StackRadar

CVE-2026-34043

Medium

Advisory

Published 27 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
155
of 17,781 indexed, latest versions
Container images
160
deployed by those charts
Fix available
1 of 2
affected packages

Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects

Carried by container images the latest versions of 155 of 17,781 indexed charts deploy, on 160 images.

Affected packageAffected versionsFixed inImages
serialize-javascriptnpm5.0.1, 6.0.0, 6.0.1, 6.0.2+2 more7.0.5160
node-serialize-javascriptdeb6.0.1-1no fix listed1
OSV records
GHSA-qj8w-gfj5-8c6vUBUNTU-CVE-2026-34043

Charts affected

155 by stars
ChartLatestAffected imagesRadar Score
uoappuoapp1.1.01 of 1See more

uoapp uoapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-34043.

Container imageDigestPackageFixed in
okaforuchena/uo-docker:V1.0.0004e81250f48
serialize-javascript@6.0.0
7.0.5

Open the chart page →

1,187
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34043.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
serialize-javascript@7.0.4
7.0.5

Open the chart page →

4,305
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-34043.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
serialize-javascript@6.0.2
7.0.5

Open the chart page →

5,984
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34043.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
serialize-javascript@5.0.1
7.0.5

Open the chart page →

2,559
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-34043.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
serialize-javascript@6.0.1
7.0.5

Open the chart page →

16,083

Container images carrying it

160 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
serialize-javascript@6.0.2
7.0.5
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
serialize-javascript@6.0.2
7.0.5
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
serialize-javascript@6.0.0
7.0.5
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
serialize-javascript@6.0.0
7.0.5
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
serialize-javascript@6.0.0
7.0.5
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
serialize-javascript@6.0.2
7.0.5
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
serialize-javascript@5.0.1
7.0.5
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
serialize-javascript@6.0.2
7.0.5
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
serialize-javascript@6.0.2
7.0.5
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
serialize-javascript@6.0.2
7.0.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.