StackRadar

CVE-2026-48779

High

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.008
55th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
443
of 17,781 indexed, latest versions
Container images
441
deployed by those charts
Fix available
1 of 2
affected packages

ws: Memory exhaustion DoS from tiny fragments and data chunks

Carried by container images the latest versions of 443 of 17,781 indexed charts deploy, on 441 images.

Affected packageAffected versionsFixed inImages
wsnpm1.1.0, 1.1.1, 1.1.2, 1.1.4+57 more5.2.5, 6.2.4, 7.5.11, 8.21.0441
node-wsdeb8.11.0+~cs13.7.3-1no fix listed2
OSV records
DEBIAN-CVE-2026-48779GHSA-96hv-2xvq-fx4p

Charts affected

443 by stars
ChartLatestAffected imagesRadar Score
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
ws@7.5.10
7.5.11

Open the chart page →

1,809
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
ws@8.18.3
8.21.0

Open the chart page →

1,391
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
ws@8.18.3
8.21.0

Open the chart page →

33,242
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
ws@8.17.1
8.21.0

Open the chart page →

1,490
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
ws@6.2.1
6.2.4

Open the chart page →

3,651
lynxpromptlynxpromptVerified publisher0.1.21 of 3See more

lynxprompt lynxprompt 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
ws@8.20.0
8.21.0

Open the chart page →

1,852
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
ws@8.16.0
8.21.0

Open the chart page →

9,774
nodecg-chartmarathon-charts0.1.51 of 2See more

nodecg-chart marathon-charts 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/rodg/nodecg-base:latest31be4bf87070
ws@8.11.0
8.21.0

Open the chart page →

7,315
kubevismario-fVerified publisher2.0.11 of 1See more

kubevis mario-f 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
ws@6.2.2
6.2.4

Open the chart page →

5,287
maxcrm-chartsmaxcrm-chartsVerified publisher1.1.2011 of 4See more

maxcrm-charts maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
ws@6.2.1
6.2.4

Open the chart page →

5,940
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
ws@5.2.3
5.2.5

Open the chart page →

29,588
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
ws@8.17.1
8.21.0

Open the chart page →

9,668
kommandermesosphere-stable0.39.21 of 29See more

kommander mesosphere-stable 0.39.2

1 of the 29 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
ws@7.3.1
7.5.11

Open the chart page →

68,284
opsportalmesosphere-stable0.9.51 of 3See more

opsportal mesosphere-stable 0.9.5

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mesosphere/kommander:6.100.13917e82333a9
ws@7.3.1
7.5.11

Open the chart page →

7,027
middleware-odigosmiddleware-labsVerified publisher0.2.411 of 6See more

middleware-odigos middleware-labs 0.2.41

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-ui:middleware-test-0.0.787120a4561a9
ws@7.5.8
7.5.11

Open the chart page →

8,370
middleware-visionmiddleware-labsVerified publisher0.2.651 of 6See more

middleware-vision middleware-labs 0.2.65

1 of the 6 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-ui:middleware-test-0.0.853772b7b42c7
ws@7.5.8
7.5.11

Open the chart page →

8,361
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
ws@8.18.2
8.21.0

Open the chart page →

43,341
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
ws@7.4.6
7.5.11

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
ws@7.4.6
7.5.11

Open the chart page →

10,603
iotmmontesVerified publisher0.3.23 of 7See more

iot mmontes 0.3.2

3 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
ws@6.2.2
6.2.4
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
ws@7.4.6
7.5.11
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
ws@6.2.2
6.2.4

Open the chart page →

10,608
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ws@8.18.3
8.21.0

Open the chart page →

2,457
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
ws@7.5.10
7.5.11

Open the chart page →

14,809
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
ws@7.5.10
7.5.11

Open the chart page →

1,948
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ws@8.18.3
8.21.0

Open the chart page →

2,457
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
ws@6.2.1
6.2.4

Open the chart page →

6,438
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
ws@1.1.1
5.2.5
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
ws@1.1.4
5.2.5

Open the chart page →

7,048
monopolymonopolypackage0.1.01 of 1See more

monopoly monopolypackage 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
gonzague/monopoly:latest70465995deea
ws@3.3.3
5.2.5

