StackRadar

CVE-2026-56848

High

Advisory

Published 4 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
85
of 17,781 indexed, latest versions
Container images
76
deployed by those charts
Fix available
1 of 4
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 85 of 17,781 indexed charts deploy, on 76 images.

Affected packageAffected versionsFixed inImages
nodejsdeb4.2.6~dfsg-1ubuntu4.1, 7.10.1-2nodesource1~xenial1, 8.9.4-1nodesource1, 8.10.0~dfsg-2ubuntu0.4+42 moreno fix listed62
nodejsapk22.16.0-r2, 22.22.0-r0, 22.23.0-r0, 24.11.1-r0+2 more22.23.2-r0, 24.18.1-r011
nodejs-25apk25.2.1-r0, 25.8.1-r0no fix listed2
nodejs-20apk20.18.3-r0no fix listed1
OSV records
ALPINE-CVE-2026-56848DEBIAN-CVE-2026-56848UBUNTU-CVE-2026-56848CGA-7j82-7jwr-pm55CGA-vpg2-73gr-45hm
Also known as
CGA-9wcv-42q2-w2qx, CGA-w75j-wfvv-3mc6

Charts affected

85 by stars
ChartLatestAffected imagesRadar Score
puppeteergeek-cookbookVerified publisher1.2.21 of 1See more

puppeteer geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
nodejs@17.5.0-deb-1nodesource1
no fix listed

Open the chart page →

15,730
octoboxhalkeye0.1.11 of 1See more

octobox halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
octoboxio/octobox:latestd909041c46eb
nodejs@24.11.1-r0
24.18.1-r0

Open the chart page →

3,255
7dtdhelm-7dtd0.1.01 of 1See more

7dtd helm-7dtd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
vinanrra/7dtd-server:v0.4.4f9534490bd2b
nodejs@16.19.1-deb-1nodesource1
no fix listed

Open the chart page →

10,627
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
nodejs@24.15.0-1nodesource1
no fix listed

Open the chart page →

7,633
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
nodejs@18.20.4-1nodesource1
no fix listed

Open the chart page →

18,813
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
nodejs@22.16.0-1nodesource1
no fix listed

Open the chart page →

9,653
ibm-microclimateibm-charts0.1.01 of 8See more

ibm-microclimate ibm-charts 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
ibmcom/microclimate-theia:lateste17bdccc5030
nodejs@4.2.6~dfsg-1ubuntu4.1
no fix listed

Open the chart page →

57,669
ilum-uiilumOfficialVerified publisher6.7.31 of 2See more

ilum-ui ilum 6.7.3

1 of the 2 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
ilum/ui:6.7.3998937726679
nodejs@22.23.0-r0
22.23.2-r0

Open the chart page →

1,235
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
nodejs@18.19.0+dfsg-6~deb12u2
no fix listed

Open the chart page →

10,780
k8s-dev-podk8s-dev-pod0.3.11 of 1See more

k8s-dev-pod k8s-dev-pod 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
nodejs@22.16.0-1nodesource1
no fix listed

Open the chart page →

8,811
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
nodejs@16.14.2-deb-1nodesource1
no fix listed

Open the chart page →

9,783
huekatool1.0.81 of 1See more

hue katool 1.0.8

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
gethue/hue:4.11.011b649636e68
nodejs@14.21.2-deb-1nodesource1
no fix listed

Open the chart page →

16,417
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
kitware/cdash:v5.3.0d7767d9b9da4
nodejs@24.19.0-1nodesource1
no fix listed

Open the chart page →

12,062
kubiya-runnerkubiya-helm-chartsOfficialVerified publisher0.9.41 of 9See more

kubiya-runner kubiya-helm-charts 0.9.4

1 of the 9 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
nodejs@18.20.8-1nodesource1
no fix listed

Open the chart page →

20,204
kinesaliteleprechaun-charts0.1.21 of 1See more

kinesalite leprechaun-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
instructure/kinesalite:latest34400d82f28f
nodejs@16.20.2-1nodesource1
no fix listed

