StackRadar

CVE-2026-77465

High

Advisory

Published 3 Sept 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
24
of 17,781 indexed, latest versions
Container images
22
deployed by those charts
Fix available
1 of 1
affected package

toml-node: Uncontrolled Recursion

Carried by container images the latest versions of 24 of 17,781 indexed charts deploy, on 22 images.

Affected packageAffected versionsFixed inImages
tomlnpm2.3.6, 3.0.04.2.022
OSV records
GHSA-82x6-q7mm-w9cf

Charts affected

24 by stars
ChartLatestAffected imagesRadar Score
n8ncommunity-chartsVerified publisher1.24.401 of 1See more

n8n community-charts 1.24.40

1 of the 1 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
n8nio/n8n:2.38.45d9f0cc5672b
toml@3.0.0
4.2.0

Open the chart page →

772
n8nopen-8gears2.1.11 of 1See more

n8n open-8gears 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.8cfe2704ff858
toml@3.0.0
4.2.0

Open the chart page →

1,038
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
toml@3.0.0
4.2.0

Open the chart page →

10,775
n8nhelmforgeVerified publisher2.0.01 of 2See more

n8n helmforge 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
n8nio/n8n:2.38.45d9f0cc5672b
toml@3.0.0
4.2.0

Open the chart page →

863
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
toml@3.0.0
4.2.0

Open the chart page →

4,016
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
toml@2.3.6
4.2.0

Open the chart page →

2,519
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
toml@3.0.0
4.2.0

Open the chart page →

7,801
growthbookgrowthbook5.0.11 of 2See more

growthbook growthbook 5.0.1

1 of the 2 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
growthbook/growthbook:5.0.1f53ead646b5f
toml@3.0.0
4.2.0

Open the chart page →

709
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
toml@3.0.0
4.2.0

Open the chart page →

2,575
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad1 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

1 of the 6 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
toml@3.0.0
4.2.0

Open the chart page →

18,293
decisionrules-aksdecisionrules-aksVerified publisher0.2.01 of 2See more

decisionrules-aks decisionrules-aks 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
toml@3.0.0
4.2.0

Open the chart page →

1,138
decisionrules-eksdecisionrules-eksVerified publisher0.3.01 of 2See more

decisionrules-eks decisionrules-eks 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
toml@3.0.0
4.2.0

Open the chart page →

1,138
decisionrules-ingressdecisionrules-ingressVerified publisher0.2.01 of 2See more

decisionrules-ingress decisionrules-ingress 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
toml@3.0.0
4.2.0

Open the chart page →

1,138
decisionrules-ocpdecisionrules-ocpVerified publisher0.1.01 of 4See more

decisionrules-ocp decisionrules-ocp 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
decisionrules/server:latestf38d8571fa06
toml@3.0.0
4.2.0

Open the chart page →

2,685
desishowbiz-frontenddesishowbiz1.0.01 of 1See more

desishowbiz-frontend desishowbiz 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
rahulbhiwagade122/desishowbiz:latest08490b70998c
toml@3.0.0
4.2.0

Open the chart page →

2,529
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
governify/registry:v3.4.0d3f37f4f8168
toml@3.0.0
4.2.0

Open the chart page →

22,512
Governify-Falcongovernify0.1.02 of 10See more

Governify-Falcon governify 0.1.0

2 of the 10 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
governify/collector-dynamic:v1.3.06d3d1a5b46a9
toml@3.0.0
4.2.0
governify/registry:v3.4.0d3f37f4f8168
toml@3.0.0
4.2.0

Open the chart page →

24,319
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
toml@3.0.0
4.2.0

Open the chart page →

3,014
nocodbinseefrlab0.2.01 of 1See more

nocodb inseefrlab 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
nocodb/nocodb:latest4b760f0d2547
toml@3.0.0
4.2.0

Open the chart page →

781
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
toml@3.0.0
4.2.0

Open the chart page →

5,826
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
toml@3.0.0
4.2.0

Open the chart page →

1,038
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
toml@3.0.0
4.2.0

Open the chart page →

1,038
routr-connectroutr0.4.35 of 10See more

routr-connect routr 0.4.3

5 of the 10 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
fonoster/routr-connect:2.13.6e8c84b5eaa67
toml@3.0.0
4.2.0
fonoster/routr-dispatcher:2.13.65f8f380dc174
toml@3.0.0
4.2.0
fonoster/routr-location:2.13.6051ba9c34ef5
toml@3.0.0
4.2.0
fonoster/routr-pgdata:2.13.6e4d5f5ff1945
toml@3.0.0
4.2.0
fonoster/routr-registry:2.13.6e27001f2813c
toml@3.0.0
4.2.0

Open the chart page →

11,021
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-77465.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
toml@3.0.0
4.2.0

Open the chart page →

3,014

Container images carrying it

22 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
decisionrules/server:latestf38d8571fa06
toml@3.0.0
4.2.0
4
governify/registry:v3.4.0d3f37f4f8168
toml@3.0.0
4.2.0
2
infisical/infisical:latest:v0.165.602082bf13163
toml@3.0.0
4.2.0
2
n8nio/n8n:2.36.714c4285bc303
toml@3.0.0
4.2.0
2
n8nio/n8n:2.38.45d9f0cc5672b
toml@3.0.0
4.2.0
2
budibase/apps:3.41.344fe6feab985
toml@3.0.0
4.2.0
1
fonoster/routr-connect:2.13.6e8c84b5eaa67
toml@3.0.0
4.2.0
1
fonoster/routr-dispatcher:2.13.65f8f380dc174
toml@3.0.0
4.2.0
1
fonoster/routr-location:2.13.6051ba9c34ef5
toml@3.0.0
4.2.0
1
fonoster/routr-pgdata:2.13.6e4d5f5ff1945
toml@3.0.0
4.2.0
1
fonoster/routr-registry:2.13.6e27001f2813c
toml@3.0.0
4.2.0
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
toml@3.0.0
4.2.0
1
growthbook/growthbook:5.0.1f53ead646b5f
toml@3.0.0
4.2.0
1
n8nio/n8n:2.25.7761374d4eb84
toml@3.0.0
4.2.0
1
n8nio/n8n:1.86.08b39ed5a2de9
toml@3.0.0
4.2.0
1
n8nio/n8n:2.36.8cfe2704ff858
toml@3.0.0
4.2.0
1
nocodb/nocodb:latest4b760f0d2547
toml@3.0.0
4.2.0
1
nocodb/nocodb:0.301.5d9516f0bf546
toml@3.0.0
4.2.0
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
toml@3.0.0
4.2.0
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
toml@3.0.0
4.2.0
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
toml@3.0.0
4.2.0
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
toml@2.3.6
4.2.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.