StackRadar

CVE-2026-8769

Medium

Advisory

Published 18 May 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.006
45th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
20
of 17,781 indexed, latest versions
Container images
19
deployed by those charts
Fix available
1 of 1
affected package

@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue

Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 19 images.

Affected packageAffected versionsFixed inImages
@ai-sdk/provider-utilsnpm2.0.4, 2.2.8, 3.0.9, 3.0.19+8 more3.0.28, 4.0.3319
OSV records
GHSA-866g-f22w-33x8

Charts affected

20 by stars
ChartLatestAffected imagesRadar Score
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
@ai-sdk/provider-utils@4.0.19
4.0.33

Open the chart page →

10,775
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
@ai-sdk/provider-utils@4.0.21
4.0.33

Open the chart page →

5,564
defectdojodefectdojo1.9.511 of 4See more

defectdojo defectdojo 1.9.51

1 of the 4 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
defectdojo/defectdojo-nginx:3.3.14002f38324bc
@ai-sdk/provider-utils@4.0.5
4.0.33

Open the chart page →

2,408
nocodbzekker6Verified publisher1.10.01 of 1See more

nocodb zekker6 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
nocodb/nocodb:0.301.5d9516f0bf546
@ai-sdk/provider-utils@2.2.8
3.0.28

Open the chart page →

4,016
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
@ai-sdk/provider-utils@4.0.19
4.0.33

Open the chart page →

7,473
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
@ai-sdk/provider-utils@4.0.26
4.0.33

Open the chart page →

3,123
growthbookgrowthbook5.0.11 of 2See more

growthbook growthbook 5.0.1

1 of the 2 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
growthbook/growthbook:5.0.1f53ead646b5f
@ai-sdk/provider-utils@4.0.8
4.0.33

Open the chart page →

709
n8nn8n-helm2.25.71 of 1See more

n8n n8n-helm 2.25.7

1 of the 1 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
n8nio/n8n:2.25.7761374d4eb84
@ai-sdk/provider-utils@4.0.21
4.0.33

Open the chart page →

2,575
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
@ai-sdk/provider-utils@2.2.8
3.0.28

Open the chart page →

31,844
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
@ai-sdk/provider-utils@4.0.19
4.0.33

Open the chart page →

18,075
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
@ai-sdk/provider-utils@3.0.19
3.0.28

Open the chart page →

3,820
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
@ai-sdk/provider-utils@4.0.2
4.0.33

Open the chart page →

4,650
flanksource-uiflanksourceVerified publisher1.4.3181 of 1See more

flanksource-ui flanksource 1.4.318

1 of the 1 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.318891f21df54fb
@ai-sdk/provider-utils@4.0.2
4.0.33

Open the chart page →

2,558
mission-controlflanksourceVerified publisher0.1.3361 of 8See more

mission-control flanksource 0.1.336

1 of the 8 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
@ai-sdk/provider-utils@4.0.2
4.0.33

Open the chart page →

8,902
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
@ai-sdk/provider-utils@4.0.23
4.0.33

Open the chart page →

3,014
nocodbinseefrlab0.2.01 of 1See more

nocodb inseefrlab 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
nocodb/nocodb:latest4b760f0d2547
@ai-sdk/provider-utils@2.2.8
3.0.28

Open the chart page →

781
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
@ai-sdk/provider-utils@4.0.23
4.0.33

Open the chart page →

3,014
strapistrapi-xmv0.1.11 of 1See more

strapi strapi-xmv 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
@ai-sdk/provider-utils@3.0.9
3.0.28

Open the chart page →

676
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
@ai-sdk/provider-utils@4.0.29
4.0.33

Open the chart page →

5,550
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-8769.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
@ai-sdk/provider-utils@2.0.4
3.0.28

Open the chart page →

6,285

Container images carrying it

19 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
infisical/infisical:latest:v0.165.602082bf13163
@ai-sdk/provider-utils@4.0.23
4.0.33
2
budibase/apps:3.41.344fe6feab985
@ai-sdk/provider-utils@4.0.19
4.0.33
1
defectdojo/defectdojo-nginx:3.3.14002f38324bc
@ai-sdk/provider-utils@4.0.5
4.0.33
1
directus/directus:12.0.29c8470ea465c
@ai-sdk/provider-utils@4.0.19
4.0.33
1
docmost/docmost:0.95.041c8d777cf23
@ai-sdk/provider-utils@4.0.21
4.0.33
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
@ai-sdk/provider-utils@4.0.2
4.0.33
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
@ai-sdk/provider-utils@4.0.2
4.0.33
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
@ai-sdk/provider-utils@4.0.26
4.0.33
1
growthbook/growthbook:5.0.1f53ead646b5f
@ai-sdk/provider-utils@4.0.8
4.0.33
1
library/kibana:8.18.004c0fc150f3a
@ai-sdk/provider-utils@2.0.4
3.0.28
1
n8nio/n8n:2.25.7761374d4eb84
@ai-sdk/provider-utils@4.0.21
4.0.33
1
nocodb/nocodb:latest4b760f0d2547
@ai-sdk/provider-utils@2.2.8
3.0.28
1
nocodb/nocodb:0.301.5d9516f0bf546
@ai-sdk/provider-utils@2.2.8
3.0.28
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
@ai-sdk/provider-utils@4.0.19
4.0.33
1
treskon/portrait-ui:DEV-lateste7970783bc8d
@ai-sdk/provider-utils@2.2.8
3.0.28
1
twentycrm/twenty:v2.22.0e7d9948bf284
@ai-sdk/provider-utils@4.0.29
4.0.33
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
@ai-sdk/provider-utils@3.0.19
3.0.28
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
@ai-sdk/provider-utils@3.0.9
3.0.28
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
@ai-sdk/provider-utils@4.0.2
4.0.33
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.