StackRadar

CVE-2026-75899

High

Advisory

Published 24 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
68
of 17,781 indexed, latest versions
Container images
65
deployed by those charts
Fix available
1 of 2
affected packages

fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding

Carried by container images the latest versions of 68 of 17,781 indexed charts deploy, on 65 images.

Affected packageAffected versionsFixed inImages
fast-urinpm3.1.2, 3.1.3, 3.1.4, 3.1.5+2 more3.1.6, 4.1.362
node-ajvdeb6.10.2-1, 8.12.0~ds+~2.1.1-4no fix listed3
OSV records
GHSA-fph4-wmhf-6fwfUBUNTU-CVE-2026-75899

Charts affected

68 by stars
ChartLatestAffected imagesRadar Score
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
fast-uri@3.1.5
3.1.6

Open the chart page →

1,038
rocketchatrocketchat-server7.0.24 of 12See more

rocketchat rocketchat-server 7.0.2

4 of the 12 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
rocketchat/account-service:8.6.144af8ac4e711
fast-uri@3.1.2
3.1.6
rocketchat/authorization-service:8.6.16bc18fb5d0e5
fast-uri@3.1.2
3.1.6
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
fast-uri@3.1.2
3.1.6
rocketchat/presence-service:8.6.1c1170bdfe797
fast-uri@3.1.2
3.1.6

Open the chart page →

12,279
opensearch-dashboardsopensearch-project-helm-chartsVerified publisher3.8.01 of 1See more

opensearch-dashboards opensearch-project-helm-charts 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
fast-uri@3.1.2
3.1.6

Open the chart page →

280
penpotpenpotOfficialVerified publisher1.9.01 of 4See more

penpot penpot 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
penpotapp/mcp:2.17.284f3f07ead11
fast-uri@3.1.2
3.1.6

Open the chart page →

4,314
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
fast-uri@3.1.2
3.1.6

Open the chart page →

5,660
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
fast-uri@3.1.5
3.1.6

Open the chart page →

10,775
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
fast-uri@3.1.3
3.1.6

Open the chart page →

1,339
dialdialOfficialVerified publisher7.2.01 of 4See more

dial dial 7.2.0

1 of the 4 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
epam/ai-dial-chat:0.49.0bd6b13695cdc
fast-uri@3.1.5
3.1.6

Open the chart page →

2,163
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
fast-uri@3.1.5
3.1.6

Open the chart page →

9,460
umamihelmforgeVerified publisher2.3.31 of 3See more

umami helmforge 2.3.3

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.3.1fa32d116cf20
fast-uri@3.1.5
3.1.6

Open the chart page →

2,027
ghostcloudpirates-ghostVerified publisher0.20.221 of 3See more

ghost cloudpirates-ghost 0.20.22

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
fast-uri@3.1.2
3.1.6

Open the chart page →

7,146
duplistatusduplistatusVerified publisher1.2.01 of 2See more

duplistatus duplistatus 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
wsjbr/duplistatus:1.4.25e594f5f09f6
fast-uri@3.1.2
3.1.6

Open the chart page →

1,870
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/unionai-oss/flyteconsole-v2:latestdb4362ec0d3b
fast-uri@3.1.5
3.1.6

Open the chart page →

4,641
flyte-coreflyte2.0.481 of 3See more

flyte-core flyte 2.0.48

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/unionai-oss/flyteconsole-v2:latestdb4362ec0d3b
fast-uri@3.1.5
3.1.6

Open the chart page →

1,178
ghost-on-kubernetesghost-on-kubernetes-helmVerified publisher1.1.21 of 3See more

ghost-on-kubernetes ghost-on-kubernetes-helm 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
fast-uri@3.1.2
3.1.6

Open the chart page →

1,447
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
fast-uri@3.1.2
3.1.6

Open the chart page →

5,218
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
fast-uri@3.1.2
3.1.6

Open the chart page →

7,473
jellystatdjjudas21Verified publisher0.1.121 of 1See more

jellystat djjudas21 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
fast-uri@3.1.2
3.1.6

Open the chart page →

1,722
gorules-brmsgorulesVerified publisher1.18.11 of 1See more

gorules-brms gorules 1.18.1

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
gorules/brms:latest3cd59e25efad
fast-uri@3.1.5
3.1.6

Open the chart page →

311
ghostgroundhog2k0.212.121 of 1See more

ghost groundhog2k 0.212.12

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
fast-uri@3.1.2
3.1.6

Open the chart page →

2,000
growthbookgrowthbook5.0.11 of 2See more

growthbook growthbook 5.0.1

1 of the 2 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
growthbook/growthbook:5.0.1f53ead646b5f
fast-uri@3.1.5
3.1.6

