StackRadar

CVE-2026-77301

High

Advisory

Published 18 Sept 2026In the index since 19 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
61
of 17,813 indexed, latest versions
Container images
53
deployed by those charts
Fix available
1 of 1
affected package

adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS)

Carried by container images the latest versions of 61 of 17,813 indexed charts deploy, on 53 images.

Affected packageAffected versionsFixed inImages
adm-zipnpm0.4.11, 0.4.13, 0.4.16, 0.5.3+9 more0.6.153
OSV records
GHSA-7q85-xj36-vmfc

Charts affected

61 by stars
ChartLatestAffected imagesRadar Score
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-77301.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
adm-zip@0.5.9
0.6.1

Open the chart page →

4,054
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-77301.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
adm-zip@0.5.10
0.6.1

Open the chart page →

39,786
redis-vector-dbtest-opea1.0.01 of 1See more

redis-vector-db test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-77301.

Container imageDigestPackageFixed in
redis/redis-stack:7.2.0-v91c5f43fddcdd
adm-zip@0.5.10
0.6.1

Open the chart page →

5,718
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-77301.

Container imageDigestPackageFixed in
samajh/alprbackend:latestea742b4372ad
adm-zip@0.5.9
0.6.1

Open the chart page →

20,477
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-77301.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
adm-zip@0.5.10
0.6.1

Open the chart page →

4,686
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-77301.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
adm-zip@0.5.17
0.6.1

Open the chart page →

5,687
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-77301.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
adm-zip@0.5.15
0.6.1

Open the chart page →

2,805
tdarrvhdirkVerified publisher5.0.51 of 2See more

tdarr vhdirk 5.0.5

1 of the 2 container images this version deploys carry CVE-2026-77301.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
adm-zip@0.5.10
0.6.1

Open the chart page →

159,238
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-77301.

Container imageDigestPackageFixed in
ghcr.io/colanode/server:latest7006cac874fd
adm-zip@0.5.17
0.6.1

Open the chart page →

2,255
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-77301.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
adm-zip@0.5.10
0.6.1

Open the chart page →

6,507
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-77301.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
adm-zip@0.5.9
0.6.1

Open the chart page →

6,375

Container images carrying it

53 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
redis/redisinsight:3.8:latestb5e19ee240ab
adm-zip@0.5.10
0.6.1
4
ethersphere/bee-localchain:latest0558799ca992
adm-zip@0.4.16
0.6.1
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
adm-zip@0.4.16
0.6.1
2
infisical/infisical:latest:v0.165.602082bf13163
adm-zip@0.5.12
0.6.1
2
n8nio/n8n:2.36.714c4285bc303
adm-zip@0.6.0
0.6.1
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
adm-zip@0.5.10
0.6.1
2
ghcr.io/libredb/libredb-studio:0.16.11d0aa4f090ac
adm-zip@0.6.0
0.6.1
2
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
adm-zip@0.5.16
0.6.1
1
assistiot/fl_orchestrator:api-latest7473d77448e1
adm-zip@0.5.12
0.6.1
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
adm-zip@0.5.12
0.6.1
1
decayofmind/hubot:3.3.21e18e92fe694
adm-zip@0.4.13
0.6.1
1
diygod/rsshub:latest22845ada2f14
adm-zip@0.6.0
0.6.1
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
adm-zip@0.4.16
0.6.1
1
etherpad/etherpad:latest6020e7b57f4b
adm-zip@0.5.18
0.6.1
1
etherpad/etherpad:2.7.2b723fe5f2594
adm-zip@0.5.17
0.6.1
1
ethersphere/bzz-token-service:latest7624f11a72ad
adm-zip@0.4.16
0.6.1
1
gristlabs/grist:0.7.96e71b1914a7e
adm-zip@0.5.3
0.6.1
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
adm-zip@0.5.10
0.6.1
1
heywood8/redisinsight:2.28.00bc9ab313d37
adm-zip@0.5.10
0.6.1
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
adm-zip@0.4.16
0.6.1
1
joplin/server:latest3f7b852959aa
adm-zip@0.5.17
0.6.1
1
kyso/kyso-front:lateste52595c5c16f
adm-zip@0.5.10
0.6.1
1
library/ghost:4.37.0767230c0f263
adm-zip@0.5.5
0.6.1
1
library/kibana:8.18.004c0fc150f3a
adm-zip@0.5.9
0.6.1
1
makeplane/silo-commercial:v3.2.261bd29053757
adm-zip@0.6.0
0.6.1
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
adm-zip@0.5.10
0.6.1
1
minddocdev/hubot:0.1.96c60b11a4fa7
adm-zip@0.4.11
0.6.1
1
n8nio/n8n:2.25.7761374d4eb84
adm-zip@0.5.16
0.6.1
1
n8nio/n8n:1.86.08b39ed5a2de9
adm-zip@0.5.16
0.6.1
1
n8nio/n8n:2.39.8b73045abaddb
adm-zip@0.6.0
0.6.1
1
n8nio/n8n:2.39.5cfa04788a34a
adm-zip@0.6.0
0.6.1
1
n8nio/n8n:2.36.8cfe2704ff858
adm-zip@0.6.0
0.6.1
1
n8nio/n8n:1.33.1dd171d45102a
adm-zip@0.5.12
0.6.1
1
n8nio/n8n:1.115.1ed16e560c40e
adm-zip@0.5.10
0.6.1
1
polonel/trudesk:1.2.60cf6513f6fe3
adm-zip@0.5.9
0.6.1
1
redis/redisinsight:2.68019fcf774631
adm-zip@0.5.10
0.6.1
1
redis/redisinsight:3.2.055542a762210
adm-zip@0.5.10
0.6.1
1
redis/redisinsight:2.46699d341bd329
adm-zip@0.5.10
0.6.1
1
redis/redisinsight:3.485562d67a912
adm-zip@0.5.10
0.6.1
1
rocketadmin/rocketadmin:1.17.710955ef540b9
adm-zip@0.5.17
0.6.1
1
samajh/alprbackend:latestea742b4372ad
adm-zip@0.5.9
0.6.1
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
adm-zip@0.5.10
0.6.1
1
snyk/kubernetes-monitor:2.23.26fb5ad76ce84e
adm-zip@0.5.18
0.6.1
1
sqlpad/sqlpad:6.7d3d2f430dffd
adm-zip@0.5.5
0.6.1
1
treskon/portrait-ui:DEV-lateste7970783bc8d
adm-zip@0.5.10
0.6.1
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
adm-zip@0.5.15
0.6.1
1
ghcr.io/ajnart/homarr:lateste103abadfb52
adm-zip@0.5.15
0.6.1
1
ghcr.io/colanode/server:latest7006cac874fd
adm-zip@0.5.17
0.6.1
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
adm-zip@0.5.16
0.6.1
1
ghcr.io/mkutlak/alluredeck-api:0.41.0fa429df90c68
adm-zip@0.5.18
0.6.1
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.