StackRadar

CVE-2026-33672

Medium

Advisory

Published 25 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
493
of 17,787 indexed, latest versions
Container images
503
deployed by those charts
Fix available
1 of 2
affected packages

Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

Carried by container images the latest versions of 493 of 17,787 indexed charts deploy, on 503 images.

Affected packageAffected versionsFixed inImages
picomatchnpm2.1.1, 2.2.1, 2.2.2, 2.2.3+5 more2.3.2, 4.0.4503
node-anymatchdeb3.1.3+~cs4.6.1-2no fix listed1
OSV records
GHSA-3v7f-55p6-f55pUBUNTU-CVE-2026-33672

Charts affected

493 by stars
ChartLatestAffected imagesRadar Score
landing-pagelanding-pageVerified publisher0.1.01 of 1See more

landing-page landing-page 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
felipecs8/landing-page:v1db6d44e325a1
picomatch@4.0.3
4.0.4

Open the chart page →

1,119
helm-pilotlbenicio-communityVerified publisher0.2.41 of 1See more

helm-pilot lbenicio-community 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
lbenicio/helm-pilot:0.2.54594a2632510
picomatch@4.0.3
4.0.4

Open the chart page →

710
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
picomatch@4.0.2
4.0.4

Open the chart page →

3,555
stremiolbenicio-communityVerified publisher0.1.11 of 2See more

stremio lbenicio-community 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
lbenicio/stremio-web:latest732f9003de33
picomatch@4.0.3
4.0.4

Open the chart page →

2,600
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
picomatch@4.0.3
4.0.4

Open the chart page →

33,242
lgtv2mqttleprechaun-charts0.1.11 of 1See more

lgtv2mqtt leprechaun-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/leprechaun/lgtv2mqtt:latestac2e11c41ffb
picomatch@2.3.1
2.3.2

Open the chart page →

1,062
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
picomatch@4.0.3
4.0.4

Open the chart page →

1,809
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
picomatch@4.0.3
4.0.4

Open the chart page →

33,242
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
picomatch@4.0.2
4.0.4

Open the chart page →

1,490
squareonelsst-sqre0.4.11 of 1See more

squareone lsst-sqre 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
lsstsqre/squareone:0.4.09ded78e7fe03
picomatch@2.3.0
2.3.2

Open the chart page →

2,247
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
picomatch@2.2.2
2.3.2

Open the chart page →

3,651
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
picomatch@2.3.1
2.3.2

Open the chart page →

9,774
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
picomatch@4.0.2
4.0.4

Open the chart page →

10,897
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
picomatch@2.3.1
2.3.2

Open the chart page →

7,315
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
picomatch@2.3.0
2.3.2

Open the chart page →

5,287
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
picomatch@2.3.1
2.3.2

Open the chart page →

8,303
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
picomatch@2.2.3
2.3.2

Open the chart page →

5,940
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
picomatch@2.3.1
2.3.2

Open the chart page →

9,668
miot-appmicroboxlabs0.3.31 of 1See more

miot-app microboxlabs 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
picomatch@4.0.3
4.0.4

Open the chart page →

509
miot-docsmicroboxlabs0.1.11 of 1See more

miot-docs microboxlabs 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-docs:lateste09d92c61f43
picomatch@4.0.3
4.0.4

Open the chart page →

378
miot-stackmicroboxlabs0.2.21 of 2See more

miot-stack microboxlabs 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
picomatch@4.0.3
4.0.4

Open the chart page →

509
modulariotmicroboxlabs0.9.02 of 4See more

modulariot microboxlabs 0.9.0

2 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
picomatch@4.0.3
4.0.4
ghcr.io/microboxlabs/miot-docs:latest0307d2fd9f5c
picomatch@4.0.3
4.0.4

Open the chart page →

2,256
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
picomatch@2.3.1
2.3.2

Open the chart page →

43,341
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
picomatch@2.2.2
2.3.2

Open the chart page →

10,603
standard-application-stackmintel11.4.11See more

standard-application-stack mintel 11.4.1

1 container image this version deploys carries CVE-2026-33672.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
picomatch@2.2.2
2.3.2

Open the chart page →

account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
picomatch@2.3.0
2.3.2

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
picomatch@2.3.0
2.3.2

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
picomatch@2.2.3
2.3.2

Open the chart page →

12,108
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
picomatch@2.3.1
2.3.2

Open the chart page →

2,457
finance-portalmojaloop5.1.44 of 11See more

finance-portal mojaloop 5.1.4

4 of the 11 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
picomatch@4.0.2
4.0.4
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
picomatch@2.3.1
2.3.2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
picomatch@2.3.1
2.3.2
mojaloop/role-assignment-service:v2.1.0def4bf273721
picomatch@2.3.1
2.3.2

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
picomatch@2.2.2
2.3.2

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
picomatch@2.3.0
2.3.2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
picomatch@2.2.3
2.3.2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
picomatch@2.2.2
2.3.2

Open the chart page →

19,226
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
picomatch@4.0.2
4.0.4

Open the chart page →

2,631
reporting-hub-bop-api-svcmojaloop4.1.31 of 1See more

reporting-hub-bop-api-svc mojaloop 4.1.3

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
picomatch@2.3.1
2.3.2

Open the chart page →

1,661
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
picomatch@2.3.1
2.3.2

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
picomatch@2.3.1
2.3.2

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
picomatch@2.3.1
2.3.2

Open the chart page →

2,457
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
picomatch@2.2.2
2.3.2

