StackRadar

CVE-2026-33672

Medium

Advisory

Published 25 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
498
of 17,781 indexed, latest versions
Container images
508
deployed by those charts
Fix available
1 of 2
affected packages

Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

Carried by container images the latest versions of 498 of 17,781 indexed charts deploy, on 508 images.

Affected packageAffected versionsFixed inImages
picomatchnpm2.1.1, 2.2.1, 2.2.2, 2.2.3+5 more2.3.2, 4.0.4508
node-anymatchdeb3.1.3+~cs4.6.1-2no fix listed1
OSV records
GHSA-3v7f-55p6-f55pUBUNTU-CVE-2026-33672

Charts affected

498 by stars
ChartLatestAffected imagesRadar Score
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
picomatch@2.3.1
2.3.2

Open the chart page →

6,608
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
picomatch@4.0.2
4.0.4

Open the chart page →

4,016
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
picomatch@2.3.1
2.3.2

Open the chart page →

3,128
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
picomatch@2.3.1
2.3.2

Open the chart page →

2,116
myawesomeappmyawesomeapp1.1.01 of 1See more

myawesomeapp myawesomeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebapp:latestea5b71588a76
picomatch@2.3.1
2.3.2

Open the chart page →

1,267
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
picomatch@2.3.1
2.3.2

Open the chart page →

2,116
myawesomeappmyawesomeapp20.1.01 of 1See more

myawesomeapp myawesomeapp2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mpopoola1/nodejsapp:latest061fc532de7d
picomatch@2.3.1
2.3.2

Open the chart page →

1,118
myawesomeapp-feb24myawesomeapp-feb240.1.11 of 1See more

myawesomeapp-feb24 myawesomeapp-feb24 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
josepht05/nodejs-feb24:latest36cb0c618c94
picomatch@2.3.1
2.3.2

Open the chart page →

1,070
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
picomatch@2.3.1
2.3.2

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
picomatch@2.3.1
2.3.2

Open the chart page →

2,116
myawesomeappoctmyawesomeappoct0.1.11 of 1See more

myawesomeappoct myawesomeappoct 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
myawesomeappoctmyawesomeappoct20230.1.11 of 1See more

myawesomeappoct myawesomeappoct2023 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
hamid2021/nodejs-dockercli:latest429d99890c3c
picomatch@2.3.1
2.3.2

Open the chart page →

1,118
mydannyappmydannyapp1.1.01 of 1See more

mydannyapp mydannyapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
danny1dockerhub/nodejswebapp:lateste434683fcc89
picomatch@2.3.1
2.3.2

Open the chart page →

1,267
mygreatappmygreatapp0.1.01 of 1See more

mygreatapp mygreatapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ktitilayo2/nodejswebapp:latest8bac28058688
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
myhelmappmyhelm-app1.1.01 of 1See more

myhelmapp myhelm-app 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
patdada/bella-docker:v1.0.075127147a624
picomatch@2.3.1
2.3.2

Open the chart page →

1,625
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
picomatch@2.3.1
2.3.2

Open the chart page →

3,359
myhelmappmyhelmapp11.1.01 of 1See more

myhelmapp myhelmapp1 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
josepht05/titajo-docker:v1.0.0d94024965d78
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
myhelmappmyhelmpapp1.1.01 of 1See more

myhelmapp myhelmpapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
picomatch@2.3.1
2.3.2

Open the chart page →

1,235
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
picomatch@2.3.1
2.3.2

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
picomatch@2.3.1
2.3.2

Open the chart page →

3,269
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
picomatch@4.0.3
4.0.4

Open the chart page →

30,028
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
picomatch@4.0.3
4.0.4

Open the chart page →

1,166
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
picomatch@2.3.1
2.3.2

Open the chart page →

6,982
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
picomatch@4.0.3
4.0.4

Open the chart page →

7,310
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
picomatch@4.0.3
4.0.4

