StackRadar

CVE-2026-33671

High

Advisory

Published 25 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
498
of 17,781 indexed, latest versions
Container images
508
deployed by those charts
Fix available
1 of 2
affected packages

Picomatch has a ReDoS vulnerability via extglob quantifiers

Carried by container images the latest versions of 498 of 17,781 indexed charts deploy, on 508 images.

Affected packageAffected versionsFixed inImages
picomatchnpm2.1.1, 2.2.1, 2.2.2, 2.2.3+5 more2.3.2, 4.0.4508
node-anymatchdeb3.1.3+~cs4.6.1-2no fix listed1
OSV records
GHSA-c2c7-rcm5-vvqjUBUNTU-CVE-2026-33671

Charts affected

498 by stars
ChartLatestAffected imagesRadar Score
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
picomatch@4.0.3
4.0.4

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
picomatch@4.0.3
4.0.4

Open the chart page →

68,240
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
langgenius/dify-web:1.0.0d64914ff0d6d
picomatch@2.3.1
2.3.2

Open the chart page →

19,224
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
picomatch@2.3.1
2.3.2

Open the chart page →

4,551
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-33671.

Open the chart page →

4,251
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
picomatch@2.1.1
2.3.2

Open the chart page →

11,174
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
picomatch@4.0.3
4.0.4

Open the chart page →

30,159
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
picomatch@2.3.0
2.3.2

Open the chart page →

3,744
azuriteemberstackVerified publisher1.0.211 of 1See more

azurite emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
picomatch@4.0.3
4.0.4

Open the chart page →

365
blobscanethereum-helm-chartsVerified publisher0.1.11 of 1See more

blobscan ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ethpandaops/blobscan:latest7a9ab6370657
picomatch@2.3.1
2.3.2

Open the chart page →

1,329
ethstatsethereum-helm-chartsVerified publisher0.1.41 of 1See more

ethstats ethereum-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
skylenet/ethstats-server:pow-latestd757cc016198
picomatch@2.3.1
2.3.2

Open the chart page →

1,109
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
picomatch@4.0.3
4.0.4

Open the chart page →

2,522
bee-localchainethersphereVerified publisher0.2.01 of 1See more

bee-localchain ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
picomatch@2.3.1
2.3.2

Open the chart page →

2,266
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
picomatch@2.3.0
2.3.2

Open the chart page →

3,260
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
picomatch@2.3.1
2.3.2

Open the chart page →

4,756
multichain-proxyethersphereVerified publisher0.1.01 of 1See more

multichain-proxy ethersphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ethersphere/multichain-proxy:0.0.261f5419afbcd
picomatch@2.3.1
2.3.2

Open the chart page →

795
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
picomatch@2.3.1
2.3.2

Open the chart page →

3,320
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.01 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/marcuwynu23/express-typescript-sample:latest9ef671b78ea8
picomatch@4.0.3
4.0.4

Open the chart page →

5,748
mandefactlyVerified publisher0.5.161 of 3See more

mande factly 0.5.16

1 of the 3 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
factly/mande-web:0.34.1742355964b0e
picomatch@2.3.1
2.3.2

Open the chart page →

4,777
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
picomatch@2.3.1
2.3.2

Open the chart page →

3,311
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-user-service:1.049e164a9a439
picomatch@2.3.1
2.3.2

Open the chart page →

7,691
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
picomatch@4.0.3
4.0.4

Open the chart page →

1,847
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
picomatch@2.3.1
2.3.2

Open the chart page →

3,159
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
picomatch@4.0.3
4.0.4

Open the chart page →

1,489
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
picomatch@2.3.0
2.3.2

Open the chart page →

12,222
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
picomatch@2.2.2
2.3.2

Open the chart page →

10,994
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
picomatch@2.2.2
2.3.2

Open the chart page →

4,043
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
picomatch@2.3.0
2.3.2

Open the chart page →

4,591
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
picomatch@4.0.3
4.0.4

Open the chart page →

4,259
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
picomatch@2.3.1
2.3.2

Open the chart page →

34,754
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
picomatch@2.3.1
2.3.2

Open the chart page →

9,019
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
picomatch@2.3.1
2.3.2

Open the chart page →

2,973
Governify-Bluejaygovernify0.1.05 of 12See more

Governify-Bluejay governify 0.1.0

5 of the 12 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
picomatch@2.3.0
2.3.2
governify/director:v1.4.0608c6940bb98
picomatch@2.2.2
2.3.2
governify/registry:v3.4.0d3f37f4f8168
picomatch@2.2.2
2.3.2
governify/render:v2.2.0daeca1ce28e6
picomatch@2.2.2
2.3.2
governify/reporter:v2.2.038595913458f
picomatch@2.2.2
2.3.2

Open the chart page →

22,512
Governify-Falcongovernify0.1.06 of 10See more

Governify-Falcon governify 0.1.0

6 of the 10 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
picomatch@2.3.0
2.3.2
governify/collector-dynamic:v1.3.06d3d1a5b46a9
picomatch@2.2.3
2.3.2
governify/director:v1.4.0608c6940bb98
picomatch@2.2.2
2.3.2
governify/registry:v3.4.0d3f37f4f8168
picomatch@2.2.2
2.3.2
governify/render:v2.2.0daeca1ce28e6
picomatch@2.2.2
2.3.2
governify/reporter:v2.2.038595913458f
picomatch@2.2.2
2.3.2

Open the chart page →

24,319
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
picomatch@2.3.1
2.3.2

Open the chart page →

49,025
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
picomatch@2.3.1
2.3.2

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
picomatch@2.3.1
2.3.2

Open the chart page →

2,682
h2ph2pVerified publisher1.0.11 of 1See more

h2p h2p 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
dacinfomotion/h2p:latest68fa393b472c
picomatch@2.3.1
2.3.2

