StackRadar

CVE-2026-8723

Medium

Advisory

Published 17 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
212
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
1 of 2
affected packages

qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set

Carried by container images the latest versions of 212 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
qsnpm6.11.1, 6.11.2, 6.12.0, 6.12.1+6 more6.15.2201
node-qsdeb2.2.4-1, 2.2.4-1ubuntu1, 6.9.1+ds-1no fix listed5
OSV records
GHSA-q8mj-m7cp-5q26UBUNTU-CVE-2026-8723

Charts affected

212 by stars
ChartLatestAffected imagesRadar Score
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
qs@6.11.2
6.15.2

Open the chart page →

2,316
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
qs@6.14.0
6.15.2

Open the chart page →

2,457
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
moreillon/camera-proxy:latestce60056b50c2
qs@6.13.0
6.15.2

Open the chart page →

11,643
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
qs@6.11.2
6.15.2

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
qs@6.13.0
6.15.2

Open the chart page →

4,960
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
qs@6.11.2
6.15.2

Open the chart page →

6,608
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
qs@6.12.1
6.15.2

Open the chart page →

109,294
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
qs@6.14.2
6.15.2

Open the chart page →

30,028
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
qs@6.14.1
6.15.2

Open the chart page →

2,383
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
qs@6.13.0
6.15.2

Open the chart page →

10,218
nostreamnostream0.1.01 of 1See more

nostream nostream 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/cameri/nostream:main8726533b9e69
qs@6.14.2
6.15.2

Open the chart page →

595
nocodbone-acre-fundVerified publisher0.4.61 of 3See more

nocodb one-acre-fund 0.4.6

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
nocodb/nocodb:0.258.06779a4ddedf2
qs@6.13.0
6.15.2

Open the chart page →

4,219
raspberrymaticopenccuVerified publisher3.83.61 of 1See more

raspberrymatic openccu 3.83.6

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
qs@6.14.0
6.15.2

Open the chart page →

2,421
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
node-qs@2.2.4-1ubuntu1
no fix listed

Open the chart page →

36,215
example-idpory0.64.01 of 1See more

example-idp ory 0.64.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
oryd/hydra-login-consent-node:v26.2.06465e95993b5
qs@6.13.0
6.15.2

Open the chart page →

838
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
qs@6.11.2
6.15.2

Open the chart page →

71,208
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
qs@6.11.2
6.15.2

Open the chart page →

6,583
outscale-s3-exploreroutscale-s3-explorer0.1.41 of 1See more

outscale-s3-explorer outscale-s3-explorer 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
qs@6.13.0
6.15.2

Open the chart page →

1,811
pacmanpacman-mhVerified publisher0.1.281 of 2See more

pacman pacman-mh 0.1.28

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/michaelhaigh/pacman:latestb0931b1f085d
qs@6.14.1
6.15.2

Open the chart page →

3,562
pairdroppascaliskeVerified publisher2.0.01 of 1See more

pairdrop pascaliske 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/pairdrop:version-v1.11.23279d2d986c0
qs@6.13.0
6.15.2

Open the chart page →

663
prismeai-coreprismeai1.12.12 of 7See more

prismeai-core prismeai 1.12.1

2 of the 7 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-events:prod470da8f8730c
qs@6.14.1
6.15.2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-runtime:prodbce6d452ad08
qs@6.14.1
6.15.2

Open the chart page →

3,270
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
qs@6.14.1
6.15.2

Open the chart page →

1,858
recipe-apprecipe-app0.1.01 of 2See more

recipe-app recipe-app 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
qs@6.13.0
6.15.2

Open the chart page →

3,271
redisinsightredisinsightVerified publisher0.1.01 of 1See more

redisinsight redisinsight 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
qs@6.14.0
6.15.2

Open the chart page →

1,038
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
qs@6.13.0
6.15.2

Open the chart page →

4,600
kresusrm3lVerified publisher0.2.11 of 3See more

kresus rm3l 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
bnjbvr/kresus:0.22.137e216b182c8
qs@6.13.0
6.15.2

