StackRadar

CVE-2026-33672

Medium

Advisory

Published 25 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
498
of 17,781 indexed, latest versions
Container images
508
deployed by those charts
Fix available
1 of 2
affected packages

Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

Carried by container images the latest versions of 498 of 17,781 indexed charts deploy, on 508 images.

Affected packageAffected versionsFixed inImages
picomatchnpm2.1.1, 2.2.1, 2.2.2, 2.2.3+5 more2.3.2, 4.0.4508
node-anymatchdeb3.1.3+~cs4.6.1-2no fix listed1
OSV records
GHSA-3v7f-55p6-f55pUBUNTU-CVE-2026-33672

Charts affected

498 by stars
ChartLatestAffected imagesRadar Score
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
picomatch@4.0.3
4.0.4

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
picomatch@4.0.3
4.0.4

Open the chart page →

68,240
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
langgenius/dify-web:1.0.0d64914ff0d6d
picomatch@2.3.1
2.3.2

Open the chart page →

19,224
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
picomatch@2.3.1
2.3.2

Open the chart page →

4,551
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-33672.

Open the chart page →

4,251
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
picomatch@2.1.1
2.3.2

Open the chart page →

11,174
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
picomatch@4.0.3
4.0.4

Open the chart page →

30,159
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
picomatch@2.3.0
2.3.2

Open the chart page →

3,744
azuriteemberstackVerified publisher1.0.211 of 1See more

azurite emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
picomatch@4.0.3
4.0.4

Open the chart page →

365
blobscanethereum-helm-chartsVerified publisher0.1.11 of 1See more

blobscan ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ethpandaops/blobscan:latest7a9ab6370657
picomatch@2.3.1
2.3.2

Open the chart page →

1,329
ethstatsethereum-helm-chartsVerified publisher0.1.41 of 1See more

ethstats ethereum-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
skylenet/ethstats-server:pow-latestd757cc016198
picomatch@2.3.1
2.3.2

Open the chart page →

1,109
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
picomatch@4.0.3
4.0.4

Open the chart page →

2,522
bee-localchainethersphereVerified publisher0.2.01 of 1See more

bee-localchain ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
picomatch@2.3.1
2.3.2

Open the chart page →

2,266
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
picomatch@2.3.0
2.3.2

Open the chart page →

3,260
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
picomatch@2.3.1
2.3.2

Open the chart page →

4,756
multichain-proxyethersphereVerified publisher0.1.01 of 1See more

multichain-proxy ethersphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ethersphere/multichain-proxy:0.0.261f5419afbcd
picomatch@2.3.1
2.3.2

Open the chart page →

795
onboarding-faucetethersphereVerified publisher0.2.01 of 1See more

onboarding-faucet ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ethersphere/onboarding-faucet:0.3.0513154aab230
picomatch@2.3.1
2.3.2

Open the chart page →

3,320
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.01 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/marcuwynu23/express-typescript-sample:latest9ef671b78ea8
picomatch@4.0.3
4.0.4

Open the chart page →

5,748
mandefactlyVerified publisher0.5.161 of 3See more

mande factly 0.5.16

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
factly/mande-web:0.34.1742355964b0e
picomatch@2.3.1
2.3.2

Open the chart page →

4,777
fickyhelmappfickyhelmapp1.1.01 of 1See more

fickyhelmapp fickyhelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
picomatch@2.3.1
2.3.2

Open the chart page →

3,311
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-user-service:1.049e164a9a439
picomatch@2.3.1
2.3.2

Open the chart page →

7,691
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
picomatch@4.0.3
4.0.4

Open the chart page →

1,847
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
picomatch@2.3.1
2.3.2

Open the chart page →

3,159
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
picomatch@4.0.3
4.0.4

Open the chart page →

1,489
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
picomatch@2.3.0
2.3.2

Open the chart page →

12,222
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
picomatch@2.2.2
2.3.2

Open the chart page →

10,994
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
picomatch@2.2.2
2.3.2

Open the chart page →

4,043
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
picomatch@2.3.0
2.3.2

Open the chart page →

4,591
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
picomatch@4.0.3
4.0.4

Open the chart page →

4,259
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
picomatch@2.3.1
2.3.2

Open the chart page →

34,754
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
picomatch@2.3.1
2.3.2

Open the chart page →

9,019
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
picomatch@2.3.1
2.3.2

Open the chart page →

2,973
Governify-Bluejaygovernify0.1.05 of 12See more

Governify-Bluejay governify 0.1.0

5 of the 12 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
picomatch@2.3.0
2.3.2
governify/director:v1.4.0608c6940bb98
picomatch@2.2.2
2.3.2
governify/registry:v3.4.0d3f37f4f8168
picomatch@2.2.2
2.3.2
governify/render:v2.2.0daeca1ce28e6
picomatch@2.2.2
2.3.2
governify/reporter:v2.2.038595913458f
picomatch@2.2.2
2.3.2

Open the chart page →

22,512
Governify-Falcongovernify0.1.06 of 10See more

Governify-Falcon governify 0.1.0

6 of the 10 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
picomatch@2.3.0
2.3.2
governify/collector-dynamic:v1.3.06d3d1a5b46a9
picomatch@2.2.3
2.3.2
governify/director:v1.4.0608c6940bb98
picomatch@2.2.2
2.3.2
governify/registry:v3.4.0d3f37f4f8168
picomatch@2.2.2
2.3.2
governify/render:v2.2.0daeca1ce28e6
picomatch@2.2.2
2.3.2
governify/reporter:v2.2.038595913458f
picomatch@2.2.2
2.3.2

Open the chart page →

24,319
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
picomatch@2.3.1
2.3.2

Open the chart page →

49,025
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
picomatch@2.3.1
2.3.2

