StackRadar

CVE-2026-48779

High

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
443
of 17,781 indexed, latest versions
Container images
441
deployed by those charts
Fix available
1 of 2
affected packages

ws: Memory exhaustion DoS from tiny fragments and data chunks

Carried by container images the latest versions of 443 of 17,781 indexed charts deploy, on 441 images.

Affected packageAffected versionsFixed inImages
wsnpm1.1.0, 1.1.1, 1.1.2, 1.1.4+57 more5.2.5, 6.2.4, 7.5.11, 8.21.0441
node-wsdeb8.11.0+~cs13.7.3-1no fix listed2
OSV records
DEBIAN-CVE-2026-48779GHSA-96hv-2xvq-fx4p

Charts affected

443 by stars
ChartLatestAffected imagesRadar Score
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
ws@8.18.0
8.21.0

Open the chart page →

4,219
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
ws@8.18.3
8.21.0

Open the chart page →

2,421
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
ws@6.2.2
6.2.4

Open the chart page →

9,968
mishtip2p-avs0.1.01 of 2See more

mishti p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mishtinetwork/operator:latestbb3fe67a5f7c
ws@8.5.0
8.21.0

Open the chart page →

3,999
ungatep2p-avs0.1.01 of 3See more

ungate p2p-avs 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
ws@8.5.0
8.21.0

Open the chart page →

27,373
myappp4-helm0.1.01 of 6See more

myapp p4-helm 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ws@5.2.2
5.2.5

Open the chart page →

19,720
walletconnect-relayparadeum-teamVerified publisher0.1.21 of 1See more

walletconnect-relay paradeum-team 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/netwarps/walletconnect-relay:v2.1.3-rc.15d90b9c193e0
ws@8.8.1
8.21.0

Open the chart page →

1,243
pairdroppascaliskeVerified publisher2.0.01 of 1See more

pairdrop pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/pairdrop:version-v1.11.23279d2d986c0
ws@8.18.1
8.21.0

Open the chart page →

663
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
ws@6.1.4
6.2.4

Open the chart page →

6,524
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
ws@5.2.2
5.2.5

Open the chart page →

28,484
radio-dixitalpvillaverdeVerified publisher1.6.01 of 1See more

radio-dixital pvillaverde 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
pvillaverde/radio_dixital:1.5.0326a793e509f
ws@8.17.0
8.21.0

Open the chart page →

415
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
ws@7.5.10
7.5.11

Open the chart page →

1,858
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
ws@7.5.4
7.5.11

Open the chart page →

29,227
redisinsightredisinsightVerified publisher0.1.01 of 1See more

redisinsight redisinsight 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
ws@8.17.1
8.21.0

Open the chart page →

1,038
redisinsightredisinsight-helmVerified publisher0.1.11 of 1See more

redisinsight redisinsight-helm 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
redis/redisinsight:2.46699d341bd329
ws@8.11.0
8.21.0

Open the chart page →

1,884
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
ws@8.18.0
8.21.0

Open the chart page →

7,084
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
ws@7.4.6
7.5.11

Open the chart page →

6,026
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
ws@7.4.4
7.5.11

Open the chart page →

5,215
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
ws@8.18.2
8.21.0

Open the chart page →

5,338
audiobookshelfrubxkubeVerified publisher0.1.31 of 1See more

audiobookshelf rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ws@8.11.0
8.21.0

Open the chart page →

1,722
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
ws@8.11.0
8.21.0

Open the chart page →

7,413
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
ws@8.20.1
8.21.0

Open the chart page →

30,219
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
ws@8.18.3
8.21.0

Open the chart page →

5,819
safe-stacksafe-global0.1.02 of 9See more

safe-stack safe-global 0.1.0

2 of the 9 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
ws@7.4.6
7.5.11
safeglobal/safe-client-gateway-nest:v1.51.012ccfd93fcaf
ws@8.17.1
8.21.0

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
ws@7.4.6
7.5.11

Open the chart page →

16,620
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
ws@8.11.0
8.21.0

Open the chart page →

4,744
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
ws@8.18.3
8.21.0

Open the chart page →

4,684
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
ws@3.3.3
5.2.5

Open the chart page →

5,582
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
ws@7.4.6
7.5.11

Open the chart page →

3,118
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
ws@8.13.0
8.21.0

Open the chart page →

4,431
etherpadschoenwald0.3.01 of 1See more

etherpad schoenwald 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
etherpad/etherpad:2.7.2b723fe5f2594
ws@8.18.3
8.21.0

Open the chart page →

2,133
semaphoreschoenwald0.1.31 of 1See more

semaphore schoenwald 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
0hlov3/semaphore:v1.0.050f874ec096b
ws@7.5.9
7.5.11

Open the chart page →

1,796
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ws@8.18.0
8.21.0

Open the chart page →

5,497
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
ws@6.2.2
6.2.4

Open the chart page →

3,143
skoonerskooner0.2.21 of 1See more

skooner skooner 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
ws@8.14.1
8.21.0

Open the chart page →

1,341
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
ws@7.5.9
7.5.11

Open the chart page →

7,574
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
ws@6.2.1
6.2.4

Open the chart page →

2,460
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-director:2.5.1110228ecd353b
ws@7.4.6
7.5.11

Open the chart page →

4,285
k8soketisoketi1.0.11 of 1See more

k8soketi soketi 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
ws@8.10.0
8.21.0

Open the chart page →

2,267
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
ws@7.5.5
7.5.11

Open the chart page →

3,228
speckle-preview-service-branch-testing6speckleVerified publisher2.23.14-branch.testing6.334655-b4e04ee1 of 1See more

speckle-preview-service-branch-testing6 speckle 2.23.14-branch.testing6.334655-b4e04ee

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
ws@8.17.1
8.21.0

Open the chart page →

5,950
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e13 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

3 of the 5 container images this version deploys carry CVE-2026-48779.

