StackRadar

CVE-2026-82417

Medium

Advisory

Published 31 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
725
of 17,787 indexed, latest versions
Container images
729
deployed by those charts
Fix available
1 of 2
affected packages

qs: Denial of Service via Attacker Controlled isBuffer

Carried by container images the latest versions of 725 of 17,787 indexed charts deploy, on 729 images.

Affected packageAffected versionsFixed inImages
qsnpm2.3.3, 5.2.0, 6.2.1, 6.3.0+31 more6.16.0729
node-qsdeb2.2.4-1, 2.2.4-1ubuntu1, 6.9.1+ds-1no fix listed5
OSV records
GHSA-4mjr-xmp4-gh2gUBUNTU-CVE-2026-82417

Charts affected

725 by stars
ChartLatestAffected imagesRadar Score
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
qs@6.15.0
6.16.0

Open the chart page →

4,266
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
qs@6.5.3
6.16.0

Open the chart page →

9,036
api-mapperglenndehaanVerified publisher1.2.01 of 1See more

api-mapper glenndehaan 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
glenndehaan/api-mapper:latest6ff6310683bf
qs@6.5.3
6.16.0

Open the chart page →

1,158
contentbridgeglenndehaanVerified publisher1.1.01 of 1See more

contentbridge glenndehaan 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
glenndehaan/contentbridge:latest99b9e4f73848
qs@6.11.0
6.16.0

Open the chart page →

1,000
kube-hookglenndehaanVerified publisher1.0.31 of 1See more

kube-hook glenndehaan 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
glenndehaan/kube-hook:latest0a7116f48bfe
qs@6.5.3
6.16.0

Open the chart page →

923
Governify-Bluejaygovernify0.1.05 of 12See more

Governify-Bluejay governify 0.1.0

5 of the 12 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
qs@6.7.0
6.16.0
governify/director:v1.4.0608c6940bb98
qs@6.7.0
6.16.0
governify/registry:v3.4.0d3f37f4f8168
qs@6.5.2
6.16.0
governify/render:v2.2.0daeca1ce28e6
qs@6.7.0
6.16.0
governify/reporter:v2.2.038595913458f
qs@6.5.2
6.16.0

Open the chart page →

22,565
Governify-Falcongovernify0.1.06 of 10See more

Governify-Falcon governify 0.1.0

6 of the 10 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
qs@6.7.0
6.16.0
governify/collector-dynamic:v1.3.06d3d1a5b46a9
qs@6.7.0
6.16.0
governify/director:v1.4.0608c6940bb98
qs@6.7.0
6.16.0
governify/registry:v3.4.0d3f37f4f8168
qs@6.5.2
6.16.0
governify/render:v2.2.0daeca1ce28e6
qs@6.7.0
6.16.0
governify/reporter:v2.2.038595913458f
qs@6.5.2
6.16.0

Open the chart page →

24,360
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
qs@6.10.4
6.16.0

Open the chart page →

47,117
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
qs@6.7.0
6.16.0

Open the chart page →

2,683
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
qs@6.7.0
6.16.0

Open the chart page →

2,683
littlelink-serverh2mVerified publisher1.0.11 of 1See more

littlelink-server h2m 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
qs@6.13.0
6.16.0

Open the chart page →

819
h2ph2pVerified publisher1.0.11 of 1See more

h2p h2p 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
dacinfomotion/h2p:latest68fa393b472c
qs@6.11.0
6.16.0

Open the chart page →

1,713
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
qs@6.14.0
6.16.0

Open the chart page →

2,949
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
qs@6.15.3
6.16.0

Open the chart page →

8,798
gitter-irc-bridgehalkeye0.1.11 of 1See more

gitter-irc-bridge halkeye 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
qs@6.5.2
6.16.0

Open the chart page →

3,642
hubothalkeye0.0.11 of 1See more

hubot halkeye 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
halkeye/hubot:latest9764d2202130
qs@6.5.2
6.16.0

Open the chart page →

2,116
irslackdhalkeye0.1.01 of 1See more

irslackd halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
halkeye/irslackd:latest7638bfba70b0
qs@6.5.2
6.16.0

