StackRadar

CVE-2026-75838

Medium

Advisory

Published 7 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.1
base score, highest
EPSS
0.003
23rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
76
of 17,781 indexed, latest versions
Container images
68
deployed by those charts
Fix available
1 of 1
affected package

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

Carried by container images the latest versions of 76 of 17,781 indexed charts deploy, on 68 images.

Affected packageAffected versionsFixed inImages
dompurifynpm2.1.1, 2.2.6, 2.2.7, 2.3.1+29 more3.4.1368
OSV records
GHSA-55q2-fjhq-7xh7

Charts affected

76 by stars
ChartLatestAffected imagesRadar Score
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
dompurify@3.4.1
3.4.13

Open the chart page →

2,756
kyso-frontkyso1.0.01 of 1See more

kyso-front kyso 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
kyso/kyso-front:lateste52595c5c16f
dompurify@2.3.10
3.4.13

Open the chart page →

2,685
homarrmedia-servarrVerified publisher0.55.11 of 1See more

homarr media-servarr 0.55.1

1 of the 1 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
dompurify@3.4.11
3.4.13

Open the chart page →

435
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
dompurify@2.1.1
3.4.13

Open the chart page →

10,603
standard-application-stackmintel11.4.01 of 12See more

standard-application-stack mintel 11.4.0

1 of the 12 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
dompurify@2.1.1
3.4.13

Open the chart page →

10,603
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
dompurify@3.3.0
3.4.13

Open the chart page →

4,960
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
dompurify@2.4.3
3.4.13

Open the chart page →

6,608
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
dompurify@3.2.0
3.4.13

Open the chart page →

4,219
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
dompurify@3.3.1
3.4.13

Open the chart page →

1,858
stackrox-chartredhat-cop0.0.101 of 1See more

stackrox-chart redhat-cop 0.0.10

1 of the 1 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
dompurify@2.3.1
3.4.13

Open the chart page →

29,227
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
dompurify@3.2.6
3.4.13

Open the chart page →

5,338
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
dompurify@3.0.5
3.4.13

Open the chart page →

7,413
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
dompurify@2.4.3
3.4.13

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
dompurify@2.3.3
3.4.13

Open the chart page →

3,638
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
dompurify@3.0.11
3.4.13

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
dompurify@3.0.11
3.4.13

Open the chart page →

16,400
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
dompurify@3.0.11
3.4.13

Open the chart page →

16,400
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
dompurify@3.0.11
3.4.13

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
dompurify@3.0.11
3.4.13

Open the chart page →

15,635
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
dompurify@3.4.11
3.4.13

Open the chart page →

5,550
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
dompurify@3.3.0
3.4.13

Open the chart page →

2,620
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
dompurify@3.2.4
3.4.13

Open the chart page →

5,484
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
dompurify@3.4.12
3.4.13

Open the chart page →

280
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
dompurify@3.3.1
3.4.13

Open the chart page →

5,459
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
dompurify@2.1.1
3.4.13

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-75838.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
dompurify@2.5.6
3.4.13

Open the chart page →

9,381

Container images carrying it

68 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
dompurify@2.3.10
3.4.13
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
dompurify@2.1.1
3.4.13
2
governify/assets-manager:v1.4.12987672448c7
dompurify@2.2.6
3.4.13
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
dompurify@2.1.1
3.4.13
2
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
dompurify@3.4.12
3.4.13
2
outlinewiki/outline:0.69.1d060dcd8f9aa
dompurify@2.4.3
3.4.13
2
requarks/wiki:2:latest68f0d1848261
dompurify@3.3.1
3.4.13
2
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
dompurify@3.3.2
3.4.13
1
archivebox/archivebox:0.7.41a5a37331091
dompurify@3.0.7
3.4.13
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
dompurify@2.1.1
3.4.13
1
assistiot/open_api_frontend:1.0.1f11d82defc70
dompurify@2.3.10
3.4.13
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
dompurify@3.2.7
3.4.13
1
docmost/docmost:0.95.041c8d777cf23
dompurify@3.4.11
3.4.13
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
dompurify@3.2.6
3.4.13
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
dompurify@3.4.11
3.4.13
1
fosrl/pangolin:latest83a55f933b4d
dompurify@3.4.0
3.4.13
1
fosrl/pangolin:1.13.0c32ad797ab96
dompurify@3.2.7
3.4.13
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
dompurify@2.3.8
3.4.13
1
joplin/server:3.0-beta52af57880c0e
dompurify@3.0.5
3.4.13
1
joplin/server:2.14.2-betab87564ef34e9
dompurify@3.0.5
3.4.13
1
kyso/kyso-front:lateste52595c5c16f
dompurify@2.3.10
3.4.13
1
library/ghost:6.37.01ef2e532ca4d
dompurify@3.4.1
3.4.13
1
library/ghost:6.25.12654b1e90413
dompurify@3.3.0
3.4.13
1
library/ghost:6.41.129773d6be407
dompurify@3.4.1
3.4.13
1
library/ghost:6.39.0-alpine77196da4b0df
dompurify@3.4.1
3.4.13
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
dompurify@3.3.0
3.4.13
1
maildev/maildev:2.2.1180ef51f65ee
dompurify@3.1.6
3.4.13
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
dompurify@2.2.6
3.4.13
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
dompurify@2.4.3
3.4.13
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
dompurify@2.4.3
3.4.13
1
nocodb/nocodb:latest4b760f0d2547
dompurify@3.4.8
3.4.13
1
nocodb/nocodb:0.258.06779a4ddedf2
dompurify@3.2.0
3.4.13
1
nocodb/nocodb:0.301.5d9516f0bf546
dompurify@3.3.3
3.4.13
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
dompurify@2.5.6
3.4.13
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
dompurify@2.4.1
3.4.13
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
dompurify@2.4.7
3.4.13
1
outlinewiki/outline:0.82.0494dfb9249a6
dompurify@3.2.3
3.4.13
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
dompurify@3.3.1
3.4.13
1
requarks/wiki:canary-2.5.2438b5865a7386c
dompurify@2.2.7
3.4.13
1
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
dompurify@3.0.11
3.4.13
1
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
dompurify@3.0.11
3.4.13
1
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
dompurify@3.0.11
3.4.13
1
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
dompurify@3.0.11
3.4.13
1
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
dompurify@3.0.11
3.4.13
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
dompurify@3.4.12
3.4.13
1
twentycrm/twenty:v2.22.0e7d9948bf284
dompurify@3.4.11
3.4.13
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
dompurify@2.3.4
3.4.13
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
dompurify@3.1.4
3.4.13
1
wazuh/wazuh-dashboard:4.4.11787550d2358
dompurify@2.4.1
3.4.13
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
dompurify@3.2.4
3.4.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.