StackRadar

CVE-2026-64649

High

Advisory

Published 22 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.3
base score, highest
EPSS
0.009
57th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
68
of 17,781 indexed, latest versions
Container images
66
deployed by those charts
Fix available
1 of 1
affected package

Next.js: Server-Side Request Forgery in Server Actions on custom servers

Carried by container images the latest versions of 68 of 17,781 indexed charts deploy, on 66 images.

Affected packageAffected versionsFixed inImages
nextnpm14.1.1, 14.1.3, 14.1.4, 14.2.2+35 more15.5.21, 16.2.1166
OSV records
GHSA-89xv-2m56-2m9x

Charts affected

68 by stars
ChartLatestAffected imagesRadar Score
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
next@15.3.4
15.5.21

Open the chart page →

24,400
miot-appmicroboxlabs0.3.31 of 1See more

miot-app microboxlabs 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
next@16.2.6
16.2.11

Open the chart page →

509
miot-stackmicroboxlabs0.2.21 of 2See more

miot-stack microboxlabs 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
next@16.2.6
16.2.11

Open the chart page →

509
modulariotmicroboxlabs0.9.01 of 4See more

modulariot microboxlabs 0.9.0

1 of the 4 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
next@16.2.6
16.2.11

Open the chart page →

2,256
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
next@15.5.9
15.5.21

Open the chart page →

4,016
neosyncneosyncVerified publisher0.5.411 of 3See more

neosync neosync 0.5.41

1 of the 3 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
next@15.3.1
15.5.21

Open the chart page →

7,184
appneosync-appVerified publisher0.5.411 of 1See more

app neosync-app 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
next@15.3.1
15.5.21

Open the chart page →

1,569
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit:1.24.02434560e8f0e
next@14.2.4
15.5.21

Open the chart page →

5,017
alquimia-studioopenshift0.2.01 of 1See more

alquimia-studio openshift 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
alquimiaai/studio:certification38a1f0341982
next@15.2.4
15.5.21

Open the chart page →

2,370
dify-enterpriseopenshift3.9.82 of 13See more

dify-enterprise openshift 3.9.8

2 of the 13 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
next@16.2.6
16.2.11
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
next@16.2.6
16.2.11

Open the chart page →

4,660
podscopepodscope0.2.31 of 1See more

podscope podscope 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/kadajett/podscope:0.2.3eeedf17112d7
next@16.0.3
16.2.11

Open the chart page →

1,484
pumperlypumperlyVerified publisher0.1.21 of 3See more

pumperly pumperly 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
drumsergio/pumperly:1.4.885bbc3915e9e
next@16.2.2
16.2.11

Open the chart page →

2,854
radar-self-enrolment-uiradar-baseVerified publisher0.4.21 of 1See more

radar-self-enrolment-ui radar-base 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
next@15.5.4
15.5.21

Open the chart page →

1,506
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
next@14.2.25
15.5.21

Open the chart page →

5,338
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
next@16.2.6
16.2.11

Open the chart page →

5,819
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
next@16.2.6
16.2.11

Open the chart page →

1,991
saleor-appstrieb-work0.6.03 of 5See more

saleor-apps trieb-work 0.6.0

3 of the 5 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
next@15.2.4
15.5.21
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
next@15.2.4
15.5.21
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
next@15.2.4
15.5.21

Open the chart page →

6,994
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-64649.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
next@14.2.25
15.5.21

Open the chart page →

5,984

Container images carrying it

66 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/rybbit-io/rybbit-client:latest9a3bbb2e837a
next@16.2.6
16.2.11
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
next@14.2.35
15.5.21
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
next@15.2.4
15.5.21
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
next@15.2.4
15.5.21
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
next@15.2.4
15.5.21
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
next@15.5.9
15.5.21
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
next@15.5.7
15.5.21
1
ghcr.io/umami-software/umami:3.1.0e3f80c0625aa
next@16.2.4
16.2.11
1
ghcr.io/wachd/wachd:0.4.1805b05c56da94
next@16.2.4
16.2.11
1
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
next@16.0.3
16.2.11
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
next@15.2.4
15.5.21
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
next@14.2.5
15.5.21
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
next@15.5.20
15.5.21
1
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
next@15.5.18
15.5.21
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
next@14.2.32
15.5.21
1
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
next@15.5.18
15.5.21
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.