Open the chart page →

709
keycloak-reporterkeycloak-reporterVerified publisher1.4.151 of 1See more

keycloak-reporter keycloak-reporter 1.4.15

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
fast-uri@3.1.5
3.1.6

Open the chart page →

1,322
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
fast-uri@3.1.2
3.1.6

Open the chart page →

2,575
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
fast-uri@3.1.4
3.1.6

Open the chart page →

31,844
immichsecustorVerified publisher2.0.41 of 1See more

immich secustor 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
fast-uri@3.1.4
3.1.6

Open the chart page →

3,059
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
fast-uri@3.1.4
3.1.6

Open the chart page →

18,075
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
fast-uri@3.1.2
3.1.6

Open the chart page →

2,522
trifidzazukoOfficialVerified publisher0.2.11 of 1See more

trifid zazuko 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
fast-uri@3.1.2
3.1.6

Open the chart page →

338
turborepo-remote-cacheadriantr1.1.11 of 1See more

turborepo-remote-cache adriantr 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ducktors/turborepo-remote-cache:latest31ec9e83c844
fast-uri@3.1.2
3.1.6

Open the chart page →

523
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
fast-uri@4.1.2
4.1.3

Open the chart page →

951
codehubcodehubVerified publisher6.2.181 of 5See more

codehub codehub 6.2.18

1 of the 5 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
jupyterhub/jupyterhub:5.4.63974ba945e65
node-ajv@8.12.0~ds+~2.1.1-4
no fix listed

Open the chart page →

13,220
decisionrules-aksdecisionrules-aksVerified publisher0.2.01 of 2See more

decisionrules-aks decisionrules-aks 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
fast-uri@3.1.5
3.1.6

Open the chart page →

1,138
decisionrules-eksdecisionrules-eksVerified publisher0.3.01 of 2See more

decisionrules-eks decisionrules-eks 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
fast-uri@3.1.5
3.1.6

Open the chart page →

1,138
decisionrules-ingressdecisionrules-ingressVerified publisher0.2.01 of 2See more

decisionrules-ingress decisionrules-ingress 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
fast-uri@3.1.5
3.1.6

Open the chart page →

1,138
decisionrules-ocpdecisionrules-ocpVerified publisher0.1.01 of 4See more

decisionrules-ocp decisionrules-ocp 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
fast-uri@3.1.5
3.1.6

Open the chart page →

2,685
dial-admindialVerified publisher0.18.01 of 3See more

dial-admin dial 0.18.0

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
epam/ai-dial-admin-frontend:0.20.021d91ad74755
fast-uri@3.1.5
3.1.6

Open the chart page →

4,046
dyff-frontenddyff-frontendVerified publisher0.20.11 of 1See more

dyff-frontend dyff-frontend 0.20.1

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
fast-uri@3.1.2
3.1.6

Open the chart page →

973
node-redegebackVerified publisher2.0.131 of 1See more

node-red egeback 2.0.13

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
nodered/node-red:5.0.410f40d0a83e7
fast-uri@3.1.4
3.1.6

Open the chart page →

975
edp-installepmdedpOfficialVerified publisher3.15.01 of 7See more

edp-install epmdedp 3.15.0

1 of the 7 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
fast-uri@3.1.2
3.1.6

Open the chart page →

2,033
krci-portalepmdedpVerified publisher0.8.01 of 1See more

krci-portal epmdedp 0.8.0

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
epamedp/krci-portal:0.8.0687acf641097
fast-uri@3.1.2
3.1.6

Open the chart page →

839
flanksource-uiflanksourceVerified publisher1.4.3181 of 1See more

flanksource-ui flanksource 1.4.318

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.318891f21df54fb
fast-uri@3.1.3
3.1.6

Open the chart page →

2,558
mission-controlflanksourceVerified publisher0.1.3361 of 8See more

mission-control flanksource 0.1.336

1 of the 8 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
fast-uri@3.1.3
3.1.6

Open the chart page →

8,902
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
fast-uri@3.1.4
3.1.6

Open the chart page →

9,047
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
fast-uri@3.1.2
3.1.6

Open the chart page →

739
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
library/ghost:6.62.0a7a268bbfb7f
fast-uri@3.1.2
3.1.6

Open the chart page →

2,463
hoppscotchhelmforgeVerified publisher1.1.111 of 2See more

hoppscotch helmforge 1.1.11

1 of the 2 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2026.8.0d50725df661f
fast-uri@3.1.5
3.1.6

Open the chart page →

2,046
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
fast-uri@3.1.3
3.1.6

Open the chart page →

11,042
strapihelmforgeVerified publisher2.3.141 of 3See more

strapi helmforge 2.3.14

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
helmforge/strapi-base:5.52.270e9143d6d92
fast-uri@3.1.5
3.1.6

