StackRadar

CVE-2026-82417

Medium

Advisory

Published 31 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
726
of 17,781 indexed, latest versions
Container images
730
deployed by those charts
Fix available
1 of 2
affected packages

qs: Denial of Service via Attacker Controlled isBuffer

Carried by container images the latest versions of 726 of 17,781 indexed charts deploy, on 730 images.

Affected packageAffected versionsFixed inImages
qsnpm2.3.3, 5.2.0, 6.2.1, 6.3.0+31 more6.16.0730
node-qsdeb2.2.4-1, 2.2.4-1ubuntu1, 6.9.1+ds-1no fix listed5
OSV records
GHSA-4mjr-xmp4-gh2gUBUNTU-CVE-2026-82417

Charts affected

726 by stars
ChartLatestAffected imagesRadar Score
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
qs@6.10.5
6.16.0

Open the chart page →

10,530
librechatlibrechat1.8.101 of 3See more

librechat librechat 1.8.10

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
qs@6.13.0
6.16.0

Open the chart page →

2,654
musicocielmusicocielVerified publisher0.0.01 of 3See more

musicociel musicociel 0.0.0

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
davdiv/musicociel:deva85f99be882c
qs@6.11.0
6.16.0

Open the chart page →

4,406
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/tale/headplane:0.5.50dbc52cffc19
qs@6.5.3
6.16.0

Open the chart page →

7,949
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
qs@6.11.0
6.16.0

Open the chart page →

9,261
taigarc-helm-charts0.1.01 of 7See more

taiga rc-helm-charts 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
taigaio/taiga-events:6.4.00bf2d24a57d9
qs@6.5.2
6.16.0

Open the chart page →

7,255
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
qs@6.7.0
6.16.0

Open the chart page →

8,212
ghostcloudpirates-ghostVerified publisher0.20.221 of 3See more

ghost cloudpirates-ghost 0.20.22

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
qs@6.15.3
6.16.0

Open the chart page →

7,146
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
qs@6.12.1
6.16.0

Open the chart page →

7,450
community-solid-servercommunity-solid-server3.0.01 of 1See more

community-solid-server community-solid-server 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
solidproject/community-server:6.0.2ccc4acb7e9a1
qs@6.11.1
6.16.0

Open the chart page →

1,613
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
qs@6.11.2
6.16.0

Open the chart page →

17,404
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
qs@6.11.2
6.16.0

Open the chart page →

28,839
hubotdecayofmind1.0.21 of 3See more

hubot decayofmind 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
decayofmind/hubot:3.3.21e18e92fe694
qs@6.5.2
6.16.0

Open the chart page →

2,513
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
qs@6.11.0
6.16.0

Open the chart page →

3,451
nightscoutgabe565Verified publisher0.13.01 of 2See more

nightscout gabe565 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
qs@6.5.2
6.16.0

Open the chart page →

2,521
rsshubgabe565Verified publisher0.8.01 of 3See more

rsshub gabe565 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
diygod/rsshub:latest1d4b508b6357
qs@6.14.2
6.16.0

Open the chart page →

1,717
audiobookshelfgeek-cookbookVerified publisher1.2.21 of 1See more

audiobookshelf geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
qs@6.9.7
6.16.0

Open the chart page →

1,959
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
qs@6.5.2
6.16.0

Open the chart page →

22,773
mealiegeek-cookbookVerified publisher5.1.21 of 2See more

mealie geek-cookbook 5.1.2

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
qs@6.7.0
6.16.0

Open the chart page →

7,579
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
qs@6.5.2
6.16.0

Open the chart page →

3,476
ghost-on-kubernetesghost-on-kubernetes-helmVerified publisher1.1.21 of 3See more

ghost-on-kubernetes ghost-on-kubernetes-helm 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/sredevopsorg/ghost-on-kubernetes:maindd991bafa85e
qs@6.15.3
6.16.0

Open the chart page →

1,447
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
qs@6.7.0
6.16.0

Open the chart page →

10,311
dynamodbkeyporttech0.1.271 of 2See more

dynamodb keyporttech 0.1.27

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
aaronshaf/dynamodb-admin:latestac41724cd997
qs@6.15.2
6.16.0