Open the chart page →

1,130
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
ws@7.5.8
7.5.11

Open the chart page →

10,959
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
ws@7.2.5
7.5.11

Open the chart page →

6,684
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
ws@8.11.0
8.21.0

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
ws@8.18.3
8.21.0

Open the chart page →

4,960
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
ws@8.2.3
8.21.0

Open the chart page →

6,608
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
ws@8.2.3
8.21.0

Open the chart page →

3,128
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
ws@8.13.0
8.21.0

Open the chart page →

2,116
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
ws@8.13.0
8.21.0

Open the chart page →

2,116
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
ws@8.13.0
8.21.0

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
ws@8.13.0
8.21.0

Open the chart page →

2,116
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
ws@7.5.9
7.5.11

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
ws@8.3.0
8.21.0

Open the chart page →

3,269
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
ws@3.3.3
5.2.5

Open the chart page →

109,294
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
ws@8.19.0
8.21.0

Open the chart page →

30,028
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
ws@8.20.0
8.21.0

Open the chart page →

1,166
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
ws@8.16.0
8.21.0

Open the chart page →

6,982
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
ws@8.19.0
8.21.0

Open the chart page →

2,383
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
ws@8.19.0
8.21.0

Open the chart page →

3,798
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
ws@3.3.3
5.2.5

Open the chart page →

2,919
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
ws@7.5.9
7.5.11

Open the chart page →

15,132
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
ws@7.5.9
7.5.11

Open the chart page →

15,206
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
ws@8.13.0
8.21.0

Open the chart page →

15,187
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-48779.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
ws@6.1.4
6.2.4

Open the chart page →

27,465

Container images carrying it

441 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kodekloud/examplevotingapp_result:v1e510023fdf38
ws@7.4.6
7.5.11
4
oscarsotosanchez/server:v1.06e2e1279126b
ws@5.2.2
5.2.5
4
redis/redisinsight:3.8:latestb5e19ee240ab
ws@8.17.1
8.21.0
4
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
ws@8.11.0
8.21.0
4
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
ws@8.14.1
8.21.0
4
pantsel/konga:latestc8172b75607d
ws@1.1.2
5.2.5
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
ws@8.13.0
8.21.0
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
ws@3.3.3
5.2.5
3
agoldis/sorry-cypress-director:2.5.1110228ecd353b
ws@7.4.6
7.5.11
2
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
ws@6.2.1
6.2.4
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
ws@6.2.1
6.2.4
2
ethersphere/bee-localchain:latest0558799ca992
ws@7.4.6
7.5.11
2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
ws@5.2.2
5.2.5
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
ws@7.4.6
7.5.11
2
governify/assets-manager:v1.4.12987672448c7
ws@6.2.0
6.2.4
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
ws@8.17.1
8.21.0
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
ws@7.4.5
7.5.11
2
krtk6160/galoy-nostrcc82a694f818
ws@8.12.1
8.21.0
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
ws@7.5.9
7.5.11
2
louislam/uptime-kuma:2.5.4917318f9d7be
ws@8.19.0
8.21.0
2
louislam/uptime-kuma:2.3.29aeb4e51d038
ws@8.18.3
8.21.0
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
ws@8.19.0
8.21.0
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
ws@6.2.1
6.2.4
2
mesosphere/kommander:6.100.13917e82333a9
ws@7.3.1
7.5.11
2
migmartri/prerender:latest486aacfd5aa9
ws@1.1.1
5.2.5
2
mojaloop/reporting:v12.1.0d480a62103d6
ws@7.5.10
7.5.11
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
ws@8.18.3
8.21.0
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
ws@7.4.6
7.5.11
2
outlinewiki/outline:0.69.1d060dcd8f9aa
ws@8.13.0
8.21.0
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
ws@8.11.0
8.21.0
2
requarks/wiki:2:latest68f0d1848261
ws@5.2.4
5.2.5
2
shahanafarooqui/rtl:0.13.3e2195188a451
ws@8.11.0
8.21.0
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
ws@8.5.0
8.21.0
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
ws@6.2.2
6.2.4
2
taigaio/taiga-events:latest92fc0822564f
ws@7.4.6
7.5.11
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
ws@7.4.6
7.5.11
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
ws@6.2.2
6.2.4
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
ws@7.4.6
7.5.11
2
0hlov3/semaphore:v1.0.050f874ec096b
ws@7.5.9
7.5.11
1
activepieces/activepieces:0.90.430c10a04fe3d
ws@8.17.1
8.21.0
1
activepieces/activepieces:0.23.0c26188b44e62
ws@8.11.0
8.21.0
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
ws@8.19.0
8.21.0
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
ws@8.16.0
8.21.0
1
alazidis/stornx:1.1.1602d4f7f090c
ws@8.18.2
8.21.0
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
ws@5.2.2
5.2.5
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
ws@7.5.10
7.5.11
1
apimap/developer:v1.3.1406d3858e20c
ws@7.5.9
7.5.11
1
apimap/portal:v2.4.0041a4790c65c
ws@8.5.0
8.21.0
1
archivebox/archivebox:0.7.41a5a37331091
ws@8.20.1
8.21.0
1
arfath29/3-tier-app-frontend:latest384b3e377f47
ws@6.2.2
6.2.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.