StackRadar

CVE-2026-41907

High

Advisory

Published 22 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
598
of 17,787 indexed, latest versions
Container images
597
deployed by those charts
Fix available
1 of 2
affected packages

uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided

Carried by container images the latest versions of 598 of 17,787 indexed charts deploy, on 597 images.

Affected packageAffected versionsFixed inImages
uuidnpm2.0.2, 2.0.3, 3.0.1, 3.1.0+15 more11.1.1, 13.0.1595
node-uuiddeb1.4.0-1, 1.4.7-5, 3.3.2-2, 8.3.2+~8.3.3-4no fix listed6
OSV records
GHSA-w5hq-g745-h8pqUBUNTU-CVE-2026-41907
Also known as
CVE-2026-41988

Charts affected

598 by stars
ChartLatestAffected imagesRadar Score
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
uuid@8.3.2
11.1.1

Open the chart page →

2,862
mergeabledoubanVerified publisher0.2.21 of 1See more

mergeable douban 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
ghcr.io/leoquote/mergeable:latest451706815103
uuid@3.3.2
11.1.1

Open the chart page →

4,223
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.02 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
uuid@8.3.2
11.1.1
oscarsotosanchez/weatherservice:v1.0911ec961d10b
uuid@3.3.3
11.1.1

Open the chart page →

24,656
dumpstoredumpstore0.1.11 of 2See more

dumpstore dumpstore 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
uuid@9.0.1
11.1.1

Open the chart page →

4,251
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
uuid@3.3.2
11.1.1

Open the chart page →

11,174
benchmarking-tooleclipse-aeriosVerified publisher1.0.01 of 1See more

benchmarking-tool eclipse-aerios 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
uuid@10.0.0
11.1.1

Open the chart page →

687
backend-charteks-3-tier-app-chart0.1.01 of 1See more

backend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
arfath29/3-tier-app-backend:latestee0750b18406
uuid@3.4.0
11.1.1

Open the chart page →

1,693
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
uuid@3.4.0
11.1.1

Open the chart page →

3,744
azuriteemberstackVerified publisher1.0.211 of 1See more

azurite emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
uuid@8.3.2
11.1.1

Open the chart page →

365
eolicplantseolicplantsVerified publisher0.1.02 of 7See more

eolicplants eolicplants 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
uuid@8.3.2
11.1.1
oscarsotosanchez/weatherservice:v1.0911ec961d10b
uuid@3.3.3
11.1.1

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.02 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
uuid@8.3.2
11.1.1
oscarsotosanchez/weatherservice:v1.0911ec961d10b
uuid@3.3.3
11.1.1

Open the chart page →

27,256
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
uuid@8.3.2
11.1.1

Open the chart page →

27,096
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
uuid@3.4.0
11.1.1

Open the chart page →

1,755
blobscanethereum-helm-chartsVerified publisher0.1.11 of 1See more

blobscan ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
ethpandaops/blobscan:latest7a9ab6370657
uuid@8.3.2
11.1.1

Open the chart page →

1,329
blobscan-indexerethereum-helm-chartsVerified publisher0.1.11 of 1See more

blobscan-indexer ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
ethpandaops/blobscan-indexer:latestc58eb9ffe446
uuid@3.3.3
11.1.1

Open the chart page →

2,114
ganacheethereum-helm-chartsVerified publisher0.1.31 of 2See more

ganache ethereum-helm-charts 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
trufflesuite/ganache-cli:v6.12.2c062707f17f3
uuid@3.3.3
11.1.1

Open the chart page →

1,608
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
uuid@9.0.1
11.1.1

Open the chart page →

2,522
testnet-faucetethereum-helm-chartsVerified publisher0.1.31 of 1See more

testnet-faucet ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
parithoshj/testnet-faucet:9859e0dcdca426fea6d
uuid@3.3.3
11.1.1

Open the chart page →

3,005
bee-localchainethersphereVerified publisher0.2.01 of 1See more

bee-localchain ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
uuid@8.3.2
11.1.1

Open the chart page →

2,266
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
uuid@3.3.3
11.1.1

Open the chart page →

3,260
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
uuid@8.3.2
11.1.1

Open the chart page →

4,756
mandefactlyVerified publisher0.5.161 of 3See more

mande factly 0.5.16

1 of the 3 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
factly/mande-web:0.34.1742355964b0e
uuid@9.0.1
11.1.1

