StackRadar

CVE-2026-48816

Medium

Advisory

Published 1 Jul 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
39
of 17,781 indexed, latest versions
Container images
37
deployed by those charts
Fix available
1 of 1
affected package

sigstore-js has Insufficient Verification of Data Authenticity

Carried by container images the latest versions of 39 of 17,781 indexed charts deploy, on 37 images.

Affected packageAffected versionsFixed inImages
@sigstore/verifynpm3.1.03.1.137
OSV records
GHSA-xgjw-pm74-86q4

Charts affected

39 by stars
ChartLatestAffected imagesRadar Score
verdaccioverdaccio4.35.11 of 1See more

verdaccio verdaccio 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

215
apisix-ingress-controllerapisix1.3.11 of 2See more

apisix-ingress-controller apisix 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

1,616
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

9,203
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

5,660
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

10,775
dynamodbkeyporttech0.1.271 of 2See more

dynamodb keyporttech 0.1.27

1 of the 2 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
aaronshaf/dynamodb-admin:latestac41724cd997
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

1,304
bitwarden-crd-operatorlerentisVerified publisher0.18.01 of 1See more

bitwarden-crd-operator lerentis 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

2,003
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

5,218
pacmanpacmanVerified publisher2.0.21 of 2See more

pacman pacman 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
ghcr.io/shuguet/pacman:latesta0ec71732c3c
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

638
enbuildenbuildVerified publisher0.0.501 of 6See more

enbuild enbuild 0.0.50

1 of the 6 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

31,510
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

12,397
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

2,575
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

5,482
stornxstornxVerified publisher1.1.11 of 9See more

stornx stornx 1.1.1

1 of the 9 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

11,574
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
supabase/storage-api:v1.60.4c8eb9858eafe
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

18,075
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

3,833
activepiecesadnoctemVerified publisher0.5.01 of 1See more

activepieces adnoctem 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
activepieces/activepieces:0.90.430c10a04fe3d
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

1,055
turborepo-remote-cacheadriantr1.1.11 of 1See more

turborepo-remote-cache adriantr 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
ducktors/turborepo-remote-cache:latest31ec9e83c844
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

523
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

6,486
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

1,755
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

4,259
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

7,633
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

11,042
self-learning-platformhelm-self-learning-platformVerified publisher1.1.01 of 1See more

self-learning-platform helm-self-learning-platform 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
devopsiaci/self-learning-platform:1.1.3d9441c931f75
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

1,468
portfolio-trackerkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

portfolio-tracker kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

1,498
lynxpromptlynxpromptVerified publisher0.1.21 of 3See more

lynxprompt lynxprompt 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

1,852
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

8,303
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

2,396
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

1,166
your-spotifyrubxkubeVerified publisher1.0.12 of 3See more

your-spotify rubxkube 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
yooooomi/your_spotify_client:1.20.0e4da90a0634c
@sigstore/verify@3.1.0
3.1.1
yooooomi/your_spotify_server:1.20.0624ea009f2ef
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

5,066
etherpadschoenwald0.3.01 of 1See more

etherpad schoenwald 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
etherpad/etherpad:2.7.2b723fe5f2594
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

2,133
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

5,201
stewardsoftwaremillVerified publisher0.1.121 of 1See more

steward softwaremill 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
fthomas/scala-steward:latest367afe974b7a
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

589
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

9,556
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

3,746
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

4,305
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

1,616
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-48816.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
@sigstore/verify@3.1.0
3.1.1

Open the chart page →

5,459

Container images carrying it

37 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
requarks/wiki:2:latest68f0d1848261
@sigstore/verify@3.1.0
3.1.1
2
verdaccio/verdaccio:6.10.209b403888c8f
@sigstore/verify@3.1.0
3.1.1
2
ghcr.io/api7/adc:0.27.1f65f53dd9668
@sigstore/verify@3.1.0
3.1.1
2
aaronshaf/dynamodb-admin:latestac41724cd997
@sigstore/verify@3.1.0
3.1.1
1
activepieces/activepieces:0.90.430c10a04fe3d
@sigstore/verify@3.1.0
3.1.1
1
alazidis/stornx:1.1.1602d4f7f090c
@sigstore/verify@3.1.0
3.1.1
1
archivebox/archivebox:0.7.41a5a37331091
@sigstore/verify@3.1.0
3.1.1
1
budibase/database:2.1.0d90f656261c9
@sigstore/verify@3.1.0
3.1.1
1
chatwoot/chatwoot:v4.15.167ebc751c171
@sigstore/verify@3.1.0
3.1.1
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
@sigstore/verify@3.1.0
3.1.1
1
drumsergio/genieacs:1.2.16.028244054e1bf
@sigstore/verify@3.1.0
3.1.1
1
drumsergio/lynxprompt:2.0.75c6afb6679301
@sigstore/verify@3.1.0
3.1.1
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
@sigstore/verify@3.1.0
3.1.1
1
etherpad/etherpad:2.7.2b723fe5f2594
@sigstore/verify@3.1.0
3.1.1
1
evoapicloud/evolution-api:latest966625532d90
@sigstore/verify@3.1.0
3.1.1
1
fthomas/scala-steward:latest367afe974b7a
@sigstore/verify@3.1.0
3.1.1
1
gethue/hue:latest7d5c1b9f8a79
@sigstore/verify@3.1.0
3.1.1
1
haohanyang/compass-web:0.5.054f2112602ee
@sigstore/verify@3.1.0
3.1.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
@sigstore/verify@3.1.0
3.1.1
1
mautic/mautic:7-apacheeb8cc73d97e1
@sigstore/verify@3.1.0
3.1.1
1
n8nio/n8n:2.25.7761374d4eb84
@sigstore/verify@3.1.0
3.1.1
1
neoskop/ixy:2.1.125152b474f54
@sigstore/verify@3.1.0
3.1.1
1
rocketadmin/rocketadmin:1.17.710955ef540b9
@sigstore/verify@3.1.0
3.1.1
1
supabase/storage-api:v1.60.4c8eb9858eafe
@sigstore/verify@3.1.0
3.1.1
1
supabase/storage-api:latestf6c42a04163d
@sigstore/verify@3.1.0
3.1.1
1
yooooomi/your_spotify_client:1.20.0e4da90a0634c
@sigstore/verify@3.1.0
3.1.1
1
yooooomi/your_spotify_server:1.20.0624ea009f2ef
@sigstore/verify@3.1.0
3.1.1
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
@sigstore/verify@3.1.0
3.1.1
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
@sigstore/verify@3.1.0
3.1.1
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
@sigstore/verify@3.1.0
3.1.1
1
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
@sigstore/verify@3.1.0
3.1.1
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
@sigstore/verify@3.1.0
3.1.1
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
@sigstore/verify@3.1.0
3.1.1
1
ghcr.io/shuguet/pacman:latesta0ec71732c3c
@sigstore/verify@3.1.0
3.1.1
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
@sigstore/verify@3.1.0
3.1.1
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
@sigstore/verify@3.1.0
3.1.1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
@sigstore/verify@3.1.0
3.1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.