StackRadar

CVE-2026-5758

Medium

Advisory

Published 15 Apr 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
21
of 17,781 indexed, latest versions
Container images
22
deployed by those charts
Fix available
1 of 1
affected package

Mafintosh's protocol-buffers-schema is vulnerable to prototype pollution

Carried by container images the latest versions of 21 of 17,781 indexed charts deploy, on 22 images.

Affected packageAffected versionsFixed inImages
protocol-buffers-schemanpm3.3.2, 3.6.03.6.122
OSV records
GHSA-j452-xhg8-qg39

Charts affected

21 by stars
ChartLatestAffected imagesRadar Score
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

11,384
wazuhwazuh-helmVerified publisher0.0.81 of 4See more

wazuh wazuh-helm 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

6,168
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

10,530
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
protocol-buffers-schema@3.3.2
3.6.1

Open the chart page →

17,896
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

1,843
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
ghcr.io/data-fair/data-fair:3cc9498b64b5b
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

38,346
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

15,712
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
protocol-buffers-schema@3.3.2
3.6.1

Open the chart page →

17,284
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

31,844
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
protocol-buffers-schema@3.3.2
3.6.1

Open the chart page →

6,879
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

7,405
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
protocol-buffers-schema@3.6.0
3.6.1
countly/frontend:25.05.42acbc11499b6
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

7,295
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

13,852
airtraildefault-ghVerified publisher0.2.21 of 2See more

airtrail default-gh 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
johly/airtrail:v3.11.19f702b91e0e7
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

1,662
adventurelogdjjudas21Verified publisher0.1.11 of 3See more

adventurelog djjudas21 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

7,459
geonetwork-k8sgeonetwork-k8sVerified publisher4.2.81 of 5See more

geonetwork-k8s geonetwork-k8s 4.2.8

1 of the 5 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
library/kibana:7.17.150172f1c538e7
protocol-buffers-schema@3.3.2
3.6.1

Open the chart page →

34,754
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

2,973
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

18,813
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

2,685
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

5,484
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-5758.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
protocol-buffers-schema@3.6.0
3.6.1

Open the chart page →

9,381

Container images carrying it

22 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
protocol-buffers-schema@3.3.2
3.6.1
1
countly/api:25.05.4f4cc7447c4f5
protocol-buffers-schema@3.6.0
3.6.1
1
countly/countly-server:25.05.4e3c238248f99
protocol-buffers-schema@3.6.0
3.6.1
1
countly/frontend:25.05.42acbc11499b6
protocol-buffers-schema@3.6.0
3.6.1
1
johly/airtrail:v3.11.19f702b91e0e7
protocol-buffers-schema@3.6.0
3.6.1
1
kyso/kyso-front:lateste52595c5c16f
protocol-buffers-schema@3.6.0
3.6.1
1
library/kibana:7.17.150172f1c538e7
protocol-buffers-schema@3.3.2
3.6.1
1
library/kibana:7.17.8c5781ba340ef
protocol-buffers-schema@3.3.2
3.6.1
1
library/kibana:7.17.3e2e2031c15be
protocol-buffers-schema@3.3.2
3.6.1
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
protocol-buffers-schema@3.6.0
3.6.1
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
protocol-buffers-schema@3.6.0
3.6.1
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
protocol-buffers-schema@3.6.0
3.6.1
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
protocol-buffers-schema@3.6.0
3.6.1
1
qxip/qryn:3.2.3977acc9c7a9fd
protocol-buffers-schema@3.6.0
3.6.1
1
treskon/portrait-ui:DEV-lateste7970783bc8d
protocol-buffers-schema@3.6.0
3.6.1
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
protocol-buffers-schema@3.6.0
3.6.1
1
wazuh/wazuh-dashboard:4.4.11787550d2358
protocol-buffers-schema@3.6.0
3.6.1
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
protocol-buffers-schema@3.6.0
3.6.1
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
protocol-buffers-schema@3.6.0
3.6.1
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
protocol-buffers-schema@3.6.0
3.6.1
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
protocol-buffers-schema@3.6.0
3.6.1
1
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
protocol-buffers-schema@3.6.0
3.6.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.