StackRadar

CVE-2026-48779

High

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
443
of 17,781 indexed, latest versions
Container images
441
deployed by those charts
Fix available
1 of 2
affected packages

ws: Memory exhaustion DoS from tiny fragments and data chunks

Carried by container images the latest versions of 443 of 17,781 indexed charts deploy, on 441 images.

Affected packageAffected versionsFixed inImages
wsnpm1.1.0, 1.1.1, 1.1.2, 1.1.4+57 more5.2.5, 6.2.4, 7.5.11, 8.21.0441
node-wsdeb8.11.0+~cs13.7.3-1no fix listed2
OSV records
DEBIAN-CVE-2026-48779GHSA-96hv-2xvq-fx4p

Charts affected

443 by stars
ChartLatestAffected imagesRadar Score
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
ws@7.5.10
7.5.11

Open the chart page →

1,809
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ws@8.18.3
8.21.0

Open the chart page →

1,391
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
ws@8.18.3
8.21.0

Open the chart page →

33,242
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
ws@8.17.1
8.21.0

Open the chart page →

1,490
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
ws@6.2.1
6.2.4

Open the chart page →

3,651
lynxpromptlynxpromptVerified publisher0.1.21 of 3See more

lynxprompt lynxprompt 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
ws@8.20.0
8.21.0

Open the chart page →

1,852
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
ws@8.16.0
8.21.0

Open the chart page →

9,774
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
ws@8.11.0
8.21.0

Open the chart page →

7,315
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
ws@6.2.2
6.2.4

Open the chart page →

5,287
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
ws@6.2.1
6.2.4

Open the chart page →

5,940
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
ws@5.2.3
5.2.5

Open the chart page →

29,588
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
ws@8.17.1
8.21.0

Open the chart page →

9,668
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
ws@7.3.1
7.5.11

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
ws@7.3.1
7.5.11

Open the chart page →

7,027
middleware-odigosmiddleware-labsVerified publisher0.2.411 of 6See more

middleware-odigos middleware-labs 0.2.41

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-ui:middleware-test-0.0.787120a4561a9
ws@7.5.8
7.5.11

Open the chart page →

8,370
middleware-visionmiddleware-labsVerified publisher0.2.651 of 6See more

middleware-vision middleware-labs 0.2.65

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-ui:middleware-test-0.0.853772b7b42c7
ws@7.5.8
7.5.11

Open the chart page →

8,361
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
ws@8.18.2
8.21.0

Open the chart page →

43,341
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
ws@7.4.6
7.5.11

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
ws@7.4.6
7.5.11

Open the chart page →

10,603
iotmmontesVerified publisher0.3.23 of 7See more

iot mmontes 0.3.2

3 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
ws@6.2.2
6.2.4
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
ws@7.4.6
7.5.11
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
ws@6.2.2
6.2.4

Open the chart page →

10,608
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ws@8.18.3
8.21.0

Open the chart page →

2,457
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
ws@7.5.10
7.5.11

Open the chart page →

14,809
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
ws@7.5.10
7.5.11

Open the chart page →

1,948
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ws@8.18.3
8.21.0

Open the chart page →

2,457
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
ws@6.2.1
6.2.4

Open the chart page →

6,438
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
ws@1.1.1
5.2.5
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
ws@1.1.4
5.2.5

Open the chart page →

7,048
monopolymonopolypackage0.1.01 of 1See more

monopoly monopolypackage 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
gonzague/monopoly:latest70465995deea
ws@3.3.3
5.2.5

