StackRadar

CVE-2026-40895

Medium

Advisory

Published 14 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
352
of 17,787 indexed, latest versions
Container images
344
deployed by those charts
Fix available
1 of 1
affected package

follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets

Carried by container images the latest versions of 352 of 17,787 indexed charts deploy, on 344 images.

Affected packageAffected versionsFixed inImages
follow-redirectsnpm1.0.0, 1.2.5, 1.5.10, 1.6.1+26 more1.16.0344
OSV records
GHSA-r4q5-vmmm-2653

Charts affected

352 by stars
ChartLatestAffected imagesRadar Score
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-40895.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
follow-redirects@1.14.8
1.16.0

Open the chart page →

1,752
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-40895.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
follow-redirects@1.15.6
1.16.0

Open the chart page →

9,381

Container images carrying it

344 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
follow-redirects@1.15.2
1.16.0
1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
follow-redirects@1.15.2
1.16.0
1
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
follow-redirects@1.15.2
1.16.0
1
thingsboard/tb-web-ui:3.4.157f98ed53b3d
follow-redirects@1.15.1
1.16.0
1
thingsboard/tb-web-ui:3.6.0d388378062cc
follow-redirects@1.15.1
1.16.0
1
thmmniii/fbs-qcm-backend:v1.27.1afbe511e5c24
follow-redirects@1.15.11
1.16.0
1
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
follow-redirects@1.15.6
1.16.0
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
follow-redirects@1.14.7
1.16.0
1
tzahi12345/youtubedl-material:4.23720b856bd2f
follow-redirects@1.13.1
1.16.0
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
follow-redirects@1.15.6
1.16.0
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
follow-redirects@1.15.11
1.16.0
1
unleashorg/unleash-server:7.5.09adb37e399ba
follow-redirects@1.15.11
1.16.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
follow-redirects@1.14.7
1.16.0
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
follow-redirects@1.15.6
1.16.0
1
vlebediantsev/notes-admin-front:latest007c6670ff48
follow-redirects@1.15.2
1.16.0
1
vlebediantsev/notes-project-front:latest945675fd2636
follow-redirects@1.15.2
1.16.0
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
follow-redirects@1.15.2
1.16.0
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
follow-redirects@1.15.6
1.16.0
1
wazuh/wazuh-dashboard:4.4.11787550d2358
follow-redirects@1.15.2
1.16.0
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
follow-redirects@1.15.6
1.16.0
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
follow-redirects@1.15.6
1.16.0
1
winfred008/amazon:910a68de5b398
follow-redirects@1.15.2
1.16.0
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
follow-redirects@1.15.9
1.16.0
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
follow-redirects@1.15.5
1.16.0
1
ymuski/skooner:latest67819ca511b5
follow-redirects@1.14.8
1.16.0
1
youssef11gaber10/deployment-ui-react:latestba6853e35c60
follow-redirects@1.14.5
1.16.0
1
zooz/predator:1.6f491d1f7a865
follow-redirects@1.14.9
1.16.0
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
follow-redirects@1.14.0
1.16.0
1
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
follow-redirects@1.14.9
1.16.0
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
follow-redirects@1.15.5
1.16.0
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
follow-redirects@1.15.6
1.16.0
1
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
follow-redirects@1.15.2
1.16.0
1
ghcr.io/ajnart/homarr:lateste103abadfb52
follow-redirects@1.15.6
1.16.0
1
ghcr.io/appscode/platform-ui:2.4.0668ee2682eaf
follow-redirects@1.15.11
1.16.0
1
ghcr.io/beluga-cloud/actual/actualserver:23.12.1c8a0d5ec5a12
follow-redirects@1.15.2
1.16.0
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
follow-redirects@1.15.11
1.16.0
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
follow-redirects@1.15.11
1.16.0
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
follow-redirects@1.15.11
1.16.0
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
follow-redirects@1.15.6
1.16.0
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
follow-redirects@1.15.9
1.16.0
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
follow-redirects@1.13.2
1.16.0
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
follow-redirects@1.13.2
1.16.0
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
follow-redirects@1.13.2
1.16.0
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
follow-redirects@1.13.2
1.16.0
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
follow-redirects@1.15.6
1.16.0
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
follow-redirects@1.15.9
1.16.0
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
follow-redirects@1.15.5
1.16.0
1
ghcr.io/data-fair/metrics:0a8d40779eeae
follow-redirects@1.15.1
1.16.0
1
ghcr.io/data-fair/notify:3c739b74dabb0
follow-redirects@1.15.9
1.16.0
1
ghcr.io/data-fair/processings:15a9216989707
follow-redirects@1.15.3
1.16.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.