StackRadar

CVE-2026-48815

High

Advisory

Published 1 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
452
of 17,787 indexed, latest versions
Container images
477
deployed by those charts
Fix available
1 of 1
affected package

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

Carried by container images the latest versions of 452 of 17,787 indexed charts deploy, on 477 images.

Affected packageAffected versionsFixed inImages
sigstorenpm1.0.0, 1.2.0, 1.4.0, 1.5.2+10 more4.1.1477
OSV records
GHSA-52v5-jr5w-gjxr

Charts affected

452 by stars
ChartLatestAffected imagesRadar Score
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
sigstore@2.3.0
4.1.1

Open the chart page →

14,100
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
sigstore@1.4.0
4.1.1

Open the chart page →

1,589

Container images carrying it

477 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
documenso/documenso:v1.8.17f16a9449f18
sigstore@2.3.1
4.1.1
1
drumsergio/genieacs:1.2.16.028244054e1bf
sigstore@4.1.0
4.1.1
1
drumsergio/lynxprompt:2.0.75c6afb6679301
sigstore@4.1.0
4.1.1
1
drumsergio/pumperly:1.4.885bbc3915e9e
sigstore@3.1.0
4.1.1
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
sigstore@2.1.0
4.1.1
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
sigstore@4.1.0
4.1.1
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
sigstore@2.3.1
4.1.1
1
etherpad/etherpad:2.7.2b723fe5f2594
sigstore@4.1.0
4.1.1
1
ethersphere/etherproxy:1.0.056029b0985f4
sigstore@1.7.0
4.1.1
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
sigstore@3.0.0
4.1.1
1
ethpandaops/ethereumjs:masterfb84b718500f
sigstore@2.3.1
4.1.1
1
evoapicloud/evolution-api:latest966625532d90
sigstore@4.1.0
4.1.1
1
fallenbagel/jellyseerr:latest4538137bc5af
sigstore@3.1.0
4.1.1
1
felddy/foundryvtt:12.343.06c5e3e9ffbb0
sigstore@2.3.0
4.1.1
1
felipecs8/conversor-temperatura:v1f945423be36d
sigstore@2.3.1
4.1.1
1
felipecs8/landing-page:v1db6d44e325a1
sigstore@3.1.0
4.1.1
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
sigstore@2.3.1
4.1.1
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
sigstore@3.0.0
4.1.1
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
sigstore@3.0.0
4.1.1
1
folioci/mod-graphql:latestf0655a6a08fd
sigstore@2.3.1
4.1.1
1
fonoster/routr-pgdata-migrations:2.13.6c7b1dba81eb3
sigstore@2.3.0
4.1.1
1
fosrl/pangolin:1.13.0c32ad797ab96
sigstore@4.0.0
4.1.1
1
fthomas/scala-steward:latest367afe974b7a
sigstore@4.1.0
4.1.1
1
gethue/hue:latest7d5c1b9f8a79
sigstore@4.1.0
4.1.1
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
sigstore@3.1.0
4.1.1
1
globalping/globalping-probe:latest8acbd23009fd
sigstore@3.1.0
4.1.1
1
hamid2021/nodejs-dockercli:latest429d99890c3c
sigstore@2.1.0
4.1.1
1
hansehe/graphql-gateway:1.0.458e09540afbc
sigstore@2.1.0
4.1.1
1
haohanyang/compass-web:0.5.054f2112602ee
sigstore@4.1.0
4.1.1
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
sigstore@1.5.2
4.1.1
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
sigstore@2.3.1
4.1.1
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
sigstore@1.2.0
4.1.1
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
sigstore@1.7.0
4.1.1
1
heywood8/redisinsight:2.28.00bc9ab313d37
sigstore@1.0.0
4.1.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
sigstore@3.1.0
4.1.1
1
honglab/slack-emoji-maker:v0.0.1ca075a926fe1
sigstore@2.3.1
4.1.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
sigstore@2.3.1
4.1.1
1
ilum/marquez-web:0.53.2716437a51a6c
sigstore@4.0.0
4.1.1
1
instill/console:0.68.54cd70e2df5c6
sigstore@2.3.1
4.1.1
1
instructure/kinesalite:latest34400d82f28f
sigstore@1.7.0
4.1.1
1
intelloop/atlas-cmms-frontend:v1.5.12409c2a00ab6
sigstore@2.1.0
4.1.1
1
jaedb/iris:latest048cfbf58d57
sigstore@2.3.1
4.1.1
1
jesec/flood:4.14.3c887dad96b40
sigstore@3.1.0
4.1.1
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
sigstore@2.3.1
4.1.1
1
jkroepke/github_exporter:1.8.03d850992786d
sigstore@4.0.0
4.1.1
1
johly/airtrail:v3.11.19f702b91e0e7
sigstore@3.1.0
4.1.1
1
joplin/server:3.0-beta52af57880c0e
sigstore@2.3.0
4.1.1
1
joplin/server:2.14.2-betab87564ef34e9
sigstore@2.1.0
4.1.1
1
josepht05/nodejs-feb24:latest36cb0c618c94
sigstore@2.1.0
4.1.1
1
josepht05/titajo-docker:v1.0.0d94024965d78
sigstore@2.1.0
4.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.