StackRadar

CVE-2026-84375

High

Advisory

Published 2 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
500
of 17,781 indexed, latest versions
Container images
492
deployed by those charts
Fix available
1 of 2
affected packages

js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources

Carried by container images the latest versions of 500 of 17,781 indexed charts deploy, on 492 images.

Affected packageAffected versionsFixed inImages
js-yamlnpm3.5.5, 3.6.1, 3.7.0, 3.9.1+15 more3.15.2, 4.3.2492
node-js-yamldeb4.1.0+dfsg+~4.0.5-7no fix listed1
OSV records
GHSA-2883-xcg3-v3hhUBUNTU-CVE-2026-84375

Charts affected

500 by stars
ChartLatestAffected imagesRadar Score
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
js-yaml@4.1.0
4.3.2

Open the chart page →

5,228
dashykrzwiatrzyk1.0.01 of 1See more

dashy krzwiatrzyk 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
js-yaml@3.14.1
3.15.2

Open the chart page →

3,143
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
langgenius/dify-web:0.6.11a2a294743634
js-yaml@4.1.0
4.3.2

Open the chart page →

20,403
chibisafel4gVerified publisher0.1.12 of 3See more

chibisafe l4g 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
chibisafe/chibisafe:latest836467a50792
js-yaml@4.1.0
4.3.2
chibisafe/chibisafe-server:latest3da4fcbc1a18
js-yaml@4.1.0
4.3.2

Open the chart page →

5,654
litlyxlitlyx0.2.02 of 5See more

litlyx litlyx 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
js-yaml@3.13.1
3.15.2
litlyx/litlyx-dashboard:lateste64ff2d52385
js-yaml@4.1.1
4.3.2

Open the chart page →

7,874
chatwootmaxcrm-chartsVerified publisher1.1.2011 of 4See more

chatwoot maxcrm-charts 1.1.201

1 of the 4 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v3.1.0d530ab8c1753
js-yaml@3.14.1
3.15.2

Open the chart page →

5,940
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
js-yaml@4.1.0
4.3.2

Open the chart page →

13,738
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
js-yaml@4.1.1
4.3.2

Open the chart page →

2,575
open-api-discoveryopen-api-discoveryVerified publisher0.1.11 of 1See more

open-api-discovery open-api-discovery 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
lukasreining/open-api-schema-collector:0.1.050e021c42e33
js-yaml@4.1.0
4.3.2

Open the chart page →

2,473
librechatopenshift1.9.01 of 3See more

librechat openshift 1.9.0

1 of the 3 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
js-yaml@3.13.1
3.15.2

Open the chart page →

5,779
patchworkpatchworkVerified publisher0.8.61 of 2See more

patchwork patchwork 0.8.6

1 of the 2 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/patchwork:mainc01e018bced4
js-yaml@4.1.0
4.3.2

Open the chart page →

2,083
pdf-editor-helmpdf-editor-web1.0.01 of 4See more

pdf-editor-helm pdf-editor-web 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
dipugodocker/pdf-editor:1.0-frontendd431c37fe1cd
js-yaml@3.14.1
3.15.2

Open the chart page →

4,206
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
js-yaml@4.1.1
4.3.2

Open the chart page →

7,035
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
js-yaml@4.1.0
4.3.2
treskon/portrait-ui:DEV-lateste7970783bc8d
js-yaml@4.1.0
4.3.2

Open the chart page →

31,844
psa-restricted-patcherpsa-restricted-patcherVerified publisher0.10.11 of 1See more

psa-restricted-patcher psa-restricted-patcher 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/psa-restricted-patcher:maina53ef16b024a
js-yaml@4.1.0
4.3.2

Open the chart page →

1,401
pumejwebapppumejnodejswebapp0.1.01 of 1See more

pumejwebapp pumejnodejswebapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
pumejlab/nodejs-webapp:latestf563eabcb819
js-yaml@4.1.0
4.3.2

Open the chart page →

1,164
flamerlex0.3.01 of 1See more

flame rlex 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
pawelmalak/flame:2.1.193e7b0abb603
js-yaml@4.1.0
4.3.2

Open the chart page →

2,449
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
js-yaml@3.14.2
3.15.2

Open the chart page →

5,482
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
js-yaml@3.14.1
3.15.2

Open the chart page →

6,879
jellyseerrrtomik-helm-chartsVerified publisher0.0.11 of 1See more

jellyseerr rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
js-yaml@4.1.0
4.3.2

Open the chart page →

2,823
immichsecustorVerified publisher2.0.41 of 1See more

immich secustor 2.0.4

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
js-yaml@4.3.0
4.3.2

Open the chart page →

3,059
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
js-yaml@4.1.0
4.3.2

Open the chart page →

10,380
stackradar-scannerstackradarVerified publisher0.3.01 of 1See more

stackradar-scanner stackradar 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
ghcr.io/lockdep/stackradar-scanner:0.3.0dd8a35d50c2d
js-yaml@4.3.1
4.3.2