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
picomatch@2.3.1
2.3.2

Open the chart page →

2,682
h2ph2pVerified publisher1.0.11 of 1See more

h2p h2p 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
dacinfomotion/h2p:latest68fa393b472c
picomatch@2.3.1
2.3.2

Open the chart page →

1,713
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
picomatch@2.3.1
2.3.2

Open the chart page →

2,950
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
picomatch@4.0.3
4.0.4

Open the chart page →

9,047
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
picomatch@2.2.2
2.3.2

Open the chart page →

8,213
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
picomatch@2.3.1
2.3.2

Open the chart page →

3,451
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
picomatch@4.0.3
4.0.4

Open the chart page →

778
affinehelmforgeVerified publisher1.0.01 of 3See more

affine helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
picomatch@4.0.3
4.0.4

Open the chart page →

4,018
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
picomatch@4.0.2
4.0.4

Open the chart page →

5,769
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
picomatch@4.0.3
4.0.4

Open the chart page →

739
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
picomatch@2.3.1
2.3.2

Open the chart page →

18,813
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
picomatch@4.0.1
4.0.4

Open the chart page →

1,271
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
library/ghost:6.62.0a7a268bbfb7f
picomatch@4.0.3
4.0.4

Open the chart page →

2,463
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
picomatch@4.0.3
4.0.4

Open the chart page →

11,042

Container images carrying it

508 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
picomatch@2.2.2
2.3.2
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
picomatch@2.3.1
2.3.2
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
picomatch@2.3.1
2.3.2
1
nocodb/nocodb:0.258.06779a4ddedf2
picomatch@2.3.1
2.3.2
1
nocodb/nocodb:0.301.5d9516f0bf546
picomatch@2.3.1
2.3.2
1
nodered/node-red:4.1.10-minimald73ae167cb9b
picomatch@4.0.3
4.0.4
1
nottiey/mynodejswebapp:latest9c35a24c9eb3
picomatch@2.3.1
2.3.2
1
oada/auth:4.0.0c0d077e79ef4
picomatch@4.0.2
4.0.4
1
oada/http-handler:4.0.0d87efe8ba4b0
picomatch@4.0.2
4.0.4
1
oada/rev-graph-update:4.0.0ebc8343f05ff
picomatch@4.0.2
4.0.4
1
oada/shares:4.0.0c6ffb4e8ed63
picomatch@4.0.2
4.0.4
1
oada/startup:4.0.0fc09495e2f3c
picomatch@4.0.2
4.0.4
1
oada/sync-handler:4.0.0b7a2cfc137cf
picomatch@4.0.2
4.0.4
1
oada/users:4.0.0b6c562fa5b1b
picomatch@4.0.2
4.0.4
1
oada/webhooks:4.0.06590c60de347
picomatch@4.0.2
4.0.4
1
oada/well-known:4.0.07943fde43b19
picomatch@4.0.2
4.0.4
1
oada/write-handler:4.0.08464c7f48aae
picomatch@4.0.2
4.0.4
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
picomatch@4.0.2
4.0.4
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
picomatch@2.3.1
2.3.2
1
okaforuchena/uo-docker:V1.0.0004e81250f48
picomatch@2.3.1
2.3.2
1
ondrejsika/parking:latestb1fd497416c8
picomatch@2.1.1
2.3.2
1
ooghenekaro/amazon:latest03394ba1d6d8
picomatch@2.3.1
2.3.2
1
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
picomatch@2.3.1
2.3.2
1
ooghenekaro/nodejswebapp:latestea5b71588a76
picomatch@2.3.1
2.3.2
1
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
picomatch@2.3.1
2.3.2
1
opea/codegen-ui:1.02bee4eb66f3e
picomatch@2.3.1
2.3.2
1
opea/codetrans-ui:1.03ef121f34610
picomatch@2.3.1
2.3.2
1
opea/docsum-ui:1.07f854e9bffaf
picomatch@2.3.1
2.3.2
1
openbas/caldera-server:5.1.0a277796d9724
picomatch@2.3.1
2.3.2
1
opencti/platform:7.260910.0186fc757c3eb
picomatch@4.0.3
4.0.4
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
picomatch@2.3.1
2.3.2
1
openmined/syft-frontend:0.9.5d11524a3854a
picomatch@2.3.1
2.3.2
1
openproject/hocuspocus:release-338001b288dc1359dfb5
picomatch@4.0.2
4.0.4
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
picomatch@2.3.1
2.3.2
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
picomatch@2.3.1
2.3.2
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
picomatch@2.3.1
2.3.2
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
picomatch@2.3.1
2.3.2
1
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
picomatch@2.3.1
2.3.2
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
picomatch@2.3.1
2.3.2
1
otwld/velero-ui:0.10.2d1954b759e47
picomatch@4.0.3
4.0.4
1
outlinewiki/outline:0.82.0494dfb9249a6
picomatch@4.0.2
4.0.4
1
patdada/bella-docker:v1.0.075127147a624
picomatch@2.3.1
2.3.2
1
phntom/codimd:2.4.31b9aafbb62e6
picomatch@2.3.1
2.3.2
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
picomatch@2.3.1
2.3.2
1
polonel/trudesk:1.2.60cf6513f6fe3
picomatch@2.3.0
2.3.2
1
pretix/standalone:2026.7.05df3b7aa852e
picomatch@4.0.3
4.0.4
1
prowlercloud/prowler-ui:5.31.179ee83c8e702
picomatch@4.0.3
4.0.4
1
pumejlab/nodejs-webapp:latestf563eabcb819
picomatch@2.3.1
2.3.2
1
pysga1996/python-redis-web:latestfdeec30ad482
picomatch@2.2.2
2.3.2
1
qxip/qryn:3.2.3977acc9c7a9fd
picomatch@2.3.1
2.3.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.