StackRadar

CVE-2026-9496

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
656
of 17,787 indexed, latest versions
Container images
669
deployed by those charts
Fix available
1 of 2
affected packages

pacote is vulnerable to Denial of Service (DoS) via the addGitSha function

Carried by container images the latest versions of 656 of 17,787 indexed charts deploy, on 669 images.

Affected packageAffected versionsFixed inImages
npmdeb3.5.2-0ubuntu4, 6.14.4+ds-1ubuntu2, 9.2.0~ds1-2, 11.17.0-0no fix listed7
pacotenpm11.2.7, 11.3.1, 11.3.3, 11.3.4+30 more21.5.1663
OSV records
DEBIAN-CVE-2026-9496GHSA-w4pp-8pjf-rmxwUBUNTU-CVE-2026-9496

Charts affected

656 by stars
ChartLatestAffected imagesRadar Score
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
pacote@21.5.0
21.5.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
pacote@21.5.0
21.5.1

Open the chart page →

5,459
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
pacote@18.0.3
21.5.1

Open the chart page →

14,100
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
pacote@13.6.2
21.5.1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
pacote@15.0.8
21.5.1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
pacote@13.6.2
21.5.1
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
pacote@13.6.2
21.5.1

Open the chart page →

16,083
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
pacote@15.1.3
21.5.1

Open the chart page →

1,589
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
pacote@12.0.2
21.5.1

Open the chart page →

3,118

Container images carrying it

669 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
thmmniii/fbs-collab:v1.27.15d389e3c5ce6
pacote@20.0.0
21.5.1
1
thmmniii/fbs-qcm-backend:v1.27.1afbe511e5c24
pacote@18.0.6
21.5.1
1
thmmniii/fbs-qcm-frontend:v1.27.1a347f7f4d144
pacote@18.0.6
21.5.1
1
tobirachel/node-project3:v17d9f37154994
pacote@15.1.3
21.5.1
1
treskon/portrait-ui:DEV-lateste7970783bc8d
pacote@19.0.2
21.5.1
1
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
pacote@15.1.3
21.5.1
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
pacote@18.0.6
21.5.1
1
vabene1111/recipes:2.3.50f8d061895e9
pacote@21.0.0
21.5.1
1
vcnngr/pnbackend:latesteaf44ad0ad1f
pacote@18.0.6
21.5.1
1
veecode/devportalc443520aebf7
pacote@21.5.0
21.5.1
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
pacote@18.0.6
21.5.1
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
pacote@13.6.2
21.5.1
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
pacote@18.0.6
21.5.1
1
visualregressiontracker/migration:5.0.1f983a1d4306e
pacote@15.1.3
21.5.1
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
pacote@15.2.0
21.5.1
1
vlebediantsev/notes-admin-front:latest007c6670ff48
pacote@15.2.0
21.5.1
1
vlebediantsev/notes-project-front:latest945675fd2636
pacote@15.2.0
21.5.1
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
pacote@15.2.0
21.5.1
1
wettyoss/wetty:latest7423b3d40ba2
pacote@20.0.1
21.5.1
1
winfred008/amazon:910a68de5b398
pacote@17.0.4
21.5.1
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
pacote@18.0.3
21.5.1
1
wsjbr/duplistatus:1.4.25e594f5f09f6
pacote@21.5.0
21.5.1
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
pacote@17.0.6
21.5.1
1
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
pacote@18.0.6
21.5.1
1
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
pacote@18.0.6
21.5.1
1
yooooomi/your_spotify_client:1.20.0e4da90a0634c
pacote@21.5.0
21.5.1
1
yooooomi/your_spotify_server:1.20.0624ea009f2ef
pacote@21.5.0
21.5.1
1
youssef11gaber10/deployment-ui-react:latestba6853e35c60
pacote@13.5.0
21.5.1
1
yuzutech/kroki-bpmn:0.29.1444805c4b917
pacote@20.0.0
21.5.1
1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
pacote@19.0.1
21.5.1
1
yuzutech/kroki-excalidraw:0.29.157917319ea70
pacote@20.0.0
21.5.1
1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
pacote@19.0.1
21.5.1
1
zimengxiong/excalidash-backend:0.4.271273af713c91
pacote@18.0.6
21.5.1
1
zimengxiong/excalidash-backend:0.6.0cbdab75f31b2
pacote@18.0.6
21.5.1
1
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
pacote@12.0.2
21.5.1
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
pacote@11.2.7
21.5.1
1
zwavejs/zwave-js-ui:11.22.314d018bb689e
pacote@19.0.1
21.5.1
1
ghcr.io/0xemma/reddark:main2a115e991894
pacote@15.1.3
21.5.1
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
pacote@19.0.1
21.5.1
1
ghcr.io/advplyr/audiobookshelf:2.0.3140aed2752c3
pacote@12.0.3
21.5.1
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
pacote@18.0.6
21.5.1
1
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
pacote@15.1.3
21.5.1
1
ghcr.io/ajnart/homarr:0.13.4985456bdfb46
pacote@15.2.0
21.5.1
1
ghcr.io/ajnart/homarr:lateste103abadfb52
pacote@15.1.3
21.5.1
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
pacote@18.0.6
21.5.1
1
ghcr.io/aolde/lametric-nightscout-proxy:latest7d1951b6baf5
pacote@13.6.2
21.5.1
1
ghcr.io/appscode/platform-ui:2.4.0668ee2682eaf
pacote@20.0.1
21.5.1
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
pacote@18.0.6
21.5.1
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
pacote@18.0.6
21.5.1
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
pacote@17.0.6
21.5.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.