StackRadar

CVE-2026-33672

Medium

Advisory

Published 25 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
498
of 17,781 indexed, latest versions
Container images
508
deployed by those charts
Fix available
1 of 2
affected packages

Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching

Carried by container images the latest versions of 498 of 17,781 indexed charts deploy, on 508 images.

Affected packageAffected versionsFixed inImages
picomatchnpm2.1.1, 2.2.1, 2.2.2, 2.2.3+5 more2.3.2, 4.0.4508
node-anymatchdeb3.1.3+~cs4.6.1-2no fix listed1
OSV records
GHSA-3v7f-55p6-f55pUBUNTU-CVE-2026-33672

Charts affected

498 by stars
ChartLatestAffected imagesRadar Score
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
picomatch@2.3.1
2.3.2

Open the chart page →

3,143
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
langgenius/dify-web:0.6.11a2a294743634
picomatch@2.3.1
2.3.2

Open the chart page →

20,403
kube-ingress-dash-chartkube-ingress-dashVerified publisher0.3.11 of 1See more

kube-ingress-dash-chart kube-ingress-dash 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
picomatch@4.0.3
4.0.4

Open the chart page →

1,505
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
picomatch@2.3.1
2.3.2

Open the chart page →

5,654
litellmlitellm-helm0.2.01 of 1See more

litellm litellm-helm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
picomatch@4.0.3
4.0.4

Open the chart page →

4,292
litlyxlitlyx0.2.03 of 5See more

litlyx litlyx 0.2.0

3 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
litlyx/litlyx-consumer:latest02225e77d316
picomatch@4.0.3
4.0.4
litlyx/litlyx-dashboard:lateste64ff2d52385
picomatch@4.0.2
4.0.4
litlyx/litlyx-producer:latest10407f36613f
picomatch@4.0.2
4.0.4

Open the chart page →

7,874
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
picomatch@2.2.3
2.3.2

Open the chart page →

5,940
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
picomatch@2.3.1
2.3.2

Open the chart page →

13,738
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
picomatch@4.0.3
4.0.4

Open the chart page →

2,575
oadaoadaVerified publisher5.0.510 of 11See more

oada oada 5.0.5

10 of the 11 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
oada/auth:4.0.0c0d077e79ef4
picomatch@4.0.2
4.0.4
oada/http-handler:4.0.0d87efe8ba4b0
picomatch@4.0.2
4.0.4
oada/rev-graph-update:4.0.0ebc8343f05ff
picomatch@4.0.2
4.0.4
oada/shares:4.0.0c6ffb4e8ed63
picomatch@4.0.2
4.0.4
oada/startup:4.0.0fc09495e2f3c
picomatch@4.0.2
4.0.4
oada/sync-handler:4.0.0b7a2cfc137cf
picomatch@4.0.2
4.0.4
oada/users:4.0.0b6c562fa5b1b
picomatch@4.0.2
4.0.4
oada/webhooks:4.0.06590c60de347
picomatch@4.0.2
4.0.4
oada/well-known:4.0.07943fde43b19
picomatch@4.0.2
4.0.4
oada/write-handler:4.0.08464c7f48aae
picomatch@4.0.2
4.0.4

Open the chart page →

13,317
kuttone-acre-fundVerified publisher0.2.51 of 1See more

kutt one-acre-fund 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
kutt/kutt:latestfa3d24a89b04
picomatch@4.0.3
4.0.4

Open the chart page →

454
open5gs-webuiopen5gs-webuiVerified publisher2.3.11 of 2See more

open5gs-webui open5gs-webui 2.3.1

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
picomatch@2.3.1
2.3.2

Open the chart page →

5,300
openccuopenccuVerified publisher3.89.81 of 1See more

openccu openccu 3.89.8

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/openccu/openccu:3.89.8.20260719b2de2ff6e8e0
picomatch@4.0.2
4.0.4

Open the chart page →

1,916
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
picomatch@4.0.2
4.0.4

Open the chart page →

6,873
pdf-editor-helmpdf-editor-web1.0.01 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
picomatch@2.3.1
2.3.2

Open the chart page →

4,206
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
picomatch@2.3.1
2.3.2
treskon/portrait-ui:DEV-lateste7970783bc8d
picomatch@2.3.1
2.3.2

Open the chart page →

31,844
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
prowlercloud/prowler-ui:5.31.179ee83c8e702
picomatch@4.0.3
4.0.4

Open the chart page →

8,158
psa-restricted-patcherpsa-restricted-patcherVerified publisher0.10.11 of 1See more

psa-restricted-patcher psa-restricted-patcher 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
picomatch@4.0.2
4.0.4

Open the chart page →

1,401
pumejwebapppumejnodejswebapp0.1.01 of 1See more

pumejwebapp pumejnodejswebapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
pumejlab/nodejs-webapp:latestf563eabcb819
picomatch@2.3.1
2.3.2

