StackRadar

CVE-2026-71847

Low

Advisory

Published 7 Aug 2026In the index since 8 Sept 2026
Severity
Low
worst across findings
CVSS
2.0
base score, highest
EPSS
0.003
26th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
3
of 17,787 indexed, latest versions
Container images
3
deployed by those charts
Fix available
1 of 1
affected package

Ruby JSON: JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams

Carried by container images the latest versions of 3 of 17,787 indexed charts deploy, on 3 images.

Affected packageAffected versionsFixed inImages
jsongem2.21.12.21.23
OSV records
GHSA-9hj4-r449-hfvc

Charts affected

3 by stars
ChartLatestAffected imagesRadar Score
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2026-71847.

Container imageDigestPackageFixed in
ghcr.io/caninehq/canine:latesta058034ca006
json@2.21.1
2.21.2

Open the chart page →

13,363
fluentd-aggregatorfluentd-aggregatorOfficialVerified publisher1.0.01 of 2See more

fluentd-aggregator fluentd-aggregator 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-71847.

Container imageDigestPackageFixed in
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
json@2.21.1
2.21.2

Open the chart page →

1,712
deltabadgerk8s-chartsVerified publisher2.0.01 of 1See more

deltabadger k8s-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-71847.

Container imageDigestPackageFixed in
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
json@2.21.1
2.21.2

Open the chart page →

5,681

Container images carrying it

3 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/caninehq/canine:latesta058034ca006
json@2.21.1
2.21.2
1
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
json@2.21.1
2.21.2
1
ghcr.io/fluent/fluentd-aggregator-docker-image:2.1.0ad25916eebbb
json@2.21.1
2.21.2
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.