StackRadar

CVE-2026-48068

High

Advisory

Published 11 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
78
of 17,781 indexed, latest versions
Container images
79
deployed by those charts
Fix available
1 of 1
affected package

@grpc/grpc-js: A malformed request can cause a server crash

Carried by container images the latest versions of 78 of 17,781 indexed charts deploy, on 79 images.

Affected packageAffected versionsFixed inImages
@grpc/grpc-jsnpm1.1.8, 1.3.2, 1.3.3, 1.4.2+31 more1.9.16, 1.10.12, 1.11.4, 1.12.7+2 more79
OSV records
GHSA-5375-pq7m-f5r2

Charts affected

78 by stars
ChartLatestAffected imagesRadar Score
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
@grpc/grpc-js@1.8.22
1.9.16

Open the chart page →

33,242
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
@grpc/grpc-js@1.4.4
1.9.16

Open the chart page →

29,588
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
@grpc/grpc-js@1.10.9
1.10.12

Open the chart page →

9,668
homarrmedia-servarrVerified publisher0.55.11 of 1See more

homarr media-servarr 0.55.1

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
@grpc/grpc-js@1.12.5
1.12.7

Open the chart page →

435
middleware-odigosmiddleware-labsVerified publisher0.2.411 of 6See more

middleware-odigos middleware-labs 0.2.41

1 of the 6 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
@grpc/grpc-js@1.8.11
1.9.16

Open the chart page →

8,370
middleware-visionmiddleware-labsVerified publisher0.2.651 of 6See more

middleware-vision middleware-labs 0.2.65

1 of the 6 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
@grpc/grpc-js@1.8.12
1.9.16

Open the chart page →

8,361
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
@grpc/grpc-js@1.14.0
1.14.4

Open the chart page →

2,457
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
@grpc/grpc-js@1.13.4
1.13.5
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
@grpc/grpc-js@1.13.4
1.13.5
mojaloop/role-assignment-service:v2.1.0def4bf273721
@grpc/grpc-js@1.9.14
1.9.16

Open the chart page →

14,809
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
@grpc/grpc-js@1.13.4
1.13.5

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
@grpc/grpc-js@1.13.4
1.13.5

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
@grpc/grpc-js@1.9.14
1.9.16

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
@grpc/grpc-js@1.14.0
1.14.4

Open the chart page →

2,457
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
@grpc/grpc-js@1.8.14
1.9.16

Open the chart page →

2,116
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
@grpc/grpc-js@1.8.14
1.9.16

Open the chart page →

2,116
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
@grpc/grpc-js@1.8.14
1.9.16

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
@grpc/grpc-js@1.8.14
1.9.16

Open the chart page →

2,116
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
@grpc/grpc-js@1.8.22
1.9.16

Open the chart page →

30,028
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
@grpc/grpc-js@1.13.4
1.13.5

Open the chart page →

68,240
routr-connectroutr0.4.35 of 10See more

routr-connect routr 0.4.3

5 of the 10 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
fonoster/routr-connect:2.13.6e8c84b5eaa67
@grpc/grpc-js@1.10.11
1.10.12
fonoster/routr-dispatcher:2.13.65f8f380dc174
@grpc/grpc-js@1.10.11
1.10.12
fonoster/routr-location:2.13.6051ba9c34ef5
@grpc/grpc-js@1.10.11
1.10.12
fonoster/routr-pgdata:2.13.6e4d5f5ff1945
@grpc/grpc-js@1.10.11
1.10.12
fonoster/routr-registry:2.13.6e27001f2813c
@grpc/grpc-js@1.10.11
1.10.12

Open the chart page →

11,021
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
@grpc/grpc-js@1.8.22
1.9.16

Open the chart page →

30,219
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
@grpc/grpc-js@1.7.3
1.9.16

Open the chart page →

4,744
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
@grpc/grpc-js@1.6.12
1.9.16

Open the chart page →

5,582
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
@grpc/grpc-js@1.13.4
1.13.5

Open the chart page →

1,313
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
@grpc/grpc-js@1.3.3
1.9.16

Open the chart page →

3,881
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
thingsboard/tb-js-executor:3.4.113e1eadf8ace
@grpc/grpc-js@1.6.7
1.9.16

Open the chart page →

25,394
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
@grpc/grpc-js@1.1.8
1.9.16

Open the chart page →

2,838
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
@grpc/grpc-js@1.8.22
1.9.16

Open the chart page →

6,285
workadventureworkadventure1.1.03 of 9See more

workadventure workadventure 1.1.0

3 of the 9 container images this version deploys carry CVE-2026-48068.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
@grpc/grpc-js@1.8.13
1.9.16
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
@grpc/grpc-js@1.8.13
1.9.16
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
@grpc/grpc-js@1.8.13
1.9.16

