StackRadar

CVE-2026-9496

High

Advisory

Published 26 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.003
28th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
663
of 17,781 indexed, latest versions
Container images
677
deployed by those charts
Fix available
1 of 2
affected packages

pacote is vulnerable to Denial of Service (DoS) via the addGitSha function

Carried by container images the latest versions of 663 of 17,781 indexed charts deploy, on 677 images.

Affected packageAffected versionsFixed inImages
npmdeb3.5.2-0ubuntu4, 6.14.4+ds-1ubuntu2, 9.2.0~ds1-2, 11.17.0-0no fix listed7
pacotenpm11.2.7, 11.3.1, 11.3.3, 11.3.4+30 more21.5.1671
OSV records
DEBIAN-CVE-2026-9496GHSA-w4pp-8pjf-rmxwUBUNTU-CVE-2026-9496

Charts affected

663 by stars
ChartLatestAffected imagesRadar Score
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
pacote@19.0.2
21.5.1

Open the chart page →

30,159
rocketchatrocketchat-server7.0.24 of 12See more

rocketchat rocketchat-server 7.0.2

4 of the 12 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
rocketchat/account-service:8.6.144af8ac4e711
pacote@20.0.1
21.5.1
rocketchat/authorization-service:8.6.16bc18fb5d0e5
pacote@20.0.1
21.5.1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
pacote@20.0.1
21.5.1
rocketchat/presence-service:8.6.1c1170bdfe797
pacote@19.0.2
21.5.1

Open the chart page →

12,279
penpotpenpotOfficialVerified publisher1.9.02 of 4See more

penpot penpot 1.9.0

2 of the 4 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
penpotapp/exporter:2.17.272a8061e8806
pacote@21.5.0
21.5.1
penpotapp/mcp:2.17.284f3f07ead11
pacote@21.5.0
21.5.1

Open the chart page →

4,314
node-rednode-redVerified publisher0.40.21 of 1See more

node-red node-red 0.40.2

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
nodered/node-red:4.1.2216e7403aab9
pacote@18.0.6
21.5.1

Open the chart page →

2,172
mongo-expresscowboysysopVerified publisher7.0.01 of 1See more

mongo-express cowboysysop 7.0.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
library/mongo-express:1.0.21b23d7976f02
pacote@18.0.3
21.5.1

Open the chart page →

1,210
difydoubanVerified publisher0.10.02 of 6See more

dify douban 0.10.0

2 of the 6 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.124e65e8a351a2
pacote@17.0.4
21.5.1
langgenius/dify-web:1.10.1-fix.1c306ac577912
pacote@20.0.0
21.5.1

Open the chart page →

19,391
difydify-helmVerified publisher0.38.03 of 11See more

dify dify-helm 0.38.0

3 of the 11 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
pacote@20.0.0
21.5.1
langgenius/dify-api:1.16.1dcefa5f7c47c
pacote@20.0.0
21.5.1
langgenius/dify-web:1.16.187dd47e4e28f
pacote@19.0.1
21.5.1

Open the chart page →

22,002
verdaccioverdaccio4.35.11 of 1See more

verdaccio verdaccio 4.35.1

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
verdaccio/verdaccio:6.10.209b403888c8f
pacote@21.5.0
21.5.1

Open the chart page →

215
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.01 of 5See more

openproject openproject-helm-charts 13.11.0

1 of the 5 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
openproject/hocuspocus:release-338001b288dc1359dfb5
pacote@19.0.1
21.5.1

Open the chart page →

19,926
apisix-ingress-controllerapisix1.3.11 of 2See more

apisix-ingress-controller apisix 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
pacote@21.5.0
21.5.1

Open the chart page →

1,616
chatwootchatwootVerified publisher2.0.241 of 3See more

chatwoot chatwoot 2.0.24

1 of the 3 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
chatwoot/chatwoot:v4.15.167ebc751c171
pacote@21.5.0
21.5.1

Open the chart page →

9,203
stacks-blockchain-apihirosystemsVerified publisher6.5.11 of 5See more

stacks-blockchain-api hirosystems 6.5.1

1 of the 5 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
pacote@20.0.0
21.5.1

