StackRadar

CVE-2026-82417

Medium

Advisory

Published 31 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
726
of 17,781 indexed, latest versions
Container images
730
deployed by those charts
Fix available
1 of 2
affected packages

qs: Denial of Service via Attacker Controlled isBuffer

Carried by container images the latest versions of 726 of 17,781 indexed charts deploy, on 730 images.

Affected packageAffected versionsFixed inImages
qsnpm2.3.3, 5.2.0, 6.2.1, 6.3.0+31 more6.16.0730
node-qsdeb2.2.4-1, 2.2.4-1ubuntu1, 6.9.1+ds-1no fix listed5
OSV records
GHSA-4mjr-xmp4-gh2gUBUNTU-CVE-2026-82417

Charts affected

726 by stars
ChartLatestAffected imagesRadar Score
opensearch-dashboardscaptnbpVerified publisher2.2.11 of 1See more

opensearch-dashboards captnbp 2.2.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
qs@6.10.4
6.16.0

Open the chart page →

1,843
fluxcd-webuiccowleyVerified publisher0.0.21 of 2See more

fluxcd-webui ccowley 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
adrianberger/fluxcd-webui:latest76848c0d2780
qs@6.5.2
6.16.0

Open the chart page →

3,509
home-assistant-matter-servercharts-derwitt-devVerified publisher4.2.11 of 2See more

home-assistant-matter-server charts-derwitt-dev 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
qs@6.15.3
6.16.0

Open the chart page →

2,360
node-redcharts-derwitt-devVerified publisher2.1.21 of 1See more

node-red charts-derwitt-dev 2.1.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
nodered/node-red:5.0.7a649dd711d55
qs@6.15.3
6.16.0

Open the chart page →

101
maildevchristianhuthVerified publisher1.6.01 of 1See more

maildev christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
maildev/maildev:2.2.1180ef51f65ee
qs@6.13.0
6.16.0

Open the chart page →

1,143
skoonerchristianhuthVerified publisher0.4.01 of 1See more

skooner christianhuth 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
qs@6.11.0
6.16.0

Open the chart page →

1,341
squestchristianhuthVerified publisher6.6.71 of 4See more

squest christianhuth 6.6.7

1 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
quay.io/hewlettpackardenterprise/squest:2.8.465694109877e
qs@6.9.4
6.16.0

Open the chart page →

9,971
data-fairdata354-helmVerified publisher1.1.28 of 12See more

data-fair data354-helm 1.1.2

8 of the 12 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
koumoul/capture:17108d47be3b2
qs@6.5.2
6.16.0
koumoul/openapi-viewer:18eeca2e8285b
qs@6.5.1
6.16.0
ghcr.io/data-fair/data-fair:3cc9498b64b5b
qs@6.5.3
6.16.0
ghcr.io/data-fair/metrics:0a8d40779eeae
qs@6.10.3
6.16.0
ghcr.io/data-fair/notify:3c739b74dabb0
qs@6.13.0
6.16.0
ghcr.io/data-fair/portals:18b621866ceb2
qs@6.15.3
6.16.0
ghcr.io/data-fair/processings:15a9216989707
qs@6.11.0
6.16.0
ghcr.io/data-fair/simple-directory:438a4f32fad82
qs@6.10.3
6.16.0

Open the chart page →

38,346
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
qs@6.11.0
6.16.0

Open the chart page →

5,056
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
qs@6.15.2
6.16.0

Open the chart page →

7,473
jellystatdjjudas21Verified publisher0.1.121 of 1See more

jellystat djjudas21 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
qs@6.15.2
6.16.0

Open the chart page →

1,722
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
qs@6.11.0
6.16.0

Open the chart page →

3,925
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
qs@6.13.0
6.16.0

Open the chart page →

5,670
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-82417.

Open the chart page →

31,510
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
qs@6.14.2
6.16.0

Open the chart page →

1,442
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
qs@6.5.3
6.16.0

Open the chart page →

11,458
recaptcha-v3-verifierf3k-techVerified publisher1.110.01 of 1See more

recaptcha-v3-verifier f3k-tech 1.110.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
f3ktech/recaptcha-v3-verifier:1.1.048e78987cf91
qs@6.14.0
6.16.0

Open the chart page →

1,208
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
qs@6.7.0
6.16.0

Open the chart page →

2,519
foundryvttgeek-cookbookVerified publisher3.4.21 of 1See more

foundryvtt geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
felddy/foundryvtt:0.8.36c5d90b90349
qs@6.5.2
6.16.0

Open the chart page →

2,042
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
qs@6.9.7
6.16.0

Open the chart page →

4,260
magic-mirrorgeek-cookbookVerified publisher4.4.21 of 1See more

magic-mirror geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
qs@6.5.2
6.16.0

