StackRadar

CVE-2026-67316

Medium

Advisory

Published 20 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
328
of 17,781 indexed, latest versions
Container images
319
deployed by those charts
Fix available
1 of 1
affected package

Axios: Prototype pollution gadgets can alter axios request construction

Carried by container images the latest versions of 328 of 17,781 indexed charts deploy, on 319 images.

Affected packageAffected versionsFixed inImages
axiosnpm0.15.3, 0.16.2, 0.18.0, 0.18.1+64 more0.33.0, 1.18.0319
OSV records
GHSA-mmx7-hfxf-jppx

Charts affected

328 by stars
ChartLatestAffected imagesRadar Score
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
axios@1.7.7
1.18.0

Open the chart page →

15,635
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
axios@1.7.4
1.18.0

Open the chart page →

4,052
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
axios@0.18.1
0.33.0

Open the chart page →

3,881
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
axios@1.16.0
1.18.0

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
axios@1.16.0
1.18.0

Open the chart page →

919
strapistrapi-xmv0.1.11 of 1See more

strapi strapi-xmv 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
axios@1.16.0
1.18.0

Open the chart page →

676
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
axios@0.21.1
0.33.0

Open the chart page →

4,017
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
axios@0.21.4
0.33.0

Open the chart page →

39,090
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
axios@0.21.4
0.33.0

Open the chart page →

5,604
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
axios@0.21.4
0.33.0

Open the chart page →

20,270
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
axios@1.7.7
1.18.0

Open the chart page →

2,408
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
axios@1.16.0
1.18.0

Open the chart page →

4,661
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
axios@0.21.4
0.33.0

Open the chart page →

3,576
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
axios@1.6.5
1.18.0

Open the chart page →

2,806
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
axios@1.17.0
1.18.0

Open the chart page →

5,550
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
axios@1.13.6
1.18.0

Open the chart page →

2,028
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
axios@1.8.3
1.18.0

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
axios@1.13.2
1.18.0

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
axios@1.16.1
1.18.0

Open the chart page →

1,787
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
axios@0.21.4
0.33.0

Open the chart page →

3,129
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
axios@1.7.4
1.18.0

Open the chart page →

2,789
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
axios@0.21.4
0.33.0

Open the chart page →

3,118
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
axios@1.9.0
1.18.0

Open the chart page →

5,984
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
axios@1.12.2
1.18.0

Open the chart page →

5,484
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
axios@1.15.2
1.18.0

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
axios@1.8.3
1.18.0

Open the chart page →

6,285
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
axios@1.3.5
1.18.0
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
axios@1.3.5
1.18.0
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
axios@1.3.5
1.18.0
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
axios@1.3.5
1.18.0

Open the chart page →

16,083
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-67316.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
axios@0.28.1
0.33.0

Open the chart page →

9,381

Container images carrying it

319 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
fiware/iotagent-ul:1.14.0fe11f55a926d
axios@0.19.2
0.33.0
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
axios@1.6.2
1.18.0
1
fosrl/pangolin:1.13.0c32ad797ab96
axios@1.13.2
1.18.0
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
axios@0.21.4
0.33.0
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
axios@0.21.1
0.33.0
1
gristlabs/grist:0.7.96e71b1914a7e
axios@0.18.0
0.33.0
1
halkeye/irslackd:latest7638bfba70b0
axios@0.18.1
0.33.0
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
axios@0.26.1
0.33.0
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
axios@1.4.0
1.18.0
1
henrywhitaker3/speedtest-tracker:latest47159a940229
axios@0.21.1
0.33.0
1
heywood8/redisinsight:2.28.00bc9ab313d37
axios@0.25.0
0.33.0
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
axios@0.21.1
0.33.0
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
axios@0.21.3
0.33.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
axios@1.7.7
1.18.0
1
hugohg34/server:0.0.2503e5d8960ff
axios@0.24.0
0.33.0
1
ianw/quickchart:v1.7.1dc49dd460c37
axios@0.24.0
0.33.0
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
axios@0.21.4
0.33.0
1
ibmcom/microclimate-portal:latested5505e5c7ec
axios@0.15.3
0.33.0
1
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
axios@0.19.0
0.33.0
1
instill/console:0.68.54cd70e2df5c6
axios@1.11.0
1.18.0
1
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
axios@0.21.4
0.33.0
1
interlayhq/interbtc-hydra-processor:0.10.55b2c414307b9
axios@0.21.4
0.33.0
1
jakowenko/double-take:1.6.0b858bac9e32a
axios@0.22.0
0.33.0
1
jayfong/yapi:1.10.2163e5d621910
axios@0.18.1
0.33.0
1
joplin/server:3.0-beta52af57880c0e
axios@0.25.0
0.33.0
1
joplin/server:2.14.2-betab87564ef34e9
axios@0.25.0
0.33.0
1
keyoxide/keyoxide:stable96f27a71269d
axios@0.25.0
0.33.0
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
axios@0.26.1
0.33.0
1
kubevious/backend:1.2.22d9ba6eb46b6
axios@1.4.0
1.18.0
1
kubevious/collector:1.2.1f58226f9d84e
axios@1.4.0
1.18.0
1
kubevious/guard:1.2.19bf567704de2
axios@0.24.0
0.33.0
1
kubevious/parser:1.0.151acf1a1f0b47
axios@0.24.0
0.33.0
1
kubevious/parser:1.2.299ae7a5168c2
axios@1.4.0
1.18.0
1
kubevious/workload-operator:1.0.20b0f4c507eb6
axios@1.3.4
1.18.0
1
kyleslugg/klusterview:latestba8c36dfdfbd
axios@1.4.0
1.18.0
1
kyso/kyso-front:lateste52595c5c16f
axios@0.24.0
0.33.0
1
lavandadelpatio/frontend:latest501c3f31e0bc
axios@0.19.2
0.33.0
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
axios@1.7.7
1.18.0
1
library/ghost:6.37.01ef2e532ca4d
axios@1.16.0
1.18.0
1
library/ghost:6.25.12654b1e90413
axios@1.13.2
1.18.0
1
library/ghost:6.41.129773d6be407
axios@1.16.0
1.18.0
1
library/ghost:4.37.0767230c0f263
axios@0.21.4
0.33.0
1
library/ghost:6.39.0-alpine77196da4b0df
axios@1.16.0
1.18.0
1
library/ghost:5.79.083f7bf209844
axios@1.6.5
1.18.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
axios@1.13.2
1.18.0
1
library/kibana:7.17.150172f1c538e7
axios@0.21.4
0.33.0
1
library/kibana:8.18.004c0fc150f3a
axios@1.8.3
1.18.0
1
library/kibana:7.17.8c5781ba340ef
axios@0.27.2
0.33.0
1
library/kibana:7.17.3e2e2031c15be
axios@0.21.1
0.33.0
1
linuxserver/codimd:latestb801bbcf6386
axios@0.19.2
0.33.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.