StackRadar

CVE-2026-33671

High

Advisory

Published 25 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
498
of 17,781 indexed, latest versions
Container images
508
deployed by those charts
Fix available
1 of 2
affected packages

Picomatch has a ReDoS vulnerability via extglob quantifiers

Carried by container images the latest versions of 498 of 17,781 indexed charts deploy, on 508 images.

Affected packageAffected versionsFixed inImages
picomatchnpm2.1.1, 2.2.1, 2.2.2, 2.2.3+5 more2.3.2, 4.0.4508
node-anymatchdeb3.1.3+~cs4.6.1-2no fix listed1
OSV records
GHSA-c2c7-rcm5-vvqjUBUNTU-CVE-2026-33671

Charts affected

498 by stars
ChartLatestAffected imagesRadar Score
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
picomatch@4.0.3
4.0.4

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
picomatch@4.0.3
4.0.4

Open the chart page →

68,240
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
langgenius/dify-web:1.0.0d64914ff0d6d
picomatch@2.3.1
2.3.2

Open the chart page →

19,224
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
picomatch@2.3.1
2.3.2

Open the chart page →

4,551
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-33671.

Open the chart page →

4,251
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
picomatch@2.1.1
2.3.2

Open the chart page →

11,174
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
picomatch@4.0.3
4.0.4

Open the chart page →

30,159
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
picomatch@2.3.0
2.3.2

Open the chart page →

3,744
azuriteemberstackVerified publisher1.0.211 of 1See more

azurite emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
picomatch@4.0.3
4.0.4

Open the chart page →

365
blobscanethereum-helm-chartsVerified publisher0.1.11 of 1See more

blobscan ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ethpandaops/blobscan:latest7a9ab6370657
picomatch@2.3.1
2.3.2

Open the chart page →

1,329
ethstatsethereum-helm-chartsVerified publisher0.1.41 of 1See more

ethstats ethereum-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
skylenet/ethstats-server:pow-latestd757cc016198
picomatch@2.3.1
2.3.2

Open the chart page →

1,109
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
picomatch@4.0.3
4.0.4

Open the chart page →

2,522
bee-localchainethersphereVerified publisher0.2.01 of 1See more

bee-localchain ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
picomatch@2.3.1
2.3.2

Open the chart page →

2,266
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
picomatch@2.3.0
2.3.2

Open the chart page →

3,260
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
picomatch@2.3.1
2.3.2

Open the chart page →

4,756
multichain-proxyethersphereVerified publisher0.1.01 of 1See more

multichain-proxy ethersphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ethersphere/multichain-proxy:0.0.261f5419afbcd
picomatch@2.3.1
2.3.2

Open the chart page →

795
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
picomatch@2.3.1
2.3.2

Open the chart page →

3,320
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.01 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/marcuwynu23/express-typescript-sample:latest9ef671b78ea8
picomatch@4.0.3
4.0.4

Open the chart page →

5,748
mandefactlyVerified publisher0.5.161 of 3See more

mande factly 0.5.16

1 of the 3 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
factly/mande-web:0.34.1742355964b0e
picomatch@2.3.1
2.3.2

Open the chart page →

4,777
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
picomatch@2.3.1
2.3.2

Open the chart page →

3,311
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-user-service:1.049e164a9a439
picomatch@2.3.1
2.3.2

Open the chart page →

7,691
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
picomatch@4.0.3
4.0.4

Open the chart page →

1,847
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
picomatch@2.3.1
2.3.2

Open the chart page →

3,159
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
picomatch@4.0.3
4.0.4

Open the chart page →

1,489
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
picomatch@2.3.0
2.3.2

Open the chart page →

12,222
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
picomatch@2.2.2
2.3.2

Open the chart page →

10,994
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
picomatch@2.2.2
2.3.2

Open the chart page →

4,043
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
picomatch@2.3.0
2.3.2

