StackRadar

CVE-2026-44578

High

Advisory

Published 11 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.6
base score, highest
EPSS
0.389
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
56
of 17,781 indexed, latest versions
Container images
57
deployed by those charts
Fix available
1 of 1
affected package

Next.js vulnerable to server-side request forgery in applications using WebSocket upgrades

Carried by container images the latest versions of 56 of 17,781 indexed charts deploy, on 57 images.

Affected packageAffected versionsFixed inImages
nextnpm13.5.2, 13.5.3, 13.5.6, 13.5.11+34 more15.5.16, 16.2.557
OSV records
GHSA-c4j6-fc7j-m34r

Charts affected

56 by stars
ChartLatestAffected imagesRadar Score
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-44578.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
next@13.5.3
15.5.16

Open the chart page →

2,969
radar-self-enrolment-uiradar-baseVerified publisher0.4.21 of 1See more

radar-self-enrolment-ui radar-base 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-44578.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
next@15.5.4
15.5.16

Open the chart page →

1,506
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-44578.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
next@14.2.25
15.5.16

Open the chart page →

5,338
saleor-appstrieb-work0.6.03 of 5See more

saleor-apps trieb-work 0.6.0

3 of the 5 container images this version deploys carry CVE-2026-44578.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
next@15.2.4
15.5.16
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
next@15.2.4
15.5.16
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
next@15.2.4
15.5.16

Open the chart page →

6,994
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-44578.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
next@13.5.11
15.5.16

Open the chart page →

2,789
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-44578.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
next@14.2.25
15.5.16

Open the chart page →

5,984

Container images carrying it

57 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
next@15.5.7
15.5.16
1
ghcr.io/umami-software/umami:3.1.0e3f80c0625aa
next@16.2.4
16.2.5
1
ghcr.io/wachd/wachd:0.4.1805b05c56da94
next@16.2.4
16.2.5
1
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
next@16.0.3
16.2.5
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
next@15.2.4
15.5.16
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
next@14.2.5
15.5.16
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
next@14.2.32
15.5.16
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.