StackRadar

CVE-2026-45736

High

Advisory

Published 15 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
257
of 17,781 indexed, latest versions
Container images
248
deployed by those charts
Fix available
1 of 2
affected packages

ws: Uninitialized memory disclosure

Carried by container images the latest versions of 257 of 17,781 indexed charts deploy, on 248 images.

Affected packageAffected versionsFixed inImages
node-wsdeb8.11.0+~cs13.7.3-1no fix listed2
wsnpm8.2.0, 8.2.3, 8.3.0, 8.4.2+20 more8.20.1248
OSV records
DEBIAN-CVE-2026-45736GHSA-58qx-3vcg-4xpx

Charts affected

257 by stars
ChartLatestAffected imagesRadar Score
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
ws@8.13.0
8.20.1

Open the chart page →

5,141
containers-security-chartscontainers-security0.1.02 of 7See more

containers-security-charts containers-security 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
coldatom/containers-security-api:latesteae9e82da080
ws@8.12.0
8.20.1
coldatom/containers-security-front:latest7c2fbbb41bcf
ws@8.12.0
8.20.1

Open the chart page →

9,146
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
ws@8.18.0
8.20.1

Open the chart page →

14,559
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
ws@8.17.1
8.20.1

Open the chart page →

22,193
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
ws@8.18.0
8.20.1

Open the chart page →

4,551
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
ws@8.11.0
8.20.1

Open the chart page →

4,217
dumpstoredumpstore0.1.11 of 2See more

dumpstore dumpstore 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
ws@8.18.3
8.20.1

Open the chart page →

4,251
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
node-ws@8.11.0+~cs13.7.3-1
ws@8.11.0
no fix listed
8.20.1

Open the chart page →

9,244
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
ws@8.19.0
8.20.1

Open the chart page →

30,159
reddarkemmas-chartsVerified publisher0.0.21 of 1See more

reddark emmas-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/0xemma/reddark:main2a115e991894
ws@8.11.0
8.20.1

Open the chart page →

1,998
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
ws@8.18.3
8.20.1

Open the chart page →

1,755
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
ws@8.18.3
8.20.1

Open the chart page →

2,522
multichain-proxyethersphereVerified publisher0.1.01 of 1See more

multichain-proxy ethersphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ethersphere/multichain-proxy:0.0.261f5419afbcd
ws@8.18.1
8.20.1

Open the chart page →

795
evobotevobotVerified publisher0.1.11 of 1See more

evobot evobot 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
ws@8.14.2
8.20.1

Open the chart page →

2,987
exposrexposr0.12.01 of 1See more

exposr exposr 0.12.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/exposr/exposrd:v0.12.0561c8f23bdb6
ws@8.13.0
8.20.1

Open the chart page →

570
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
ws@8.13.0
8.20.1

Open the chart page →

3,159
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
louislam/uptime-kuma:13d632903e6af
ws@8.17.1
8.20.1

Open the chart page →

3,474
flamegabe565Verified publisher0.6.01 of 1See more

flame gabe565 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
pawelmalak/flame:multiarch2.3.19f88b17692a0
ws@8.13.0
8.20.1

Open the chart page →

2,172
galoy-paygaloymoney0.11.481 of 2See more

galoy-pay galoymoney 0.11.48

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
krtk6160/galoy-nostrdigest-pinnedcc82a694f818
ws@8.12.1
8.20.1

Open the chart page →

2,528
rtlgaloymoney0.4.31 of 2See more

rtl galoymoney 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.13.3e2195188a451
ws@8.11.0
8.20.1

Open the chart page →

2,090
galoy-paygaloymoney20.11.481 of 2See more

galoy-pay galoymoney2 0.11.48

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
krtk6160/galoy-nostrdigest-pinnedcc82a694f818
ws@8.12.1
8.20.1

Open the chart page →

2,528
rtlgaloymoney20.4.31 of 2See more

rtl galoymoney2 0.4.3

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
shahanafarooqui/rtl:0.13.3e2195188a451
ws@8.11.0
8.20.1

Open the chart page →

2,090
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
ws@8.2.3
8.20.1

Open the chart page →

12,222
puppeteergeek-cookbookVerified publisher1.2.21 of 1See more

puppeteer geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
ws@8.5.0
8.20.1

Open the chart page →

15,730
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
ws@8.14.2
8.20.1

Open the chart page →

34,754
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
ws@8.11.0
8.20.1

Open the chart page →

9,019
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
ws@8.18.0
8.20.1

Open the chart page →

2,973
api-mapperglenndehaanVerified publisher1.2.01 of 1See more

api-mapper glenndehaan 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
glenndehaan/api-mapper:latest6ff6310683bf
ws@8.16.0
8.20.1

Open the chart page →

1,158
kube-hookglenndehaanVerified publisher1.0.31 of 1See more

kube-hook glenndehaan 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
glenndehaan/kube-hook:latest0a7116f48bfe
ws@8.18.0
8.20.1

Open the chart page →

923
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
ws@8.9.0
8.20.1

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
ws@8.9.0
8.20.1

Open the chart page →

2,682
h2ph2pVerified publisher1.0.11 of 1See more

h2p h2p 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
dacinfomotion/h2p:latest68fa393b472c
ws@8.13.0
8.20.1

Open the chart page →

1,713
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
ws@8.18.0
8.20.1

Open the chart page →

2,950
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
ws@8.18.1
8.20.1

Open the chart page →

3,806
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ws@8.17.1
8.20.1

Open the chart page →

3,451
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
ws@8.19.0
8.20.1

Open the chart page →

778
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
ws@8.8.1
8.20.1

Open the chart page →

18,813
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
ws@8.17.1
8.20.1

Open the chart page →

1,271
uptime-kumahelmforgeVerified publisher1.5.121 of 1See more

uptime-kuma helmforge 1.5.12

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.33e24e96c89ef
ws@8.19.0
8.20.1

