StackRadar

CVE-2026-33672

Medium

Advisory

Published 25 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
498
of 17,781 indexed, latest versions
Container images
508
deployed by those charts
Fix available
1 of 2
affected packages

Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

Carried by container images the latest versions of 498 of 17,781 indexed charts deploy, on 508 images.

Affected packageAffected versionsFixed inImages
picomatchnpm2.1.1, 2.2.1, 2.2.2, 2.2.3+5 more2.3.2, 4.0.4508
node-anymatchdeb3.1.3+~cs4.6.1-2no fix listed1
OSV records
GHSA-3v7f-55p6-f55pUBUNTU-CVE-2026-33672

Charts affected

498 by stars
ChartLatestAffected imagesRadar Score
nightscoutgabe565Verified publisher0.13.01 of 2See more

nightscout gabe565 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
picomatch@2.3.1
2.3.2

Open the chart page →

2,521
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
picomatch@2.3.0
2.3.2

Open the chart page →

22,773
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
picomatch@2.3.1
2.3.2

Open the chart page →

7,579
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
picomatch@2.2.3
2.3.2

Open the chart page →

3,476
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
picomatch@2.3.1
2.3.2

Open the chart page →

10,311
kubebadgeskubebadges0.1.31 of 2See more

kubebadges kubebadges 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
shieldsio/shields:nextfa194b446e42
picomatch@4.0.3
4.0.4

Open the chart page →

1,798
kubeviouskubevious1.2.24 of 7See more

kubevious kubevious 1.2.2

4 of the 7 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
kubevious/backend:1.2.22d9ba6eb46b6
picomatch@2.3.1
2.3.2
kubevious/collector:1.2.1f58226f9d84e
picomatch@2.3.1
2.3.2
kubevious/guard:1.2.19bf567704de2
picomatch@2.3.1
2.3.2
kubevious/parser:1.2.299ae7a5168c2
picomatch@2.3.1
2.3.2

Open the chart page →

14,204
bitwarden-crd-operatorlerentisVerified publisher0.18.01 of 1See more

bitwarden-crd-operator lerentis 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
picomatch@4.0.3
4.0.4

Open the chart page →

2,003
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
picomatch@2.3.1
2.3.2

Open the chart page →

2,635
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
picomatch@2.2.2
2.3.2

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
picomatch@2.3.0
2.3.2
kobotoolbox/kpi:2.022.24dbcacc01bccd4
picomatch@2.3.1
2.3.2

Open the chart page →

18,517
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
picomatch@2.3.1
2.3.2

Open the chart page →

7,776
kratos-selfservice-ui-nodeory0.64.01 of 1See more

kratos-selfservice-ui-node ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
picomatch@2.3.1
2.3.2

Open the chart page →

1,966
pacmanpacmanVerified publisher2.0.21 of 2See more

pacman pacman 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/shuguet/pacman:latesta0ec71732c3c
picomatch@4.0.3
4.0.4

Open the chart page →

638
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
picomatch@2.3.0
2.3.2

Open the chart page →

24,488
soketisoketi2.0.01 of 1See more

soketi soketi 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/soketi/soketi:1.6-16-debian713223456cf1
picomatch@2.3.1
2.3.2

Open the chart page →

1,636
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
picomatch@4.0.3
4.0.4

Open the chart page →

9,770
feedbacksystemthm-mni-iiVerified publisher0.47.12 of 10See more

feedbacksystem thm-mni-ii 0.47.1

2 of the 10 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
thmmniii/fbs-collab:v1.27.15d389e3c5ce6
picomatch@2.3.1
2.3.2
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
picomatch@2.3.1
2.3.2

Open the chart page →

28,534
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
picomatch@2.3.1
2.3.2

Open the chart page →

4,016
aapbaapbVerified publisher0.1.31 of 1See more

aapb aapb 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
picomatch@4.0.3
4.0.4

Open the chart page →

1,044
agentareaagentareaVerified publisher0.0.182 of 16See more

agentarea agentarea 0.0.18

2 of the 16 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
agentarea/agentarea-frontend:latest2098a9d7b1fe
picomatch@4.0.3
4.0.4
agentarea/agentarea-mcp-runner:latestd3c209a5d531
picomatch@4.0.3
4.0.4