Open the chart page →

1,130
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
ws@7.5.8
7.5.11

Open the chart page →

10,959
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
ws@7.2.5
7.5.11

Open the chart page →

6,684
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
ws@8.11.0
8.21.0

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
ws@8.18.3
8.21.0

Open the chart page →

4,960
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
ws@8.2.3
8.21.0

Open the chart page →

6,608
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
ws@8.2.3
8.21.0

Open the chart page →

3,128
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
ws@8.13.0
8.21.0

Open the chart page →

2,116
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
ws@8.13.0
8.21.0

Open the chart page →

2,116
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
ws@8.13.0
8.21.0

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
ws@8.13.0
8.21.0

Open the chart page →

2,116
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ws@7.5.9
7.5.11

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
ws@8.3.0
8.21.0

Open the chart page →

3,269
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
ws@3.3.3
5.2.5

Open the chart page →

109,294
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
ws@8.19.0
8.21.0

Open the chart page →

30,028
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
ws@8.20.0
8.21.0

Open the chart page →

1,166
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
ws@8.16.0
8.21.0

Open the chart page →

6,982
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
ws@8.19.0
8.21.0

Open the chart page →

2,383
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
ws@8.19.0
8.21.0

Open the chart page →

3,798
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
ws@3.3.3
5.2.5

Open the chart page →

2,919
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
ws@7.5.9
7.5.11

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
ws@7.5.9
7.5.11

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
ws@8.13.0
8.21.0

Open the chart page →

15,187
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
ws@6.1.4
6.2.4

Open the chart page →

27,465

Container images carrying it

441 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
arturisimo/server-urjc:v1.0d8dc4430531e
ws@5.2.3
5.2.5
1
assistiot/composite-services-manager_agent-http-mqtt:latest16d21bc5e42e
ws@7.5.9
7.5.11
1
assistiot/composite-services-manager_agent-mqtt-http:latest27d58b8911cd
ws@7.5.9
7.5.11
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
ws@7.3.1
7.5.11
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
ws@7.3.1
7.5.11
1
assistiot/fl_orchestrator:api-latest7473d77448e1
ws@7.5.9
7.5.11
1
assistiot/open_api_frontend:1.0.1f11d82defc70
ws@7.5.9
7.5.11
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
ws@7.5.8
7.5.11
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
ws@7.5.8
7.5.11
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
ws@7.5.8
7.5.11
1
baserow/baserow:1.30.1df0c42eb67e8
ws@7.5.9
7.5.11
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
ws@7.4.3
7.5.11
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
ws@8.11.0
8.21.0
1
bluerange/bluerange-mosquitto:25f1bfbba84832
ws@7.5.10
7.5.11
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
ws@7.4.6
7.5.11
1
budibase/apps:3.41.344fe6feab985
ws@8.18.3
8.21.0
1
catalysm/csmm:latestf003b35f54d9
ws@7.4.6
7.5.11
1
ccjacobs14/amazon:59a9b14a6f09e
ws@8.13.0
8.21.0
1
chainsafe/lodestar:latest5593f6e97912
ws@8.18.3
8.21.0
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
ws@8.5.0
8.21.0
1
chatwoot/chatwoot:v4.15.167ebc751c171
ws@6.2.1
6.2.4
1
chocobozzz/peertube:v8.1.5052712130691
ws@8.19.0
8.21.0
1
cnieg/maildev:v1.1.998ee05668915
ws@6.1.4
6.2.4
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
ws@8.2.3
8.21.0
1
codercom/code-server:4.11.0-debian1e2cc688008e
ws@8.2.0
8.21.0
1
codercom/code-server:3.10.247605610ad8d
ws@7.4.5
7.5.11
1
codetogether/codetogether:latest4348c8a38752
ws@7.5.10
7.5.11
1
coldatom/containers-security-api:latesteae9e82da080
ws@8.12.0
8.21.0
1
coldatom/containers-security-front:latest7c2fbbb41bcf
ws@8.12.0
8.21.0
1
conduction/conduction-ui-app:devd591f5e6f2a9
ws@6.2.1
6.2.4
1
contane/foreman:0.5.2efb98bdcc4e9
ws@8.18.2
8.21.0
1
countly/api:25.05.4f4cc7447c4f5
ws@8.8.1
8.21.0
1
countly/countly-server:25.05.4e3c238248f99
ws@8.8.1
8.21.0
1
cryptexlabs/authf:0.12.11189c07411d7c
ws@7.5.3
7.5.11
1
cspconsole/report-processor:1.0.279a2d8840bfdf
ws@7.5.10
7.5.11
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
ws@8.20.1
8.21.0
1
dacinfomotion/h2p:latest68fa393b472c
ws@8.13.0
8.21.0
1
datarhei/restreamer:0.6.4655e12f9eeed
ws@7.2.3
7.5.11
1
davdiv/musicociel:deva85f99be882c
ws@8.16.0
8.21.0
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
ws@5.2.2
5.2.5
1
decayofmind/hubot:3.3.21e18e92fe694
ws@1.1.5
5.2.5
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
ws@7.5.10
7.5.11
1
dgtlmoon/sockpuppetbrowser:latestf166a963b550
ws@8.4.2
8.21.0
1
directus/directus:12.0.29c8470ea465c
ws@7.5.10
7.5.11
1
directus/directus:11.1.0e3c8bb975350
ws@8.18.0
8.21.0
1
diygod/rsshub:2025-11-097a6312cac0d5
ws@8.18.3
8.21.0
1
drumsergio/lynxprompt:2.0.75c6afb6679301
ws@8.20.0
8.21.0
1
electerious/ackee:3.2.05e7173fa321c
ws@7.4.5
7.5.11
1
enketo/enketo-express:3.0.4dcad9c2273f6
ws@7.4.6
7.5.11
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
ws@1.1.5
5.2.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.