StackRadar

CVE-2026-48779

High

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
443
of 17,781 indexed, latest versions
Container images
441
deployed by those charts
Fix available
1 of 2
affected packages

ws: Memory exhaustion DoS from tiny fragments and data chunks

Carried by container images the latest versions of 443 of 17,781 indexed charts deploy, on 441 images.

Affected packageAffected versionsFixed inImages
wsnpm1.1.0, 1.1.1, 1.1.2, 1.1.4+57 more5.2.5, 6.2.4, 7.5.11, 8.21.0441
node-wsdeb8.11.0+~cs13.7.3-1no fix listed2
OSV records
DEBIAN-CVE-2026-48779GHSA-96hv-2xvq-fx4p

Charts affected

443 by stars
ChartLatestAffected imagesRadar Score
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
ws@3.3.3
5.2.5

Open the chart page →

10,311
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
ws@1.1.2
5.2.5

Open the chart page →

5,209
kubeviouskubevious1.2.24 of 7See more

kubevious kubevious 1.2.2

4 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
kubevious/backend:1.2.22d9ba6eb46b6
ws@8.13.0
8.21.0
kubevious/collector:1.2.1f58226f9d84e
ws@8.11.0
8.21.0
kubevious/guard:1.2.19bf567704de2
ws@8.2.3
8.21.0
kubevious/parser:1.2.299ae7a5168c2
ws@8.13.0
8.21.0

Open the chart page →

14,204
bitwarden-crd-operatorlerentisVerified publisher0.18.01 of 1See more

bitwarden-crd-operator lerentis 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
ws@8.20.0
8.21.0

Open the chart page →

2,003
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
ws@8.11.0
8.21.0

Open the chart page →

2,635
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ws@1.1.5
5.2.5

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
ws@7.4.6
7.5.11
kobotoolbox/kpi:2.022.24dbcacc01bccd4
ws@8.5.0
8.21.0

Open the chart page →

18,517
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
ws@7.5.9
7.5.11

Open the chart page →

7,776
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
ws@7.4.6
7.5.11

Open the chart page →

24,488
soketisoketi2.0.01 of 1See more

soketi soketi 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/soketi/soketi:1.6-16-debian713223456cf1
ws@7.5.9
7.5.11

Open the chart page →

1,636
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
thmmniii/fbs-collab:v1.27.15d389e3c5ce6
ws@8.18.0
8.21.0

Open the chart page →

28,534
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
ws@8.18.0
8.21.0

Open the chart page →

8,491
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
ws@5.2.4
5.2.5

Open the chart page →

4,016
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
ws@7.4.6
7.5.11

Open the chart page →

2,851
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
ws@7.3.1
7.5.11

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
ws@7.3.1
7.5.11

Open the chart page →

10,730
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
ws@8.16.0
8.21.0

Open the chart page →

1,843
maildevchristianhuthVerified publisher1.6.01 of 1See more

maildev christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
maildev/maildev:2.2.1180ef51f65ee
ws@8.18.0
8.21.0

Open the chart page →

1,143
skoonerchristianhuthVerified publisher0.4.01 of 1See more

skooner christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
ws@8.14.1
8.21.0

Open the chart page →

1,341
data-fairdata354-helmVerified publisher1.1.26 of 12See more

data-fair data354-helm 1.1.2

6 of the 12 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
koumoul/capture:17108d47be3b2
ws@6.2.1
6.2.4
ghcr.io/data-fair/data-fair:3cc9498b64b5b
ws@7.5.9
7.5.11
ghcr.io/data-fair/metrics:0a8d40779eeae
ws@7.5.5
7.5.11
ghcr.io/data-fair/notify:3c739b74dabb0
ws@7.5.10
7.5.11
ghcr.io/data-fair/processings:15a9216989707
ws@8.14.2
8.21.0
ghcr.io/data-fair/simple-directory:438a4f32fad82
ws@6.1.4
6.2.4

Open the chart page →

38,346
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
ws@7.4.6
7.5.11

Open the chart page →

5,056
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
ws@7.5.10
7.5.11

Open the chart page →

7,473
jellystatdjjudas21Verified publisher0.1.121 of 1See more

jellystat djjudas21 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
ws@8.20.1
8.21.0

Open the chart page →

1,722
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
ws@8.13.0
8.21.0

Open the chart page →

3,925
domain-lockerdomain-locker0.2.81 of 3See more

domain-locker domain-locker 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
lissy93/domain-locker:latestd3c95edc0a8b
ws@8.18.0
8.21.0

Open the chart page →

1,882
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
ws@7.5.10
7.5.11

Open the chart page →

31,510
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
ws@8.17.1
8.21.0

Open the chart page →

1,442
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
ws@8.18.0
8.21.0

Open the chart page →

11,458
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
taigaio/taiga-events:latest92fc0822564f
ws@7.4.6
7.5.11

Open the chart page →

8,496
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
ws@6.2.1
6.2.4

Open the chart page →

2,519
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
ws@8.5.0
8.21.0

Open the chart page →

4,260
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
ws@8.2.3
8.21.0

Open the chart page →

15,653
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
ws@7.4.3
7.5.11

Open the chart page →

4,405
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
ws@6.2.2
6.2.4

Open the chart page →

7,801
sendgeek-cookbookVerified publisher1.2.21 of 1See more

send geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
ws@7.5.7
7.5.11

Open the chart page →

1,148
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
ws@8.2.3
8.21.0

Open the chart page →

5,079
zigbee2mqttgeek-cookbookVerified publisher9.4.21 of 1See more

zigbee2mqtt geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
ws@7.4.5
7.5.11

Open the chart page →

2,173
globalpingglobalpingVerified publisher1.0.111 of 1See more

globalping globalping 1.0.11

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
globalping/globalping-probe:latest8acbd23009fd
ws@8.17.1
8.21.0

