StackRadar

CVE-2026-48988

Medium

Advisory

Published 15 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
89
of 17,781 indexed, latest versions
Container images
79
deployed by those charts
Fix available
1 of 1
affected package

markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations

Carried by container images the latest versions of 89 of 17,781 indexed charts deploy, on 79 images.

Affected packageAffected versionsFixed inImages
markdown-itnpm8.4.0, 8.4.2, 10.0.0, 11.0.1+9 more14.2.079
OSV records
GHSA-6v5v-wf23-fmfq

Charts affected

89 by stars
ChartLatestAffected imagesRadar Score
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
markdown-it@12.3.2
14.2.0

Open the chart page →

2,682
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
markdown-it@11.0.1
14.2.0
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
markdown-it@11.0.1
14.2.0
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
markdown-it@11.0.1
14.2.0
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
markdown-it@11.0.1
14.2.0

Open the chart page →

89,959
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
markdown-it@14.1.0
14.2.0

Open the chart page →

18,813
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
markdown-it@11.0.1
14.2.0

Open the chart page →

4,253
dtlinfradao0.0.11 of 1See more

dtl infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
markdown-it@12.2.0
14.2.0

Open the chart page →

4,944
keyoxide-webittrident-oss0.2.31 of 1See more

keyoxide-web ittrident-oss 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
keyoxide/keyoxide:stable96f27a71269d
markdown-it@8.4.2
14.2.0

Open the chart page →

2,363
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
markdown-it@14.1.1
14.2.0

Open the chart page →

3,436
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
markdown-it@8.4.0
14.2.0

Open the chart page →

6,454
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
markdown-it@14.1.1
14.2.0

Open the chart page →

3,092
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
markdown-it@14.1.1
14.2.0

Open the chart page →

2,756
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
markdown-it@8.4.2
14.2.0

Open the chart page →

7,929
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
markdown-it@10.0.0
14.2.0

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
markdown-it@10.0.0
14.2.0

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
markdown-it@10.0.0
14.2.0

Open the chart page →

12,108
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
markdown-it@12.3.2
14.2.0

Open the chart page →

2,457
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
markdown-it@10.0.0
14.2.0
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
markdown-it@10.0.0
14.2.0
mojaloop/role-assignment-service:v2.1.0def4bf273721
markdown-it@10.0.0
14.2.0

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
markdown-it@10.0.0
14.2.0

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
markdown-it@10.0.0
14.2.0
mojaloop/central-ledger:v13.14.01abc8a7aa71c
markdown-it@10.0.0
14.2.0
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
markdown-it@10.0.0
14.2.0

Open the chart page →

19,226
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
markdown-it@10.0.0
14.2.0

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
markdown-it@10.0.0
14.2.0

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
markdown-it@10.0.0
14.2.0

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
markdown-it@12.3.2
14.2.0

Open the chart page →

2,457
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
markdown-it@14.1.0
14.2.0

Open the chart page →

4,960
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
markdown-it@13.0.1
14.2.0

Open the chart page →

3,128
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
markdown-it@13.0.2
14.2.0

Open the chart page →

1,038
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
markdown-it@14.1.1
14.2.0

Open the chart page →

3,798
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
markdown-it@10.0.0
14.2.0

Open the chart page →

27,465
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
markdown-it@12.2.0
14.2.0

Open the chart page →

9,968
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
markdown-it@13.0.2
14.2.0

Open the chart page →

1,038
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
markdown-it@13.0.1
14.2.0

Open the chart page →

6,524
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
markdown-it@13.0.2
14.2.0

Open the chart page →

7,413
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
markdown-it@14.1.0
14.2.0

Open the chart page →

4,684
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
markdown-it@13.0.1
14.2.0

Open the chart page →

3,118
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
markdown-it@13.0.1
14.2.0

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
markdown-it@12.2.0
14.2.0

Open the chart page →

3,638
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
markdown-it@13.0.2
14.2.0

Open the chart page →

5,535
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
markdown-it@13.0.1
14.2.0

Open the chart page →

3,118
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
markdown-it@11.0.1
14.2.0

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-48988.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
markdown-it@14.1.0
14.2.0