Open the chart page →

14,914
bredbandskollen-prometheus-exporteraolde0.2.31 of 1See more

bredbandskollen-prometheus-exporter aolde 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
picomatch@2.2.3
2.3.2

Open the chart page →

1,972
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
picomatch@2.2.2
2.3.2

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
picomatch@2.2.2
2.3.2

Open the chart page →

10,730
dltbrokerassist-iot-distributed-broker0.2.01 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

1 of the 9 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
picomatch@2.3.1
2.3.2

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.01 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

1 of the 9 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
picomatch@2.3.1
2.3.2

Open the chart page →

77,687
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
picomatch@4.0.3
4.0.4

Open the chart page →

1,991
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
picomatch@2.3.1
2.3.2

Open the chart page →

1,843
skoonerchristianhuthVerified publisher0.4.01 of 1See more

skooner christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
picomatch@2.3.1
2.3.2

Open the chart page →

1,341
data-fairdata354-helmVerified publisher1.1.25 of 12See more

data-fair data354-helm 1.1.2

5 of the 12 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/data-fair/data-fair:3cc9498b64b5b
picomatch@2.3.1
2.3.2
ghcr.io/data-fair/metrics:0a8d40779eeae
picomatch@2.3.0
2.3.2
ghcr.io/data-fair/notify:3c739b74dabb0
picomatch@2.3.1
2.3.2
ghcr.io/data-fair/processings:15a9216989707
picomatch@2.3.1
2.3.2
ghcr.io/data-fair/simple-directory:438a4f32fad82
picomatch@2.3.1
2.3.2

Open the chart page →

38,346
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
picomatch@2.3.1
2.3.2

Open the chart page →

5,056
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
picomatch@4.0.3
4.0.4

Open the chart page →

7,473
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
picomatch@2.3.0
2.3.2

Open the chart page →

3,925
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-33672.

Open the chart page →

31,510
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
picomatch@2.3.1
2.3.2

Open the chart page →

11,458
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
taigaio/taiga-events:latest92fc0822564f
picomatch@2.3.0
2.3.2

Open the chart page →

8,496
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
picomatch@2.2.2
2.3.2

Open the chart page →

2,519
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
picomatch@2.3.1
2.3.2

Open the chart page →

4,260
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
picomatch@2.2.2
2.3.2

Open the chart page →

3,444
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
picomatch@2.3.0
2.3.2

Open the chart page →

7,801
youtubedl-materialgeek-cookbookVerified publisher4.4.21 of 1See more

youtubedl-material geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.23720b856bd2f
picomatch@2.2.2
2.3.2

Open the chart page →

4,410
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
picomatch@4.0.3
4.0.4

Open the chart page →

3,123
globalpingglobalpingVerified publisher1.0.111 of 1See more

globalping globalping 1.0.11

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
globalping/globalping-probe:latest8acbd23009fd
picomatch@2.3.1
2.3.2

Open the chart page →

518
ghostgroundhog2k0.212.121 of 1See more

ghost groundhog2k 0.212.12

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
picomatch@4.0.3
4.0.4

Open the chart page →

2,000
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
picomatch@4.0.3
4.0.4

Open the chart page →

12,397
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
picomatch@4.0.2
4.0.4

Open the chart page →

15,712
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
picomatch@2.2.2
2.3.2

Open the chart page →

17,284
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
picomatch@2.3.0
2.3.2

Open the chart page →

3,369
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
picomatch@2.3.1
2.3.2

Open the chart page →

5,228
kikplatekikplateVerified publisher0.22.01 of 3See more

kikplate kikplate 0.22.0

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/kikplate/kikplate-web:main34bbb61e8e42
picomatch@4.0.3
4.0.4

