StackRadar

CVE-2026-94485

Medium

Advisory

Published 7 Oct 2026In the index since 8 Oct 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
54
of 18,053 indexed, latest versions
Container images
51
deployed by those charts
Fix available
1 of 1
affected package

Next.js has information disclosure in App Router metadata image routes via dynamicParams bypass

Carried by container images the latest versions of 54 of 18,053 indexed charts deploy, on 51 images.

Affected packageAffected versionsFixed inImages
nextnpm16.0.3, 16.0.10, 16.1.3, 16.1.6+13 more16.3.851
OSV records
GHSA-f87g-xv8r-7p7x

Charts affected

54 by stars
ChartLatestAffected imagesRadar Score
nstuning-apptumogroup0.1.231 of 1See more

nstuning-app tumogroup 0.1.23

1 of the 1 container images this version deploys carry CVE-2026-94485.

Container imageDigestPackageFixed in
sondresjo/nstuning-app:v1.6.1620805ad01071
next@16.3.6
16.3.8

Open the chart page →

931
pyttogpanne-apptumogroup0.1.61 of 1See more

pyttogpanne-app tumogroup 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-94485.

Container imageDigestPackageFixed in
sondresjo/pyttogpanne-app:v1.0.5e9a8d7e36e71
next@16.3.6
16.3.8

Open the chart page →

931
sjolystinnovation-apptumogroup0.1.61 of 1See more

sjolystinnovation-app tumogroup 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-94485.

Container imageDigestPackageFixed in
sondresjo/sjolystinnovation-app:v1.3.11a315219c9c2
next@16.3.6
16.3.8

Open the chart page →

931
homepageunknowniq1.8.81 of 2See more

homepage unknowniq 1.8.8

1 of the 2 container images this version deploys carry CVE-2026-94485.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v2.2.0753eeb0cc22a
next@16.3.3
16.3.8

Open the chart page →

662

Container images carrying it

51 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
next@16.0.3
16.3.8
1

syft 1.42.1 · advisories as of 8 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.