-app0.1.01 of 2See more

recipe-app recipe-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
yaml@2.5.1
2.8.3

Open the chart page →

3,271
helm-redchefredchef0.1.01 of 3See more

helm-redchef redchef 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
sharanalwar/redchef-frontend:latest5e82950b16b7
yaml@1.10.2
1.10.3

Open the chart page →

4,658
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
yaml@2.5.0
2.8.3

Open the chart page →

6,794
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
yaml@2.8.0
2.8.3

Open the chart page →

4,546
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
yaml@1.10.2
1.10.3

Open the chart page →

6,026
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
yaml@1.10.2
1.10.3

Open the chart page →

7,429
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
yaml@1.10.2
1.10.3

Open the chart page →

4,431
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
yaml@1.10.2
1.10.3

Open the chart page →

5,499
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
yaml@1.10.2
1.10.3

Open the chart page →

1,991
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
yaml@1.10.2
1.10.3

Open the chart page →

3,143
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
yaml@1.10.2
1.10.3

Open the chart page →

7,586
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
yaml@2.8.0
2.8.3

Open the chart page →

1,313
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
yaml@1.10.2
1.10.3

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
yaml@1.10.2
1.10.3

Open the chart page →

11,554
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
yaml@2.5.1
2.8.3

Open the chart page →

3,968
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
yaml@1.10.2
1.10.3

Open the chart page →

3,881
slack-emoji-makersuminhong0.1.01 of 1See more

slack-emoji-maker suminhong 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
yaml@2.7.1
2.8.3

Open the chart page →

1,653
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
yaml@2.1.1
2.8.3

Open the chart page →

4,017
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
yaml@2.5.1
2.8.3

Open the chart page →

26,489
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
yaml@2.5.1
2.8.3

Open the chart page →

26,060
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
yaml@2.5.1
2.8.3

Open the chart page →

26,535
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
yaml@1.10.2
1.10.3

Open the chart page →

20,362
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
pysga1996/python-redis-web:latestfdeec30ad482
yaml@1.10.0
1.10.3

Open the chart page →

4,662
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
yaml@2.8.2
2.8.3

Open the chart page →

2,029
unleash-proxyunleash0.8.121 of 1See more

unleash-proxy unleash 0.8.12

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
unleashorg/unleash-proxy:v1.4.82538f89e2685
yaml@2.5.1
2.8.3

Open the chart page →

929
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
yaml@2.7.0
2.8.3

Open the chart page →

5,234
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
yaml@2.8.1
2.8.3

Open the chart page →

3,747
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
yaml@2.3.4
2.8.3

Open the chart page →

6,470
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
yaml@2.7.1
2.8.3

Open the chart page →

5,774
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
yaml@2.7.0
2.8.3

Open the chart page →

5,484
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
yaml@1.10.2
1.10.3

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
yaml@1.10.2
1.10.3

Open the chart page →

28,699
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
yaml@1.10.2
1.10.3

Open the chart page →

6,323
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
yaml@1.10.0
1.10.3

Open the chart page →

5,807
workadventureworkadventure1.1.03 of 9See more

workadventure workadventure 1.1.0

3 of the 9 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
yaml@2.3.1
2.8.3
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
yaml@2.3.1
2.8.3
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
yaml@2.3.1
2.8.3

Open the chart page →

16,083
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-33532.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
yaml@2.3.4
2.8.3

Open the chart page →

9,381

Container images carrying it

180 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
yaml@1.10.2
1.10.3
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
yaml@1.10.2
1.10.3
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
yaml@1.10.2
1.10.3
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
yaml@1.10.2
1.10.3
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
yaml@1.10.0
1.10.3
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
yaml@1.10.2
1.10.3
2
governify/assets-manager:v1.4.12987672448c7
yaml@1.10.2
1.10.3
2
governify/director:v1.4.0608c6940bb98
yaml@1.10.2
1.10.3
2
governify/registry:v3.4.0d3f37f4f8168
yaml@1.10.0
1.10.3
2
governify/render:v2.2.0daeca1ce28e6
yaml@1.10.2
1.10.3
2
governify/reporter:v2.2.038595913458f
yaml@1.10.2
1.10.3
2
hookiesolutions/webhookie:latest0629694246ba
yaml@1.10.2
1.10.3
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
yaml@1.10.0
1.10.3
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
yaml@1.10.2
1.10.3
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
yaml@1.10.2
1.10.3
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
yaml@2.8.0
2.8.3
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
yaml@1.10.2
1.10.3
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
yaml@2.3.4
2.8.3
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
yaml@1.10.2
1.10.3
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
yaml@1.10.0
1.10.3
2
outlinewiki/outline:0.69.1d060dcd8f9aa
yaml@1.10.2
1.10.3
2
rajnandan1/kener:3.2.1930407afca731
yaml@2.7.0
2.8.3
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
yaml@1.10.2
1.10.3
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
yaml@1.10.2
1.10.3
2
activepieces/activepieces:0.90.430c10a04fe3d
yaml@2.5.1
2.8.3
1
activepieces/activepieces:0.23.0c26188b44e62
yaml@2.4.1
2.8.3
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
yaml@2.6.1
2.8.3
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
yaml@2.5.1
2.8.3
1
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
yaml@1.10.2
1.10.3
1
apimap/developer:v1.3.1406d3858e20c
yaml@1.10.2
1.10.3
1
apimap/portal:v2.4.0041a4790c65c
yaml@1.10.2
1.10.3
1
arfath29/3-tier-app-frontend:latest384b3e377f47
yaml@1.10.2
1.10.3
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
yaml@1.10.0
1.10.3
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
yaml@1.10.0
1.10.3
1
assistiot/fl_orchestrator:api-latest7473d77448e1
yaml@1.10.2
1.10.3
1
assistiot/open_api_frontend:1.0.1f11d82defc70
yaml@1.10.2
1.10.3
1
automatischio/automatisch:0.15.03bace7a12d5f
yaml@1.10.2
1.10.3
1
baserow/baserow:1.30.1df0c42eb67e8
yaml@1.10.2
1.10.3
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
yaml@1.10.2
1.10.3
1
ccjacobs14/amazon:59a9b14a6f09e
yaml@1.10.2
1.10.3
1
chainsafe/lodestar:latest5593f6e97912
yaml@2.7.0
2.8.3
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
yaml@2.5.1
2.8.3
1
chatwoot/chatwoot:v4.15.167ebc751c171
yaml@1.10.2
1.10.3
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
yaml@2.4.1
2.8.3
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
yaml@2.1.3
2.8.3
1
codercom/code-server:4.11.0-debian1e2cc688008e
yaml@1.0.0
1.10.3
1
codercom/code-server:3.10.247605610ad8d
yaml@1.0.0
1.10.3
1
coldatom/containers-security-front:latest7c2fbbb41bcf
yaml@1.10.2
1.10.3
1
conduction/conduction-ui-app:devd591f5e6f2a9
yaml@1.10.0
1.10.3
1
contane/foreman:0.5.2efb98bdcc4e9
yaml@2.8.0
2.8.3
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.