StackRadar

CVE-2026-76172

High

Advisory

Published 24 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
137
of 17,781 indexed, latest versions
Container images
136
deployed by those charts
Fix available
1 of 2
affected packages

fast-uri vulnerable to host confusion via percent-encoded scheme normalization

Carried by container images the latest versions of 137 of 17,781 indexed charts deploy, on 136 images.

Affected packageAffected versionsFixed inImages
fast-urinpm2.4.0, 3.0.1, 3.0.2, 3.0.3+8 more2.4.5, 3.1.6, 4.1.3133
node-ajvdeb6.10.2-1, 8.12.0~ds+~2.1.1-4no fix listed3
OSV records
GHSA-jqff-g426-hqxpUBUNTU-CVE-2026-76172

Charts affected

137 by stars
ChartLatestAffected imagesRadar Score
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
fast-uri@3.1.5
3.1.6

Open the chart page →

1,038
rocketchatrocketchat-server7.0.24 of 12See more

rocketchat rocketchat-server 7.0.2

4 of the 12 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
rocketchat/account-service:8.6.144af8ac4e711
fast-uri@3.1.2
3.1.6
rocketchat/authorization-service:8.6.16bc18fb5d0e5
fast-uri@3.1.2
3.1.6
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
fast-uri@3.1.2
3.1.6
rocketchat/presence-service:8.6.1c1170bdfe797
fast-uri@3.1.2
3.1.6

Open the chart page →

12,279
opensearch-dashboardsopensearch-project-helm-chartsVerified publisher3.8.01 of 1See more

opensearch-dashboards opensearch-project-helm-charts 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
fast-uri@3.1.2
3.1.6

Open the chart page →

280
penpotpenpotOfficialVerified publisher1.9.01 of 4See more

penpot penpot 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
penpotapp/mcp:2.17.284f3f07ead11
fast-uri@3.1.2
3.1.6

Open the chart page →

4,314
node-rednode-redVerified publisher0.40.21 of 1See more

node-red node-red 0.40.2

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
nodered/node-red:4.1.2216e7403aab9
fast-uri@3.1.0
3.1.6

Open the chart page →

2,172
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
langgenius/dify-web:1.10.1-fix.1c306ac577912
fast-uri@3.1.0
3.1.6

Open the chart page →

19,391
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
unleashorg/unleash-server:7.5.09adb37e399ba
fast-uri@3.0.1
3.1.6

Open the chart page →

2,059
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
fast-uri@3.0.1
3.1.6

Open the chart page →

7,210
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
fast-uri@2.4.0
2.4.5

Open the chart page →

8,364
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
fast-uri@3.1.2
3.1.6

Open the chart page →

5,660
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
fast-uri@3.1.0
3.1.6

Open the chart page →

3,004
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
fast-uri@3.1.5
3.1.6

Open the chart page →

10,775
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
fast-uri@3.1.0
3.1.6

Open the chart page →

30,326
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
fast-uri@3.0.6
3.1.6

Open the chart page →

5,564
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
fast-uri@3.1.3
3.1.6

Open the chart page →

1,339
dialdialOfficialVerified publisher7.2.01 of 4See more

dial dial 7.2.0

1 of the 4 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
epam/ai-dial-chat:0.49.0bd6b13695cdc
fast-uri@3.1.5
3.1.6

Open the chart page →

2,163
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
fast-uri@3.1.5
3.1.6

Open the chart page →

9,460
umamihelmforgeVerified publisher2.3.31 of 3See more

umami helmforge 2.3.3

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.3.1fa32d116cf20
fast-uri@3.1.5
3.1.6

Open the chart page →

2,027
ghostcloudpirates-ghostVerified publisher0.20.221 of 3See more

ghost cloudpirates-ghost 0.20.22

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
fast-uri@3.1.2
3.1.6

Open the chart page →

7,146
foremancontane-githubOfficialVerified publisher0.6.01 of 1See more

foreman contane-github 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
contane/foreman:0.5.2efb98bdcc4e9
fast-uri@3.0.6
3.1.6

Open the chart page →

1,152
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
fast-uri@3.0.6
3.1.6

Open the chart page →

28,839
duplistatusduplistatusVerified publisher1.2.01 of 2See more

duplistatus duplistatus 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
wsjbr/duplistatus:1.4.25e594f5f09f6
fast-uri@3.1.2
3.1.6

