StackRadar

CVE-2026-59887

High

Advisory

Published 21 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
113
of 17,781 indexed, latest versions
Container images
101
deployed by those charts
Fix available
1 of 1
affected package

linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text

Carried by container images the latest versions of 113 of 17,781 indexed charts deploy, on 101 images.

Affected packageAffected versionsFixed inImages
linkify-itnpm2.0.3, 2.1.0, 2.2.0, 3.0.2+4 more5.0.2101
OSV records
GHSA-v245-v573-v5vm

Charts affected

113 by stars
ChartLatestAffected imagesRadar Score
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
linkify-it@4.0.1
5.0.2

Open the chart page →

7,413
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
linkify-it@5.0.0
5.0.2

Open the chart page →

4,684
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
linkify-it@4.0.1
5.0.2

Open the chart page →

3,118
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
linkify-it@4.0.1
5.0.2

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
linkify-it@3.0.3
5.0.2

Open the chart page →

3,638
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
linkify-it@5.0.0
5.0.2

Open the chart page →

1,991
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
linkify-it@3.0.3
5.0.2

Open the chart page →

4,017
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
linkify-it@4.0.1
5.0.2

Open the chart page →

5,535
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
linkify-it@5.0.1
5.0.2

Open the chart page →

5,550
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
linkify-it@4.0.1
5.0.2

Open the chart page →

3,118
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
linkify-it@3.0.3
5.0.2

Open the chart page →

280
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
linkify-it@3.0.3
5.0.2

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
linkify-it@5.0.0
5.0.2

Open the chart page →

6,285

Container images carrying it

101 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/ghost:5.79.083f7bf209844
linkify-it@5.0.0
5.0.2
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
linkify-it@5.0.0
5.0.2
1
library/kibana:7.17.150172f1c538e7
linkify-it@3.0.2
5.0.2
1
library/kibana:8.18.004c0fc150f3a
linkify-it@5.0.0
5.0.2
1
library/kibana:7.17.8c5781ba340ef
linkify-it@3.0.2
5.0.2
1
library/kibana:7.17.3e2e2031c15be
linkify-it@3.0.2
5.0.2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
linkify-it@3.0.2
5.0.2
1
linuxserver/codimd:latestb801bbcf6386
linkify-it@2.2.0
5.0.2
1
linuxserver/overseerr:1.35.06108ed066d4a
linkify-it@4.0.1
5.0.2
1
n8nio/n8n:2.25.7761374d4eb84
linkify-it@5.0.0
5.0.2
1
n8nio/n8n:1.86.08b39ed5a2de9
linkify-it@5.0.0
5.0.2
1
n8nio/n8n:0.212.0a9195bc499a3
linkify-it@4.0.1
5.0.2
1
n8nio/n8n:1.33.1dd171d45102a
linkify-it@3.0.3
5.0.2
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
linkify-it@3.0.3
5.0.2
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
linkify-it@3.0.3
5.0.2
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
linkify-it@3.0.2
5.0.2
1
openproject/hocuspocus:release-338001b288dc1359dfb5
linkify-it@5.0.0
5.0.2
1
outlinewiki/outline:0.82.0494dfb9249a6
linkify-it@4.0.1
5.0.2
1
phntom/codimd:2.4.31b9aafbb62e6
linkify-it@2.2.0
5.0.2
1
polonel/trudesk:1.2.60cf6513f6fe3
linkify-it@3.0.3
5.0.2
1
requarks/wiki:canary-2.5.2438b5865a7386c
linkify-it@3.0.3
5.0.2
1
solidproject/community-server:6.0.2ccc4acb7e9a1
linkify-it@4.0.1
5.0.2
1
thelounge/thelounge:4.3.0-alpine0037aa258261
linkify-it@3.0.3
5.0.2
1
thelounge/thelounge:4.2.0-alpine639978459c3a
linkify-it@3.0.2
5.0.2
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
linkify-it@3.0.3
5.0.2
1
twentycrm/twenty:v2.22.0e7d9948bf284
linkify-it@5.0.1
5.0.2
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
linkify-it@3.0.3
5.0.2
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
linkify-it@5.0.0
5.0.2
1
ghcr.io/caninehq/canine:latesta058034ca006
linkify-it@5.0.0
5.0.2
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
linkify-it@5.0.0
5.0.2
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
linkify-it@2.1.0
5.0.2
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
linkify-it@2.1.0
5.0.2
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
linkify-it@3.0.2
5.0.2
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
linkify-it@3.0.2
5.0.2
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
linkify-it@2.2.0
5.0.2
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
linkify-it@5.0.0
5.0.2
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
linkify-it@3.0.2
5.0.2
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
linkify-it@3.0.2
5.0.2
1
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
linkify-it@4.0.1
5.0.2
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
linkify-it@5.0.1
5.0.2
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
linkify-it@5.0.0
5.0.2
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
linkify-it@3.0.2
5.0.2
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
linkify-it@4.0.1
5.0.2
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
linkify-it@5.0.0
5.0.2
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
linkify-it@5.0.0
5.0.2
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
linkify-it@5.0.0
5.0.2
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
linkify-it@5.0.0
5.0.2
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
linkify-it@3.0.2
5.0.2
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
linkify-it@4.0.1
5.0.2
1
quay.io/mittwald/kube-mail:latest04f1099241fc
linkify-it@5.0.0
5.0.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.