Open the chart page →

4,405
overseerrgeek-cookbookVerified publisher5.4.21 of 1See more

overseerr geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/sct/overseerr:1.26.1254d16af8f71
qs@6.7.0
6.16.0

Open the chart page →

3,444
recipesgeek-cookbookVerified publisher6.6.21 of 2See more

recipes geek-cookbook 6.6.2

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
vabene1111/recipes:1.0.5.2ec4e9e2905b0
qs@6.5.2
6.16.0

Open the chart page →

7,801
sendgeek-cookbookVerified publisher1.2.21 of 1See more

send geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
registry.gitlab.com/timvisee/send:v3.4.2047986cf6ef69
qs@6.10.3
6.16.0

Open the chart page →

1,148
tdarrgeek-cookbookVerified publisher4.6.21 of 2See more

tdarr geek-cookbook 4.6.2

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.00.101e3f9328327d
qs@6.5.2
6.16.0

Open the chart page →

31,000
uptime-kumageek-cookbookVerified publisher1.4.21 of 1See more

uptime-kuma geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.17.1a4eab252e5a2
qs@6.5.3
6.16.0

Open the chart page →

5,079
uptimerobotgeek-cookbookVerified publisher3.0.41 of 1See more

uptimerobot geek-cookbook 3.0.4

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
qs@6.5.2
6.16.0

Open the chart page →

1,669
youtubedl-materialgeek-cookbookVerified publisher4.4.21 of 1See more

youtubedl-material geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.23720b856bd2f
qs@6.5.2
6.16.0

Open the chart page →

4,410
zigbee2mqttgeek-cookbookVerified publisher9.4.21 of 1See more

zigbee2mqtt geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
qs@6.5.2
6.16.0

Open the chart page →

2,173
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
qs@6.15.1
6.16.0

Open the chart page →

3,123
ghostgroundhog2k0.212.121 of 1See more

ghost groundhog2k 0.212.12

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
qs@6.15.3
6.16.0

Open the chart page →

2,000
growthbookgrowthbook5.0.11 of 2See more

growthbook growthbook 5.0.1

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
growthbook/growthbook:5.0.1f53ead646b5f
qs@6.15.2
6.16.0

Open the chart page →

709
uptimekumahelm-l3st86Verified publisher0.1.101 of 1See more

uptimekuma helm-l3st86 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.23.1396510915e6be
qs@6.11.0
6.16.0

Open the chart page →

4,196
openprojecthomeenterpriseinc0.5.01 of 1See more

openproject homeenterpriseinc 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
openproject/community:12.0.2734743d11094
qs@6.5.2
6.16.0

Open the chart page →

6,810
pdc-portali4trustVerified publisher2.3.21 of 1See more

pdc-portal i4trust 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
i4trust/pdc-portal:2.0.03e77858e1219
qs@6.5.2
6.16.0

Open the chart page →

2,723
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
qs@6.14.0
6.16.0

Open the chart page →

15,712
todo-appjunktext-direct1.1.41 of 1See more

todo-app junktext-direct 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
junktext/getting-started:1.0.5a70936c04aed
qs@6.7.0
6.16.0

Open the chart page →

3,369
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
qs@6.13.0
6.16.0

Open the chart page →

5,228
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
qs@6.5.3
6.16.0

Open the chart page →

3,143
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
qs@6.5.2
6.16.0

Open the chart page →

20,403
lifecycle-jira-integrationlifecycle-jira-integration1.0.01 of 1See more

lifecycle-jira-integration lifecycle-jira-integration 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
anoopnair/lifecycle-jira-integration:latestd80c73a6089d
qs@6.9.7
6.16.0

Open the chart page →

927
litlyxlitlyx0.2.02 of 5See more

litlyx litlyx 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
litlyx/litlyx-consumer:latest02225e77d316
qs@6.13.0
6.16.0
litlyx/litlyx-producer:latest10407f36613f
qs@6.13.0
6.16.0

Open the chart page →

7,874
actualbudgetm0nsterrr-actualbudgetVerified publisher2.10.01 of 1See more

actualbudget m0nsterrr-actualbudget 2.10.0

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
qs@6.15.2
6.16.0

Open the chart page →

1,091
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
qs@6.5.2
6.16.0

Open the chart page →

5,940
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.12 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

2 of the 6 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
qs@6.5.2
6.16.0
fjvela/urjc-fjvela-server:1.0.53c840aebce22
qs@6.5.2
6.16.0

Open the chart page →

19,187
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
qs@6.13.0
6.16.0

Open the chart page →

13,738
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
qs@6.14.2
6.16.0

Open the chart page →

2,575
kuttone-acre-fundVerified publisher0.2.51 of 1See more

kutt one-acre-fund 0.2.5

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
kutt/kutt:latestfa3d24a89b04
qs@6.15.2
6.16.0

Open the chart page →

454
open5gs-webuiopen5gs-webuiVerified publisher2.3.11 of 2See more

open5gs-webui open5gs-webui 2.3.1

1 of the 2 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
qs@6.11.0
6.16.0

Open the chart page →

5,300
open-api-discoveryopen-api-discoveryVerified publisher0.1.11 of 1See more

open-api-discovery open-api-discovery 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-82417.