Open the chart page →

1,870
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/unionai-oss/flyteconsole-v2:latestdb4362ec0d3b
fast-uri@3.1.5
3.1.6

Open the chart page →

4,641
flyte-coreflyte2.0.481 of 3See more

flyte-core flyte 2.0.48

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/unionai-oss/flyteconsole-v2:latestdb4362ec0d3b
fast-uri@3.1.5
3.1.6

Open the chart page →

1,178
ghost-on-kubernetesghost-on-kubernetes-helmVerified publisher1.1.21 of 3See more

ghost-on-kubernetes ghost-on-kubernetes-helm 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
fast-uri@3.1.2
3.1.6

Open the chart page →

1,447
coreinstill-aiOfficialVerified publisher0.1.751 of 15See more

core instill-ai 0.1.75

1 of the 15 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
instill/console:0.68.54cd70e2df5c6
fast-uri@3.0.6
3.1.6

Open the chart page →

30,816
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
fast-uri@3.1.2
3.1.6

Open the chart page →

5,218
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
fast-uri@3.0.6
3.1.6

Open the chart page →

8,491
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
fast-uri@3.1.0
3.1.6

Open the chart page →

4,016
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
fast-uri@3.1.0
3.1.6

Open the chart page →

1,991
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/data-fair/notify:3c739b74dabb0
fast-uri@3.0.6
3.1.6

Open the chart page →

38,346
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
fast-uri@3.1.2
3.1.6

Open the chart page →

7,473
jellystatdjjudas21Verified publisher0.1.121 of 1See more

jellystat djjudas21 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
fast-uri@3.1.2
3.1.6

Open the chart page →

1,722
enbuildenbuildVerified publisher0.0.502 of 6See more

enbuild enbuild 0.0.50

2 of the 6 container images this version deploys carry CVE-2026-76172.

Open the chart page →

31,510
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
fast-uri@3.0.1
3.1.6

Open the chart page →

11,458
cap-captcha-serverf3k-techVerified publisher0.21.01 of 1See more

cap-captcha-server f3k-tech 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
tiago2/cap:2.159f5ae4e261e
fast-uri@3.1.0
3.1.6

Open the chart page →

1,664
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
fast-uri@3.1.0
3.1.6

Open the chart page →

3,123
gorules-brmsgorulesVerified publisher1.18.11 of 1See more

gorules-brms gorules 1.18.1

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
gorules/brms:latest3cd59e25efad
fast-uri@3.1.5
3.1.6

Open the chart page →

311
ghostgroundhog2k0.212.121 of 1See more

ghost groundhog2k 0.212.12

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
fast-uri@3.1.2
3.1.6

Open the chart page →

2,000
growthbookgrowthbook5.0.11 of 2See more

growthbook growthbook 5.0.1

1 of the 2 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
growthbook/growthbook:5.0.1f53ead646b5f
fast-uri@3.1.5
3.1.6

Open the chart page →

709
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
fast-uri@3.1.0
3.1.6

Open the chart page →

15,712
keycloak-reporterkeycloak-reporterVerified publisher1.4.151 of 1See more

keycloak-reporter keycloak-reporter 1.4.15

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
fast-uri@3.1.5
3.1.6

Open the chart page →

1,322
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
fast-uri@3.1.2
3.1.6

Open the chart page →

2,575
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
fast-uri@3.1.4
3.1.6

Open the chart page →

31,844
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
fast-uri@3.1.0
3.1.6

Open the chart page →

5,482
immichsecustorVerified publisher2.0.41 of 1See more

immich secustor 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
fast-uri@3.1.4
3.1.6

Open the chart page →

3,059
karakeepself-hosters-by-nightVerified publisher2.5.11 of 1See more

karakeep self-hosters-by-night 2.5.1

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
fast-uri@3.0.6
3.1.6

Open the chart page →

5,213
vuiseriohub1.0.61 of 3See more

vui seriohub 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
dserio83/velero-ui:0.3.1b4e1ec6664d3
fast-uri@3.0.6
3.1.6

Open the chart page →

11,532
supabasesupabse0.8.03 of 11See more

supabase supabse 0.8.0

3 of the 11 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
supabase/postgres-meta:v0.96.6a84cc713585e
fast-uri@3.0.6
3.1.6
supabase/storage-api:v1.60.4c8eb9858eafe
fast-uri@3.1.0
3.1.6
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
fast-uri@3.1.4
3.1.6

