StackRadar

CVE-2026-84368

Low

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
63
of 17,781 indexed, latest versions
Container images
58
deployed by those charts
Fix available
1 of 2
affected packages

joi: Prototype pollution via a `__proto__` language key in custom messages

Carried by container images the latest versions of 63 of 17,781 indexed charts deploy, on 58 images.

Affected packageAffected versionsFixed inImages
joinpm17.4.0, 17.4.1, 17.4.2, 17.6.0+15 more17.13.6, 18.2.554
@hapi/joinpm16.1.8, 17.1.1no fix listed8
OSV records
GHSA-6w3j-5fw6-r9vr

Charts affected

63 by stars
ChartLatestAffected imagesRadar Score
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
joi@18.0.1
18.2.5

Open the chart page →

2,457
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
joi@17.11.0
17.13.6

Open the chart page →

25,704
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
joi@17.7.0
17.13.6

Open the chart page →

30,363
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
joi@17.12.0
17.13.6

Open the chart page →

6,982
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
joi@17.11.0
17.13.6

Open the chart page →

6,282
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
joi@17.11.0
17.13.6

Open the chart page →

7,413
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
joi@17.13.1
17.13.6

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
joi@17.13.1
17.13.6

Open the chart page →

16,620
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
joi@18.0.2
18.2.5

Open the chart page →

2,028
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
joi@17.13.3
17.13.6

Open the chart page →

4,768
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
joi@18.0.2
18.2.5

Open the chart page →

4,305
opensearch-dashboardswenerme3.8.01 of 1See more

opensearch-dashboards wenerme 3.8.0

1 of the 1 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
joi@18.2.1
18.2.5

Open the chart page →

280
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-84368.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
joi@17.13.3
17.13.6

Open the chart page →

6,285

Container images carrying it

58 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
@hapi/joi@16.1.8
joi@17.4.0
no fix listed
17.13.6
5
decisionrules/server:latestf38d8571fa06
joi@17.13.4
17.13.6
4
assistiot/dlt_api:2.0.0e36a8922fa0c
@hapi/joi@17.1.1
no fix listed
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
@hapi/joi@17.1.1
joi@17.4.2
no fix listed
17.13.6
3
gjeanmart/safe-ganache-node:latest926264c8f2d1
joi@17.13.1
17.13.6
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
@hapi/joi@17.1.1
joi@17.4.0
no fix listed
17.13.6
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
@hapi/joi@17.1.1
joi@17.4.0
no fix listed
17.13.6
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
joi@17.13.3
17.13.6
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
joi@17.13.3
17.13.6
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
joi@17.12.0
17.13.6
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
joi@18.0.1
18.2.5
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
joi@17.7.0
17.13.6
2
opensearchproject/opensearch-dashboards:3.8.0ca28e40a095f
joi@18.2.1
18.2.5
2
apimap/developer:v1.3.1406d3858e20c
joi@17.6.0
17.13.6
1
apimap/portal:v2.4.0041a4790c65c
joi@17.6.0
17.13.6
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
@hapi/joi@16.1.8
no fix listed
1
assistiot/dlt_api:2.1.0c8a170683be7
@hapi/joi@17.1.1
no fix listed
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
joi@17.6.0
17.13.6
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
joi@17.6.0
17.13.6
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
joi@17.6.0
17.13.6
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
joi@17.4.2
17.13.6
1
budibase/apps:3.41.344fe6feab985
joi@18.2.1
18.2.5
1
budibase/worker:3.41.3de5e2e560ce8
joi@18.2.1
18.2.5
1
cryptexlabs/authf:0.12.11189c07411d7c
joi@17.13.3
17.13.6
1
directus/directus:12.0.29c8470ea465c
joi@18.0.1
18.2.5
1
directus/directus:11.1.0e3c8bb975350
joi@17.13.3
17.13.6
1
fallenbagel/jellyseerr:latest4538137bc5af
joi@17.13.3
17.13.6
1
globalping/globalping-probe:latest8acbd23009fd
joi@17.13.3
17.13.6
1
heywood8/redisinsight:2.28.00bc9ab313d37
joi@17.9.2
17.13.6
1
joplin/server:3.0-beta52af57880c0e
joi@17.11.0
17.13.6
1
joplin/server:2.14.2-betab87564ef34e9
joi@17.11.0
17.13.6
1
kubevious/backend:1.2.22d9ba6eb46b6
joi@17.9.2
17.13.6
1
kubevious/collector:1.2.1f58226f9d84e
joi@17.9.2
17.13.6
1
kubevious/guard:1.2.19bf567704de2
joi@17.6.0
17.13.6
1
kubevious/parser:1.0.151acf1a1f0b47
joi@17.4.1
17.13.6
1
kubevious/parser:1.2.299ae7a5168c2
joi@17.9.2
17.13.6
1
kubevious/workload-operator:1.0.20b0f4c507eb6
joi@17.9.1
17.13.6
1
library/kibana:7.17.150172f1c538e7
joi@17.7.1
17.13.6
1
library/kibana:8.18.004c0fc150f3a
joi@17.13.3
17.13.6
1
library/kibana:7.17.8c5781ba340ef
joi@17.4.0
17.13.6
1
library/kibana:7.17.3e2e2031c15be
joi@17.4.0
17.13.6
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
joi@17.11.0
17.13.6
1
neoskop/papergirl:3.2.67f52b5949f03
joi@17.12.0
17.13.6
1
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
joi@17.13.3
17.13.6
1
rocketadmin/rocketadmin:1.17.710955ef540b9
joi@18.1.2
18.2.5
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
joi@17.4.1
17.13.6
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
joi@18.0.2
18.2.5
1
unleashorg/unleash-server:7.5.09adb37e399ba
joi@18.0.2
18.2.5
1
vcnngr/pnbackend:latesteaf44ad0ad1f
joi@17.13.3
17.13.6
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
joi@18.0.2
18.2.5
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.