StackRadar

CVE-2026-8723

Medium

Advisory

Published 17 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
212
of 17,781 indexed, latest versions
Container images
206
deployed by those charts
Fix available
1 of 2
affected packages

qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set

Carried by container images the latest versions of 212 of 17,781 indexed charts deploy, on 206 images.

Affected packageAffected versionsFixed inImages
qsnpm6.11.1, 6.11.2, 6.12.0, 6.12.1+6 more6.15.2201
node-qsdeb2.2.4-1, 2.2.4-1ubuntu1, 6.9.1+ds-1no fix listed5
OSV records
GHSA-q8mj-m7cp-5q26UBUNTU-CVE-2026-8723

Charts affected

212 by stars
ChartLatestAffected imagesRadar Score
genieacsgenieacsVerified publisher0.5.11 of 2See more

genieacs genieacs 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
drumsergio/genieacs:1.2.16.028244054e1bf
qs@6.15.0
6.15.2

Open the chart page →

4,259
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
qs@6.11.1
6.15.2

Open the chart page →

9,019
kube-hookglenndehaanVerified publisher1.0.31 of 1See more

kube-hook glenndehaan 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
glenndehaan/kube-hook:latest0a7116f48bfe
qs@6.13.0
6.15.2

Open the chart page →

923
littlelink-serverh2mVerified publisher1.0.11 of 1See more

littlelink-server h2m 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
qs@6.13.0
6.15.2

Open the chart page →

819
h2ph2pVerified publisher1.0.11 of 1See more

h2p h2p 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
dacinfomotion/h2p:latest68fa393b472c
qs@6.11.2
6.15.2

Open the chart page →

1,713
librechathajowielandVerified publisher1.1.01 of 1See more

librechat hajowieland 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
qs@6.14.0
6.15.2

Open the chart page →

2,950
home-assistant-matter-hubhelm-chart-roeiVerified publisher3.0.21 of 1See more

home-assistant-matter-hub helm-chart-roei 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
luligu/matterbridge:3.0.28f97884bebc2
qs@6.14.0
6.15.2

Open the chart page →

3,806
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
qs@6.13.0
6.15.2

Open the chart page →

3,451
crucixhelm-crucix0.2.01 of 1See more

crucix helm-crucix 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/calesthio/crucix:latest67c5244b6acf
qs@6.15.0
6.15.2

Open the chart page →

778
paprahelmforgeVerified publisher1.0.01 of 1See more

papra helmforge 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
qs@6.14.0
6.15.2

Open the chart page →

2,538
ryothelmforgeVerified publisher1.0.01 of 2See more

ryot helmforge 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
qs@6.13.0
6.15.2

Open the chart page →

6,012
uptime-kumahelmforgeVerified publisher1.5.121 of 1See more

uptime-kuma helmforge 1.5.12

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.33e24e96c89ef
qs@6.14.2
6.15.2

Open the chart page →

30,099
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
qs@6.13.0
6.15.2

Open the chart page →

3,614
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
qs@6.13.0
6.15.2

Open the chart page →

3,154
ilum-marquezilumVerified publisher6.7.01 of 3See more

ilum-marquez ilum 6.7.0

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ilum/marquez-web:0.53.2716437a51a6c
qs@6.14.1
6.15.2

Open the chart page →

6,254
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
qs@6.13.0
6.15.2

Open the chart page →

11,812
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
qs@6.14.2
6.15.2

Open the chart page →

3,436
n8njanip81-helm-chartsVerified publisher0.1.41 of 1See more

n8n janip81-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
n8nio/n8n:1.86.08b39ed5a2de9
qs@6.13.0
6.15.2

Open the chart page →

5,826
hello-kubernetes-chartjhidalgo3-githubVerified publisher3.0.01 of 1See more

hello-kubernetes-chart jhidalgo3-github 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
jhidalgo3/hello-kubernetes:1.0.0.1397bf5ddfa8628d79f5
qs@6.13.0
6.15.2

Open the chart page →

914
shinsei-managerjtektVerified publisher0.2.02 of 8See more

shinsei-manager jtekt 0.2.0

2 of the 8 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
qs@6.13.0
6.15.2
moreillon/group-manager:latest3caa8f710ee0
qs@6.14.2
6.15.2

