StackRadar

CVE-2026-81176

Medium

Advisory

Published 17 Sept 2026In the index since 18 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
26
of 17,926 indexed, latest versions
Container images
30
deployed by those charts
Fix available
1 of 1
affected package

Svelte devalue: DoS via malformed input

Carried by container images the latest versions of 26 of 17,926 indexed charts deploy, on 30 images.

Affected packageAffected versionsFixed inImages
devaluenpm2.0.1, 4.3.2, 4.3.3, 5.0.0+6 more5.9.230
OSV records
GHSA-9rgm-9g3h-6x36

Charts affected

26 by stars
ChartLatestAffected imagesRadar Score
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
openmined/syft-frontend:0.9.5d11524a3854a
devalue@4.3.2
5.9.2

Open the chart page →

17,909
baserowbaserow-chartVerified publisher1.0.561 of 6See more

baserow baserow-chart 1.0.56

1 of the 6 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
baserow/web-frontend:2.3.3566d24c7d9f5
devalue@5.8.1
5.9.2

Open the chart page →

18,376
wg-easywg-easyVerified publisher0.1.61 of 1See more

wg-easy wg-easy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:150e7bc9d34e86
devalue@5.9.0
5.9.2

Open the chart page →

752
convertigoconvertigoOfficialVerified publisher8.4.41 of 5See more

convertigo convertigo 8.4.4

1 of the 5 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
devalue@2.0.1
5.9.2

Open the chart page →

15,658
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
devalue@2.0.1
5.9.2

Open the chart page →

7,750
data-fairdata354-helmVerified publisher1.1.26 of 12See more

data-fair data354-helm 1.1.2

6 of the 12 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
ghcr.io/data-fair/data-fair:3cc9498b64b5b
devalue@2.0.1
5.9.2
ghcr.io/data-fair/metrics:0a8d40779eeae
devalue@2.0.1
5.9.2
ghcr.io/data-fair/notify:3c739b74dabb0
devalue@2.0.1
5.9.2
ghcr.io/data-fair/portals:18b621866ceb2
devalue@2.0.1
5.9.2
ghcr.io/data-fair/processings:15a9216989707
devalue@2.0.1
5.9.2
ghcr.io/data-fair/simple-directory:438a4f32fad82
devalue@2.0.1
5.9.2

Open the chart page →

39,605
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
litlyx/litlyx-dashboard:lateste64ff2d52385
devalue@5.5.0
5.9.2

Open the chart page →

8,258
wg-easyslybase-wg-easyVerified publisher1.2.01 of 1See more

wg-easy slybase-wg-easy 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:15.4.00e7bc9d34e86
devalue@5.9.0
5.9.2

Open the chart page →

752
platform-uiappscodeVerified publisher2026.9.111 of 1See more

platform-ui appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
ghcr.io/appscode/platform-ui:2.5.0c27cafe398c2
devalue@5.7.1
5.9.2

Open the chart page →

592
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
devalue@4.3.2
5.9.2

Open the chart page →

33,827
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latest7e2ef5261764
devalue@5.8.2
5.9.2

Open the chart page →

6,910
logtidelogtideVerified publisher2.1.142 of 4See more

logtide logtide 2.1.14

2 of the 4 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
devalue@5.8.1
5.9.2
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
devalue@5.8.1
5.9.2

Open the chart page →

2,942
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
devalue@5.6.4
5.9.2

Open the chart page →

3,955
elkrivals-spaceVerified publisher0.1.11 of 1See more

elk rivals-space 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:main046dfdb8550c
devalue@5.6.4
5.9.2

Open the chart page →

312
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latest7e2ef5261764
devalue@5.8.2
5.9.2

Open the chart page →

6,910
s3-browsers3-browser0.4.11 of 1See more

s3-browser s3-browser 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
devalue@5.6.4
5.9.2

Open the chart page →

617
elk-frontendschoenwald0.2.221 of 1See more

elk-frontend schoenwald 0.2.22

1 of the 1 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
devalue@5.6.4
5.9.2

Open the chart page →

430
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
devalue@2.0.1
5.9.2

Open the chart page →

3,868
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
devalue@5.0.0
5.9.2

Open the chart page →

17,233
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
devalue@5.0.0
5.9.2

Open the chart page →

17,282
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
devalue@5.0.0
5.9.2

Open the chart page →

17,282
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
devalue@5.0.0
5.9.2

Open the chart page →

16,884
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
devalue@5.0.0
5.9.2

Open the chart page →

16,497
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
devalue@4.3.3
5.9.2

Open the chart page →

30,401
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
devalue@5.0.0
5.9.2

Open the chart page →

29,962
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-81176.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
devalue@5.0.0
5.9.2

Open the chart page →

30,443

Container images carrying it

30 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/lissy93/web-check:latest7e2ef5261764
devalue@5.8.2
5.9.2
2
ghcr.io/wg-easy/wg-easy:15:15.4.00e7bc9d34e86
devalue@5.9.0
5.9.2
2
baserow/baserow:1.30.1df0c42eb67e8
devalue@2.0.1
5.9.2
1
baserow/web-frontend:2.3.3566d24c7d9f5
devalue@5.8.1
5.9.2
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
devalue@2.0.1
5.9.2
1
litlyx/litlyx-dashboard:lateste64ff2d52385
devalue@5.5.0
5.9.2
1
ondrejsika/parking:latestb1fd497416c8
devalue@2.0.1
5.9.2
1
opea/codegen-ui:1.02bee4eb66f3e
devalue@4.3.3
5.9.2
1
opea/codetrans-ui:1.03ef121f34610
devalue@5.0.0
5.9.2
1
opea/docsum-ui:1.07f854e9bffaf
devalue@5.0.0
5.9.2
1
openmined/syft-frontend:0.9.5d11524a3854a
devalue@4.3.2
5.9.2
1
speckle/speckle-frontend-2:2.20.2-branch.testing4.134160-9fad4b210ad4ade8bf2
devalue@5.0.0
5.9.2
1
speckle/speckle-frontend-2:2.20.6-branch.testing1.154030-9b0911432fc940d9b4c
devalue@5.0.0
5.9.2
1
speckle/speckle-frontend-2:2.19.2-branch.hotfix-2.19.1.124125-665e7e14f9241665ae3
devalue@5.0.0
5.9.2
1
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
devalue@5.0.0
5.9.2
1
speckle/speckle-frontend-2:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbfdc008effc7a
devalue@5.0.0
5.9.2
1
ghcr.io/appscode/platform-ui:2.5.0c27cafe398c2
devalue@5.7.1
5.9.2
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
devalue@5.6.4
5.9.2
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
devalue@4.3.2
5.9.2
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
devalue@2.0.1
5.9.2
1
ghcr.io/data-fair/metrics:0a8d40779eeae
devalue@2.0.1
5.9.2
1
ghcr.io/data-fair/notify:3c739b74dabb0
devalue@2.0.1
5.9.2
1
ghcr.io/data-fair/portals:18b621866ceb2
devalue@2.0.1
5.9.2
1
ghcr.io/data-fair/processings:15a9216989707
devalue@2.0.1
5.9.2
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
devalue@2.0.1
5.9.2
1
ghcr.io/elk-zone/elk:main046dfdb8550c
devalue@5.6.4
5.9.2
1
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
devalue@5.6.4
5.9.2
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
devalue@5.8.1
5.9.2
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
devalue@5.8.1
5.9.2
1
registry.gitlab.com/evolves-fr/s3-browser:0.4.1c350c941fe7b
devalue@5.6.4
5.9.2
1

syft 1.42.1 · advisories as of 28 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.