StackRadar

CVE-2026-4923

Medium

Advisory

Published 27 Mar 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
36
of 17,781 indexed, latest versions
Container images
35
deployed by those charts
Fix available
1 of 1
affected package

path-to-regexp vulnerable to Regular Expression Denial of Service via multiple wildcards

Carried by container images the latest versions of 36 of 17,781 indexed charts deploy, on 35 images.

Affected packageAffected versionsFixed inImages
path-to-regexpnpm8.1.0, 8.2.0, 8.3.08.4.035
OSV records
GHSA-27v5-c462-wpq7

Charts affected

36 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
path-to-regexp@8.3.0
8.4.0

Open the chart page →

11,384
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
path-to-regexp@8.3.0
8.4.0

Open the chart page →

10,775
redisinsightredisinsight-guiVerified publisher1.3.51 of 1See more

redisinsight redisinsight-gui 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
redis/redisinsight:3.8b5e19ee240ab
path-to-regexp@8.2.0
8.4.0

Open the chart page →

1,038
librechatlibrechat1.8.101 of 3See more

librechat librechat 1.8.10

1 of the 3 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
path-to-regexp@8.2.0
8.4.0

Open the chart page →

2,654
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
path-to-regexp@8.3.0
8.4.0

Open the chart page →

4,016
enbuildenbuildVerified publisher0.0.502 of 6See more

enbuild enbuild 0.0.50

2 of the 6 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
path-to-regexp@8.3.0
8.4.0
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
path-to-regexp@8.3.0
8.4.0

Open the chart page →

31,510
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
path-to-regexp@8.3.0
8.4.0

Open the chart page →

15,712
stornxstornxVerified publisher1.1.11 of 9See more

stornx stornx 1.1.1

1 of the 9 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
path-to-regexp@8.2.0
8.4.0

Open the chart page →

11,574
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
path-to-regexp@8.3.0
8.4.0

Open the chart page →

4,010
adeptia-automate-mcpadeptia-automate-mcp1.0.01 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
path-to-regexp@8.3.0
8.4.0

Open the chart page →

3,600
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
path-to-regexp@8.2.0
8.4.0
sysnet4admin/colosseum-prm:log5802bfcd7fed
path-to-regexp@8.2.0
8.4.0

Open the chart page →

26,996
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
path-to-regexp@8.3.0
8.4.0

Open the chart page →

4,083
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
path-to-regexp@8.2.0
8.4.0

Open the chart page →

1,947
cors-proxycors-proxyVerified publisher1.2.01 of 1See more

cors-proxy cors-proxy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
path-to-regexp@8.3.0
8.4.0

Open the chart page →

1,598
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
path-to-regexp@8.2.0
8.4.0

Open the chart page →

14,559
dapr-agentsdapr-agents-devVerified publisher0.1.52 of 31See more

dapr-agents dapr-agents-dev 0.1.5

2 of the 31 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
path-to-regexp@8.2.0
8.4.0
ghcr.io/kagent-dev/doc2vec/mcp:1.1.14ace1de323f4a
path-to-regexp@8.2.0
8.4.0

Open the chart page →

22,193
onboarding-portalfiware1.4.31 of 1See more

onboarding-portal fiware 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
quay.io/seamware/onboarding:0.2.2b406475f9f00
path-to-regexp@8.3.0
8.4.0

Open the chart page →

1,489
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
path-to-regexp@8.2.0
8.4.0

Open the chart page →

2,950
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
path-to-regexp@8.2.0
8.4.0

Open the chart page →

3,806
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
path-to-regexp@8.3.0
8.4.0

Open the chart page →

778
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
path-to-regexp@8.2.0
8.4.0

Open the chart page →

5,826
redisinsightklicktippVerified publisher0.5.01 of 1See more

redisinsight klicktipp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
redis/redisinsight:3.2.055542a762210
path-to-regexp@8.2.0
8.4.0

Open the chart page →

1,290
pangolinkrzwiatrzyk0.11.01 of 1See more

pangolin krzwiatrzyk 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
fosrl/pangolin:1.13.0c32ad797ab96
path-to-regexp@8.3.0
8.4.0