Container imageDigestPackageFixed in
lukasreining/open-api-schema-collector:0.1.050e021c42e33
qs@6.5.3
6.16.0

Open the chart page →

2,473

Container images carrying it

730 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ondrejsika/parking:latestb1fd497416c8
qs@6.5.2
6.16.0
1
ooghenekaro/amazon:latest03394ba1d6d8
qs@6.11.0
6.16.0
1
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
qs@6.11.0
6.16.0
1
ooghenekaro/nodejswebapp:latestea5b71588a76
qs@6.11.0
6.16.0
1
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
qs@6.11.0
6.16.0
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
qs@6.11.0
6.16.0
1
openproject/community:12.0.2734743d11094
qs@6.5.2
6.16.0
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
qs@6.10.5
6.16.0
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
qs@6.10.4
6.16.0
1
openthread/otbr:latestf307f59f6432
node-qs@2.2.4-1ubuntu1
qs@5.2.0
no fix listed
6.16.0
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
qs@6.5.2
6.16.0
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
node-qs@2.2.4-1ubuntu1
qs@5.2.0
no fix listed
6.16.0
1
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
qs@6.7.0
6.16.0
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
qs@6.13.0
6.16.0
1
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
qs@6.14.2
6.16.0
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
qs@6.11.0
6.16.0
1
otwld/velero-ui:0.10.2d1954b759e47
qs@6.15.3
6.16.0
1
outlinewiki/outline:0.82.0494dfb9249a6
qs@6.9.7
6.16.0
1
pachyderm/grpc-proxy:0.4.92b27f41d4d02
qs@6.5.2
6.16.0
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
qs@2.3.3
6.16.0
1
patdada/bella-docker:v1.0.075127147a624
qs@6.5.3
6.16.0
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
qs@6.5.2
6.16.0
1
pawelmalak/flame:2.1.193e7b0abb603
qs@6.7.0
6.16.0
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
qs@6.11.0
6.16.0
1
penpotapp/exporter:2.2.15c835ffd87ab
qs@6.12.1
6.16.0
1
penpotapp/mcp:2.17.284f3f07ead11
qs@6.15.3
6.16.0
1
phntom/camo:2.3.1a9b1304d6c71
qs@6.5.2
6.16.0
1
phntom/codimd:2.4.31b9aafbb62e6
qs@6.5.2
6.16.0
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
qs@6.14.1
6.16.0
1
plumdog/db-operator:latest0c2fa2db0357
qs@6.5.2
6.16.0
1
polonel/trudesk:1.2.60cf6513f6fe3
qs@6.10.3
6.16.0
1
project2team4/react:latest3ff031a08887
qs@6.5.2
6.16.0
1
promasu/cryptpad:v4.14.1-nginx51d1142b9f95
qs@6.5.2
6.16.0
1
pumejlab/nodejs-webapp:latestf563eabcb819
qs@6.11.0
6.16.0
1
punkerside/noroot:v0.0.7be20c81d6ca1
qs@6.10.3
6.16.0
1
pysga1996/python-redis-web:latestfdeec30ad482
qs@6.7.0
6.16.0
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
qs@6.14.0
6.16.0
1
rakii8585/angular-node-webapp:latest026082a515ac
qs@6.7.0
6.16.0
1
redis/redisinsight:2.68019fcf774631
qs@6.13.0
6.16.0
1
redis/redisinsight:3.2.055542a762210
qs@6.13.0
6.16.0
1
redis/redisinsight:2.46699d341bd329
qs@6.11.0
6.16.0
1
redis/redisinsight:3.485562d67a912
qs@6.13.0
6.16.0
1
refar/apm-portal:v5.7.1dcca8e4477a6
qs@6.5.2
6.16.0
1
requarks/wiki:canary-2.5.2438b5865a7386c
qs@6.5.2
6.16.0
1
rlex/jsonvisio:1.9.5cd50ff65118e
qs@6.5.2
6.16.0
1
roadiehq/community-backstage-image:latestef355bf5b639
qs@6.7.0
6.16.0
1
robotshop/rs-cart:latest388349d5cb3c
qs@6.5.2
6.16.0
1
robotshop/rs-catalogue:latestd545747c1b97
qs@6.7.0
6.16.0
1
robotshop/rs-user:latestea509182c180
qs@6.5.2
6.16.0
1
rocketadmin/rocketadmin:1.17.710955ef540b9
qs@6.15.1
6.16.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.