Open the chart page →

2,061
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
kitware/cdash:v5.3.0d7767d9b9da4
fast-uri@3.1.5
3.1.6

Open the chart page →

12,062
portfolio-trackerkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

portfolio-tracker kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
fast-uri@3.1.2
3.1.6

Open the chart page →

1,498

Container images carrying it

65 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
decisionrules/server:latestf38d8571fa06
fast-uri@3.1.5
3.1.6
4
epamedp/krci-portal:0.8.0687acf641097
fast-uri@3.1.2
3.1.6
2
library/ghost:6.63.0e05bc1169fb2
fast-uri@3.1.2
3.1.6
2
n8nio/n8n:2.36.714c4285bc303
fast-uri@3.1.5
3.1.6
2
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
fast-uri@3.1.2
3.1.6
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
fast-uri@3.1.4
3.1.6
2
ghcr.io/unionai-oss/flyteconsole-v2:latestdb4362ec0d3b
fast-uri@3.1.5
3.1.6
2
budibase/apps:3.41.344fe6feab985
fast-uri@3.1.5
3.1.6
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
fast-uri@3.1.5
3.1.6
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
fast-uri@3.1.2
3.1.6
1
directus/directus:12.0.29c8470ea465c
fast-uri@3.1.2
3.1.6
1
drumsergio/lynxprompt:2.0.75c6afb6679301
fast-uri@3.1.2
3.1.6
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
fast-uri@3.1.2
3.1.6
1
epam/ai-dial-admin-frontend:0.20.021d91ad74755
fast-uri@3.1.5
3.1.6
1
epam/ai-dial-chat:0.49.0bd6b13695cdc
fast-uri@3.1.5
3.1.6
1
etherpad/etherpad:latest6020e7b57f4b
fast-uri@3.1.4
3.1.6
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
fast-uri@3.1.3
3.1.6
1
gorules/brms:latest3cd59e25efad
fast-uri@3.1.5
3.1.6
1
growthbook/growthbook:5.0.1f53ead646b5f
fast-uri@3.1.5
3.1.6
1
haohanyang/compass-web:0.5.054f2112602ee
fast-uri@3.1.2
3.1.6
1
helmforge/strapi-base:5.52.270e9143d6d92
fast-uri@3.1.5
3.1.6
1
hoppscotch/hoppscotch:2026.8.0d50725df661f
fast-uri@3.1.5
3.1.6
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-ajv@8.12.0~ds+~2.1.1-4
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
fast-uri@3.1.5
3.1.6
1
library/ghost:6.62.0a7a268bbfb7f
fast-uri@3.1.2
3.1.6
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-ajv@6.10.2-1
no fix listed
1
n8nio/n8n:2.25.7761374d4eb84
fast-uri@3.1.2
3.1.6
1
n8nio/n8n:2.36.8cfe2704ff858
fast-uri@3.1.5
3.1.6
1
nodered/node-red:5.0.410f40d0a83e7
fast-uri@3.1.4
3.1.6
1
nodered/node-red:4.1.10-minimald73ae167cb9b
fast-uri@3.1.2
3.1.6
1
penpotapp/mcp:2.17.284f3f07ead11
fast-uri@3.1.2
3.1.6
1
rocketchat/account-service:8.6.144af8ac4e711
fast-uri@3.1.2
3.1.6
1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
fast-uri@3.1.2
3.1.6
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
fast-uri@3.1.2
3.1.6
1
rocketchat/presence-service:8.6.1c1170bdfe797
fast-uri@3.1.2
3.1.6
1
supabase/storage-api:latestf6c42a04163d
fast-uri@4.1.1
4.1.3
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
fast-uri@3.1.4
3.1.6
1
supabase/studio:latest94a2a9d2906e
fast-uri@3.1.5
3.1.6
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-ajv@6.10.2-1
no fix listed
1
tensorzero/ui:2026.6.0f2563d54724e
fast-uri@3.1.2
3.1.6
1
tenureai/tenure:v1.0.285f5b222df9a5
fast-uri@3.1.2
3.1.6
1
treskon/portrait-ui:DEV-lateste7970783bc8d
fast-uri@3.1.4
3.1.6
1
veecode/devportalc443520aebf7
fast-uri@3.1.2
3.1.6
1
wsjbr/duplistatus:1.4.25e594f5f09f6
fast-uri@3.1.2
3.1.6
1
yooooomi/your_spotify_client:1.20.0e4da90a0634c
fast-uri@3.1.2
3.1.6
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
fast-uri@3.1.2
3.1.6
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
fast-uri@3.1.5
3.1.6
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
fast-uri@4.1.2
4.1.3
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
fast-uri@3.1.2
3.1.6
1
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
fast-uri@3.1.4
3.1.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.