StackRadar

CVE-2026-48779

High

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
443
of 17,781 indexed, latest versions
Container images
441
deployed by those charts
Fix available
1 of 2
affected packages

ws: Memory exhaustion DoS from tiny fragments and data chunks

Carried by container images the latest versions of 443 of 17,781 indexed charts deploy, on 441 images.

Affected packageAffected versionsFixed inImages
wsnpm1.1.0, 1.1.1, 1.1.2, 1.1.4+57 more5.2.5, 6.2.4, 7.5.11, 8.21.0441
node-wsdeb8.11.0+~cs13.7.3-1no fix listed2
OSV records
DEBIAN-CVE-2026-48779GHSA-96hv-2xvq-fx4p

Charts affected

443 by stars
ChartLatestAffected imagesRadar Score
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
ws@8.17.1
8.21.0

Open the chart page →

7,405
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
ws@8.18.3
8.21.0

Open the chart page →

4,083
audiobookshelfcharts-derwitt-devVerified publisher1.1.01 of 1See more

audiobookshelf charts-derwitt-dev 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ws@8.11.0
8.21.0

Open the chart page →

1,722
audiobookshelfchristianhuthVerified publisher2.4.01 of 1See more

audiobookshelf christianhuth 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ws@8.11.0
8.21.0

Open the chart page →

1,722
countlychristianhuthVerified publisher5.2.11 of 3See more

countly christianhuth 5.2.1

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
ws@8.8.1
8.21.0

Open the chart page →

7,295
arbitrumchronicleVerified publisher0.3.41 of 1See more

arbitrum chronicle 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
node-ws@8.11.0+~cs13.7.3-1
ws@8.11.0
no fix listed
8.21.0

Open the chart page →

6,998
zksyncchronicleVerified publisher0.1.01 of 2See more

zksync chronicle 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
matterlabs/external-node:v24.0.06cbfea4c694a
ws@7.5.9
7.5.11

Open the chart page →

5,982
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
ws@8.18.1
8.21.0

Open the chart page →

2,759
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
ws@1.1.5
5.2.5

Open the chart page →

27,417
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
ws@1.1.5
5.2.5

Open the chart page →

2,580
kube-slackcloudnativeapp1.0.01 of 1See more

kube-slack cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
willwill/kube-slack:v4.1.1d443017aae98
ws@6.1.3
6.2.4

Open the chart page →

1,937
node-redcloudnativeapp1.2.21 of 1See more

node-red cloudnativeapp 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
nodered/node-red-docker:0.19.6-v8070643219ea2
ws@1.1.5
5.2.5

Open the chart page →

4,790
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
ws@3.3.2
5.2.5

Open the chart page →

77,758
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
ws@7.1.2
7.5.11

Open the chart page →

25,456
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad3 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

3 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
ws@7.5.10
7.5.11
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
ws@8.18.3
8.21.0
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
ws@8.18.3
8.21.0

Open the chart page →

18,293
clusterplexclusterplexVerified publisher1.1.101 of 3See more

clusterplex clusterplex 1.1.10

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
ws@8.11.0
8.21.0

Open the chart page →

3,868
maildevcnieg1.1.11 of 1See more

maildev cnieg 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
cnieg/maildev:v1.1.998ee05668915
ws@6.1.4
6.2.4

Open the chart page →

2,449
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
ws@8.13.0
8.21.0

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
ws@8.13.0
8.21.0

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
ws@8.13.0
8.21.0

Open the chart page →

5,141
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
ws@6.2.1
6.2.4

Open the chart page →

12,907
containers-security-chartscontainers-security0.1.02 of 7See more

containers-security-charts containers-security 0.1.0

2 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
coldatom/containers-security-api:latesteae9e82da080
ws@8.12.0
8.21.0
coldatom/containers-security-front:latest7c2fbbb41bcf
ws@8.12.0
8.21.0

