StackRadar

CVE-2026-8723

Medium

Advisory

Published 17 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
212
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
1 of 2
affected packages

qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set

Carried by container images the latest versions of 212 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
qsnpm6.11.1, 6.11.2, 6.12.0, 6.12.1+6 more6.15.2201
node-qsdeb2.2.4-1, 2.2.4-1ubuntu1, 6.9.1+ds-1no fix listed5
OSV records
GHSA-q8mj-m7cp-5q26UBUNTU-CVE-2026-8723

Charts affected

212 by stars
ChartLatestAffected imagesRadar Score
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
qs@6.14.2
6.15.2

Open the chart page →

30,159
node-rednode-redVerified publisher0.40.21 of 1See more

node-red node-red 0.40.2

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
nodered/node-red:4.1.2216e7403aab9
qs@6.13.0
6.15.2

Open the chart page →

2,172
unleashunleash5.6.81 of 2See more

unleash unleash 5.6.8

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
unleashorg/unleash-server:7.5.09adb37e399ba
qs@6.14.2
6.15.2

Open the chart page →

2,059
lemmyananace-chartsVerified publisher0.6.151 of 5See more

lemmy ananace-charts 0.6.15

1 of the 5 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
dessalines/lemmy-ui:0.19.20ee4c620d8e93
qs@6.13.0
6.15.2

Open the chart page →

7,210
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
qs@6.13.0
6.15.2

Open the chart page →

8,364
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
qs@6.14.2
6.15.2

Open the chart page →

5,660
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
qs@6.14.1
6.15.2

Open the chart page →

3,004
budibasebudibase0.0.0-master2 of 7See more

budibase budibase 0.0.0-master

2 of the 7 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
qs@6.15.1
6.15.2
budibase/worker:3.41.3de5e2e560ce8
qs@6.15.0
6.15.2

Open the chart page →

10,775
n8nn8n0.23.01 of 1See more

n8n n8n 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
n8nio/n8n:1.33.1dd171d45102a
qs@6.11.2
6.15.2

Open the chart page →

5,639
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
qs@6.13.0
6.15.2

Open the chart page →

30,326
homarroben01Verified publisher1.4.01 of 1See more

homarr oben01 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
qs@6.11.2
6.15.2

Open the chart page →

2,581
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
qs@6.14.2
6.15.2

Open the chart page →

5,564
redisinsightheywood8-helm-chartsVerified publisher0.4.51 of 1See more

redisinsight heywood8-helm-charts 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
heywood8/redisinsight:2.28.00bc9ab313d37
qs@6.11.1
6.15.2

Open the chart page →

2,828
redisinsightredisinsight-guiVerified publisher1.3.51 of 1See more

redisinsight redisinsight-gui 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
redis/redisinsight:3.8b5e19ee240ab
qs@6.14.0
6.15.2

Open the chart page →

1,038
redisinsight-secureredisinsight-secureVerified publisher1.0.21 of 1See more

redisinsight-secure redisinsight-secure 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
redis/redisinsight:2.68019fcf774631
qs@6.13.0
6.15.2

Open the chart page →

1,721
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
qs@6.14.2
6.15.2

Open the chart page →

1,339
librechatlibrechat1.8.101 of 3See more

librechat librechat 1.8.10

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
qs@6.13.0
6.15.2

Open the chart page →

2,654
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
qs@6.12.1
6.15.2

Open the chart page →

7,450
community-solid-servercommunity-solid-server3.0.01 of 1See more

community-solid-server community-solid-server 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
solidproject/community-server:6.0.2ccc4acb7e9a1
qs@6.11.1
6.15.2

Open the chart page →

1,613
convertigoconvertigoOfficialVerified publisher8.4.31 of 5See more

convertigo convertigo 8.4.3

1 of the 5 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
baserow/baserow:1.30.1df0c42eb67e8
qs@6.11.2
6.15.2

Open the chart page →

17,404
cosmocosmo-platformOfficialVerified publisher0.20.01 of 10See more

cosmo cosmo-platform 0.20.0

1 of the 10 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
qs@6.11.2
6.15.2

