StackRadar

CVE-2026-40295

Medium

Advisory

Published 8 May 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
1 of 1
affected package

Devise has an Open Redirect via Unvalidated `request.referrer` in Timeoutable Session Timeout Handler

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
devisegem4.7.1, 4.8.1, 4.9.2, 4.9.4+1 more5.0.411
OSV records
GHSA-jp94-3292-c3xv

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2026-40295.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
devise@4.9.4
5.0.4

Open the chart page →

9,203
huginnutkuozdemirVerified publisher2.2.11 of 4See more

huginn utkuozdemir 2.2.1

1 of the 4 container images this version deploys carry CVE-2026-40295.

Container imageDigestPackageFixed in
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
devise@4.7.1
5.0.4

Open the chart page →

18,137
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-40295.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
devise@4.8.1
5.0.4

Open the chart page →

5,056
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-40295.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
devise@4.9.2
5.0.4

Open the chart page →

5,940
antigenic-docuseal-helm-chartantigenic-docuseal-helm-chartVerified publisher0.2.01 of 1See more

antigenic-docuseal-helm-chart antigenic-docuseal-helm-chart 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-40295.

Container imageDigestPackageFixed in
docuseal/docuseal:2.4.17493fd7f6728
devise@5.0.3
5.0.4

Open the chart page →

2,766
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2026-40295.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latesta058034ca006
devise@4.9.4
5.0.4

Open the chart page →

14,130
manyfoldjeffrescVerified publisher1.0.31 of 1See more

manyfold jeffresc 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-40295.

Container imageDigestPackageFixed in
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
devise@5.0.3
5.0.4

Open the chart page →

1,960
gitlabkubesphereVerified publisher4.2.33 of 17See more

gitlab kubesphere 4.2.3

3 of the 17 container images this version deploys carry CVE-2026-40295.

Container imageDigestPackageFixed in
mirrorgitlabcontainers/gitlab-sidekiq-ce:v13.2.294d1431683fa
devise@4.7.1
5.0.4
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
devise@4.7.1
5.0.4
mirrorgitlabcontainers/gitlab-webservice-ce:v13.2.230393f990f5c
devise@4.7.1
5.0.4

Open the chart page →

38,133
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-40295.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
devise@4.9.2
5.0.4

Open the chart page →

5,940
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-40295.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
devise@4.8.1
5.0.4

Open the chart page →

6,026

Container images carrying it

11 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
chatwoot/chatwoot:v3.1.0d530ab8c1753
devise@4.9.2
5.0.4
2
chatwoot/chatwoot:v4.15.167ebc751c171
devise@4.9.4
5.0.4
1
docuseal/docuseal:2.4.17493fd7f6728
devise@5.0.3
5.0.4
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
devise@4.7.1
5.0.4
1
mirrorgitlabcontainers/gitlab-sidekiq-ce:v13.2.294d1431683fa
devise@4.7.1
5.0.4
1
mirrorgitlabcontainers/gitlab-task-runner-ce:v13.2.29efd73993c34
devise@4.7.1
5.0.4
1
mirrorgitlabcontainers/gitlab-webservice-ce:v13.2.230393f990f5c
devise@4.7.1
5.0.4
1
ghcr.io/caninehq/canine:latesta058034ca006
devise@4.9.4
5.0.4
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
devise@5.0.3
5.0.4
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
devise@4.8.1
5.0.4
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
devise@4.8.1
5.0.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.