StackRadar

CVE-2026-59877

Medium

Advisory

Published 20 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
30th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
31
of 17,781 indexed, latest versions
Container images
33
deployed by those charts
Fix available
1 of 1
affected package

protobufjs: Denial of Service via infinite loop in .proto option parsing

Carried by container images the latest versions of 31 of 17,781 indexed charts deploy, on 33 images.

Affected packageAffected versionsFixed inImages
protobufjsnpm7.5.3, 7.5.4, 7.5.5, 7.5.6+7 more7.6.5, 8.6.633
OSV records
GHSA-j3f2-48v5-ccww

Charts affected

31 by stars
ChartLatestAffected imagesRadar Score
backstagebackstageOfficialVerified publisher2.10.11 of 1See more

backstage backstage 2.10.1

1 of the 1 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
ghcr.io/backstage/backstage:latest792e262ea504
protobufjs@7.5.5
7.6.5

Open the chart page →

1,195
rocketchatrocketchat-server7.0.24 of 12See more

rocketchat rocketchat-server 7.0.2

4 of the 12 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
rocketchat/account-service:8.6.144af8ac4e711
protobufjs@7.6.1
7.6.5
rocketchat/authorization-service:8.6.16bc18fb5d0e5
protobufjs@7.6.1
7.6.5
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
protobufjs@7.6.1
7.6.5
rocketchat/presence-service:8.6.1c1170bdfe797
protobufjs@7.6.1
7.6.5

Open the chart page →

12,279
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
protobufjs@8.4.0
8.6.6

Open the chart page →

5,660
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
protobufjs@7.5.6
7.6.5

Open the chart page →

9,460
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
protobufjs@7.6.3
7.6.5

Open the chart page →

5,218
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
protobufjs@7.5.5
7.6.5

Open the chart page →

8,491
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
protobufjs@7.5.4
7.6.5

Open the chart page →

4,016
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
protobufjs@7.5.6
7.6.5

Open the chart page →

7,473
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
protobufjs@7.5.4
7.6.5

Open the chart page →

15,712
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
protobufjs@7.5.8
7.6.5

Open the chart page →

2,575
opentelemetry-demoopentelemetry-helmVerified publisher0.41.11 of 34See more

opentelemetry-demo opentelemetry-helm 0.41.1

1 of the 34 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:3.0.0-frontend9505e349e140
protobufjs@7.6.4
7.6.5

Open the chart page →

22,420
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
supabase/storage-api:v1.60.4c8eb9858eafe
protobufjs@8.0.1
8.6.6

Open the chart page →

18,075
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
protobufjs@7.6.4
7.6.5

Open the chart page →

2,522
trifidzazukoOfficialVerified publisher0.2.11 of 1See more

trifid zazuko 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
protobufjs@7.6.3
7.6.5

Open the chart page →

338
adeptia-automate-mcpadeptia-automate-mcp1.0.02 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

2 of the 2 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
protobufjs@7.5.4
7.6.5
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
protobufjs@7.5.4
7.6.5

Open the chart page →

3,600
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad2 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

2 of the 6 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
protobufjs@7.5.3
7.6.5
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
protobufjs@7.5.3
7.6.5

Open the chart page →

18,293
devtron-enterprisedevtron48.0.01 of 28See more

devtron-enterprise devtron 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
protobufjs@7.5.3
7.6.5

Open the chart page →

68,240
devtron-enterprisedevtron-labs48.0.01 of 28See more

devtron-enterprise devtron-labs 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
protobufjs@7.5.3
7.6.5

Open the chart page →

68,240
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
epam/ai-dial-admin-frontend:0.20.021d91ad74755
protobufjs@8.6.3
8.6.6

Open the chart page →

4,046
homepagekubernetes-homelab-helm-chartsVerified publisher0.1.01 of 1See more

homepage kubernetes-homelab-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
protobufjs@7.5.5
7.6.5

Open the chart page →

1,378
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
protobufjs@7.6.4
7.6.5
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
protobufjs@7.6.4
7.6.5

Open the chart page →

2,774
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
protobufjs@7.5.4
7.6.5

Open the chart page →

2,457
finance-portalmojaloop5.1.42 of 11See more

finance-portal mojaloop 5.1.4

2 of the 11 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
protobufjs@7.5.3
7.6.5
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
protobufjs@7.5.3
7.6.5

Open the chart page →

14,809
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
protobufjs@7.5.3
7.6.5

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
protobufjs@7.5.3
7.6.5

Open the chart page →

2,318
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
protobufjs@7.5.4
7.6.5

Open the chart page →

2,457
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
protobufjs@7.5.3
7.6.5

Open the chart page →

68,240
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
protobufjs@7.5.4
7.6.5

Open the chart page →

4,684
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
protobufjs@7.5.3
7.6.5

Open the chart page →

1,313
supabaseteochenglim0.1.21 of 13See more

supabase teochenglim 0.1.2

1 of the 13 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
protobufjs@7.5.6
7.6.5

Open the chart page →

9,556
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-59877.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
protobufjs@7.5.4
7.6.5

Open the chart page →

3,746

Container images carrying it

33 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
protobufjs@7.5.3
7.6.5
3
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
protobufjs@7.5.3
7.6.5
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
protobufjs@7.5.3
7.6.5
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
protobufjs@7.5.4
7.6.5
2
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
protobufjs@7.5.4
7.6.5
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
protobufjs@7.5.4
7.6.5
1
directus/directus:12.0.29c8470ea465c
protobufjs@7.5.6
7.6.5
1
diygod/rsshub:2025-11-097a6312cac0d5
protobufjs@7.5.4
7.6.5
1
epam/ai-dial-admin-frontend:0.20.021d91ad74755
protobufjs@8.6.3
8.6.6
1
evoapicloud/evolution-api:latest966625532d90
protobufjs@7.5.4
7.6.5
1
journeyapps/powersync-service:latestbf46f66e5dcc
protobufjs@7.5.5
7.6.5
1
n8nio/n8n:2.25.7761374d4eb84
protobufjs@7.5.8
7.6.5
1
nocodb/nocodb:0.301.5d9516f0bf546
protobufjs@7.5.4
7.6.5
1
rocketchat/account-service:8.6.144af8ac4e711
protobufjs@7.6.1
7.6.5
1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
protobufjs@7.6.1
7.6.5
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
protobufjs@7.6.1
7.6.5
1
rocketchat/presence-service:8.6.1c1170bdfe797
protobufjs@7.6.1
7.6.5
1
supabase/storage-api:v1.60.4c8eb9858eafe
protobufjs@8.0.1
8.6.6
1
supabase/storage-api:latestf6c42a04163d
protobufjs@7.5.6
7.6.5
1
tenureai/tenure:v1.0.285f5b222df9a5
protobufjs@7.6.4
7.6.5
1
ghcr.io/backstage/backstage:latest792e262ea504
protobufjs@7.5.5
7.6.5
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
protobufjs@7.5.3
7.6.5
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
protobufjs@7.5.3
7.6.5
1
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
protobufjs@7.5.5
7.6.5
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
protobufjs@7.5.4
7.6.5
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
protobufjs@7.5.6
7.6.5
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
protobufjs@7.6.4
7.6.5
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
protobufjs@7.6.4
7.6.5
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
protobufjs@7.6.3
7.6.5
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
protobufjs@8.4.0
8.6.6
1
ghcr.io/open-telemetry/demo:3.0.0-frontend9505e349e140
protobufjs@7.6.4
7.6.5
1
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
protobufjs@7.6.3
7.6.5
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
protobufjs@7.5.3
7.6.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.