Open the chart page →

2,064
matrix-appservice-gitterhalkeye0.1.01 of 1See more

matrix-appservice-gitter halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
matrixdotorg/matrix-appservice-gitter:latest0d37b4d42b47
qs@6.5.2
6.16.0

Open the chart page →

3,003
theloungehalkeye4.3.11 of 1See more

thelounge halkeye 4.3.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
thelounge/thelounge:4.3.0-alpine0037aa258261
qs@6.7.0
6.16.0

Open the chart page →

1,938
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
qs@6.14.0
6.16.0

Open the chart page →

3,818
zigbee2mqtthelm-chart-roeiVerified publisher1.19.01 of 1See more

zigbee2mqtt helm-chart-roei 1.19.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
qs@6.5.2
6.16.0

Open the chart page →

2,173
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
qs@6.6.0
6.16.0

Open the chart page →

24,174
streamsheetshelm-chartsVerified publisher0.2.35 of 8See more

streamsheets helm-charts 0.2.3

5 of the 8 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
qs@6.5.2
6.16.0
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
qs@6.5.2
6.16.0
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
qs@6.5.2
6.16.0
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
qs@6.7.0
6.16.0
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
qs@6.7.0
6.16.0

Open the chart page →

89,949
nodeapphelmcharts0.1.41 of 1See more

nodeapp helmcharts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
kaushaln1/helm_node_app:lateste9f2d5dfdba0
qs@6.10.3
6.16.0

Open the chart page →

948
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
qs@6.9.4
6.16.0

Open the chart page →

8,213
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
qs@6.11.0
6.16.0

Open the chart page →

3,451
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
qs@6.15.0
6.16.0

Open the chart page →

778
affinehelmforgeVerified publisher1.0.01 of 3See more

affine helmforge 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
qs@6.15.3
6.16.0

Open the chart page →

3,895
archiveboxhelmforgeVerified publisher1.1.121 of 1See more

archivebox helmforge 1.1.12

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
archivebox/archivebox:0.7.41a5a37331091
qs@6.5.3
6.16.0

Open the chart page →

7,648
automatischhelmforgeVerified publisher1.3.71 of 4See more

automatisch helmforge 1.3.7

1 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
automatischio/automatisch:0.15.03bace7a12d5f
qs@6.11.0
6.16.0

Open the chart page →

5,794
bytestashhelmforgeVerified publisher1.0.01 of 1See more

bytestash helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
qs@6.15.2
6.16.0

Open the chart page →

739
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
qs@6.11.0
6.16.0

Open the chart page →

18,923
ghosthelmforgeVerified publisher1.2.61 of 3See more

ghost helmforge 1.2.6

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
library/ghost:6.62.0a7a268bbfb7f
qs@6.15.3
6.16.0

Open the chart page →

2,475
hoppscotchhelmforgeVerified publisher1.1.111 of 2See more

hoppscotch helmforge 1.1.11

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2026.8.0d50725df661f
qs@6.15.3
6.16.0

Open the chart page →

2,058
immichhelmforgeVerified publisher1.2.81 of 5See more

immich helmforge 1.2.8

1 of the 5 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
qs@6.15.3
6.16.0

Open the chart page →

11,080
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
qs@6.14.0
6.16.0

Open the chart page →

2,536
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
qs@6.13.0
6.16.0

Open the chart page →

5,916
strapihelmforgeVerified publisher2.3.141 of 3See more

strapi helmforge 2.3.14

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
helmforge/strapi-base:5.52.270e9143d6d92
qs@6.15.3
6.16.0

Open the chart page →

2,073
uptime-kumahelmforgeVerified publisher1.5.121 of 1See more

uptime-kuma helmforge 1.5.12

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.33e24e96c89ef
qs@6.15.3
6.16.0

Open the chart page →

30,106
wikijshomeenterpriseinc1.4.01 of 1See more

wikijs homeenterpriseinc 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
requarks/wiki:canary-2.5.2438b5865a7386c
qs@6.5.2
6.16.0

Open the chart page →

4,253
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
qs@6.11.0
6.16.0

Open the chart page →

3,615
http-folderhttp-folder2.0.01 of 1See more

http-folder http-folder 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
aureliengasser/http-folder:1.1.111c4318c2571
qs@6.5.2
6.16.0

