StackRadar

CVE-2026-84997

High

Advisory

Published 17 Sept 2026In the index since 18 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
50th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,985 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

react/http: A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU

Carried by container images the latest versions of 9 of 17,985 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
react/httpcomposerv1.4.0, v1.5.0, v1.9.0, v1.10.0+1 more1.11.17
OSV records
GHSA-x424-64qh-5j54

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
repmanszpadel-chartsVerified publisher3.52.171 of 3See more

repman szpadel-charts 3.52.17

1 of the 3 container images this version deploys carry CVE-2026-84997.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
react/http@v1.5.0
1.11.1

Open the chart page →

7,496
repmanrepman-helmchartVerified publisher1.0.121 of 3See more

repman repman-helmchart 1.0.12

1 of the 3 container images this version deploys carry CVE-2026-84997.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
react/http@v1.5.0
1.11.1

Open the chart page →

3,685
redirectwyrihaximusnetVerified publisher1.1.01 of 1See more

redirect wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-84997.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
react/http@v1.10.0
1.11.1

Open the chart page →

1,621
supportpalevilgn0me0.1.61 of 1See more

supportpal evilgn0me 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-84997.

Container imageDigestPackageFixed in
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
react/http@v1.4.0
1.11.1

Open the chart page →

21,705
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-84997.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
react/http@v1.11.0
1.11.1

Open the chart page →

10,527
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-84997.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
react/http@v1.9.0
1.11.1

Open the chart page →

53,077
icingawebsvtech-public-helm-charts1.0.01 of 2See more

icingaweb svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-84997.

Container imageDigestPackageFixed in
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
react/http@v1.9.0
1.11.1

Open the chart page →

2,077
repmanteam-blueVerified publisher0.3.01 of 5See more

repman team-blue 0.3.0

1 of the 5 container images this version deploys carry CVE-2026-84997.

Container imageDigestPackageFixed in
buddy/repman:1.4.0097c897f8b54
react/http@v1.5.0
1.11.1

Open the chart page →

4,105
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-84997.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
react/http@v1.5.0
1.11.1

Open the chart page →

2,561

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
buddy/repman:1.4.0097c897f8b54
react/http@v1.5.0
1.11.1
3
jordan/icinga2:latestf75025fe8ea8
react/http@v1.11.0
1.11.1
1
svtechnmaa/svtech_icingaweb2:v1.0.2a59d0b81dde2
react/http@v1.9.0
1.11.1
1
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
react/http@v1.9.0
1.11.1
1
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
react/http@v1.5.0
1.11.1
1
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
react/http@v1.10.0
1.11.1
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
react/http@v1.4.0
1.11.1
1

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.