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb3 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

3 of the 5 container images this version deploys carry CVE-2026-48779.

Open the chart page →

16,400
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f82 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

2 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.17.14-branch.testing.72707.921a5f884fc39bca0c8
ws@8.5.0
8.21.0
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
ws@7.5.7
7.5.11

Open the chart page →

14,679
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091143 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

3 of the 5 container images this version deploys carry CVE-2026-48779.

Open the chart page →

16,400
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4692 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

2 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d4694bd113093583
ws@8.5.0
8.21.0
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
ws@7.5.7
7.5.11

Open the chart page →

14,221
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3412 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

2 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.18.12-branch.testing3.88744-f55b3414bd113093583
ws@8.5.0
8.21.0
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
ws@7.5.7
7.5.11

Open the chart page →

14,221
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b23 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

3 of the 5 container images this version deploys carry CVE-2026-48779.

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef3 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

3 of the 5 container images this version deploys carry CVE-2026-48779.

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e2 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

2 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
ws@8.17.1
8.21.0
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
ws@7.5.10
7.5.11

Open the chart page →

11,100

Container images carrying it

441 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
ws@7.5.3
7.5.11
1
etherpad/etherpad:2.7.2b723fe5f2594
ws@8.18.3
8.21.0
1
ethersphere/bzz-token-service:latest7624f11a72ad
ws@7.4.6
7.5.11
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
ws@8.18.1
8.21.0
1
ethersphere/onboarding-faucet:0.3.0513154aab230
ws@7.4.6
7.5.11
1
ethpandaops/blobscan:latest7a9ab6370657
ws@7.4.6
7.5.11
1
ethpandaops/blobscan-indexer:latestc58eb9ffe446
ws@7.4.6
7.5.11
1
ethpandaops/ethereumjs:masterfb84b718500f
ws@8.17.1
8.21.0
1
evoapicloud/evolution-api:latest966625532d90
ws@8.17.1
8.21.0
1
fallenbagel/jellyseerr:latest4538137bc5af
ws@7.5.10
7.5.11
1
fanzynoodle/smeejas:0.0.15f9916c1a287
ws@7.5.6
7.5.11
1
fiware/idm:8.3.3a1b6ed4ae84f
ws@8.13.0
8.21.0
1
fiware/iotagent-json:3.1.0879b21a0d36d
ws@7.5.9
7.5.11
1
fiware/iotagent-ul:1.14.0fe11f55a926d
ws@6.2.1
6.2.4
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ws@1.1.5
5.2.5
1
fosrl/pangolin:1.13.0c32ad797ab96
ws@8.18.3
8.21.0
1
frappe/frappe-socketio:v13.4.12095767a9e82
ws@7.4.6
7.5.11
1
glenndehaan/api-mapper:latest6ff6310683bf
ws@8.16.0
8.21.0
1
glenndehaan/kube-hook:latest0a7116f48bfe
ws@8.18.0
8.21.0
1
globalping/globalping-probe:latest8acbd23009fd
ws@8.17.1
8.21.0
1
gonzague/monopoly:latest70465995deea
ws@3.3.3
5.2.5
1
gristlabs/grist:0.7.96e71b1914a7e
ws@7.4.4
7.5.11
1
halkeye/hubot:latest9764d2202130
ws@6.2.1
6.2.4
1
halkeye/irslackd:latest7638bfba70b0
ws@5.2.2
5.2.5
1
hansehe/graphql-gateway:1.0.458e09540afbc
ws@6.2.1
6.2.4
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
ws@8.11.0
8.21.0
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ws@7.5.9
7.5.11
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
ws@7.5.9
7.5.11
1
henrywhitaker3/speedtest-tracker:latest47159a940229
ws@6.2.1
6.2.4
1
heywood8/redisinsight:2.28.00bc9ab313d37
ws@8.11.0
8.21.0
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
ws@7.5.10
7.5.11
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
ws@8.6.0
8.21.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
ws@8.17.1
8.21.0
1
hugohg34/server:0.0.2503e5d8960ff
ws@5.2.3
5.2.5
1
ianw/quickchart:v1.7.1dc49dd460c37
ws@7.4.6
7.5.11
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
ws@3.3.3
5.2.5
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
ws@7.4.6
7.5.11
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
ws@3.3.3
5.2.5
1
ibmcom/microclimate-portal:latested5505e5c7ec
ws@3.3.3
5.2.5
1
ibmcom/microclimate-theia:lateste17bdccc5030
ws@3.3.3
5.2.5
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
ws@4.0.0
5.2.5
1
inseefrlab/shelly:cloudshell31f04ca7436b
ws@6.1.4
6.2.4
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
ws@8.8.1
8.21.0
1
jakowenko/double-take:1.6.0b858bac9e32a
ws@7.5.5
7.5.11
1
jayfong/yapi:1.10.2163e5d621910
ws@2.3.1
5.2.5
1
joplin/server:3.0-beta52af57880c0e
ws@8.11.0
8.21.0
1
joplin/server:2.14.2-betab87564ef34e9
ws@8.13.0
8.21.0
1
journeyapps/powersync-service:latestbf46f66e5dcc
ws@8.18.0
8.21.0
1
junktext/getting-started:1.0.5a70936c04aed
ws@7.5.5
7.5.11
1
junktext/getting-started:1.0.34d44adf5a4da2
ws@7.5.5
7.5.11
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.