StackRadar

CVE-2026-45736

High

Advisory

Published 15 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
257
of 17,781 indexed, latest versions
Container images
248
deployed by those charts
Fix available
1 of 2
affected packages

ws: Uninitialized memory disclosure

Carried by container images the latest versions of 257 of 17,781 indexed charts deploy, on 248 images.

Affected packageAffected versionsFixed inImages
node-wsdeb8.11.0+~cs13.7.3-1no fix listed2
wsnpm8.2.0, 8.2.3, 8.3.0, 8.4.2+20 more8.20.1248
OSV records
DEBIAN-CVE-2026-45736GHSA-58qx-3vcg-4xpx

Charts affected

257 by stars
ChartLatestAffected imagesRadar Score
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
ws@8.13.0
8.20.1

Open the chart page →

9,783
k8s-jacoco-operatork8s-jacoco-operator0.4.01 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

1 of the 4 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
ws@8.13.0
8.20.1

Open the chart page →

2,437
k8s-mutating-webhookk8s-mutating-webhook0.3.01 of 2See more

k8s-mutating-webhook k8s-mutating-webhook 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/k8s-mutating-webhook:mainaaab005242ae
ws@8.13.0
8.20.1

Open the chart page →

2,009
zwave-js-uik8sonlabVerified publisher0.7.121 of 1See more

zwave-js-ui k8sonlab 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
zwavejs/zwave-js-ui:11.22.314d018bb689e
ws@8.17.1
8.20.1

Open the chart page →

973
k8s-validating-webhookk8s-validating-webhook0.4.01 of 2See more

k8s-validating-webhook k8s-validating-webhook 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/k8s-validating-webhook:main8344061b2f22
ws@8.13.0
8.20.1

Open the chart page →

2,009
skoonerkfirfer0.0.61 of 1See more

skooner kfirfer 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
ws@8.14.1
8.20.1

Open the chart page →

1,341
redisinsightklicktippVerified publisher0.5.01 of 1See more

redisinsight klicktipp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
redis/redisinsight:3.2.055542a762210
ws@8.17.1
8.20.1

Open the chart page →

1,290
visual-regression-trackerkokuwa5.1.01 of 4See more

visual-regression-tracker kokuwa 5.1.0

1 of the 4 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
visualregressiontracker/api:5.0.11941aeb8c8bf9
ws@8.17.1
8.20.1

Open the chart page →

9,098
kubeflowkromanow94-kubeflow0.5.11 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

1 of the 30 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
ws@8.17.0
8.20.1

Open the chart page →

70,530
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
ws@8.5.0
8.20.1

Open the chart page →

4,230
pangolinkrzwiatrzyk0.11.01 of 1See more

pangolin krzwiatrzyk 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
fosrl/pangolin:1.13.0c32ad797ab96
ws@8.18.3
8.20.1

Open the chart page →

3,441
component-storekubebb0.0.231 of 1See more

component-store kubebb 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
kubebb/component-store:latestfd8ecbd73213
ws@8.14.2
8.20.1

Open the chart page →

2,178
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
kubebb/bff-server:v0.2.0-202312040fbb732379bc
ws@8.8.1
8.20.1

Open the chart page →

13,819
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
ws@8.20.0
8.20.1

Open the chart page →

2,756
homepagekubernetes-homelab-helm-chartsVerified publisher0.1.01 of 1See more

homepage kubernetes-homelab-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
ws@8.18.3
8.20.1

Open the chart page →

1,378
uptime-kumakubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

uptime-kuma kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.2.1-slim059b49d64739
ws@8.18.3
8.20.1

Open the chart page →

6,356
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
ws@8.11.0
8.20.1

Open the chart page →

2,685
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
ws@8.18.3
8.20.1

Open the chart page →

33,242
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
ws@8.18.2
8.20.1

Open the chart page →

37,942
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
ws@8.20.0
8.20.1

Open the chart page →

1,809
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ws@8.18.3
8.20.1

Open the chart page →

1,391
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
ws@8.18.3
8.20.1

Open the chart page →

33,242
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
ws@8.17.1
8.20.1

Open the chart page →

1,490
lynxpromptlynxpromptVerified publisher0.1.21 of 3See more

lynxprompt lynxprompt 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
ws@8.20.0
8.20.1