Open the chart page →

28,839
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
qs@6.13.0
6.15.2

Open the chart page →

3,451
nightscoutgabe565Verified publisher0.13.01 of 2See more

nightscout gabe565 0.13.0

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
qs@6.11.2
6.15.2

Open the chart page →

2,521
rsshubgabe565Verified publisher0.8.01 of 3See more

rsshub gabe565 0.8.0

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
diygod/rsshub:latest1d4b508b6357
qs@6.14.2
6.15.2

Open the chart page →

1,717
bitwarden-crd-operatorlerentisVerified publisher0.18.01 of 1See more

bitwarden-crd-operator lerentis 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
qs@6.15.0
6.15.2

Open the chart page →

2,003
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
qs@6.11.2
6.15.2

Open the chart page →

2,635
kratos-selfservice-ui-nodeory0.64.01 of 1See more

kratos-selfservice-ui-node ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
qs@6.14.2
6.15.2

Open the chart page →

1,966
pacmanpacmanVerified publisher2.0.21 of 2See more

pacman pacman 2.0.2

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/shuguet/pacman:latesta0ec71732c3c
qs@6.14.2
6.15.2

Open the chart page →

638
feedbacksystemthm-mni-iiVerified publisher0.47.11 of 10See more

feedbacksystem thm-mni-ii 0.47.1

1 of the 10 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
thmmniii/fbs-qcm-backend:v1.27.1afbe511e5c24
qs@6.13.0
6.15.2

Open the chart page →

28,534
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
qs@6.15.0
6.15.2

Open the chart page →

4,016
aapbaapbVerified publisher0.1.31 of 1See more

aapb aapb 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
qs@6.14.1
6.15.2

Open the chart page →

1,044
seerrbdclark-helm-chartsVerified publisher0.1.51 of 1See more

seerr bdclark-helm-charts 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
qs@6.14.1
6.15.2

Open the chart page →

1,991
maildevchristianhuthVerified publisher1.6.01 of 1See more

maildev christianhuth 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
maildev/maildev:2.2.1180ef51f65ee
qs@6.13.0
6.15.2

Open the chart page →

1,143
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/data-fair/notify:3c739b74dabb0
qs@6.13.0
6.15.2

Open the chart page →

38,346
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
qs@6.11.2
6.15.2

Open the chart page →

3,925
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
qs@6.13.0
6.15.2

Open the chart page →

5,670
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-8723.

Open the chart page →

31,510
ethereumjsethereum-helm-chartsVerified publisher0.1.21 of 2See more

ethereumjs ethereum-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ethpandaops/ethereumjs:masterfb84b718500f
qs@6.14.2
6.15.2

Open the chart page →

1,442
recaptcha-v3-verifierf3k-techVerified publisher1.110.01 of 1See more

recaptcha-v3-verifier f3k-tech 1.110.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
f3ktech/recaptcha-v3-verifier:1.1.048e78987cf91
qs@6.14.0
6.15.2

Open the chart page →

1,208
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
qs@6.15.1
6.15.2

Open the chart page →

3,123
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
qs@6.14.0
6.15.2

Open the chart page →

15,712
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
qs@6.13.0
6.15.2

Open the chart page →

5,228
litlyxlitlyx0.2.02 of 5See more

litlyx litlyx 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
litlyx/litlyx-consumer:latest02225e77d316
qs@6.13.0
6.15.2
litlyx/litlyx-producer:latest10407f36613f
qs@6.13.0
6.15.2

Open the chart page →

7,874
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
qs@6.13.0
6.15.2

Open the chart page →

13,738
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
qs@6.14.2
6.15.2

Open the chart page →

2,575
openvaultopenvaultVerified publisher0.8.11 of 2See more

openvault openvault 0.8.1

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
qs@6.13.0
6.15.2

Open the chart page →

6,873
uptime-kumapascaliskeVerified publisher3.0.01 of 1See more

uptime-kuma pascaliske 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
qs@6.13.0
6.15.2

