StackRadar

CVE-2026-87776

High

Advisory

Published 5 Oct 2026In the index since 6 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
231
of 18,026 indexed, latest versions
Container images
218
deployed by those charts
Fix available
1 of 1
affected package

compression vulnerable to Denial of Service via memory leak on premature response close

Carried by container images the latest versions of 231 of 18,026 indexed charts deploy, on 218 images.

Affected packageAffected versionsFixed inImages
compressionnpm1.5.2, 1.6.2, 1.7.1, 1.7.3+4 more1.8.2218
OSV records
GHSA-vc2v-76pw-4v95

Charts affected

231 by stars
ChartLatestAffected imagesRadar Score
speedtest-trackersoblivionscall3.0.41 of 1See more

speedtest-tracker soblivionscall 3.0.4

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
henrywhitaker3/speedtest-tracker:latest47159a940229
compression@1.7.4
1.8.2

Open the chart page →

2,632
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
compression@1.7.4
1.8.2

Open the chart page →

18,109
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
compression@1.7.4
1.8.2

Open the chart page →

18,193
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
compression@1.7.4
1.8.2

Open the chart page →

16,213
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
compression@1.7.4
1.8.2

Open the chart page →

18,193
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4691 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

1 of the 5 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
compression@1.7.4
1.8.2

Open the chart page →

15,833
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
compression@1.7.4
1.8.2

Open the chart page →

15,833
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
compression@1.7.4
1.8.2

Open the chart page →

17,762
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
compression@1.7.4
1.8.2

Open the chart page →

17,437
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
compression@1.7.4
1.8.2

Open the chart page →

12,574
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
compression@1.7.4
1.8.2

Open the chart page →

12,637
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
compression@1.7.4
1.8.2

Open the chart page →

12,637
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
compression@1.7.4
1.8.2

Open the chart page →

4,151
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
compression@1.8.1
1.8.2

Open the chart page →

6,994
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
compression@1.8.1
1.8.2

Open the chart page →

1,319
uptime-kumasupporttools2.6.01 of 3See more

uptime-kuma supporttools 2.6.0

1 of the 3 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
supporttools/uptime-kuma:v2.6f8a49ed65809
compression@1.7.4
1.8.2

Open the chart page →

5,249
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
compression@1.7.4
1.8.2

Open the chart page →

4,361
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
compression@1.8.1
1.8.2

Open the chart page →

5,002
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
samajh/alprfrontend:latest05ef4fddbb75
compression@1.7.4
1.8.2

Open the chart page →

24,015
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
catalysm/csmm:lateste8e3d06f1d70
compression@1.7.1
1.8.2

Open the chart page →

3,793
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
thingsboard/tb-web-ui:3.4.157f98ed53b3d
compression@1.7.4
1.8.2

Open the chart page →

29,173
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
compression@1.8.1
1.8.2

Open the chart page →

2,471
unleash-proxyunleash0.8.121 of 1See more

unleash-proxy unleash 0.8.12

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
unleashorg/unleash-proxy:v1.4.82538f89e2685
compression@1.7.4
1.8.2

Open the chart page →

1,087
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
compression@1.8.1
1.8.2

Open the chart page →

4,536
devportalveecode-platform-nextVerified publisher1.0.11 of 1See more

devportal veecode-platform-next 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinned881f936ff4a3
compression@1.8.1
1.8.2

Open the chart page →

1,562
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
compression@1.8.1
1.8.2

Open the chart page →

7,503
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
compression@1.7.4
1.8.2

Open the chart page →

3,473
verdacciowener4.35.21 of 1See more

verdaccio wener 4.35.2

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.5560744912b64
compression@1.8.1
1.8.2

Open the chart page →

327
wikiwener2.2.01 of 2See more

wiki wener 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
requarks/wiki:latestfffff288a52f
compression@1.8.1
1.8.2

