StackRadar

CVE-2026-48815

High

Advisory

Published 1 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
459
of 17,787 indexed, latest versions
Container images
485
deployed by those charts
Fix available
1 of 1
affected package

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

Carried by container images the latest versions of 459 of 17,787 indexed charts deploy, on 485 images.

Affected packageAffected versionsFixed inImages
sigstorenpm1.0.0, 1.2.0, 1.4.0, 1.5.2+10 more4.1.1485
OSV records
GHSA-52v5-jr5w-gjxr

Charts affected

459 by stars
ChartLatestAffected imagesRadar Score
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
sigstore@3.1.0
4.1.1

Open the chart page →

6,470
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
sigstore@2.3.0
4.1.1

Open the chart page →

3,030
websitewaldo-visionVerified publisher0.33.02 of 2See more

website waldo-vision 0.33.0

2 of the 2 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
sigstore@1.0.0
4.1.1
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
sigstore@1.0.0
4.1.1

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
sigstore@3.0.0
4.1.1

Open the chart page →

5,774
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
sigstore@4.1.0
4.1.1

Open the chart page →

1,634
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
sigstore@4.1.0
4.1.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
sigstore@4.1.0
4.1.1

Open the chart page →

5,472
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
sigstore@2.3.0
4.1.1

Open the chart page →

14,172
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
sigstore@1.4.0
4.1.1

Open the chart page →

1,588

Container images carrying it

485 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
sigstore@4.0.0
4.1.1
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
sigstore@2.3.1
4.1.1
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
sigstore@3.1.0
4.1.1
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
sigstore@2.1.0
4.1.1
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
sigstore@2.3.0
4.1.1
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
sigstore@3.0.0
4.1.1
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
sigstore@3.0.0
4.1.1
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
sigstore@3.0.0
4.1.1
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
sigstore@3.1.0
4.1.1
1
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
sigstore@3.0.0
4.1.1
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
sigstore@2.3.1
4.1.1
1
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
sigstore@3.1.0
4.1.1
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
sigstore@4.1.0
4.1.1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
sigstore@3.0.0
4.1.1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
sigstore@2.3.1
4.1.1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
sigstore@2.3.0
4.1.1
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
sigstore@2.1.0
4.1.1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
sigstore@2.1.0
4.1.1
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
sigstore@2.3.1
4.1.1
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
sigstore@4.1.0
4.1.1
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
sigstore@3.1.0
4.1.1
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
sigstore@3.1.0
4.1.1
1
quay.io/mittwald/kube-mail:latest04f1099241fc
sigstore@2.3.1
4.1.1
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
sigstore@2.2.2
4.1.1
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
sigstore@2.3.1
4.1.1
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
sigstore@3.1.0
4.1.1
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
sigstore@3.1.0
4.1.1
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
sigstore@3.0.0
4.1.1
1
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
sigstore@2.3.1
4.1.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
sigstore@3.1.0
4.1.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
sigstore@4.1.0
4.1.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
sigstore@3.1.0
4.1.1
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
sigstore@3.1.0
4.1.1
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
sigstore@3.1.0
4.1.1
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
sigstore@2.3.1
4.1.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.