CVE-2026-8769
MediumAdvisory
Published 18 May 2026In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 4.3
- base score, highest
- EPSS
- 0.006
- 45th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 20
- of 17,781 indexed, latest versions
- Container images
- 19
- deployed by those charts
- Fix available
- 1 of 1
- affected package
@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
Carried by container images the latest versions of 20 of 17,781 indexed charts deploy, on 19 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| @ai-sdk/ | 2.0.4, 2.2.8, 3.0.9, 3.0.19+8 more | 3.0.28, 4.0.33 | 19 |
- OSV records
- GHSA-866g-f22w-33x8
Charts affected
20 by stars
Container images carrying it
19 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| infisical/ | 02082bf13163 | @ai-sdk/ | 4.0.33 | 2 |
| budibase/ | 44fe6feab985 | @ai-sdk/ | 4.0.33 | 1 |
| defectdojo/ | 4002f38324bc | @ai-sdk/ | 4.0.33 | 1 |
| directus/ | 9c8470ea465c | @ai-sdk/ | 4.0.33 | 1 |
| docmost/ | 41c8d777cf23 | @ai-sdk/ | 4.0.33 | 1 |
| flanksource/ | 764c84e550db | @ai-sdk/ | 4.0.33 | 1 |
| flanksource/ | 891f21df54fb | @ai-sdk/ | 4.0.33 | 1 |
| ghostfolio/ | e3c6ab53e49b | @ai-sdk/ | 4.0.33 | 1 |
| growthbook/ | f53ead646b5f | @ai-sdk/ | 4.0.33 | 1 |
| library/ | 04c0fc150f3a | @ai-sdk/ | 3.0.28 | 1 |
| n8nio/ | 761374d4eb84 | @ai-sdk/ | 4.0.33 | 1 |
| nocodb/ | 4b760f0d2547 | @ai-sdk/ | 3.0.28 | 1 |
| nocodb/ | d9516f0bf546 | @ai-sdk/ | 3.0.28 | 1 |
| supabase/ | 606aca9fdaa7 | @ai-sdk/ | 4.0.33 | 1 |
| treskon/ | e7970783bc8d | @ai-sdk/ | 3.0.28 | 1 |
| twentycrm/ | e7d9948bf284 | @ai-sdk/ | 4.0.33 | 1 |
| ghcr.io/ | 0664c28a039b | @ai-sdk/ | 3.0.28 | 1 |
| ghcr.io/ | a288b4571142 | @ai-sdk/ | 3.0.28 | 1 |
| public.ecr.aws/ | fea799d4fb2f | @ai-sdk/ | 4.0.33 | 1 |