Open the chart page →

1,209
statsdstatsd-airflow-smd0.1.191 of 1See more

statsd statsd-airflow-smd 0.1.19

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
statsd/statsd:v0.8.6dab129e74c25
js-yaml@3.13.1
3.15.2

Open the chart page →

4,185
stornxstornxVerified publisher1.1.11 of 9See more

stornx stornx 1.1.1

1 of the 9 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
js-yaml@4.1.0
4.3.2

Open the chart page →

11,574
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
supabase/storage-api:v1.60.4c8eb9858eafe
js-yaml@4.1.1
4.3.2

Open the chart page →

18,075
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
js-yaml@3.14.2
3.15.2

Open the chart page →

2,522
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
js-yaml@3.13.1
3.15.2

Open the chart page →

7,517
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
js-yaml@3.14.1
3.15.2

Open the chart page →

12,581
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
js-yaml@3.14.0
3.15.2

Open the chart page →

3,833
scrapoxywiremindVerified publisher0.3.41 of 1See more

scrapoxy wiremind 0.3.4

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
wiremind/scrapoxy:lateste7048929a676
js-yaml@3.13.1
3.15.2

Open the chart page →

2,154
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
js-yaml@3.14.0
3.15.2

Open the chart page →

9,783
trifidzazukoOfficialVerified publisher0.2.11 of 1See more

trifid zazuko 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
js-yaml@4.2.0
4.3.2

Open the chart page →

338
adeptia-automate-mcpadeptia-automate-mcp1.0.01 of 2See more

adeptia-automate-mcp adeptia-automate-mcp 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
js-yaml@4.1.1
4.3.2

Open the chart page →

3,600
admin-portaladmin-web-portal1.2.11 of 2See more

admin-portal admin-web-portal 1.2.1

1 of the 2 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
soulou2019/node-server:latest5e6ecfcc109e
js-yaml@4.1.0
4.3.2

Open the chart page →

3,419
outlineadnoctemVerified publisher0.1.21 of 1See more

outline adnoctem 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
outlinewiki/outline:1.10.1832051f039b4
js-yaml@4.3.1
4.3.2

Open the chart page →

1,216
turborepo-remote-cacheadriantr1.1.11 of 1See more

turborepo-remote-cache adriantr 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
ducktors/turborepo-remote-cache:latest31ec9e83c844
js-yaml@4.1.1
4.3.2

Open the chart page →

523
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
js-yaml@4.1.0
4.3.2

Open the chart page →

6,486
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
js-yaml@4.1.0
4.3.2

Open the chart page →

4,880
openhab-cloudandibraeuVerified publisher1.2.61 of 1See more

openhab-cloud andibraeu 1.2.6

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
openhab/openhab-cloud:a8138a329dd2bac8c4b
js-yaml@3.14.1
3.15.2

Open the chart page →

3,437
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
js-yaml@3.14.1
3.15.2

Open the chart page →

3,237
antmediaantmediaVerified publisher3.1.01 of 4See more

antmedia antmedia 3.1.0

1 of the 4 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
library/mongo:8.002a0cc7939f5
js-yaml@3.13.1
3.15.2

Open the chart page →

4,576
trifidappuio2.0.21 of 1See more

trifid appuio 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
zazuko/trifid:2.3.7054be137de70
js-yaml@3.14.1
3.15.2

Open the chart page →

2,783
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
library/mongo:latest5211c51171f5
js-yaml@3.13.1
3.15.2

Open the chart page →

8,866
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:api-latest7473d77448e1
js-yaml@3.14.1
3.15.2

Open the chart page →

9,369
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
assistiot/open_api_frontend:1.0.1f11d82defc70
js-yaml@4.1.0
4.3.2
pantsel/konga:latestc8172b75607d
js-yaml@3.13.1
3.15.2

Open the chart page →

18,277
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
js-yaml@4.1.0
4.3.2
assistiot/smart-orchestrator_enabler:latest89f37e88c871
js-yaml@4.1.0
4.3.2
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
js-yaml@4.1.0
4.3.2

Open the chart page →

45,363
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
js-yaml@4.1.0
4.3.2

Open the chart page →

32,501
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
ltdstudio/terraforming-mars:latest0e76c6f4eac0
js-yaml@4.0.0
4.3.2

Open the chart page →

7,152
awesomeblessingappawesomeblessingapp1.1.01 of 1See more

awesomeblessingapp awesomeblessingapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-84375.

