StackRadar

CVE-2026-48779

High

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
443
of 17,781 indexed, latest versions
Container images
441
deployed by those charts
Fix available
1 of 2
affected packages

ws: Memory exhaustion DoS from tiny fragments and data chunks

Carried by container images the latest versions of 443 of 17,781 indexed charts deploy, on 441 images.

Affected packageAffected versionsFixed inImages
wsnpm1.1.0, 1.1.1, 1.1.2, 1.1.4+57 more5.2.5, 6.2.4, 7.5.11, 8.21.0441
node-wsdeb8.11.0+~cs13.7.3-1no fix listed2
OSV records
DEBIAN-CVE-2026-48779GHSA-96hv-2xvq-fx4p

Charts affected

443 by stars
ChartLatestAffected imagesRadar Score
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
ws@3.3.3
5.2.5

Open the chart page →

10,311
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
ws@1.1.2
5.2.5

Open the chart page →

5,209
kubeviouskubevious1.2.24 of 7See more

kubevious kubevious 1.2.2

4 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
kubevious/backend:1.2.22d9ba6eb46b6
ws@8.13.0
8.21.0
kubevious/collector:1.2.1f58226f9d84e
ws@8.11.0
8.21.0
kubevious/guard:1.2.19bf567704de2
ws@8.2.3
8.21.0
kubevious/parser:1.2.299ae7a5168c2
ws@8.13.0
8.21.0

Open the chart page →

14,204
bitwarden-crd-operatorlerentisVerified publisher0.18.01 of 1See more

bitwarden-crd-operator lerentis 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
ws@8.20.0
8.21.0

Open the chart page →

2,003
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
ws@8.11.0
8.21.0

Open the chart page →

2,635
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
ws@1.1.5
5.2.5

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
ws@7.4.6
7.5.11
kobotoolbox/kpi:2.022.24dbcacc01bccd4
ws@8.5.0
8.21.0

Open the chart page →

18,517
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
ws@7.5.9
7.5.11

Open the chart page →

7,776
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
ws@7.4.6
7.5.11

Open the chart page →

24,488
soketisoketi2.0.01 of 1See more

soketi soketi 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/soketi/soketi:1.6-16-debian713223456cf1
ws@7.5.9
7.5.11

Open the chart page →

1,636
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
thmmniii/fbs-collab:v1.27.15d389e3c5ce6
ws@8.18.0
8.21.0

Open the chart page →

28,534
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
ws@8.18.0
8.21.0

Open the chart page →

8,491
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
ws@5.2.4
5.2.5

Open the chart page →

4,016
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
ws@7.4.6
7.5.11

Open the chart page →

2,851
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
ws@7.3.1
7.5.11

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
ws@7.3.1
7.5.11

Open the chart page →

10,730
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
ws@8.16.0
8.21.0

Open the chart page →

1,843
maildevchristianhuthVerified publisher1.6.01 of 1See more

maildev christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
maildev/maildev:2.2.1180ef51f65ee
ws@8.18.0
8.21.0

Open the chart page →

1,143
skoonerchristianhuthVerified publisher0.4.01 of 1See more

skooner christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
ws@8.14.1
8.21.0

Open the chart page →

1,341
data-fairdata354-helmVerified publisher1.1.26 of 12See more

data-fair data354-helm 1.1.2

6 of the 12 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
koumoul/capture:17108d47be3b2
ws@6.2.1
6.2.4
ghcr.io/data-fair/data-fair:3cc9498b64b5b
ws@7.5.9
7.5.11
ghcr.io/data-fair/metrics:0a8d40779eeae
ws@7.5.5
7.5.11
ghcr.io/data-fair/notify:3c739b74dabb0
ws@7.5.10
7.5.11
ghcr.io/data-fair/processings:15a9216989707
ws@8.14.2
8.21.0
ghcr.io/data-fair/simple-directory:438a4f32fad82
ws@6.1.4
6.2.4

Open the chart page →

38,346
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
ws@7.4.6
7.5.11

Open the chart page →

5,056
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
ws@7.5.10
7.5.11

Open the chart page →

7,473
jellystatdjjudas21Verified publisher0.1.121 of 1See more

jellystat djjudas21 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
ws@8.20.1
8.21.0

Open the chart page →

1,722
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
ws@8.13.0
8.21.0

Open the chart page →

3,925
domain-lockerdomain-locker0.2.81 of 3See more

domain-locker domain-locker 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
lissy93/domain-locker:latestd3c95edc0a8b
ws@8.18.0
8.21.0

Open the chart page →

1,882
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
ws@7.5.10
7.5.11

Open the chart page →

31,510
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
ws@8.17.1
8.21.0

Open the chart page →

1,442
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
ws@8.18.0
8.21.0

Open the chart page →

11,458
taigafermosit0.0.111 of 7See more

taiga fermosit 0.0.11

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
taigaio/taiga-events:latest92fc0822564f
ws@7.4.6
7.5.11

Open the chart page →

8,496
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
ws@6.2.1
6.2.4

Open the chart page →

2,519
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
ws@8.5.0
8.21.0

Open the chart page →

4,260
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
ws@8.2.3
8.21.0

Open the chart page →

15,653
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
ws@7.4.3
7.5.11

Open the chart page →

4,405
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
ws@6.2.2
6.2.4

Open the chart page →

7,801
sendgeek-cookbookVerified publisher1.2.21 of 1See more

send geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
ws@7.5.7
7.5.11

Open the chart page →

1,148
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
ws@8.2.3
8.21.0

Open the chart page →

5,079
zigbee2mqttgeek-cookbookVerified publisher9.4.21 of 1See more

zigbee2mqtt geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
ws@7.4.5
7.5.11

