StackRadar

CVE-2026-82417

Medium

Advisory

Published 31 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
726
of 17,781 indexed, latest versions
Container images
730
deployed by those charts
Fix available
1 of 2
affected packages

qs: Denial of Service via Attacker Controlled isBuffer

Carried by container images the latest versions of 726 of 17,781 indexed charts deploy, on 730 images.

Affected packageAffected versionsFixed inImages
qsnpm2.3.3, 5.2.0, 6.2.1, 6.3.0+31 more6.16.0730
node-qsdeb2.2.4-1, 2.2.4-1ubuntu1, 6.9.1+ds-1no fix listed5
OSV records
GHSA-4mjr-xmp4-gh2gUBUNTU-CVE-2026-82417

Charts affected

726 by stars
ChartLatestAffected imagesRadar Score
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
qs@6.10.4
6.16.0

Open the chart page →

1,843
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
qs@6.5.2
6.16.0

Open the chart page →

3,509
home-assistant-matter-servercharts-derwitt-devVerified publisher4.2.11 of 2See more

home-assistant-matter-server charts-derwitt-dev 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
qs@6.15.3
6.16.0

Open the chart page →

2,360
node-redcharts-derwitt-devVerified publisher2.1.21 of 1See more

node-red charts-derwitt-dev 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
nodered/node-red:5.0.7a649dd711d55
qs@6.15.3
6.16.0

Open the chart page →

101
maildevchristianhuthVerified publisher1.6.01 of 1See more

maildev christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
maildev/maildev:2.2.1180ef51f65ee
qs@6.13.0
6.16.0

Open the chart page →

1,143
skoonerchristianhuthVerified publisher0.4.01 of 1See more

skooner christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
qs@6.11.0
6.16.0

Open the chart page →

1,341
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
qs@6.9.4
6.16.0

Open the chart page →

9,971
data-fairdata354-helmVerified publisher1.1.28 of 12See more

data-fair data354-helm 1.1.2

8 of the 12 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
koumoul/capture:17108d47be3b2
qs@6.5.2
6.16.0
koumoul/openapi-viewer:18eeca2e8285b
qs@6.5.1
6.16.0
ghcr.io/data-fair/data-fair:3cc9498b64b5b
qs@6.5.3
6.16.0
ghcr.io/data-fair/metrics:0a8d40779eeae
qs@6.10.3
6.16.0
ghcr.io/data-fair/notify:3c739b74dabb0
qs@6.13.0
6.16.0
ghcr.io/data-fair/portals:18b621866ceb2
qs@6.15.3
6.16.0
ghcr.io/data-fair/processings:15a9216989707
qs@6.11.0
6.16.0
ghcr.io/data-fair/simple-directory:438a4f32fad82
qs@6.10.3
6.16.0

Open the chart page →

38,346
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
qs@6.11.0
6.16.0

Open the chart page →

5,056
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
qs@6.15.2
6.16.0

Open the chart page →

7,473
jellystatdjjudas21Verified publisher0.1.121 of 1See more

jellystat djjudas21 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
qs@6.15.2
6.16.0

Open the chart page →

1,722
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
qs@6.11.0
6.16.0

Open the chart page →

3,925
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
qs@6.13.0
6.16.0

Open the chart page →

5,670
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-82417.

Open the chart page →

31,510
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
qs@6.14.2
6.16.0

Open the chart page →

1,442
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
qs@6.5.3
6.16.0

Open the chart page →

11,458
recaptcha-v3-verifierf3k-techVerified publisher1.110.01 of 1See more

recaptcha-v3-verifier f3k-tech 1.110.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
f3ktech/recaptcha-v3-verifier:1.1.048e78987cf91
qs@6.14.0
6.16.0

Open the chart page →

1,208
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
qs@6.7.0
6.16.0

Open the chart page →

2,519
foundryvttgeek-cookbookVerified publisher3.4.21 of 1See more

foundryvtt geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
felddy/foundryvtt:0.8.36c5d90b90349
qs@6.5.2
6.16.0