Open the chart page →

4,232
linkdinglinkding0.2.31 of 1See more

linkding linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.41.0-plusa222fb777e1f
nodejs@20.19.2-1nodesource1
no fix listed

Open the chart page →

37,942
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
nodejs@24.11.1-r0
24.18.1-r0

Open the chart page →

1,391
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
nodejs@10.19.0~dfsg-3ubuntu1
no fix listed

Open the chart page →

17,779
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
nodejs@24.15.0-1nodesource1
no fix listed

Open the chart page →

8,303
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
nodejs@10.23.0-1nodesource1
no fix listed

Open the chart page →

27,465
comacopencord1.0.01 of 9See more

comac opencord 1.0.0

1 of the 9 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
omecproject/onos-progran:1.0.05715e5648aa0
nodejs@8.9.4-1nodesource1
no fix listed

Open the chart page →

88,546
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
nodejs@8.9.4-1nodesource1
no fix listed

Open the chart page →

38,865
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
nodejs@8.10.0~dfsg-2ubuntu0.4
no fix listed

Open the chart page →

36,215
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
nodejs@14.17.5-deb-1nodesource1
no fix listed

Open the chart page →

11,909
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
nodejs@22.16.0-r2
22.23.2-r0

Open the chart page →

4,499
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
nodejs@26.8.1-1nodesource1
no fix listed

Open the chart page →

3,707
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
nodejs-25@25.8.1-r0
no fix listed

Open the chart page →

5,201
frontendsignalen4.24.01 of 1See more

frontend signalen 4.24.0

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
signalen/frontend:2.27.81ab79cb7fe21
nodejs@24.14.1-r0
24.18.1-r0

Open the chart page →

1,161
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
nodejs@10.19.0~dfsg-3ubuntu1.3
no fix listed

Open the chart page →

10,902
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
nodejs@20.20.2-1nodesource1
no fix listed

Open the chart page →

7,248
unmanicvhdirkVerified publisher0.1.41 of 1See more

unmanic vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
josh5/unmanic:0.2.64d49c4816260
nodejs@20.11.1-1nodesource1
no fix listed

Open the chart page →

9,347
video-dl-botvideo-dl-botVerified publisher1.4.31 of 1See more

video-dl-bot video-dl-bot 1.4.3

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
ghcr.io/tarampampam/video-dl-bot:1.4.36daa2dc7556b
nodejs@24.20.0-1nodesource1
no fix listed

Open the chart page →

1,961
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nodejs@14.18.1-deb-1nodesource1
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nodejs@14.18.1-deb-1nodesource1
no fix listed

Open the chart page →

28,605
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-56848.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
nodejs@20.15.0-1nodesource1
no fix listed

