StackRadar

CVE-2026-9496

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
666
of 17,787 indexed, latest versions
Container images
680
deployed by those charts
Fix available
1 of 2
affected packages

pacote is vulnerable to Denial of Service (DoS) via the addGitSha function

Carried by container images the latest versions of 666 of 17,787 indexed charts deploy, on 680 images.

Affected packageAffected versionsFixed inImages
npmdeb3.5.2-0ubuntu4, 6.14.4+ds-1ubuntu2, 9.2.0~ds1-2, 9.2.0~ds1-3+1 moreno fix listed8
pacotenpm11.2.7, 11.3.1, 11.3.3, 11.3.4+30 more21.5.1674
OSV records
DEBIAN-CVE-2026-9496GHSA-w4pp-8pjf-rmxwUBUNTU-CVE-2026-9496

Charts affected

666 by stars
ChartLatestAffected imagesRadar Score
resultappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
pacote@13.6.2
21.5.1

Open the chart page →

1,263
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
pacote@13.6.2
21.5.1

Open the chart page →

8,287
resultappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
pacote@13.6.2
21.5.1

Open the chart page →

1,263
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
pacote@13.6.2
21.5.1

Open the chart page →

8,287
websitewaldo-visionVerified publisher0.33.02 of 2See more

website waldo-vision 0.33.0

2 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
pacote@15.1.1
21.5.1
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
pacote@15.1.1
21.5.1

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
pacote@20.0.0
21.5.1

Open the chart page →

5,774
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
pacote@11.3.1
21.5.1

Open the chart page →

2,559
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
pacote@12.0.2
21.5.1

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
pacote@12.0.2
21.5.1

Open the chart page →

28,699
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
pacote@21.5.0
21.5.1

Open the chart page →

1,634
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
pacote@21.5.0
21.5.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
pacote@21.5.0
21.5.1

Open the chart page →

5,472
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
pacote@18.0.3
21.5.1

Open the chart page →

14,172
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
pacote@13.6.2
21.5.1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
pacote@15.0.8
21.5.1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
pacote@13.6.2
21.5.1
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
pacote@13.6.2
21.5.1

Open the chart page →

16,083
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
pacote@15.1.3
21.5.1

Open the chart page →

1,588
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
pacote@12.0.2
21.5.1

Open the chart page →

3,118

Container images carrying it

680 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
pacote@21.5.0
21.5.1
1
ghcr.io/hiteshnayak305/cors-proxy:1.2.0e6ff0a131556
pacote@21.0.0
21.5.1
1
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
pacote@21.5.0
21.5.1
1
ghcr.io/homarr-labs/homarr:v1.77.0f23ad77a681b
pacote@21.5.0
21.5.1
1
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
pacote@18.0.6
21.5.1
1
ghcr.io/huscker/townsquare-backend:2.15.2e106681e7673
pacote@18.0.6
21.5.1
1
ghcr.io/ignisda/ryot:v10.5.0a752b6aee537
pacote@21.0.0
21.5.1
1
ghcr.io/immich-app/immich-server:v3.2.12ab6a6273755
pacote@21.5.0
21.5.1
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
pacote@21.4.0
21.5.1
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
pacote@19.0.1
21.5.1
1
ghcr.io/jeboehm/fetchmailmgr:0.3.2126c4691b28a4
pacote@19.0.1
21.5.1
1
ghcr.io/jens-maus/raspberrymatic:3.83.6.202508244b22b4f407c4
pacote@19.0.1
21.5.1
1
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
pacote@18.0.6
21.5.1
1
ghcr.io/jordan-dalby/bytestash:1.5.12eb4f736b8cd4
pacote@19.0.2
21.5.1
1
ghcr.io/jr0dd/puppeteer:v13.3.26047599cd78e
pacote@12.0.3
21.5.1
1
ghcr.io/k10app/basicuserservice:latest2ee057ad3bef
pacote@13.6.2
21.5.1
1
ghcr.io/k10app/catalog:latest639c980be0f1
pacote@13.6.2
21.5.1
1
ghcr.io/k10app/order:lateste1017d0dbd78
pacote@15.0.7
21.5.1
1
ghcr.io/kadajett/podscope:0.2.3eeedf17112d7
pacote@18.0.6
21.5.1
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
pacote@19.0.1
21.5.1
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
pacote@21.5.0
21.5.1
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
pacote@20.0.0
21.5.1
1
ghcr.io/kikplate/kikplate-web:main34bbb61e8e42
pacote@19.0.2
21.5.1
1
ghcr.io/kubedb/mongo-gui:latestee0354b7a57a
pacote@13.5.0
21.5.1
1
ghcr.io/kubiyabot/agent-manager:v0.4.13757bdd779345
pacote@18.0.6
21.5.1
1
ghcr.io/kubiyabot/workflow-engine:v1.46.2560a16a56d4e
pacote@17.0.5
21.5.1
1
ghcr.io/leprechaun/lgtv2mqtt:latestac2e11c41ffb
pacote@13.6.2
21.5.1
1
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
pacote@21.4.0
21.5.1
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
pacote@20.0.1
21.5.1
1
ghcr.io/linuxserver/pairdrop:version-v1.11.23279d2d986c0
pacote@21.0.4
21.5.1
1
ghcr.io/lockdep/stackradar-scanner:0.3.0dd8a35d50c2d
pacote@19.0.2
21.5.1
1
ghcr.io/logtide-dev/logtide-backend:1.0.265463e02f887
pacote@18.0.6
21.5.1
1
ghcr.io/logtide-dev/logtide-frontend:1.0.22a7da1451f86
pacote@18.0.6
21.5.1
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pacote@18.0.6
21.5.1
1
ghcr.io/m9sweeper/dash:1.6.02e27cdff8344
pacote@17.0.4
21.5.1
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
pacote@18.0.6
21.5.1
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
pacote@18.0.6
21.5.1
1
ghcr.io/manzil-infinity180/frontend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b44e6394b715d9
pacote@18.0.6
21.5.1
1
ghcr.io/marcuwynu23/express-typescript-sample:latest9ef671b78ea8
pacote@19.0.2
21.5.1
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
pacote@11.3.4
21.5.1
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
pacote@13.6.2
21.5.1
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
pacote@18.0.6
21.5.1
1
ghcr.io/michaelhaigh/pacman:latestb0931b1f085d
pacote@19.0.2
21.5.1
1
ghcr.io/microboxlabs/miot-docs:latest0307d2fd9f5c
pacote@20.0.1
21.5.1
1
ghcr.io/microboxlabs/miot-docs:lateste09d92c61f43
pacote@19.0.2
21.5.1
1
ghcr.io/middleware-labs/odigos-ui:middleware-test-0.0.787120a4561a9
pacote@13.6.2
21.5.1
1
ghcr.io/middleware-labs/vision-ui:middleware-test-0.0.853772b7b42c7
pacote@13.6.2
21.5.1
1
ghcr.io/mrprimate/ddb-proxy:0.0.258dc2d7fb460f
pacote@13.6.2
21.5.1
1
ghcr.io/multica-ai/multica-web:v0.4.43fc937fbbf8e5
pacote@20.0.1
21.5.1
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
pacote@21.0.3
21.5.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.