StackRadar

CVE-2026-49458

Medium

Advisory

Published 15 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.004
34th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
63
of 17,781 indexed, latest versions
Container images
56
deployed by those charts
Fix available
1 of 1
affected package

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

Carried by container images the latest versions of 63 of 17,781 indexed charts deploy, on 56 images.

Affected packageAffected versionsFixed inImages
dompurifynpm2.1.1, 2.2.6, 2.2.7, 2.3.1+25 more3.4.656
OSV records
GHSA-hpcv-96wg-7vj8

Charts affected

63 by stars
ChartLatestAffected imagesRadar Score
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
dompurify@3.0.5
3.4.6

Open the chart page →

7,413
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
dompurify@2.4.3
3.4.6

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
dompurify@2.3.3
3.4.6

Open the chart page →

3,638
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
dompurify@3.0.11
3.4.6

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
dompurify@3.0.11
3.4.6

Open the chart page →

16,400
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
dompurify@3.0.11
3.4.6

Open the chart page →

16,400
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
dompurify@3.0.11
3.4.6

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
dompurify@3.0.11
3.4.6

Open the chart page →

15,635
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
dompurify@3.3.0
3.4.6

Open the chart page →

2,620
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
dompurify@3.2.4
3.4.6

Open the chart page →

5,484
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
dompurify@3.3.1
3.4.6

Open the chart page →

5,459
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
dompurify@2.1.1
3.4.6

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-49458.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
dompurify@2.5.6
3.4.6

Open the chart page →

9,381

Container images carrying it

56 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
dompurify@2.3.10
3.4.6
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
dompurify@2.1.1
3.4.6
2
governify/assets-manager:v1.4.12987672448c7
dompurify@2.2.6
3.4.6
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
dompurify@2.1.1
3.4.6
2
outlinewiki/outline:0.69.1d060dcd8f9aa
dompurify@2.4.3
3.4.6
2
requarks/wiki:2:latest68f0d1848261
dompurify@3.3.1
3.4.6
2
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
dompurify@3.3.2
3.4.6
1
archivebox/archivebox:0.7.41a5a37331091
dompurify@3.0.7
3.4.6
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
dompurify@2.1.1
3.4.6
1
assistiot/open_api_frontend:1.0.1f11d82defc70
dompurify@2.3.10
3.4.6
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
dompurify@3.2.7
3.4.6
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
dompurify@3.2.6
3.4.6
1
fosrl/pangolin:latest83a55f933b4d
dompurify@3.4.0
3.4.6
1
fosrl/pangolin:1.13.0c32ad797ab96
dompurify@3.2.7
3.4.6
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
dompurify@2.3.8
3.4.6
1
joplin/server:3.0-beta52af57880c0e
dompurify@3.0.5
3.4.6
1
joplin/server:2.14.2-betab87564ef34e9
dompurify@3.0.5
3.4.6
1
kyso/kyso-front:lateste52595c5c16f
dompurify@2.3.10
3.4.6
1
library/ghost:6.37.01ef2e532ca4d
dompurify@3.4.1
3.4.6
1
library/ghost:6.25.12654b1e90413
dompurify@3.3.0
3.4.6
1
library/ghost:6.41.129773d6be407
dompurify@3.4.1
3.4.6
1
library/ghost:6.39.0-alpine77196da4b0df
dompurify@3.4.1
3.4.6
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
dompurify@3.3.0
3.4.6
1
maildev/maildev:2.2.1180ef51f65ee
dompurify@3.1.6
3.4.6
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
dompurify@2.2.6
3.4.6
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
dompurify@2.4.3
3.4.6
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
dompurify@2.4.3
3.4.6
1
nocodb/nocodb:0.258.06779a4ddedf2
dompurify@3.2.0
3.4.6
1
nocodb/nocodb:0.301.5d9516f0bf546
dompurify@3.3.3
3.4.6
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
dompurify@2.5.6
3.4.6
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
dompurify@2.4.1
3.4.6
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
dompurify@2.4.7
3.4.6
1
outlinewiki/outline:0.82.0494dfb9249a6
dompurify@3.2.3
3.4.6
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
dompurify@3.3.1
3.4.6
1
requarks/wiki:canary-2.5.2438b5865a7386c
dompurify@2.2.7
3.4.6
1
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
dompurify@3.0.11
3.4.6
1
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
dompurify@3.0.11
3.4.6
1
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
dompurify@3.0.11
3.4.6
1
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
dompurify@3.0.11
3.4.6
1
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
dompurify@3.0.11
3.4.6
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
dompurify@2.3.4
3.4.6
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
dompurify@3.1.4
3.4.6
1
wazuh/wazuh-dashboard:4.4.11787550d2358
dompurify@2.4.1
3.4.6
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
dompurify@3.2.4
3.4.6
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
dompurify@3.2.4
3.4.6
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
dompurify@3.1.6
3.4.6
1
zimengxiong/excalidash-backend:0.4.271273af713c91
dompurify@3.3.0
3.4.6
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
dompurify@3.2.6
3.4.6
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
dompurify@3.2.6
3.4.6
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
dompurify@3.2.6
3.4.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.