CVE-2026-62985
HighAdvisory
Published 22 Sept 2026In the index since 23 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.005
- 38th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 7
- of 17,985 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 1 of 1
- affected package
request-filtering-agent: Synchronous throw from createConnection() for literal private-IP hosts bypasses req.on('error'), crashing the Node.js process
Carried by container images the latest versions of 7 of 17,985 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| request-filtering-agentnpm | 1.0.7, 1.1.2, 3.2.0 | 3.2.1 | 6 |
- OSV records
- GHSA-r3r9-wp5j-pq5g
Charts affected
7 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| outlinekubitodevVerified publisher | 1.2.2 | 1 of 4See more | 6,295 |
| outlineoutline | 0.0.9 | 1 of 4See more | 5,289 |
| kobotoolboxone-acre-fundVerified publisher | 0.7.4 | 1 of 9See more | 23,335 |
| nocodbzekker6Verified publisher | 1.10.0 | 1 of 1See more | 5,005 |
| activepiecesadnoctemVerified publisher | 0.6.0 | 1 of 1See more | 1,795 |
| nocodbone-acre-fundVerified publisher | 0.4.6 | 1 of 3See more | 4,856 |
| outlineschmitzis | 0.0.8 | 1 of 4See more | 5,289 |
Container images carrying it
6 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| outlinewiki/ | d060dcd8f9aa | request-filtering-agent | 3.2.1 | 2 |
| activepieces/ | 58414dfc94c4 | request-filtering-agent | 3.2.1 | 1 |
| enketo/ | dcad9c2273f6 | request-filtering-agent | 3.2.1 | 1 |
| nocodb/ | 6779a4ddedf2 | request-filtering-agent | 3.2.1 | 1 |
| nocodb/ | d9516f0bf546 | request-filtering-agent | 3.2.1 | 1 |
| outlinewiki/ | 494dfb9249a6 | request-filtering-agent | 3.2.1 | 1 |