StackRadar

CVE-2026-48815

High

Advisory

Published 1 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
459
of 17,787 indexed, latest versions
Container images
485
deployed by those charts
Fix available
1 of 1
affected package

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

Carried by container images the latest versions of 459 of 17,787 indexed charts deploy, on 485 images.

Affected packageAffected versionsFixed inImages
sigstorenpm1.0.0, 1.2.0, 1.4.0, 1.5.2+10 more4.1.1485
OSV records
GHSA-52v5-jr5w-gjxr

Charts affected

459 by stars
ChartLatestAffected imagesRadar Score
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
sigstore@3.1.0
4.1.1

Open the chart page →

6,470
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
sigstore@2.3.0
4.1.1

Open the chart page →

3,030
websitewaldo-visionVerified publisher0.33.02 of 2See more

website waldo-vision 0.33.0

2 of the 2 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
sigstore@1.0.0
4.1.1
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
sigstore@1.0.0
4.1.1

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
sigstore@3.0.0
4.1.1

Open the chart page →

5,774
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
sigstore@4.1.0
4.1.1

Open the chart page →

1,634
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
sigstore@4.1.0
4.1.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
sigstore@4.1.0
4.1.1

Open the chart page →

5,472
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
sigstore@2.3.0
4.1.1

Open the chart page →

14,172
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
sigstore@1.4.0
4.1.1

Open the chart page →

1,588

Container images carrying it

485 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
sigstore@2.3.1
4.1.1
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
sigstore@2.2.2
4.1.1
1
ghcr.io/berriai/litellm-database:litellm_stable_release_branch-v1.75.5-stableab63d26a8a2c
sigstore@3.1.0
4.1.1
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
sigstore@2.3.1
4.1.1
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
sigstore@2.3.1
4.1.1
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
sigstore@2.3.1
4.1.1
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
sigstore@4.1.0
4.1.1
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
sigstore@2.3.1
4.1.1
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
sigstore@3.0.0
4.1.1
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
sigstore@3.1.0
4.1.1
1
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
sigstore@3.0.0
4.1.1
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
sigstore@2.3.1
4.1.1
1
ghcr.io/calesthio/crucix:latest67c5244b6acf
sigstore@3.1.0
4.1.1
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
sigstore@1.7.0
4.1.1
1
ghcr.io/colanode/server:latest7006cac874fd
sigstore@3.1.0
4.1.1
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
sigstore@2.3.0
4.1.1
1
ghcr.io/cross-seed/cross-seed:6.13.7a1fed512261f
sigstore@2.3.1
4.1.1
1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
sigstore@4.0.0
4.1.1
1
ghcr.io/curium-rocks/k8s-mutating-webhook:mainaaab005242ae
sigstore@2.1.0
4.1.1
1
ghcr.io/curium-rocks/k8s-validating-webhook:main8344061b2f22
sigstore@2.1.0
4.1.1
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
sigstore@2.3.1
4.1.1
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
sigstore@2.3.1
4.1.1
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
sigstore@2.1.0
4.1.1
1
ghcr.io/data-fair/notify:3c739b74dabb0
sigstore@3.0.0
4.1.1
1
ghcr.io/data-fair/portals:18b621866ceb2
sigstore@1.0.0
4.1.1
1
ghcr.io/data-fair/processings:15a9216989707
sigstore@2.1.0
4.1.1
1
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
sigstore@2.1.0
4.1.1
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
sigstore@3.0.0
4.1.1
1
ghcr.io/firecrawl/firecrawl:2.11.33470453d7102cc
sigstore@3.1.0
4.1.1
1
ghcr.io/firecrawl/playwright-service:latest1f6eba640320
sigstore@2.3.1
4.1.1
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
sigstore@2.3.1
4.1.1
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
sigstore@3.1.0
4.1.1
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
sigstore@3.1.0
4.1.1
1
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
sigstore@3.1.0
4.1.1
1
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
sigstore@3.1.0
4.1.1
1
ghcr.io/gethomepage/homepage:v2.3.0f82027665453
sigstore@3.1.0
4.1.1
1
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
sigstore@2.3.1
4.1.1
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
sigstore@4.1.0
4.1.1
1
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
sigstore@3.1.0
4.1.1
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
sigstore@2.3.1
4.1.1
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
sigstore@2.3.1
4.1.1
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
sigstore@3.1.0
4.1.1
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
sigstore@4.1.0
4.1.1
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
sigstore@3.1.0
4.1.1
1
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
sigstore@3.1.0
4.1.1
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
sigstore@3.0.0
4.1.1
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
sigstore@2.3.1
4.1.1
1
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
sigstore@3.1.0
4.1.1
1
ghcr.io/kadajett/podscope:0.2.3eeedf17112d7
sigstore@2.3.1
4.1.1
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
sigstore@3.1.0
4.1.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.