StackRadar

CVE-2026-86253

Medium

Advisory

Published 18 Mar 2026In the index since 10 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
8
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read

Carried by container images the latest versions of 8 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
h3npm1.8.2, 1.10.0, 1.10.2, 1.12.0+2 more1.15.67
OSV records
GHSA-wr4h-v87w-p3r7

Charts affected

8 by stars
ChartLatestAffected imagesRadar Score
homarroben01Verified publisher1.4.01 of 1See more

homarr oben01 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-86253.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
h3@1.10.0
1.15.6

Open the chart page →

2,581
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-86253.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
h3@1.10.2
1.15.6

Open the chart page →

32,501
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-86253.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
h3@1.8.2
1.15.6

Open the chart page →

4,560
wireguardnicklasfrahm-wireguard0.2.01 of 1See more

wireguard nicklasfrahm-wireguard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-86253.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
h3@1.12.0
1.15.6

Open the chart page →

1,157
wg-easyrm3lVerified publisher0.2.01 of 1See more

wg-easy rm3l 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-86253.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
h3@1.12.0
1.15.6

Open the chart page →

1,157
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-86253.

Container imageDigestPackageFixed in
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
h3@1.13.0
1.15.6

Open the chart page →

15,635
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-86253.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
h3@1.10.0
1.15.6

Open the chart page →

2,789
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-86253.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
h3@1.15.1
1.15.6

Open the chart page →

5,984

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
h3@1.12.0
1.15.6
2
moonrailgun/tianji:1.11.2b528c8f8fcc4
h3@1.8.2
1.15.6
1
sigp/siren:v3.0.42c219b04758e
h3@1.15.1
1.15.6
1
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
h3@1.13.0
1.15.6
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
h3@1.10.0
1.15.6
1
ghcr.io/ajnart/homarr:lateste103abadfb52
h3@1.10.0
1.15.6
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
h3@1.10.2
1.15.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.