StackRadar

CVE-2026-33916

Medium

Advisory

Published 26 Mar 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
117
of 17,781 indexed, latest versions
Container images
109
deployed by those charts
Fix available
1 of 2
affected packages

Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection

Carried by container images the latest versions of 117 of 17,781 indexed charts deploy, on 109 images.

Affected packageAffected versionsFixed inImages
handlebarsnpm4.0.6, 4.0.10, 4.0.11, 4.0.12+8 more4.7.9109
node-handlebarsdeb3:4.7.7+~4.1.0-1no fix listed1
OSV records
GHSA-2qvq-rjwj-gvw9UBUNTU-CVE-2026-33916

Charts affected

117 by stars
ChartLatestAffected imagesRadar Score
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
handlebars@4.7.8
4.7.9

Open the chart page →

2,969
routr-connectroutr0.4.35 of 10See more

routr-connect routr 0.4.3

5 of the 10 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
fonoster/routr-connect:2.13.6e8c84b5eaa67
handlebars@4.7.8
4.7.9
fonoster/routr-dispatcher:2.13.65f8f380dc174
handlebars@4.7.8
4.7.9
fonoster/routr-location:2.13.6051ba9c34ef5
handlebars@4.7.8
4.7.9
fonoster/routr-pgdata:2.13.6e4d5f5ff1945
handlebars@4.7.8
4.7.9
fonoster/routr-registry:2.13.6e27001f2813c
handlebars@4.7.8
4.7.9

Open the chart page →

11,021
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
handlebars@4.7.7
4.7.9

Open the chart page →

7,413
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
handlebars@4.7.8
4.7.9

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
handlebars@4.7.8
4.7.9

Open the chart page →

16,620
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
handlebars@4.7.8
4.7.9

Open the chart page →

1,991
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
handlebars@4.7.7
4.7.9

Open the chart page →

3,881
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
handlebars@4.5.3
4.7.9

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
handlebars@4.5.3
4.7.9

Open the chart page →

12,460
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
handlebars@4.7.7
4.7.9

Open the chart page →

4,017
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
handlebars@4.7.7
4.7.9

Open the chart page →

3,576
saleor-appstrieb-work0.6.02 of 5See more

saleor-apps trieb-work 0.6.0

2 of the 5 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
handlebars@4.7.7
4.7.9
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
handlebars@4.7.7
4.7.9

Open the chart page →

6,994
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
handlebars@4.7.7
4.7.9

Open the chart page →

5,484
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
handlebars@4.7.8
4.7.9

Open the chart page →

6,285
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
handlebars@4.7.6
4.7.9

Open the chart page →

5,806
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
handlebars@4.7.7
4.7.9

Open the chart page →

16,083
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-33916.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
handlebars@4.7.7
4.7.9

Open the chart page →

9,381

Container images carrying it

109 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
handlebars@4.7.7
4.7.9
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
handlebars@4.7.8
4.7.9
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
handlebars@4.7.8
4.7.9
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
handlebars@4.7.7
4.7.9
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
handlebars@4.7.7
4.7.9
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
handlebars@4.0.10
4.7.9
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
handlebars@4.7.3
4.7.9
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
handlebars@4.7.8
4.7.9
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
handlebars@4.7.8
4.7.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.