Open the chart page →

2,042
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
qs@6.9.7
6.16.0

Open the chart page →

4,260
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
qs@6.5.2
6.16.0

Open the chart page →

4,405
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
qs@6.7.0
6.16.0

Open the chart page →

3,444
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
qs@6.5.2
6.16.0

Open the chart page →

7,801
sendgeek-cookbookVerified publisher1.2.21 of 1See more

send geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
qs@6.10.3
6.16.0

Open the chart page →

1,148
tdarrgeek-cookbookVerified publisher4.6.21 of 2See more

tdarr geek-cookbook 4.6.2

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.00.101e3f9328327d
qs@6.5.2
6.16.0

Open the chart page →

31,000
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
qs@6.5.3
6.16.0

Open the chart page →

5,079
uptimerobotgeek-cookbookVerified publisher3.0.41 of 1See more

uptimerobot geek-cookbook 3.0.4

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
qs@6.5.2
6.16.0

Open the chart page →

1,669
youtubedl-materialgeek-cookbookVerified publisher4.4.21 of 1See more

youtubedl-material geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.23720b856bd2f
qs@6.5.2
6.16.0

Open the chart page →

4,410
zigbee2mqttgeek-cookbookVerified publisher9.4.21 of 1See more

zigbee2mqtt geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
qs@6.5.2
6.16.0

Open the chart page →

2,173
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
qs@6.15.1
6.16.0

Open the chart page →

3,123
ghostgroundhog2k0.212.121 of 1See more

ghost groundhog2k 0.212.12

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
qs@6.15.3
6.16.0

Open the chart page →

2,000
growthbookgrowthbook5.0.11 of 2See more

growthbook growthbook 5.0.1

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
growthbook/growthbook:5.0.1f53ead646b5f
qs@6.15.2
6.16.0

Open the chart page →

709
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
qs@6.11.0
6.16.0

Open the chart page →

4,196
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
qs@6.5.2
6.16.0

Open the chart page →

6,810
pdc-portali4trustVerified publisher2.3.21 of 1See more

pdc-portal i4trust 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
i4trust/pdc-portal:2.0.03e77858e1219
qs@6.5.2
6.16.0

Open the chart page →

2,723
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
qs@6.14.0
6.16.0

Open the chart page →

15,712
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
qs@6.7.0
6.16.0

Open the chart page →

3,369
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
qs@6.13.0
6.16.0

Open the chart page →

5,228
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
qs@6.5.3
6.16.0

Open the chart page →

3,143
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
qs@6.5.2
6.16.0

Open the chart page →

20,403
lifecycle-jira-integrationlifecycle-jira-integration1.0.01 of 1See more

lifecycle-jira-integration lifecycle-jira-integration 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
anoopnair/lifecycle-jira-integration:latestd80c73a6089d
qs@6.9.7
6.16.0

Open the chart page →

927
litlyxlitlyx0.2.02 of 5See more

litlyx litlyx 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
litlyx/litlyx-consumer:latest02225e77d316
qs@6.13.0
6.16.0
litlyx/litlyx-producer:latest10407f36613f
qs@6.13.0
6.16.0

Open the chart page →

7,874
actualbudgetm0nsterrr-actualbudgetVerified publisher2.10.01 of 1See more

actualbudget m0nsterrr-actualbudget 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
qs@6.15.2
6.16.0

Open the chart page →

1,091
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
qs@6.5.2
6.16.0

Open the chart page →

5,940
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.12 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

2 of the 6 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
qs@6.5.2
6.16.0
fjvela/urjc-fjvela-server:1.0.53c840aebce22
qs@6.5.2
6.16.0

Open the chart page →

19,187
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
qs@6.13.0
6.16.0

Open the chart page →

13,738
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
qs@6.14.2
6.16.0

Open the chart page →

2,575
kuttone-acre-fundVerified publisher0.2.51 of 1See more

kutt one-acre-fund 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
kutt/kutt:latestfa3d24a89b04
qs@6.15.2
6.16.0

Open the chart page →

454
open5gs-webuiopen5gs-webuiVerified publisher2.3.11 of 2See more

open5gs-webui open5gs-webui 2.3.1

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
qs@6.11.0
6.16.0

Open the chart page →

5,300
open-api-discoveryopen-api-discoveryVerified publisher0.1.11 of 1See more

open-api-discovery open-api-discovery 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
lukasreining/open-api-schema-collector:0.1.050e021c42e33
qs@6.5.3
6.16.0

