StackRadar

CVE-2026-48815

High

Advisory

Published 1 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
452
of 17,787 indexed, latest versions
Container images
477
deployed by those charts
Fix available
1 of 1
affected package

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

Carried by container images the latest versions of 452 of 17,787 indexed charts deploy, on 477 images.

Affected packageAffected versionsFixed inImages
sigstorenpm1.0.0, 1.2.0, 1.4.0, 1.5.2+10 more4.1.1477
OSV records
GHSA-52v5-jr5w-gjxr

Charts affected

452 by stars
ChartLatestAffected imagesRadar Score
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
sigstore@2.3.0
4.1.1

Open the chart page →

14,100
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
sigstore@1.4.0
4.1.1

Open the chart page →

1,589

Container images carrying it

477 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
sigstore@2.3.1
4.1.1
1
alazidis/stornx:1.1.1602d4f7f090c
sigstore@4.1.0
4.1.1
1
alquimiaai/studio:certification38a1f0341982
sigstore@2.3.1
4.1.1
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
sigstore@2.3.1
4.1.1
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
sigstore@2.3.1
4.1.1
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
sigstore@2.3.1
4.1.1
1
archivebox/archivebox:0.7.41a5a37331091
sigstore@4.1.0
4.1.1
1
assistiot/multi-link_client:latestcf048365d042
sigstore@2.1.0
4.1.1
1
assistiot/multi-link_server:latestf38c76a4c960
sigstore@2.1.0
4.1.1
1
automatischio/automatisch:0.15.03bace7a12d5f
sigstore@3.0.0
4.1.1
1
baserow/baserow:1.30.1df0c42eb67e8
sigstore@2.2.2
4.1.1
1
belirta/beli-docker:v1.0.0f65ad0e23b4d
sigstore@1.5.2
4.1.1
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
sigstore@2.3.1
4.1.1
1
bluerange/bluerange-mosquitto:25f1bfbba84832
sigstore@4.0.0
4.1.1
1
bnjbvr/kresus:0.22.137e216b182c8
sigstore@2.3.1
4.1.1
1
bnwokoye/nodejswebapp:latest74de7dc7ebfb
sigstore@1.0.0
4.1.1
1
budibase/apps:3.41.344fe6feab985
sigstore@3.1.0
4.1.1
1
budibase/database:2.1.0d90f656261c9
sigstore@4.1.0
4.1.1
1
budibase/worker:3.41.3de5e2e560ce8
sigstore@3.1.0
4.1.1
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
sigstore@2.3.1
4.1.1
1
ccjacobs14/amazon:59a9b14a6f09e
sigstore@2.1.0
4.1.1
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
sigstore@3.0.0
4.1.1
1
chatwoot/chatwoot:v4.15.167ebc751c171
sigstore@4.1.0
4.1.1
1
chibisafe/chibisafe:latest836467a50792
sigstore@2.3.1
4.1.1
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
sigstore@2.3.1
4.1.1
1
chocobozzz/peertube:v8.1.5052712130691
sigstore@2.3.1
4.1.1
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
sigstore@3.0.0
4.1.1
1
contane/foreman:0.5.2efb98bdcc4e9
sigstore@3.0.0
4.1.1
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
sigstore@3.1.0
4.1.1
1
countly/api:25.05.4f4cc7447c4f5
sigstore@2.3.0
4.1.1
1
countly/countly-server:25.05.4e3c238248f99
sigstore@2.3.0
4.1.1
1
countly/frontend:25.05.42acbc11499b6
sigstore@2.3.0
4.1.1
1
cryptexlabs/authf:0.12.11189c07411d7c
sigstore@2.1.0
4.1.1
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
sigstore@2.1.0
4.1.1
1
cspconsole/report-processor:1.0.279a2d8840bfdf
sigstore@3.1.0
4.1.1
1
dacinfomotion/h2p:latest68fa393b472c
sigstore@1.7.0
4.1.1
1
danny1dockerhub/nodejswebapp:lateste434683fcc89
sigstore@1.0.0
4.1.1
1
davdiv/musicociel:deva85f99be882c
sigstore@2.1.0
4.1.1
1
dbgate/dbgate:7.2.0-alpine287077002446
sigstore@2.3.1
4.1.1
1
dbgate/dbgate:7.2.3f2dc7423ea88
sigstore@3.1.0
4.1.1
1
decisionrules/business-intelligence:latest1135a6d4f09b
sigstore@3.1.0
4.1.1
1
defactops/defactops-backend:1.0.2307b663c0092a
sigstore@2.2.2
4.1.1
1
devkrishan001/backend:latestf1c3acadeabe
sigstore@2.3.1
4.1.1
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
sigstore@4.1.0
4.1.1
1
devravinder/node-express-app:1.0.05325a96967b5
sigstore@3.0.0
4.1.1
1
dgtlmoon/sockpuppetbrowser:latestf166a963b550
sigstore@1.4.0
4.1.1
1
directus/directus:12.0.29c8470ea465c
sigstore@3.1.0
4.1.1
1
directus/directus:11.1.0e3c8bb975350
sigstore@2.3.0
4.1.1
1
diygod/rsshub:2025-11-097a6312cac0d5
sigstore@3.1.0
4.1.1
1
docmost/docmost:0.95.041c8d777cf23
sigstore@3.1.0
4.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.