StackRadar

CVE-2026-42334

High

Advisory

Published 5 May 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
37
of 17,781 indexed, latest versions
Container images
37
deployed by those charts
Fix available
1 of 1
affected package

Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

Carried by container images the latest versions of 37 of 17,781 indexed charts deploy, on 37 images.

Affected packageAffected versionsFixed inImages
mongoosenpm4.13.14, 5.7.5, 5.12.5, 5.12.6+24 more6.13.9, 7.8.9, 8.22.137
OSV records
GHSA-wpg9-53fq-2r8h
Also known as
BIT-mongoose-2026-42334

Charts affected

37 by stars
ChartLatestAffected imagesRadar Score
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
mongoose@5.13.23
6.13.9

Open the chart page →

30,326
librechatlibrechat1.8.101 of 3See more

librechat librechat 1.8.10

1 of the 3 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
mongoose@8.9.5
8.22.1

Open the chart page →

2,654
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
mongoose@5.13.20
6.13.9

Open the chart page →

9,261
litlyxlitlyx0.2.03 of 5See more

litlyx litlyx 0.2.0

3 of the 5 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
litlyx/litlyx-consumer:latest02225e77d316
mongoose@8.20.1
8.22.1
litlyx/litlyx-dashboard:lateste64ff2d52385
mongoose@8.20.1
8.22.1
litlyx/litlyx-producer:latest10407f36613f
mongoose@8.20.1
8.22.1

Open the chart page →

7,874
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
mongoose@6.13.2
6.13.9

Open the chart page →

13,738
open5gs-webuiopen5gs-webuiVerified publisher2.3.11 of 2See more

open5gs-webui open5gs-webui 2.3.1

1 of the 2 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
mongoose@5.13.20
6.13.9

Open the chart page →

5,300
ackeesudaVerified publisher0.2.11 of 1See more

ackee suda 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
electerious/ackee:3.2.05e7173fa321c
mongoose@6.0.6
6.13.9

Open the chart page →

1,602
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
mongoose@4.13.14
6.13.9

Open the chart page →

25,443
openhab-cloudandibraeuVerified publisher1.2.61 of 1See more

openhab-cloud andibraeu 1.2.6

1 of the 1 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
openhab/openhab-cloud:a8138a329dd2bac8c4b
mongoose@5.13.15
6.13.9

Open the chart page →

3,437
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:api-latest7473d77448e1
mongoose@5.13.22
6.13.9

Open the chart page →

9,369
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
mongoose@6.3.4
6.13.9
assistiot/smart-orchestrator_enabler:latest89f37e88c871
mongoose@6.3.4
6.13.9
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
mongoose@6.3.4
6.13.9

Open the chart page →

45,363
dumpstoredumpstore0.1.11 of 2See more

dumpstore dumpstore 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
mongoose@8.16.1
8.22.1

Open the chart page →

4,251
backend-charteks-3-tier-app-chart0.1.01 of 1See more

backend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
arfath29/3-tier-app-backend:latestee0750b18406
mongoose@5.12.14
6.13.9

Open the chart page →

1,693
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-user-service:1.049e164a9a439
mongoose@6.13.8
6.13.9

Open the chart page →

7,691
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
mongoose@7.6.3
7.8.9

Open the chart page →

64,489
iotagent-jsonfiware0.1.21 of 1See more

iotagent-json fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
fiware/iotagent-json:3.1.0879b21a0d36d
mongoose@5.13.20
6.13.9

Open the chart page →

937
iotagent-ulfiware0.1.21 of 1See more

iotagent-ul fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
fiware/iotagent-ul:1.14.0fe11f55a926d
mongoose@5.7.5
6.13.9

Open the chart page →

3,337
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
governify/registry:v3.4.0d3f37f4f8168
mongoose@5.12.6
6.13.9

Open the chart page →

22,512
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
governify/registry:v3.4.0d3f37f4f8168
mongoose@5.12.6
6.13.9

Open the chart page →

24,319
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
mongoose@8.12.1
8.22.1

Open the chart page →

2,950
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
mongoose@8.8.0
8.22.1

Open the chart page →

3,154
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
mongoose@5.7.5
6.13.9

Open the chart page →

6,454
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
mongoose@6.12.3
6.13.9