Open the chart page →

3,798
nodeapp-chartnodeapp-chart0.1.01 of 1See more

nodeapp-chart nodeapp-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
laly9999/node-app-dockerized:latest75ae77a20c6c
picomatch@2.3.1
2.3.2

Open the chart page →

1,118
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
picomatch@2.3.1
2.3.2

Open the chart page →

10,218
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
picomatch@2.3.1
2.3.2

Open the chart page →

2,919
nostreamnostream0.1.01 of 1See more

nostream nostream 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/cameri/nostream:main8726533b9e69
picomatch@4.0.3
4.0.4

Open the chart page →

595
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
picomatch@2.3.1
2.3.2

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
picomatch@2.3.1
2.3.2

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
picomatch@2.3.1
2.3.2

Open the chart page →

15,187
nottieawesomeappnottieawesomeapp0.1.01 of 1See more

nottieawesomeapp nottieawesomeapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nottiey/mynodejswebapp:latest9c35a24c9eb3
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
picomatch@2.2.2
2.3.2

Open the chart page →

27,465
ferdi-serverobeoneVerified publisher1.0.31 of 2See more

ferdi-server obeone 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
getferdi/ferdi-server:1.3.26e620b85afaa
picomatch@2.3.1
2.3.2

Open the chart page →

1,866
firecrawlobeoneVerified publisher3.0.11 of 5See more

firecrawl obeone 3.0.1

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/firecrawl:2.11.33092ee28c20a0d
picomatch@4.0.3
4.0.4

Open the chart page →

9,995
node-appoli-the-devVerified publisher1.0.01 of 1See more

node-app oli-the-dev 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
library/node:22-bookworm-slim83f487e0a634
picomatch@4.0.3
4.0.4

Open the chart page →

1,149
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
picomatch@2.3.1
2.3.2

Open the chart page →

4,219
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
picomatch@2.3.1
2.3.2

Open the chart page →

2,421
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
picomatch@2.3.1
2.3.2

Open the chart page →

2,370
dify-enterpriseopenshift3.9.82 of 13See more

dify-enterprise openshift 3.9.8

2 of the 13 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
picomatch@2.3.1
2.3.2
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
picomatch@2.3.1
2.3.2

Open the chart page →

4,660
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
picomatch@2.3.0
2.3.2

Open the chart page →

9,968
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
picomatch@2.3.1
2.3.2

Open the chart page →

838
ungatep2p-avs0.1.01 of 3See more

ungate p2p-avs 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
picomatch@2.3.1
2.3.2

Open the chart page →

27,373
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/michaelhaigh/pacman:latestb0931b1f085d
picomatch@4.0.3
4.0.4

Open the chart page →

3,562
pairdroppascaliskeVerified publisher2.0.01 of 1See more

pairdrop pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/pairdrop:version-v1.11.23279d2d986c0
picomatch@4.0.3
4.0.4

Open the chart page →

663
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
picomatch@2.3.1
2.3.2

Open the chart page →

6,524
pumperlypumperlyVerified publisher0.1.21 of 3See more

pumperly pumperly 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
drumsergio/pumperly:1.4.885bbc3915e9e
picomatch@4.0.3
4.0.4

Open the chart page →

2,854
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
picomatch@2.3.1
2.3.2

Open the chart page →

2,969
radar-self-enrolment-uiradar-baseVerified publisher0.4.21 of 1See more

radar-self-enrolment-ui radar-base 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
picomatch@4.0.2
4.0.4