Open the chart page →

63,461
docker-hub-rssjuniorjpdj0.1.311 of 1See more

docker-hub-rss juniorjpdj 0.1.31

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
qs@6.14.0
6.15.2

Open the chart page →

1,966
actual-budgetk8s-chartsVerified publisher0.2.31 of 1See more

actual-budget k8s-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
actualbudget/actual-server:25.3.158fecd9088b7
qs@6.13.0
6.15.2

Open the chart page →

2,611
zwave-js-uik8sonlabVerified publisher0.7.121 of 1See more

zwave-js-ui k8sonlab 0.7.12

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
zwavejs/zwave-js-ui:11.22.314d018bb689e
qs@6.14.2
6.15.2

Open the chart page →

973
kenerkener-chart0.0.71 of 1See more

kener kener-chart 0.0.7

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
qs@6.13.0
6.15.2

Open the chart page →

5,228
keycloak-multi-client-notifierkeycloak-multi-client-notifier2.1.21 of 2See more

keycloak-multi-client-notifier keycloak-multi-client-notifier 2.1.2

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
qs@6.14.2
6.15.2

Open the chart page →

1,473
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
kitware/cdash:v5.3.0d7767d9b9da4
qs@6.14.2
6.15.2

Open the chart page →

12,062
redisinsightklicktippVerified publisher0.5.01 of 1See more

redisinsight klicktipp 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
redis/redisinsight:3.2.055542a762210
qs@6.13.0
6.15.2

Open the chart page →

1,290
pangolinkrzwiatrzyk0.11.01 of 1See more

pangolin krzwiatrzyk 0.11.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
fosrl/pangolin:1.13.0c32ad797ab96
qs@6.14.0
6.15.2

Open the chart page →

3,441
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
qs@6.14.2
6.15.2

Open the chart page →

2,756
seerrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

seerr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
qs@6.14.1
6.15.2

Open the chart page →

2,548
uptime-kumakubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

uptime-kuma kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.2.1-slim059b49d64739
qs@6.14.2
6.15.2

Open the chart page →

6,356
kube-mailkubernetes-replicator0.11.11 of 3See more

kube-mail kubernetes-replicator 0.11.1

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
quay.io/mittwald/kube-mail:latest04f1099241fc
qs@6.13.0
6.15.2

Open the chart page →

2,509
penpotkubitodevVerified publisher1.2.11 of 5See more

penpot kubitodev 1.2.1

1 of the 5 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
penpotapp/exporter:2.2.15c835ffd87ab
qs@6.12.1
6.15.2

Open the chart page →

16,877
landing-pagelanding-pageVerified publisher0.1.01 of 1See more

landing-page landing-page 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
felipecs8/landing-page:v1db6d44e325a1
qs@6.13.0
6.15.2

Open the chart page →

1,119
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
qs@6.14.0
6.15.2

Open the chart page →

3,555
stremiolbenicio-communityVerified publisher0.1.11 of 2See more

stremio lbenicio-community 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
lbenicio/stremio-web:latest732f9003de33
qs@6.15.1
6.15.2

Open the chart page →

2,600
uptime-kumalbenicio-communityVerified publisher0.1.11 of 1See more

uptime-kuma lbenicio-community 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
qs@6.15.1
6.15.2

Open the chart page →

33,242
node-redlmatfyVerified publisher0.1.61 of 1See more

node-red lmatfy 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
nodered/node-red:4.1.10-minimald73ae167cb9b
qs@6.14.2
6.15.2

Open the chart page →

1,809
uptime-kumaloeken-at-homeVerified publisher2.3.21 of 1See more

uptime-kuma loeken-at-home 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.3.29aeb4e51d038
qs@6.15.1
6.15.2

Open the chart page →

33,242
redisinsightlogic3579Verified publisher3.4.01 of 1See more

redisinsight logic3579 3.4.0

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
redis/redisinsight:3.485562d67a912
qs@6.13.0
6.15.2

Open the chart page →

1,490
nublado2lsst-sqre0.8.51 of 2See more

nublado2 lsst-sqre 0.8.5

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
lsstsqre/nublado2:2.0.1b75bf8aaafa4
node-qs@6.9.1+ds-1
no fix listed

Open the chart page →

17,779
m9sweeperm9sweeperVerified publisher1.6.01 of 6See more

m9sweeper m9sweeper 1.6.0

1 of the 6 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
qs@6.11.2
6.15.2

Open the chart page →

9,774
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
qs@6.14.1
6.15.2

Open the chart page →

8,303
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
qs@6.13.0
6.15.2

Open the chart page →

9,668
mini-blogmini-blog-helm0.1.01 of 3See more

mini-blog mini-blog-helm 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
qs@6.13.0
6.15.2

