StackRadar

CVE-2026-48801

High

Advisory

Published 26 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
109
of 17,781 indexed, latest versions
Container images
97
deployed by those charts
Fix available
1 of 1
affected package

LinkifyIt#match scan loop has quadratic algorithmic complexity

Carried by container images the latest versions of 109 of 17,781 indexed charts deploy, on 97 images.

Affected packageAffected versionsFixed inImages
linkify-itnpm2.0.3, 2.1.0, 2.2.0, 3.0.2+3 more5.0.197
OSV records
GHSA-22p9-wv53-3rq4

Charts affected

109 by stars
ChartLatestAffected imagesRadar Score
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-48801.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
linkify-it@4.0.1
5.0.1

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-48801.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
linkify-it@3.0.3
5.0.1

Open the chart page →

3,638
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-48801.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
linkify-it@5.0.0
5.0.1

Open the chart page →

1,991
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-48801.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
linkify-it@3.0.3
5.0.1

Open the chart page →

4,017
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-48801.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
linkify-it@4.0.1
5.0.1

Open the chart page →

5,535
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48801.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
linkify-it@4.0.1
5.0.1

Open the chart page →

3,118
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-48801.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
linkify-it@3.0.3
5.0.1

Open the chart page →

280
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-48801.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
linkify-it@3.0.3
5.0.1

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-48801.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
linkify-it@5.0.0
5.0.1

Open the chart page →

6,285

Container images carrying it

97 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
assistiot/dlt_api:2.0.0e36a8922fa0c
linkify-it@3.0.3
5.0.1
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
linkify-it@2.2.0
5.0.1
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
linkify-it@3.0.3
5.0.1
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
linkify-it@3.0.3
5.0.1
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
linkify-it@5.0.0
5.0.1
3
governify/assets-manager:v1.4.12987672448c7
linkify-it@2.2.0
5.0.1
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
linkify-it@5.0.0
5.0.1
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
linkify-it@2.2.0
5.0.1
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
linkify-it@2.2.0
5.0.1
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
linkify-it@2.2.0
5.0.1
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
linkify-it@2.2.0
5.0.1
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
linkify-it@2.2.0
5.0.1
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
linkify-it@3.0.3
5.0.1
2
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
linkify-it@3.0.3
5.0.1
2
outlinewiki/outline:0.69.1d060dcd8f9aa
linkify-it@4.0.1
5.0.1
2
requarks/wiki:2:latest68f0d1848261
linkify-it@3.0.3
5.0.1
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
linkify-it@4.0.1
5.0.1
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
linkify-it@2.0.3
5.0.1
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
linkify-it@2.0.3
5.0.1
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
linkify-it@2.0.3
5.0.1
1
assistiot/dlt_api:2.1.0c8a170683be7
linkify-it@3.0.3
5.0.1
1
baserow/baserow:1.30.1df0c42eb67e8
linkify-it@5.0.0
5.0.1
1
chocobozzz/peertube:v8.1.5052712130691
linkify-it@5.0.0
5.0.1
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
linkify-it@4.0.1
5.0.1
1
codetogether/codetogether:latest4348c8a38752
linkify-it@3.0.3
5.0.1
1
countly/api:25.05.4f4cc7447c4f5
linkify-it@3.0.3
5.0.1
1
countly/countly-server:25.05.4e3c238248f99
linkify-it@5.0.0
5.0.1
1
countly/frontend:25.05.42acbc11499b6
linkify-it@5.0.0
5.0.1
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
linkify-it@5.0.0
5.0.1
1
diygod/rsshub:2025-11-097a6312cac0d5
linkify-it@5.0.0
5.0.1
1
enketo/enketo-express:3.0.4dcad9c2273f6
linkify-it@2.2.0
5.0.1
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
linkify-it@3.0.3
5.0.1
1
ethpandaops/ethereumjs:masterfb84b718500f
linkify-it@5.0.0
5.0.1
1
fallenbagel/jellyseerr:latest4538137bc5af
linkify-it@5.0.0
5.0.1
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
linkify-it@4.0.1
5.0.1
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
linkify-it@5.0.0
5.0.1
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
linkify-it@3.0.2
5.0.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
linkify-it@5.0.0
5.0.1
1
jayfong/yapi:1.10.2163e5d621910
linkify-it@2.2.0
5.0.1
1
joplin/server:latest3f7b852959aa
linkify-it@4.0.1
5.0.1
1
joplin/server:3.0-beta52af57880c0e
linkify-it@4.0.1
5.0.1
1
joplin/server:2.14.2-betab87564ef34e9
linkify-it@4.0.1
5.0.1
1
keyoxide/keyoxide:stable96f27a71269d
linkify-it@2.2.0
5.0.1
1
library/ghost:6.37.01ef2e532ca4d
linkify-it@5.0.0
5.0.1
1
library/ghost:6.25.12654b1e90413
linkify-it@5.0.0
5.0.1
1
library/ghost:6.41.129773d6be407
linkify-it@5.0.0
5.0.1
1
library/ghost:4.37.0767230c0f263
linkify-it@3.0.3
5.0.1
1
library/ghost:6.39.0-alpine77196da4b0df
linkify-it@5.0.0
5.0.1
1
library/ghost:5.79.083f7bf209844
linkify-it@5.0.0
5.0.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
linkify-it@5.0.0
5.0.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.