StackRadar

CVE-2026-82417

Medium

Advisory

Published 31 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
725
of 17,787 indexed, latest versions
Container images
729
deployed by those charts
Fix available
1 of 2
affected packages

qs: Denial of Service via Attacker Controlled isBuffer

Carried by container images the latest versions of 725 of 17,787 indexed charts deploy, on 729 images.

Affected packageAffected versionsFixed inImages
qsnpm2.3.3, 5.2.0, 6.2.1, 6.3.0+31 more6.16.0729
node-qsdeb2.2.4-1, 2.2.4-1ubuntu1, 6.9.1+ds-1no fix listed5
OSV records
GHSA-4mjr-xmp4-gh2gUBUNTU-CVE-2026-82417

Charts affected

725 by stars
ChartLatestAffected imagesRadar Score
standard-application-stackmintel11.4.11 of 12See more

standard-application-stack mintel 11.4.1

1 of the 12 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
qs@6.5.2
6.16.0

Open the chart page →

10,515
iotmmontesVerified publisher0.3.24 of 7See more

iot mmontes 0.3.2

4 of the 7 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
qs@6.11.0
6.16.0
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
qs@6.5.2
6.16.0
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
qs@6.11.0
6.16.0
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
qs@6.5.2
6.16.0

Open the chart page →

10,608
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
qs@6.5.2
6.16.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
qs@6.5.2
6.16.0

Open the chart page →

11,734
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
qs@6.5.2
6.16.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
qs@6.5.2
6.16.0

Open the chart page →

11,734
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
qs@6.5.2
6.16.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
qs@6.5.2
6.16.0

Open the chart page →

12,147
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
qs@6.14.0
6.16.0

Open the chart page →

2,458
finance-portalmojaloop5.1.45 of 11See more

finance-portal mojaloop 5.1.4

5 of the 11 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
qs@6.5.3
6.16.0
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
qs@6.13.0
6.16.0
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
qs@6.11.0
6.16.0
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
qs@6.13.0
6.16.0
mojaloop/role-assignment-service:v2.1.0def4bf273721
qs@6.11.0
6.16.0

Open the chart page →

14,811
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
qs@6.5.2
6.16.0
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
qs@6.5.2
6.16.0

Open the chart page →

11,518
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
qs@6.5.2
6.16.0
mojaloop/central-ledger:v13.14.01abc8a7aa71c
qs@6.5.2
6.16.0
mojaloop/event-sidecar:v11.0.189b8ab71b74b
qs@6.5.2
6.16.0
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
qs@6.5.2
6.16.0

Open the chart page →

19,265
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
qs@6.13.0
6.16.0

Open the chart page →

2,632
reporting-hub-bop-api-svcmojaloop4.1.31 of 1See more

reporting-hub-bop-api-svc mojaloop 4.1.3

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
qs@6.11.0
6.16.0

Open the chart page →

1,661
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
qs@6.13.0
6.16.0

Open the chart page →

2,318
reporting-legacy-apimojaloop2.2.01 of 1See more

reporting-legacy-api mojaloop 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/reporting:v12.1.0d480a62103d6
qs@6.5.3
6.16.0

Open the chart page →

1,949
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
qs@6.11.0
6.16.0

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
qs@6.14.0
6.16.0

Open the chart page →

2,458
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
library/mongo-express:latest1b23d7976f02
qs@6.11.0
6.16.0

Open the chart page →

5,217
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
qs@6.5.2
6.16.0

Open the chart page →

6,438
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
qs@6.3.2
6.16.0
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
qs@6.4.0
6.16.0

Open the chart page →

7,048
api-proxymoreillonVerified publisher0.1.41 of 1See more

api-proxy moreillon 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
moreillon/api-proxy:2373c1953739ef6956b5
qs@6.11.0
6.16.0

Open the chart page →

1,712
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
moreillon/camera-proxy:latestce60056b50c2
qs@6.13.0
6.16.0

Open the chart page →

11,694
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
qs@6.10.3
6.16.0

Open the chart page →

8,556
group-managermoreillonVerified publisher0.4.41 of 3See more

group-manager moreillon 0.4.4

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
moreillon/group-manager:v4.9.0d5a0ec8394c0
qs@6.11.0
6.16.0

Open the chart page →

9,886
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
qs@6.10.3
6.16.0

Open the chart page →

10,998
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
qs@6.11.0
6.16.0

Open the chart page →

23,263
user-manager-neo4jmoreillonVerified publisher0.9.72 of 6See more

user-manager-neo4j moreillon 0.9.7

2 of the 6 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
moreillon/group-manager:v4.9.0d5a0ec8394c0
qs@6.11.0
6.16.0
moreillon/user-manager:v5.0.2e1c9bfab5c16
qs@6.11.0
6.16.0

