StackRadar

CVE-2026-44979

Medium

Advisory

Published 27 May 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
30
of 17,781 indexed, latest versions
Container images
25
deployed by those charts
Fix available
1 of 1
affected package

@hapi/wreck leaks sensitive `Proxy-Authorization` header across cross-hostname redirects

Carried by container images the latest versions of 30 of 17,781 indexed charts deploy, on 25 images.

Affected packageAffected versionsFixed inImages
@hapi/wrecknpm15.0.1, 15.1.0, 17.1.0, 17.2.0+2 more18.1.125
OSV records
GHSA-vhjm-w67q-g75c

Charts affected

30 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
@hapi/wreck@17.2.0
18.1.1

Open the chart page →

11,384
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
@hapi/wreck@17.2.0
18.1.1

Open the chart page →

6,168
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
@hapi/wreck@17.2.0
18.1.1

Open the chart page →

10,530
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
@hapi/wreck@15.1.0
18.1.1

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
@hapi/wreck@15.1.0
18.1.1

Open the chart page →

10,730
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
@hapi/wreck@17.2.0
18.1.1

Open the chart page →

1,843
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
ghcr.io/data-fair/simple-directory:438a4f32fad82
@hapi/wreck@15.1.0
18.1.1

Open the chart page →

38,346
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
@hapi/wreck@17.1.0
18.1.1

Open the chart page →

17,284
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
@hapi/wreck@17.1.0
18.1.1

Open the chart page →

6,879
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
@hapi/wreck@15.1.0
18.1.1

Open the chart page →

5,806
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
@hapi/wreck@17.2.0
18.1.1

Open the chart page →

13,852
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
@hapi/wreck@17.1.0
18.1.1

Open the chart page →

34,754
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
@hapi/wreck@15.0.1
18.1.1

Open the chart page →

7,929
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
@hapi/wreck@15.1.0
18.1.1

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
@hapi/wreck@15.1.0
18.1.1

Open the chart page →

10,603
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@hapi/wreck@17.1.0
18.1.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/wreck@15.1.0
18.1.1

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@hapi/wreck@17.1.0
18.1.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/wreck@15.1.0
18.1.1

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
@hapi/wreck@17.1.0
18.1.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/wreck@15.1.0
18.1.1

Open the chart page →

12,108
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
@hapi/wreck@18.1.0
18.1.1

Open the chart page →

2,457
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
@hapi/wreck@18.1.0
18.1.1
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
@hapi/wreck@18.1.0
18.1.1
mojaloop/role-assignment-service:v2.1.0def4bf273721
@hapi/wreck@18.0.1
18.1.1

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/wreck@15.1.0
18.1.1
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
@hapi/wreck@17.1.0
18.1.1

Open the chart page →

11,479
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@hapi/wreck@17.1.0
18.1.1
mojaloop/central-ledger:v13.14.01abc8a7aa71c
@hapi/wreck@17.1.0
18.1.1
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/wreck@15.1.0
18.1.1
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
@hapi/wreck@17.1.0
18.1.1

Open the chart page →

19,226
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
@hapi/wreck@18.1.0
18.1.1

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
@hapi/wreck@18.1.0
18.1.1

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
@hapi/wreck@18.0.1
18.1.1

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
@hapi/wreck@18.1.0
18.1.1

Open the chart page →

2,457
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
@hapi/wreck@17.2.0
18.1.1

Open the chart page →

5,484
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
@hapi/wreck@18.1.0
18.1.1

Open the chart page →

6,285
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
@hapi/wreck@15.1.0
18.1.1

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-44979.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
@hapi/wreck@17.2.0
18.1.1

Open the chart page →

9,381

Container images carrying it

25 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/wreck@15.1.0
18.1.1
5
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@hapi/wreck@17.1.0
18.1.1
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
@hapi/wreck@15.1.0
18.1.1
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
@hapi/wreck@17.1.0
18.1.1
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
@hapi/wreck@17.1.0
18.1.1
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
@hapi/wreck@18.1.0
18.1.1
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
@hapi/wreck@18.1.0
18.1.1
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
@hapi/wreck@18.0.1
18.1.1
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
@hapi/wreck@18.1.0
18.1.1
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
@hapi/wreck@15.1.0
18.1.1
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
@hapi/wreck@15.0.1
18.1.1
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
@hapi/wreck@15.1.0
18.1.1
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
@hapi/wreck@15.1.0
18.1.1
1
library/kibana:7.17.150172f1c538e7
@hapi/wreck@17.1.0
18.1.1
1
library/kibana:8.18.004c0fc150f3a
@hapi/wreck@18.1.0
18.1.1
1
library/kibana:7.17.8c5781ba340ef
@hapi/wreck@17.1.0
18.1.1
1
library/kibana:7.17.3e2e2031c15be
@hapi/wreck@17.1.0
18.1.1
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
@hapi/wreck@17.2.0
18.1.1
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
@hapi/wreck@17.2.0
18.1.1
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
@hapi/wreck@17.2.0
18.1.1
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
@hapi/wreck@17.2.0
18.1.1
1
wazuh/wazuh-dashboard:4.4.11787550d2358
@hapi/wreck@17.2.0
18.1.1
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
@hapi/wreck@17.2.0
18.1.1
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
@hapi/wreck@17.2.0
18.1.1
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
@hapi/wreck@15.1.0
18.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.