StackRadar

CVE-2026-87776

High

Advisory

Published 5 Oct 2026In the index since 6 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
47th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
231
of 18,026 indexed, latest versions
Container images
218
deployed by those charts
Fix available
1 of 1
affected package

compression vulnerable to Denial of Service via memory leak on premature response close

Carried by container images the latest versions of 231 of 18,026 indexed charts deploy, on 218 images.

Affected packageAffected versionsFixed inImages
compressionnpm1.5.2, 1.6.2, 1.7.1, 1.7.3+4 more1.8.2218
OSV records
GHSA-vc2v-76pw-4v95

Charts affected

231 by stars
ChartLatestAffected imagesRadar Score
mojaloopmojaloop14.0.03 of 6See more

mojaloop mojaloop 14.0.0

3 of the 6 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
compression@1.7.4
1.8.2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
compression@1.7.4
1.8.2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
compression@1.7.4
1.8.2

Open the chart page →

20,648
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
compression@1.8.1
1.8.2

Open the chart page →

3,019
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
compression@1.8.0
1.8.2

Open the chart page →

2,922
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
compression@1.7.4
1.8.2

Open the chart page →

2,554
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
compression@1.8.1
1.8.2

Open the chart page →

2,900
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
compression@1.7.4
1.8.2

Open the chart page →

8,148
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
compression@1.7.4
1.8.2

Open the chart page →

5,290
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
compression@1.8.1
1.8.2

Open the chart page →

6,165
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
compression@1.7.4
1.8.2

Open the chart page →

7,398
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
compression@1.7.4
1.8.2

Open the chart page →

3,879
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
compression@1.7.4
1.8.2

Open the chart page →

2,388
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
compression@1.7.4
1.8.2

Open the chart page →

2,388
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
compression@1.7.4
1.8.2

Open the chart page →

2,430
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
compression@1.7.4
1.8.2

Open the chart page →

2,388
my-helm-chartmy-helm-chart0.1.01 of 3See more

my-helm-chart my-helm-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
lyzhang1999/frontend:latest4b25cf264fd7
compression@1.7.4
1.8.2

Open the chart page →

4,598
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
compression@1.7.4
1.8.2

Open the chart page →

20,021
n8nn8n-openshiftVerified publisher1.18.01 of 1See more

n8n n8n-openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
compression@1.8.1
1.8.2

Open the chart page →

2,259
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
compression@1.7.4
1.8.2

Open the chart page →

3,474
smilencsaVerified publisher1.1.01 of 23See more

smile ncsa 1.1.0

1 of the 23 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
compression@1.7.4
1.8.2

Open the chart page →

291,203
uptime-kumancsaVerified publisher1.7.31 of 1See more

uptime-kuma ncsa 1.7.3

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.5c74379ac4509
compression@1.8.1
1.8.2

Open the chart page →

34,014
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
compression@1.8.1
1.8.2

Open the chart page →

2,881
audacitynicholaswildeVerified publisher0.1.41 of 1See more

audacity nicholaswilde 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/audacity:version-3.0.2cdf203db1e50
compression@1.7.4
1.8.2

Open the chart page →

24,362
digikamnicholaswildeVerified publisher1.0.01 of 1See more

digikam nicholaswilde 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/digikam:version-7.3.055b4c7f320ae
compression@1.7.4
1.8.2

Open the chart page →

26,418
doublecommandernicholaswildeVerified publisher1.0.21 of 1See more

doublecommander nicholaswilde 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/doublecommander:version-0.8.2-1d92969a929c2
compression@1.7.4
1.8.2

Open the chart page →

27,585
filezillanicholaswildeVerified publisher1.0.11 of 1See more

filezilla nicholaswilde 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/filezilla:version-3.51.0-r15103cdd266ce
compression@1.7.4
1.8.2

Open the chart page →

4,268
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
compression@1.7.4
1.8.2

Open the chart page →

16,104
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
compression@1.7.4
1.8.2

Open the chart page →

16,182
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
compression@1.7.4
1.8.2

Open the chart page →

16,160
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
compression@1.7.4
1.8.2

Open the chart page →

29,024
praecoone-acre-fundVerified publisher0.2.01 of 3See more

praeco one-acre-fund 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
praecoapp/praeco:1.8.1322be3218d7df
compression@1.7.4
1.8.2

Open the chart page →

9,849
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
compression@1.7.4
1.8.2

Open the chart page →

10,448
n8nopenshift1.18.01 of 1See more

n8n openshift 1.18.0

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
n8nio/n8n:2.36.714c4285bc303
compression@1.8.1
1.8.2

Open the chart page →

2,259
code-serverquench-code-serverVerified publisher0.0.161 of 1See more

code-server quench-code-server 0.0.16

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/code-serverdigest-pinnedb47da07b47ff
compression@1.8.1
1.8.2

Open the chart page →

49
uptime-kumaquench-uptime-kuma0.0.61 of 1See more

uptime-kuma quench-uptime-kuma 0.0.6

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
ghcr.io/quenchworks/images/uptime-kumadigest-pinned438b24dc0ab9
compression@1.8.1
1.8.2

Open the chart page →

78
claude-relayrevolution10.1.371 of 4See more

claude-relay revolution1 0.1.37

1 of the 4 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
compression@1.8.1
1.8.2

Open the chart page →

5,926
jsonplaceholderrgnu1.0.01 of 1See more

jsonplaceholder rgnu 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
svenwal/jsonplaceholder:latestba2f285af432
compression@1.7.4
1.8.2

Open the chart page →

1,641
jsonvisiorlex0.1.01 of 1See more

jsonvisio rlex 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
rlex/jsonvisio:1.9.5cd50ff65118e
compression@1.7.4
1.8.2