Open the chart page →

13,010
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
qs@6.13.0
6.15.2

Open the chart page →

43,341
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
qs@6.14.0
6.15.2

Open the chart page →

2,457
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
qs@6.13.0
6.15.2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
qs@6.13.0
6.15.2
mojaloop/role-assignment-service:v2.1.0def4bf273721
qs@6.11.2
6.15.2

Open the chart page →

14,809
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
qs@6.13.0
6.15.2

Open the chart page →

2,631
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
qs@6.13.0
6.15.2

Open the chart page →

2,318

Container images carrying it

206 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
redis/redisinsight:3.8:latestb5e19ee240ab
qs@6.14.0
6.15.2
4
rcdelacruz/my-strapi-app:js-amd6438007f358355
qs@6.11.2
6.15.2
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
qs@6.14.1
6.15.2
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
qs@6.15.0
6.15.2
3
ethersphere/bee-localchain:latest0558799ca992
qs@6.12.0
6.15.2
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
qs@6.12.1
6.15.2
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
qs@6.13.0
6.15.2
2
library/arangodb:3.11.81e75d74954a4
qs@6.11.2
6.15.2
2
louislam/uptime-kuma:2.5.4917318f9d7be
qs@6.14.2
6.15.2
2
louislam/uptime-kuma:2.3.29aeb4e51d038
qs@6.15.1
6.15.2
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
qs@6.14.2
6.15.2
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
qs@6.13.0
6.15.2
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
qs@6.13.0
6.15.2
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
qs@6.11.2
6.15.2
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
qs@6.14.0
6.15.2
2
rajnandan1/kener:3.2.1930407afca731
qs@6.13.0
6.15.2
2
requarks/wiki:2:latest68f0d1848261
qs@6.15.1
6.15.2
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
qs@6.14.2
6.15.2
2
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
qs@6.13.0
6.15.2
2
activepieces/activepieces:0.23.0c26188b44e62
qs@6.11.2
6.15.2
1
actualbudget/actual-server:25.3.158fecd9088b7
qs@6.13.0
6.15.2
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
qs@6.14.2
6.15.2
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
qs@6.14.2
6.15.2
1
alazidis/stornx:1.1.1602d4f7f090c
qs@6.14.0
6.15.2
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
qs@6.13.0
6.15.2
1
baserow/baserow:1.30.1df0c42eb67e8
qs@6.11.2
6.15.2
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
qs@6.13.0
6.15.2
1
bluerange/bluerange-mosquitto:25f1bfbba84832
qs@6.13.0
6.15.2
1
bnjbvr/kresus:0.22.137e216b182c8
qs@6.13.0
6.15.2
1
budibase/apps:3.41.344fe6feab985
qs@6.15.1
6.15.2
1
budibase/worker:3.41.3de5e2e560ce8
qs@6.15.0
6.15.2
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
qs@6.13.0
6.15.2
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
qs@6.11.1
6.15.2
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
qs@6.13.0
6.15.2
1
chocobozzz/peertube:v8.1.5052712130691
qs@6.15.0
6.15.2
1
codetogether/codetogether:latest4348c8a38752
qs@6.12.1
6.15.2
1
cryptexlabs/authf:0.12.11189c07411d7c
qs@6.13.0
6.15.2
1
dacinfomotion/h2p:latest68fa393b472c
qs@6.11.2
6.15.2
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
qs@6.13.0
6.15.2
1
devkrishan001/backend:latestf1c3acadeabe
qs@6.15.1
6.15.2
1
devravinder/node-express-app:1.0.05325a96967b5
qs@6.13.0
6.15.2
1
directus/directus:11.1.0e3c8bb975350
qs@6.13.0
6.15.2
1
diygod/rsshub:latest1d4b508b6357
qs@6.14.2
6.15.2
1
diygod/rsshub:2025-11-097a6312cac0d5
qs@6.14.0
6.15.2
1
docmost/docmost:0.95.041c8d777cf23
qs@6.14.2
6.15.2
1
documenso/documenso:v1.8.17f16a9449f18
qs@6.11.2
6.15.2
1
drumsergio/genieacs:1.2.16.028244054e1bf
qs@6.15.0
6.15.2
1
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
qs@6.13.0
6.15.2
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
qs@6.13.0
6.15.2
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
node-qs@2.2.4-1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.