StackRadar

CVE-2026-85730

High

Advisory

Published 9 Sept 2026In the index since 10 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

smol-toml: Denial of Service via malformed TOML documents

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
smol-tomlnpm1.5.2, 1.6.11.7.17
OSV records
GHSA-7w5x-hrqm-74c2

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
pretixtechwolf12Verified publisher2026.7.01 of 3See more

pretix techwolf12 2026.7.0

1 of the 3 container images this version deploys carry CVE-2026-85730.

Container imageDigestPackageFixed in
pretix/standalone:2026.7.05df3b7aa852e
smol-toml@1.6.1
1.7.1

Open the chart page →

9,770
rocketadminrocketadminOfficialVerified publisher1.0.421 of 1See more

rocketadmin rocketadmin 1.0.42

1 of the 1 container images this version deploys carry CVE-2026-85730.

Container imageDigestPackageFixed in
rocketadmin/rocketadmin:1.17.710955ef540b9
smol-toml@1.6.1
1.7.1

Open the chart page →

5,482
tenuretenureVerified publisher1.0.61 of 2See more

tenure tenure 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-85730.

Container imageDigestPackageFixed in
tenureai/tenure:v1.0.285f5b222df9a5
smol-toml@1.6.1
1.7.1

Open the chart page →

2,522
web-checkhajowielandVerified publisher1.0.11 of 1See more

web-check hajowieland 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-85730.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
smol-toml@1.6.1
1.7.1

Open the chart page →

9,047
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-85730.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
smol-toml@1.6.1
1.7.1

Open the chart page →

9,047
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-85730.

Container imageDigestPackageFixed in
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
smol-toml@1.5.2
1.7.1

Open the chart page →

5,819
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-85730.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
smol-toml@1.6.1
1.7.1

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-85730.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
smol-toml@1.6.1
1.7.1

Open the chart page →

919
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-85730.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
smol-toml@1.6.1
1.7.1

Open the chart page →

3,972

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
smol-toml@1.6.1
1.7.1
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
smol-toml@1.6.1
1.7.1
2
pretix/standalone:2026.7.05df3b7aa852e
smol-toml@1.6.1
1.7.1
1
rocketadmin/rocketadmin:1.17.710955ef540b9
smol-toml@1.6.1
1.7.1
1
tensorzero/ui:2026.6.0f2563d54724e
smol-toml@1.6.1
1.7.1
1
tenureai/tenure:v1.0.285f5b222df9a5
smol-toml@1.6.1
1.7.1
1
ghcr.io/rybbit-io/rybbit-backend:lateste0d1b397e33c
smol-toml@1.5.2
1.7.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.