Open the chart page →

1,506

Container images carrying it

508 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
helga09/shoes_ukr:v1.1.17999bc8b77c0
picomatch@2.3.1
2.3.2
1
heywood8/redisinsight:2.28.00bc9ab313d37
picomatch@2.3.1
2.3.2
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
picomatch@4.0.2
4.0.4
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
picomatch@2.3.1
2.3.2
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
picomatch@2.3.1
2.3.2
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
picomatch@2.3.1
2.3.2
1
ianw/quickchart:v1.7.1dc49dd460c37
picomatch@2.3.1
2.3.2
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
picomatch@2.3.1
2.3.2
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
picomatch@2.3.1
2.3.2
1
ilum/marquez-web:0.53.2716437a51a6c
picomatch@2.3.1
2.3.2
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
picomatch@2.3.0
2.3.2
1
jakowenko/double-take:1.6.0b858bac9e32a
picomatch@2.3.0
2.3.2
1
jayfong/yapi:1.10.2163e5d621910
picomatch@2.3.0
2.3.2
1
jesec/flood:4.14.3c887dad96b40
picomatch@4.0.3
4.0.4
1
jkroepke/github_exporter:1.8.03d850992786d
picomatch@4.0.3
4.0.4
1
johly/airtrail:v3.11.19f702b91e0e7
picomatch@4.0.3
4.0.4
1
joplin/server:latest3f7b852959aa
picomatch@4.0.2
4.0.4
1
joplin/server:3.0-beta52af57880c0e
picomatch@2.3.0
2.3.2
1
joplin/server:2.14.2-betab87564ef34e9
picomatch@2.3.0
2.3.2
1
josepht05/nodejs-feb24:latest36cb0c618c94
picomatch@2.3.1
2.3.2
1
josepht05/titajo-docker:v1.0.0d94024965d78
picomatch@2.3.1
2.3.2
1
junktext/getting-started:1.0.5a70936c04aed
picomatch@2.3.0
2.3.2
1
junktext/getting-started:1.0.34d44adf5a4da2
picomatch@2.3.0
2.3.2
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-anymatch@3.1.3+~cs4.6.1-2
picomatch@2.3.1
no fix listed
2.3.2
1
keyoxide/keyoxide:stable96f27a71269d
picomatch@2.3.1
2.3.2
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
picomatch@2.3.1
2.3.2
1
ktitilayo2/nodejswebapp:latest8bac28058688
picomatch@2.3.1
2.3.2
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
picomatch@2.3.1
2.3.2
1
kubebb/component-store:latestfd8ecbd73213
picomatch@2.3.1
2.3.2
1
kubevious/backend:1.2.22d9ba6eb46b6
picomatch@2.3.1
2.3.2
1
kubevious/collector:1.2.1f58226f9d84e
picomatch@2.3.1
2.3.2
1
kubevious/guard:1.2.19bf567704de2
picomatch@2.3.1
2.3.2
1
kubevious/parser:1.0.151acf1a1f0b47
picomatch@2.3.0
2.3.2
1
kubevious/parser:1.2.299ae7a5168c2
picomatch@2.3.1
2.3.2
1
kubevious/workload-operator:1.0.20b0f4c507eb6
picomatch@2.3.1
2.3.2
1
kyleslugg/klusterview:latestba8c36dfdfbd
picomatch@2.3.1
2.3.2
1
kyso/kyso-front:lateste52595c5c16f
picomatch@2.3.1
2.3.2
1
laly9999/node-app:1dd0e503913e1
picomatch@2.3.1
2.3.2
1
laly9999/node-app-dockerized:latest75ae77a20c6c
picomatch@2.3.1
2.3.2
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
picomatch@4.0.2
4.0.4
1
langgenius/dify-api:1.16.1dcefa5f7c47c
picomatch@4.0.2
4.0.4
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
picomatch@2.3.1
2.3.2
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
picomatch@2.3.1
2.3.2
1
langgenius/dify-web:1.16.187dd47e4e28f
picomatch@4.0.2
4.0.4
1
langgenius/dify-web:0.6.11a2a294743634
picomatch@2.3.1
2.3.2
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
picomatch@4.0.2
4.0.4
1
langgenius/dify-web:1.0.0d64914ff0d6d
picomatch@2.3.1
2.3.2
1
lavandadelpatio/frontend:latest501c3f31e0bc
picomatch@2.2.2
2.3.2
1
lbenicio/helm-pilot:0.2.54594a2632510
picomatch@4.0.3
4.0.4
1
lbenicio/stremio-web:latest732f9003de33
picomatch@4.0.3
4.0.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.