StackRadar

CVE-2026-46378

High

Advisory

Published 19 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
6th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
5
of 17,781 indexed, latest versions
Container images
4
deployed by those charts
Fix available
1 of 2
affected packages

Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal

Carried by container images the latest versions of 5 of 17,781 indexed charts deploy, on 4 images.

Affected packageAffected versionsFixed inImages
github.com/tomwright/dasel/v3golangv3.4.13.10.11
github.com/tomwright/dasel/v2golangv2.4.1, v2.8.1no fix listed3
OSV records
GHSA-m6xr-fvfg-5g64GO-2026-5493

Charts affected

5 by stars
ChartLatestAffected imagesRadar Score
influxdb2influxdata2.1.21 of 1See more

influxdb2 influxdata 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-46378.

Container imageDigestPackageFixed in
library/influxdb:2.7.4-alpinea10d46445d68
github.com/tomwright/dasel/v2@v2.4.1
no fix listed

Open the chart page →

2,103
influxdbinfluxdb20.1.01 of 1See more

influxdb influxdb2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46378.

Container imageDigestPackageFixed in
library/influxdb:latestf75e48af0598
github.com/tomwright/dasel/v3@v3.4.1
3.10.1

Open the chart page →

2,333
scrutinykubernetes-homelab-helm-chartsVerified publisher0.2.21 of 3See more

scrutiny kubernetes-homelab-helm-charts 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-46378.

Container imageDigestPackageFixed in
library/influxdb:2.8571eb4514977
github.com/tomwright/dasel/v2@v2.8.1
no fix listed

Open the chart page →

5,500
influxdbmy-personal-influxdb20.1.01 of 1See more

influxdb my-personal-influxdb2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-46378.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
github.com/tomwright/dasel/v2@v2.8.1
no fix listed

Open the chart page →

3,867
speedtestsantisbon0.1.01 of 3See more

speedtest santisbon 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-46378.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
github.com/tomwright/dasel/v2@v2.8.1
no fix listed

Open the chart page →

12,668

Container images carrying it

4 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/influxdb:2.7b8d940ca9376
github.com/tomwright/dasel/v2@v2.8.1
no fix listed
2
library/influxdb:2.8571eb4514977
github.com/tomwright/dasel/v2@v2.8.1
no fix listed
1
library/influxdb:2.7.4-alpinea10d46445d68
github.com/tomwright/dasel/v2@v2.4.1
no fix listed
1
library/influxdb:latestf75e48af0598
github.com/tomwright/dasel/v3@v3.4.1
3.10.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.