StackRadar

CVE-2026-59887

High

Advisory

Published 21 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
113
of 17,781 indexed, latest versions
Container images
101
deployed by those charts
Fix available
1 of 1
affected package

linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text

Carried by container images the latest versions of 113 of 17,781 indexed charts deploy, on 101 images.

Affected packageAffected versionsFixed inImages
linkify-itnpm2.0.3, 2.1.0, 2.2.0, 3.0.2+4 more5.0.2101
OSV records
GHSA-v245-v573-v5vm

Charts affected

113 by stars
ChartLatestAffected imagesRadar Score
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
linkify-it@4.0.1
5.0.2

Open the chart page →

7,413
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
linkify-it@5.0.0
5.0.2

Open the chart page →

4,684
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
linkify-it@4.0.1
5.0.2

Open the chart page →

3,118
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
linkify-it@4.0.1
5.0.2

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
linkify-it@3.0.3
5.0.2

Open the chart page →

3,638
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
linkify-it@5.0.0
5.0.2

Open the chart page →

1,991
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
linkify-it@3.0.3
5.0.2

Open the chart page →

4,017
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
linkify-it@4.0.1
5.0.2

Open the chart page →

5,535
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
linkify-it@5.0.1
5.0.2

Open the chart page →

5,550
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
linkify-it@4.0.1
5.0.2

Open the chart page →

3,118
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
linkify-it@3.0.3
5.0.2

Open the chart page →

280
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
linkify-it@3.0.3
5.0.2

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-59887.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
linkify-it@5.0.0
5.0.2

Open the chart page →

6,285

Container images carrying it

101 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/wekan/wekan:v5.65cb17600883a3
linkify-it@3.0.3
5.0.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.