StackRadar

CVE-2026-92599

High

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
58
of 17,957 indexed, latest versions
Container images
59
deployed by those charts
Fix available
1 of 1
affected package

joi: Quadratic regular-expression backtracking in `Joi.string().isoDate()`

Carried by container images the latest versions of 58 of 17,957 indexed charts deploy, on 59 images.

Affected packageAffected versionsFixed inImages
joinpm17.4.0, 17.4.1, 17.4.2, 17.6.0+17 more17.13.7, 18.2.659
OSV records
GHSA-6h2x-m376-mqjq

Charts affected

58 by stars
ChartLatestAffected imagesRadar Score
console-webovrclk-20.1.11 of 1See more

console-web ovrclk-2 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-92599.

Container imageDigestPackageFixed in
ghcr.io/akash-network/deploy-web:2.46.0ac540172c120
joi@17.13.3
17.13.7

Open the chart page →

2,920
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-92599.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
joi@17.11.0
17.13.7

Open the chart page →

6,430
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-92599.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
joi@17.11.0
17.13.7

Open the chart page →

7,939
safe-stacksafe-global0.1.01 of 9See more

safe-stack safe-global 0.1.0

1 of the 9 container images this version deploys carry CVE-2026-92599.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
joi@17.13.1
17.13.7

Open the chart page →

20,302
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-92599.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
joi@17.13.1
17.13.7

Open the chart page →

16,987
unleash-enterpriseunleash1.0.31 of 1See more

unleash-enterprise unleash 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-92599.

Container imageDigestPackageFixed in
unleashorg/unleash-enterprise:7.5.0245aeba40053
joi@18.0.2
18.2.6

Open the chart page →

2,331
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2026-92599.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
joi@17.13.3
17.13.7

Open the chart page →

5,256
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-92599.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
joi@18.0.2
18.2.6

Open the chart page →

4,954

Container images carrying it

59 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/exposr/exposrd:v0.12.0561c8f23bdb6
joi@17.6.0
17.13.7
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
joi@17.13.3
17.13.7
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
joi@17.11.0
17.13.7
1
ghcr.io/linuxserver/mstream:version-v5.2.522c012bcc43c
joi@17.4.2
17.13.7
1
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
joi@17.8.3
17.13.7
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
joi@17.8.4
17.13.7
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
joi@17.13.3
17.13.7
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
joi@17.11.0
17.13.7
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
joi@17.13.6
17.13.7
1

syft 1.42.1 · advisories as of 30 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.