CVE-2026-8162
HighAdvisory
Published 18 May 2026In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.003
- 20th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 20
- of 17,781 indexed, latest versions
- Container images
- 17
- deployed by those charts
- Fix available
- 1 of 1
- affected package
multiparty vulnerable to Denial of Service via Uncaught Exception in filename* parameter parsing
Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 17 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| multipartynpm | 2.1.8, 2.2.0, 3.2.10, 3.3.2+4 more | 4.3.0 | 17 |
- OSV records
- GHSA-xh3c-6gcq-g4rv
Charts affected
20 by stars
Container images carrying it
17 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| pantsel/ | c8172b75607d | multiparty | 4.3.0 | 3 |
| mojaloop/ | d480a62103d6 | multiparty | 4.3.0 | 2 |
| catalysm/ | f003b35f54d9 | multiparty | 4.3.0 | 1 |
| chocobozzz/ | 052712130691 | multiparty | 4.3.0 | 1 |
| decayofmind/ | 1e18e92fe694 | multiparty | 4.3.0 | 1 |
| getferdi/ | 6e620b85afaa | multiparty | 4.3.0 | 1 |
| gristlabs/ | 6e71b1914a7e | multiparty | 4.3.0 | 1 |
| halkeye/ | 9764d2202130 | multiparty | 4.3.0 | 1 |
| joplin/ | 3f7b852959aa | multiparty | 4.3.0 | 1 |
| joplin/ | 52af57880c0e | multiparty | 4.3.0 | 1 |
| joplin/ | b87564ef34e9 | multiparty | 4.3.0 | 1 |
| konradkleine/ | 181aad54ee64 | multiparty | 4.3.0 | 1 |
| linuxserver/ | 45c5fe102ff3 | multiparty | 4.3.0 | 1 |
| minddocdev/ | 6c60b11a4fa7 | multiparty | 4.3.0 | 1 |
| wekanteam/ | 68a51f0327df | multiparty | 4.3.0 | 1 |
| quay.io/ | cb17600883a3 | multiparty | 4.3.0 | 1 |
| registry.gitlab.com/ | fcf07d5ff7e2 | multiparty | 4.3.0 | 1 |