StackRadar

CVE-2026-48758

Medium

Advisory

Published 26 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.4
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
362
of 17,781 indexed, latest versions
Container images
383
deployed by those charts
Fix available
1 of 1
affected package

@sigstore/core has DSSE payloadType type-binding failure

Carried by container images the latest versions of 362 of 17,781 indexed charts deploy, on 383 images.

Affected packageAffected versionsFixed inImages
@sigstore/corenpm1.0.0, 1.1.0, 2.0.0, 3.0.0+2 more3.2.1383
OSV records
GHSA-jfc7-64v2-mr8c

Charts affected

362 by stars
ChartLatestAffected imagesRadar Score
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
@sigstore/core@1.1.0
3.2.1

Open the chart page →

2,620
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
@sigstore/core@2.0.0
3.2.1

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
@sigstore/core@3.2.0
3.2.1

Open the chart page →

3,746
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
@sigstore/core@1.1.0
3.2.1

Open the chart page →

4,768
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
@sigstore/core@3.1.0
3.2.1

Open the chart page →

4,305
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
@sigstore/core@2.0.0
3.2.1

Open the chart page →

2,076
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
@sigstore/core@1.1.0
3.2.1

Open the chart page →

3,031
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
@sigstore/core@2.0.0
3.2.1

Open the chart page →

5,984
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
@sigstore/core@3.2.0
3.2.1

Open the chart page →

1,616
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
@sigstore/core@3.2.0
3.2.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
@sigstore/core@3.2.0
3.2.1

Open the chart page →

5,459
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48758.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
@sigstore/core@1.1.0
3.2.1

Open the chart page →

14,100

Container images carrying it

383 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/wachd/wachd:0.4.1805b05c56da94
@sigstore/core@2.0.0
3.2.1
1
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
@sigstore/core@3.0.0
3.2.1
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
@sigstore/core@1.1.0
3.2.1
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
@sigstore/core@2.0.0
3.2.1
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
@sigstore/core@1.1.0
3.2.1
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
@sigstore/core@2.0.0
3.2.1
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
@sigstore/core@2.0.0
3.2.1
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
@sigstore/core@2.0.0
3.2.1
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
@sigstore/core@2.0.0
3.2.1
1
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
@sigstore/core@2.0.0
3.2.1
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
@sigstore/core@1.1.0
3.2.1
1
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
@sigstore/core@2.0.0
3.2.1
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
@sigstore/core@3.1.0
3.2.1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
@sigstore/core@2.0.0
3.2.1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
@sigstore/core@1.1.0
3.2.1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
@sigstore/core@1.1.0
3.2.1
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
@sigstore/core@1.1.0
3.2.1
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
@sigstore/core@3.2.0
3.2.1
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
@sigstore/core@2.0.0
3.2.1
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
@sigstore/core@2.0.0
3.2.1
1
quay.io/mittwald/kube-mail:latest04f1099241fc
@sigstore/core@1.1.0
3.2.1
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
@sigstore/core@1.0.0
3.2.1
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
@sigstore/core@1.1.0
3.2.1
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
@sigstore/core@2.0.0
3.2.1
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
@sigstore/core@2.0.0
3.2.1
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
@sigstore/core@2.0.0
3.2.1
1
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
@sigstore/core@1.1.0
3.2.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
@sigstore/core@2.0.0
3.2.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
@sigstore/core@3.2.0
3.2.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
@sigstore/core@2.0.0
3.2.1
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
@sigstore/core@2.0.0
3.2.1
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
@sigstore/core@2.0.0
3.2.1
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
@sigstore/core@1.1.0
3.2.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.