StackRadar

CVE-2026-45736

High

Advisory

Published 15 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
257
of 17,781 indexed, latest versions
Container images
248
deployed by those charts
Fix available
1 of 2
affected packages

ws: Uninitialized memory disclosure

Carried by container images the latest versions of 257 of 17,781 indexed charts deploy, on 248 images.

Affected packageAffected versionsFixed inImages
node-wsdeb8.11.0+~cs13.7.3-1no fix listed2
wsnpm8.2.0, 8.2.3, 8.3.0, 8.4.2+20 more8.20.1248
OSV records
DEBIAN-CVE-2026-45736GHSA-58qx-3vcg-4xpx

Charts affected

257 by stars
ChartLatestAffected imagesRadar Score
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
ws@8.20.0
8.20.1

Open the chart page →

2,076
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
ws@8.11.0
8.20.1

Open the chart page →

3,031
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
ws@8.18.0
8.20.1

Open the chart page →

5,984
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
ws@8.18.0
8.20.1

Open the chart page →

6,285
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
ws@8.11.0
8.20.1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
ws@8.11.0
8.20.1

Open the chart page →

16,083
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
ws@8.18.0
8.20.1

Open the chart page →

9,381
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-45736.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
ws@8.4.2
8.20.1

Open the chart page →

1,589

Container images carrying it

248 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
etherpad/etherpad:2.7.2b723fe5f2594
ws@8.18.3
8.20.1
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
ws@8.18.1
8.20.1
1
ethpandaops/ethereumjs:masterfb84b718500f
ws@8.17.1
8.20.1
1
evoapicloud/evolution-api:latest966625532d90
ws@8.17.1
8.20.1
1
fiware/idm:8.3.3a1b6ed4ae84f
ws@8.13.0
8.20.1
1
fosrl/pangolin:1.13.0c32ad797ab96
ws@8.18.3
8.20.1
1
glenndehaan/api-mapper:latest6ff6310683bf
ws@8.16.0
8.20.1
1
glenndehaan/kube-hook:latest0a7116f48bfe
ws@8.18.0
8.20.1
1
globalping/globalping-probe:latest8acbd23009fd
ws@8.17.1
8.20.1
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
ws@8.11.0
8.20.1
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ws@8.13.0
8.20.1
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
ws@8.13.0
8.20.1
1
heywood8/redisinsight:2.28.00bc9ab313d37
ws@8.11.0
8.20.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
ws@8.17.1
8.20.1
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
ws@8.6.0
8.20.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ws@8.17.1
8.20.1
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
ws@8.8.1
8.20.1
1
jakowenko/double-take:1.6.0b858bac9e32a
ws@8.2.3
8.20.1
1
joplin/server:3.0-beta52af57880c0e
ws@8.11.0
8.20.1
1
joplin/server:2.14.2-betab87564ef34e9
ws@8.13.0
8.20.1
1
journeyapps/powersync-service:latestbf46f66e5dcc
ws@8.18.0
8.20.1
1
keyoxide/keyoxide:stable96f27a71269d
ws@8.5.0
8.20.1
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
ws@8.5.0
8.20.1
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ws@8.18.3
8.20.1
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
ws@8.8.1
8.20.1
1
kubebb/component-store:latestfd8ecbd73213
ws@8.14.2
8.20.1
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
ws@8.17.0
8.20.1
1
kubevious/backend:1.2.22d9ba6eb46b6
ws@8.13.0
8.20.1
1
kubevious/collector:1.2.1f58226f9d84e
ws@8.11.0
8.20.1
1
kubevious/guard:1.2.19bf567704de2
ws@8.2.3
8.20.1
1
kubevious/parser:1.2.299ae7a5168c2
ws@8.13.0
8.20.1
1
kyleslugg/klusterview:latestba8c36dfdfbd
ws@8.13.0
8.20.1
1
kyso/kyso-front:lateste52595c5c16f
ws@8.11.0
8.20.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ws@8.18.0
8.20.1
1
library/ghost:6.37.01ef2e532ca4d
ws@8.20.0
8.20.1
1
library/ghost:6.25.12654b1e90413
ws@8.18.3
8.20.1
1
library/ghost:6.41.129773d6be407
ws@8.20.0
8.20.1
1
library/ghost:4.37.0767230c0f263
ws@8.5.0
8.20.1
1
library/ghost:6.39.0-alpine77196da4b0df
ws@8.20.0
8.20.1
1
library/ghost:5.79.083f7bf209844
ws@8.11.0
8.20.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
ws@8.18.3
8.20.1
1
library/kibana:7.17.150172f1c538e7
ws@8.14.2
8.20.1
1
library/kibana:8.18.004c0fc150f3a
ws@8.18.0
8.20.1
1
library/kibana:7.17.8c5781ba340ef
ws@8.9.0
8.20.1
1
linuxserver/code-server:4.10.1a5e43a05ae79
ws@8.2.0
8.20.1
1
lissy93/dashy:2.0.51991f7be5ed0
ws@8.3.0
8.20.1
1
lissy93/domain-locker:latestd3c95edc0a8b
ws@8.18.0
8.20.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
ws@8.18.3
8.20.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
ws@8.18.3
8.20.1
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
ws@8.11.0
8.20.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.