Open the chart page →

2,473

Container images carrying it

730 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
anoopnair/lifecycle-jira-integration:latestd80c73a6089d
qs@6.9.7
6.16.0
1
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
qs@6.5.2
6.16.0
1
apimap/developer:v1.3.1406d3858e20c
qs@6.10.3
6.16.0
1
apimap/portal:v2.4.0041a4790c65c
qs@6.10.3
6.16.0
1
archivebox/archivebox:0.7.41a5a37331091
qs@6.5.3
6.16.0
1
arfath29/3-tier-app-backend:latestee0750b18406
qs@6.5.3
6.16.0
1
arfath29/3-tier-app-frontend:latest384b3e377f47
qs@6.7.0
6.16.0
1
arturisimo/server-urjc:v1.0d8dc4430531e
qs@6.10.3
6.16.0
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
qs@6.5.2
6.16.0
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
qs@6.9.4
6.16.0
1
assistiot/dlt_api:2.1.0c8a170683be7
qs@6.11.0
6.16.0
1
assistiot/fl_orchestrator:api-latest7473d77448e1
qs@6.5.3
6.16.0
1
assistiot/monitoring_notifying:2.0.068324d0fa5bb
qs@6.11.0
6.16.0
1
assistiot/multi-link_client:latestcf048365d042
qs@6.11.0
6.16.0
1
assistiot/multi-link_server:latestf38c76a4c960
qs@6.11.0
6.16.0
1
assistiot/open_api_frontend:1.0.1f11d82defc70
qs@6.5.2
6.16.0
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
qs@6.5.3
6.16.0
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
qs@6.5.3
6.16.0
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
qs@6.10.3
6.16.0
1
aureliengasser/http-folder:1.1.111c4318c2571
qs@6.5.2
6.16.0
1
automatischio/automatisch:0.15.03bace7a12d5f
qs@6.11.0
6.16.0
1
baserow/baserow:1.30.1df0c42eb67e8
qs@6.11.2
6.16.0
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
qs@6.5.2
6.16.0
1
belirta/beli-docker:v1.0.0f65ad0e23b4d
qs@6.11.0
6.16.0
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
qs@6.13.0
6.16.0
1
bicarus/http-https-echo:2785dd6a7e805e
qs@6.10.3
6.16.0
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
qs@6.9.3
6.16.0
1
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
qs@6.5.2
6.16.0
1
bluerange/bluerange-mosquitto:25f1bfbba84832
qs@6.5.2
6.16.0
1
bnjbvr/kresus:0.22.137e216b182c8
qs@6.13.0
6.16.0
1
bnwokoye/nodejswebapp:latest74de7dc7ebfb
qs@6.11.0
6.16.0
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
qs@6.5.2
6.16.0
1
budibase/apps:3.41.344fe6feab985
qs@6.15.1
6.16.0
1
budibase/worker:3.41.3de5e2e560ce8
qs@6.15.0
6.16.0
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
qs@6.5.2
6.16.0
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
qs@6.13.0
6.16.0
1
catalysm/csmm:latestf003b35f54d9
qs@6.7.0
6.16.0
1
ccjacobs14/amazon:59a9b14a6f09e
qs@6.11.0
6.16.0
1
chainsafe/lodestar:latest5593f6e97912
qs@6.15.2
6.16.0
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
qs@6.11.1
6.16.0
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
qs@6.13.0
6.16.0
1
chatwoot/chatwoot:v4.15.167ebc751c171
qs@6.5.2
6.16.0
1
chocobozzz/peertube:v8.1.5052712130691
qs@6.15.0
6.16.0
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
qs@6.5.2
6.16.0
1
cnieg/maildev:v1.1.998ee05668915
qs@6.7.0
6.16.0
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
qs@6.5.2
6.16.0
1
codercom/code-server:4.11.0-debian1e2cc688008e
qs@6.7.0
6.16.0
1
codercom/code-server:3.10.247605610ad8d
qs@6.7.0
6.16.0
1
codetogether/codetogether:latest4348c8a38752
qs@6.12.1
6.16.0
1
coldatom/containers-security-api:latesteae9e82da080
qs@6.5.3
6.16.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.