Container imageDigestPackageFixed in
bnwokoye/nodejswebapp:latest74de7dc7ebfb
js-yaml@4.1.0
4.3.2

Open the chart page →

1,267

Container images carrying it

492 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
js-yaml@3.14.1
3.15.2
1
moreillon/food-manager:lateste8fd856e593d
js-yaml@4.1.0
4.3.2
1
moreillon/group-manager:latest3caa8f710ee0
js-yaml@4.1.0
4.3.2
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
js-yaml@3.14.1
3.15.2
1
mozilla/sentencecollector:2.0.91da6ff5c4895
js-yaml@3.13.1
3.15.2
1
mpopoola1/nodejsapp:latest061fc532de7d
js-yaml@4.1.0
4.3.2
1
n8nio/n8n:2.25.7761374d4eb84
js-yaml@4.1.1
4.3.2
1
n8nio/n8n:1.86.08b39ed5a2de9
js-yaml@4.1.0
4.3.2
1
n8nio/n8n:0.212.0a9195bc499a3
js-yaml@4.1.0
4.3.2
1
n8nio/n8n:2.36.8cfe2704ff858
js-yaml@4.3.1
4.3.2
1
n8nio/n8n:1.33.1dd171d45102a
js-yaml@4.1.0
4.3.2
1
neoskop/ixy:2.1.125152b474f54
js-yaml@4.1.1
4.3.2
1
neoskop/papergirl:3.2.67f52b5949f03
js-yaml@4.1.0
4.3.2
1
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
js-yaml@4.1.0
4.3.2
1
nightscout/cgm-remote-monitor:14.2.500c3b4833f1b
js-yaml@3.13.1
3.15.2
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
js-yaml@4.0.0
4.3.2
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
js-yaml@3.14.1
3.15.2
1
nocodb/nocodb:0.301.5d9516f0bf546
js-yaml@3.14.2
3.15.2
1
nodered/node-red:5.0.410f40d0a83e7
js-yaml@4.3.0
4.3.2
1
nodered/node-red:4.1.2216e7403aab9
js-yaml@4.1.1
4.3.2
1
nodered/node-red:4.1.10-minimald73ae167cb9b
js-yaml@4.1.1
4.3.2
1
nodered/node-red:2.2.2e131dcadfe92
js-yaml@3.14.1
3.15.2
1
nodered/node-red:3.0.2-18e2632a7a35dd
js-yaml@4.1.0
4.3.2
1
nodered/node-red-docker:0.19.6-v8070643219ea2
js-yaml@3.12.0
3.15.2
1
nottiey/mynodejswebapp:latest9c35a24c9eb3
js-yaml@4.1.0
4.3.2
1
obolnetwork/charon-dkg-sidecar:maine263be0a7440
js-yaml@4.1.0
4.3.2
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
js-yaml@4.1.0
4.3.2
1
okaforuchena/uo-docker:V1.0.0004e81250f48
js-yaml@4.1.0
4.3.2
1
ondrejsika/parking:latestb1fd497416c8
js-yaml@3.13.1
3.15.2
1
ooghenekaro/amazon:latest03394ba1d6d8
js-yaml@4.1.0
4.3.2
1
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
js-yaml@4.1.0
4.3.2
1
ooghenekaro/nodejswebapp:latestea5b71588a76
js-yaml@4.1.0
4.3.2
1
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
js-yaml@4.1.0
4.3.2
1
opea/codegen-ui:1.02bee4eb66f3e
js-yaml@4.1.0
4.3.2
1
openbas/caldera-server:5.1.0a277796d9724
js-yaml@4.1.0
4.3.2
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
js-yaml@3.14.1
3.15.2
1
openmined/syft-frontend:0.9.5d11524a3854a
js-yaml@4.1.0
4.3.2
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
js-yaml@3.14.1
3.15.2
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
js-yaml@3.14.1
3.15.2
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
js-yaml@3.14.1
3.15.2
1
otwld/velero-ui:0.10.2d1954b759e47
js-yaml@4.3.0
4.3.2
1
outlinewiki/outline:1.10.1832051f039b4
js-yaml@4.3.1
4.3.2
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
js-yaml@3.12.1
3.15.2
1
patdada/bella-docker:v1.0.075127147a624
js-yaml@4.1.0
4.3.2
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
js-yaml@3.14.1
3.15.2
1
pawelmalak/flame:2.1.193e7b0abb603
js-yaml@4.1.0
4.3.2
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
js-yaml@4.1.0
4.3.2
1
phntom/codimd:2.4.31b9aafbb62e6
js-yaml@3.13.1
3.15.2
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
js-yaml@4.1.1
4.3.2
1
plumdog/db-operator:latest0c2fa2db0357
js-yaml@3.14.1
3.15.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.