StackRadar

CVE-2026-8723

Medium

Advisory

Published 17 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
212
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
1 of 2
affected packages

qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set

Carried by container images the latest versions of 212 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
qsnpm6.11.1, 6.11.2, 6.12.0, 6.12.1+6 more6.15.2201
node-qsdeb2.2.4-1, 2.2.4-1ubuntu1, 6.9.1+ds-1no fix listed5
OSV records
GHSA-q8mj-m7cp-5q26UBUNTU-CVE-2026-8723

Charts affected

212 by stars
ChartLatestAffected imagesRadar Score
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
qs@6.13.0
6.15.2

Open the chart page →

2,408
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
qs@6.14.0
6.15.2

Open the chart page →

4,661
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
qs@6.11.2
6.15.2

Open the chart page →

5,535
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
qs@6.14.2
6.15.2

Open the chart page →

2,028
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
qs@6.14.1
6.15.2

Open the chart page →

2,620
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
qs@6.13.0
6.15.2

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
qs@6.13.0
6.15.2

Open the chart page →

3,746
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
qs@6.13.0
6.15.2

Open the chart page →

4,768
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
qs@6.14.2
6.15.2

Open the chart page →

1,787
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
qs@6.11.2
6.15.2

Open the chart page →

2,789
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
qs@6.14.0
6.15.2

Open the chart page →

5,984
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
qs@6.15.1
6.15.2

Open the chart page →

5,459

Container images carrying it

206 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
etherpad/etherpad:2.7.2b723fe5f2594
qs@6.15.1
6.15.2
1
ethersphere/multichain-proxy:0.0.261f5419afbcd
qs@6.13.0
6.15.2
1
ethpandaops/ethereumjs:masterfb84b718500f
qs@6.14.2
6.15.2
1
evoapicloud/evolution-api:latest966625532d90
qs@6.13.0
6.15.2
1
f3ktech/recaptcha-v3-verifier:1.1.048e78987cf91
qs@6.14.0
6.15.2
1
fallenbagel/jellyseerr:latest4538137bc5af
qs@6.14.0
6.15.2
1
felipecs8/app-movies-series:v14e51693fcdf5
qs@6.13.0
6.15.2
1
felipecs8/conversor-temperatura:v1f945423be36d
qs@6.14.2
6.15.2
1
felipecs8/landing-page:v1db6d44e325a1
qs@6.13.0
6.15.2
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
qs@6.11.2
6.15.2
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
qs@6.11.2
6.15.2
1
foggbh/stocky:latest8b7a2e5ecf4e
qs@6.14.2
6.15.2
1
folioci/mod-graphql:latestf0655a6a08fd
qs@6.13.0
6.15.2
1
fonoster/routr-registry:2.13.6e27001f2813c
qs@6.13.0
6.15.2
1
fosrl/pangolin:1.13.0c32ad797ab96
qs@6.14.0
6.15.2
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
qs@6.15.1
6.15.2
1
glenndehaan/kube-hook:latest0a7116f48bfe
qs@6.13.0
6.15.2
1
heywood8/redisinsight:2.28.00bc9ab313d37
qs@6.11.1
6.15.2
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
qs@6.13.0
6.15.2
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
qs@6.13.0
6.15.2
1
ilum/marquez-web:0.53.2716437a51a6c
qs@6.14.1
6.15.2
1
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
qs@6.13.0
6.15.2
1
joplin/server:latest3f7b852959aa
qs@6.11.2
6.15.2
1
joplin/server:3.0-beta52af57880c0e
qs@6.11.2
6.15.2
1
joplin/server:2.14.2-betab87564ef34e9
qs@6.11.2
6.15.2
1
kitware/cdash:v5.3.0d7767d9b9da4
qs@6.14.2
6.15.2
1
laly9999/node-app:1dd0e503913e1
qs@6.13.0
6.15.2
1
lbenicio/stremio-web:latest732f9003de33
qs@6.15.1
6.15.2
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
qs@6.13.0
6.15.2
1
library/ghost:6.37.01ef2e532ca4d
qs@6.14.2
6.15.2
1
library/ghost:6.25.12654b1e90413
qs@6.13.0
6.15.2
1
library/ghost:6.39.0-alpine77196da4b0df
qs@6.14.2
6.15.2
1
library/ghost:5.79.083f7bf209844
qs@6.11.1
6.15.2
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
qs@6.13.0
6.15.2
1
litlyx/litlyx-consumer:latest02225e77d316
qs@6.13.0
6.15.2
1
litlyx/litlyx-producer:latest10407f36613f
qs@6.13.0
6.15.2
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
qs@6.14.2
6.15.2
1
louislam/uptime-kuma:13d632903e6af
qs@6.13.0
6.15.2
1
louislam/uptime-kuma:2.5.33e24e96c89ef
qs@6.14.2
6.15.2
1
louislam/uptime-kuma:2.0.24c364ef96aad
qs@6.13.0
6.15.2
1
louislam/uptime-kuma:2.4.091e963bfda56
qs@6.14.2
6.15.2
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
qs@6.13.0
6.15.2
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-qs@6.9.1+ds-1
no fix listed
1
luligu/matterbridge:3.0.28f97884bebc2
qs@6.14.0
6.15.2
1
maildev/maildev:2.2.1180ef51f65ee
qs@6.13.0
6.15.2
1
mautic/mautic:7-apacheeb8cc73d97e1
qs@6.14.1
6.15.2
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
qs@6.13.0
6.15.2
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
qs@6.11.2
6.15.2
1
moreillon/api-proxy:latestd7d4a5463525
qs@6.13.0
6.15.2
1
moreillon/camera-proxy:latestce60056b50c2
qs@6.13.0
6.15.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.