Open the chart page →

9,146
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
ws@8.18.0
8.21.0

Open the chart page →

14,559
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
ws@7.4.6
7.5.11

Open the chart page →

5,488
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
ws@1.1.2
5.2.5

Open the chart page →

5,209
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
ws@7.5.3
7.5.11

Open the chart page →

3,769
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
ws@7.4.6
7.5.11

Open the chart page →

13,852
cspconsolecspconsole1.3.111 of 5See more

cspconsole cspconsole 1.3.11

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
cspconsole/report-processor:1.0.279a2d8840bfdf
ws@7.5.10
7.5.11

Open the chart page →

12,274
dapr-agentsdapr-agents-devVerified publisher0.1.51 of 31See more

dapr-agents dapr-agents-dev 0.1.5

1 of the 31 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
ws@8.17.1
8.21.0

Open the chart page →

22,193
db-operatordb-operatorVerified publisher0.1.01 of 1See more

db-operator db-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
plumdog/db-operator:latest0c2fa2db0357
ws@7.5.6
7.5.11

Open the chart page →

3,042
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
ws@7.5.10
7.5.11

Open the chart page →

2,529
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
ws@5.2.2
5.2.5

Open the chart page →

27,550
difydify1.0.02 of 4See more

dify dify 1.0.0

2 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
langgenius/dify-api:1.0.0066035f93856
ws@7.3.1
7.5.11
langgenius/dify-web:1.0.0d64914ff0d6d
ws@7.5.10
7.5.11

Open the chart page →

19,224
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
ws@8.18.0
8.21.0

Open the chart page →

4,551
uptime-kumadjjudas21Verified publisher1.5.181 of 1See more

uptime-kuma djjudas21 1.5.18

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.12bc6f244ecf27
ws@8.11.0
8.21.0

Open the chart page →

4,217
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
ws@5.2.2
5.2.5

Open the chart page →

24,656
dumpstoredumpstore0.1.11 of 2See more

dumpstore dumpstore 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
ws@8.18.3
8.21.0

Open the chart page →

4,251
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
ws@5.2.2
5.2.5

Open the chart page →

11,174
arbitrumdysnixVerified publisher0.1.11 of 1See more

arbitrum dysnix 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
node-ws@8.11.0+~cs13.7.3-1
ws@8.11.0
no fix listed
8.21.0

Open the chart page →

9,244
uptime-kumaegebackVerified publisher2.0.121 of 1See more

uptime-kuma egeback 2.0.12

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
ws@8.19.0
8.21.0

Open the chart page →

30,159
frontend-charteks-3-tier-app-chart0.1.01 of 1See more

frontend-chart eks-3-tier-app-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
arfath29/3-tier-app-frontend:latest384b3e377f47
ws@6.2.2
6.2.4

Open the chart page →

3,744
reddarkemmas-chartsVerified publisher0.0.21 of 1See more

reddark emmas-charts 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/0xemma/reddark:main2a115e991894
ws@8.11.0
8.21.0

Open the chart page →

1,998
eolicplantseolicplantsVerified publisher0.1.01 of 7See more

eolicplants eolicplants 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
ws@5.2.2
5.2.5

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.01 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
ws@5.2.2
5.2.5

Open the chart page →

27,256
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
ws@5.2.3
5.2.5

Open the chart page →

27,096
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
ws@8.18.3
8.21.0

Open the chart page →

1,755
blobscanethereum-helm-chartsVerified publisher0.1.11 of 1See more

blobscan ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ethpandaops/blobscan:latest7a9ab6370657
ws@7.4.6
7.5.11

Open the chart page →

1,329
blobscan-indexerethereum-helm-chartsVerified publisher0.1.11 of 1See more

blobscan-indexer ethereum-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ethpandaops/blobscan-indexer:latestc58eb9ffe446
ws@7.4.6
7.5.11

Open the chart page →

2,114
ethstatsethereum-helm-chartsVerified publisher0.1.41 of 1See more

ethstats ethereum-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
skylenet/ethstats-server:pow-latestd757cc016198
ws@6.2.2
6.2.4

