StackRadar

CVE-2026-67214

Medium

Advisory

Published 29 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
306
of 17,781 indexed, latest versions
Container images
317
deployed by those charts
Fix available
1 of 2
affected packages

nanoid: non-secure generators can loop indefinitely with negative size

Carried by container images the latest versions of 306 of 17,781 indexed charts deploy, on 317 images.

Affected packageAffected versionsFixed inImages
nanoidnpm2.1.11, 3.1.12, 3.1.16, 3.1.20+26 more3.3.16, 5.1.16317
node-postcssdeb8.4.31+~cs8.0.26-1no fix listed1
OSV records
GHSA-28wg-ghj8-5hjvUBUNTU-CVE-2026-67214

Charts affected

306 by stars
ChartLatestAffected imagesRadar Score
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-67214.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nanoid@2.1.11
3.3.16

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-67214.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nanoid@2.1.11
3.3.16

Open the chart page →

28,605
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-67214.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
nanoid@5.1.9
5.1.16

Open the chart page →

280
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-67214.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
nanoid@3.2.0
3.3.16

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-67214.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
nanoid@3.3.8
3.3.16

Open the chart page →

6,285
workadventureworkadventure1.1.03 of 9See more

workadventure workadventure 1.1.0

3 of the 9 container images this version deploys carry CVE-2026-67214.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
nanoid@3.3.6
3.3.16
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
nanoid@3.3.6
3.3.16
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
nanoid@3.3.6
3.3.16

Open the chart page →

16,083

Container images carrying it

317 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
rcdelacruz/my-strapi-app:js-amd6438007f358355
nanoid@3.3.7
3.3.16
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
nanoid@3.3.4
3.3.16
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
nanoid@3.3.12
3.3.16
3
governify/assets-manager:v1.4.12987672448c7
nanoid@3.1.25
3.3.16
2
hookiesolutions/webhookie:latest0629694246ba
nanoid@2.1.11
3.3.16
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
nanoid@3.3.7
3.3.16
2
kutt/kutt:latest:v3.2.6fa3d24a89b04
nanoid@3.3.8
3.3.16
2
louislam/uptime-kuma:2.3.29aeb4e51d038
nanoid@3.3.12
3.3.16
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
nanoid@3.3.11
3.3.16
2
moreillon/api-proxy:a3e8b41e9e578c9653b6
nanoid@3.3.3
3.3.16
2
moreillon/group-manager:v4.9.0d5a0ec8394c0
nanoid@3.3.1
3.3.16
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
nanoid@3.3.3
3.3.16
2
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
nanoid@5.1.9
5.1.16
2
outlinewiki/outline:0.69.1d060dcd8f9aa
nanoid@3.3.4
3.3.16
2
rajnandan1/kener:3.2.1930407afca731
nanoid@3.3.8
3.3.16
2
requarks/wiki:2:latest68f0d1848261
nanoid@3.2.0
3.3.16
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
nanoid@3.3.12
3.3.16
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
nanoid@3.1.23
3.3.16
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
nanoid@3.3.7
3.3.16
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
nanoid@3.3.1
3.3.16
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
nanoid@3.3.4
3.3.16
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
nanoid@3.3.8
3.3.16
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
nanoid@2.1.11
3.3.16
2
activepieces/activepieces:0.23.0c26188b44e62
nanoid@3.3.6
3.3.16
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
nanoid@3.3.11
3.3.16
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
nanoid@3.3.11
3.3.16
1
alquimiaai/studio:certification38a1f0341982
nanoid@3.3.11
3.3.16
1
anamskenneth/recipe_frontend:2025-06-079ecf04f42cc3
nanoid@3.3.7
3.3.16
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
nanoid@3.3.11
3.3.16
1
apimap/developer:v1.3.1406d3858e20c
nanoid@3.3.4
3.3.16
1
apimap/portal:v2.4.0041a4790c65c
nanoid@3.3.4
3.3.16
1
arfath29/3-tier-app-frontend:latest384b3e377f47
nanoid@3.1.23
3.3.16
1
assistiot/open_api_frontend:1.0.1f11d82defc70
nanoid@3.3.4
3.3.16
1
automatischio/automatisch:0.15.03bace7a12d5f
nanoid@3.3.11
3.3.16
1
baserow/baserow:1.30.1df0c42eb67e8
nanoid@3.3.7
3.3.16
1
belirta/beli-docker:v1.0.0f65ad0e23b4d
nanoid@3.3.3
3.3.16
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
nanoid@3.3.4
3.3.16
1
bnwokoye/nodejswebapp:latest74de7dc7ebfb
nanoid@3.3.3
3.3.16
1
ccjacobs14/amazon:59a9b14a6f09e
nanoid@3.3.6
3.3.16
1
chainsafe/lodestar:latest5593f6e97912
nanoid@3.3.11
3.3.16
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
nanoid@3.3.8
3.3.16
1
chibisafe/chibisafe:latest836467a50792
nanoid@3.3.7
3.3.16
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
nanoid@3.3.7
3.3.16
1
chocobozzz/peertube:v8.1.5052712130691
nanoid@3.3.11
3.3.16
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
nanoid@3.3.4
3.3.16
1
coldatom/containers-security-front:latest7c2fbbb41bcf
nanoid@3.3.4
3.3.16
1
conduction/conduction-ui-app:devd591f5e6f2a9
nanoid@3.1.20
3.3.16
1
countly/api:25.05.4f4cc7447c4f5
nanoid@3.3.3
3.3.16
1
countly/countly-server:25.05.4e3c238248f99
nanoid@3.3.3
3.3.16
1
countly/frontend:25.05.42acbc11499b6
nanoid@3.3.3
3.3.16
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.