StackRadar

CVE-2026-33864

Critical

Advisory

Published 26 Mar 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.4
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
13
deployed by those charts
Fix available
1 of 1
affected package

Convict has Prototype Pollution via startsWith() function

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 13 images.

Affected packageAffected versionsFixed inImages
convictnpm5.0.0, 6.2.2, 6.2.46.2.513
OSV records
GHSA-44fc-8fm5-q62h

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
n8nn8n0.23.01 of 1See more

n8n n8n 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-33864.

Container imageDigestPackageFixed in
n8nio/n8n:1.33.1dd171d45102a
convict@6.2.4
6.2.5

Open the chart page →

5,639
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-33864.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
convict@6.2.4
6.2.5

Open the chart page →

7,776
sendgeek-cookbookVerified publisher1.2.21 of 1See more

send geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-33864.

Container imageDigestPackageFixed in
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
convict@6.2.2
6.2.5

Open the chart page →

1,148
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-33864.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
convict@5.0.0
6.2.5
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
convict@5.0.0
6.2.5
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
convict@5.0.0
6.2.5
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
convict@5.0.0
6.2.5

Open the chart page →

89,959
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33864.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
convict@6.2.4
6.2.5

Open the chart page →

5,826
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-33864.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
convict@6.2.4
6.2.5

Open the chart page →

2,457
finance-portalmojaloop5.1.44 of 11See more

finance-portal mojaloop 5.1.4

4 of the 11 container images this version deploys carry CVE-2026-33864.

Container imageDigestPackageFixed in
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
convict@6.2.4
6.2.5
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
convict@6.2.4
6.2.5
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
convict@6.2.4
6.2.5
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
convict@6.2.4
6.2.5

Open the chart page →

14,809
reporting-aggregator-svcmojaloop1.0.71 of 1See more

reporting-aggregator-svc mojaloop 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-33864.

Container imageDigestPackageFixed in
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
convict@6.2.4
6.2.5

Open the chart page →

800
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-33864.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
convict@6.2.4
6.2.5

Open the chart page →

2,631
reporting-hub-bop-api-svcmojaloop4.1.31 of 1See more

reporting-hub-bop-api-svc mojaloop 4.1.3

1 of the 1 container images this version deploys carry CVE-2026-33864.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
convict@6.2.4
6.2.5

Open the chart page →

1,661
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-33864.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
convict@6.2.4
6.2.5

Open the chart page →

2,318
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-33864.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
convict@6.2.4
6.2.5

Open the chart page →

2,457

Container images carrying it

13 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
convict@6.2.4
6.2.5
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
convict@6.2.4
6.2.5
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
convict@6.2.4
6.2.5
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
convict@6.2.4
6.2.5
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
convict@6.2.4
6.2.5
2
n8nio/n8n:1.86.08b39ed5a2de9
convict@6.2.4
6.2.5
1
n8nio/n8n:0.212.0a9195bc499a3
convict@6.2.4
6.2.5
1
n8nio/n8n:1.33.1dd171d45102a
convict@6.2.4
6.2.5
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
convict@5.0.0
6.2.5
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
convict@5.0.0
6.2.5
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
convict@5.0.0
6.2.5
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
convict@5.0.0
6.2.5
1
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
convict@6.2.2
6.2.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.