StackRadar

CVE-2026-64648

Medium

Advisory

Published 22 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.0
base score, highest
EPSS
0.003
27th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
78
of 17,781 indexed, latest versions
Container images
76
deployed by those charts
Fix available
1 of 1
affected package

Next.js: Cache confusion of response bodies for requests with bodies

Carried by container images the latest versions of 78 of 17,781 indexed charts deploy, on 76 images.

Affected packageAffected versionsFixed inImages
nextnpm13.0.7, 13.2.4, 13.4.12, 13.5.2+43 more15.5.21, 16.2.1176
OSV records
GHSA-68g3-v927-f742

Charts affected

78 by stars
ChartLatestAffected imagesRadar Score
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
next@13.5.2
15.5.21

Open the chart page →

2,685
helm-pilotlbenicio-communityVerified publisher0.2.41 of 1See more

helm-pilot lbenicio-community 0.2.4

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
lbenicio/helm-pilot:0.2.54594a2632510
next@16.2.9
16.2.11

Open the chart page →

710
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
next@14.2.25
15.5.21

Open the chart page →

3,555
dashboardleechistest1.0.01 of 1See more

dashboard leechistest 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
sysnet4admin/dashboard:bluec5bd3bb1b5a6
next@14.2.3
15.5.21

Open the chart page →

1,344
lynxpromptlynxpromptVerified publisher0.1.21 of 3See more

lynxprompt lynxprompt 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
next@16.2.6
16.2.11

Open the chart page →

1,852
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
next@13.5.6
15.5.21

Open the chart page →

4,647
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
next@15.3.4
15.5.21

Open the chart page →

24,400
miot-appmicroboxlabs0.3.31 of 1See more

miot-app microboxlabs 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
next@16.2.6
16.2.11

Open the chart page →

509
miot-stackmicroboxlabs0.2.21 of 2See more

miot-stack microboxlabs 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
next@16.2.6
16.2.11

Open the chart page →

509
modulariotmicroboxlabs0.9.01 of 4See more

modulariot microboxlabs 0.9.0

1 of the 4 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
next@16.2.6
16.2.11

Open the chart page →

2,256
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
next@15.5.9
15.5.21

Open the chart page →

4,016
neosyncneosyncVerified publisher0.5.411 of 3See more

neosync neosync 0.5.41

1 of the 3 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
next@15.3.1
15.5.21

Open the chart page →

7,184
appneosync-appVerified publisher0.5.411 of 1See more

app neosync-app 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
next@15.3.1
15.5.21

Open the chart page →

1,569
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit:1.24.02434560e8f0e
next@14.2.4
15.5.21

Open the chart page →

5,017
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
next@15.2.4
15.5.21

Open the chart page →

2,370
dify-enterpriseopenshift3.9.82 of 13See more

dify-enterprise openshift 3.9.8

2 of the 13 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
next@16.2.6
16.2.11
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
next@16.2.6
16.2.11

Open the chart page →

4,660
podscopepodscope0.2.31 of 1See more

podscope podscope 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/kadajett/podscope:0.2.3eeedf17112d7
next@16.0.3
16.2.11

Open the chart page →

1,484
pumperlypumperlyVerified publisher0.1.21 of 3See more

pumperly pumperly 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
drumsergio/pumperly:1.4.885bbc3915e9e
next@16.2.2
16.2.11

Open the chart page →

2,854
kratos-selfservice-ui-noderadar-baseVerified publisher0.43.11 of 1See more

kratos-selfservice-ui-node radar-base 0.43.1

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
next@13.5.3
15.5.21

Open the chart page →

2,969
radar-self-enrolment-uiradar-baseVerified publisher0.4.21 of 1See more

radar-self-enrolment-ui radar-base 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
next@15.5.4
15.5.21

Open the chart page →

1,506
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
next@14.2.25
15.5.21

Open the chart page →

5,338
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
next@16.2.6
16.2.11

Open the chart page →

5,819
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
next@16.2.6
16.2.11

Open the chart page →

1,991
counter-dhlsikademo0.3.01 of 3See more

counter-dhl sikademo 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
next@13.0.7
15.5.21

Open the chart page →

4,820
saleor-appstrieb-work0.6.03 of 5See more

saleor-apps trieb-work 0.6.0

3 of the 5 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
next@15.2.4
15.5.21
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
next@15.2.4
15.5.21
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
next@15.2.4
15.5.21