Open the chart page →

518
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
ws@8.11.0
8.21.0

Open the chart page →

4,196
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
ws@8.17.1
8.21.0

Open the chart page →

15,712
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
ws@7.4.6
7.5.11

Open the chart page →

17,284
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
ws@7.5.5
7.5.11

Open the chart page →

3,369
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
ws@6.2.2
6.2.4

Open the chart page →

3,143
difykubeblocksVerified publisher0.5.12 of 5See more

dify kubeblocks 0.5.1

2 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
ws@7.3.1
7.5.11
langgenius/dify-web:0.6.11a2a294743634
ws@7.5.9
7.5.11

Open the chart page →

20,403
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
litlyx/litlyx-dashboard:lateste64ff2d52385
ws@8.18.3
8.21.0

Open the chart page →

7,874
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
ws@6.2.1
6.2.4

Open the chart page →

5,940
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ws@5.2.2
5.2.5

Open the chart page →

19,187
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
ws@8.20.1
8.21.0

Open the chart page →

2,575
open-api-discoveryopen-api-discoveryVerified publisher0.1.11 of 1See more

open-api-discovery open-api-discovery 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
lukasreining/open-api-schema-collector:0.1.050e021c42e33
ws@7.5.9
7.5.11

Open the chart page →

2,473
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
ws@8.17.1
8.21.0

Open the chart page →

6,883

Container images carrying it

441 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
arturisimo/server-urjc:v1.0d8dc4430531e
ws@5.2.3
5.2.5
1
assistiot/composite-services-manager_agent-http-mqtt:latest16d21bc5e42e
ws@7.5.9
7.5.11
1
assistiot/composite-services-manager_agent-mqtt-http:latest27d58b8911cd
ws@7.5.9
7.5.11
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
ws@7.3.1
7.5.11
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
ws@7.3.1
7.5.11
1
assistiot/fl_orchestrator:api-latest7473d77448e1
ws@7.5.9
7.5.11
1
assistiot/open_api_frontend:1.0.1f11d82defc70
ws@7.5.9
7.5.11
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
ws@7.5.8
7.5.11
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
ws@7.5.8
7.5.11
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
ws@7.5.8
7.5.11
1
baserow/baserow:1.30.1df0c42eb67e8
ws@7.5.9
7.5.11
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
ws@7.4.3
7.5.11
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
ws@8.11.0
8.21.0
1
bluerange/bluerange-mosquitto:25f1bfbba84832
ws@7.5.10
7.5.11
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
ws@7.4.6
7.5.11
1
budibase/apps:3.41.344fe6feab985
ws@8.18.3
8.21.0
1
catalysm/csmm:latestf003b35f54d9
ws@7.4.6
7.5.11
1
ccjacobs14/amazon:59a9b14a6f09e
ws@8.13.0
8.21.0
1
chainsafe/lodestar:latest5593f6e97912
ws@8.18.3
8.21.0
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
ws@8.5.0
8.21.0
1
chatwoot/chatwoot:v4.15.167ebc751c171
ws@6.2.1
6.2.4
1
chocobozzz/peertube:v8.1.5052712130691
ws@8.19.0
8.21.0
1
cnieg/maildev:v1.1.998ee05668915
ws@6.1.4
6.2.4
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
ws@8.2.3
8.21.0
1
codercom/code-server:4.11.0-debian1e2cc688008e
ws@8.2.0
8.21.0
1
codercom/code-server:3.10.247605610ad8d
ws@7.4.5
7.5.11
1
codetogether/codetogether:latest4348c8a38752
ws@7.5.10
7.5.11
1
coldatom/containers-security-api:latesteae9e82da080
ws@8.12.0
8.21.0
1
coldatom/containers-security-front:latest7c2fbbb41bcf
ws@8.12.0
8.21.0
1
conduction/conduction-ui-app:devd591f5e6f2a9
ws@6.2.1
6.2.4
1
contane/foreman:0.5.2efb98bdcc4e9
ws@8.18.2
8.21.0
1
countly/api:25.05.4f4cc7447c4f5
ws@8.8.1
8.21.0
1
countly/countly-server:25.05.4e3c238248f99
ws@8.8.1
8.21.0
1
cryptexlabs/authf:0.12.11189c07411d7c
ws@7.5.3
7.5.11
1
cspconsole/report-processor:1.0.279a2d8840bfdf
ws@7.5.10
7.5.11
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
ws@8.20.1
8.21.0
1
dacinfomotion/h2p:latest68fa393b472c
ws@8.13.0
8.21.0
1
datarhei/restreamer:0.6.4655e12f9eeed
ws@7.2.3
7.5.11
1
davdiv/musicociel:deva85f99be882c
ws@8.16.0
8.21.0
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
ws@5.2.2
5.2.5
1
decayofmind/hubot:3.3.21e18e92fe694
ws@1.1.5
5.2.5
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
ws@7.5.10
7.5.11
1
dgtlmoon/sockpuppetbrowser:latestf166a963b550
ws@8.4.2
8.21.0
1
directus/directus:12.0.29c8470ea465c
ws@7.5.10
7.5.11
1
directus/directus:11.1.0e3c8bb975350
ws@8.18.0
8.21.0
1
diygod/rsshub:2025-11-097a6312cac0d5
ws@8.18.3
8.21.0
1
drumsergio/lynxprompt:2.0.75c6afb6679301
ws@8.20.0
8.21.0
1
electerious/ackee:3.2.05e7173fa321c
ws@7.4.5
7.5.11
1
enketo/enketo-express:3.0.4dcad9c2273f6
ws@7.4.6
7.5.11
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
ws@1.1.5
5.2.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.