StackRadar

CVE-2026-48758

Medium

Advisory

Published 26 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
362
of 17,781 indexed, latest versions
Container images
383
deployed by those charts
Fix available
1 of 1
affected package

@sigstore/core has DSSE payloadType type-binding failure

Carried by container images the latest versions of 362 of 17,781 indexed charts deploy, on 383 images.

Affected packageAffected versionsFixed inImages
@sigstore/corenpm1.0.0, 1.1.0, 2.0.0, 3.0.0+2 more3.2.1383
OSV records
GHSA-jfc7-64v2-mr8c

Charts affected

362 by stars
ChartLatestAffected imagesRadar Score
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
@sigstore/core@1.0.0
3.2.1

Open the chart page →

4,217
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
@sigstore/core@1.1.0
3.2.1

Open the chart page →

2,862
dumpstoredumpstore0.1.12 of 2See more

dumpstore dumpstore 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-48758.

Open the chart page →

4,251
dyff-frontenddyff-frontendVerified publisher0.20.11 of 1See more

dyff-frontend dyff-frontend 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
@sigstore/core@1.1.0
3.2.1

Open the chart page →

973
self-orchestratoreclipse-aeriosVerified publisher1.2.01 of 1See more

self-orchestrator eclipse-aerios 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
eclipseaerios/self-orchestrator:1.2.08b123bec5679
@sigstore/core@1.1.0
3.2.1

Open the chart page →

2,385
dashboardedu1.0.01 of 1See more

dashboard edu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
@sigstore/core@1.1.0
3.2.1

Open the chart page →

1,344
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
@sigstore/core@2.0.0
3.2.1

Open the chart page →

30,159
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
library/node:18-alpine8d6421d663b4
@sigstore/core@1.1.0
3.2.1

Open the chart page →

2,942
azuriteemberstackVerified publisher1.0.211 of 1See more

azurite emberstack 1.0.21

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
@sigstore/core@2.0.0
3.2.1

Open the chart page →

365
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
@sigstore/core@1.1.0
3.2.1

Open the chart page →

2,033
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
@sigstore/core@1.1.0
3.2.1

Open the chart page →

839
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
@sigstore/core@3.2.0
3.2.1

Open the chart page →

1,755
multichain-proxyethersphereVerified publisher0.1.01 of 1See more

multichain-proxy ethersphere 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ethersphere/multichain-proxy:0.0.261f5419afbcd
@sigstore/core@2.0.0
3.2.1

Open the chart page →

795
express-ts-app-helm-chartsexpress-ts-app-helm-chartsVerified publisher1.0.01 of 4See more

express-ts-app-helm-charts express-ts-app-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/marcuwynu23/express-typescript-sample:latest9ef671b78ea8
@sigstore/core@2.0.0
3.2.1

Open the chart page →

5,748
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
@sigstore/core@1.1.0
3.2.1

Open the chart page →

64,489
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
@sigstore/core@2.0.0
3.2.1

Open the chart page →

1,847
fdsc-dashboardfiware0.6.81 of 1See more

fdsc-dashboard fiware 0.6.8

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
@sigstore/core@1.1.0
3.2.1

Open the chart page →

705
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
@sigstore/core@2.0.0
3.2.1

Open the chart page →

1,489
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
@sigstore/core@2.0.0
3.2.1

Open the chart page →

4,650
flanksource-uiflanksourceVerified publisher1.4.3181 of 1See more

flanksource-ui flanksource 1.4.318

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.318891f21df54fb
@sigstore/core@2.0.0
3.2.1

Open the chart page →

2,558
mission-controlflanksourceVerified publisher0.1.3361 of 8See more

mission-control flanksource 0.1.336

1 of the 8 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
@sigstore/core@2.0.0
3.2.1

Open the chart page →

8,902
uptime-kumafluent-operatorVerified publisher0.1.01 of 1See more

uptime-kuma fluent-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
louislam/uptime-kuma:13d632903e6af
@sigstore/core@1.1.0
3.2.1

Open the chart page →

3,474
mod-graphqlfolio-org0.1.301 of 1See more

mod-graphql folio-org 0.1.30

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
folioci/mod-graphql:latestf0655a6a08fd
@sigstore/core@1.1.0
3.2.1

