StackRadar

CVE-2026-33938

High

Advisory

Published 27 Mar 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.007
52nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
117
of 17,781 indexed, latest versions
Container images
109
deployed by those charts
Fix available
1 of 2
affected packages

Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block

Carried by container images the latest versions of 117 of 17,781 indexed charts deploy, on 109 images.

Affected packageAffected versionsFixed inImages
handlebarsnpm4.0.6, 4.0.10, 4.0.11, 4.0.12+8 more4.7.9109
node-handlebarsdeb3:4.7.7+~4.1.0-1no fix listed1
OSV records
GHSA-3mfm-83xf-c92rUBUNTU-CVE-2026-33938

Charts affected

117 by stars
ChartLatestAffected imagesRadar Score
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
handlebars@4.5.3
4.7.9

Open the chart page →

11,174
bee-localchainethersphereVerified publisher0.2.01 of 1See more

bee-localchain ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
handlebars@4.7.8
4.7.9

Open the chart page →

2,266
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
handlebars@4.7.8
4.7.9

Open the chart page →

4,756
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
handlebars@4.7.8
4.7.9

Open the chart page →

64,489
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
handlebars@4.7.8
4.7.9

Open the chart page →

4,650
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
handlebars@4.7.7
4.7.9

Open the chart page →

34,754
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
handlebars@4.7.8
4.7.9

Open the chart page →

9,019
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
handlebars@4.7.8
4.7.9

Open the chart page →

2,973
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
handlebars@4.7.8
4.7.9

Open the chart page →

2,950
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
handlebars@4.7.6
4.7.9

Open the chart page →

8,213
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
handlebars@4.7.7
4.7.9

Open the chart page →

3,451
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
handlebars@4.7.8
4.7.9

Open the chart page →

5,769
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
handlebars@4.7.7
4.7.9

Open the chart page →

18,813
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
handlebars@4.7.8
4.7.9

Open the chart page →

1,271
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
handlebars@4.7.8
4.7.9

Open the chart page →

3,614
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
handlebars@4.1.2
4.7.9

Open the chart page →

32,915
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
ibmcom/microclimate-portal:latested5505e5c7ec
handlebars@4.0.11
4.7.9

Open the chart page →

57,669
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
handlebars@4.7.8
4.7.9

Open the chart page →

11,812
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
handlebars@4.7.7
4.7.9

Open the chart page →

4,944
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
handlebars@4.7.7
4.7.9

Open the chart page →

7,232
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
handlebars@4.7.8
4.7.9

Open the chart page →

5,826
monocularjenkins-x0.6.41 of 4See more

monocular jenkins-x 0.6.4

1 of the 4 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
handlebars@4.0.6
4.7.9

Open the chart page →

4,614
hello-kubernetes-chartjhidalgo3-githubVerified publisher3.0.01 of 1See more

hello-kubernetes-chart jhidalgo3-github 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
handlebars@4.7.8
4.7.9

Open the chart page →

914
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
handlebars@4.7.7
4.7.9

Open the chart page →

6,454
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
handlebars@4.7.7
4.7.9

Open the chart page →

4,230
seerrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

seerr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
handlebars@4.7.8
4.7.9

Open the chart page →

2,548
multitenantkvalitetsitVerified publisher2.2.181 of 1See more

multitenant kvalitetsit 2.2.18

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
handlebars@4.7.7
4.7.9

Open the chart page →

1,614
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
handlebars@4.7.8
4.7.9

Open the chart page →

3,555
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
handlebars@4.3.5
4.7.9

Open the chart page →

7,929
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
handlebars@4.7.8
4.7.9

Open the chart page →

9,774
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
handlebars@4.7.7
4.7.9

Open the chart page →

5,287
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
handlebars@4.7.7
4.7.9

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
handlebars@4.7.7
4.7.9

Open the chart page →

10,603
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
handlebars@4.7.7
4.7.9

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
handlebars@4.7.7
4.7.9

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
handlebars@4.7.7
4.7.9
mojaloop/event-sidecar:v11.0.189b8ab71b74b
handlebars@4.7.7
4.7.9

Open the chart page →

12,108
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
handlebars@4.7.8
4.7.9

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
handlebars@4.7.7
4.7.9
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
handlebars@4.7.7
4.7.9

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
handlebars@4.7.7
4.7.9
mojaloop/event-sidecar:v11.0.189b8ab71b74b
handlebars@4.7.7
4.7.9
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
handlebars@4.7.7
4.7.9

Open the chart page →

19,226
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
handlebars@4.7.8
4.7.9