Open the chart page →

1,109
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
ws@8.18.3
8.21.0

Open the chart page →

2,522

Container images carrying it

441 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
ws@7.5.3
7.5.11
1
etherpad/etherpad:2.7.2b723fe5f2594
ws@8.18.3
8.21.0
1
ethersphere/bzz-token-service:latest7624f11a72ad
ws@7.4.6
7.5.11
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
ws@8.18.1
8.21.0
1
ethersphere/onboarding-faucet:0.3.0513154aab230
ws@7.4.6
7.5.11
1
ethpandaops/blobscan:latest7a9ab6370657
ws@7.4.6
7.5.11
1
ethpandaops/blobscan-indexer:latestc58eb9ffe446
ws@7.4.6
7.5.11
1
ethpandaops/ethereumjs:masterfb84b718500f
ws@8.17.1
8.21.0
1
evoapicloud/evolution-api:latest966625532d90
ws@8.17.1
8.21.0
1
fallenbagel/jellyseerr:latest4538137bc5af
ws@7.5.10
7.5.11
1
fanzynoodle/smeejas:0.0.15f9916c1a287
ws@7.5.6
7.5.11
1
fiware/idm:8.3.3a1b6ed4ae84f
ws@8.13.0
8.21.0
1
fiware/iotagent-json:3.1.0879b21a0d36d
ws@7.5.9
7.5.11
1
fiware/iotagent-ul:1.14.0fe11f55a926d
ws@6.2.1
6.2.4
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ws@1.1.5
5.2.5
1
fosrl/pangolin:1.13.0c32ad797ab96
ws@8.18.3
8.21.0
1
frappe/frappe-socketio:v13.4.12095767a9e82
ws@7.4.6
7.5.11
1
glenndehaan/api-mapper:latest6ff6310683bf
ws@8.16.0
8.21.0
1
glenndehaan/kube-hook:latest0a7116f48bfe
ws@8.18.0
8.21.0
1
globalping/globalping-probe:latest8acbd23009fd
ws@8.17.1
8.21.0
1
gonzague/monopoly:latest70465995deea
ws@3.3.3
5.2.5
1
gristlabs/grist:0.7.96e71b1914a7e
ws@7.4.4
7.5.11
1
halkeye/hubot:latest9764d2202130
ws@6.2.1
6.2.4
1
halkeye/irslackd:latest7638bfba70b0
ws@5.2.2
5.2.5
1
hansehe/graphql-gateway:1.0.458e09540afbc
ws@6.2.1
6.2.4
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
ws@8.11.0
8.21.0
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ws@7.5.9
7.5.11
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
ws@7.5.9
7.5.11
1
henrywhitaker3/speedtest-tracker:latest47159a940229
ws@6.2.1
6.2.4
1
heywood8/redisinsight:2.28.00bc9ab313d37
ws@8.11.0
8.21.0
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
ws@7.5.10
7.5.11
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
ws@8.6.0
8.21.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ws@8.17.1
8.21.0
1
hugohg34/server:0.0.2503e5d8960ff
ws@5.2.3
5.2.5
1
ianw/quickchart:v1.7.1dc49dd460c37
ws@7.4.6
7.5.11
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
ws@3.3.3
5.2.5
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
ws@7.4.6
7.5.11
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
ws@3.3.3
5.2.5
1
ibmcom/microclimate-portal:latested5505e5c7ec
ws@3.3.3
5.2.5
1
ibmcom/microclimate-theia:lateste17bdccc5030
ws@3.3.3
5.2.5
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
ws@4.0.0
5.2.5
1
inseefrlab/shelly:cloudshell31f04ca7436b
ws@6.1.4
6.2.4
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
ws@8.8.1
8.21.0
1
jakowenko/double-take:1.6.0b858bac9e32a
ws@7.5.5
7.5.11
1
jayfong/yapi:1.10.2163e5d621910
ws@2.3.1
5.2.5
1
joplin/server:3.0-beta52af57880c0e
ws@8.11.0
8.21.0
1
joplin/server:2.14.2-betab87564ef34e9
ws@8.13.0
8.21.0
1
journeyapps/powersync-service:latestbf46f66e5dcc
ws@8.18.0
8.21.0
1
junktext/getting-started:1.0.5a70936c04aed
ws@7.5.5
7.5.11
1
junktext/getting-started:1.0.34d44adf5a4da2
ws@7.5.5
7.5.11
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.