StackRadar

CVE-2026-76172

High

Advisory

Published 24 Aug 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.002
14th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
137
of 17,781 indexed, latest versions
Container images
136
deployed by those charts
Fix available
1 of 2
affected packages

fast-uri vulnerable to host confusion via percent-encoded scheme normalization

Carried by container images the latest versions of 137 of 17,781 indexed charts deploy, on 136 images.

Affected packageAffected versionsFixed inImages
fast-urinpm2.4.0, 3.0.1, 3.0.2, 3.0.3+8 more2.4.5, 3.1.6, 4.1.3133
node-ajvdeb6.10.2-1, 8.12.0~ds+~2.1.1-4no fix listed3
OSV records
GHSA-jqff-g426-hqxpUBUNTU-CVE-2026-76172

Charts affected

137 by stars
ChartLatestAffected imagesRadar Score
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
fast-uri@3.1.5
3.1.6

Open the chart page →

1,038
rocketchatrocketchat-server7.0.24 of 12See more

rocketchat rocketchat-server 7.0.2

4 of the 12 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
rocketchat/account-service:8.6.144af8ac4e711
fast-uri@3.1.2
3.1.6
rocketchat/authorization-service:8.6.16bc18fb5d0e5
fast-uri@3.1.2
3.1.6
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
fast-uri@3.1.2
3.1.6
rocketchat/presence-service:8.6.1c1170bdfe797
fast-uri@3.1.2
3.1.6

Open the chart page →

12,279
opensearch-dashboardsopensearch-project-helm-chartsVerified publisher3.8.01 of 1See more

opensearch-dashboards opensearch-project-helm-charts 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
fast-uri@3.1.2
3.1.6

Open the chart page →

280
penpotpenpotOfficialVerified publisher1.9.01 of 4See more

penpot penpot 1.9.0

1 of the 4 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
penpotapp/mcp:2.17.284f3f07ead11
fast-uri@3.1.2
3.1.6

Open the chart page →

4,314
node-rednode-redVerified publisher0.40.21 of 1See more

node-red node-red 0.40.2

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
nodered/node-red:4.1.2216e7403aab9
fast-uri@3.1.0
3.1.6

Open the chart page →

2,172
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
langgenius/dify-web:1.10.1-fix.1c306ac577912
fast-uri@3.1.0
3.1.6

Open the chart page →

19,391
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
unleashorg/unleash-server:7.5.09adb37e399ba
fast-uri@3.0.1
3.1.6

Open the chart page →

2,059
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
fast-uri@3.0.1
3.1.6

Open the chart page →

7,210
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
fast-uri@2.4.0
2.4.5

Open the chart page →

8,364
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
fast-uri@3.1.2
3.1.6

Open the chart page →

5,660
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
fast-uri@3.1.0
3.1.6

Open the chart page →

3,004
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
fast-uri@3.1.5
3.1.6

Open the chart page →

10,775
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
fast-uri@3.1.0
3.1.6

Open the chart page →

30,326
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
fast-uri@3.0.6
3.1.6

Open the chart page →

5,564
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
fast-uri@3.1.3
3.1.6

Open the chart page →

1,339
dialdialOfficialVerified publisher7.2.01 of 4See more

dial dial 7.2.0

1 of the 4 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
epam/ai-dial-chat:0.49.0bd6b13695cdc
fast-uri@3.1.5
3.1.6

Open the chart page →

2,163
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
fast-uri@3.1.5
3.1.6

Open the chart page →

9,460
umamihelmforgeVerified publisher2.3.31 of 3See more

umami helmforge 2.3.3

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.3.1fa32d116cf20
fast-uri@3.1.5
3.1.6

Open the chart page →

2,027
ghostcloudpirates-ghostVerified publisher0.20.221 of 3See more

ghost cloudpirates-ghost 0.20.22

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
fast-uri@3.1.2
3.1.6

Open the chart page →

7,146
foremancontane-githubOfficialVerified publisher0.6.01 of 1See more

foreman contane-github 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
contane/foreman:0.5.2efb98bdcc4e9
fast-uri@3.0.6
3.1.6

