StackRadar

CVE-2026-48988

Medium

Advisory

Published 15 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
89
of 17,781 indexed, latest versions
Container images
79
deployed by those charts
Fix available
1 of 1
affected package

markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

Carried by container images the latest versions of 89 of 17,781 indexed charts deploy, on 79 images.

Affected packageAffected versionsFixed inImages
markdown-itnpm8.4.0, 8.4.2, 10.0.0, 11.0.1+9 more14.2.079
OSV records
GHSA-6v5v-wf23-fmfq

Charts affected

89 by stars
ChartLatestAffected imagesRadar Score
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
markdown-it@12.3.2
14.2.0

Open the chart page →

2,682
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
markdown-it@11.0.1
14.2.0
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
markdown-it@11.0.1
14.2.0
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
markdown-it@11.0.1
14.2.0
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
markdown-it@11.0.1
14.2.0

Open the chart page →

89,959
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
markdown-it@14.1.0
14.2.0

Open the chart page →

18,813
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
markdown-it@11.0.1
14.2.0

Open the chart page →

4,253
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
markdown-it@12.2.0
14.2.0

Open the chart page →

4,944
keyoxide-webittrident-oss0.2.31 of 1See more

keyoxide-web ittrident-oss 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
keyoxide/keyoxide:stable96f27a71269d
markdown-it@8.4.2
14.2.0

Open the chart page →

2,363
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
markdown-it@14.1.1
14.2.0

Open the chart page →

3,436
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
markdown-it@8.4.0
14.2.0

Open the chart page →

6,454
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
markdown-it@14.1.1
14.2.0

Open the chart page →

3,092
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
markdown-it@14.1.1
14.2.0

Open the chart page →

2,756
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
markdown-it@8.4.2
14.2.0

Open the chart page →

7,929
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
markdown-it@10.0.0
14.2.0

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
markdown-it@10.0.0
14.2.0

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
markdown-it@10.0.0
14.2.0

Open the chart page →

12,108
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
markdown-it@12.3.2
14.2.0

Open the chart page →

2,457
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
markdown-it@10.0.0
14.2.0
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
markdown-it@10.0.0
14.2.0
mojaloop/role-assignment-service:v2.1.0def4bf273721
markdown-it@10.0.0
14.2.0

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
markdown-it@10.0.0
14.2.0

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
markdown-it@10.0.0
14.2.0
mojaloop/central-ledger:v13.14.01abc8a7aa71c
markdown-it@10.0.0
14.2.0
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
markdown-it@10.0.0
14.2.0

Open the chart page →

19,226
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
markdown-it@10.0.0
14.2.0

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
markdown-it@10.0.0
14.2.0

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
markdown-it@10.0.0
14.2.0

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
markdown-it@12.3.2
14.2.0

Open the chart page →

2,457
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
markdown-it@14.1.0
14.2.0

Open the chart page →

4,960
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
markdown-it@13.0.1
14.2.0

Open the chart page →

3,128
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
markdown-it@13.0.2
14.2.0

Open the chart page →

1,038
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
markdown-it@14.1.1
14.2.0

Open the chart page →

3,798
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
markdown-it@10.0.0
14.2.0

Open the chart page →

27,465
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
markdown-it@12.2.0
14.2.0

Open the chart page →

9,968
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
markdown-it@13.0.2
14.2.0

Open the chart page →

1,038
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
markdown-it@13.0.1
14.2.0

Open the chart page →

6,524
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
markdown-it@13.0.2
14.2.0

Open the chart page →

7,413
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
markdown-it@14.1.0
14.2.0

Open the chart page →

4,684
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
markdown-it@13.0.1
14.2.0

Open the chart page →

3,118
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
markdown-it@13.0.1
14.2.0

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
markdown-it@12.2.0
14.2.0

Open the chart page →

3,638
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
markdown-it@13.0.2
14.2.0

Open the chart page →

5,535
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
markdown-it@13.0.1
14.2.0

Open the chart page →

3,118
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
markdown-it@11.0.1
14.2.0

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
markdown-it@14.1.0
14.2.0

Open the chart page →

6,285

Container images carrying it

79 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
linuxserver/codimd:latestb801bbcf6386
markdown-it@10.0.0
14.2.0
1
n8nio/n8n:0.212.0a9195bc499a3
markdown-it@12.3.2
14.2.0
1
n8nio/n8n:2.36.8cfe2704ff858
markdown-it@13.0.2
14.2.0
1
n8nio/n8n:1.33.1dd171d45102a
markdown-it@12.3.2
14.2.0
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
markdown-it@12.3.2
14.2.0
1
openproject/hocuspocus:release-338001b288dc1359dfb5
markdown-it@14.1.0
14.2.0
1
outlinewiki/outline:0.82.0494dfb9249a6
markdown-it@14.0.0
14.2.0
1
phntom/codimd:2.4.31b9aafbb62e6
markdown-it@13.0.1
14.2.0
1
requarks/wiki:canary-2.5.2438b5865a7386c
markdown-it@11.0.1
14.2.0
1
solidproject/community-server:6.0.2ccc4acb7e9a1
markdown-it@13.0.1
14.2.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
markdown-it@8.4.2
14.2.0
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
markdown-it@14.1.1
14.2.0
1
ghcr.io/caninehq/canine:latesta058034ca006
markdown-it@14.1.0
14.2.0
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
markdown-it@14.1.0
14.2.0
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
markdown-it@11.0.1
14.2.0
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
markdown-it@11.0.1
14.2.0
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
markdown-it@11.0.1
14.2.0
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
markdown-it@11.0.1
14.2.0
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
markdown-it@8.4.2
14.2.0
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
markdown-it@12.0.4
14.2.0
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
markdown-it@11.0.1
14.2.0
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
markdown-it@14.1.1
14.2.0
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
markdown-it@14.1.0
14.2.0
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
markdown-it@14.1.0
14.2.0
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
markdown-it@14.1.0
14.2.0
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
markdown-it@12.2.0
14.2.0
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
markdown-it@13.0.2
14.2.0
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
markdown-it@14.1.1
14.2.0
1
quay.io/wekan/wekan:v5.65cb17600883a3
markdown-it@12.2.0
14.2.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.