Open the chart page →

4,777
smeejasfanzynoodle0.0.11 of 1See more

smeejas fanzynoodle 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
fanzynoodle/smeejas:0.0.15f9916c1a287
uuid@3.4.0
11.1.1

Open the chart page →

4,127
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
uuid@3.4.0
11.1.1

Open the chart page →

64,489
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
uuid@8.3.2
11.1.1

Open the chart page →

1,847
iotagent-jsonfiware0.1.21 of 1See more

iotagent-json fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
fiware/iotagent-json:3.1.0879b21a0d36d
uuid@8.3.2
11.1.1

Open the chart page →

937
iotagent-ulfiware0.1.21 of 1See more

iotagent-ul fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
fiware/iotagent-ul:1.14.0fe11f55a926d
uuid@3.3.3
11.1.1

Open the chart page →

3,337
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
uuid@3.4.0
11.1.1

Open the chart page →

3,159
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
uuid@8.3.2
11.1.1

Open the chart page →

1,489
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
uuid@8.3.2
11.1.1

Open the chart page →

4,650
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
louislam/uptime-kuma:13d632903e6af
uuid@8.3.2
11.1.1

Open the chart page →

3,474
mod-graphqlfolio-org0.1.301 of 1See more

mod-graphql folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
folioci/mod-graphql:latestf0655a6a08fd
uuid@9.0.1
11.1.1

Open the chart page →

1,091
flamegabe565Verified publisher0.6.01 of 1See more

flame gabe565 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
pawelmalak/flame:multiarch2.3.19f88b17692a0
uuid@8.3.2
11.1.1

Open the chart page →

2,172
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
uuid@3.3.3
11.1.1

Open the chart page →

5,941
rtlgaloymoney0.4.31 of 2See more

rtl galoymoney 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.13.3e2195188a451
uuid@3.4.0
11.1.1

Open the chart page →

2,090
rtlgaloymoney20.4.31 of 2See more

rtl galoymoney2 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.13.3e2195188a451
uuid@3.4.0
11.1.1

Open the chart page →

2,090
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
uuid@8.3.2
11.1.1

Open the chart page →

12,222
flaresolverrgeek-cookbookVerified publisher5.4.21 of 1See more

flaresolverr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v1.2.896f8c08c0c1b
uuid@8.3.1
11.1.1

Open the chart page →

1,870
floodgeek-cookbookVerified publisher6.4.21 of 1See more

flood geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
jesec/flood:4.6.060bd59cfb4eb
uuid@3.4.0
11.1.1

Open the chart page →

2,000
grocygeek-cookbookVerified publisher8.5.21 of 1See more

grocy geek-cookbook 8.5.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
linuxserver/grocy:version-v3.1.3291296e66c2a
uuid@3.4.0
11.1.1

Open the chart page →

1,043
haste-servergeek-cookbookVerified publisher3.4.21 of 1See more

haste-server geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
uuid@3.3.2
11.1.1

Open the chart page →

10,994
nightscoutgeek-cookbookVerified publisher1.2.21 of 1See more

nightscout geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
uuid@3.4.0
11.1.1

Open the chart page →

4,043
node-redgeek-cookbookVerified publisher10.3.21 of 1See more

node-red geek-cookbook 10.3.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
nodered/node-red:2.2.2e131dcadfe92
uuid@3.3.3
11.1.1

Open the chart page →

2,102
openemrgeek-cookbookVerified publisher5.2.01 of 1See more

openemr geek-cookbook 5.2.0

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
openemr/openemr:6.1.089eaa6d9a4e3
uuid@8.3.2
11.1.1

Open the chart page →

8,392
rtorrent-floodgeek-cookbookVerified publisher9.4.21 of 1See more

rtorrent-flood geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
jesec/rtorrent-flood:latestf0c894ec459e
uuid@3.4.0
11.1.1

Open the chart page →

2,000
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
uuid@3.4.0
11.1.1

Open the chart page →

4,591
theloungegeek-cookbookVerified publisher3.4.21 of 1See more

thelounge geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
thelounge/thelounge:4.2.0-alpine639978459c3a
uuid@3.3.3
11.1.1

Open the chart page →

2,689
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
uuid@9.0.0
11.1.1

Open the chart page →

34,754
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
uuid@9.0.1
11.1.1

Open the chart page →

9,019
api-mapperglenndehaanVerified publisher1.2.01 of 1See more

api-mapper glenndehaan 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-41907.