Open the chart page →

1,091
garge-appgargeVerified publisher0.1.461 of 1See more

garge-app garge 0.1.46

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
sondresjo/garge-app:v1.20.691767c10ad0e
@sigstore/core@2.0.0
3.2.1

Open the chart page →

1,842
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
@sigstore/core@1.1.0
3.2.1

Open the chart page →

12,958
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
@sigstore/core@3.1.0
3.2.1

Open the chart page →

4,259
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
@sigstore/core@1.1.0
3.2.1

Open the chart page →

2,973
glassflow-etlglassflowVerified publisher0.5.211 of 16See more

glassflow-etl glassflow 0.5.21

1 of the 16 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
@sigstore/core@1.1.0
3.2.1

Open the chart page →

12,056
opentelemetry-demogpg-dev0.33.83 of 27See more

opentelemetry-demo gpg-dev 0.33.8

3 of the 27 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
@sigstore/core@1.1.0
3.2.1
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
@sigstore/core@1.0.0
3.2.1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
@sigstore/core@1.1.0
3.2.1

Open the chart page →

49,025
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
@sigstore/core@1.1.0
3.2.1

Open the chart page →

2,950
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
@sigstore/core@2.0.0
3.2.1

Open the chart page →

9,047
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
@sigstore/core@2.0.0
3.2.1

Open the chart page →

3,806
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
@sigstore/core@1.1.0
3.2.1

Open the chart page →

948
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
@sigstore/core@1.1.0
3.2.1

Open the chart page →

3,451
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
@sigstore/core@2.0.0
3.2.1

Open the chart page →

778
affinehelmforgeVerified publisher1.0.01 of 3See more

affine helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
@sigstore/core@2.0.0
3.2.1

Open the chart page →

4,018
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
@sigstore/core@3.2.0
3.2.1

Open the chart page →

7,633
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
@sigstore/core@2.0.0
3.2.1

Open the chart page →

5,769
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
@sigstore/core@2.0.0
3.2.1

Open the chart page →

739
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
@sigstore/core@1.1.0
3.2.1

Open the chart page →

18,813
croniclehelmforgeVerified publisher1.1.101 of 1See more

cronicle helmforge 1.1.10

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
soulteary/cronicle:0.9.80ac2512fa6e39
@sigstore/core@1.1.0
3.2.1

Open the chart page →

1,271
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
library/ghost:6.62.0a7a268bbfb7f
@sigstore/core@2.0.0
3.2.1

Open the chart page →

2,463
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
@sigstore/core@3.1.0
3.2.1

Open the chart page →

11,042
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
@sigstore/core@2.0.0
3.2.1

Open the chart page →

9,653
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
@sigstore/core@2.0.0
3.2.1

Open the chart page →

6,012
uptime-kumahelmforgeVerified publisher1.5.121 of 1See more

uptime-kuma helmforge 1.5.12

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.33e24e96c89ef
@sigstore/core@2.0.0
3.2.1

Open the chart page →

30,099
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
@sigstore/core@1.0.0
3.2.1

Open the chart page →

25,017
self-learning-platformhelm-self-learning-platformVerified publisher1.1.01 of 1See more

self-learning-platform helm-self-learning-platform 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
devopsiaci/self-learning-platform:1.1.3d9441c931f75
@sigstore/core@3.1.0
3.2.1

Open the chart page →

1,468
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
@sigstore/core@1.1.0
3.2.1

Open the chart page →

3,614
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
@sigstore/core@1.1.0
3.2.1