Open the chart page →

6,438
api-proxymoreillonVerified publisher0.1.41 of 1See more

api-proxy moreillon 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
moreillon/api-proxy:2373c1953739ef6956b5
picomatch@2.3.1
2.3.2

Open the chart page →

1,712
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
moreillon/camera-proxy:latestce60056b50c2
picomatch@2.3.1
2.3.2

Open the chart page →

11,643
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
picomatch@2.3.1
2.3.2

Open the chart page →

8,556
group-managermoreillonVerified publisher0.4.41 of 3See more

group-manager moreillon 0.4.4

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
moreillon/group-manager:v4.9.0d5a0ec8394c0
picomatch@2.3.1
2.3.2

Open the chart page →

9,835
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
picomatch@2.3.1
2.3.2

Open the chart page →

25,704
user-manager-neo4jmoreillonVerified publisher0.9.72 of 6See more

user-manager-neo4j moreillon 0.9.7

2 of the 6 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
moreillon/group-manager:v4.9.0d5a0ec8394c0
picomatch@2.3.1
2.3.2
moreillon/user-manager:v5.0.2e1c9bfab5c16
picomatch@2.3.1
2.3.2

Open the chart page →

30,363
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
picomatch@2.2.2
2.3.2

Open the chart page →

6,684
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
picomatch@2.3.1
2.3.2

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
picomatch@4.0.3
4.0.4

Open the chart page →

4,960
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
picomatch@2.3.1
2.3.2

Open the chart page →

6,608
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
picomatch@4.0.2
4.0.4

Open the chart page →

4,016
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
picomatch@2.3.1
2.3.2

Open the chart page →

3,128

Container images carrying it

503 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
picomatch@2.3.1
2.3.2
1
tobirachel/node-project3:v17d9f37154994
picomatch@2.3.1
2.3.2
1
treskon/portrait-ui:DEV-lateste7970783bc8d
picomatch@2.3.1
2.3.2
1
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
picomatch@2.3.1
2.3.2
1
tzahi12345/youtubedl-material:4.23720b856bd2f
picomatch@2.2.2
2.3.2
1
ubercadence/web:v3.29.58564a5b44a6d
picomatch@2.2.2
2.3.2
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
picomatch@2.3.1
2.3.2
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
picomatch@4.0.3
4.0.4
1
vabene1111/recipes:2.3.50f8d061895e9
picomatch@4.0.2
4.0.4
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
picomatch@2.3.0
2.3.2
1
vcnngr/pnbackend:latesteaf44ad0ad1f
picomatch@2.3.1
2.3.2
1
veecode/devportalc443520aebf7
picomatch@2.3.1
2.3.2
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
picomatch@2.3.1
2.3.2
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
picomatch@2.3.1
2.3.2
1
vlebediantsev/notes-admin-front:latest007c6670ff48
picomatch@2.3.1
2.3.2
1
vlebediantsev/notes-project-front:latest945675fd2636
picomatch@2.3.1
2.3.2
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
picomatch@2.3.1
2.3.2
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
picomatch@2.3.1
2.3.2
1
wazuh/wazuh-dashboard:4.4.11787550d2358
picomatch@2.3.1
2.3.2
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
picomatch@2.3.1
2.3.2
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
picomatch@2.3.1
2.3.2
1
wettyoss/wetty:latest7423b3d40ba2
picomatch@4.0.3
4.0.4
1
winfred008/amazon:910a68de5b398
picomatch@2.3.1
2.3.2
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
picomatch@2.3.1
2.3.2
1
ymuski/skooner:latest67819ca511b5
picomatch@2.2.3
2.3.2
1
yooooomi/your_spotify_client:1.20.0e4da90a0634c
picomatch@4.0.3
4.0.4
1
yooooomi/your_spotify_server:1.20.0624ea009f2ef
picomatch@4.0.3
4.0.4
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
picomatch@4.0.2
4.0.4
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
picomatch@4.0.2
4.0.4
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
picomatch@2.3.1
2.3.2
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
picomatch@4.0.2
4.0.4
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
picomatch@2.2.3
2.3.2
1
zwavejs/zwave-js-ui:11.22.314d018bb689e
picomatch@4.0.2
4.0.4
1
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
picomatch@2.3.1
2.3.2
1
ghcr.io/aolde/lametric-nightscout-proxy:latest7d1951b6baf5
picomatch@2.3.1
2.3.2
1
ghcr.io/appscode/platform-ui:2.4.0668ee2682eaf
picomatch@4.0.3
4.0.4
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
picomatch@4.0.3
4.0.4
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
picomatch@2.3.1
2.3.2
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
picomatch@4.0.3
4.0.4
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
picomatch@2.3.1
2.3.2
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
picomatch@4.0.3
4.0.4
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
picomatch@4.0.2
4.0.4
1
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
picomatch@2.3.1
2.3.2
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
picomatch@2.3.1
2.3.2
1
ghcr.io/calesthio/crucix:latest67c5244b6acf
picomatch@4.0.3
4.0.4
1
ghcr.io/cameri/nostream:main8726533b9e69
picomatch@4.0.3
4.0.4
1
ghcr.io/caninehq/canine:latesta058034ca006
picomatch@2.3.1
2.3.2
1
ghcr.io/colanode/server:latest7006cac874fd
picomatch@4.0.3
4.0.4
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
picomatch@2.3.1
2.3.2
1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
picomatch@4.0.3
4.0.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.