StackRadar

CVE-2026-48038

Medium

Advisory

Published 11 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
80
of 17,781 indexed, latest versions
Container images
80
deployed by those charts
Fix available
1 of 1
affected package

joi has an uncaught RangeError on deeply nested input through recursive `link()` schemas

Carried by container images the latest versions of 80 of 17,781 indexed charts deploy, on 80 images.

Affected packageAffected versionsFixed inImages
joinpm6.10.1, 10.0.6, 10.6.0, 11.4.0+19 more17.13.4, 18.2.180
OSV records
GHSA-q7cg-457f-vx79

Charts affected

80 by stars
ChartLatestAffected imagesRadar Score
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
joi@17.4.2
17.13.4
mojaloop/event-sidecar:v11.0.189b8ab71b74b
joi@13.7.0
17.13.4

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
joi@17.4.0
17.13.4
mojaloop/event-sidecar:v11.0.189b8ab71b74b
joi@13.7.0
17.13.4

Open the chart page →

12,108
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
joi@18.0.1
18.2.1

Open the chart page →

2,457
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
joi@17.13.3
17.13.4
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
joi@17.13.3
17.13.4
mojaloop/role-assignment-service:v2.1.0def4bf273721
joi@17.12.0
17.13.4

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
joi@13.7.0
17.13.4
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
joi@17.4.0
17.13.4

Open the chart page →

11,479
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
joi@17.4.2
17.13.4
mojaloop/central-ledger:v13.14.01abc8a7aa71c
joi@17.4.0
17.13.4
mojaloop/event-sidecar:v11.0.189b8ab71b74b
joi@13.7.0
17.13.4
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
joi@17.4.0
17.13.4

Open the chart page →

19,226
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
joi@17.13.3
17.13.4

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
joi@17.13.3
17.13.4

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
joi@17.12.0
17.13.4

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
joi@18.0.1
18.2.1

Open the chart page →

2,457
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
joi@10.0.6
17.13.4
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
joi@10.6.0
17.13.4

Open the chart page →

7,048
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
joi@17.11.0
17.13.4

Open the chart page →

25,704
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
joi@17.7.0
17.13.4

Open the chart page →

30,363
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
joi@17.12.0
17.13.4

Open the chart page →

6,982
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
joi@14.3.1
17.13.4

Open the chart page →

71,208
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
joi@14.3.1
17.13.4

Open the chart page →

6,583
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
joi@17.11.0
17.13.4

Open the chart page →

6,282
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
joi@17.11.0
17.13.4

Open the chart page →

7,413
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
joi@17.13.1
17.13.4

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
joi@17.13.1
17.13.4

Open the chart page →

16,620
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
joi@14.3.1
17.13.4

Open the chart page →

4,744
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
joi@11.4.0
17.13.4

Open the chart page →

3,881
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
joi@14.3.1
17.13.4

Open the chart page →

6,881
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
joi@18.0.2
18.2.1

Open the chart page →

2,028
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
joi@17.13.3
17.13.4

Open the chart page →

4,768
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
joi@18.0.2
18.2.1

Open the chart page →

4,305
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
joi@14.3.1
17.13.4

Open the chart page →

5,484
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
joi@17.13.3
17.13.4

Open the chart page →

6,285
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
joi@13.7.0
17.13.4

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-48038.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
joi@14.3.1
17.13.4

Open the chart page →

9,381

Container images carrying it

80 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
neoskop/papergirl:3.2.67f52b5949f03
joi@17.12.0
17.13.4
1
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
joi@10.6.0
17.13.4
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
joi@13.7.0
17.13.4
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
joi@14.3.1
17.13.4
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
joi@14.3.1
17.13.4
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
joi@14.3.1
17.13.4
1
rocketadmin/rocketadmin:1.17.710955ef540b9
joi@18.1.2
18.2.1
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
joi@11.4.0
17.13.4
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
joi@17.4.1
17.13.4
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
joi@18.0.2
18.2.1
1
unleashorg/unleash-server:7.5.09adb37e399ba
joi@18.0.2
18.2.1
1
vcnngr/pnbackend:latesteaf44ad0ad1f
joi@17.13.3
17.13.4
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
joi@14.3.1
17.13.4
1
wazuh/wazuh-dashboard:4.4.11787550d2358
joi@13.7.0
17.13.4
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
joi@14.3.1
17.13.4
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
joi@14.3.1
17.13.4
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
joi@18.0.2
18.2.1
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
joi@6.10.1
17.13.4
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
joi@6.10.1
17.13.4
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
joi@6.10.1
17.13.4
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
joi@6.10.1
17.13.4
1
ghcr.io/exposr/exposrd:v0.12.0561c8f23bdb6
joi@17.6.0
17.13.4
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
joi@17.13.3
17.13.4
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
joi@17.11.0
17.13.4
1
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
joi@17.8.3
17.13.4
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
joi@17.8.4
17.13.4
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
joi@17.13.3
17.13.4
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
joi@17.11.0
17.13.4
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
joi@10.6.0
17.13.4
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
joi@11.4.0
17.13.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.