StackRadar

CVE-2026-67319

Medium

Advisory

Published 20 Jul 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.3
base score, highest
EPSS
0.002
15th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
328
of 17,787 indexed, latest versions
Container images
319
deployed by those charts
Fix available
1 of 1
affected package

Axios: Nested axios option objects can consume polluted prototype values

Carried by container images the latest versions of 328 of 17,787 indexed charts deploy, on 319 images.

Affected packageAffected versionsFixed inImages
axiosnpm0.15.3, 0.16.2, 0.18.0, 0.18.1+64 more0.33.0, 1.18.0319
OSV records
GHSA-7q8q-rj6j-mhjq

Charts affected

328 by stars
ChartLatestAffected imagesRadar Score
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
axios@1.7.7
1.18.0

Open the chart page →

15,635
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
axios@1.7.4
1.18.0

Open the chart page →

4,052
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
axios@0.18.1
0.33.0

Open the chart page →

3,881
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
axios@1.16.0
1.18.0

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
axios@1.16.0
1.18.0

Open the chart page →

919
strapistrapi-xmv0.1.11 of 1See more

strapi strapi-xmv 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
axios@1.16.0
1.18.0

Open the chart page →

676
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
axios@0.21.1
0.33.0

Open the chart page →

4,017
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
axios@0.21.4
0.33.0

Open the chart page →

39,090
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
axios@0.21.4
0.33.0

Open the chart page →

5,604
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
axios@0.21.4
0.33.0

Open the chart page →

20,270
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
axios@1.7.7
1.18.0

Open the chart page →

2,408
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
axios@1.16.0
1.18.0

Open the chart page →

4,661
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
axios@0.21.4
0.33.0

Open the chart page →

3,576
node-redthl-chartsVerified publisher0.1.01 of 1See more

node-red thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
nodered/node-red:3.0.2-18e2632a7a35dd
axios@1.6.5
1.18.0

Open the chart page →

2,806
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
axios@1.17.0
1.18.0

Open the chart page →

5,550
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
axios@1.13.6
1.18.0

Open the chart page →

2,028
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
axios@1.8.3
1.18.0

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
axios@1.13.2
1.18.0

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.221See more

devportal veecode-platform-next 0.1.22

1 container image this version deploys carries CVE-2026-67319.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
axios@1.16.1
1.18.0

Open the chart page →

genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
axios@0.21.4
0.33.0

Open the chart page →

3,129
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
axios@1.7.4
1.18.0

Open the chart page →

2,789
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
axios@0.21.4
0.33.0

Open the chart page →

3,118
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
axios@1.9.0
1.18.0

Open the chart page →

5,984
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
axios@1.12.2
1.18.0

Open the chart page →

5,484
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
axios@1.15.2
1.18.0

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
axios@1.8.3
1.18.0

Open the chart page →

6,285
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
axios@1.3.5
1.18.0
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
axios@1.3.5
1.18.0
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
axios@1.3.5
1.18.0
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
axios@1.3.5
1.18.0

Open the chart page →

16,083
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-67319.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
axios@0.28.1
0.33.0

Open the chart page →

9,381

Container images carrying it

319 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
axios@1.11.0
1.18.0
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
axios@1.8.4
1.18.0
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
axios@1.16.0
1.18.0
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
axios@0.21.4
0.33.0
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
axios@0.21.4
0.33.0
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
axios@0.21.4
0.33.0
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
axios@0.26.1
0.33.0
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
axios@1.15.0
1.18.0
1
quay.io/ibmgaragecloud/slack-notifications:latest041df93e2bac
axios@0.21.1
0.33.0
1
quay.io/mittwald/kube-mail:latest04f1099241fc
axios@1.10.0
1.18.0
1
quay.io/netwarps/walletconnect-relay:v2.1.3-rc.15d90b9c193e0
axios@0.26.1
0.33.0
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
axios@1.1.3
1.18.0
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
axios@0.21.4
0.33.0
1
quay.io/soketi/soketi:1.6-16-debian713223456cf1
axios@0.21.4
0.33.0
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
axios@1.11.0
1.18.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
axios@1.13.6
1.18.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
axios@1.9.0
1.18.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
axios@1.13.6
1.18.0
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
axios@0.16.2
0.33.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.