StackRadar

CVE-2026-33939

High

Advisory

Published 27 Mar 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
117
of 17,781 indexed, latest versions
Container images
109
deployed by those charts
Fix available
1 of 2
affected packages

Handlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation

Carried by container images the latest versions of 117 of 17,781 indexed charts deploy, on 109 images.

Affected packageAffected versionsFixed inImages
handlebarsnpm4.0.6, 4.0.10, 4.0.11, 4.0.12+8 more4.7.9109
node-handlebarsdeb3:4.7.7+~4.1.0-1no fix listed1
OSV records
GHSA-9cx6-37pm-9jffUBUNTU-CVE-2026-33939

Charts affected

117 by stars
ChartLatestAffected imagesRadar Score
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
handlebars@4.7.8
4.7.9

Open the chart page →

2,969
routr-connectroutr0.4.35 of 10See more

routr-connect routr 0.4.3

5 of the 10 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
fonoster/routr-connect:2.13.6e8c84b5eaa67
handlebars@4.7.8
4.7.9
fonoster/routr-dispatcher:2.13.65f8f380dc174
handlebars@4.7.8
4.7.9
fonoster/routr-location:2.13.6051ba9c34ef5
handlebars@4.7.8
4.7.9
fonoster/routr-pgdata:2.13.6e4d5f5ff1945
handlebars@4.7.8
4.7.9
fonoster/routr-registry:2.13.6e27001f2813c
handlebars@4.7.8
4.7.9

Open the chart page →

11,021
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
handlebars@4.7.7
4.7.9

Open the chart page →

7,413
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
handlebars@4.7.8
4.7.9

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
handlebars@4.7.8
4.7.9

Open the chart page →

16,620
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
handlebars@4.7.8
4.7.9

Open the chart page →

1,991
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
handlebars@4.7.7
4.7.9

Open the chart page →

3,881
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
handlebars@4.5.3
4.7.9

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
handlebars@4.5.3
4.7.9

Open the chart page →

12,460
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
handlebars@4.7.7
4.7.9

Open the chart page →

4,017
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
handlebars@4.7.7
4.7.9

Open the chart page →

3,576
saleor-appstrieb-work0.6.02 of 5See more

saleor-apps trieb-work 0.6.0

2 of the 5 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
handlebars@4.7.7
4.7.9
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
handlebars@4.7.7
4.7.9

Open the chart page →

6,994
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
handlebars@4.7.7
4.7.9

Open the chart page →

5,484
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
handlebars@4.7.8
4.7.9

Open the chart page →

6,285
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
handlebars@4.7.6
4.7.9

Open the chart page →

5,806
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
handlebars@4.7.7
4.7.9

Open the chart page →

16,083
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-33939.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
handlebars@4.7.7
4.7.9

Open the chart page →

9,381

Container images carrying it

109 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
handlebars@4.7.7
4.7.9
5
pantsel/konga:latestc8172b75607d
handlebars@4.0.10
4.7.9
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
handlebars@4.7.8
4.7.9
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
handlebars@4.7.8
4.7.9
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
handlebars@4.7.6
4.7.9
2
ethersphere/bee-localchain:latest0558799ca992
handlebars@4.7.8
4.7.9
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
handlebars@4.7.8
4.7.9
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
handlebars@4.7.7
4.7.9
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
handlebars@4.5.3
4.7.9
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
handlebars@4.7.6
4.7.9
2
migmartri/prerender:latest486aacfd5aa9
handlebars@4.0.6
4.7.9
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
handlebars@4.7.7
4.7.9
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
handlebars@4.7.7
4.7.9
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
handlebars@4.7.8
4.7.9
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
handlebars@4.7.7
4.7.9
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
handlebars@4.3.5
4.7.9
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
handlebars@4.5.3
4.7.9
1
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
handlebars@4.7.7
4.7.9
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
handlebars@4.7.6
4.7.9
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
handlebars@4.7.6
4.7.9
1
automatischio/automatisch:0.15.03bace7a12d5f
handlebars@4.7.8
4.7.9
1
catalysm/csmm:latestf003b35f54d9
handlebars@4.7.7
4.7.9
1
countly/api:25.05.4f4cc7447c4f5
handlebars@4.7.7
4.7.9
1
countly/countly-server:25.05.4e3c238248f99
handlebars@4.7.7
4.7.9
1
countly/frontend:25.05.42acbc11499b6
handlebars@4.7.7
4.7.9
1
daskdev/dask-notebook:1.1.0052630f5ca04
handlebars@4.0.12
4.7.9
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
handlebars@4.7.7
4.7.9
1
fallenbagel/jellyseerr:latest4538137bc5af
handlebars@4.7.8
4.7.9
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
handlebars@4.7.8
4.7.9
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
handlebars@4.5.3
4.7.9
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
handlebars@4.7.8
4.7.9
1
fonoster/routr-connect:2.13.6e8c84b5eaa67
handlebars@4.7.8
4.7.9
1
fonoster/routr-dispatcher:2.13.65f8f380dc174
handlebars@4.7.8
4.7.9
1
fonoster/routr-location:2.13.6051ba9c34ef5
handlebars@4.7.8
4.7.9
1
fonoster/routr-pgdata:2.13.6e4d5f5ff1945
handlebars@4.7.8
4.7.9
1
fonoster/routr-registry:2.13.6e27001f2813c
handlebars@4.7.8
4.7.9
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
handlebars@4.1.2
4.7.9
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
handlebars@4.7.8
4.7.9
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
handlebars@4.7.7
4.7.9
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
handlebars@4.1.2
4.7.9
1
ibmcom/microclimate-portal:latested5505e5c7ec
handlebars@4.0.11
4.7.9
1
jayfong/yapi:1.10.2163e5d621910
handlebars@4.7.7
4.7.9
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
handlebars@4.7.8
4.7.9
1
joplin/server:3.0-beta52af57880c0e
handlebars@4.7.7
4.7.9
1
joplin/server:2.14.2-betab87564ef34e9
handlebars@4.7.7
4.7.9
1
jupyterhub/jupyterhub:5.4.63974ba945e65
handlebars@4.7.7
node-handlebars@3:4.7.7+~4.1.0-1
4.7.9
no fix listed
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
handlebars@4.7.7
4.7.9
1
kvalitetsit/kithosting-networkpolicytests:0.0.12b99cfa3c5df
handlebars@4.7.7
4.7.9
1
library/ghost:6.25.12654b1e90413
handlebars@4.7.8
4.7.9
1
library/ghost:4.37.0767230c0f263
handlebars@4.7.7
4.7.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.