Open the chart page →

1,852
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
ws@8.16.0
8.20.1

Open the chart page →

9,774
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
ws@8.11.0
8.20.1

Open the chart page →

7,315
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
ws@8.17.1
8.20.1

Open the chart page →

9,668
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
ws@8.18.2
8.20.1

Open the chart page →

43,341
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ws@8.18.3
8.20.1

Open the chart page →

2,457
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ws@8.18.3
8.20.1

Open the chart page →

2,457
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
ws@8.11.0
8.20.1

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
ws@8.18.3
8.20.1

Open the chart page →

4,960
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
ws@8.2.3
8.20.1

Open the chart page →

6,608
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
ws@8.2.3
8.20.1

Open the chart page →

3,128
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
ws@8.13.0
8.20.1

Open the chart page →

2,116
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
ws@8.13.0
8.20.1

Open the chart page →

2,116
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
ws@8.13.0
8.20.1

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
ws@8.13.0
8.20.1

Open the chart page →

2,116
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ws@8.13.0
8.20.1

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
ws@8.3.0
8.20.1

Open the chart page →

3,269
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
ws@8.19.0
8.20.1

Open the chart page →

30,028
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
ws@8.20.0
8.20.1

Open the chart page →

1,166
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
ws@8.16.0
8.20.1

Open the chart page →

6,982
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
ws@8.19.0
8.20.1

Open the chart page →

2,383
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
ws@8.19.0
8.20.1

Open the chart page →

3,798
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
ws@8.13.0
8.20.1

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
ws@8.13.0
8.20.1

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
ws@8.13.0
8.20.1

Open the chart page →

15,187
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
ws@8.18.0
8.20.1

Open the chart page →

4,219
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
ws@8.18.3
8.20.1

Open the chart page →

2,421

Container images carrying it

248 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
etherpad/etherpad:2.7.2b723fe5f2594
ws@8.18.3
8.20.1
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
ws@8.18.1
8.20.1
1
ethpandaops/ethereumjs:masterfb84b718500f
ws@8.17.1
8.20.1
1
evoapicloud/evolution-api:latest966625532d90
ws@8.17.1
8.20.1
1
fiware/idm:8.3.3a1b6ed4ae84f
ws@8.13.0
8.20.1
1
fosrl/pangolin:1.13.0c32ad797ab96
ws@8.18.3
8.20.1
1
glenndehaan/api-mapper:latest6ff6310683bf
ws@8.16.0
8.20.1
1
glenndehaan/kube-hook:latest0a7116f48bfe
ws@8.18.0
8.20.1
1
globalping/globalping-probe:latest8acbd23009fd
ws@8.17.1
8.20.1
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
ws@8.11.0
8.20.1
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ws@8.13.0
8.20.1
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
ws@8.13.0
8.20.1
1
heywood8/redisinsight:2.28.00bc9ab313d37
ws@8.11.0
8.20.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
ws@8.17.1
8.20.1
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
ws@8.6.0
8.20.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ws@8.17.1
8.20.1
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
ws@8.8.1
8.20.1
1
jakowenko/double-take:1.6.0b858bac9e32a
ws@8.2.3
8.20.1
1
joplin/server:3.0-beta52af57880c0e
ws@8.11.0
8.20.1
1
joplin/server:2.14.2-betab87564ef34e9
ws@8.13.0
8.20.1
1
journeyapps/powersync-service:latestbf46f66e5dcc
ws@8.18.0
8.20.1
1
keyoxide/keyoxide:stable96f27a71269d
ws@8.5.0
8.20.1
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
ws@8.5.0
8.20.1
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ws@8.18.3
8.20.1
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
ws@8.8.1
8.20.1
1
kubebb/component-store:latestfd8ecbd73213
ws@8.14.2
8.20.1
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
ws@8.17.0
8.20.1
1
kubevious/backend:1.2.22d9ba6eb46b6
ws@8.13.0
8.20.1
1
kubevious/collector:1.2.1f58226f9d84e
ws@8.11.0
8.20.1
1
kubevious/guard:1.2.19bf567704de2
ws@8.2.3
8.20.1
1
kubevious/parser:1.2.299ae7a5168c2
ws@8.13.0
8.20.1
1
kyleslugg/klusterview:latestba8c36dfdfbd
ws@8.13.0
8.20.1
1
kyso/kyso-front:lateste52595c5c16f
ws@8.11.0
8.20.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ws@8.18.0
8.20.1
1
library/ghost:6.37.01ef2e532ca4d
ws@8.20.0
8.20.1
1
library/ghost:6.25.12654b1e90413
ws@8.18.3
8.20.1
1
library/ghost:6.41.129773d6be407
ws@8.20.0
8.20.1
1
library/ghost:4.37.0767230c0f263
ws@8.5.0
8.20.1
1
library/ghost:6.39.0-alpine77196da4b0df
ws@8.20.0
8.20.1
1
library/ghost:5.79.083f7bf209844
ws@8.11.0
8.20.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
ws@8.18.3
8.20.1
1
library/kibana:7.17.150172f1c538e7
ws@8.14.2
8.20.1
1
library/kibana:8.18.004c0fc150f3a
ws@8.18.0
8.20.1
1
library/kibana:7.17.8c5781ba340ef
ws@8.9.0
8.20.1
1
linuxserver/code-server:4.10.1a5e43a05ae79
ws@8.2.0
8.20.1
1
lissy93/dashy:2.0.51991f7be5ed0
ws@8.3.0
8.20.1
1
lissy93/domain-locker:latestd3c95edc0a8b
ws@8.18.0
8.20.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
ws@8.18.3
8.20.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
ws@8.18.3
8.20.1
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
ws@8.11.0
8.20.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.