Open the chart page →

2,825
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
compression@1.7.4
1.8.2

Open the chart page →

8,151
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
compression@1.8.1
1.8.2

Open the chart page →

34,228
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
yooooomi/your_spotify_client:1.20.0e4da90a0634c
compression@1.8.1
1.8.2

Open the chart page →

6,358
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
compression@1.7.4
1.8.2

Open the chart page →

5,983
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
compression@1.7.4
1.8.2

Open the chart page →

3,473
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
compression@1.7.1
1.8.2

Open the chart page →

3,908
semaphoreschoenwald0.1.31 of 1See more

semaphore schoenwald 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
0hlov3/semaphore:v1.0.050f874ec096b
compression@1.7.4
1.8.2

Open the chart page →

1,946
uptime-kumaschoenwald1.0.101 of 1See more

uptime-kuma schoenwald 1.0.10

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
compression@1.8.1
1.8.2

Open the chart page →

34,025
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
compression@1.7.4
1.8.2

Open the chart page →

7,177
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
compression@1.7.4
1.8.2

Open the chart page →

3,377
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
compression@1.8.1
1.8.2

Open the chart page →

3,645
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
compression@1.7.4
1.8.2

Open the chart page →

4,428
sneakerssneakers1.0.01 of 4See more

sneakers sneakers 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-87776.

Container imageDigestPackageFixed in
helga09/shoes_ukr:v1.1.17999bc8b77c0
compression@1.7.4
1.8.2

Open the chart page →

9,977

Container images carrying it

218 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
compression@1.7.4
1.8.2
3
pantsel/konga:latestc8172b75607d
compression@1.6.2
1.8.2
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
compression@1.7.4
1.8.2
3
verdaccio/verdaccio:6.10.5560744912b64
compression@1.8.1
1.8.2
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
compression@1.8.1
1.8.2
3
chatwoot/chatwoot:v3.1.0d530ab8c1753
compression@1.7.4
1.8.2
2
governify/registry:v3.4.0d3f37f4f8168
compression@1.7.4
1.8.2
2
governify/render:v2.2.0daeca1ce28e6
compression@1.7.4
1.8.2
2
governify/reporter:v2.2.038595913458f
compression@1.7.4
1.8.2
2
library/ghost:6.67.0428ce627d581
compression@1.8.1
1.8.2
2
louislam/uptime-kuma:2.5.4917318f9d7be
compression@1.8.1
1.8.2
2
louislam/uptime-kuma:1.23.1396510915e6be
compression@1.7.4
1.8.2
2
louislam/uptime-kuma:2.3.29aeb4e51d038
compression@1.8.1
1.8.2
2
louislam/uptime-kuma:2.5.0a8610b3b4c38
compression@1.8.1
1.8.2
2
louislam/uptime-kuma:2.5.5c74379ac4509
compression@1.8.1
1.8.2
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
compression@1.7.4
1.8.2
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
compression@1.7.4
1.8.2
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
compression@1.7.4
1.8.2
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
compression@1.8.1
1.8.2
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
compression@1.8.0
1.8.2
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
compression@1.7.4
1.8.2
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
compression@1.8.1
1.8.2
2
n8nio/n8n:2.36.714c4285bc303
compression@1.8.1
1.8.2
2
requarks/wiki:latestfffff288a52f
compression@1.8.1
1.8.2
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
compression@1.8.1
1.8.2
2
stakater/stakater-nordmart-review-ui:1.0.143f4926eedc74
compression@1.7.4
1.8.2
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
compression@1.7.4
1.8.2
2
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
compression@1.8.1
1.8.2
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
compression@1.7.4
1.8.2
2
ghcr.io/techno-tim/littlelink-server:lateste84ea9d93b60
compression@1.8.0
1.8.2
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
compression@1.7.4
1.8.2
2
0hlov3/semaphore:v1.0.050f874ec096b
compression@1.7.4
1.8.2
1
apimap/developer:v1.3.1406d3858e20c
compression@1.7.4
1.8.2
1
apimap/portal:v2.4.0041a4790c65c
compression@1.7.4
1.8.2
1
arfath29/3-tier-app-frontend:latest384b3e377f47
compression@1.7.4
1.8.2
1
assistiot/open_api_frontend:1.0.1f11d82defc70
compression@1.7.4
1.8.2
1
baserow/baserow:1.30.1df0c42eb67e8
compression@1.7.4
1.8.2
1
catalysm/csmm:lateste8e3d06f1d70
compression@1.7.1
1.8.2
1
cccs/assemblyline-ui-frontend:4.7.4.stable21c00e72d90666
compression@1.8.1
1.8.2
1
ccjacobs14/amazon:59a9b14a6f09e
compression@1.7.4
1.8.2
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
compression@1.7.4
1.8.2
1
codercom/code-server:4.11.0-debian1e2cc688008e
compression@1.7.4
1.8.2
1
codercom/code-server:3.10.247605610ad8d
compression@1.7.4
1.8.2
1
coldatom/containers-security-front:latest7c2fbbb41bcf
compression@1.7.4
1.8.2
1
conduction/conduction-ui-app:devd591f5e6f2a9
compression@1.7.4
1.8.2
1
cyfershepard/jellystat:1.1.12e61c759ec706
compression@1.8.1
1.8.2
1
datarhei/restreamer:0.6.4655e12f9eeed
compression@1.7.4
1.8.2
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
compression@1.7.4
1.8.2
1
enketo/enketo-express:3.0.4dcad9c2273f6
compression@1.7.4
1.8.2
1
evoapicloud/evolution-api:latest966625532d90
compression@1.8.1
1.8.2
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.