Open the chart page →

3,441
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
path-to-regexp@8.2.0
8.4.0

Open the chart page →

1,490
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
path-to-regexp@8.1.0
8.4.0

Open the chart page →

9,668
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
path-to-regexp@8.2.0
8.4.0

Open the chart page →

14,809
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
path-to-regexp@8.2.0
8.4.0

Open the chart page →

2,318
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
path-to-regexp@8.3.0
8.4.0

Open the chart page →

4,960
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
path-to-regexp@8.2.0
8.4.0

Open the chart page →

2,421
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
path-to-regexp@8.3.0
8.4.0

Open the chart page →

1,858
redisinsightredisinsightVerified publisher0.1.01 of 1See more

redisinsight redisinsight 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
path-to-regexp@8.2.0
8.4.0

Open the chart page →

1,038
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
path-to-regexp@8.2.0
8.4.0

Open the chart page →

1,313
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
path-to-regexp@8.2.0
8.4.0

Open the chart page →

4,661
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
path-to-regexp@8.3.0
8.4.0

Open the chart page →

2,028
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
path-to-regexp@8.3.0
8.4.0

Open the chart page →

2,620
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-4923.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
path-to-regexp@8.3.0
8.4.0

Open the chart page →

5,484

Container images carrying it

35 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
redis/redisinsight:3.8:latestb5e19ee240ab
path-to-regexp@8.2.0
8.4.0
4
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
path-to-regexp@8.2.0
8.4.0
2
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
path-to-regexp@8.3.0
8.4.0
1
alazidis/stornx:1.1.1602d4f7f090c
path-to-regexp@8.2.0
8.4.0
1
budibase/apps:3.41.344fe6feab985
path-to-regexp@8.3.0
8.4.0
1
fosrl/pangolin:1.13.0c32ad797ab96
path-to-regexp@8.3.0
8.4.0
1
library/ghost:6.25.12654b1e90413
path-to-regexp@8.3.0
8.4.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
path-to-regexp@8.3.0
8.4.0
1
luligu/matterbridge:3.0.28f97884bebc2
path-to-regexp@8.2.0
8.4.0
1
n8nio/n8n:1.86.08b39ed5a2de9
path-to-regexp@8.2.0
8.4.0
1
nocodb/nocodb:0.301.5d9516f0bf546
path-to-regexp@8.3.0
8.4.0
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
path-to-regexp@8.3.0
8.4.0
1
redis/redisinsight:3.2.055542a762210
path-to-regexp@8.2.0
8.4.0
1
redis/redisinsight:3.485562d67a912
path-to-regexp@8.2.0
8.4.0
1
sysnet4admin/colosseum-cms:loge74b43c7f492
path-to-regexp@8.2.0
8.4.0
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
path-to-regexp@8.2.0
8.4.0
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
path-to-regexp@8.3.0
8.4.0
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
path-to-regexp@8.3.0
8.4.0
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
path-to-regexp@8.3.0
8.4.0
1
zimengxiong/excalidash-backend:0.4.271273af713c91
path-to-regexp@8.3.0
8.4.0
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
path-to-regexp@8.3.0
8.4.0
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
path-to-regexp@8.2.0
8.4.0
1
ghcr.io/calesthio/crucix:latest67c5244b6acf
path-to-regexp@8.3.0
8.4.0
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
path-to-regexp@8.2.0
8.4.0
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
path-to-regexp@8.2.0
8.4.0
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
path-to-regexp@8.2.0
8.4.0
1
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
path-to-regexp@8.3.0
8.4.0
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
path-to-regexp@8.3.0
8.4.0
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
path-to-regexp@8.2.0
8.4.0
1
ghcr.io/kagent-dev/doc2vec/mcp:1.1.14ace1de323f4a
path-to-regexp@8.2.0
8.4.0
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
path-to-regexp@8.1.0
8.4.0
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
path-to-regexp@8.2.0
8.4.0
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
path-to-regexp@8.3.0
8.4.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
path-to-regexp@8.3.0
8.4.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
path-to-regexp@8.3.0
8.4.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.