Container imageDigestPackageFixed in
glenndehaan/api-mapper:latest6ff6310683bf
uuid@3.4.0
11.1.1

Open the chart page →

1,158

Container images carrying it

597 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
uuid@8.3.2
11.1.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
uuid@10.0.0
11.1.1
1
hugohg34/server:0.0.2503e5d8960ff
uuid@8.3.2
11.1.1
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
uuid@3.1.0
11.1.1
1
i4trust/pdc-portal:2.0.03e77858e1219
uuid@3.4.0
11.1.1
1
ianw/quickchart:v1.7.1dc49dd460c37
uuid@3.4.0
11.1.1
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
uuid@3.4.0
11.1.1
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
uuid@3.3.2
11.1.1
1
ibmcom/app-nav-init:1.0.1240ff499eb5b
uuid@3.1.0
11.1.1
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
uuid@3.1.0
11.1.1
1
ibmcom/bai-admin-dev:19.0.202d882f2836e
uuid@3.3.2
11.1.1
1
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
uuid@3.3.2
11.1.1
1
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
uuid@3.3.2
11.1.1
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
uuid@3.1.0
11.1.1
1
ibmcom/microclimate-portal:latested5505e5c7ec
uuid@3.1.0
11.1.1
1
ibmcom/microclimate-theia:lateste17bdccc5030
uuid@3.2.1
11.1.1
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
uuid@3.3.2
11.1.1
1
improwised/erpnext-worker:v13.4.197280b55cbd4
uuid@3.3.3
11.1.1
1
instructure/kinesalite:latest34400d82f28f
uuid@7.0.3
11.1.1
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
uuid@8.3.2
11.1.1
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
uuid@3.4.0
11.1.1
1
istio/examples-bookinfo-ratings-v1:1.17.0b6a6b88d3578
uuid@3.3.3
11.1.1
1
jakowenko/double-take:1.6.0b858bac9e32a
uuid@8.3.2
11.1.1
1
jayfong/yapi:1.10.2163e5d621910
uuid@3.4.0
11.1.1
1
jesec/flood:4.7.03d1d0bec117a
uuid@3.4.0
11.1.1
1
jesec/flood:4.6.060bd59cfb4eb
uuid@3.4.0
11.1.1
1
jesec/rtorrent-flood:latestf0c894ec459e
uuid@3.4.0
11.1.1
1
joplin/server:latest3f7b852959aa
uuid@13.0.0
13.0.1
1
joplin/server:3.0-beta52af57880c0e
uuid@8.3.2
11.1.1
1
joplin/server:2.14.2-betab87564ef34e9
uuid@8.3.2
11.1.1
1
journeyapps/powersync-service:latestbf46f66e5dcc
uuid@8.3.2
11.1.1
1
junktext/getting-started:1.0.5a70936c04aed
uuid@3.4.0
11.1.1
1
junktext/getting-started:1.0.34d44adf5a4da2
uuid@3.4.0
11.1.1
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-uuid@8.3.2+~8.3.3-4
uuid@8.3.2
no fix listed
11.1.1
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
uuid@3.3.3
11.1.1
1
kitware/cdash:v5.3.0d7767d9b9da4
uuid@8.3.2
11.1.1
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
uuid@8.3.2
11.1.1
1
konradkleine/docker-registry-frontend:v2181aad54ee64
uuid@3.1.0
11.1.1
1
koumoul/capture:17108d47be3b2
uuid@3.3.2
11.1.1
1
koumoul/openapi-viewer:18eeca2e8285b
uuid@3.2.1
11.1.1
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
uuid@8.3.2
11.1.1
1
kubebb/component-store:latestfd8ecbd73213
uuid@9.0.0
11.1.1
1
kubebb/tamp-portal:v5.6.0fadac6d52470
uuid@3.4.0
11.1.1
1
kubebb/tdsf-portal:v5.7.0258458311bc9
uuid@3.4.0
11.1.1
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
uuid@3.3.3
11.1.1
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
uuid@3.3.2
11.1.1
1
kubesphere/examples-bookinfo-ratings-v1:1.13.0f1b5bf878196
uuid@3.3.2
11.1.1
1
kubevious/backend:1.2.22d9ba6eb46b6
uuid@3.4.0
11.1.1
1
kubevious/collector:1.2.1f58226f9d84e
uuid@9.0.0
11.1.1
1
kubevious/guard:1.2.19bf567704de2
uuid@8.3.2
11.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.