StackRadar

CVE-2026-48779

High

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
443
of 17,781 indexed, latest versions
Container images
441
deployed by those charts
Fix available
1 of 2
affected packages

ws: Memory exhaustion DoS from tiny fragments and data chunks

Carried by container images the latest versions of 443 of 17,781 indexed charts deploy, on 441 images.

Affected packageAffected versionsFixed inImages
wsnpm1.1.0, 1.1.1, 1.1.2, 1.1.4+57 more5.2.5, 6.2.4, 7.5.11, 8.21.0441
node-wsdeb8.11.0+~cs13.7.3-1no fix listed2
OSV records
DEBIAN-CVE-2026-48779GHSA-96hv-2xvq-fx4p

Charts affected

443 by stars
ChartLatestAffected imagesRadar Score
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
ws@3.3.3
5.2.5

Open the chart page →

10,311
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
ws@1.1.2
5.2.5

Open the chart page →

5,209
kubeviouskubevious1.2.24 of 7See more

kubevious kubevious 1.2.2

4 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
kubevious/backend:1.2.22d9ba6eb46b6
ws@8.13.0
8.21.0
kubevious/collector:1.2.1f58226f9d84e
ws@8.11.0
8.21.0
kubevious/guard:1.2.19bf567704de2
ws@8.2.3
8.21.0
kubevious/parser:1.2.299ae7a5168c2
ws@8.13.0
8.21.0

Open the chart page →

14,204
bitwarden-crd-operatorlerentisVerified publisher0.18.01 of 1See more

bitwarden-crd-operator lerentis 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
ws@8.20.0
8.21.0

Open the chart page →

2,003
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
ws@8.11.0
8.21.0

Open the chart page →

2,635
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ws@1.1.5
5.2.5

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
ws@7.4.6
7.5.11
kobotoolbox/kpi:2.022.24dbcacc01bccd4
ws@8.5.0
8.21.0

Open the chart page →

18,517
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
ws@7.5.9
7.5.11

Open the chart page →

7,776
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
ws@7.4.6
7.5.11

Open the chart page →

24,488
soketisoketi2.0.01 of 1See more

soketi soketi 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/soketi/soketi:1.6-16-debian713223456cf1
ws@7.5.9
7.5.11

Open the chart page →

1,636
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
thmmniii/fbs-collab:v1.27.15d389e3c5ce6
ws@8.18.0
8.21.0

Open the chart page →

28,534
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
ws@8.18.0
8.21.0

Open the chart page →

8,491
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
ws@5.2.4
5.2.5

Open the chart page →

4,016
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
ws@7.4.6
7.5.11

Open the chart page →

2,851
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
ws@7.3.1
7.5.11

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
ws@7.3.1
7.5.11

Open the chart page →

10,730
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
ws@8.16.0
8.21.0

Open the chart page →

1,843
maildevchristianhuthVerified publisher1.6.01 of 1See more

maildev christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
maildev/maildev:2.2.1180ef51f65ee
ws@8.18.0
8.21.0

Open the chart page →

1,143
skoonerchristianhuthVerified publisher0.4.01 of 1See more

skooner christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
ws@8.14.1
8.21.0

Open the chart page →

1,341
data-fairdata354-helmVerified publisher1.1.26 of 12See more

data-fair data354-helm 1.1.2

6 of the 12 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
koumoul/capture:17108d47be3b2
ws@6.2.1
6.2.4
ghcr.io/data-fair/data-fair:3cc9498b64b5b
ws@7.5.9
7.5.11
ghcr.io/data-fair/metrics:0a8d40779eeae
ws@7.5.5
7.5.11
ghcr.io/data-fair/notify:3c739b74dabb0
ws@7.5.10
7.5.11
ghcr.io/data-fair/processings:15a9216989707
ws@8.14.2
8.21.0
ghcr.io/data-fair/simple-directory:438a4f32fad82
ws@6.1.4
6.2.4

Open the chart page →

38,346
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
ws@7.4.6
7.5.11

Open the chart page →

5,056
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
ws@7.5.10
7.5.11

Open the chart page →

7,473
jellystatdjjudas21Verified publisher0.1.121 of 1See more

jellystat djjudas21 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
ws@8.20.1
8.21.0

Open the chart page →

1,722
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
ws@8.13.0
8.21.0

Open the chart page →

3,925
domain-lockerdomain-locker0.2.81 of 3See more

domain-locker domain-locker 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
lissy93/domain-locker:latestd3c95edc0a8b
ws@8.18.0
8.21.0

Open the chart page →

1,882
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
ws@7.5.10
7.5.11

Open the chart page →

31,510
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
ws@8.17.1
8.21.0

Open the chart page →

1,442
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
ws@8.18.0
8.21.0

Open the chart page →

11,458
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
taigaio/taiga-events:latest92fc0822564f
ws@7.4.6
7.5.11

Open the chart page →

8,496
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
ws@6.2.1
6.2.4

Open the chart page →

2,519
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
ws@8.5.0
8.21.0

Open the chart page →

4,260
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
ws@8.2.3
8.21.0

Open the chart page →

15,653
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
ws@7.4.3
7.5.11

Open the chart page →

4,405
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
ws@6.2.2
6.2.4

Open the chart page →

7,801
sendgeek-cookbookVerified publisher1.2.21 of 1See more

send geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
ws@7.5.7
7.5.11

Open the chart page →

1,148
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
ws@8.2.3
8.21.0

Open the chart page →

5,079
zigbee2mqttgeek-cookbookVerified publisher9.4.21 of 1See more

zigbee2mqtt geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
ws@7.4.5
7.5.11

Open the chart page →

2,173
globalpingglobalpingVerified publisher1.0.111 of 1See more

globalping globalping 1.0.11

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
globalping/globalping-probe:latest8acbd23009fd
ws@8.17.1
8.21.0

