StackRadar

CVE-2026-33672

Medium

Advisory

Published 25 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
493
of 17,787 indexed, latest versions
Container images
503
deployed by those charts
Fix available
1 of 2
affected packages

Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

Carried by container images the latest versions of 493 of 17,787 indexed charts deploy, on 503 images.

Affected packageAffected versionsFixed inImages
picomatchnpm2.1.1, 2.2.1, 2.2.2, 2.2.3+5 more2.3.2, 4.0.4503
node-anymatchdeb3.1.3+~cs4.6.1-2no fix listed1
OSV records
GHSA-3v7f-55p6-f55pUBUNTU-CVE-2026-33672

Charts affected

493 by stars
ChartLatestAffected imagesRadar Score
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
picomatch@2.3.1
2.3.2

Open the chart page →

2,116
myawesomeappmyawesomeapp1.1.01 of 1See more

myawesomeapp myawesomeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebapp:latestea5b71588a76
picomatch@2.3.1
2.3.2

Open the chart page →

1,267
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
picomatch@2.3.1
2.3.2

Open the chart page →

2,116
myawesomeappmyawesomeapp20.1.01 of 1See more

myawesomeapp myawesomeapp2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mpopoola1/nodejsapp:latest061fc532de7d
picomatch@2.3.1
2.3.2

Open the chart page →

1,118
myawesomeapp-feb24myawesomeapp-feb240.1.11 of 1See more

myawesomeapp-feb24 myawesomeapp-feb24 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
josepht05/nodejs-feb24:latest36cb0c618c94
picomatch@2.3.1
2.3.2

Open the chart page →

1,070
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
picomatch@2.3.1
2.3.2

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
picomatch@2.3.1
2.3.2

Open the chart page →

2,116
myawesomeappoctmyawesomeappoct0.1.11 of 1See more

myawesomeappoct myawesomeappoct 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
myawesomeappoctmyawesomeappoct20230.1.11 of 1See more

myawesomeappoct myawesomeappoct2023 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
hamid2021/nodejs-dockercli:latest429d99890c3c
picomatch@2.3.1
2.3.2

Open the chart page →

1,118
mydannyappmydannyapp1.1.01 of 1See more

mydannyapp mydannyapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
danny1dockerhub/nodejswebapp:lateste434683fcc89
picomatch@2.3.1
2.3.2

Open the chart page →

1,267
mygreatappmygreatapp0.1.01 of 1See more

mygreatapp mygreatapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ktitilayo2/nodejswebapp:latest8bac28058688
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
myhelmappmyhelm-app1.1.01 of 1See more

myhelmapp myhelm-app 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
patdada/bella-docker:v1.0.075127147a624
picomatch@2.3.1
2.3.2

Open the chart page →

1,625
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
picomatch@2.3.1
2.3.2

Open the chart page →

3,359
myhelmappmyhelmapp11.1.01 of 1See more

myhelmapp myhelmapp1 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
josepht05/titajo-docker:v1.0.0d94024965d78
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
myhelmappmyhelmpapp1.1.01 of 1See more

myhelmapp myhelmpapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
picomatch@2.3.1
2.3.2

Open the chart page →

1,235
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
picomatch@2.3.1
2.3.2

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
picomatch@2.3.1
2.3.2

Open the chart page →

3,269
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
picomatch@4.0.3
4.0.4

Open the chart page →

30,028
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
picomatch@4.0.3
4.0.4

Open the chart page →

1,166
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
picomatch@2.3.1
2.3.2

Open the chart page →

6,982
neurofaceneurofaceVerified publisher1.4.21 of 3See more

neuroface neuroface 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
picomatch@4.0.3
4.0.4

Open the chart page →

7,310
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
picomatch@4.0.3
4.0.4

Open the chart page →

3,798
nodeapp-chartnodeapp-chart0.1.01 of 1See more

nodeapp-chart nodeapp-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
laly9999/node-app-dockerized:latest75ae77a20c6c
picomatch@2.3.1
2.3.2