Open the chart page →

22,589
iotmmontesVerified publisher0.3.21 of 7See more

iot mmontes 0.3.2

1 of the 7 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
mongoose@5.13.16
6.13.9

Open the chart page →

10,608
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
mongoose@5.12.9
6.13.9

Open the chart page →

12,108
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
mongoose@8.17.0
8.22.1

Open the chart page →

14,809
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
mongoose@5.12.9
6.13.9

Open the chart page →

19,226
reporting-aggregator-svcmojaloop1.0.71 of 1See more

reporting-aggregator-svc mojaloop 1.0.7

1 of the 1 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
mongoose@8.17.0
8.22.1

Open the chart page →

800
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
moreillon/camera-proxy:latestce60056b50c2
mongoose@6.13.2
6.13.9

Open the chart page →

11,643
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
mongoose@6.4.4
6.13.9

Open the chart page →

10,959
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
mongoose@5.13.21
6.13.9

Open the chart page →

25,704
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
mongoose@8.17.0
8.22.1

Open the chart page →

2,370
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
mongoose@5.13.9
6.13.9

Open the chart page →

9,968
stateful-data-generatortalhajuikar-helm-charts0.1.21 of 2See more

stateful-data-generator talhajuikar-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
mongoose@7.8.7
7.8.9

Open the chart page →

4,860
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
mongoose@6.4.3
6.13.9

Open the chart page →

4,017
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
mongoose@5.13.15
6.13.9

Open the chart page →

20,270
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42334.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
mongoose@5.12.5
6.13.9

Open the chart page →

6,881

Container images carrying it

37 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
governify/registry:v3.4.0d3f37f4f8168
mongoose@5.12.6
6.13.9
2
gradiant/open5gs-webui:2.7.5fbd10c017541
mongoose@5.13.20
6.13.9
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
mongoose@5.12.9
6.13.9
2
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
mongoose@8.17.0
8.22.1
2
alquimiaai/studio:certification38a1f0341982
mongoose@8.17.0
8.22.1
1
arfath29/3-tier-app-backend:latestee0750b18406
mongoose@5.12.14
6.13.9
1
assistiot/fl_orchestrator:api-latest7473d77448e1
mongoose@5.13.22
6.13.9
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
mongoose@6.3.4
6.13.9
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
mongoose@6.3.4
6.13.9
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
mongoose@6.3.4
6.13.9
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
mongoose@6.13.8
6.13.9
1
denisshav/backend:latest4cc8dc5a4499
mongoose@5.12.5
6.13.9
1
electerious/ackee:3.2.05e7173fa321c
mongoose@6.0.6
6.13.9
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
mongoose@7.6.3
7.8.9
1
fiware/iotagent-json:3.1.0879b21a0d36d
mongoose@5.13.20
6.13.9
1
fiware/iotagent-ul:1.14.0fe11f55a926d
mongoose@5.7.5
6.13.9
1
jayfong/yapi:1.10.2163e5d621910
mongoose@5.7.5
6.13.9
1
litlyx/litlyx-consumer:latest02225e77d316
mongoose@8.20.1
8.22.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
mongoose@8.20.1
8.22.1
1
litlyx/litlyx-producer:latest10407f36613f
mongoose@8.20.1
8.22.1
1
moreillon/camera-proxy:latestce60056b50c2
mongoose@6.13.2
6.13.9
1
moreillon/food-manager:lateste8fd856e593d
mongoose@6.13.2
6.13.9
1
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
mongoose@6.4.4
6.13.9
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
mongoose@5.13.21
6.13.9
1
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
mongoose@5.13.23
6.13.9
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
mongoose@5.13.15
6.13.9
1
polonel/trudesk:1.2.60cf6513f6fe3
mongoose@6.4.3
6.13.9
1
samajh/alprbackend:latestea742b4372ad
mongoose@5.13.15
6.13.9
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
mongoose@8.12.1
8.22.1
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
mongoose@8.9.5
8.22.1
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
mongoose@8.16.1
8.22.1
1
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
mongoose@5.13.16
6.13.9
1
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
mongoose@7.8.7
7.8.9
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
mongoose@6.12.3
6.13.9
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
mongoose@5.13.9
6.13.9
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
mongoose@4.13.14
6.13.9
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
mongoose@8.8.0
8.22.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.