StackRadar

CVE-2026-90771

Low

Advisory

Published 13 Sept 2026In the index since 6 Oct 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.004
31st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
99
of 18,026 indexed, latest versions
Container images
94
deployed by those charts
Fix available
1 of 1
affected package

joi messages compilation allows prototype replacement through __proto__ error codes

Carried by container images the latest versions of 99 of 18,026 indexed charts deploy, on 94 images.

Affected packageAffected versionsFixed inImages
joinpm6.10.1, 10.0.6, 10.6.0, 11.4.0+25 more17.13.8, 18.2.994
OSV records
GHSA-wr44-6hxh-3jwq

Charts affected

99 by stars
ChartLatestAffected imagesRadar Score
shinsei-managerjtektVerified publisher0.2.01 of 8See more

shinsei-manager jtekt 0.2.0

1 of the 8 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
joi@17.7.0
17.13.8

Open the chart page →

68,829
tooljetkrzwiatrzyk1.1.11 of 2See more

tooljet krzwiatrzyk 1.1.1

1 of the 2 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
tooljet/tooljet-ce:v1.18.0c85a4720e42e
joi@17.4.1
17.13.8

Open the chart page →

6,745
seerrkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 1See more

seerr kubernetes-homelab-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
joi@17.13.3
17.13.8

Open the chart page →

3,000
kubevious-agentkubevious1.0.41 of 1See more

kubevious-agent kubevious 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
kubevious/parser:1.0.151acf1a1f0b47
joi@17.4.1
17.13.8

Open the chart page →

2,087
workload-operatorkubevious0.0.31 of 1See more

workload-operator kubevious 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
kubevious/workload-operator:1.0.20b0f4c507eb6
joi@17.9.1
17.13.8

Open the chart page →

2,179
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
joi@17.13.3
17.13.8

Open the chart page →

3,948
efklovemew67Verified publisher0.0.11 of 2See more

efk lovemew67 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
nshou/elasticsearch-kibana:kibana7a1d1e36814d1
joi@17.4.0
17.13.8

Open the chart page →

4,456
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
joi@13.7.0
17.13.8

Open the chart page →

8,165
wudm0sh1-helm-charts0.2.01 of 1See more

wud m0sh1-helm-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
getwud/wud:8.1.1b1cd01c43839
joi@17.13.3
17.13.8

Open the chart page →

7,829
middleware-odigosmiddleware-labsVerified publisher0.2.411 of 6See more

middleware-odigos middleware-labs 0.2.41

1 of the 6 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
joi@17.8.3
17.13.8

Open the chart page →

11,119
middleware-visionmiddleware-labsVerified publisher0.2.651 of 6See more

middleware-vision middleware-labs 0.2.65

1 of the 6 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
joi@17.8.4
17.13.8

Open the chart page →

11,108
aws-api-gateway-operatormintel0.1.21 of 11See more

aws-api-gateway-operator mintel 0.1.2

1 of the 11 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
joi@13.7.0
17.13.8

Open the chart page →

12,077
standard-application-stackmintel11.5.01 of 12See more

standard-application-stack mintel 11.5.0

1 of the 12 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:1.0.039695180364b
joi@13.7.0
17.13.8

Open the chart page →

11,596
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
joi@17.4.2
17.13.8
mojaloop/event-sidecar:v11.0.189b8ab71b74b
joi@13.7.0
17.13.8

Open the chart page →

12,743
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
joi@17.4.2
17.13.8
mojaloop/event-sidecar:v11.0.189b8ab71b74b
joi@13.7.0
17.13.8

Open the chart page →

12,743
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
joi@17.4.0
17.13.8
mojaloop/event-sidecar:v11.0.189b8ab71b74b
joi@13.7.0
17.13.8

Open the chart page →

13,164
bofmojaloop5.1.61 of 1See more

bof mojaloop 5.1.6

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
joi@18.0.1
18.2.9

Open the chart page →

2,900
finance-portalmojaloop5.1.43 of 11See more

finance-portal mojaloop 5.1.4

3 of the 11 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
joi@17.13.3
17.13.8
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
joi@17.13.3
17.13.8
mojaloop/role-assignment-service:v2.1.0def4bf273721
joi@17.12.0
17.13.8

Open the chart page →

16,967
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
joi@13.7.0
17.13.8
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
joi@17.4.0
17.13.8