Open the chart page →

1,118
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
picomatch@2.3.1
2.3.2

Open the chart page →

10,218
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
picomatch@2.3.1
2.3.2

Open the chart page →

2,919
nostreamnostream0.1.01 of 1See more

nostream nostream 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/cameri/nostream:main8726533b9e69
picomatch@4.0.3
4.0.4

Open the chart page →

595
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
picomatch@2.3.1
2.3.2

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
picomatch@2.3.1
2.3.2

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
picomatch@2.3.1
2.3.2

Open the chart page →

15,187
nottieawesomeappnottieawesomeapp0.1.01 of 1See more

nottieawesomeapp nottieawesomeapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nottiey/mynodejswebapp:latest9c35a24c9eb3
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
picomatch@2.2.2
2.3.2

Open the chart page →

27,465
node-appoli-the-devVerified publisher1.0.01 of 1See more

node-app oli-the-dev 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
library/node:22-bookworm-slim83f487e0a634
picomatch@4.0.3
4.0.4

Open the chart page →

1,149
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
picomatch@2.3.1
2.3.2

Open the chart page →

4,219
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
picomatch@2.3.1
2.3.2

Open the chart page →

2,421
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
picomatch@2.3.1
2.3.2

Open the chart page →

2,370
dify-enterpriseopenshift3.9.82 of 13See more

dify-enterprise openshift 3.9.8

2 of the 13 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
picomatch@2.3.1
2.3.2
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
picomatch@2.3.1
2.3.2

Open the chart page →

4,660
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
picomatch@2.3.0
2.3.2

Open the chart page →

9,968
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
picomatch@2.3.1
2.3.2

Open the chart page →

838
ungatep2p-avs0.1.01 of 3See more

ungate p2p-avs 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
picomatch@2.3.1
2.3.2

Open the chart page →

27,373
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/michaelhaigh/pacman:latestb0931b1f085d
picomatch@4.0.3
4.0.4

Open the chart page →

3,562
pairdroppascaliskeVerified publisher2.0.01 of 1See more

pairdrop pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/pairdrop:version-v1.11.23279d2d986c0
picomatch@4.0.3
4.0.4

Open the chart page →

663
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
picomatch@2.3.1
2.3.2

Open the chart page →

6,524
pumperlypumperlyVerified publisher0.1.21 of 3See more

pumperly pumperly 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
drumsergio/pumperly:1.4.885bbc3915e9e
picomatch@4.0.3
4.0.4

Open the chart page →

2,854
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
picomatch@2.3.1
2.3.2

Open the chart page →

2,969
radar-self-enrolment-uiradar-baseVerified publisher0.4.21 of 1See more

radar-self-enrolment-ui radar-base 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
picomatch@4.0.2
4.0.4

Open the chart page →

1,506
rancher-auto-registerrancher-auto-registerVerified publisher0.1.01 of 1See more

rancher-auto-register rancher-auto-register 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
picomatch@4.0.3
4.0.4

Open the chart page →

1,837
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
picomatch@2.3.1
2.3.2

Open the chart page →

1,858
recipe-apprecipe-app0.1.02 of 2See more

recipe-app recipe-app 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
picomatch@2.3.1
2.3.2
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
picomatch@2.3.1
2.3.2

Open the chart page →

3,271
helm-redchefredchef0.1.01 of 3See more

helm-redchef redchef 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
sharanalwar/redchef-frontend:latest5e82950b16b7
picomatch@2.3.1
2.3.2

Open the chart page →

4,763
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
picomatch@2.3.0
2.3.2