Open the chart page →

16,083

Container images carrying it

79 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
assistiot/dlt_api:2.0.0e36a8922fa0c
@grpc/grpc-js@1.9.13
1.9.16
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
@grpc/grpc-js@1.13.4
1.13.5
3
krtk6160/galoy-nostrcc82a694f818
@grpc/grpc-js@1.8.8
1.9.16
2
louislam/uptime-kuma:2.5.4917318f9d7be
@grpc/grpc-js@1.8.22
1.9.16
2
louislam/uptime-kuma:2.3.29aeb4e51d038
@grpc/grpc-js@1.8.22
1.9.16
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
@grpc/grpc-js@1.8.22
1.9.16
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
@grpc/grpc-js@1.13.4
1.13.5
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
@grpc/grpc-js@1.13.4
1.13.5
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
@grpc/grpc-js@1.9.14
1.9.16
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
@grpc/grpc-js@1.14.0
1.14.4
2
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
@grpc/grpc-js@1.14.3
1.14.4
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
@grpc/grpc-js@1.14.3
1.14.4
1
arturisimo/server-urjc:v1.0d8dc4430531e
@grpc/grpc-js@1.4.4
1.9.16
1
assistiot/dlt_api:2.1.0c8a170683be7
@grpc/grpc-js@1.4.2
1.9.16
1
ccjacobs14/amazon:59a9b14a6f09e
@grpc/grpc-js@1.8.14
1.9.16
1
codercom/code-server:4.11.0-debian1e2cc688008e
@grpc/grpc-js@1.6.12
1.9.16
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
@grpc/grpc-js@1.12.6
1.12.7
1
countly/api:25.05.4f4cc7447c4f5
@grpc/grpc-js@1.10.9
1.10.12
1
countly/countly-server:25.05.4e3c238248f99
@grpc/grpc-js@1.10.9
1.10.12
1
countly/frontend:25.05.42acbc11499b6
@grpc/grpc-js@1.10.9
1.10.12
1
cryptexlabs/authf:0.12.11189c07411d7c
@grpc/grpc-js@1.11.2
1.11.4
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
@grpc/grpc-js@1.8.0
1.9.16
1
fonoster/routr-connect:2.13.6e8c84b5eaa67
@grpc/grpc-js@1.10.11
1.10.12
1
fonoster/routr-dispatcher:2.13.65f8f380dc174
@grpc/grpc-js@1.10.11
1.10.12
1
fonoster/routr-location:2.13.6051ba9c34ef5
@grpc/grpc-js@1.10.11
1.10.12
1
fonoster/routr-pgdata:2.13.6e4d5f5ff1945
@grpc/grpc-js@1.10.11
1.10.12
1
fonoster/routr-registry:2.13.6e27001f2813c
@grpc/grpc-js@1.10.11
1.10.12
1
hugohg34/server:0.0.2503e5d8960ff
@grpc/grpc-js@1.4.4
1.9.16
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
@grpc/grpc-js@1.4.4
1.9.16
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
@grpc/grpc-js@1.10.8
1.10.12
1
library/ghost:5.79.083f7bf209844
@grpc/grpc-js@1.9.7
1.9.16
1
library/kibana:8.18.004c0fc150f3a
@grpc/grpc-js@1.8.22
1.9.16
1
linuxserver/code-server:4.10.1a5e43a05ae79
@grpc/grpc-js@1.6.12
1.9.16
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
@grpc/grpc-js@1.8.22
1.9.16
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
@grpc/grpc-js@1.7.3
1.9.16
1
louislam/uptime-kuma:13d632903e6af
@grpc/grpc-js@1.8.22
1.9.16
1
louislam/uptime-kuma:2.5.33e24e96c89ef
@grpc/grpc-js@1.8.22
1.9.16
1
louislam/uptime-kuma:2.0.24c364ef96aad
@grpc/grpc-js@1.8.22
1.9.16
1
louislam/uptime-kuma:2.4.091e963bfda56
@grpc/grpc-js@1.8.22
1.9.16
1
louislam/uptime-kuma:1.23.1396510915e6be
@grpc/grpc-js@1.7.3
1.9.16
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
@grpc/grpc-js@1.8.22
1.9.16
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
@grpc/grpc-js@1.7.3
1.9.16
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
@grpc/grpc-js@1.6.12
1.9.16
1
mitchxxx/amazon:214e72480ec63a
@grpc/grpc-js@1.8.14
1.9.16
1
n8nio/n8n:2.25.7761374d4eb84
@grpc/grpc-js@1.14.3
1.14.4
1
n8nio/n8n:1.86.08b39ed5a2de9
@grpc/grpc-js@1.13.2
1.13.5
1
n8nio/n8n:1.33.1dd171d45102a
@grpc/grpc-js@1.8.21
1.9.16
1
ooghenekaro/amazon:latest03394ba1d6d8
@grpc/grpc-js@1.8.14
1.9.16
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
@grpc/grpc-js@1.10.9
1.10.12
1
qxip/qryn:3.2.3977acc9c7a9fd
@grpc/grpc-js@1.11.1
1.11.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.