StackRadar

CVE-2026-53550

Medium

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
454
of 17,787 indexed, latest versions
Container images
450
deployed by those charts
Fix available
1 of 2
affected packages

JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

Carried by container images the latest versions of 454 of 17,787 indexed charts deploy, on 450 images.

Affected packageAffected versionsFixed inImages
js-yamlnpm1.0.3, 3.5.5, 3.6.1, 3.7.0+11 more3.15.0, 4.2.0450
node-js-yamldeb4.1.0+dfsg+~4.0.5-7no fix listed1
OSV records
GHSA-h67p-54hq-rp68UBUNTU-CVE-2026-53550

Charts affected

454 by stars
ChartLatestAffected imagesRadar Score
workadventureworkadventure1.1.02 of 9See more

workadventure workadventure 1.1.0

2 of the 9 container images this version deploys carry CVE-2026-53550.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
js-yaml@4.1.0
4.2.0
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
js-yaml@4.1.0
4.2.0

Open the chart page →

16,083
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-53550.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
js-yaml@4.1.0
4.2.0

Open the chart page →

1,752
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-53550.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
js-yaml@3.13.1
3.15.0

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-53550.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
js-yaml@3.14.1
3.15.0

Open the chart page →

9,381

Container images carrying it

450 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
winfred008/amazon:910a68de5b398
js-yaml@4.1.0
4.2.0
1
wiremind/scrapoxy:lateste7048929a676
js-yaml@3.13.1
3.15.0
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
js-yaml@4.1.0
4.2.0
1
ymuski/skooner:latest67819ca511b5
js-yaml@4.1.0
4.2.0
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
js-yaml@4.1.1
4.2.0
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
js-yaml@4.1.1
4.2.0
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
js-yaml@4.1.1
4.2.0
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
js-yaml@4.1.1
4.2.0
1
zazuko/trifid:2.3.7054be137de70
js-yaml@3.14.1
3.15.0
1
zooz/predator:1.6f491d1f7a865
js-yaml@3.13.1
3.15.0
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
js-yaml@3.14.1
3.15.0
1
zwavejs/zwave-js-ui:11.22.314d018bb689e
js-yaml@4.1.1
4.2.0
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
js-yaml@4.1.1
4.2.0
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
js-yaml@4.1.0
4.2.0
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
js-yaml@4.1.1
4.2.0
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
js-yaml@4.1.1
4.2.0
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
js-yaml@4.1.0
4.2.0
1
ghcr.io/bryopsida/patchwork:mainc01e018bced4
js-yaml@4.1.0
4.2.0
1
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
js-yaml@4.1.0
4.2.0
1
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
js-yaml@3.14.1
3.15.0
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
js-yaml@4.1.0
4.2.0
1
ghcr.io/colanode/server:latest7006cac874fd
js-yaml@4.1.1
4.2.0
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
js-yaml@4.1.0
4.2.0
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
js-yaml@3.14.1
3.15.0
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
js-yaml@3.14.0
3.15.0
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
js-yaml@3.14.0
3.15.0
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
js-yaml@3.14.0
3.15.0
1
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
js-yaml@4.1.0
4.2.0
1
ghcr.io/curium-rocks/k8s-mutating-webhook:mainaaab005242ae
js-yaml@4.1.0
4.2.0
1
ghcr.io/curium-rocks/k8s-validating-webhook:main8344061b2f22
js-yaml@4.1.0
4.2.0
1
ghcr.io/curium-rocks/kube-admission-controller-starter:maine9716966f30b
js-yaml@4.1.0
4.2.0
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
js-yaml@4.1.0
4.2.0
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
js-yaml@4.1.0
4.2.0
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
js-yaml@3.14.1
3.15.0
1
ghcr.io/data-fair/metrics:0a8d40779eeae
js-yaml@3.14.1
3.15.0
1
ghcr.io/data-fair/notify:3c739b74dabb0
js-yaml@3.14.1
3.15.0
1
ghcr.io/data-fair/processings:15a9216989707
js-yaml@3.14.1
3.15.0
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
js-yaml@3.14.1
3.15.0
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
js-yaml@3.13.1
3.15.0
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
js-yaml@4.1.0
4.2.0
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
js-yaml@4.1.0
4.2.0
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
js-yaml@4.1.0
4.2.0
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
js-yaml@4.1.0
4.2.0
1
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
js-yaml@4.1.1
4.2.0
1
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
js-yaml@4.1.0
4.2.0
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
js-yaml@4.1.0
4.2.0
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
js-yaml@4.1.0
4.2.0
1
ghcr.io/k8s-at-home/haste-server:latest827aa2f2389d
js-yaml@3.14.0
3.15.0
1
ghcr.io/leoquote/mergeable:latest451706815103
js-yaml@3.14.0
3.15.0
1
ghcr.io/leprechaun/lgtv2mqtt:latestac2e11c41ffb
js-yaml@4.1.0
4.2.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.