Open the chart page →

4,591
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
picomatch@4.0.3
4.0.4

Open the chart page →

4,259
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
picomatch@2.3.1
2.3.2

Open the chart page →

34,754
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
picomatch@2.3.1
2.3.2

Open the chart page →

9,019
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
picomatch@2.3.1
2.3.2

Open the chart page →

2,973
Governify-Bluejaygovernify0.1.05 of 12See more

Governify-Bluejay governify 0.1.0

5 of the 12 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
picomatch@2.3.0
2.3.2
governify/director:v1.4.0608c6940bb98
picomatch@2.2.2
2.3.2
governify/registry:v3.4.0d3f37f4f8168
picomatch@2.2.2
2.3.2
governify/render:v2.2.0daeca1ce28e6
picomatch@2.2.2
2.3.2
governify/reporter:v2.2.038595913458f
picomatch@2.2.2
2.3.2

Open the chart page →

22,512
Governify-Falcongovernify0.1.06 of 10See more

Governify-Falcon governify 0.1.0

6 of the 10 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
picomatch@2.3.0
2.3.2
governify/collector-dynamic:v1.3.06d3d1a5b46a9
picomatch@2.2.3
2.3.2
governify/director:v1.4.0608c6940bb98
picomatch@2.2.2
2.3.2
governify/registry:v3.4.0d3f37f4f8168
picomatch@2.2.2
2.3.2
governify/render:v2.2.0daeca1ce28e6
picomatch@2.2.2
2.3.2
governify/reporter:v2.2.038595913458f
picomatch@2.2.2
2.3.2

Open the chart page →

24,319
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
picomatch@2.3.1
2.3.2

Open the chart page →

49,025
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
picomatch@2.3.1
2.3.2

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
picomatch@2.3.1
2.3.2

Open the chart page →

2,682
h2ph2pVerified publisher1.0.11 of 1See more

h2p h2p 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
dacinfomotion/h2p:latest68fa393b472c
picomatch@2.3.1
2.3.2

Open the chart page →

1,713
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
picomatch@2.3.1
2.3.2

Open the chart page →

2,950
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
picomatch@4.0.3
4.0.4

Open the chart page →

9,047
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
picomatch@2.2.2
2.3.2

Open the chart page →

8,213
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
picomatch@2.3.1
2.3.2

Open the chart page →

3,451
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
picomatch@4.0.3
4.0.4

Open the chart page →

778
affinehelmforgeVerified publisher1.0.01 of 3See more

affine helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
picomatch@4.0.3
4.0.4

Open the chart page →

4,018
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
picomatch@4.0.2
4.0.4

Open the chart page →

5,769
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
picomatch@4.0.3
4.0.4

Open the chart page →

739
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
picomatch@2.3.1
2.3.2

Open the chart page →

18,813
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
picomatch@4.0.1
4.0.4

Open the chart page →

1,271
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
library/ghost:6.62.0a7a268bbfb7f
picomatch@4.0.3
4.0.4

Open the chart page →

2,463
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
picomatch@4.0.3
4.0.4