Open the chart page →

518
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
ws@8.11.0
8.21.0

Open the chart page →

4,196
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
ws@8.17.1
8.21.0

Open the chart page →

15,712
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
ws@7.4.6
7.5.11

Open the chart page →

17,284
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
ws@7.5.5
7.5.11

Open the chart page →

3,369
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
ws@6.2.2
6.2.4

Open the chart page →

3,143
difykubeblocksVerified publisher0.5.12 of 5See more

dify kubeblocks 0.5.1

2 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
ws@7.3.1
7.5.11
langgenius/dify-web:0.6.11a2a294743634
ws@7.5.9
7.5.11

Open the chart page →

20,403
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
litlyx/litlyx-dashboard:lateste64ff2d52385
ws@8.18.3
8.21.0

Open the chart page →

7,874
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
ws@6.2.1
6.2.4

Open the chart page →

5,940
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ws@5.2.2
5.2.5

Open the chart page →

19,187
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
ws@8.20.1
8.21.0

Open the chart page →

2,575
open-api-discoveryopen-api-discoveryVerified publisher0.1.11 of 1See more

open-api-discovery open-api-discovery 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
lukasreining/open-api-schema-collector:0.1.050e021c42e33
ws@7.5.9
7.5.11

Open the chart page →

2,473
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
ws@8.17.1
8.21.0

Open the chart page →

6,883

Container images carrying it

441 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
ws@7.5.3
7.5.11
1
etherpad/etherpad:2.7.2b723fe5f2594
ws@8.18.3
8.21.0
1
ethersphere/bzz-token-service:latest7624f11a72ad
ws@7.4.6
7.5.11
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
ws@8.18.1
8.21.0
1
ethersphere/onboarding-faucet:0.3.0513154aab230
ws@7.4.6
7.5.11
1
ethpandaops/blobscan:latest7a9ab6370657
ws@7.4.6
7.5.11
1
ethpandaops/blobscan-indexer:latestc58eb9ffe446
ws@7.4.6
7.5.11
1
ethpandaops/ethereumjs:masterfb84b718500f
ws@8.17.1
8.21.0
1
evoapicloud/evolution-api:latest966625532d90
ws@8.17.1
8.21.0
1
fallenbagel/jellyseerr:latest4538137bc5af
ws@7.5.10
7.5.11
1
fanzynoodle/smeejas:0.0.15f9916c1a287
ws@7.5.6
7.5.11
1
fiware/idm:8.3.3a1b6ed4ae84f
ws@8.13.0
8.21.0
1
fiware/iotagent-json:3.1.0879b21a0d36d
ws@7.5.9
7.5.11
1
fiware/iotagent-ul:1.14.0fe11f55a926d
ws@6.2.1
6.2.4
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ws@1.1.5
5.2.5
1
fosrl/pangolin:1.13.0c32ad797ab96
ws@8.18.3
8.21.0
1
frappe/frappe-socketio:v13.4.12095767a9e82
ws@7.4.6
7.5.11
1
glenndehaan/api-mapper:latest6ff6310683bf
ws@8.16.0
8.21.0
1
glenndehaan/kube-hook:latest0a7116f48bfe
ws@8.18.0
8.21.0
1
globalping/globalping-probe:latest8acbd23009fd
ws@8.17.1
8.21.0
1
gonzague/monopoly:latest70465995deea
ws@3.3.3
5.2.5
1
gristlabs/grist:0.7.96e71b1914a7e
ws@7.4.4
7.5.11
1
halkeye/hubot:latest9764d2202130
ws@6.2.1
6.2.4
1
halkeye/irslackd:latest7638bfba70b0
ws@5.2.2
5.2.5
1
hansehe/graphql-gateway:1.0.458e09540afbc
ws@6.2.1
6.2.4
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
ws@8.11.0
8.21.0
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ws@7.5.9
7.5.11
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
ws@7.5.9
7.5.11
1
henrywhitaker3/speedtest-tracker:latest47159a940229
ws@6.2.1
6.2.4
1
heywood8/redisinsight:2.28.00bc9ab313d37
ws@8.11.0
8.21.0
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
ws@7.5.10
7.5.11
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
ws@8.6.0
8.21.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ws@8.17.1
8.21.0
1
hugohg34/server:0.0.2503e5d8960ff
ws@5.2.3
5.2.5
1
ianw/quickchart:v1.7.1dc49dd460c37
ws@7.4.6
7.5.11
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
ws@3.3.3
5.2.5
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
ws@7.4.6
7.5.11
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
ws@3.3.3
5.2.5
1
ibmcom/microclimate-portal:latested5505e5c7ec
ws@3.3.3
5.2.5
1
ibmcom/microclimate-theia:lateste17bdccc5030
ws@3.3.3
5.2.5
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
ws@4.0.0
5.2.5
1
inseefrlab/shelly:cloudshell31f04ca7436b
ws@6.1.4
6.2.4
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
ws@8.8.1
8.21.0
1
jakowenko/double-take:1.6.0b858bac9e32a
ws@7.5.5
7.5.11
1
jayfong/yapi:1.10.2163e5d621910
ws@2.3.1
5.2.5
1
joplin/server:3.0-beta52af57880c0e
ws@8.11.0
8.21.0
1
joplin/server:2.14.2-betab87564ef34e9
ws@8.13.0
8.21.0
1
journeyapps/powersync-service:latestbf46f66e5dcc
ws@8.18.0
8.21.0
1
junktext/getting-started:1.0.5a70936c04aed
ws@7.5.5
7.5.11
1
junktext/getting-started:1.0.34d44adf5a4da2
ws@7.5.5
7.5.11
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.