StackRadar

CVE-2026-4358

High

Advisory

Published 17 Mar 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
13
deployed by those charts
Fix available
2 of 3
affected packages

Memory safety issues in slot-based execution hash table spill

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 13 images.

Affected packageAffected versionsFixed inImages
mongodbbitnami7.0.5-3, 7.0.8-1, 7.0.14-1, 8.0.8-0+3 more7.0.317
MongoDB (R)bitnami7.0.5-3, 7.0.8-17.0.312
mongodbdeb1:3.6.3-0ubuntu1.4, 1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3no fix listed6
OSV records
BIT-mongodb-2026-4358UBUNTU-CVE-2026-4358

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
codefreshcodefresh-onpremOfficialVerified publisher2.12.131 of 42See more

codefresh codefresh-onprem 2.12.13

1 of the 42 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
mongodb@7.0.14-1
7.0.31

Open the chart page →

14,956
litmuslitmuschaos3.30.01 of 6See more

litmus litmuschaos 3.30.0

1 of the 6 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
mongodb@8.0.13-0
7.0.31

Open the chart page →

7,007
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
mongodb@1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
no fix listed

Open the chart page →

7,268
unifi-controllerqonstruktVerified publisher2.6.11 of 1See more

unifi-controller qonstrukt 2.6.1

1 of the 1 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:8.0.240ae315a3a456
mongodb@1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
no fix listed

Open the chart page →

10,469
unifigeek-cookbookVerified publisher5.1.31 of 1See more

unifi geek-cookbook 5.1.3

1 of the 1 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.4.162b3edc809a3ff
mongodb@1:3.6.3-0ubuntu1.4
no fix listed

Open the chart page →

11,839
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
mongodb@1:3.6.3-0ubuntu1.4
no fix listed

Open the chart page →

11,553
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
mongodb@8.0.10-1
7.0.31

Open the chart page →

4,238
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.5-debian-11-r66fe59ed5d79f
mongodb@7.0.5-3
MongoDB (R)@7.0.5-3
7.0.31
7.0.31

Open the chart page →

12,907
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
mongodb@1:3.6.3-0ubuntu1.4
no fix listed

Open the chart page →

11,553
mongodbcowboysysopVerified publisher15.1.51 of 1See more

mongodb cowboysysop 15.1.5

1 of the 1 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
mongodb@7.0.8-1
MongoDB (R)@7.0.8-1
7.0.31
7.0.31

Open the chart page →

6,161
unifiegebackVerified publisher2.1.61 of 1See more

unifi egeback 2.1.6

1 of the 1 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
mongodb@1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
no fix listed

Open the chart page →

7,268
unifik8sonlabVerified publisher0.3.71 of 1See more

unifi k8sonlab 0.3.7

1 of the 1 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
mongodb@1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
no fix listed

Open the chart page →

7,268
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
mongodb@1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
no fix listed

Open the chart page →

11,188
mongodbpetersandor14.1.81 of 1See more

mongodb petersandor 14.1.8

1 of the 1 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
bitnami/mongodb:8.0.8b3bd5b6be9a0
mongodb@8.0.8-0
7.0.31

Open the chart page →

4,109
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:latestb0652af9c8d0
mongodb@8.0.11-0
7.0.31

Open the chart page →

5,066
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-4358.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
mongodb@1:3.6.3-0ubuntu1.4
no fix listed

Open the chart page →

14,493

Container images carrying it

13 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
jacobalberty/unifi:v10.0.162896c0ab82d33
mongodb@1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
no fix listed
3
mbentley/omada-controller:4.3f4e682274bed
mongodb@1:3.6.3-0ubuntu1.4
no fix listed
2
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
mongodb@7.0.14-1
7.0.31
1
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
mongodb@8.0.13-0
7.0.31
1
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
mongodb@7.0.8-1
MongoDB (R)@7.0.8-1
7.0.31
7.0.31
1
bitnamilegacy/mongodb:7.0.5-debian-11-r66fe59ed5d79f
mongodb@7.0.5-3
MongoDB (R)@7.0.5-3
7.0.31
7.0.31
1
bitnamilegacy/mongodb:latestb0652af9c8d0
mongodb@8.0.11-0
7.0.31
1
bitnami/mongodb:8.0.8b3bd5b6be9a0
mongodb@8.0.8-0
7.0.31
1
jacobalberty/unifi:v7.1.664a3616625dda
mongodb@1:3.6.3-0ubuntu1.4
no fix listed
1
jacobalberty/unifi:v7.4.162b3edc809a3ff
mongodb@1:3.6.3-0ubuntu1.4
no fix listed
1
linuxserver/unifi-controller:8.0.240ae315a3a456
mongodb@1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
no fix listed
1
linuxserver/unifi-controller:7.3.83ab105cc50322
mongodb@1:3.6.9+really3.6.8+90~g8e540c0b6d-0ubuntu5.3
no fix listed
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
mongodb@8.0.10-1
7.0.31
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.