Open the chart page →

11,042

Container images carrying it

508 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
codercom/code-server:4.11.0-debian1e2cc688008e
picomatch@2.3.1
2.3.2
1
codercom/code-server:3.10.247605610ad8d
picomatch@2.2.3
2.3.2
1
codetogether/codetogether:latest4348c8a38752
picomatch@2.3.1
2.3.2
1
coldatom/containers-security-front:latest7c2fbbb41bcf
picomatch@2.3.1
2.3.2
1
conduction/conduction-ui-app:devd591f5e6f2a9
picomatch@2.2.2
2.3.2
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
picomatch@4.0.2
4.0.4
1
countly/api:25.05.4f4cc7447c4f5
picomatch@2.3.1
2.3.2
1
countly/countly-server:25.05.4e3c238248f99
picomatch@2.3.1
2.3.2
1
countly/frontend:25.05.42acbc11499b6
picomatch@2.3.1
2.3.2
1
cryptexlabs/authf:0.12.11189c07411d7c
picomatch@2.3.1
2.3.2
1
cspconsole/report-processor:1.0.279a2d8840bfdf
picomatch@4.0.3
4.0.4
1
dacinfomotion/h2p:latest68fa393b472c
picomatch@2.3.1
2.3.2
1
danny1dockerhub/nodejswebapp:lateste434683fcc89
picomatch@2.3.1
2.3.2
1
dbgate/dbgate:7.2.3f2dc7423ea88
picomatch@4.0.3
4.0.4
1
decisionrules/business-intelligence:latest1135a6d4f09b
picomatch@4.0.3
4.0.4
1
denisshav/backend:latest4cc8dc5a4499
picomatch@2.2.3
2.3.2
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
picomatch@2.3.1
2.3.2
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
picomatch@4.0.3
4.0.4
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
picomatch@2.3.1
2.3.2
1
directus/directus:12.0.29c8470ea465c
picomatch@4.0.3
4.0.4
1
directus/directus:11.1.0e3c8bb975350
picomatch@2.3.1
2.3.2
1
diygod/rsshub:2025-11-097a6312cac0d5
picomatch@4.0.2
4.0.4
1
docmost/docmost:0.95.041c8d777cf23
picomatch@4.0.3
4.0.4
1
drumsergio/genieacs:1.2.16.028244054e1bf
picomatch@4.0.3
4.0.4
1
drumsergio/pumperly:1.4.885bbc3915e9e
picomatch@4.0.3
4.0.4
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
picomatch@4.0.3
4.0.4
1
electerious/ackee:3.2.05e7173fa321c
picomatch@2.3.0
2.3.2
1
enketo/enketo-express:3.0.4dcad9c2273f6
picomatch@2.3.0
2.3.2
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
picomatch@2.3.0
2.3.2
1
etherpad/etherpad:2.7.2b723fe5f2594
picomatch@4.0.3
4.0.4
1
ethersphere/bzz-token-service:latest7624f11a72ad
picomatch@2.3.0
2.3.2
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
picomatch@2.3.1
2.3.2
1
ethersphere/onboarding-faucet:0.3.0513154aab230
picomatch@2.3.1
2.3.2
1
ethpandaops/blobscan:latest7a9ab6370657
picomatch@2.3.1
2.3.2
1
evoapicloud/evolution-api:latest966625532d90
picomatch@4.0.3
4.0.4
1
factly/mande-web:0.34.1742355964b0e
picomatch@2.3.1
2.3.2
1
fallenbagel/jellyseerr:latest4538137bc5af
picomatch@4.0.2
4.0.4
1
felipecs8/landing-page:v1db6d44e325a1
picomatch@4.0.3
4.0.4
1
fiware/idm:8.3.3a1b6ed4ae84f
picomatch@2.3.1
2.3.2
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
picomatch@2.2.2
2.3.2
1
fosrl/pangolin:1.13.0c32ad797ab96
picomatch@2.3.1
2.3.2
1
fthomas/scala-steward:latest367afe974b7a
picomatch@4.0.3
4.0.4
1
getferdi/ferdi-server:1.3.26e620b85afaa
picomatch@2.3.1
2.3.2
1
gethue/hue:latest7d5c1b9f8a79
picomatch@4.0.3
4.0.4
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
picomatch@4.0.3
4.0.4
1
globalping/globalping-probe:latest8acbd23009fd
picomatch@2.3.1
2.3.2
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
picomatch@2.2.3
2.3.2
1
gristlabs/grist:0.7.96e71b1914a7e
picomatch@2.2.2
2.3.2
1
hamid2021/nodejs-dockercli:latest429d99890c3c
picomatch@2.3.1
2.3.2
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
picomatch@2.3.1
2.3.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.