Open the chart page →

2,599
verdacciowenerme4.35.21 of 1See more

verdaccio wenerme 4.35.2

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.5560744912b64
compression@1.8.1
1.8.2

Open the chart page →

327
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
requarks/wiki:2af71a17dc27c
compression@1.8.1
1.8.2

Open the chart page →

4,321

Container images carrying it

218 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
compression@1.7.4
1.8.2
1
wekanteam/wekan:v4.2268a51f0327df
compression@1.7.1
1.8.2
1
wettyoss/wetty:latestc52dac712353
compression@1.8.1
1.8.2
1
winfred008/amazon:910a68de5b398
compression@1.7.4
1.8.2
1
wiremind/scrapoxy:lateste7048929a676
compression@1.7.4
1.8.2
1
yooooomi/your_spotify_client:1.20.0e4da90a0634c
compression@1.8.1
1.8.2
1
zazuko/trifid:2.3.7054be137de70
compression@1.7.4
1.8.2
1
zwavejs/zwave-js-ui:11.24.2717f9d260902
compression@1.8.1
1.8.2
1
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
compression@1.8.1
1.8.2
1
ghcr.io/blessingnator/keycloak-mcn-backend:2.0.5967470f05472
compression@1.8.1
1.8.2
1
ghcr.io/bluesky-social/pds:0.405e164855fa1
compression@1.8.1
1.8.2
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
compression@1.8.1
1.8.2
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
compression@1.8.1
1.8.2
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
compression@1.7.4
1.8.2
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
compression@1.8.0
1.8.2
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
compression@1.7.3
1.8.2
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
compression@1.7.3
1.8.2
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
compression@1.7.1
1.8.2
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
compression@1.7.3
1.8.2
1
ghcr.io/danny-avila/librechat:v0.7.87fe76551a78e
compression@1.7.4
1.8.2
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
compression@1.7.4
1.8.2
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
compression@1.7.4
1.8.2
1
ghcr.io/data-fair/metrics:0a8d40779eeae
compression@1.7.4
1.8.2
1
ghcr.io/data-fair/notify:3c739b74dabb0
compression@1.8.0
1.8.2
1
ghcr.io/data-fair/portals:18b621866ceb2
compression@1.8.1
1.8.2
1
ghcr.io/data-fair/processings:15a9216989707
compression@1.7.4
1.8.2
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
compression@1.7.4
1.8.2
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
compression@1.8.0
1.8.2
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
compression@1.7.5
1.8.2
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
compression@1.8.0
1.8.2
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
compression@1.8.0
1.8.2
1
ghcr.io/fpsacha/zomboid-panel:v1.0.6605e16dd56cfb
compression@1.8.1
1.8.2
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
compression@1.7.4
1.8.2
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
compression@1.8.1
1.8.2
1
ghcr.io/immich-app/immich-server:v3.2.4d317916b2809
compression@1.8.1
1.8.2
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
compression@1.8.1
1.8.2
1
ghcr.io/linuxserver/audacity:version-3.0.2cdf203db1e50
compression@1.7.4
1.8.2
1
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
compression@1.7.4
1.8.2
1
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
compression@1.7.4
1.8.2
1
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
compression@1.7.4
1.8.2
1
ghcr.io/linuxserver/filezilla:version-3.51.0-r15103cdd266ce
compression@1.7.4
1.8.2
1
ghcr.io/linuxserver/hedgedoc:version-1.9.0792a12ee976a
compression@1.7.4
1.8.2
1
ghcr.io/linuxserver/pixapop:v1.2-ls15605ebc091fa1
compression@1.7.3
1.8.2
1
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
compression@1.7.4
1.8.2
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
compression@1.7.4
1.8.2
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
compression@1.7.4
1.8.2
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
compression@1.7.4
1.8.2
1
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
compression@1.7.4
1.8.2
1
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
compression@1.7.4
1.8.2
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
compression@1.8.1
1.8.2
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.