StackRadar

CVE-2026-8723

Medium

Advisory

Published 17 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
213
of 17,787 indexed, latest versions
Container images
207
deployed by those charts
Fix available
1 of 2
affected packages

qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set

Carried by container images the latest versions of 213 of 17,787 indexed charts deploy, on 207 images.

Affected packageAffected versionsFixed inImages
qsnpm6.11.1, 6.11.2, 6.12.0, 6.12.1+6 more6.15.2202
node-qsdeb2.2.4-1, 2.2.4-1ubuntu1, 6.9.1+ds-1no fix listed5
OSV records
GHSA-q8mj-m7cp-5q26UBUNTU-CVE-2026-8723

Charts affected

213 by stars
ChartLatestAffected imagesRadar Score
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
qs@6.13.0
6.15.2

Open the chart page →

2,408
thanhvt27-lab-k8sthanh-vtVerified publisher0.1.41 of 5See more

thanhvt27-lab-k8s thanh-vt 0.1.4

1 of the 5 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
redis/redisinsight:latestb5e19ee240ab
qs@6.14.0
6.15.2

Open the chart page →

4,662
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
qs@6.11.2
6.15.2

Open the chart page →

5,489
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
qs@6.14.2
6.15.2

Open the chart page →

2,029
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
zimengxiong/excalidash-backend:0.4.271273af713c91
qs@6.14.1
6.15.2

Open the chart page →

2,622
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
qs@6.13.0
6.15.2

Open the chart page →

5,234
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
qs@6.13.0
6.15.2

Open the chart page →

3,747
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
qs@6.13.0
6.15.2

Open the chart page →

4,769
devportalveecode-platform-nextVerified publisher0.1.221 of 1See more

devportal veecode-platform-next 0.1.22

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
qs@6.14.2
6.15.2

Open the chart page →

1,806
homarrvhdirkVerified publisher0.1.51 of 1See more

homarr vhdirk 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:lateste103abadfb52
qs@6.11.2
6.15.2

Open the chart page →

2,789
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
qs@6.11.2
6.15.2

Open the chart page →

6,470
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
qs@6.14.0
6.15.2

Open the chart page →

5,774
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-8723.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
qs@6.15.1
6.15.2

Open the chart page →

5,472

Container images carrying it

207 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
redis/redisinsight:3.8:latestb5e19ee240ab
qs@6.14.0
6.15.2
4
rcdelacruz/my-strapi-app:js-amd6438007f358355
qs@6.11.2
6.15.2
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
qs@6.14.1
6.15.2
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
qs@6.15.0
6.15.2
3
ethersphere/bee-localchain:latest0558799ca992
qs@6.12.0
6.15.2
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
qs@6.12.1
6.15.2
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
qs@6.13.0
6.15.2
2
library/arangodb:3.11.81e75d74954a4
qs@6.11.2
6.15.2
2
louislam/uptime-kuma:2.5.4917318f9d7be
qs@6.14.2
6.15.2
2
louislam/uptime-kuma:2.3.29aeb4e51d038
qs@6.15.1
6.15.2
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
qs@6.14.2
6.15.2
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
qs@6.13.0
6.15.2
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
qs@6.13.0
6.15.2
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
qs@6.11.2
6.15.2
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
qs@6.14.0
6.15.2
2
rajnandan1/kener:3.2.1930407afca731
qs@6.13.0
6.15.2
2
requarks/wiki:2:latest68f0d1848261
qs@6.15.1
6.15.2
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
qs@6.14.2
6.15.2
2
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
qs@6.13.0
6.15.2
2
activepieces/activepieces:0.23.0c26188b44e62
qs@6.11.2
6.15.2
1
actualbudget/actual-server:25.3.158fecd9088b7
qs@6.13.0
6.15.2
1
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
qs@6.14.2
6.15.2
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
qs@6.14.2
6.15.2
1
alazidis/stornx:1.1.1602d4f7f090c
qs@6.14.0
6.15.2
1
anamskenneth/recipe_backend:2025-06-079b7d2cd389b7
qs@6.13.0
6.15.2
1
baserow/baserow:1.30.1df0c42eb67e8
qs@6.11.2
6.15.2
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
qs@6.13.0
6.15.2
1
bluerange/bluerange-mosquitto:25f1bfbba84832
qs@6.13.0
6.15.2
1
bnjbvr/kresus:0.22.137e216b182c8
qs@6.13.0
6.15.2
1
budibase/apps:3.41.344fe6feab985
qs@6.15.1
6.15.2
1
budibase/worker:3.41.3de5e2e560ce8
qs@6.15.0
6.15.2
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
qs@6.13.0
6.15.2
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
qs@6.11.1
6.15.2
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
qs@6.13.0
6.15.2
1
chocobozzz/peertube:v8.1.5052712130691
qs@6.15.0
6.15.2
1
codetogether/codetogether:latest4348c8a38752
qs@6.12.1
6.15.2
1
cryptexlabs/authf:0.12.11189c07411d7c
qs@6.13.0
6.15.2
1
dacinfomotion/h2p:latest68fa393b472c
qs@6.11.2
6.15.2
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
qs@6.13.0
6.15.2
1
devkrishan001/backend:latestf1c3acadeabe
qs@6.15.1
6.15.2
1
devravinder/node-express-app:1.0.05325a96967b5
qs@6.13.0
6.15.2
1
directus/directus:11.1.0e3c8bb975350
qs@6.13.0
6.15.2
1
diygod/rsshub:latest1d4b508b6357
qs@6.14.2
6.15.2
1
diygod/rsshub:2025-11-097a6312cac0d5
qs@6.14.0
6.15.2
1
docmost/docmost:0.95.041c8d777cf23
qs@6.14.2
6.15.2
1
documenso/documenso:v1.8.17f16a9449f18
qs@6.11.2
6.15.2
1
drumsergio/genieacs:1.2.16.028244054e1bf
qs@6.15.0
6.15.2
1
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
qs@6.13.0
6.15.2
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
qs@6.13.0
6.15.2
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
node-qs@2.2.4-1
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.