StackRadar

CVE-2026-33672

Medium

Advisory

Published 25 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
498
of 17,781 indexed, latest versions
Container images
508
deployed by those charts
Fix available
1 of 2
affected packages

Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

Carried by container images the latest versions of 498 of 17,781 indexed charts deploy, on 508 images.

Affected packageAffected versionsFixed inImages
picomatchnpm2.1.1, 2.2.1, 2.2.2, 2.2.3+5 more2.3.2, 4.0.4508
node-anymatchdeb3.1.3+~cs4.6.1-2no fix listed1
OSV records
GHSA-3v7f-55p6-f55pUBUNTU-CVE-2026-33672

Charts affected

498 by stars
ChartLatestAffected imagesRadar Score
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
picomatch@2.3.1
2.3.2

Open the chart page →

6,608
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
picomatch@4.0.2
4.0.4

Open the chart page →

4,016
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
picomatch@2.3.1
2.3.2

Open the chart page →

3,128
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
picomatch@2.3.1
2.3.2

Open the chart page →

2,116
myawesomeappmyawesomeapp1.1.01 of 1See more

myawesomeapp myawesomeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebapp:latestea5b71588a76
picomatch@2.3.1
2.3.2

Open the chart page →

1,267
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
picomatch@2.3.1
2.3.2

Open the chart page →

2,116
myawesomeappmyawesomeapp20.1.01 of 1See more

myawesomeapp myawesomeapp2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mpopoola1/nodejsapp:latest061fc532de7d
picomatch@2.3.1
2.3.2

Open the chart page →

1,118
myawesomeapp-feb24myawesomeapp-feb240.1.11 of 1See more

myawesomeapp-feb24 myawesomeapp-feb24 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
josepht05/nodejs-feb24:latest36cb0c618c94
picomatch@2.3.1
2.3.2

Open the chart page →

1,070
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
picomatch@2.3.1
2.3.2

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
picomatch@2.3.1
2.3.2

Open the chart page →

2,116
myawesomeappoctmyawesomeappoct0.1.11 of 1See more

myawesomeappoct myawesomeappoct 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
myawesomeappoctmyawesomeappoct20230.1.11 of 1See more

myawesomeappoct myawesomeappoct2023 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
hamid2021/nodejs-dockercli:latest429d99890c3c
picomatch@2.3.1
2.3.2

Open the chart page →

1,118
mydannyappmydannyapp1.1.01 of 1See more

mydannyapp mydannyapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
danny1dockerhub/nodejswebapp:lateste434683fcc89
picomatch@2.3.1
2.3.2

Open the chart page →

1,267
mygreatappmygreatapp0.1.01 of 1See more

mygreatapp mygreatapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ktitilayo2/nodejswebapp:latest8bac28058688
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
myhelmappmyhelm-app1.1.01 of 1See more

myhelmapp myhelm-app 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
patdada/bella-docker:v1.0.075127147a624
picomatch@2.3.1
2.3.2

Open the chart page →

1,625
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
picomatch@2.3.1
2.3.2

Open the chart page →

3,359
myhelmappmyhelmapp11.1.01 of 1See more

myhelmapp myhelmapp1 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
josepht05/titajo-docker:v1.0.0d94024965d78
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
myhelmappmyhelmpapp1.1.01 of 1See more

myhelmapp myhelmpapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
picomatch@2.3.1
2.3.2

Open the chart page →

1,235
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
picomatch@2.3.1
2.3.2

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
picomatch@2.3.1
2.3.2

Open the chart page →

3,269
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
picomatch@4.0.3
4.0.4

Open the chart page →

30,028
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
picomatch@4.0.3
4.0.4

Open the chart page →

1,166
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
picomatch@2.3.1
2.3.2

Open the chart page →

6,982
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
picomatch@4.0.3
4.0.4

Open the chart page →

7,310
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
picomatch@4.0.3
4.0.4

Open the chart page →

3,798
nodeapp-chartnodeapp-chart0.1.01 of 1See more

nodeapp-chart nodeapp-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
laly9999/node-app-dockerized:latest75ae77a20c6c
picomatch@2.3.1
2.3.2