Open the chart page →

12,263
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
joi@17.4.2
17.13.8
mojaloop/central-ledger:v13.14.01abc8a7aa71c
joi@17.4.0
17.13.8
mojaloop/event-sidecar:v11.0.189b8ab71b74b
joi@13.7.0
17.13.8
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
joi@17.4.0
17.13.8

Open the chart page →

20,648
reporting-events-processor-svcmojaloop3.5.31 of 1See more

reporting-events-processor-svc mojaloop 3.5.3

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
joi@17.13.3
17.13.8

Open the chart page →

3,019
reporting-hub-bop-experience-api-svcmojaloop1.0.31 of 1See more

reporting-hub-bop-experience-api-svc mojaloop 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
joi@17.13.3
17.13.8

Open the chart page →

2,922
role-assignment-servicemojaloop3.1.01 of 1See more

role-assignment-service mojaloop 3.1.0

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
mojaloop/role-assignment-service:v2.1.0def4bf273721
joi@17.12.0
17.13.8

Open the chart page →

2,554
security-role-perm-operator-svcmojaloop3.0.01 of 1See more

security-role-perm-operator-svc mojaloop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
joi@18.0.1
18.2.9

Open the chart page →

2,900
monocularmonocular1.4.152 of 5See more

monocular monocular 1.4.15

2 of the 5 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
joi@10.0.6
17.13.8
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
joi@10.6.0
17.13.8

Open the chart page →

9,155
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
joi@17.11.0
17.13.8

Open the chart page →

28,039
user-manager-neo4jmoreillonVerified publisher0.9.71 of 6See more

user-manager-neo4j moreillon 0.9.7

1 of the 6 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
moreillon/user-manager:v5.0.2e1c9bfab5c16
joi@17.7.0
17.13.8

Open the chart page →

32,937
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
joi@17.12.0
17.13.8

Open the chart page →

2,966
praecoone-acre-fundVerified publisher0.2.01 of 3See more

praeco one-acre-fund 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
praecoapp/elastalert-server:202302195a0d8715e8b1
joi@17.8.0
17.13.8

Open the chart page →

9,849
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
joi@14.3.1
17.13.8

Open the chart page →

234,921
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
library/arangodb:3.11.81e75d74954a4
joi@14.3.1
17.13.8

Open the chart page →

8,081
console-webovrclk-20.1.11 of 1See more

console-web ovrclk-2 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
ghcr.io/akash-network/deploy-web:2.46.0ac540172c120
joi@17.13.3
17.13.8

Open the chart page →

3,154
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
joi@17.11.0
17.13.8

Open the chart page →

6,943
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
joi@17.11.0
17.13.8

Open the chart page →

8,151
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
joi@17.13.1
17.13.8

Open the chart page →

20,820
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
joi@17.13.1
17.13.8

Open the chart page →

17,329
uptime-kumasarab97Verified publisher0.1.51 of 1See more

uptime-kuma sarab97 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.22.10b55bcb83a1c
joi@14.3.1
17.13.8

Open the chart page →

5,983
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
joi@11.4.0
17.13.8

Open the chart page →

4,151
uptime-kumasupporttools2.6.01 of 3See more

uptime-kuma supporttools 2.6.0

1 of the 3 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
supporttools/uptime-kuma:v2.6f8a49ed65809
joi@14.3.1
17.13.8

Open the chart page →

5,249
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
joi@14.3.1
17.13.8

Open the chart page →

8,660
learning-fluentdtungntt0.1.01 of 4See more

learning-fluentd tungntt 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
library/kibana:7.9.1b1bbcaa57738
joi@13.7.0
17.13.8

Open the chart page →

8,494
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
joi@18.0.2
18.2.9

Open the chart page →

2,471
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
joi@17.13.3
17.13.8

Open the chart page →

5,829
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
joi@18.0.2
18.2.9

Open the chart page →

5,214
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
joi@14.3.1
17.13.8

Open the chart page →

7,239
opensearch-dashboardswener3.9.01 of 1See more

opensearch-dashboards wener 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
joi@18.2.8
18.2.9

Open the chart page →

312
opensearch-dashboardswenerme3.9.01 of 1See more

opensearch-dashboards wenerme 3.9.0

1 of the 1 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
joi@18.2.8
18.2.9

