StackRadar

CVE-2026-71429

Medium

Advisory

Published 3 Sept 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.2
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
27
of 17,781 indexed, latest versions
Container images
22
deployed by those charts
Fix available
1 of 1
affected package

stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)

Carried by container images the latest versions of 27 of 17,781 indexed charts deploy, on 22 images.

Affected packageAffected versionsFixed inImages
stream-jsonnpm1.8.0, 1.9.0, 1.9.1, 2.1.03.5.022
OSV records
GHSA-528h-pc64-c93x

Charts affected

27 by stars
ChartLatestAffected imagesRadar Score
n8ncommunity-chartsVerified publisher1.24.401 of 1See more

n8n community-charts 1.24.40

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
n8nio/n8n:2.38.45d9f0cc5672b
stream-json@1.9.1
3.5.0

Open the chart page →

772
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
stream-json@1.9.1
3.5.0

Open the chart page →

1,038
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
stream-json@1.9.1
3.5.0

Open the chart page →

2,938
n8nhelmforgeVerified publisher2.0.02 of 2See more

n8n helmforge 2.0.0

2 of the 2 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
n8nio/n8n:2.38.45d9f0cc5672b
stream-json@1.9.1
3.5.0
n8nio/runners:2.38.4fedf098f3d40
stream-json@1.9.1
3.5.0

Open the chart page →

863
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
stream-json@1.8.0
3.5.0

Open the chart page →

28,839
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
stream-json@1.9.1
3.5.0

Open the chart page →

977
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
stream-json@1.9.1
3.5.0

Open the chart page →

4,016
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
stream-json@1.9.1
3.5.0

Open the chart page →

7,473
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
stream-json@1.9.1
3.5.0

Open the chart page →

1,442
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
stream-json@1.9.1
3.5.0

Open the chart page →

2,575
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
stream-json@1.8.0
3.5.0

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
stream-json@1.8.0
3.5.0

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
stream-json@1.8.0
3.5.0

Open the chart page →

5,141
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
stream-json@1.8.0
3.5.0

Open the chart page →

4,551
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
stream-json@1.9.1
3.5.0

Open the chart page →

1,755
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
stream-json@1.8.0
3.5.0

Open the chart page →

2,973
strapihelmforgeVerified publisher2.3.141 of 3See more

strapi helmforge 2.3.14

1 of the 3 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
helmforge/strapi-base:5.52.270e9143d6d92
stream-json@1.9.1
3.5.0

Open the chart page →

2,061
nocodbinseefrlab0.2.01 of 1See more

nocodb inseefrlab 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
nocodb/nocodb:latest4b760f0d2547
stream-json@1.9.1
3.5.0

Open the chart page →

781
mongo-compassmongo-compass-webVerified publisher1.1.41 of 1See more

mongo-compass mongo-compass-web 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.1f4f8fe4e21f1
stream-json@1.9.1
3.5.0

Open the chart page →

1,759
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
stream-json@1.9.1
3.5.0

Open the chart page →

2,396
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
stream-json@1.9.1
3.5.0

Open the chart page →

1,038
nostreamnostream0.1.01 of 1See more

nostream nostream 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
ghcr.io/cameri/nostream:main8726533b9e69
stream-json@2.1.0
3.5.0

Open the chart page →

595
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
stream-json@1.9.0
3.5.0

Open the chart page →

4,219
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
stream-json@1.9.1
3.5.0

Open the chart page →

1,038
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
stream-json@1.9.1
3.5.0

Open the chart page →

2,638
strapistrapi-xmv0.1.11 of 1See more

strapi strapi-xmv 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
stream-json@1.8.0
3.5.0

Open the chart page →

676
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-71429.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
stream-json@1.9.1
3.5.0

Open the chart page →

3,746

Container images carrying it

22 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
rcdelacruz/my-strapi-app:js-amd6438007f358355
stream-json@1.8.0
3.5.0
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
stream-json@1.9.1
3.5.0
3
n8nio/n8n:2.36.714c4285bc303
stream-json@1.9.1
3.5.0
2
n8nio/n8n:2.38.45d9f0cc5672b
stream-json@1.9.1
3.5.0
2
directus/directus:12.0.29c8470ea465c
stream-json@1.9.1
3.5.0
1
directus/directus:11.1.0e3c8bb975350
stream-json@1.8.0
3.5.0
1
ethpandaops/ethereumjs:masterfb84b718500f
stream-json@1.9.1
3.5.0
1
evoapicloud/evolution-api:latest966625532d90
stream-json@1.9.1
3.5.0
1
haohanyang/compass-web:0.5.054f2112602ee
stream-json@1.9.1
3.5.0
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
stream-json@1.9.1
3.5.0
1
helmforge/strapi-base:5.52.270e9143d6d92
stream-json@1.9.1
3.5.0
1
n8nio/n8n:2.25.7761374d4eb84
stream-json@1.9.1
3.5.0
1
n8nio/n8n:2.36.8cfe2704ff858
stream-json@1.9.1
3.5.0
1
n8nio/runners:2.38.4fedf098f3d40
stream-json@1.9.1
3.5.0
1
nocodb/nocodb:latest4b760f0d2547
stream-json@1.9.1
3.5.0
1
nocodb/nocodb:0.258.06779a4ddedf2
stream-json@1.9.0
3.5.0
1
nocodb/nocodb:0.301.5d9516f0bf546
stream-json@1.9.1
3.5.0
1
qxip/qryn:3.2.3977acc9c7a9fd
stream-json@1.8.0
3.5.0
1
ghcr.io/cameri/nostream:main8726533b9e69
stream-json@2.1.0
3.5.0
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
stream-json@1.8.0
3.5.0
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
stream-json@1.8.0
3.5.0
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
stream-json@1.9.1
3.5.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.