Open the chart page →

1,118
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
picomatch@2.3.1
2.3.2

Open the chart page →

10,218
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
picomatch@2.3.1
2.3.2

Open the chart page →

2,919
nostreamnostream0.1.01 of 1See more

nostream nostream 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/cameri/nostream:main8726533b9e69
picomatch@4.0.3
4.0.4

Open the chart page →

595
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
picomatch@2.3.1
2.3.2

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
picomatch@2.3.1
2.3.2

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
picomatch@2.3.1
2.3.2

Open the chart page →

15,187
nottieawesomeappnottieawesomeapp0.1.01 of 1See more

nottieawesomeapp nottieawesomeapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nottiey/mynodejswebapp:latest9c35a24c9eb3
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
picomatch@2.2.2
2.3.2

Open the chart page →

27,465
ferdi-serverobeoneVerified publisher1.0.31 of 2See more

ferdi-server obeone 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
getferdi/ferdi-server:1.3.26e620b85afaa
picomatch@2.3.1
2.3.2

Open the chart page →

1,866
firecrawlobeoneVerified publisher3.0.11 of 5See more

firecrawl obeone 3.0.1

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/firecrawl:2.11.33092ee28c20a0d
picomatch@4.0.3
4.0.4

Open the chart page →

9,995
node-appoli-the-devVerified publisher1.0.01 of 1See more

node-app oli-the-dev 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
library/node:22-bookworm-slim83f487e0a634
picomatch@4.0.3
4.0.4

Open the chart page →

1,149
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
picomatch@2.3.1
2.3.2

Open the chart page →

4,219
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
picomatch@2.3.1
2.3.2

Open the chart page →

2,421
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
picomatch@2.3.1
2.3.2

Open the chart page →

2,370
dify-enterpriseopenshift3.9.82 of 13See more

dify-enterprise openshift 3.9.8

2 of the 13 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
picomatch@2.3.1
2.3.2
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
picomatch@2.3.1
2.3.2

Open the chart page →

4,660
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
picomatch@2.3.0
2.3.2

Open the chart page →

9,968
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
picomatch@2.3.1
2.3.2

Open the chart page →

838
ungatep2p-avs0.1.01 of 3See more

ungate p2p-avs 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
picomatch@2.3.1
2.3.2

Open the chart page →

27,373
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/michaelhaigh/pacman:latestb0931b1f085d
picomatch@4.0.3
4.0.4

Open the chart page →

3,562
pairdroppascaliskeVerified publisher2.0.01 of 1See more

pairdrop pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/pairdrop:version-v1.11.23279d2d986c0
picomatch@4.0.3
4.0.4

Open the chart page →

663
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
picomatch@2.3.1
2.3.2

Open the chart page →

6,524
pumperlypumperlyVerified publisher0.1.21 of 3See more

pumperly pumperly 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
drumsergio/pumperly:1.4.885bbc3915e9e
picomatch@4.0.3
4.0.4

Open the chart page →

2,854
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
picomatch@2.3.1
2.3.2

Open the chart page →

2,969
radar-self-enrolment-uiradar-baseVerified publisher0.4.21 of 1See more

radar-self-enrolment-ui radar-base 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
picomatch@4.0.2
4.0.4