Open the chart page →

15,591
devtron-enterpriseromholdings48.0.01 of 28See more

devtron-enterprise romholdings 48.0.0

1 of the 28 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
qs@6.15.0
6.15.2

Open the chart page →

68,240
routr-connectroutr0.4.31 of 10See more

routr-connect routr 0.4.3

1 of the 10 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
fonoster/routr-registry:2.13.6e27001f2813c
qs@6.13.0
6.15.2

Open the chart page →

11,021
karakeeprtomik-helm-chartsVerified publisher0.0.11 of 3See more

karakeep rtomik-helm-charts 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
qs@6.14.0
6.15.2

Open the chart page →

5,338
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
qs@6.11.2
6.15.2

Open the chart page →

7,413
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
qs@6.14.2
6.15.2

Open the chart page →

30,219
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
qs@6.12.1
6.15.2

Open the chart page →

19,560
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
qs@6.12.1
6.15.2

Open the chart page →

16,620
rsshubsb-helm-charts0.3.01 of 1See more

rsshub sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
diygod/rsshub:2025-11-097a6312cac0d5
qs@6.14.0
6.15.2

Open the chart page →

4,684
etherpadschoenwald0.3.01 of 1See more

etherpad schoenwald 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
etherpad/etherpad:2.7.2b723fe5f2594
qs@6.15.1
6.15.2

Open the chart page →

2,133
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
qs@6.13.0
6.15.2

Open the chart page →

5,497
seerr-chartseerr-chartVerified publisher3.9.11 of 1See more

seerr-chart seerr-chart 3.9.1

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.4.1f4768de5f616
qs@6.14.1
6.15.2

Open the chart page →

1,991
shopsyncshopsyncVerified publisher1.0.01 of 1See more

shopsync shopsync 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
shyamkrishna21/shopsync:latest3998b83def53
qs@6.14.2
6.15.2

Open the chart page →

1,088
simple-node-expresssimple-node-express1.0.01 of 1See more

simple-node-express simple-node-express 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
devravinder/node-express-app:1.0.05325a96967b5
qs@6.13.0
6.15.2

Open the chart page →

752
speckle-preview-service-branch-testing6speckleVerified publisher2.23.14-branch.testing6.334655-b4e04ee1 of 1See more

speckle-preview-service-branch-testing6 speckle 2.23.14-branch.testing6.334655-b4e04ee

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
qs@6.13.0
6.15.2

Open the chart page →

5,950
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef2 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

2 of the 5 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
qs@6.13.0
6.15.2
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
qs@6.13.0
6.15.2

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e3 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

3 of the 4 container images this version deploys carry CVE-2026-8723.

Open the chart page →

11,100
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
qs@6.14.0
6.15.2

Open the chart page →

1,313
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
qs@6.11.1
6.15.2

Open the chart page →

4,052
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
qs@6.14.2
6.15.2

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
qs@6.14.2
6.15.2

Open the chart page →

919
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-qs@6.9.1+ds-1
no fix listed

Open the chart page →

10,902
stateful-data-generatortalhajuikar-helm-charts0.1.21 of 2See more

stateful-data-generator talhajuikar-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
qs@6.13.0
6.15.2

