StackRadar

CVE-2026-66010

Low

Advisory

Published 21 Jul 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.1
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
75
of 17,781 indexed, latest versions
Container images
67
deployed by those charts
Fix available
1 of 1
affected package

DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.

Carried by container images the latest versions of 75 of 17,781 indexed charts deploy, on 67 images.

Affected packageAffected versionsFixed inImages
dompurifynpm2.1.1, 2.2.6, 2.2.7, 2.3.1+28 more3.4.1267
OSV records
GHSA-c2j3-45gr-mqc4

Charts affected

75 by stars
ChartLatestAffected imagesRadar Score
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
dompurify@2.3.10
3.4.12

Open the chart page →

2,685
homarrmedia-servarrVerified publisher0.55.11 of 1See more

homarr media-servarr 0.55.1

1 of the 1 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
dompurify@3.4.11
3.4.12

Open the chart page →

435
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
dompurify@2.1.1
3.4.12

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
dompurify@2.1.1
3.4.12

Open the chart page →

10,603
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
dompurify@3.3.0
3.4.12

Open the chart page →

4,960
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
dompurify@2.4.3
3.4.12

Open the chart page →

6,608
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
dompurify@3.2.0
3.4.12

Open the chart page →

4,219
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
dompurify@3.3.1
3.4.12

Open the chart page →

1,858
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
dompurify@2.3.1
3.4.12

Open the chart page →

29,227
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
dompurify@3.2.6
3.4.12

Open the chart page →

5,338
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
dompurify@3.0.5
3.4.12

Open the chart page →

7,413
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
dompurify@2.4.3
3.4.12

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
dompurify@2.3.3
3.4.12

Open the chart page →

3,638
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
dompurify@3.0.11
3.4.12

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
dompurify@3.0.11
3.4.12

Open the chart page →

16,400
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
dompurify@3.0.11
3.4.12

Open the chart page →

16,400
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
dompurify@3.0.11
3.4.12

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
dompurify@3.0.11
3.4.12

Open the chart page →

15,635
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
dompurify@3.4.11
3.4.12

Open the chart page →

5,550
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
dompurify@3.3.0
3.4.12

Open the chart page →

2,620
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
dompurify@3.2.4
3.4.12

Open the chart page →

5,484
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
dompurify@3.4.11
3.4.12

Open the chart page →

280
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
dompurify@3.3.1
3.4.12

Open the chart page →

5,459
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
dompurify@2.1.1
3.4.12

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-66010.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
dompurify@2.5.6
3.4.12

Open the chart page →

9,381

Container images carrying it

67 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
yuzutech/kroki-excalidraw:0.29.157917319ea70
dompurify@3.1.6
3.4.12
1
zimengxiong/excalidash-backend:0.4.271273af713c91
dompurify@3.3.0
3.4.12
1
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
dompurify@3.4.11
3.4.12
1
ghcr.io/homarr-labs/homarr:v1.77.0f23ad77a681b
dompurify@3.4.11
3.4.12
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
dompurify@3.2.6
3.4.12
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
dompurify@3.2.6
3.4.12
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
dompurify@3.2.6
3.4.12
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
dompurify@2.2.7
3.4.12
1
ghcr.io/mkutlak/alluredeck-api:0.41.0fa429df90c68
dompurify@3.4.11
3.4.12
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
dompurify@3.4.9
3.4.12
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
dompurify@3.4.5
3.4.12
1
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
dompurify@3.3.3
3.4.12
1
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
dompurify@3.4.9
3.4.12
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
dompurify@3.4.11
3.4.12
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
dompurify@3.4.0
3.4.12
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
dompurify@2.3.1
3.4.12
1
quay.io/wekan/wekan:v5.65cb17600883a3
dompurify@2.3.3
3.4.12
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.