Open the chart page →

1,304
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
qs@6.4.0
6.16.0

Open the chart page →

5,209
kubeviouskubevious1.2.24 of 7See more

kubevious kubevious 1.2.2

4 of the 7 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
kubevious/backend:1.2.22d9ba6eb46b6
qs@6.5.3
6.16.0
kubevious/collector:1.2.1f58226f9d84e
qs@6.11.0
6.16.0
kubevious/guard:1.2.19bf567704de2
qs@6.9.7
6.16.0
kubevious/parser:1.2.299ae7a5168c2
qs@6.11.0
6.16.0

Open the chart page →

14,204
bitwarden-crd-operatorlerentisVerified publisher0.18.01 of 1See more

bitwarden-crd-operator lerentis 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
qs@6.15.0
6.16.0

Open the chart page →

2,003
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
qs@6.11.2
6.16.0

Open the chart page →

2,635
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
qs@6.5.2
6.16.0

Open the chart page →

6,868
kobotoolboxone-acre-fundVerified publisher0.7.42 of 9See more

kobotoolbox one-acre-fund 0.7.4

2 of the 9 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
qs@6.5.2
6.16.0
kobotoolbox/kpi:2.022.24dbcacc01bccd4
qs@6.9.7
6.16.0

Open the chart page →

18,517
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
qs@6.11.0
6.16.0

Open the chart page →

7,776
openclaw-with-brainopenclaw-with-brainVerified publisher0.1.671 of 3See more

openclaw-with-brain openclaw-with-brain 0.1.67

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
qs@6.15.2
6.16.0

Open the chart page →

5,218
kratos-selfservice-ui-nodeory0.64.01 of 1See more

kratos-selfservice-ui-node ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
qs@6.14.2
6.16.0

Open the chart page →

1,966
pacmanpacmanVerified publisher2.0.21 of 2See more

pacman pacman 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/shuguet/pacman:latesta0ec71732c3c
qs@6.14.2
6.16.0

Open the chart page →

638
overseerrpree-helm-chartsVerified publisher1.2.01 of 1See more

overseerr pree-helm-charts 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.35.06197516c9d7b
qs@6.5.3
6.16.0

Open the chart page →

2,702
laravelrenoki-co1.0.01 of 2See more

laravel renoki-co 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
quay.io/renokico/laravel-helm-demo:0.6.03207f957e80c
qs@6.5.2
6.16.0

Open the chart page →

6,931
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
qs@6.15.3
6.16.0

Open the chart page →

977
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
qs@6.5.2
6.16.0

Open the chart page →

24,488
thingsboard-clusterthingsboard-cluster-bettaVerified publisher0.2.261 of 6See more

thingsboard-cluster thingsboard-cluster-betta 0.2.26

1 of the 6 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
thingsboard/tb-web-ui:3.6.0d388378062cc
qs@6.10.3
6.16.0

Open the chart page →

14,566
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
thmmniii/fbs-qcm-backend:v1.27.1afbe511e5c24
qs@6.13.0
6.16.0

Open the chart page →

28,534
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
qs@6.15.0
6.16.0

Open the chart page →

4,016
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
qs@6.5.2
6.16.0

Open the chart page →

2,851
aapbaapbVerified publisher0.1.31 of 1See more

aapb aapb 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
qs@6.14.1
6.16.0

Open the chart page →

1,044
github-actions-runneradwerx0.10.31 of 1See more

github-actions-runner adwerx 0.10.3

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
adwerx/github-actions-runner:2.276.1-20.04-1840d2b078682
qs@6.5.2
6.16.0

Open the chart page →

13,635
bredbandskollen-prometheus-exporteraolde0.2.31 of 1See more

bredbandskollen-prometheus-exporter aolde 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
qs@6.5.2
6.16.0

Open the chart page →

1,972
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
qs@6.9.4
6.16.0

Open the chart page →

17,896
siemassist-iot-cybersecurity-monitroting-siem0.1.01 of 3See more

siem assist-iot-cybersecurity-monitroting-siem 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
qs@6.5.2
6.16.0

Open the chart page →

10,730
dltbrokerassist-iot-distributed-broker0.2.03 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
qs@6.11.0
6.16.0
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
qs@6.5.1
6.16.0
hyperledger/fabric-couchdb:0.4.15f6c724592abf
qs@6.5.1
6.16.0

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.03 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
qs@6.11.0
6.16.0
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
qs@6.5.1
6.16.0
hyperledger/fabric-couchdb:0.4.15f6c724592abf
qs@6.5.1
6.16.0