Open the chart page →

1,713
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
picomatch@2.3.1
2.3.2

Open the chart page →

2,950
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
picomatch@4.0.3
4.0.4

Open the chart page →

9,047
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
picomatch@2.2.2
2.3.2

Open the chart page →

8,213
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
picomatch@2.3.1
2.3.2

Open the chart page →

3,451
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
picomatch@4.0.3
4.0.4

Open the chart page →

778
affinehelmforgeVerified publisher1.0.01 of 3See more

affine helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
picomatch@4.0.3
4.0.4

Open the chart page →

4,018
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
picomatch@4.0.2
4.0.4

Open the chart page →

5,769
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
picomatch@4.0.3
4.0.4

Open the chart page →

739
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
picomatch@2.3.1
2.3.2

Open the chart page →

18,813
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
picomatch@4.0.1
4.0.4

Open the chart page →

1,271
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
library/ghost:6.62.0a7a268bbfb7f
picomatch@4.0.3
4.0.4

Open the chart page →

2,463
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-33671.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
picomatch@4.0.3
4.0.4

Open the chart page →

11,042

Container images carrying it

508 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
picomatch@2.3.1
2.3.2
1
library/ghost:6.37.01ef2e532ca4d
picomatch@4.0.3
4.0.4
1
library/ghost:6.25.12654b1e90413
picomatch@4.0.3
4.0.4
1
library/ghost:6.41.129773d6be407
picomatch@4.0.3
4.0.4
1
library/ghost:4.37.0767230c0f263
picomatch@2.3.1
2.3.2
1
library/ghost:6.39.0-alpine77196da4b0df
picomatch@4.0.3
4.0.4
1
library/ghost:5.79.083f7bf209844
picomatch@2.3.1
2.3.2
1
library/ghost:6.62.0a7a268bbfb7f
picomatch@4.0.3
4.0.4
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
picomatch@2.3.1
2.3.2
1
library/kibana:7.17.150172f1c538e7
picomatch@2.3.1
2.3.2
1
library/kibana:8.18.004c0fc150f3a
picomatch@2.3.1
2.3.2
1
library/kibana:7.17.8c5781ba340ef
picomatch@2.2.2
2.3.2
1
library/kibana:7.17.3e2e2031c15be
picomatch@2.2.2
2.3.2
1
library/node:22-bookworm-slim83f487e0a634
picomatch@4.0.3
4.0.4
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
picomatch@2.3.0
2.3.2
1
linuxserver/code-server:4.10.1a5e43a05ae79
picomatch@2.3.1
2.3.2
1
linuxserver/codimd:latestb801bbcf6386
picomatch@2.2.2
2.3.2
1
lissy93/dashy:2.0.51991f7be5ed0
picomatch@2.3.1
2.3.2
1
lissy93/networking-toolbox:latest700862839553
picomatch@4.0.2
4.0.4
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
picomatch@4.0.3
4.0.4
1
litlyx/litlyx-consumer:latest02225e77d316
picomatch@4.0.3
4.0.4
1
litlyx/litlyx-dashboard:lateste64ff2d52385
picomatch@4.0.2
4.0.4
1
litlyx/litlyx-producer:latest10407f36613f
picomatch@4.0.2
4.0.4
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
picomatch@4.0.2
4.0.4
1
louislam/uptime-kuma:2.5.33e24e96c89ef
picomatch@4.0.3
4.0.4
1
louislam/uptime-kuma:2.4.091e963bfda56
picomatch@4.0.3
4.0.4
1
lsstsqre/squareone:0.4.09ded78e7fe03
picomatch@2.3.0
2.3.2
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
picomatch@2.3.0
2.3.2
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
picomatch@2.3.1
2.3.2
1
mautic/mautic:7-apacheeb8cc73d97e1
picomatch@2.3.1
2.3.2
1
mcpuse/inspector:latest91b25e3eb604
picomatch@4.0.3
4.0.4
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
picomatch@2.3.1
2.3.2
1
misskey/misskey:12.110.1e08b7c478093
picomatch@2.2.2
2.3.2
1
mitchxxx/amazon:214e72480ec63a
picomatch@2.3.1
2.3.2
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
picomatch@2.3.1
2.3.2
1
moreillon/api-proxy:2373c1953739ef6956b5
picomatch@2.3.1
2.3.2
1
moreillon/api-proxy:latestd7d4a5463525
picomatch@2.3.1
2.3.2
1
moreillon/camera-proxy:latestce60056b50c2
picomatch@2.3.1
2.3.2
1
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
picomatch@2.3.1
2.3.2
1
moreillon/food-manager:lateste8fd856e593d
picomatch@2.3.1
2.3.2
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
picomatch@2.3.1
2.3.2
1
mozilla/sentencecollector:2.0.91da6ff5c4895
picomatch@2.2.2
2.3.2
1
mpopoola1/nodejsapp:latest061fc532de7d
picomatch@2.3.1
2.3.2
1
n8nio/n8n:2.25.7761374d4eb84
picomatch@4.0.3
4.0.4
1
n8nio/n8n:1.86.08b39ed5a2de9
picomatch@2.3.1
2.3.2
1
n8nio/n8n:0.212.0a9195bc499a3
picomatch@2.3.1
2.3.2
1
n8nio/n8n:1.33.1dd171d45102a
picomatch@2.3.1
2.3.2
1
neoskop/ixy:2.1.125152b474f54
picomatch@4.0.3
4.0.4
1
neoskop/papergirl:3.2.67f52b5949f03
picomatch@2.3.1
2.3.2
1
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
picomatch@2.3.1
2.3.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.