StackRadar

CVE-2026-59880

High

Advisory

Published 21 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
77
of 17,781 indexed, latest versions
Container images
67
deployed by those charts
Fix available
1 of 1
affected package

Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

Carried by container images the latest versions of 77 of 17,781 indexed charts deploy, on 67 images.

Affected packageAffected versionsFixed inImages
immutablenpm3.7.6, 3.8.2, 4.0.0, 4.0.0-rc.14+13 more3.8.4, 4.3.9, 5.1.867
OSV records
GHSA-xvcm-6775-5m9r

Charts affected

77 by stars
ChartLatestAffected imagesRadar Score
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
immutable@3.8.2
3.8.4

Open the chart page →

12,108
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
immutable@5.1.4
5.1.8

Open the chart page →

2,457
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
immutable@5.1.3
5.1.8
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
immutable@5.1.3
5.1.8
mojaloop/role-assignment-service:v2.1.0def4bf273721
immutable@4.3.4
4.3.9

Open the chart page →

14,809
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
immutable@3.8.2
3.8.4

Open the chart page →

11,479
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
immutable@3.8.2
3.8.4
mojaloop/central-ledger:v13.14.01abc8a7aa71c
immutable@3.8.2
3.8.4
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
immutable@3.8.2
3.8.4

Open the chart page →

19,226
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
immutable@5.1.3
5.1.8

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
immutable@5.1.3
5.1.8

Open the chart page →

2,318
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
immutable@4.3.4
4.3.9

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
immutable@5.1.4
5.1.8

Open the chart page →

2,457
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
immutable@4.0.0
4.3.9

Open the chart page →

3,269
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
immutable@4.2.4
4.3.9

Open the chart page →

2,919
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
immutable@4.3.2
4.3.9

Open the chart page →

15,206
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
immutable@3.8.2
3.8.4

Open the chart page →

9,968
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
immutable@4.3.7
4.3.9

Open the chart page →

7,084
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
immutable@4.2.4
4.3.9

Open the chart page →

6,026
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
immutable@5.1.2
5.1.8

Open the chart page →

5,338
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
immutable@4.0.0
4.3.9

Open the chart page →

7,413
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
immutable@4.3.6
4.3.9

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
immutable@4.3.6
4.3.9

Open the chart page →

16,620
semaphoreschoenwald0.1.31 of 1See more

semaphore schoenwald 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
0hlov3/semaphore:v1.0.050f874ec096b
immutable@4.1.0
4.3.9

Open the chart page →

1,796
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
immutable@4.1.0
4.3.9

Open the chart page →

3,143
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
immutable@4.3.0
4.3.9

Open the chart page →

7,574
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
immutable@4.1.0
4.3.9

Open the chart page →

4,017
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
immutable@4.3.7
4.3.9

Open the chart page →

28,814
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
immutable@4.3.4
4.3.9

Open the chart page →

2,789
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
immutable@3.7.6
3.8.4

Open the chart page →

5,459
workadventureworkadventure1.1.01 of 9See more

workadventure workadventure 1.1.0

1 of the 9 container images this version deploys carry CVE-2026-59880.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
immutable@4.2.1
4.3.9

Open the chart page →

16,083

Container images carrying it

67 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
immutable@3.8.2
3.8.4
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
immutable@3.7.6
3.8.4
3
ethersphere/bee-localchain:latest0558799ca992
immutable@4.3.5
4.3.9
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
immutable@4.3.6
4.3.9
2
gradiant/open5gs-webui:2.7.5fbd10c017541
immutable@4.3.4
4.3.9
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
immutable@3.8.2
3.8.4
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
immutable@3.8.2
3.8.4
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
immutable@5.1.3
5.1.8
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
immutable@5.1.3
5.1.8
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
immutable@4.3.4
4.3.9
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
immutable@5.1.4
5.1.8
2
requarks/wiki:2:latest68f0d1848261
immutable@3.7.6
3.8.4
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
immutable@4.1.0
4.3.9
2
0hlov3/semaphore:v1.0.050f874ec096b
immutable@4.1.0
4.3.9
1
assistiot/open_api_frontend:1.0.1f11d82defc70
immutable@3.8.2
3.8.4
1
countly/api:25.05.4f4cc7447c4f5
immutable@4.3.0
4.3.9
1
countly/countly-server:25.05.4e3c238248f99
immutable@4.3.0
4.3.9
1
countly/frontend:25.05.42acbc11499b6
immutable@4.3.0
4.3.9
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
immutable@4.3.7
4.3.9
1
directus/directus:11.1.0e3c8bb975350
immutable@4.3.7
4.3.9
1
electerious/ackee:3.2.05e7173fa321c
immutable@3.7.6
3.8.4
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
immutable@4.0.0-rc.14
4.3.9
1
ethersphere/bzz-token-service:latest7624f11a72ad
immutable@4.0.0-rc.14
4.3.9
1
ethersphere/onboarding-faucet:0.3.0513154aab230
immutable@4.0.0
4.3.9
1
factly/mande-web:0.34.1742355964b0e
immutable@4.3.4
4.3.9
1
fiware/idm:8.3.3a1b6ed4ae84f
immutable@4.3.0
4.3.9
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
immutable@4.3.0
4.3.9
1
ibmcom/microclimate-portal:latested5505e5c7ec
immutable@3.8.2
3.8.4
1
jayfong/yapi:1.10.2163e5d621910
immutable@3.8.2
3.8.4
1
joplin/server:3.0-beta52af57880c0e
immutable@4.0.0
4.3.9
1
joplin/server:2.14.2-betab87564ef34e9
immutable@4.0.0
4.3.9
1
kobotoolbox/kpi:2.022.24dbcacc01bccd4
immutable@3.8.2
3.8.4
1
kyleslugg/klusterview:latestba8c36dfdfbd
immutable@4.3.0
4.3.9
1
langgenius/dify-web:0.6.11a2a294743634
immutable@4.3.0
4.3.9
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
immutable@5.1.4
5.1.8
1
langgenius/dify-web:1.0.0d64914ff0d6d
immutable@4.3.7
4.3.9
1
lissy93/dashy:2.0.51991f7be5ed0
immutable@4.0.0
4.3.9
1
misskey/misskey:12.110.1e08b7c478093
immutable@4.0.0
4.3.9
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
immutable@4.0.0
4.3.9
1
opea/codegen-ui:1.02bee4eb66f3e
immutable@4.3.7
4.3.9
1
openmined/syft-frontend:0.9.5d11524a3854a
immutable@4.3.4
4.3.9
1
polonel/trudesk:1.2.60cf6513f6fe3
immutable@4.1.0
4.3.9
1
requarks/wiki:canary-2.5.2438b5865a7386c
immutable@3.7.6
3.8.4
1
solidproject/community-server:6.0.2ccc4acb7e9a1
immutable@4.1.0
4.3.9
1
supabase/studio:20241021-9f9b08326d8070c55e9
immutable@4.3.4
4.3.9
1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
immutable@4.2.1
4.3.9
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
immutable@4.3.7
4.3.9
1
vlebediantsev/notes-project-front:latest945675fd2636
immutable@4.3.2
4.3.9
1
wettyoss/wetty:latest7423b3d40ba2
immutable@5.1.5
5.1.8
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
immutable@4.3.0
4.3.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.