Open the chart page →

30,195
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
qs@6.5.2
6.16.0

Open the chart page →

6,684
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
qs@6.11.2
6.16.0

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
qs@6.13.0
6.16.0

Open the chart page →

4,908
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
qs@6.11.2
6.16.0

Open the chart page →

6,646
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
qs@6.5.2
6.16.0

Open the chart page →

3,128
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
qs@6.5.2
6.16.0

Open the chart page →

12,861
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
qs@6.5.2
6.16.0

Open the chart page →

12,861
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
qs@6.11.0
6.16.0

Open the chart page →

2,116
myawesomeappmyawesomeapp1.1.01 of 1See more

myawesomeapp myawesomeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebapp:latestea5b71588a76
qs@6.11.0
6.16.0

Open the chart page →

1,267
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
qs@6.11.0
6.16.0

Open the chart page →

2,116
myawesomeappmyawesomeapp20.1.01 of 1See more

myawesomeapp myawesomeapp2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
mpopoola1/nodejsapp:latest061fc532de7d
qs@6.11.0
6.16.0

Open the chart page →

1,118
myawesomeapp-feb24myawesomeapp-feb240.1.11 of 1See more

myawesomeapp-feb24 myawesomeapp-feb24 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
josepht05/nodejs-feb24:latest36cb0c618c94
qs@6.11.0
6.16.0

Open the chart page →

1,070
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
qs@6.11.0
6.16.0

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
qs@6.11.0
6.16.0

Open the chart page →

2,116
myawesomeappoctmyawesomeappoct0.1.11 of 1See more

myawesomeappoct myawesomeappoct 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
qs@6.11.0
6.16.0

Open the chart page →

1,164
myawesomeappoctmyawesomeappoct20230.1.11 of 1See more

myawesomeappoct myawesomeappoct2023 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
hamid2021/nodejs-dockercli:latest429d99890c3c
qs@6.11.0
6.16.0

Open the chart page →

1,118
mydannyappmydannyapp1.1.01 of 1See more

mydannyapp mydannyapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
danny1dockerhub/nodejswebapp:lateste434683fcc89
qs@6.11.0
6.16.0

Open the chart page →

1,267
mygreatappmygreatapp0.1.01 of 1See more

mygreatapp mygreatapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ktitilayo2/nodejswebapp:latest8bac28058688
qs@6.11.0
6.16.0

Open the chart page →

1,164
myhelmappmyhelm-app1.1.01 of 1See more

myhelmapp myhelm-app 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
patdada/bella-docker:v1.0.075127147a624
qs@6.5.3
6.16.0

Open the chart page →

1,625
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
qs@6.11.0
6.16.0

Open the chart page →

3,359
myhelmappmyhelmapp11.1.01 of 1See more

myhelmapp myhelmapp1 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
josepht05/titajo-docker:v1.0.0d94024965d78
qs@6.11.0
6.16.0

Open the chart page →

1,164
myhelmappmyhelmpapp1.1.01 of 1See more

myhelmapp myhelmpapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
qs@6.11.0
6.16.0

Open the chart page →

1,235
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
qs@6.11.0
6.16.0

Open the chart page →

17,411
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
qs@6.15.2
6.16.0

Open the chart page →

1,039
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
qs@6.5.3
6.16.0

Open the chart page →

3,270

Container images carrying it

729 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
qs@6.7.0
6.16.0
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
qs@6.5.5
6.16.0
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
qs@6.4.0
6.16.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
qs@6.9.4
6.16.0
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
qs@6.5.2
6.16.0
1
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
qs@6.5.2
6.16.0
1
quay.io/ibmgaragecloud/slack-notifications:latest041df93e2bac
qs@6.5.2
6.16.0
1
quay.io/mittwald/kube-mail:latest04f1099241fc
qs@6.13.0
6.16.0
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
qs@6.5.2
6.16.0
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
qs@6.5.2
6.16.0
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
qs@6.5.2
6.16.0
1
quay.io/renokico/laravel-helm-demo:octane-0.6.0cad83090c58f
qs@6.5.2
6.16.0
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
qs@6.14.2
6.16.0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
qs@6.5.2
6.16.0
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
qs@6.15.2
6.16.0
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
qs@6.14.1
6.16.0
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
qs@6.5.3
6.16.0
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
qs@6.7.0
6.16.0
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
qs@6.5.2
6.16.0
1
quay.io/wekan/wekan:v5.65cb17600883a3
qs@6.4.0
6.16.0
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
qs@6.15.3
6.16.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
qs@6.15.0
6.16.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
qs@6.13.0
6.16.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
qs@6.15.0
6.16.0
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
qs@6.5.1
6.16.0
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod470da8f8730c
qs@6.14.1
6.16.0
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbce6d452ad08
qs@6.14.1
6.16.0
1
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
qs@6.10.3
6.16.0
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
qs@6.13.0
6.16.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.