Open the chart page →

29,227

Container images carrying it

503 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
redis/redisinsight:3.485562d67a912
picomatch@4.0.2
4.0.4
1
requarks/wiki:canary-2.5.2438b5865a7386c
picomatch@2.3.0
2.3.2
1
roadiehq/community-backstage-image:latestef355bf5b639
picomatch@2.2.2
2.3.2
1
rocketadmin/rocketadmin:1.17.710955ef540b9
picomatch@4.0.3
4.0.4
1
rocketchat/account-service:8.6.144af8ac4e711
picomatch@4.0.3
4.0.4
1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
picomatch@4.0.3
4.0.4
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
picomatch@4.0.3
4.0.4
1
rocketchat/presence-service:8.6.1c1170bdfe797
picomatch@4.0.3
4.0.4
1
safeglobal/safe-client-gateway-nest:v1.51.012ccfd93fcaf
picomatch@4.0.1
4.0.4
1
samajh/alprbackend:latestea742b4372ad
picomatch@2.3.1
2.3.2
1
samajh/alprfrontend:latest05ef4fddbb75
picomatch@2.3.1
2.3.2
1
shahanafarooqui/rtl:0.11.0d0cd3d868aca
picomatch@2.3.0
2.3.2
1
sharanalwar/redchef-frontend:latest5e82950b16b7
picomatch@2.3.1
2.3.2
1
shieldsio/shields:nextfa194b446e42
picomatch@4.0.3
4.0.4
1
shinobisystems/shinobi:dev3ca746937856
picomatch@2.3.0
2.3.2
1
shinobisystems/shinobi:latestc2f5ce2e1067
picomatch@2.3.0
2.3.2
1
shyamkrishna21/cloudvault:latestaf2785f5bb71
picomatch@4.0.2
4.0.4
1
sigp/siren:v3.0.42c219b04758e
picomatch@2.3.1
2.3.2
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
picomatch@2.3.0
2.3.2
1
skylenet/ethstats-server:pow-latestd757cc016198
picomatch@2.3.1
2.3.2
1
solidproject/community-server:6.0.2ccc4acb7e9a1
picomatch@2.3.1
2.3.2
1
soulteary/cronicle:0.9.80ac2512fa6e39
picomatch@4.0.1
4.0.4
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
picomatch@2.3.1
2.3.2
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
picomatch@2.3.1
2.3.2
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
picomatch@2.3.1
2.3.2
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
picomatch@2.3.1
2.3.2
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
picomatch@2.3.1
2.3.2
1
speckle/speckle-server:2.26.379f14a2bf931
picomatch@2.3.1
2.3.2
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
picomatch@2.3.1
2.3.2
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
picomatch@2.3.1
2.3.2
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
picomatch@2.3.1
2.3.2
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
picomatch@2.3.1
2.3.2
1
srini78/nodejswebappeks:latest5d1cbdc6833a
picomatch@2.3.1
2.3.2
1
stakater/workshop-exercise:0.0.26076926b7159d3
picomatch@2.3.1
2.3.2
1
stanfordoval/almond-server:latest1a63cdccedaf
picomatch@2.3.0
2.3.2
1
supabase/storage-api:v1.60.4c8eb9858eafe
picomatch@4.0.3
4.0.4
1
supabase/storage-api:latestf6c42a04163d
picomatch@4.0.3
4.0.4
1
supabase/studio:20241021-9f9b08326d8070c55e9
picomatch@2.3.1
2.3.2
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
picomatch@4.0.3
4.0.4
1
supabase/studio:latest94a2a9d2906e
picomatch@4.0.3
4.0.4
1
sysnet4admin/colosseum-cms:loge74b43c7f492
picomatch@2.3.1
2.3.2
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
picomatch@2.3.1
2.3.2
1
taigaio/taiga-events:6.4.00bf2d24a57d9
picomatch@2.3.0
2.3.2
1
temporalio/web:1.14.033cfa863d8ce
picomatch@2.2.2
2.3.2
1
tensorzero/ui:2026.6.0f2563d54724e
picomatch@4.0.3
4.0.4
1
thecloudspark/app-result:1.09a5302cb8312
picomatch@2.3.1
2.3.2
1
thecodingmachine/workadventure-back:v1.17.764001369dad5
picomatch@2.3.1
2.3.2
1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
picomatch@2.3.1
2.3.2
1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
picomatch@2.3.1
2.3.2
1
thmmniii/fbs-collab:v1.27.15d389e3c5ce6
picomatch@2.3.1
2.3.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.