StackRadar

CVE-2026-75899

High

Advisory

Published 24 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
68
of 17,781 indexed, latest versions
Container images
65
deployed by those charts
Fix available
1 of 2
affected packages

fast-uri vulnerable to server-side request forgery via repeated hostname percent-decoding

Carried by container images the latest versions of 68 of 17,781 indexed charts deploy, on 65 images.

Affected packageAffected versionsFixed inImages
fast-urinpm3.1.2, 3.1.3, 3.1.4, 3.1.5+2 more3.1.6, 4.1.362
node-ajvdeb6.10.2-1, 8.12.0~ds+~2.1.1-4no fix listed3
OSV records
GHSA-fph4-wmhf-6fwfUBUNTU-CVE-2026-75899

Charts affected

68 by stars
ChartLatestAffected imagesRadar Score
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
fast-uri@3.1.2
3.1.6

Open the chart page →

1,809
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
fast-uri@3.1.2
3.1.6
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
fast-uri@3.1.2
3.1.6

Open the chart page →

2,774
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-ajv@6.10.2-1
no fix listed

Open the chart page →

17,779
lynxpromptlynxpromptVerified publisher0.1.21 of 3See more

lynxprompt lynxprompt 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
drumsergio/lynxprompt:2.0.75c6afb6679301
fast-uri@3.1.2
3.1.6

Open the chart page →

1,852
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
fast-uri@3.1.2
3.1.6

Open the chart page →

2,396
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
fast-uri@3.1.5
3.1.6

Open the chart page →

1,038
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
fast-uri@3.1.2
3.1.6

Open the chart page →

3,798
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
fast-uri@3.1.5
3.1.6

Open the chart page →

1,038
portalplatform-mesh-portal0.19.41 of 1See more

portal platform-mesh-portal 0.19.4

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/platform-mesh/portal:v0.26.123c937255cac2
fast-uri@3.1.5
3.1.6

Open the chart page →

301
prismeai-coreprismeai1.12.12 of 7See more

prismeai-core prismeai 1.12.1

2 of the 7 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod470da8f8730c
fast-uri@3.1.5
3.1.6
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbce6d452ad08
fast-uri@3.1.5
3.1.6

Open the chart page →

3,270
etherpadredhat-cop0.0.81 of 1See more

etherpad redhat-cop 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
etherpad/etherpad:latest6020e7b57f4b
fast-uri@3.1.4
3.1.6

Open the chart page →

895
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
fast-uri@3.1.4
3.1.6

Open the chart page →

9,047
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
yooooomi/your_spotify_client:1.20.0e4da90a0634c
fast-uri@3.1.2
3.1.6

Open the chart page →

5,066
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-ajv@6.10.2-1
no fix listed

Open the chart page →

10,902
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
fast-uri@3.1.2
3.1.6

Open the chart page →

3,972
supabaseteochenglim0.1.22 of 13See more

supabase teochenglim 0.1.2

2 of the 13 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
fast-uri@4.1.1
4.1.3
supabase/studio:latest94a2a9d2906e
fast-uri@3.1.5
3.1.6

Open the chart page →

9,556
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
fast-uri@3.1.2
3.1.6

Open the chart page →

1,787
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-75899.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
fast-uri@3.1.2
3.1.6

