StackRadar

CVE-2026-90776

High

Advisory

Published 30 Sept 2026In the index since 1 Oct 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,985 indexed, latest versions
Container images
9
deployed by those charts
Fix available
1 of 1
affected package

Nodemailer addressparser: O(n^2) on comment-joined addresses enables a remote DoS (reachable via mailparser)

Carried by container images the latest versions of 9 of 17,985 indexed charts deploy, on 9 images.

Affected packageAffected versionsFixed inImages
nodemailernpm9.1.1, 10.0.1, 10.0.210.0.59
OSV records
GHSA-prgh-xp8r-p3m5

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
ghostcloudpirates-ghostVerified publisher0.20.261 of 3See more

ghost cloudpirates-ghost 0.20.26

1 of the 3 container images this version deploys carry CVE-2026-90776.

Container imageDigestPackageFixed in
library/ghost:6.64.0586821cfebac
nodemailer@10.0.1
10.0.5

Open the chart page →

7,901
ghost-on-kubernetesghost-on-kubernetes-helmVerified publisher1.1.21 of 3See more

ghost-on-kubernetes ghost-on-kubernetes-helm 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-90776.

Container imageDigestPackageFixed in
ghcr.io/sredevopsorg/ghost-on-kubernetes:main06adb21bfdfc
nodemailer@10.0.1
10.0.5

Open the chart page →

1,979
ghostchart-ghost0.1.61 of 2See more

ghost chart-ghost 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-90776.

Container imageDigestPackageFixed in
library/ghost:6.65.0-alpine3.23fea3264f902e
nodemailer@10.0.1
10.0.5

Open the chart page →

1,450
ghosthelmforgeVerified publisher1.2.101 of 3See more

ghost helmforge 1.2.10

1 of the 3 container images this version deploys carry CVE-2026-90776.

Container imageDigestPackageFixed in
library/ghost:6.65.090592b712b6b
nodemailer@10.0.1
10.0.5

Open the chart page →

2,979
reactive-resumehelmforgeVerified publisher1.0.01 of 4See more

reactive-resume helmforge 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-90776.

Container imageDigestPackageFixed in
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
nodemailer@10.0.2
10.0.5

Open the chart page →

3,134
twentyhelmforgeVerified publisher1.0.31 of 5See more

twenty helmforge 1.0.3

1 of the 5 container images this version deploys carry CVE-2026-90776.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.43.0b2b662b1bef1
nodemailer@9.1.1
10.0.5

Open the chart page →

2,811
nocodbinseefrlab0.2.01 of 1See more

nocodb inseefrlab 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-90776.

Container imageDigestPackageFixed in
nocodb/nocodb:latest4ccfc5114506
nodemailer@9.1.1
10.0.5

Open the chart page →

758
prismeai-coreprismeai1.12.31 of 7See more

prismeai-core prismeai 1.12.3

1 of the 7 container images this version deploys carry CVE-2026-90776.

Container imageDigestPackageFixed in
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
nodemailer@9.1.1
10.0.5

Open the chart page →

5,061
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-90776.

Container imageDigestPackageFixed in
twentycrm/twenty:latest47bcefe4e497
nodemailer@9.1.1
10.0.5

Open the chart page →

73,550

Container images carrying it

9 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/ghost:6.64.0586821cfebac
nodemailer@10.0.1
10.0.5
1
library/ghost:6.65.090592b712b6b
nodemailer@10.0.1
10.0.5
1
library/ghost:6.65.0-alpine3.23fea3264f902e
nodemailer@10.0.1
10.0.5
1
nocodb/nocodb:latest4ccfc5114506
nodemailer@9.1.1
10.0.5
1
twentycrm/twenty:latest:v2.41.047bcefe4e497
nodemailer@9.1.1
10.0.5
1
twentycrm/twenty:v2.43.0b2b662b1bef1
nodemailer@9.1.1
10.0.5
1
ghcr.io/amruthpillai/reactive-resume:v5.3.0c487ec5edcfe
nodemailer@10.0.2
10.0.5
1
ghcr.io/sredevopsorg/ghost-on-kubernetes:main06adb21bfdfc
nodemailer@10.0.1
10.0.5
1
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-api-gateway:prodf8474a665b11
nodemailer@9.1.1
10.0.5
1

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.