Open the chart page →

2,173
globalpingglobalpingVerified publisher1.0.111 of 1See more

globalping globalping 1.0.11

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
globalping/globalping-probe:latest8acbd23009fd
ws@8.17.1
8.21.0

Open the chart page →

518
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
ws@8.11.0
8.21.0

Open the chart page →

4,196
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
ws@8.17.1
8.21.0

Open the chart page →

15,712
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
ws@7.4.6
7.5.11

Open the chart page →

17,284
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
ws@7.5.5
7.5.11

Open the chart page →

3,369
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
ws@6.2.2
6.2.4

Open the chart page →

3,143
difykubeblocksVerified publisher0.5.12 of 5See more

dify kubeblocks 0.5.1

2 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
ws@7.3.1
7.5.11
langgenius/dify-web:0.6.11a2a294743634
ws@7.5.9
7.5.11

Open the chart page →

20,403
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
litlyx/litlyx-dashboard:lateste64ff2d52385
ws@8.18.3
8.21.0

Open the chart page →

7,874
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
ws@6.2.1
6.2.4

Open the chart page →

5,940
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ws@5.2.2
5.2.5

Open the chart page →

19,187
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
ws@8.20.1
8.21.0

Open the chart page →

2,575
open-api-discoveryopen-api-discoveryVerified publisher0.1.11 of 1See more

open-api-discovery open-api-discovery 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
lukasreining/open-api-schema-collector:0.1.050e021c42e33
ws@7.5.9
7.5.11

Open the chart page →

2,473
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
ws@8.17.1
8.21.0

Open the chart page →

6,883

Container images carrying it

441 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
keyoxide/keyoxide:stable96f27a71269d
ws@8.5.0
8.21.0
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
ws@8.5.0
8.21.0
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ws@8.18.3
8.21.0
1
konradkleine/docker-registry-frontend:v2181aad54ee64
ws@1.1.2
5.2.5
1
koumoul/capture:17108d47be3b2
ws@6.2.1
6.2.4
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
ws@7.5.8
7.5.11
1
kubebb/component-store:latestfd8ecbd73213
ws@8.14.2
8.21.0
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
ws@6.2.1
6.2.4
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
ws@8.17.0
8.21.0
1
kubevious/backend:1.2.22d9ba6eb46b6
ws@8.13.0
8.21.0
1
kubevious/collector:1.2.1f58226f9d84e
ws@8.11.0
8.21.0
1
kubevious/guard:1.2.19bf567704de2
ws@8.2.3
8.21.0
1
kubevious/parser:1.2.299ae7a5168c2
ws@8.13.0
8.21.0
1
kyleslugg/klusterview:latestba8c36dfdfbd
ws@8.13.0
8.21.0
1
kyso/kyso-front:lateste52595c5c16f
ws@8.11.0
8.21.0
1
langgenius/dify-api:1.0.0066035f93856
ws@7.3.1
7.5.11
1
langgenius/dify-api:0.6.11fca918260dd6
ws@7.3.1
7.5.11
1
langgenius/dify-web:0.6.11a2a294743634
ws@7.5.9
7.5.11
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
ws@7.5.10
7.5.11
1
langgenius/dify-web:1.0.0d64914ff0d6d
ws@7.5.10
7.5.11
1
lavandadelpatio/frontend:latest501c3f31e0bc
ws@6.2.1
6.2.4
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
ws@8.18.0
8.21.0
1
library/ghost:6.37.01ef2e532ca4d
ws@8.20.0
8.21.0
1
library/ghost:6.25.12654b1e90413
ws@8.18.3
8.21.0
1
library/ghost:6.41.129773d6be407
ws@8.20.0
8.21.0
1
library/ghost:4.37.0767230c0f263
ws@8.5.0
8.21.0
1
library/ghost:6.39.0-alpine77196da4b0df
ws@8.20.0
8.21.0
1
library/ghost:5.79.083f7bf209844
ws@8.11.0
8.21.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
ws@8.18.3
8.21.0
1
library/kibana:7.17.150172f1c538e7
ws@8.14.2
8.21.0
1
library/kibana:8.18.004c0fc150f3a
ws@8.18.0
8.21.0
1
library/kibana:7.17.8c5781ba340ef
ws@8.9.0
8.21.0
1
library/kibana:7.17.3e2e2031c15be
ws@7.4.6
7.5.11
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
ws@7.4.6
7.5.11
1
linuxserver/code-server:4.10.1a5e43a05ae79
ws@8.2.0
8.21.0
1
linuxserver/codimd:latestb801bbcf6386
ws@6.1.4
6.2.4
1
lissy93/dashy:2.0.51991f7be5ed0
ws@8.3.0
8.21.0
1
lissy93/domain-locker:latestd3c95edc0a8b
ws@8.18.0
8.21.0
1
litlyx/litlyx-dashboard:lateste64ff2d52385
ws@8.18.3
8.21.0
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
ws@7.5.10
7.5.11
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
ws@8.11.0
8.21.0
1
louislam/uptime-kuma:13d632903e6af
ws@7.5.10
7.5.11
1
louislam/uptime-kuma:2.5.33e24e96c89ef
ws@8.19.0
8.21.0
1
louislam/uptime-kuma:2.0.24c364ef96aad
ws@8.17.1
8.21.0
1
louislam/uptime-kuma:2.4.091e963bfda56
ws@8.20.1
8.21.0
1
louislam/uptime-kuma:1.23.1396510915e6be
ws@8.11.0
8.21.0
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
ws@8.17.1
8.21.0
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
ws@8.2.3
8.21.0
1
louislam/uptime-kuma:1.18.5a84767d7934f
ws@7.5.9
7.5.11
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
ws@8.11.0
8.21.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.