Open the chart page →

77,687
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
qs@6.14.1
6.16.0

Open the chart page →

1,991
actualbeluga-cloudVerified publisher2.0.01 of 1See more

actual beluga-cloud 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/actual/actualserver:23.12.1c8a0d5ec5a12
qs@6.11.0
6.16.0

Open the chart page →

1,262

Container images carrying it

730 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
fanzynoodle/smeejas:0.0.15f9916c1a287
qs@6.5.2
6.16.0
1
felddy/foundryvtt:0.8.36c5d90b90349
qs@6.5.2
6.16.0
1
felipecs8/app-movies-series:v14e51693fcdf5
qs@6.13.0
6.16.0
1
felipecs8/conversor-temperatura:v1f945423be36d
qs@6.14.2
6.16.0
1
felipecs8/landing-page:v1db6d44e325a1
qs@6.13.0
6.16.0
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
qs@6.11.0
6.16.0
1
fiware/idm:8.3.3a1b6ed4ae84f
qs@6.11.0
6.16.0
1
fiware/iotagent-json:3.1.0879b21a0d36d
qs@6.10.3
6.16.0
1
fiware/iotagent-ul:1.14.0fe11f55a926d
qs@6.5.2
6.16.0
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
qs@6.5.2
6.16.0
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
qs@6.11.2
6.16.0
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
qs@6.15.3
6.16.0
1
foggbh/stocky:latest8b7a2e5ecf4e
qs@6.14.2
6.16.0
1
folioci/mod-graphql:latestf0655a6a08fd
qs@6.13.0
6.16.0
1
fonoster/routr-registry:2.13.6e27001f2813c
qs@6.13.0
6.16.0
1
fosrl/pangolin:1.13.0c32ad797ab96
qs@6.14.0
6.16.0
1
frappe/frappe-socketio:v13.4.12095767a9e82
qs@6.5.2
6.16.0
1
galaxy/galaxy-init:v18.010267bad550e6
qs@6.4.0
6.16.0
1
getferdi/ferdi-server:1.3.26e620b85afaa
qs@6.5.2
6.16.0
1
gethue/hue:4.11.011b649636e68
qs@6.5.2
6.16.0
1
gethue/hue:4.10.05702b2c37ff9
qs@6.5.2
6.16.0
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
qs@6.15.1
6.16.0
1
glenndehaan/api-mapper:latest6ff6310683bf
qs@6.5.3
6.16.0
1
glenndehaan/contentbridge:latest99b9e4f73848
qs@6.11.0
6.16.0
1
glenndehaan/kube-hook:latest0a7116f48bfe
qs@6.5.3
6.16.0
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
qs@6.7.0
6.16.0
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
qs@6.5.2
6.16.0
1
gristlabs/grist:0.7.96e71b1914a7e
qs@6.5.2
6.16.0
1
growthbook/growthbook:5.0.1f53ead646b5f
qs@6.15.2
6.16.0
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
qs@6.5.2
6.16.0
1
halkeye/hubot:latest9764d2202130
qs@6.5.2
6.16.0
1
halkeye/irslackd:latest7638bfba70b0
qs@6.5.2
6.16.0
1
hamid2021/nodejs-dockercli:latest429d99890c3c
qs@6.11.0
6.16.0
1
hansehe/graphql-gateway:1.0.458e09540afbc
qs@6.7.0
6.16.0
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
qs@6.5.2
6.16.0
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
qs@6.5.3
6.16.0
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
qs@6.11.0
6.16.0
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
qs@6.11.0
6.16.0
1
helmforge/strapi-base:5.52.270e9143d6d92
qs@6.15.3
6.16.0
1
henrywhitaker3/speedtest-tracker:latest47159a940229
qs@6.7.0
6.16.0
1
heywood8/redisinsight:2.28.00bc9ab313d37
qs@6.11.1
6.16.0
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
qs@6.7.0
6.16.0
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
qs@6.5.3
6.16.0
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
qs@6.7.0
6.16.0
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
qs@6.11.0
6.16.0
1
hoppscotch/hoppscotch:2026.8.0d50725df661f
qs@6.15.3
6.16.0
1
hugohg34/server:0.0.2503e5d8960ff
qs@6.10.3
6.16.0
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
qs@6.5.1
6.16.0
1
i4trust/pdc-portal:2.0.03e77858e1219
qs@6.5.2
6.16.0
1
ianw/quickchart:v1.7.1dc49dd460c37
qs@6.5.3
6.16.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.