StackRadar

CVE-2026-75975

High

Advisory

Published 24 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
137
of 17,781 indexed, latest versions
Container images
136
deployed by those charts
Fix available
1 of 2
affected packages

fast-uri vulnerable to server-side request forgery via malformed IPv6 normalization

Carried by container images the latest versions of 137 of 17,781 indexed charts deploy, on 136 images.

Affected packageAffected versionsFixed inImages
fast-urinpm2.4.0, 3.0.1, 3.0.2, 3.0.3+8 more2.4.5, 3.1.6, 4.1.3133
node-ajvdeb6.10.2-1, 8.12.0~ds+~2.1.1-4no fix listed3
OSV records
GHSA-f65p-4m7j-42xcUBUNTU-CVE-2026-75975

Charts affected

137 by stars
ChartLatestAffected imagesRadar Score
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
fast-uri@3.1.0
3.1.6

Open the chart page →

2,457
finance-portalmojaloop5.1.42 of 11See more

finance-portal mojaloop 5.1.4

2 of the 11 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
fast-uri@3.0.6
3.1.6
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
fast-uri@3.0.6
3.1.6

Open the chart page →

14,809
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
fast-uri@3.0.6
3.1.6

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
fast-uri@3.0.6
3.1.6

Open the chart page →

2,318
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
fast-uri@3.1.0
3.1.6

Open the chart page →

2,457
mongo-compassmongo-compass-web-helm1.1.01 of 1See more

mongo-compass mongo-compass-web-helm 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
haohanyang/compass-web:0.5.054f2112602ee
fast-uri@3.1.2
3.1.6

Open the chart page →

2,396
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
fast-uri@3.0.1
3.1.6

Open the chart page →

17,929
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
fast-uri@3.1.5
3.1.6

Open the chart page →

1,038
ixyneoskop2.1.11 of 1See more

ixy neoskop 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
neoskop/ixy:2.1.125152b474f54
fast-uri@3.1.0
3.1.6

Open the chart page →

1,166
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
fast-uri@3.1.2
3.1.6

Open the chart page →

3,798
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
fast-uri@3.0.3
3.1.6

Open the chart page →

4,219
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
fast-uri@3.1.5
3.1.6

Open the chart page →

1,038
portalplatform-mesh-portal0.19.41 of 1See more

portal platform-mesh-portal 0.19.4

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
ghcr.io/platform-mesh/portal:v0.26.123c937255cac2
fast-uri@3.1.5
3.1.6

Open the chart page →

301
prismeai-coreprismeai1.12.12 of 7See more

prismeai-core prismeai 1.12.1

2 of the 7 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod470da8f8730c
fast-uri@3.1.5
3.1.6
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbce6d452ad08
fast-uri@3.1.5
3.1.6

Open the chart page →

3,270
etherpadredhat-cop0.0.81 of 1See more

etherpad redhat-cop 0.0.8

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
etherpad/etherpad:latest6020e7b57f4b
fast-uri@3.1.4
3.1.6

Open the chart page →

895
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
fast-uri@3.1.0
3.1.6

Open the chart page →

4,600
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
fast-uri@3.1.4
3.1.6

Open the chart page →

9,047
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
fast-uri@3.0.6
3.1.6

Open the chart page →

5,338
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
yooooomi/your_spotify_client:1.20.0e4da90a0634c
fast-uri@3.1.2
3.1.6

Open the chart page →

5,066
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
fast-uri@3.1.0
3.1.6

Open the chart page →

5,819
etherpadschoenwald0.3.01 of 1See more

etherpad schoenwald 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
etherpad/etherpad:2.7.2b723fe5f2594
fast-uri@3.1.0
3.1.6

Open the chart page →

2,133
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
fast-uri@3.0.1
3.1.6

Open the chart page →

5,497
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
fast-uri@3.1.0
3.1.6

Open the chart page →

1,991
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
fast-uri@3.0.5
3.1.6

Open the chart page →

1,313
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
fast-uri@3.0.1
3.1.6

Open the chart page →

4,052
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-ajv@6.10.2-1
no fix listed

Open the chart page →

10,902
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
fast-uri@3.1.2
3.1.6

Open the chart page →

3,972
supabaseteochenglim0.1.22 of 13See more

supabase teochenglim 0.1.2

2 of the 13 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
supabase/storage-api:latestf6c42a04163d
fast-uri@4.1.1
4.1.3
supabase/studio:latest94a2a9d2906e
fast-uri@3.1.5
3.1.6

Open the chart page →

9,556
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
fast-uri@3.0.1
3.1.6

Open the chart page →

2,408
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
fast-uri@3.1.0
3.1.6

Open the chart page →

2,028
unleash-proxyunleash0.8.121 of 1See more

unleash-proxy unleash 0.8.12

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
unleashorg/unleash-proxy:v1.4.82538f89e2685
fast-uri@3.0.2
3.1.6

Open the chart page →

929
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
fast-uri@3.1.0
3.1.6

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
fast-uri@3.1.2
3.1.6

Open the chart page →

1,787
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
fast-uri@3.1.0
3.1.6

Open the chart page →

2,076
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
fast-uri@3.0.6
3.1.6

Open the chart page →

5,984
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
fast-uri@3.1.2
3.1.6

Open the chart page →

280
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-75975.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
fast-uri@3.0.3
3.1.6

Open the chart page →

6,285

Container images carrying it

136 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
fast-uri@3.0.1
3.1.6
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
fast-uri@3.0.6
3.1.6
1
ghcr.io/colanode/server:latest7006cac874fd
fast-uri@3.1.0
3.1.6
1
ghcr.io/data-fair/notify:3c739b74dabb0
fast-uri@3.0.6
3.1.6
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
fast-uri@3.1.2
3.1.6
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
fast-uri@3.1.0
3.1.6
1
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
fast-uri@3.1.4
3.1.6
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
fast-uri@3.1.3
3.1.6
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
fast-uri@3.1.0
3.1.6
1
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
fast-uri@3.0.6
3.1.6
1
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
fast-uri@3.1.2
3.1.6
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
fast-uri@3.0.6
3.1.6
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
fast-uri@3.0.6
3.1.6
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
fast-uri@3.1.2
3.1.6
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
fast-uri@3.1.2
3.1.6
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
fast-uri@3.1.2
3.1.6
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
fast-uri@3.1.2
3.1.6
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
fast-uri@3.0.1
3.1.6
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
fast-uri@3.0.1
3.1.6
1
ghcr.io/platform-mesh/portal:v0.26.123c937255cac2
fast-uri@3.1.5
3.1.6
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
fast-uri@3.1.0
3.1.6
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
fast-uri@3.0.1
3.1.6
1
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
fast-uri@3.1.2
3.1.6
1
ghcr.io/umami-software/umami:3.3.1fa32d116cf20
fast-uri@3.1.5
3.1.6
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
fast-uri@3.1.0
3.1.6
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
fast-uri@3.0.6
3.1.6
1
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
fast-uri@3.1.2
3.1.6
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
fast-uri@3.0.5
3.1.6
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
fast-uri@3.1.3
3.1.6
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
fast-uri@3.1.3
3.1.6
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
fast-uri@3.1.0
3.1.6
1
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
fast-uri@3.1.2
3.1.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
fast-uri@3.1.0
3.1.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
fast-uri@3.1.0
3.1.6
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod470da8f8730c
fast-uri@3.1.5
3.1.6
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbce6d452ad08
fast-uri@3.1.5
3.1.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.