Open the chart page →

280

Container images carrying it

65 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
decisionrules/server:latestf38d8571fa06
fast-uri@3.1.5
3.1.6
4
epamedp/krci-portal:0.8.0687acf641097
fast-uri@3.1.2
3.1.6
2
library/ghost:6.63.0e05bc1169fb2
fast-uri@3.1.2
3.1.6
2
n8nio/n8n:2.36.714c4285bc303
fast-uri@3.1.5
3.1.6
2
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
fast-uri@3.1.2
3.1.6
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
fast-uri@3.1.4
3.1.6
2
ghcr.io/unionai-oss/flyteconsole-v2:latestdb4362ec0d3b
fast-uri@3.1.5
3.1.6
2
budibase/apps:3.41.344fe6feab985
fast-uri@3.1.5
3.1.6
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
fast-uri@3.1.5
3.1.6
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
fast-uri@3.1.2
3.1.6
1
directus/directus:12.0.29c8470ea465c
fast-uri@3.1.2
3.1.6
1
drumsergio/lynxprompt:2.0.75c6afb6679301
fast-uri@3.1.2
3.1.6
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
fast-uri@3.1.2
3.1.6
1
epam/ai-dial-admin-frontend:0.20.021d91ad74755
fast-uri@3.1.5
3.1.6
1
epam/ai-dial-chat:0.49.0bd6b13695cdc
fast-uri@3.1.5
3.1.6
1
etherpad/etherpad:latest6020e7b57f4b
fast-uri@3.1.4
3.1.6
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
fast-uri@3.1.3
3.1.6
1
gorules/brms:latest3cd59e25efad
fast-uri@3.1.5
3.1.6
1
growthbook/growthbook:5.0.1f53ead646b5f
fast-uri@3.1.5
3.1.6
1
haohanyang/compass-web:0.5.054f2112602ee
fast-uri@3.1.2
3.1.6
1
helmforge/strapi-base:5.52.270e9143d6d92
fast-uri@3.1.5
3.1.6
1
hoppscotch/hoppscotch:2026.8.0d50725df661f
fast-uri@3.1.5
3.1.6
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-ajv@8.12.0~ds+~2.1.1-4
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
fast-uri@3.1.5
3.1.6
1
library/ghost:6.62.0a7a268bbfb7f
fast-uri@3.1.2
3.1.6
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-ajv@6.10.2-1
no fix listed
1
n8nio/n8n:2.25.7761374d4eb84
fast-uri@3.1.2
3.1.6
1
n8nio/n8n:2.36.8cfe2704ff858
fast-uri@3.1.5
3.1.6
1
nodered/node-red:5.0.410f40d0a83e7
fast-uri@3.1.4
3.1.6
1
nodered/node-red:4.1.10-minimald73ae167cb9b
fast-uri@3.1.2
3.1.6
1
penpotapp/mcp:2.17.284f3f07ead11
fast-uri@3.1.2
3.1.6
1
rocketchat/account-service:8.6.144af8ac4e711
fast-uri@3.1.2
3.1.6
1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
fast-uri@3.1.2
3.1.6
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
fast-uri@3.1.2
3.1.6
1
rocketchat/presence-service:8.6.1c1170bdfe797
fast-uri@3.1.2
3.1.6
1
supabase/storage-api:latestf6c42a04163d
fast-uri@4.1.1
4.1.3
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
fast-uri@3.1.4
3.1.6
1
supabase/studio:latest94a2a9d2906e
fast-uri@3.1.5
3.1.6
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-ajv@6.10.2-1
no fix listed
1
tensorzero/ui:2026.6.0f2563d54724e
fast-uri@3.1.2
3.1.6
1
tenureai/tenure:v1.0.285f5b222df9a5
fast-uri@3.1.2
3.1.6
1
treskon/portrait-ui:DEV-lateste7970783bc8d
fast-uri@3.1.4
3.1.6
1
veecode/devportalc443520aebf7
fast-uri@3.1.2
3.1.6
1
wsjbr/duplistatus:1.4.25e594f5f09f6
fast-uri@3.1.2
3.1.6
1
yooooomi/your_spotify_client:1.20.0e4da90a0634c
fast-uri@3.1.2
3.1.6
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
fast-uri@3.1.2
3.1.6
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
fast-uri@3.1.5
3.1.6
1
ghcr.io/bryopsida/openmct:main38b6a50a62b2
fast-uri@4.1.2
4.1.3
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
fast-uri@3.1.2
3.1.6
1
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
fast-uri@3.1.4
3.1.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.