Open the chart page →

6,883
patchworkpatchworkVerified publisher0.8.61 of 2See more

patchwork patchwork 0.8.6

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/patchwork:mainc01e018bced4
qs@6.13.0
6.15.2

Open the chart page →

2,083
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
qs@6.15.0
6.15.2

Open the chart page →

7,035
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
qs@6.14.2
6.15.2

Open the chart page →

31,844

Container images carrying it

206 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
redis/redisinsight:3.8:latestb5e19ee240ab
qs@6.14.0
6.15.2
4
rcdelacruz/my-strapi-app:js-amd6438007f358355
qs@6.11.2
6.15.2
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
qs@6.14.1
6.15.2
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
qs@6.15.0
6.15.2
3
ethersphere/bee-localchain:latest0558799ca992
qs@6.12.0
6.15.2
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
qs@6.12.1
6.15.2
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
qs@6.13.0
6.15.2
2
library/arangodb:3.11.81e75d74954a4
qs@6.11.2
6.15.2
2
louislam/uptime-kuma:2.5.4917318f9d7be
qs@6.14.2
6.15.2
2
louislam/uptime-kuma:2.3.29aeb4e51d038
qs@6.15.1
6.15.2
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
qs@6.14.2
6.15.2
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
qs@6.13.0
6.15.2
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
qs@6.13.0
6.15.2
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
qs@6.11.2
6.15.2
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
qs@6.14.0
6.15.2
2
rajnandan1/kener:3.2.1930407afca731
qs@6.13.0
6.15.2
2
requarks/wiki:2:latest68f0d1848261
qs@6.15.1
6.15.2
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
qs@6.14.2
6.15.2
2
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
qs@6.13.0
6.15.2
2
activepieces/activepieces:0.23.0c26188b44e62
qs@6.11.2
6.15.2
1
actualbudget/actual-server:25.3.158fecd9088b7
qs@6.13.0
6.15.2
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
qs@6.14.2
6.15.2
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
qs@6.14.2
6.15.2
1
alazidis/stornx:1.1.1602d4f7f090c
qs@6.14.0
6.15.2
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
qs@6.13.0
6.15.2
1
baserow/baserow:1.30.1df0c42eb67e8
qs@6.11.2
6.15.2
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
qs@6.13.0
6.15.2
1
bluerange/bluerange-mosquitto:25f1bfbba84832
qs@6.13.0
6.15.2
1
bnjbvr/kresus:0.22.137e216b182c8
qs@6.13.0
6.15.2
1
budibase/apps:3.41.344fe6feab985
qs@6.15.1
6.15.2
1
budibase/worker:3.41.3de5e2e560ce8
qs@6.15.0
6.15.2
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
qs@6.13.0
6.15.2
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
qs@6.11.1
6.15.2
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
qs@6.13.0
6.15.2
1
chocobozzz/peertube:v8.1.5052712130691
qs@6.15.0
6.15.2
1
codetogether/codetogether:latest4348c8a38752
qs@6.12.1
6.15.2
1
cryptexlabs/authf:0.12.11189c07411d7c
qs@6.13.0
6.15.2
1
dacinfomotion/h2p:latest68fa393b472c
qs@6.11.2
6.15.2
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
qs@6.13.0
6.15.2
1
devkrishan001/backend:latestf1c3acadeabe
qs@6.15.1
6.15.2
1
devravinder/node-express-app:1.0.05325a96967b5
qs@6.13.0
6.15.2
1
directus/directus:11.1.0e3c8bb975350
qs@6.13.0
6.15.2
1
diygod/rsshub:latest1d4b508b6357
qs@6.14.2
6.15.2
1
diygod/rsshub:2025-11-097a6312cac0d5
qs@6.14.0
6.15.2
1
docmost/docmost:0.95.041c8d777cf23
qs@6.14.2
6.15.2
1
documenso/documenso:v1.8.17f16a9449f18
qs@6.11.2
6.15.2
1
drumsergio/genieacs:1.2.16.028244054e1bf
qs@6.15.0
6.15.2
1
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
qs@6.13.0
6.15.2
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
qs@6.13.0
6.15.2
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
node-qs@2.2.4-1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.