Open the chart page →

312
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
joi@13.7.0
17.13.8

Open the chart page →

6,098
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-90771.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
joi@14.3.1
17.13.8

Open the chart page →

12,360

Container images carrying it

94 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
joi@13.7.0
17.13.8
5
decisionrules/server:latestbb3a93224b5a
joi@17.13.7
17.13.8
4
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
joi@17.4.2
17.13.8
3
opensearchproject/opensearch-dashboards:3.9.04bdb8ded547c
joi@18.2.8
18.2.9
3
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
joi@13.7.0
17.13.8
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
joi@17.13.1
17.13.8
2
library/arangodb:3.11.81e75d74954a4
joi@14.3.1
17.13.8
2
louislam/uptime-kuma:1.23.1396510915e6be
joi@14.3.1
17.13.8
2
migmartri/prerender:latest486aacfd5aa9
joi@10.0.6
17.13.8
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
joi@17.4.0
17.13.8
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
joi@17.4.0
17.13.8
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
joi@17.13.3
17.13.8
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
joi@17.13.3
17.13.8
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
joi@17.12.0
17.13.8
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
joi@18.0.1
18.2.9
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
joi@17.7.0
17.13.8
2
opensearchproject/opensearch-dashboards:1.0.039695180364b
joi@13.7.0
17.13.8
2
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
joi@13.7.0
17.13.8
1
apimap/developer:v1.3.1406d3858e20c
joi@17.6.0
17.13.8
1
apimap/portal:v2.4.0041a4790c65c
joi@17.6.0
17.13.8
1
assistiot/cybersecurity-monitoring_id-kbn:latest2297b4350211
joi@13.7.0
17.13.8
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
joi@13.7.0
17.13.8
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
joi@17.6.0
17.13.8
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
joi@17.6.0
17.13.8
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
joi@17.6.0
17.13.8
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
joi@17.4.2
17.13.8
1
budibase/apps:3.41.344fe6feab985
joi@18.2.1
18.2.9
1
budibase/worker:3.41.3de5e2e560ce8
joi@18.2.1
18.2.9
1
codiacimages/codiac-cluster-agent:1.0.380cd44ca7a7ee
joi@18.0.2
18.2.9
1
cryptexlabs/authf:0.12.11189c07411d7c
joi@17.13.3
17.13.8
1
denisshav/backend:latest4cc8dc5a4499
joi@14.3.1
17.13.8
1
directus/directus:12.0.29c8470ea465c
joi@18.0.1
18.2.9
1
directus/directus:11.1.0e3c8bb975350
joi@17.13.3
17.13.8
1
fallenbagel/jellyseerr:latest4538137bc5af
joi@17.13.3
17.13.8
1
fallenbagel/jellyseerr:2.2.3a324fa4d81cc
joi@17.13.3
17.13.8
1
getwud/wud:8.1.1b1cd01c43839
joi@17.13.3
17.13.8
1
globalping/globalping-probe:latestb8469caf783a
joi@17.13.3
17.13.8
1
heywood8/redisinsight:2.28.00bc9ab313d37
joi@17.9.2
17.13.8
1
ibmcom/microclimate-portal:latested5505e5c7ec
joi@6.10.1
17.13.8
1
jayfong/yapi:1.10.2163e5d621910
joi@6.10.1
17.13.8
1
joplin/server:3.0-beta52af57880c0e
joi@17.11.0
17.13.8
1
kubevious/backend:1.2.22d9ba6eb46b6
joi@17.9.2
17.13.8
1
kubevious/collector:1.2.1f58226f9d84e
joi@17.9.2
17.13.8
1
kubevious/guard:1.2.19bf567704de2
joi@17.6.0
17.13.8
1
kubevious/parser:1.0.151acf1a1f0b47
joi@17.4.1
17.13.8
1
kubevious/parser:1.2.299ae7a5168c2
joi@17.9.2
17.13.8
1
kubevious/workload-operator:1.0.20b0f4c507eb6
joi@17.9.1
17.13.8
1
library/kibana:7.17.150172f1c538e7
joi@17.7.1
17.13.8
1
library/kibana:7.9.1b1bbcaa57738
joi@13.7.0
17.13.8
1
library/kibana:7.17.8c5781ba340ef
joi@17.4.0
17.13.8
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.