Open the chart page →

1,152
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
fast-uri@3.0.6
3.1.6

Open the chart page →

28,839
duplistatusduplistatusVerified publisher1.2.01 of 2See more

duplistatus duplistatus 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
wsjbr/duplistatus:1.4.25e594f5f09f6
fast-uri@3.1.2
3.1.6

Open the chart page →

1,870
flyte-binaryflyte2.0.481 of 4See more

flyte-binary flyte 2.0.48

1 of the 4 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/unionai-oss/flyteconsole-v2:latestdb4362ec0d3b
fast-uri@3.1.5
3.1.6

Open the chart page →

4,641
flyte-coreflyte2.0.481 of 3See more

flyte-core flyte 2.0.48

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/unionai-oss/flyteconsole-v2:latestdb4362ec0d3b
fast-uri@3.1.5
3.1.6

Open the chart page →

1,178
ghost-on-kubernetesghost-on-kubernetes-helmVerified publisher1.1.21 of 3See more

ghost-on-kubernetes ghost-on-kubernetes-helm 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
fast-uri@3.1.2
3.1.6

Open the chart page →

1,447
coreinstill-aiOfficialVerified publisher0.1.751 of 15See more

core instill-ai 0.1.75

1 of the 15 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
instill/console:0.68.54cd70e2df5c6
fast-uri@3.0.6
3.1.6

Open the chart page →

30,816
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
fast-uri@3.1.2
3.1.6

Open the chart page →

5,218
wgerwgerOfficialVerified publisher1.0.01 of 8See more

wger wger 1.0.0

1 of the 8 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
journeyapps/powersync-service:latestbf46f66e5dcc
fast-uri@3.0.6
3.1.6

Open the chart page →

8,491
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
fast-uri@3.1.0
3.1.6

Open the chart page →

4,016
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
fast-uri@3.1.0
3.1.6

Open the chart page →

1,991
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/data-fair/notify:3c739b74dabb0
fast-uri@3.0.6
3.1.6

Open the chart page →

38,346
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
fast-uri@3.1.2
3.1.6

Open the chart page →

7,473
jellystatdjjudas21Verified publisher0.1.121 of 1See more

jellystat djjudas21 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
fast-uri@3.1.2
3.1.6

Open the chart page →

1,722
enbuildenbuildVerified publisher0.0.502 of 6See more

enbuild enbuild 0.0.50

2 of the 6 container images this version deploys carry CVE-2026-76172.

Open the chart page →

31,510
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
fast-uri@3.0.1
3.1.6

Open the chart page →

11,458
cap-captcha-serverf3k-techVerified publisher0.21.01 of 1See more

cap-captcha-server f3k-tech 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
tiago2/cap:2.159f5ae4e261e
fast-uri@3.1.0
3.1.6

Open the chart page →

1,664
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
fast-uri@3.1.0
3.1.6

Open the chart page →

3,123
gorules-brmsgorulesVerified publisher1.18.11 of 1See more

gorules-brms gorules 1.18.1

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
gorules/brms:latest3cd59e25efad
fast-uri@3.1.5
3.1.6

Open the chart page →

311
ghostgroundhog2k0.212.121 of 1See more

ghost groundhog2k 0.212.12

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
fast-uri@3.1.2
3.1.6

Open the chart page →

2,000
growthbookgrowthbook5.0.11 of 2See more

growthbook growthbook 5.0.1

1 of the 2 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
growthbook/growthbook:5.0.1f53ead646b5f
fast-uri@3.1.5
3.1.6

