StackRadar

CVE-2026-84367

Low

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.003
19th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
57
of 17,781 indexed, latest versions
Container images
54
deployed by those charts
Fix available
1 of 1
affected package

joi: object().rename() with a template target can set the validated object's prototype

Carried by container images the latest versions of 57 of 17,781 indexed charts deploy, on 54 images.

Affected packageAffected versionsFixed inImages
joinpm17.4.0, 17.4.1, 17.4.2, 17.6.0+15 more17.13.5, 18.2.454
OSV records
GHSA-gg4h-3hg2-grpc

Charts affected

57 by stars
ChartLatestAffected imagesRadar Score
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-84367.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
joi@17.13.1
17.13.5

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-84367.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
joi@17.13.1
17.13.5

Open the chart page →

16,620
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-84367.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
joi@18.0.2
18.2.4

Open the chart page →

2,028
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-84367.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
joi@17.13.3
17.13.5

Open the chart page →

4,768
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84367.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
joi@18.0.2
18.2.4

Open the chart page →

4,305
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-84367.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
joi@18.2.1
18.2.4

Open the chart page →

280
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-84367.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
joi@17.13.3
17.13.5

Open the chart page →

6,285

Container images carrying it

54 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
joi@17.8.3
17.13.5
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
joi@17.8.4
17.13.5
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
joi@17.13.3
17.13.5
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
joi@17.11.0
17.13.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.