StackRadar

CVE-2026-48815

High

Advisory

Published 1 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
458
of 17,781 indexed, latest versions
Container images
484
deployed by those charts
Fix available
1 of 1
affected package

sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced

Carried by container images the latest versions of 458 of 17,781 indexed charts deploy, on 484 images.

Affected packageAffected versionsFixed inImages
sigstorenpm1.0.0, 1.2.0, 1.4.0, 1.5.2+10 more4.1.1484
OSV records
GHSA-52v5-jr5w-gjxr

Charts affected

458 by stars
ChartLatestAffected imagesRadar Score
vote-appvote-appVerified publisher1.0.71 of 6See more

vote-app vote-app 1.0.7

1 of the 6 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
thecloudspark/app-result:1.09a5302cb8312
sigstore@2.3.0
4.1.1

Open the chart page →

3,031
websitewaldo-visionVerified publisher0.33.02 of 2See more

website waldo-vision 0.33.0

2 of the 2 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
sigstore@1.0.0
4.1.1
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
sigstore@1.0.0
4.1.1

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
sigstore@3.0.0
4.1.1

Open the chart page →

5,984
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
sigstore@4.1.0
4.1.1

Open the chart page →

1,616
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
sigstore@4.1.0
4.1.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
sigstore@4.1.0
4.1.1

Open the chart page →

5,459
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
sigstore@2.3.0
4.1.1

Open the chart page →

14,100
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-48815.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
sigstore@1.4.0
4.1.1

Open the chart page →

1,589

Container images carrying it

484 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
decisionrules/server:latestf38d8571fa06
sigstore@3.1.0
4.1.1
4
redis/redisinsight:3.8:latestb5e19ee240ab
sigstore@3.1.0
4.1.1
4
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
sigstore@2.3.1
4.1.1
4
rcdelacruz/my-strapi-app:js-amd6438007f358355
sigstore@2.1.0
4.1.1
3
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
sigstore@3.1.0
4.1.1
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
sigstore@3.1.0
4.1.1
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
sigstore@4.0.0
4.1.1
3
epamedp/krci-portal:0.8.0687acf641097
sigstore@2.3.0
4.1.1
2
ethersphere/bee-localchain:latest0558799ca992
sigstore@2.1.0
4.1.1
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
sigstore@1.5.2
4.1.1
2
gradiant/open5gs-webui:2.7.5fbd10c017541
sigstore@2.1.0
4.1.1
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
sigstore@2.3.1
4.1.1
2
ilum/ui:6.7.3998937726679
sigstore@4.0.0
4.1.1
2
infisical/infisical:latest:v0.165.602082bf13163
sigstore@2.3.1
4.1.1
2
kutt/kutt:latest:v3.2.6fa3d24a89b04
sigstore@3.1.0
4.1.1
2
langgenius/dify-sandbox:0.2.009b7e8705673
sigstore@2.1.0
4.1.1
2
library/ghost:6.63.0e05bc1169fb2
sigstore@3.1.0
4.1.1
2
library/mongo-express:1.0.2:latest1b23d7976f02
sigstore@2.3.0
4.1.1
2
louislam/uptime-kuma:2.5.4917318f9d7be
sigstore@3.1.0
4.1.1
2
louislam/uptime-kuma:2.3.29aeb4e51d038
sigstore@3.1.0
4.1.1
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
sigstore@3.1.0
4.1.1
2
mojaloop/reporting:v12.1.0d480a62103d6
sigstore@2.3.1
4.1.1
2
mojaloop/reporting-aggregator-svc:v0.0.92635baf23298
sigstore@3.0.0
4.1.1
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
sigstore@3.1.0
4.1.1
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
sigstore@3.0.0
4.1.1
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
sigstore@2.1.0
4.1.1
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
sigstore@4.0.0
4.1.1
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
sigstore@2.1.0
4.1.1
2
outlinewiki/outline:0.69.1d060dcd8f9aa
sigstore@1.0.0
4.1.1
2
rajnandan1/kener:3.2.1930407afca731
sigstore@3.0.0
4.1.1
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
sigstore@1.7.0
4.1.1
2
requarks/wiki:2:latest68f0d1848261
sigstore@4.1.0
4.1.1
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
sigstore@2.1.0
4.1.1
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
sigstore@2.3.1
4.1.1
2
verdaccio/verdaccio:6.10.209b403888c8f
sigstore@4.1.0
4.1.1
2
ghcr.io/api7/adc:0.27.1f65f53dd9668
sigstore@4.1.0
4.1.1
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
sigstore@3.0.0
4.1.1
2
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
sigstore@2.3.1
4.1.1
2
ghcr.io/gethomepage/homepage:latest:v2.2.0753eeb0cc22a
sigstore@3.1.0
4.1.1
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
sigstore@3.1.0
4.1.1
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
sigstore@3.0.0
4.1.1
2
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
sigstore@2.1.0
4.1.1
2
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
sigstore@3.0.0
4.1.1
2
aaronshaf/dynamodb-admin:latestac41724cd997
sigstore@4.1.0
4.1.1
1
activepieces/activepieces:0.90.430c10a04fe3d
sigstore@4.1.0
4.1.1
1
actualbudget/actual-server:25.3.158fecd9088b7
sigstore@2.3.1
4.1.1
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
sigstore@3.1.0
4.1.1
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
sigstore@3.1.0
4.1.1
1
agentarea/agentarea-frontend:latest2098a9d7b1fe
sigstore@3.1.0
4.1.1
1
agentarea/agentarea-mcp-runner:latestd3c209a5d531
sigstore@3.1.0
4.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.