Open the chart page →

709
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
fast-uri@3.1.0
3.1.6

Open the chart page →

15,712
keycloak-reporterkeycloak-reporterVerified publisher1.4.151 of 1See more

keycloak-reporter keycloak-reporter 1.4.15

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
fast-uri@3.1.5
3.1.6

Open the chart page →

1,322
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
fast-uri@3.1.2
3.1.6

Open the chart page →

2,575
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
fast-uri@3.1.4
3.1.6

Open the chart page →

31,844
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
fast-uri@3.1.0
3.1.6

Open the chart page →

5,482
immichsecustorVerified publisher2.0.41 of 1See more

immich secustor 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
fast-uri@3.1.4
3.1.6

Open the chart page →

3,059
karakeepself-hosters-by-nightVerified publisher2.5.11 of 1See more

karakeep self-hosters-by-night 2.5.1

1 of the 1 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
fast-uri@3.0.6
3.1.6

Open the chart page →

5,213
vuiseriohub1.0.61 of 3See more

vui seriohub 1.0.6

1 of the 3 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
dserio83/velero-ui:0.3.1b4e1ec6664d3
fast-uri@3.0.6
3.1.6

Open the chart page →

11,532
supabasesupabse0.8.03 of 11See more

supabase supabse 0.8.0

3 of the 11 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
supabase/postgres-meta:v0.96.6a84cc713585e
fast-uri@3.0.6
3.1.6
supabase/storage-api:v1.60.4c8eb9858eafe
fast-uri@3.1.0
3.1.6
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
fast-uri@3.1.4
3.1.6

Open the chart page →

18,075
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-76172.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
fast-uri@3.1.2
3.1.6

Open the chart page →

2,522

Container images carrying it

136 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
fast-uri@3.0.1
3.1.6
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
fast-uri@3.0.6
3.1.6
1
ghcr.io/colanode/server:latest7006cac874fd
fast-uri@3.1.0
3.1.6
1
ghcr.io/data-fair/notify:3c739b74dabb0
fast-uri@3.0.6
3.1.6
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
fast-uri@3.1.2
3.1.6
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
fast-uri@3.1.0
3.1.6
1
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
fast-uri@3.1.4
3.1.6
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
fast-uri@3.1.3
3.1.6
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
fast-uri@3.1.0
3.1.6
1
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
fast-uri@3.0.6
3.1.6
1
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
fast-uri@3.1.2
3.1.6
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
fast-uri@3.0.6
3.1.6
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
fast-uri@3.0.6
3.1.6
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
fast-uri@3.1.2
3.1.6
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
fast-uri@3.1.2
3.1.6
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
fast-uri@3.1.2
3.1.6
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
fast-uri@3.1.2
3.1.6
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
fast-uri@3.0.1
3.1.6
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
fast-uri@3.0.1
3.1.6
1
ghcr.io/platform-mesh/portal:v0.26.123c937255cac2
fast-uri@3.1.5
3.1.6
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
fast-uri@3.1.0
3.1.6
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
fast-uri@3.0.1
3.1.6
1
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
fast-uri@3.1.2
3.1.6
1
ghcr.io/umami-software/umami:3.3.1fa32d116cf20
fast-uri@3.1.5
3.1.6
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
fast-uri@3.1.0
3.1.6
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
fast-uri@3.0.6
3.1.6
1
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
fast-uri@3.1.2
3.1.6
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
fast-uri@3.0.5
3.1.6
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
fast-uri@3.1.3
3.1.6
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
fast-uri@3.1.3
3.1.6
1
quay.io/wraft/wraft-frontend:latestf1bbbd5e9bb9
fast-uri@3.1.0
3.1.6
1
registry.gitlab.com/dyff/dyff-frontend:0.20.152549f52ae53
fast-uri@3.1.2
3.1.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
fast-uri@3.1.0
3.1.6
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
fast-uri@3.1.0
3.1.6
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod470da8f8730c
fast-uri@3.1.5
3.1.6
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbce6d452ad08
fast-uri@3.1.5
3.1.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.