Open the chart page →

2,770

Container images carrying it

508 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
codercom/code-server:4.11.0-debian1e2cc688008e
picomatch@2.3.1
2.3.2
1
codercom/code-server:3.10.247605610ad8d
picomatch@2.2.3
2.3.2
1
codetogether/codetogether:latest4348c8a38752
picomatch@2.3.1
2.3.2
1
coldatom/containers-security-front:latest7c2fbbb41bcf
picomatch@2.3.1
2.3.2
1
conduction/conduction-ui-app:devd591f5e6f2a9
picomatch@2.2.2
2.3.2
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
picomatch@4.0.2
4.0.4
1
countly/api:25.05.4f4cc7447c4f5
picomatch@2.3.1
2.3.2
1
countly/countly-server:25.05.4e3c238248f99
picomatch@2.3.1
2.3.2
1
countly/frontend:25.05.42acbc11499b6
picomatch@2.3.1
2.3.2
1
cryptexlabs/authf:0.12.11189c07411d7c
picomatch@2.3.1
2.3.2
1
cspconsole/report-processor:1.0.279a2d8840bfdf
picomatch@4.0.3
4.0.4
1
dacinfomotion/h2p:latest68fa393b472c
picomatch@2.3.1
2.3.2
1
danny1dockerhub/nodejswebapp:lateste434683fcc89
picomatch@2.3.1
2.3.2
1
dbgate/dbgate:7.2.3f2dc7423ea88
picomatch@4.0.3
4.0.4
1
decisionrules/business-intelligence:latest1135a6d4f09b
picomatch@4.0.3
4.0.4
1
denisshav/backend:latest4cc8dc5a4499
picomatch@2.2.3
2.3.2
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
picomatch@2.3.1
2.3.2
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
picomatch@4.0.3
4.0.4
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
picomatch@2.3.1
2.3.2
1
directus/directus:12.0.29c8470ea465c
picomatch@4.0.3
4.0.4
1
directus/directus:11.1.0e3c8bb975350
picomatch@2.3.1
2.3.2
1
diygod/rsshub:2025-11-097a6312cac0d5
picomatch@4.0.2
4.0.4
1
docmost/docmost:0.95.041c8d777cf23
picomatch@4.0.3
4.0.4
1
drumsergio/genieacs:1.2.16.028244054e1bf
picomatch@4.0.3
4.0.4
1
drumsergio/pumperly:1.4.885bbc3915e9e
picomatch@4.0.3
4.0.4
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
picomatch@4.0.3
4.0.4
1
electerious/ackee:3.2.05e7173fa321c
picomatch@2.3.0
2.3.2
1
enketo/enketo-express:3.0.4dcad9c2273f6
picomatch@2.3.0
2.3.2
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
picomatch@2.3.0
2.3.2
1
etherpad/etherpad:2.7.2b723fe5f2594
picomatch@4.0.3
4.0.4
1
ethersphere/bzz-token-service:latest7624f11a72ad
picomatch@2.3.0
2.3.2
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
picomatch@2.3.1
2.3.2
1
ethersphere/onboarding-faucet:0.3.0513154aab230
picomatch@2.3.1
2.3.2
1
ethpandaops/blobscan:latest7a9ab6370657
picomatch@2.3.1
2.3.2
1
evoapicloud/evolution-api:latest966625532d90
picomatch@4.0.3
4.0.4
1
factly/mande-web:0.34.1742355964b0e
picomatch@2.3.1
2.3.2
1
fallenbagel/jellyseerr:latest4538137bc5af
picomatch@4.0.2
4.0.4
1
felipecs8/landing-page:v1db6d44e325a1
picomatch@4.0.3
4.0.4
1
fiware/idm:8.3.3a1b6ed4ae84f
picomatch@2.3.1
2.3.2
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
picomatch@2.2.2
2.3.2
1
fosrl/pangolin:1.13.0c32ad797ab96
picomatch@2.3.1
2.3.2
1
fthomas/scala-steward:latest367afe974b7a
picomatch@4.0.3
4.0.4
1
getferdi/ferdi-server:1.3.26e620b85afaa
picomatch@2.3.1
2.3.2
1
gethue/hue:latest7d5c1b9f8a79
picomatch@4.0.3
4.0.4
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
picomatch@4.0.3
4.0.4
1
globalping/globalping-probe:latest8acbd23009fd
picomatch@2.3.1
2.3.2
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
picomatch@2.2.3
2.3.2
1
gristlabs/grist:0.7.96e71b1914a7e
picomatch@2.2.2
2.3.2
1
hamid2021/nodejs-dockercli:latest429d99890c3c
picomatch@2.3.1
2.3.2
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
picomatch@2.3.1
2.3.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.