Open the chart page →

3,407

Container images carrying it

383 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
gethue/hue:latest7d5c1b9f8a79
@sigstore/core@3.1.0
3.2.1
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
@sigstore/core@2.0.0
3.2.1
1
globalping/globalping-probe:latest8acbd23009fd
@sigstore/core@2.0.0
3.2.1
1
haohanyang/compass-web:0.5.054f2112602ee
@sigstore/core@3.2.0
3.2.1
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
@sigstore/core@1.1.0
3.2.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
@sigstore/core@2.0.0
3.2.1
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
@sigstore/core@1.1.0
3.2.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
@sigstore/core@1.1.0
3.2.1
1
ilum/marquez-web:0.53.2716437a51a6c
@sigstore/core@3.0.0
3.2.1
1
instill/console:0.68.54cd70e2df5c6
@sigstore/core@1.1.0
3.2.1
1
jaedb/iris:latest048cfbf58d57
@sigstore/core@1.1.0
3.2.1
1
jesec/flood:4.14.3c887dad96b40
@sigstore/core@2.0.0
3.2.1
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
@sigstore/core@1.1.0
3.2.1
1
jkroepke/github_exporter:1.8.03d850992786d
@sigstore/core@3.0.0
3.2.1
1
johly/airtrail:v3.11.19f702b91e0e7
@sigstore/core@2.0.0
3.2.1
1
joplin/server:3.0-beta52af57880c0e
@sigstore/core@1.1.0
3.2.1
1
kaushaln1/helm_node_app:lateste9f2d5dfdba0
@sigstore/core@1.1.0
3.2.1
1
laly9999/node-app:1dd0e503913e1
@sigstore/core@1.1.0
3.2.1
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
@sigstore/core@2.0.0
3.2.1
1
langgenius/dify-api:1.16.1dcefa5f7c47c
@sigstore/core@2.0.0
3.2.1
1
langgenius/dify-web:1.16.187dd47e4e28f
@sigstore/core@2.0.0
3.2.1
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
@sigstore/core@2.0.0
3.2.1
1
langgenius/dify-web:1.0.0d64914ff0d6d
@sigstore/core@1.1.0
3.2.1
1
lbenicio/helm-pilot:0.2.54594a2632510
@sigstore/core@2.0.0
3.2.1
1
lbenicio/stremio-web:latest732f9003de33
@sigstore/core@2.0.0
3.2.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
@sigstore/core@1.1.0
3.2.1
1
library/ghost:6.37.01ef2e532ca4d
@sigstore/core@2.0.0
3.2.1
1
library/ghost:6.25.12654b1e90413
@sigstore/core@2.0.0
3.2.1
1
library/ghost:6.41.129773d6be407
@sigstore/core@2.0.0
3.2.1
1
library/ghost:6.39.0-alpine77196da4b0df
@sigstore/core@2.0.0
3.2.1
1
library/ghost:6.62.0a7a268bbfb7f
@sigstore/core@2.0.0
3.2.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
@sigstore/core@2.0.0
3.2.1
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
@sigstore/core@1.1.0
3.2.1
1
library/node:22-bookworm-slim83f487e0a634
@sigstore/core@2.0.0
3.2.1
1
library/node:18-alpine8d6421d663b4
@sigstore/core@1.1.0
3.2.1
1
library/node:208f693eaa7e0a
@sigstore/core@1.1.0
3.2.1
1
lissy93/domain-locker:latestd3c95edc0a8b
@sigstore/core@1.1.0
3.2.1
1
lissy93/networking-toolbox:latest700862839553
@sigstore/core@2.0.0
3.2.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
@sigstore/core@3.1.0
3.2.1
1
litlyx/litlyx-consumer:latest02225e77d316
@sigstore/core@2.0.0
3.2.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
@sigstore/core@2.0.0
3.2.1
1
litlyx/litlyx-producer:latest10407f36613f
@sigstore/core@2.0.0
3.2.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
@sigstore/core@2.0.0
3.2.1
1
louislam/uptime-kuma:13d632903e6af
@sigstore/core@1.1.0
3.2.1
1
louislam/uptime-kuma:2.5.33e24e96c89ef
@sigstore/core@2.0.0
3.2.1
1
louislam/uptime-kuma:2.0.24c364ef96aad
@sigstore/core@1.1.0
3.2.1
1
louislam/uptime-kuma:2.4.091e963bfda56
@sigstore/core@2.0.0
3.2.1
1
louislam/uptime-kuma:1.23.1396510915e6be
@sigstore/core@1.0.0
3.2.1
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
@sigstore/core@1.1.0
3.2.1
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
@sigstore/core@1.0.0
3.2.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.