Open the chart page →

1,164
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
picomatch@4.0.3
4.0.4

Open the chart page →

5,482
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
picomatch@2.2.2
2.3.2

Open the chart page →

6,879
jellyseerrrtomik-helm-chartsVerified publisher0.0.11 of 1See more

jellyseerr rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
picomatch@2.3.1
2.3.2

Open the chart page →

2,823
karakeepself-hosters-by-nightVerified publisher2.5.11 of 1See more

karakeep self-hosters-by-night 2.5.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
picomatch@4.0.2
4.0.4

Open the chart page →

5,213
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
speckle/speckle-server:2.26.379f14a2bf931
picomatch@2.3.1
2.3.2

Open the chart page →

10,380
stackradar-scannerstackradarVerified publisher0.3.01 of 1See more

stackradar-scanner stackradar 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/lockdep/stackradar-scanner:0.3.0dd8a35d50c2d
picomatch@4.0.3
4.0.4

Open the chart page →

1,209
stornxstornxVerified publisher1.1.11 of 9See more

stornx stornx 1.1.1

1 of the 9 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
picomatch@4.0.3
4.0.4

Open the chart page →

11,574
ackeesudaVerified publisher0.2.11 of 1See more

ackee suda 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
electerious/ackee:3.2.05e7173fa321c
picomatch@2.3.0
2.3.2

Open the chart page →

1,602
supabasesupabse0.8.02 of 11See more

supabase supabse 0.8.0

2 of the 11 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
supabase/storage-api:v1.60.4c8eb9858eafe
picomatch@4.0.3
4.0.4
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
picomatch@4.0.3
4.0.4

Open the chart page →

18,075
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
picomatch@2.3.1
2.3.2

Open the chart page →

12,581
taigaunxwaresVerified publisher2026.3.81 of 6See more

taiga unxwares 2026.3.8

1 of the 6 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
taigaio/taiga-events:latest92fc0822564f
picomatch@2.3.0
2.3.2

Open the chart page →

9,148
wachdwachdVerified publisher0.4.371 of 1See more

wachd wachd 0.4.37

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/wachd/wachd:0.4.1805b05c56da94
picomatch@4.0.3
4.0.4

Open the chart page →

1,269
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
picomatch@4.0.3
4.0.4

Open the chart page →

3,833
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
picomatch@2.3.0
2.3.2

Open the chart page →

9,783
qleverzazukoVerified publisher0.7.01 of 2See more

qlever zazuko 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
picomatch@4.0.2
4.0.4

Open the chart page →

2,900
adeptia-automate-mcpadeptia-automate-mcp1.0.02 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
picomatch@4.0.2
4.0.4
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
picomatch@2.3.1
2.3.2

Open the chart page →

3,600
activepiecesadnoctemVerified publisher0.5.01 of 1See more

activepieces adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
activepieces/activepieces:0.90.430c10a04fe3d
picomatch@4.0.3
4.0.4

Open the chart page →

1,055
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
picomatch@4.0.3
4.0.4

Open the chart page →

3,820
uptime-kumaadnoctemVerified publisher0.4.11 of 1See more

uptime-kuma adnoctem 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
picomatch@4.0.3
4.0.4

Open the chart page →

30,028
turborepo-remote-cacheadriantr1.1.11 of 1See more

turborepo-remote-cache adriantr 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ducktors/turborepo-remote-cache:latest31ec9e83c844
picomatch@4.0.3
4.0.4

Open the chart page →

523
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
picomatch@4.0.3
4.0.4

Open the chart page →

6,486
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
picomatch@2.3.1
2.3.2

Open the chart page →

4,880
homepagealareira1.0.11 of 1See more

homepage alareira 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:latest753eeb0cc22a
picomatch@4.0.3
4.0.4

Open the chart page →

352
katalogalpineworks0.1.21 of 5See more

katalog alpineworks 0.1.2

1 of the 5 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
picomatch@2.3.1
2.3.2

Open the chart page →

4,497
openhab-cloudandibraeuVerified publisher1.2.61 of 1See more

openhab-cloud andibraeu 1.2.6

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
openhab/openhab-cloud:a8138a329dd2bac8c4b
picomatch@2.3.1
2.3.2

Open the chart page →

3,437
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
picomatch@2.3.1
2.3.2

Open the chart page →

3,237
angular-node-chartangular-webapp2.0.01 of 1See more

angular-node-chart angular-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
rakii8585/angular-node-webapp:latest026082a515ac
picomatch@2.3.1
2.3.2

Open the chart page →

2,616
lametric-nightscout-proxyaolde0.1.01 of 1See more

lametric-nightscout-proxy aolde 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/aolde/lametric-nightscout-proxy:latest7d1951b6baf5
picomatch@2.3.1
2.3.2

Open the chart page →

1,186
apimap-developerapimapOfficialVerified publisher1.4.11 of 1See more

apimap-developer apimap 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
apimap/developer:v1.3.1406d3858e20c
picomatch@2.3.1
2.3.2

Open the chart page →

2,353
apimap-portalapimapOfficialVerified publisher2.4.01 of 1See more

apimap-portal apimap 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
apimap/portal:v2.4.0041a4790c65c
picomatch@2.3.0
2.3.2

Open the chart page →

2,396
platform-uiappscodeVerified publisher2026.9.111 of 1See more

platform-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-33672.