Open the chart page →

1,847
townsquarehuscker-chartsVerified publisher1.0.41 of 2See more

townsquare huscker-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
qs@6.11.0
6.16.0

Open the chart page →

3,355
crypto-watchdoghuseyinnurbaki0.1.01 of 1See more

crypto-watchdog huseyinnurbaki 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
hhaluk/crypto-watchdog:0.4.0a6555953d941
qs@6.7.0
6.16.0

Open the chart page →

2,656
ibm-app-navigatoribm-charts1.0.12 of 5See more

ibm-app-navigator ibm-charts 1.0.1

2 of the 5 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ibmcom/app-nav-init:1.0.1240ff499eb5b
qs@6.5.1
6.16.0
ibmcom/app-nav-ui:1.0.1e2a86997b36b
qs@6.5.1
6.16.0

Open the chart page →

32,911
ibm-business-automation-insights-devibm-charts3.2.02 of 6See more

ibm-business-automation-insights-dev ibm-charts 3.2.0

2 of the 6 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ibmcom/bai-admin-dev:19.0.202d882f2836e
qs@6.5.1
6.16.0
ibmcom/bai-setup-dev:19.0.2b8e8df11072d
qs@6.5.2
6.16.0

Open the chart page →

39,343
ibm-kerify-devibm-charts1.0.01 of 1See more

ibm-kerify-dev ibm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ibmcom/icp-sert-bats:3.2.0b558f2b444ae
qs@6.5.2
6.16.0

Open the chart page →

8,221
ibm-microclimateibm-charts0.1.03 of 8See more

ibm-microclimate ibm-charts 0.1.0

3 of the 8 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
qs@6.5.1
6.16.0
ibmcom/microclimate-portal:latested5505e5c7ec
qs@6.5.1
6.16.0
ibmcom/microclimate-theia:lateste17bdccc5030
qs@6.5.1
6.16.0

Open the chart page →

57,728
ibm-voice-gateway-devibm-charts3.1.01 of 2See more

ibm-voice-gateway-dev ibm-charts 3.1.0

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ibmcom/voice-gateway-mr:1.0.5.00762ab1df6c1
qs@6.5.2
6.16.0

Open the chart page →

4,504
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
qs@6.13.0
6.16.0

Open the chart page →

3,181

Container images carrying it

729 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
qs@6.7.0
6.16.0
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
qs@6.5.5
6.16.0
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
qs@6.4.0
6.16.0
1
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
qs@6.9.4
6.16.0
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
qs@6.5.2
6.16.0
1
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
qs@6.5.2
6.16.0
1
quay.io/ibmgaragecloud/slack-notifications:latest041df93e2bac
qs@6.5.2
6.16.0
1
quay.io/mittwald/kube-mail:latest04f1099241fc
qs@6.13.0
6.16.0
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
qs@6.5.2
6.16.0
1
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
qs@6.5.2
6.16.0
1
quay.io/renokico/laravel-helm-demo:worker-0.6.04b188259267e
qs@6.5.2
6.16.0
1
quay.io/renokico/laravel-helm-demo:octane-0.6.0cad83090c58f
qs@6.5.2
6.16.0
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
qs@6.14.2
6.16.0
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
qs@6.5.2
6.16.0
1
quay.io/seamware/fdsc-dashboard:0.6.0f7706c316c5a
qs@6.15.2
6.16.0
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
qs@6.14.1
6.16.0
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
qs@6.5.3
6.16.0
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
qs@6.7.0
6.16.0
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
qs@6.5.2
6.16.0
1
quay.io/wekan/wekan:v5.65cb17600883a3
qs@6.4.0
6.16.0
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
qs@6.15.3
6.16.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-backend:1.0.31c7afac3446d6
qs@6.15.0
6.16.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
qs@6.13.0
6.16.0
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-user:1.0.31d8a9cd4e1ae3
qs@6.15.0
6.16.0
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
qs@6.5.1
6.16.0
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod470da8f8730c
qs@6.14.1
6.16.0
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbce6d452ad08
qs@6.14.1
6.16.0
1
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
qs@6.10.3
6.16.0
1
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
qs@6.13.0
6.16.0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.