Open the chart page →

1,506

Container images carrying it

508 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
codercom/code-server:4.11.0-debian1e2cc688008e
picomatch@2.3.1
2.3.2
1
codercom/code-server:3.10.247605610ad8d
picomatch@2.2.3
2.3.2
1
codetogether/codetogether:latest4348c8a38752
picomatch@2.3.1
2.3.2
1
coldatom/containers-security-front:latest7c2fbbb41bcf
picomatch@2.3.1
2.3.2
1
conduction/conduction-ui-app:devd591f5e6f2a9
picomatch@2.2.2
2.3.2
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
picomatch@4.0.2
4.0.4
1
countly/api:25.05.4f4cc7447c4f5
picomatch@2.3.1
2.3.2
1
countly/countly-server:25.05.4e3c238248f99
picomatch@2.3.1
2.3.2
1
countly/frontend:25.05.42acbc11499b6
picomatch@2.3.1
2.3.2
1
cryptexlabs/authf:0.12.11189c07411d7c
picomatch@2.3.1
2.3.2
1
cspconsole/report-processor:1.0.279a2d8840bfdf
picomatch@4.0.3
4.0.4
1
dacinfomotion/h2p:latest68fa393b472c
picomatch@2.3.1
2.3.2
1
danny1dockerhub/nodejswebapp:lateste434683fcc89
picomatch@2.3.1
2.3.2
1
dbgate/dbgate:7.2.3f2dc7423ea88
picomatch@4.0.3
4.0.4
1
decisionrules/business-intelligence:latest1135a6d4f09b
picomatch@4.0.3
4.0.4
1
denisshav/backend:latest4cc8dc5a4499
picomatch@2.2.3
2.3.2
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
picomatch@2.3.1
2.3.2
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
picomatch@4.0.3
4.0.4
1
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
picomatch@2.3.1
2.3.2
1
directus/directus:12.0.29c8470ea465c
picomatch@4.0.3
4.0.4
1
directus/directus:11.1.0e3c8bb975350
picomatch@2.3.1
2.3.2
1
diygod/rsshub:2025-11-097a6312cac0d5
picomatch@4.0.2
4.0.4
1
docmost/docmost:0.95.041c8d777cf23
picomatch@4.0.3
4.0.4
1
drumsergio/genieacs:1.2.16.028244054e1bf
picomatch@4.0.3
4.0.4
1
drumsergio/pumperly:1.4.885bbc3915e9e
picomatch@4.0.3
4.0.4
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
picomatch@4.0.3
4.0.4
1
electerious/ackee:3.2.05e7173fa321c
picomatch@2.3.0
2.3.2
1
enketo/enketo-express:3.0.4dcad9c2273f6
picomatch@2.3.0
2.3.2
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
picomatch@2.3.0
2.3.2
1
etherpad/etherpad:2.7.2b723fe5f2594
picomatch@4.0.3
4.0.4
1
ethersphere/bzz-token-service:latest7624f11a72ad
picomatch@2.3.0
2.3.2
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
picomatch@2.3.1
2.3.2
1
ethersphere/onboarding-faucet:0.3.0513154aab230
picomatch@2.3.1
2.3.2
1
ethpandaops/blobscan:latest7a9ab6370657
picomatch@2.3.1
2.3.2
1
evoapicloud/evolution-api:latest966625532d90
picomatch@4.0.3
4.0.4
1
factly/mande-web:0.34.1742355964b0e
picomatch@2.3.1
2.3.2
1
fallenbagel/jellyseerr:latest4538137bc5af
picomatch@4.0.2
4.0.4
1
felipecs8/landing-page:v1db6d44e325a1
picomatch@4.0.3
4.0.4
1
fiware/idm:8.3.3a1b6ed4ae84f
picomatch@2.3.1
2.3.2
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
picomatch@2.2.2
2.3.2
1
fosrl/pangolin:1.13.0c32ad797ab96
picomatch@2.3.1
2.3.2
1
fthomas/scala-steward:latest367afe974b7a
picomatch@4.0.3
4.0.4
1
getferdi/ferdi-server:1.3.26e620b85afaa
picomatch@2.3.1
2.3.2
1
gethue/hue:latest7d5c1b9f8a79
picomatch@4.0.3
4.0.4
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
picomatch@4.0.3
4.0.4
1
globalping/globalping-probe:latest8acbd23009fd
picomatch@2.3.1
2.3.2
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
picomatch@2.2.3
2.3.2
1
gristlabs/grist:0.7.96e71b1914a7e
picomatch@2.2.2
2.3.2
1
hamid2021/nodejs-dockercli:latest429d99890c3c
picomatch@2.3.1
2.3.2
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
picomatch@2.3.1
2.3.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.