Container imageDigestPackageFixed in
ghcr.io/appscode/platform-ui:2.4.0668ee2682eaf
picomatch@4.0.3
4.0.4

Open the chart page →

690

Container images carrying it

508 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
decisionrules/server:latestf38d8571fa06
picomatch@4.0.3
4.0.4
4
kodekloud/examplevotingapp_result:v1e510023fdf38
picomatch@2.3.1
2.3.2
4
redis/redisinsight:3.8:latestb5e19ee240ab
picomatch@4.0.2
4.0.4
4
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
picomatch@2.3.1
2.3.2
4
assistiot/dlt_api:2.0.0e36a8922fa0c
picomatch@2.3.1
2.3.2
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
picomatch@2.3.0
2.3.2
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
picomatch@2.3.1
2.3.2
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
picomatch@2.3.1
2.3.2
3
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
picomatch@4.0.3
4.0.4
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
picomatch@4.0.3
4.0.4
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
picomatch@4.0.3
4.0.4
3
agoldis/sorry-cypress-api:2.5.11afaa5a84051d
picomatch@2.2.2
2.3.2
2
agoldis/sorry-cypress-director:2.5.1110228ecd353b
picomatch@2.2.2
2.3.2
2
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
picomatch@2.2.2
2.3.2
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
picomatch@2.2.3
2.3.2
2
ethersphere/bee-localchain:latest0558799ca992
picomatch@2.3.1
2.3.2
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
picomatch@2.3.1
2.3.2
2
governify/assets-manager:v1.4.12987672448c7
picomatch@2.3.0
2.3.2
2
governify/director:v1.4.0608c6940bb98
picomatch@2.2.2
2.3.2
2
governify/registry:v3.4.0d3f37f4f8168
picomatch@2.2.2
2.3.2
2
governify/render:v2.2.0daeca1ce28e6
picomatch@2.2.2
2.3.2
2
governify/reporter:v2.2.038595913458f
picomatch@2.2.2
2.3.2
2
gradiant/open5gs-webui:2.7.5fbd10c017541
picomatch@2.3.1
2.3.2
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
picomatch@2.3.1
2.3.2
2
ilum/ui:6.7.3998937726679
picomatch@4.0.3
4.0.4
2
kutt/kutt:latest:v3.2.6fa3d24a89b04
picomatch@4.0.3
4.0.4
2
library/ghost:6.63.0e05bc1169fb2
picomatch@4.0.3
4.0.4
2
louislam/uptime-kuma:2.5.4917318f9d7be
picomatch@4.0.3
4.0.4
2
louislam/uptime-kuma:2.3.29aeb4e51d038
picomatch@4.0.3
4.0.4
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
picomatch@4.0.3
4.0.4
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
picomatch@2.2.2
2.3.2
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
picomatch@2.2.3
2.3.2
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
picomatch@2.2.2
2.3.2
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
picomatch@4.0.2
4.0.4
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
picomatch@2.3.1
2.3.2
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
picomatch@2.3.1
2.3.2
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
picomatch@2.3.1
2.3.2
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
picomatch@2.3.1
2.3.2
2
moreillon/api-proxy:a3e8b41e9e578c9653b6
picomatch@2.3.1
2.3.2
2
moreillon/group-manager:v4.9.0d5a0ec8394c0
picomatch@2.3.1
2.3.2
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
picomatch@2.3.1
2.3.2
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
picomatch@2.2.2
2.3.2
2
outlinewiki/outline:0.69.1d060dcd8f9aa
picomatch@2.3.1
2.3.2
2
rajnandan1/kener:3.2.1930407afca731
picomatch@2.3.1
2.3.2
2
requarks/wiki:2:latest68f0d1848261
picomatch@4.0.3
4.0.4
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
picomatch@2.3.0
2.3.2
2
taigaio/taiga-events:latest92fc0822564f
picomatch@2.3.0
2.3.2
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
picomatch@2.3.0
2.3.2
2
verdaccio/verdaccio:6.10.209b403888c8f
picomatch@4.0.3
4.0.4
2
ghcr.io/gethomepage/homepage:latest:v2.2.0753eeb0cc22a
picomatch@4.0.3
4.0.4
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.