Open the chart page →

18,075
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
fast-uri@3.1.2
3.1.6

Open the chart page →

2,522

Container images carrying it

136 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
decisionrules/server:latestf38d8571fa06
fast-uri@3.1.5
3.1.6
4
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
fast-uri@3.1.0
3.1.6
3
epamedp/krci-portal:0.8.0687acf641097
fast-uri@3.1.2
3.1.6
2
library/ghost:6.63.0e05bc1169fb2
fast-uri@3.1.2
3.1.6
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
fast-uri@3.0.6
3.1.6
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
fast-uri@3.0.6
3.1.6
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
fast-uri@3.1.0
3.1.6
2
n8nio/n8n:2.36.714c4285bc303
fast-uri@3.1.5
3.1.6
2
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
fast-uri@3.1.2
3.1.6
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
fast-uri@3.1.4
3.1.6
2
ghcr.io/unionai-oss/flyteconsole-v2:latestdb4362ec0d3b
fast-uri@3.1.5
3.1.6
2
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
fast-uri@3.1.0
3.1.6
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
fast-uri@3.1.0
3.1.6
1
automatischio/automatisch:0.15.03bace7a12d5f
fast-uri@3.0.3
3.1.6
1
budibase/apps:3.41.344fe6feab985
fast-uri@3.1.5
3.1.6
1
chainsafe/lodestar:latest5593f6e97912
fast-uri@3.1.0
3.1.6
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
fast-uri@3.0.1
3.1.6
1
contane/foreman:0.5.2efb98bdcc4e9
fast-uri@3.0.6
3.1.6
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
fast-uri@3.1.5
3.1.6
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
fast-uri@3.0.6
3.1.6
1
cryptexlabs/authf:0.12.11189c07411d7c
fast-uri@3.0.3
3.1.6
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
fast-uri@3.1.2
3.1.6
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
fast-uri@3.0.1
3.1.6
1
directus/directus:12.0.29c8470ea465c
fast-uri@3.1.2
3.1.6
1
docmost/docmost:0.95.041c8d777cf23
fast-uri@3.0.6
3.1.6
1
drumsergio/lynxprompt:2.0.75c6afb6679301
fast-uri@3.1.2
3.1.6
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
fast-uri@3.0.6
3.1.6
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
fast-uri@3.1.2
3.1.6
1
epam/ai-dial-admin-frontend:0.20.021d91ad74755
fast-uri@3.1.5
3.1.6
1
epam/ai-dial-chat:0.49.0bd6b13695cdc
fast-uri@3.1.5
3.1.6
1
etherpad/etherpad:latest6020e7b57f4b
fast-uri@3.1.4
3.1.6
1
etherpad/etherpad:2.7.2b723fe5f2594
fast-uri@3.1.0
3.1.6
1
evoapicloud/evolution-api:latest966625532d90
fast-uri@3.1.0
3.1.6
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
fast-uri@3.1.3
3.1.6
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
fast-uri@3.1.0
3.1.6
1
gorules/brms:latest3cd59e25efad
fast-uri@3.1.5
3.1.6
1
growthbook/growthbook:5.0.1f53ead646b5f
fast-uri@3.1.5
3.1.6
1
haohanyang/compass-web:0.5.054f2112602ee
fast-uri@3.1.2
3.1.6
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
fast-uri@3.0.1
3.1.6
1
helmforge/strapi-base:5.52.270e9143d6d92
fast-uri@3.1.5
3.1.6
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
fast-uri@2.4.0
2.4.5
1
hoppscotch/hoppscotch:2026.8.0d50725df661f
fast-uri@3.1.5
3.1.6
1
instill/console:0.68.54cd70e2df5c6
fast-uri@3.0.6
3.1.6
1
journeyapps/powersync-service:latestbf46f66e5dcc
fast-uri@3.0.6
3.1.6
1
jupyterhub/jupyterhub:5.4.63974ba945e65
node-ajv@8.12.0~ds+~2.1.1-4
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
fast-uri@3.1.5
3.1.6
1
koenkk/zigbee2mqtt:2.7.260a295b40f4e
fast-uri@3.0.6
3.1.6
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
fast-uri@3.1.0
3.1.6
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
fast-uri@3.0.1
3.1.6
1
library/ghost:6.37.01ef2e532ca4d
fast-uri@3.1.0
3.1.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.