Open the chart page →

6,285

Container images carrying it

79 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
assistiot/dlt_api:2.0.0e36a8922fa0c
markdown-it@12.3.2
14.2.0
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
markdown-it@10.0.0
14.2.0
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
markdown-it@12.3.2
14.2.0
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
markdown-it@12.3.2
14.2.0
3
governify/assets-manager:v1.4.12987672448c7
markdown-it@8.4.2
14.2.0
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
markdown-it@10.0.0
14.2.0
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
markdown-it@10.0.0
14.2.0
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
markdown-it@10.0.0
14.2.0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
markdown-it@10.0.0
14.2.0
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
markdown-it@10.0.0
14.2.0
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
markdown-it@12.3.2
14.2.0
2
n8nio/n8n:2.36.714c4285bc303
markdown-it@13.0.2
14.2.0
2
n8nio/n8n:2.38.45d9f0cc5672b
markdown-it@13.0.2
14.2.0
2
outlinewiki/outline:0.69.1d060dcd8f9aa
markdown-it@13.0.1
14.2.0
2
requarks/wiki:2:latest68f0d1848261
markdown-it@11.0.1
14.2.0
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
markdown-it@13.0.1
14.2.0
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
markdown-it@8.4.2
14.2.0
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
markdown-it@10.0.0
14.2.0
1
assistiot/dlt_api:2.1.0c8a170683be7
markdown-it@12.3.2
14.2.0
1
baserow/baserow:1.30.1df0c42eb67e8
markdown-it@13.0.2
14.2.0
1
chocobozzz/peertube:v8.1.5052712130691
markdown-it@14.1.1
14.2.0
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
markdown-it@13.0.1
14.2.0
1
codetogether/codetogether:latest4348c8a38752
markdown-it@12.3.2
14.2.0
1
countly/api:25.05.4f4cc7447c4f5
markdown-it@12.3.2
14.2.0
1
countly/countly-server:25.05.4e3c238248f99
markdown-it@14.1.0
14.2.0
1
countly/frontend:25.05.42acbc11499b6
markdown-it@14.1.0
14.2.0
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
markdown-it@14.1.0
14.2.0
1
diygod/rsshub:2025-11-097a6312cac0d5
markdown-it@14.1.0
14.2.0
1
enketo/enketo-express:3.0.4dcad9c2273f6
markdown-it@8.4.2
14.2.0
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
markdown-it@12.2.0
14.2.0
1
ethpandaops/ethereumjs:masterfb84b718500f
markdown-it@14.1.1
14.2.0
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
markdown-it@14.1.0
14.2.0
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
markdown-it@12.2.0
14.2.0
1
jayfong/yapi:1.10.2163e5d621910
markdown-it@8.4.0
14.2.0
1
joplin/server:latest3f7b852959aa
markdown-it@13.0.2
14.2.0
1
joplin/server:3.0-beta52af57880c0e
markdown-it@13.0.2
14.2.0
1
joplin/server:2.14.2-betab87564ef34e9
markdown-it@13.0.2
14.2.0
1
keyoxide/keyoxide:stable96f27a71269d
markdown-it@8.4.2
14.2.0
1
library/ghost:6.37.01ef2e532ca4d
markdown-it@14.1.1
14.2.0
1
library/ghost:6.25.12654b1e90413
markdown-it@14.1.0
14.2.0
1
library/ghost:6.41.129773d6be407
markdown-it@14.1.1
14.2.0
1
library/ghost:4.37.0767230c0f263
markdown-it@12.3.2
14.2.0
1
library/ghost:6.39.0-alpine77196da4b0df
markdown-it@14.1.1
14.2.0
1
library/ghost:5.79.083f7bf209844
markdown-it@14.0.0
14.2.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
markdown-it@14.1.0
14.2.0
1
library/kibana:7.17.150172f1c538e7
markdown-it@12.3.2
14.2.0
1
library/kibana:8.18.004c0fc150f3a
markdown-it@14.1.0
14.2.0
1
library/kibana:7.17.8c5781ba340ef
markdown-it@12.3.2
14.2.0
1
library/kibana:7.17.3e2e2031c15be
markdown-it@12.3.2
14.2.0
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
markdown-it@12.0.6
14.2.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.