StackRadar

CVE-2026-8161

High

Advisory

Published 18 May 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
17
deployed by those charts
Fix available
1 of 1
affected package

multiparty: Denial of Service via Prototype Pollution leads to Uncaught Exception

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 17 images.

Affected packageAffected versionsFixed inImages
multipartynpm2.1.8, 2.2.0, 3.2.10, 3.3.2+4 more4.3.017
OSV records
GHSA-qxch-whhj-8956

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
hubotdecayofmind1.0.21 of 3See more

hubot decayofmind 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
decayofmind/hubot:3.3.21e18e92fe694
multiparty@4.2.1
4.3.0

Open the chart page →

2,513
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
multiparty@3.2.10
4.3.0

Open the chart page →

5,209
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
multiparty@4.2.3
4.3.0

Open the chart page →

3,925
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
multiparty@4.2.3
4.3.0

Open the chart page →

7,035
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
multiparty@3.2.10
4.3.0

Open the chart page →

18,277
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
multiparty@3.3.2
4.3.0

Open the chart page →

4,069
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
multiparty@4.2.1
4.3.0

Open the chart page →

2,580
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
multiparty@3.2.10
4.3.0

Open the chart page →

5,209
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
multiparty@3.3.2
4.3.0

Open the chart page →

5,941
hubothalkeye0.0.11 of 1See more

hubot halkeye 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
halkeye/hubot:latest9764d2202130
multiparty@4.2.1
4.3.0

Open the chart page →

2,116
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
multiparty@4.2.3
4.3.0

Open the chart page →

3,154
finance-portalmojaloop5.1.41 of 11See more

finance-portal mojaloop 5.1.4

1 of the 11 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
multiparty@2.1.8
4.3.0

Open the chart page →

14,809
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
multiparty@2.1.8
4.3.0

Open the chart page →

1,948
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
multiparty@2.2.0
4.3.0

Open the chart page →

27,465
ferdi-serverobeoneVerified publisher1.0.31 of 2See more

ferdi-server obeone 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
getferdi/ferdi-server:1.3.26e620b85afaa
multiparty@4.2.1
4.3.0

Open the chart page →

1,866
gristrlex0.1.01 of 1See more

grist rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
gristlabs/grist:0.7.96e71b1914a7e
multiparty@4.2.2
4.3.0

Open the chart page →

5,215
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
multiparty@4.2.3
4.3.0

Open the chart page →

7,413
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
multiparty@3.3.2
4.3.0

Open the chart page →

3,638
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
multiparty@4.1.3
4.3.0

Open the chart page →

3,576
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-8161.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
multiparty@4.2.3
4.3.0

Open the chart page →

5,535

Container images carrying it

17 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
pantsel/konga:latestc8172b75607d
multiparty@3.2.10
4.3.0
3
mojaloop/reporting:v12.1.0d480a62103d6
multiparty@2.1.8
4.3.0
2
catalysm/csmm:latestf003b35f54d9
multiparty@4.1.3
4.3.0
1
chocobozzz/peertube:v8.1.5052712130691
multiparty@4.2.3
4.3.0
1
decayofmind/hubot:3.3.21e18e92fe694
multiparty@4.2.1
4.3.0
1
getferdi/ferdi-server:1.3.26e620b85afaa
multiparty@4.2.1
4.3.0
1
gristlabs/grist:0.7.96e71b1914a7e
multiparty@4.2.2
4.3.0
1
halkeye/hubot:latest9764d2202130
multiparty@4.2.1
4.3.0
1
joplin/server:latest3f7b852959aa
multiparty@4.2.3
4.3.0
1
joplin/server:3.0-beta52af57880c0e
multiparty@4.2.3
4.3.0
1
joplin/server:2.14.2-betab87564ef34e9
multiparty@4.2.3
4.3.0
1
konradkleine/docker-registry-frontend:v2181aad54ee64
multiparty@3.3.2
4.3.0
1
linuxserver/cloud9:latest45c5fe102ff3
multiparty@2.2.0
4.3.0
1
minddocdev/hubot:0.1.96c60b11a4fa7
multiparty@4.2.1
4.3.0
1
wekanteam/wekan:v4.2268a51f0327df
multiparty@3.3.2
4.3.0
1
quay.io/wekan/wekan:v5.65cb17600883a3
multiparty@3.3.2
4.3.0
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
multiparty@4.2.3
4.3.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.