CVE-2026-77301
HighAdvisory
Published 18 Sept 2026In the index since 19 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.004
- 35th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 61
- of 17,813 indexed, latest versions
- Container images
- 53
- deployed by those charts
- Fix available
- 1 of 1
- affected package
adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)
Carried by container images the latest versions of 61 of 17,813 indexed charts deploy, on 53 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| adm-zipnpm | 0.4.11, 0.4.13, 0.4.16, 0.5.3+9 more | 0.6.1 | 53 |
- OSV records
- GHSA-7q85-xj36-vmfc
Charts affected
61 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| trudesktechpreta | 1.0.0 | 1 of 3See more | 4,054 |
| chatqnatest-opea | 1.0.0 | 1 of 11See more | 39,786 |
| redis-vector-dbtest-opea | 1.0.0 | 1 of 1See more | 5,718 |
| vehicle-dashboardtest-vehi-dash | 0.1.0 | 1 of 7See more | 20,477 |
| thanhvt27-lab-k8sthanh-vtVerified publisher | 0.1.4 | 1 of 5See more | 4,686 |
| joplintobiassackmann | 0.1.7 | 1 of 2See more | 5,687 |
| homarrvhdirkVerified publisher | 0.1.5 | 1 of 1See more | 2,805 |
| tdarrvhdirkVerified publisher | 5.0.5 | 1 of 2See more | 159,238 |
| colanodevictorlane | 0.3.3 | 1 of 3See more | 2,255 |
| n8nvictorlane | 1.0.18 | 1 of 1See more | 6,507 |
| kibanawiremindVerified publisher | 8.5.23 | 1 of 2See more | 6,375 |
Container images carrying it
53 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| ghcr.io/ | 26bbd45110d5 | adm-zip | 0.6.1 | 1 |
| registry.gitlab.com/ | c7afac3446d6 | adm-zip | 0.6.1 | 1 |
| registry.gitlab.com/ | 0e3cd8c7776d | adm-zip | 0.6.1 | 1 |