StackRadar

CVE-2026-6321

High

Advisory

Published 4 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
86
of 17,781 indexed, latest versions
Container images
90
deployed by those charts
Fix available
1 of 2
affected packages

fast-uri vulnerable to path traversal via percent-encoded dot segments

Carried by container images the latest versions of 86 of 17,781 indexed charts deploy, on 90 images.

Affected packageAffected versionsFixed inImages
fast-urinpm2.1.0, 2.2.0, 2.3.0, 2.4.0+6 more2.4.1, 3.1.187
node-ajvdeb6.10.2-1, 8.12.0~ds+~2.1.1-4no fix listed3
OSV records
GHSA-q3j6-qgpj-74h6UBUNTU-CVE-2026-6321

Charts affected

86 by stars
ChartLatestAffected imagesRadar Score
k8s-jacoco-operatork8s-jacoco-operator0.4.01 of 4See more

k8s-jacoco-operator k8s-jacoco-operator 0.4.0

1 of the 4 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/k8s-jacoco-operator:maina558ceae6cdb
fast-uri@2.1.0
2.4.1

Open the chart page →

2,437
k8s-mutating-webhookk8s-mutating-webhook0.3.01 of 2See more

k8s-mutating-webhook k8s-mutating-webhook 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/k8s-mutating-webhook:mainaaab005242ae
fast-uri@2.1.0
2.4.1

Open the chart page →

2,009
k8s-validating-webhookk8s-validating-webhook0.4.01 of 2See more

k8s-validating-webhook k8s-validating-webhook 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/k8s-validating-webhook:main8344061b2f22
fast-uri@2.1.0
2.4.1

Open the chart page →

2,009
kube-admission-controller-starterk8s-validating-webhook0.2.01 of 2See more

kube-admission-controller-starter k8s-validating-webhook 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/kube-admission-controller-starter:maine9716966f30b
fast-uri@2.1.0
2.4.1

Open the chart page →

2,166
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
fast-uri@3.1.0
3.1.1

Open the chart page →

2,756
zigbee2mqttlmatfyVerified publisher0.1.141 of 2See more

zigbee2mqtt lmatfy 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:2.7.260a295b40f4e
fast-uri@3.0.6
3.1.1

Open the chart page →

1,391
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-ajv@6.10.2-1
no fix listed

Open the chart page →

17,779
docker-mailservermailserverVerified publisher0.2.651 of 9See more

docker-mailserver mailserver 0.2.65

1 of the 9 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
fast-uri@3.0.6
3.1.1

Open the chart page →

10,897
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
fast-uri@3.1.0
3.1.1

Open the chart page →

8,303
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
fast-uri@3.0.6
3.1.1

Open the chart page →

43,341
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
fast-uri@3.1.0
3.1.1

Open the chart page →

2,457
finance-portalmojaloop5.1.42 of 11See more

finance-portal mojaloop 5.1.4

2 of the 11 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
fast-uri@3.0.6
3.1.1
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
fast-uri@3.0.6
3.1.1

Open the chart page →

14,809
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
fast-uri@3.0.6
3.1.1

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
fast-uri@3.0.6
3.1.1

Open the chart page →

2,318
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
fast-uri@3.1.0
3.1.1

Open the chart page →

2,457
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
fast-uri@3.0.1
3.1.1

Open the chart page →

17,929
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
fast-uri@3.1.0
3.1.1

Open the chart page →

1,166
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
fast-uri@3.0.3
3.1.1

Open the chart page →

4,219
walletconnect-relayparadeum-teamVerified publisher0.1.21 of 1See more

walletconnect-relay paradeum-team 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
quay.io/netwarps/walletconnect-relay:v2.1.3-rc.15d90b9c193e0
fast-uri@2.1.0
2.4.1

Open the chart page →

1,243
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
fast-uri@3.1.0
3.1.1

Open the chart page →

4,600
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
fast-uri@3.0.6
3.1.1

Open the chart page →

5,338
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
fast-uri@3.1.0
3.1.1

Open the chart page →

5,819
etherpadschoenwald0.3.01 of 1See more

etherpad schoenwald 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
etherpad/etherpad:2.7.2b723fe5f2594
fast-uri@3.1.0
3.1.1

Open the chart page →

2,133
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
fast-uri@3.0.1
3.1.1

Open the chart page →

5,497
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
fast-uri@3.1.0
3.1.1

Open the chart page →

1,991
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
fast-uri@3.0.5
3.1.1

Open the chart page →

1,313
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
fast-uri@3.0.1
3.1.1

Open the chart page →

4,052
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-ajv@6.10.2-1
no fix listed

Open the chart page →

10,902
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
fast-uri@3.0.1
3.1.1

