StackRadar

CVE-2026-40345

High

Advisory

Published 17 Aug 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.005
39th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
12
of 17,781 indexed, latest versions
Container images
12
deployed by those charts
Fix available
1 of 1
affected package

DeepmergeTS has stack exhaustion when merging recursive object graphs

Carried by container images the latest versions of 12 of 17,781 indexed charts deploy, on 12 images.

Affected packageAffected versionsFixed inImages
deepmerge-tsnpm5.1.0, 7.1.0, 7.1.58.0.012
OSV records
GHSA-ggr8-5vv4-36mx

Charts affected

12 by stars
ChartLatestAffected imagesRadar Score
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-40345.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
deepmerge-ts@7.1.5
8.0.0

Open the chart page →

10,775
umamihelmforgeVerified publisher2.3.31 of 3See more

umami helmforge 2.3.3

1 of the 3 container images this version deploys carry CVE-2026-40345.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.3.1fa32d116cf20
deepmerge-ts@7.1.5
8.0.0

Open the chart page →

2,027
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-40345.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
deepmerge-ts@5.1.0
8.0.0

Open the chart page →

4,016
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-40345.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
deepmerge-ts@7.1.5
8.0.0

Open the chart page →

3,123
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-40345.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
deepmerge-ts@7.1.0
8.0.0

Open the chart page →

31,844
activepiecesadnoctemVerified publisher0.5.01 of 1See more

activepieces adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-40345.

Container imageDigestPackageFixed in
activepieces/activepieces:0.90.430c10a04fe3d
deepmerge-ts@7.1.0
8.0.0

Open the chart page →

1,055
portfolio-trackerkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

portfolio-tracker kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-40345.

Container imageDigestPackageFixed in
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
deepmerge-ts@7.1.5
8.0.0

Open the chart page →

1,498
umamikubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

umami kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-40345.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.1.0e3f80c0625aa
deepmerge-ts@7.1.5
8.0.0

Open the chart page →

2,596
lynxpromptlynxpromptVerified publisher0.1.21 of 3See more

lynxprompt lynxprompt 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-40345.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
deepmerge-ts@7.1.5
8.0.0

Open the chart page →

1,852
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-40345.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
deepmerge-ts@7.1.5
8.0.0

Open the chart page →

4,016
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-40345.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
deepmerge-ts@5.1.0
8.0.0

Open the chart page →

4,052
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-40345.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
deepmerge-ts@7.1.5
8.0.0

Open the chart page →

3,746

Container images carrying it

12 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
activepieces/activepieces:0.90.430c10a04fe3d
deepmerge-ts@7.1.0
8.0.0
1
budibase/apps:3.41.344fe6feab985
deepmerge-ts@7.1.5
8.0.0
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
deepmerge-ts@5.1.0
8.0.0
1
drumsergio/lynxprompt:2.0.75c6afb6679301
deepmerge-ts@7.1.5
8.0.0
1
evoapicloud/evolution-api:latest966625532d90
deepmerge-ts@7.1.5
8.0.0
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
deepmerge-ts@7.1.5
8.0.0
1
nocodb/nocodb:0.301.5d9516f0bf546
deepmerge-ts@5.1.0
8.0.0
1
treskon/portrait-ui:DEV-lateste7970783bc8d
deepmerge-ts@7.1.0
8.0.0
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
deepmerge-ts@7.1.5
8.0.0
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
deepmerge-ts@7.1.5
8.0.0
1
ghcr.io/umami-software/umami:3.1.0e3f80c0625aa
deepmerge-ts@7.1.5
8.0.0
1
ghcr.io/umami-software/umami:3.3.1fa32d116cf20
deepmerge-ts@7.1.5
8.0.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.