Open the chart page →

6,994
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
next@13.5.11
15.5.21

Open the chart page →

2,789
websitewaldo-visionVerified publisher0.33.01 of 2See more

website waldo-vision 0.33.0

1 of the 2 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
next@13.2.4
15.5.21

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-64648.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
next@14.2.25
15.5.21

Open the chart page →

5,984

Container images carrying it

76 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
next@16.2.6
16.2.11
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
next@16.2.6
16.2.11
3
sysnet4admin/dashboard:bluec5bd3bb1b5a6
next@14.2.3
15.5.21
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
next@15.3.1
15.5.21
2
alquimiaai/studio:certification38a1f0341982
next@15.2.4
15.5.21
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
next@15.4.8
15.5.21
1
chibisafe/chibisafe:latest836467a50792
next@14.3.0-canary.33
15.5.21
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
next@16.1.6
16.2.11
1
documenso/documenso:v1.8.17f16a9449f18
next@14.2.6
15.5.21
1
drumsergio/lynxprompt:2.0.75c6afb6679301
next@16.2.6
16.2.11
1
drumsergio/pumperly:1.4.885bbc3915e9e
next@16.2.2
16.2.11
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
next@15.2.3
15.5.21
1
factly/mande-web:0.34.1742355964b0e
next@13.5.3
15.5.21
1
fallenbagel/jellyseerr:latest4538137bc5af
next@14.2.25
15.5.21
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
next@14.2.2
15.5.21
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
next@15.5.20
15.5.21
1
fosrl/pangolin:1.13.0c32ad797ab96
next@15.5.7
15.5.21
1
helmforge/opencut:v0.3.0bf11156e0ab5
next@16.1.3
16.2.11
1
instill/console:0.68.54cd70e2df5c6
next@15.4.7
15.5.21
1
kyso/kyso-front:lateste52595c5c16f
next@13.5.2
15.5.21
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
next@16.2.6
16.2.11
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
next@16.2.6
16.2.11
1
langgenius/dify-web:0.6.11a2a294743634
next@14.1.0
15.5.21
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
next@15.5.7
15.5.21
1
langgenius/dify-web:1.0.0d64914ff0d6d
next@14.2.15
15.5.21
1
lbenicio/helm-pilot:0.2.54594a2632510
next@16.2.9
16.2.11
1
lobehub/lobe-chat:1.96.9da0c21fefcd3
next@15.3.4
15.5.21
1
nocodb/nocodb:0.301.5d9516f0bf546
next@15.5.13
15.5.21
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
next@13.5.3
15.5.21
1
prowlercloud/prowler-ui:5.31.179ee83c8e702
next@16.2.9
16.2.11
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
next@15.2.4
15.5.21
1
sigp/siren:v3.0.42c219b04758e
next@14.2.25
15.5.21
1
supabase/studio:20241021-9f9b08326d8070c55e9
next@14.2.13
15.5.21
1
treskon/portrait-ui:DEV-lateste7970783bc8d
next@14.1.3
15.5.21
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
next@14.2.26
15.5.21
1
wsjbr/duplistatus:1.4.25e594f5f09f6
next@16.2.9
16.2.11
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
next@14.1.1
15.5.21
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
next@15.3.4
15.5.21
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
next@13.4.12
15.5.21
1
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
next@13.4.12
15.5.21
1
ghcr.io/ajnart/homarr:lateste103abadfb52
next@13.5.11
15.5.21
1
ghcr.io/alpineworks/katalog-frontend:v1.0.734b76dcb1c10
next@14.1.4
15.5.21
1
ghcr.io/bulwarkmail/webmail:1.6.0f0a266506fcf
next@16.2.4
16.2.11
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
next@15.2.3
15.5.21
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
next@14.2.25
15.5.21
1
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
next@16.2.4
16.2.11
1
ghcr.io/glassflow/glassflow-etl-fe:v3.2.05eaad43bd6c5
next@16.0.10
16.2.11
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
next@16.2.7
16.2.11
1
ghcr.io/kadajett/podscope:0.2.3eeedf17112d7
next@16.0.3
16.2.11
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
next@15.3.3
15.5.21
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.