Open the chart page →

2,408
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
fast-uri@3.1.0
3.1.1

Open the chart page →

2,028
unleash-proxyunleash0.8.121 of 1See more

unleash-proxy unleash 0.8.12

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
unleashorg/unleash-proxy:v1.4.82538f89e2685
fast-uri@3.0.2
3.1.1

Open the chart page →

929
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
fast-uri@3.1.0
3.1.1

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
fast-uri@3.1.0
3.1.1

Open the chart page →

1,787
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
fast-uri@3.1.0
3.1.1

Open the chart page →

2,076
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
fast-uri@3.0.6
3.1.1

Open the chart page →

5,984
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-6321.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
fast-uri@3.0.3
3.1.1

Open the chart page →

6,285

Container images carrying it

90 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
fast-uri@3.1.0
3.1.1
3
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
fast-uri@3.0.6
3.1.1
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
fast-uri@3.0.6
3.1.1
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
fast-uri@3.1.0
3.1.1
2
activepieces/activepieces:0.23.0c26188b44e62
fast-uri@2.3.0
2.4.1
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
fast-uri@3.1.0
3.1.1
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
fast-uri@3.1.0
3.1.1
1
automatischio/automatisch:0.15.03bace7a12d5f
fast-uri@3.0.3
3.1.1
1
chainsafe/lodestar:latest5593f6e97912
fast-uri@3.1.0
3.1.1
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
fast-uri@3.0.1
3.1.1
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
fast-uri@2.3.0
2.4.1
1
contane/foreman:0.5.2efb98bdcc4e9
fast-uri@3.0.6
3.1.1
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
fast-uri@3.0.6
3.1.1
1
cryptexlabs/authf:0.12.11189c07411d7c
fast-uri@3.0.3
3.1.1
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
fast-uri@3.0.1
3.1.1
1
docmost/docmost:0.95.041c8d777cf23
fast-uri@3.0.6
3.1.1
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
fast-uri@3.0.6
3.1.1
1
etherpad/etherpad:2.7.2b723fe5f2594
fast-uri@3.1.0
3.1.1
1
evoapicloud/evolution-api:latest966625532d90
fast-uri@3.1.0
3.1.1
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
fast-uri@3.1.0
3.1.1
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
fast-uri@3.0.1
3.1.1
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
fast-uri@2.4.0
2.4.1
1
instill/console:0.68.54cd70e2df5c6
fast-uri@3.0.6
3.1.1
1
journeyapps/powersync-service:latestbf46f66e5dcc
fast-uri@3.0.6
3.1.1
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-ajv@8.12.0~ds+~2.1.1-4
no fix listed
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
fast-uri@3.0.6
3.1.1
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
fast-uri@3.1.0
3.1.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
fast-uri@3.0.1
3.1.1
1
library/ghost:6.37.01ef2e532ca4d
fast-uri@3.1.0
3.1.1
1
library/ghost:6.41.129773d6be407
fast-uri@3.1.0
3.1.1
1
library/ghost:6.39.0-alpine77196da4b0df
fast-uri@3.1.0
3.1.1
1
library/kibana:8.18.004c0fc150f3a
fast-uri@3.0.3
3.1.1
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-ajv@6.10.2-1
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
fast-uri@3.1.0
3.1.1
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
fast-uri@3.0.6
3.1.1
1
n8nio/n8n:1.86.08b39ed5a2de9
fast-uri@3.0.6
3.1.1
1
neoskop/ixy:2.1.125152b474f54
fast-uri@3.1.0
3.1.1
1
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
fast-uri@3.1.0
3.1.1
1
nocodb/nocodb:0.258.06779a4ddedf2
fast-uri@3.0.3
3.1.1
1
nocodb/nocodb:0.301.5d9516f0bf546
fast-uri@3.1.0
3.1.1
1
nodered/node-red:4.1.2216e7403aab9
fast-uri@3.1.0
3.1.1
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
fast-uri@3.1.0
3.1.1
1
qxip/qryn:3.2.3977acc9c7a9fd
fast-uri@3.0.1
3.1.1
1
rocketadmin/rocketadmin:1.17.710955ef540b9
fast-uri@3.1.0
3.1.1
1
sigp/siren:v3.0.42c219b04758e
fast-uri@3.0.6
3.1.1
1
supabase/postgres-meta:v0.96.6a84cc713585e
fast-uri@3.0.6
3.1.1
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
fast-uri@2.2.0
2.4.1
1
supabase/storage-api:v1.60.4c8eb9858eafe
fast-uri@3.1.0
3.1.1
1
supabase/storage-api:v1.12.0f983fb50bd95
fast-uri@2.2.0
2.4.1
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-ajv@6.10.2-1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.