Open the chart page →

14,100

Container images carrying it

76 by charts deploying them

A fixed version is listed for 1 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
aktosecurity/akto-puppeteer-replay:latest3aa7b960bf32
nodejs@24.17.0-r0
24.18.1-r0
3
dgraph/dgraph:v21.12.03b55ea83fffe
nodejs@14.17.5-deb-1nodesource1
no fix listed
3
hookiesolutions/webhookie:latest0629694246ba
nodejs@14.18.1-deb-1nodesource1
no fix listed
2
ilum/ui:6.7.3998937726679
nodejs@22.23.0-r0
22.23.2-r0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
nodejs@16.14.2-deb-1nodesource1
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
nodejs@22.16.0-1nodesource1
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
nodejs@16.18.0-deb-1nodesource1
no fix listed
2
agentarea/agentarea-mcp-runner:latestd3c209a5d531
nodejs@22.23.2-1nodesource1
no fix listed
1
archivebox/archivebox:0.7.41a5a37331091
nodejs@24.15.0-1nodesource1
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
nodejs@21.7.3-1nodesource1
no fix listed
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
nodejs@16.7.0-deb-1nodesource1
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
nodejs@18.20.4-1nodesource1
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
nodejs@18.19.0+dfsg-6~deb12u2
no fix listed
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
nodejs@4.2.6~dfsg-1ubuntu4.1
no fix listed
1
ethpandaops/assertoor:latest1efa2fba6711
nodejs@24.18.0-1nodesource1
no fix listed
1
galaxy/galaxy-init:v18.010267bad550e6
nodejs@9.11.1-1nodesource1
no fix listed
1
gethue/hue:4.11.011b649636e68
nodejs@14.21.2-deb-1nodesource1
no fix listed
1
gethue/hue:4.10.05702b2c37ff9
nodejs@14.17.0-1nodesource1
no fix listed
1
gethue/hue:latest7d5c1b9f8a79
nodejs@24.13.1-1nodesource1
no fix listed
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
nodejs@14.15.3-deb-1nodesource1
no fix listed
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
nodejs@18.17.1-deb-1nodesource1
no fix listed
1
ibmcom/microclimate-theia:lateste17bdccc5030
nodejs@4.2.6~dfsg-1ubuntu4.1
no fix listed
1
instructure/kinesalite:latest34400d82f28f
nodejs@16.20.2-1nodesource1
no fix listed
1
jaedb/iris:latest048cfbf58d57
nodejs@18.20.8-1nodesource1
no fix listed
1
jakowenko/double-take:1.6.0b858bac9e32a
nodejs@16.13.0-deb-1nodesource1
no fix listed
1
jedi132000/nextapp:latestdc2a81e92f23
nodejs@16.18.0-deb-1nodesource1
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
nodejs@20.11.1-1nodesource1
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
nodejs@18.19.1+dfsg-6ubuntu5
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
nodejs@24.19.0-1nodesource1
no fix listed
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
nodejs@24.11.1-r0
24.18.1-r0
1
kubeshark/front:v53.4cc7f07b99fac
nodejs@24.17.0-r0
24.18.1-r0
1
langgenius/dify-api:1.0.0066035f93856
nodejs@18.19.0+dfsg-6~deb12u2
no fix listed
1
langgenius/dify-api:1.16.1dcefa5f7c47c
nodejs@22.21.0-1nodesource1
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
nodejs@18.19.0+dfsg-6~deb12u1
no fix listed
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
nodejs@14.17.0-1nodesource1
no fix listed
1
linuxserver/codimd:latestb801bbcf6386
nodejs@10.23.0-1nodesource1
no fix listed
1
linuxserver/overseerr:1.35.06108ed066d4a
nodejs@22.22.0-r0
22.23.2-r0
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
nodejs-25@25.8.1-r0
no fix listed
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
nodejs@10.19.0~dfsg-3ubuntu1
no fix listed
1
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
nodejs@16.20.2-1nodesource1
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
nodejs@24.15.0-1nodesource1
no fix listed
1
middlewareeng/middleware:0.3.1747d880812f1
nodejs@22.16.0-1nodesource1
no fix listed
1
muluder/prograncontrollermcord:0.1.843b597a93da7
nodejs@8.9.4-1nodesource1
no fix listed
1
octoboxio/octobox:latestd909041c46eb
nodejs@24.11.1-r0
24.18.1-r0
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
nodejs@18.20.4+dfsg-1~deb12u1
no fix listed
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
nodejs@18.19.0+dfsg-6~deb12u2
no fix listed
1
omecproject/onos-progran:1.0.05715e5648aa0
nodejs@8.9.4-1nodesource1
no fix listed
1
openhab/openhab:5.2.1bfd4a60e90da
nodejs@20.19.2+dfsg-1+deb13u2
no fix listed
1
openmined/syft-frontend:0.9.5d11524a3854a
nodejs-20@20.18.3-r0
no fix listed
1
openthread/otbr:latestf307f59f6432
nodejs@8.10.0~dfsg-2ubuntu0.4
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.