Open the chart page →

30,099
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
ws@8.6.0
8.20.1

Open the chart page →

25,017
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ws@8.17.1
8.20.1

Open the chart page →

3,614
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
ws@8.14.2
8.20.1

Open the chart page →

3,407
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
ws@8.18.0
8.20.1

Open the chart page →

11,812
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
ws@8.12.0
8.20.1

Open the chart page →

4,944
interlay-firesquidinterlay0.1.112 of 4See more

interlay-firesquid interlay 0.1.11

2 of the 4 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
ws@8.8.1
8.20.1
subsquid/substrate-explorer:firesquid0889a857f192
ws@8.12.0
8.20.1

Open the chart page →

4,667
keyoxide-webittrident-oss0.2.31 of 1See more

keyoxide-web ittrident-oss 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
keyoxide/keyoxide:stable96f27a71269d
ws@8.5.0
8.20.1

Open the chart page →

2,363
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
ws@8.20.0
8.20.1

Open the chart page →

3,436
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
ws@8.18.1
8.20.1

Open the chart page →

5,826
audiobookshelfk8s-home-lab-repo2.0.11 of 1See more

audiobookshelf k8s-home-lab-repo 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
ws@8.11.0
8.20.1

Open the chart page →

2,350
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
ws@8.20.0
8.20.1

Open the chart page →

3,092

Container images carrying it

248 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
etherpad/etherpad:2.7.2b723fe5f2594
ws@8.18.3
8.20.1
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
ws@8.18.1
8.20.1
1
ethpandaops/ethereumjs:masterfb84b718500f
ws@8.17.1
8.20.1
1
evoapicloud/evolution-api:latest966625532d90
ws@8.17.1
8.20.1
1
fiware/idm:8.3.3a1b6ed4ae84f
ws@8.13.0
8.20.1
1
fosrl/pangolin:1.13.0c32ad797ab96
ws@8.18.3
8.20.1
1
glenndehaan/api-mapper:latest6ff6310683bf
ws@8.16.0
8.20.1
1
glenndehaan/kube-hook:latest0a7116f48bfe
ws@8.18.0
8.20.1
1
globalping/globalping-probe:latest8acbd23009fd
ws@8.17.1
8.20.1
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
ws@8.11.0
8.20.1
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ws@8.13.0
8.20.1
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
ws@8.13.0
8.20.1
1
heywood8/redisinsight:2.28.00bc9ab313d37
ws@8.11.0
8.20.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
ws@8.17.1
8.20.1
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
ws@8.6.0
8.20.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ws@8.17.1
8.20.1
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
ws@8.8.1
8.20.1
1
jakowenko/double-take:1.6.0b858bac9e32a
ws@8.2.3
8.20.1
1
joplin/server:3.0-beta52af57880c0e
ws@8.11.0
8.20.1
1
joplin/server:2.14.2-betab87564ef34e9
ws@8.13.0
8.20.1
1
journeyapps/powersync-service:latestbf46f66e5dcc
ws@8.18.0
8.20.1
1
keyoxide/keyoxide:stable96f27a71269d
ws@8.5.0
8.20.1
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
ws@8.5.0
8.20.1
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ws@8.18.3
8.20.1
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
ws@8.8.1
8.20.1
1
kubebb/component-store:latestfd8ecbd73213
ws@8.14.2
8.20.1
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
ws@8.17.0
8.20.1
1
kubevious/backend:1.2.22d9ba6eb46b6
ws@8.13.0
8.20.1
1
kubevious/collector:1.2.1f58226f9d84e
ws@8.11.0
8.20.1
1
kubevious/guard:1.2.19bf567704de2
ws@8.2.3
8.20.1
1
kubevious/parser:1.2.299ae7a5168c2
ws@8.13.0
8.20.1
1
kyleslugg/klusterview:latestba8c36dfdfbd
ws@8.13.0
8.20.1
1
kyso/kyso-front:lateste52595c5c16f
ws@8.11.0
8.20.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ws@8.18.0
8.20.1
1
library/ghost:6.37.01ef2e532ca4d
ws@8.20.0
8.20.1
1
library/ghost:6.25.12654b1e90413
ws@8.18.3
8.20.1
1
library/ghost:6.41.129773d6be407
ws@8.20.0
8.20.1
1
library/ghost:4.37.0767230c0f263
ws@8.5.0
8.20.1
1
library/ghost:6.39.0-alpine77196da4b0df
ws@8.20.0
8.20.1
1
library/ghost:5.79.083f7bf209844
ws@8.11.0
8.20.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
ws@8.18.3
8.20.1
1
library/kibana:7.17.150172f1c538e7
ws@8.14.2
8.20.1
1
library/kibana:8.18.004c0fc150f3a
ws@8.18.0
8.20.1
1
library/kibana:7.17.8c5781ba340ef
ws@8.9.0
8.20.1
1
linuxserver/code-server:4.10.1a5e43a05ae79
ws@8.2.0
8.20.1
1
lissy93/dashy:2.0.51991f7be5ed0
ws@8.3.0
8.20.1
1
lissy93/domain-locker:latestd3c95edc0a8b
ws@8.18.0
8.20.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
ws@8.18.3
8.20.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
ws@8.18.3
8.20.1
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
ws@8.11.0
8.20.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.