Open the chart page →

4,860
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
qs@6.15.0
6.15.2

Open the chart page →

3,972
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
qs@6.13.0
6.15.2

Open the chart page →

11,648

Container images carrying it

206 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
moreillon/food-manager:lateste8fd856e593d
qs@6.13.0
6.15.2
1
moreillon/group-manager:latest3caa8f710ee0
qs@6.14.2
6.15.2
1
n8nio/n8n:2.25.7761374d4eb84
qs@6.14.2
6.15.2
1
n8nio/n8n:1.86.08b39ed5a2de9
qs@6.13.0
6.15.2
1
n8nio/n8n:1.33.1dd171d45102a
qs@6.11.2
6.15.2
1
netrisai/controller-web-service-backend:4.6.0-0086e865080e86c
qs@6.13.0
6.15.2
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
qs@6.11.2
6.15.2
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
qs@6.11.2
6.15.2
1
nocodb/nocodb:0.258.06779a4ddedf2
qs@6.13.0
6.15.2
1
nocodb/nocodb:0.301.5d9516f0bf546
qs@6.15.0
6.15.2
1
nodered/node-red:4.1.2216e7403aab9
qs@6.13.0
6.15.2
1
nodered/node-red:4.1.10-minimald73ae167cb9b
qs@6.14.2
6.15.2
1
openthread/otbr:latestf307f59f6432
node-qs@2.2.4-1ubuntu1
no fix listed
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
node-qs@2.2.4-1ubuntu1
no fix listed
1
oryd/hydra-login-consent-node:v26.2.06465e95993b5
qs@6.13.0
6.15.2
1
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
qs@6.14.2
6.15.2
1
penpotapp/exporter:2.2.15c835ffd87ab
qs@6.12.1
6.15.2
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
qs@6.14.1
6.15.2
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
qs@6.14.0
6.15.2
1
redis/redisinsight:2.68019fcf774631
qs@6.13.0
6.15.2
1
redis/redisinsight:3.2.055542a762210
qs@6.13.0
6.15.2
1
redis/redisinsight:3.485562d67a912
qs@6.13.0
6.15.2
1
rocketadmin/rocketadmin:1.17.710955ef540b9
qs@6.15.1
6.15.2
1
shyamkrishna21/cloudvault:latestaf2785f5bb71
qs@6.14.2
6.15.2
1
shyamkrishna21/shopsync:latest3998b83def53
qs@6.14.2
6.15.2
1
sigp/siren:v3.0.42c219b04758e
qs@6.14.0
6.15.2
1
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
qs@6.12.1
6.15.2
1
solidproject/community-server:6.0.2ccc4acb7e9a1
qs@6.11.1
6.15.2
1
speckle/speckle-monitor-deployment:2.25.10-branch.testing6.645-b125c1e2dbc553ed87c
qs@6.13.0
6.15.2
1
speckle/speckle-monitor-deployment:2.26.3d51e1b0cf231
qs@6.13.0
6.15.2
1
speckle/speckle-preview-service:2.26.3092384dba45d
qs@6.13.0
6.15.2
1
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
qs@6.13.0
6.15.2
1
speckle/speckle-preview-service:2.23.14-branch.testing6.334655-b4e04ee6dee853ba74a
qs@6.13.0
6.15.2
1
speckle/speckle-preview-service:2.25.10-branch.testing6.645-b125c1e787adcb20a3a
qs@6.13.0
6.15.2
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
qs@6.13.0
6.15.2
1
speckle/speckle-server:2.26.379f14a2bf931
qs@6.13.0
6.15.2
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
qs@6.13.0
6.15.2
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
node-qs@6.9.1+ds-1
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
qs@6.14.0
6.15.2
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
qs@6.14.0
6.15.2
1
tensorzero/ui:2026.6.0f2563d54724e
qs@6.15.0
6.15.2
1
th0th/node-red:4.0.3-debiand06fa39f7406
qs@6.13.0
6.15.2
1
thmmniii/fbs-qcm-backend:v1.27.1afbe511e5c24
qs@6.13.0
6.15.2
1
treskon/portrait-ui:DEV-lateste7970783bc8d
qs@6.14.2
6.15.2
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
qs@6.13.0
6.15.2
1
unleashorg/unleash-enterprise:7.5.0245aeba40053
qs@6.14.2
6.15.2
1
unleashorg/unleash-server:7.5.09adb37e399ba
qs@6.14.2
6.15.2
1
vcnngr/pnbackend:latesteaf44ad0ad1f
qs@6.13.0
6.15.2
1
veecode/devportalc443520aebf7
qs@6.14.2
6.15.2
1
zimengxiong/excalidash-backend:0.4.271273af713c91
qs@6.14.1
6.15.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.