StackRadar

CVE-2026-9496

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
666
of 17,787 indexed, latest versions
Container images
680
deployed by those charts
Fix available
1 of 2
affected packages

pacote is vulnerable to Denial of Service (DoS) via the addGitSha function

Carried by container images the latest versions of 666 of 17,787 indexed charts deploy, on 680 images.

Affected packageAffected versionsFixed inImages
npmdeb3.5.2-0ubuntu4, 6.14.4+ds-1ubuntu2, 9.2.0~ds1-2, 9.2.0~ds1-3+1 moreno fix listed8
pacotenpm11.2.7, 11.3.1, 11.3.3, 11.3.4+30 more21.5.1674
OSV records
DEBIAN-CVE-2026-9496GHSA-w4pp-8pjf-rmxwUBUNTU-CVE-2026-9496

Charts affected

666 by stars
ChartLatestAffected imagesRadar Score
resultappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
pacote@13.6.2
21.5.1

Open the chart page →

1,263
voteappvoting-app-helm-charts-repoVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
pacote@13.6.2
21.5.1

Open the chart page →

8,287
resultappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
pacote@13.6.2
21.5.1

Open the chart page →

1,263
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
pacote@13.6.2
21.5.1

Open the chart page →

8,287
websitewaldo-visionVerified publisher0.33.02 of 2See more

website waldo-vision 0.33.0

2 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
pacote@15.1.1
21.5.1
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
pacote@15.1.1
21.5.1

Open the chart page →

3,474
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
pacote@20.0.0
21.5.1

Open the chart page →

5,774
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
pacote@11.3.1
21.5.1

Open the chart page →

2,559
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
pacote@12.0.2
21.5.1

Open the chart page →

14,420
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
pacote@12.0.2
21.5.1

Open the chart page →

28,699
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
pacote@21.5.0
21.5.1

Open the chart page →

1,634
verdacciowenerme4.35.11 of 1See more

verdaccio wenerme 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
pacote@21.5.0
21.5.1

Open the chart page →

215
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
pacote@21.5.0
21.5.1

Open the chart page →

5,472
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
pacote@18.0.3
21.5.1

Open the chart page →

14,172
workadventureworkadventure1.1.04 of 9See more

workadventure workadventure 1.1.0

4 of the 9 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
thecodingmachine/workadventure-back:v1.17.764001369dad5
pacote@13.6.2
21.5.1
thecodingmachine/workadventure-map-storage:v1.17.75bdab56da2fa
pacote@15.0.8
21.5.1
thecodingmachine/workadventure-play:v1.17.7d8f66979b9b4
pacote@13.6.2
21.5.1
thecodingmachine/workadventure-uploader:v1.17.73ccd467543b3
pacote@13.6.2
21.5.1

Open the chart page →

16,083
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
pacote@15.1.3
21.5.1

Open the chart page →

1,588
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
pacote@12.0.2
21.5.1

Open the chart page →

3,118

Container images carrying it

680 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/openccu/openccu:3.89.9.20260914eaeefd355dca
pacote@20.0.1
21.5.1
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
pacote@21.5.0
21.5.1
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
pacote@21.1.0
21.5.1
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
pacote@18.0.6
21.5.1
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
pacote@18.0.6
21.5.1
1
ghcr.io/open-telemetry/demo:1.12.0-paymentserviceb0f13eef3abf
pacote@17.0.6
21.5.1
1
ghcr.io/open-telemetry/demo:1.12.0-flagduif6bdafaa9075
pacote@18.0.6
21.5.1
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
pacote@13.5.0
21.5.1
1
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
pacote@20.0.0
21.5.1
1
ghcr.io/radar-base/radar-self-enrolment-ui:0.1.0b9a7cd3cc099
pacote@19.0.1
21.5.1
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
pacote@19.0.1
21.5.1
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
pacote@13.6.2
21.5.1
1
ghcr.io/sct/overseerr:1.35.06197516c9d7b
pacote@18.0.6
21.5.1
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
pacote@18.0.6
21.5.1
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
pacote@19.0.1
21.5.1
1
ghcr.io/shuguet/pacman:latesta0ec71732c3c
pacote@21.5.0
21.5.1
1
ghcr.io/solucteam/outscale-s3-explorer:v1.0.09665c3e71889
pacote@18.0.6
21.5.1
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
pacote@19.0.1
21.5.1
1
ghcr.io/talhajuikar/stateful-data-generator:v1.1.1dfd7ea7303a2
pacote@13.6.2
21.5.1
1
ghcr.io/techno-tim/littlelink-server:latest735a1fcd078b
pacote@17.0.4
21.5.1
1
ghcr.io/theconnman/docker-hub-rss:0.6.238eba84b2be8
pacote@19.0.1
21.5.1
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
pacote@21.5.0
21.5.1
1
ghcr.io/toeverything/affine:0.27.4b649f5ce2384
pacote@19.0.2
21.5.1
1
ghcr.io/trieb-work/saleor-apps/saleor-app-products-feed:1.23.11d435b4ab372
pacote@20.0.0
21.5.1
1
ghcr.io/trieb-work/saleor-apps/saleor-app-search:1.24.328edefb6c92d
pacote@20.0.0
21.5.1
1
ghcr.io/trieb-work/saleor-apps/saleor-app-smtp:1.4.357a06bfba327
pacote@19.0.1
21.5.1
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
pacote@20.0.0
21.5.1
1
ghcr.io/umami-software/umami:postgresql-v1.39.560fa8875aff8
pacote@13.6.2
21.5.1
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
pacote@19.0.1
21.5.1
1
ghcr.io/umami-software/umami:3.1.0e3f80c0625aa
pacote@19.0.2
21.5.1
1
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
pacote@13.6.2
21.5.1
1
ghcr.io/wachd/wachd:0.4.1805b05c56da94
pacote@19.0.2
21.5.1
1
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
pacote@15.1.1
21.5.1
1
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
pacote@15.1.1
21.5.1
1
ghcr.io/wasilak/kube-ingress-dash:0.3.1ff55992f905c
pacote@21.0.3
21.5.1
1
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
pacote@11.3.1
21.5.1
1
ghcr.io/wei-shaw/claude-relay-service:v1.1.292398c34934453
pacote@18.0.6
21.5.1
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
pacote@21.0.0
21.5.1
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
pacote@17.0.4
21.5.1
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
pacote@18.0.3
21.5.1
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
pacote@20.0.0
21.5.1
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
pacote@19.0.1
21.5.1
1
ghcr.io/wundergraph/cosmo/studio:0.111.0454f4384713a
pacote@19.0.1
21.5.1
1
ghcr.io/xmv-solutions-gmbh/strapi:latesta288b4571142
pacote@19.0.2
21.5.1
1
ghcr.io/zazukoians/qlever-ui:v0.10.034c7b540a095
pacote@20.0.0
21.5.1
1
ghcr.io/zoriya/kyoo_front:4.7.1d7f76c9c65d9
pacote@18.0.6
21.5.1
1
mcr.microsoft.com/azure-storage/azurite:latest830430c1da1a
pacote@20.0.1
21.5.1
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
pacote@21.4.0
21.5.1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
pacote@20.0.0
21.5.1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
pacote@18.0.6
21.5.1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.