Open the chart page →

2,316
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
handlebars@4.0.6
4.7.9
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
handlebars@4.0.10
4.7.9

Open the chart page →

7,048
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
handlebars@4.7.6
4.7.9

Open the chart page →

6,684
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
handlebars@4.7.8
4.7.9

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
handlebars@4.7.8
4.7.9

Open the chart page →

4,960
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
handlebars@4.7.7
4.7.9

Open the chart page →

109,294
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
handlebars@4.7.8
4.7.9

Open the chart page →

2,383
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
handlebars@4.7.6
4.7.9

Open the chart page →

27,465
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
handlebars@4.7.8
4.7.9

Open the chart page →

4,219
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
handlebars@4.4.5
4.7.9

Open the chart page →

1,986
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-33938.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
handlebars@4.7.7
4.7.9

Open the chart page →

6,524

Container images carrying it

109 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
handlebars@4.7.7
4.7.9
5
pantsel/konga:latestc8172b75607d
handlebars@4.0.10
4.7.9
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
handlebars@4.7.8
4.7.9
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
handlebars@4.7.8
4.7.9
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
handlebars@4.7.6
4.7.9
2
ethersphere/bee-localchain:latest0558799ca992
handlebars@4.7.8
4.7.9
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
handlebars@4.7.8
4.7.9
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
handlebars@4.7.7
4.7.9
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
handlebars@4.5.3
4.7.9
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
handlebars@4.7.6
4.7.9
2
migmartri/prerender:latest486aacfd5aa9
handlebars@4.0.6
4.7.9
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
handlebars@4.7.7
4.7.9
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
handlebars@4.7.7
4.7.9
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
handlebars@4.7.8
4.7.9
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
handlebars@4.7.7
4.7.9
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
handlebars@4.3.5
4.7.9
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
handlebars@4.5.3
4.7.9
1
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
handlebars@4.7.7
4.7.9
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
handlebars@4.7.6
4.7.9
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
handlebars@4.7.6
4.7.9
1
automatischio/automatisch:0.15.03bace7a12d5f
handlebars@4.7.8
4.7.9
1
catalysm/csmm:latestf003b35f54d9
handlebars@4.7.7
4.7.9
1
countly/api:25.05.4f4cc7447c4f5
handlebars@4.7.7
4.7.9
1
countly/countly-server:25.05.4e3c238248f99
handlebars@4.7.7
4.7.9
1
countly/frontend:25.05.42acbc11499b6
handlebars@4.7.7
4.7.9
1
daskdev/dask-notebook:1.1.0052630f5ca04
handlebars@4.0.12
4.7.9
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
handlebars@4.7.7
4.7.9
1
fallenbagel/jellyseerr:latest4538137bc5af
handlebars@4.7.8
4.7.9
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
handlebars@4.7.8
4.7.9
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
handlebars@4.5.3
4.7.9
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
handlebars@4.7.8
4.7.9
1
fonoster/routr-connect:2.13.6e8c84b5eaa67
handlebars@4.7.8
4.7.9
1
fonoster/routr-dispatcher:2.13.65f8f380dc174
handlebars@4.7.8
4.7.9
1
fonoster/routr-location:2.13.6051ba9c34ef5
handlebars@4.7.8
4.7.9
1
fonoster/routr-pgdata:2.13.6e4d5f5ff1945
handlebars@4.7.8
4.7.9
1
fonoster/routr-registry:2.13.6e27001f2813c
handlebars@4.7.8
4.7.9
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
handlebars@4.1.2
4.7.9
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
handlebars@4.7.8
4.7.9
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
handlebars@4.7.7
4.7.9
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
handlebars@4.1.2
4.7.9
1
ibmcom/microclimate-portal:latested5505e5c7ec
handlebars@4.0.11
4.7.9
1
jayfong/yapi:1.10.2163e5d621910
handlebars@4.7.7
4.7.9
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
handlebars@4.7.8
4.7.9
1
joplin/server:3.0-beta52af57880c0e
handlebars@4.7.7
4.7.9
1
joplin/server:2.14.2-betab87564ef34e9
handlebars@4.7.7
4.7.9
1
jupyterhub/jupyterhub:5.4.63974ba945e65
handlebars@4.7.7
node-handlebars@3:4.7.7+~4.1.0-1
4.7.9
no fix listed
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
handlebars@4.7.7
4.7.9
1
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
handlebars@4.7.7
4.7.9
1
library/ghost:6.25.12654b1e90413
handlebars@4.7.8
4.7.9
1
library/ghost:4.37.0767230c0f263
handlebars@4.7.7
4.7.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.