Open the chart page →

8,364
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
pacote@21.1.0
21.5.1

Open the chart page →

5,660
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
pacote@15.1.1
21.5.1

Open the chart page →

4,431
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
pacote@18.0.6
21.5.1

Open the chart page →

5,352
servarrkubitodevVerified publisher1.5.21 of 10See more

servarr kubitodev 1.5.2

1 of the 10 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/seerr-team/seerr:latestf4768de5f616
pacote@19.0.2
21.5.1

Open the chart page →

3,004
velero-uiotwldVerified publisher0.15.01 of 1See more

velero-ui otwld 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
otwld/velero-ui:0.10.2d1954b759e47
pacote@19.0.2
21.5.1

Open the chart page →

1,332
supabasetokens-studioVerified publisher1.0.03 of 14See more

supabase tokens-studio 1.0.0

3 of the 14 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
supabase/postgres-meta:v0.84.2d0a96973e9f1
pacote@18.0.6
21.5.1
supabase/storage-api:v1.12.0f983fb50bd95
pacote@18.0.6
21.5.1
supabase/studio:20241021-9f9b08326d8070c55e9
pacote@18.0.6
21.5.1

Open the chart page →

23,123
budibasebudibase0.0.0-master3 of 7See more

budibase budibase 0.0.0-master

3 of the 7 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
budibase/apps:3.41.344fe6feab985
pacote@19.0.2
21.5.1
budibase/database:2.1.0d90f656261c9
pacote@21.5.0
21.5.1
budibase/worker:3.41.3de5e2e560ce8
pacote@19.0.2
21.5.1

Open the chart page →

10,775
krokicowboysysopVerified publisher6.1.04 of 5See more

kroki cowboysysop 6.1.0

4 of the 5 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.29.1444805c4b917
pacote@20.0.0
21.5.1
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
pacote@19.0.1
21.5.1
yuzutech/kroki-excalidraw:0.29.157917319ea70
pacote@20.0.0
21.5.1
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
pacote@19.0.1
21.5.1

Open the chart page →

6,743
n8nn8n0.23.01 of 1See more

n8n n8n 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
n8nio/n8n:1.33.1dd171d45102a
pacote@15.2.0
21.5.1

Open the chart page →

5,639
sorry-cypresssorry-cypressVerified publisher1.20.02 of 4See more

sorry-cypress sorry-cypress 1.20.0

2 of the 4 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-api:2.5.11afaa5a84051d
pacote@13.6.2
21.5.1
agoldis/sorry-cypress-director:2.5.1110228ecd353b
pacote@13.6.2
21.5.1

Open the chart page →

4,285
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
pacote@21.5.0
21.5.1

Open the chart page →

2,938
umamichristianhuthVerified publisher7.13.01 of 2See more

umami christianhuth 7.13.0

1 of the 2 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
pacote@19.0.1
21.5.1

Open the chart page →

2,367
echo-serverealenn0.5.01 of 1See more

echo-server ealenn 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ealen/echo-server:0.6.0359761caae37
pacote@13.5.0
21.5.1

Open the chart page →

766
ilumilumOfficialVerified publisher6.7.31 of 19See more

ilum ilum 6.7.3

1 of the 19 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ilum/ui:6.7.3998937726679
pacote@21.0.4
21.5.1

Open the chart page →

23,228
homepagem0nsterrr-homepageVerified publisher5.3.01 of 1See more

homepage m0nsterrr-homepage 5.3.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v2.3.0f82027665453
pacote@19.0.2
21.5.1

Open the chart page →

352
homarroben01Verified publisher1.4.01 of 1See more

homarr oben01 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
pacote@15.1.3
21.5.1

Open the chart page →

2,581
umamiwaldo-visionVerified publisher0.0.11 of 1See more

umami waldo-vision 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v1.39.560fa8875aff8
pacote@13.6.2
21.5.1

Open the chart page →

1,255
uptime-kumaduyet0.1.71 of 1See more

uptime-kuma duyet 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
louislam/uptime-kuma:1.18.5a84767d7934f
pacote@13.6.1
21.5.1

Open the chart page →

4,515
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
pacote@19.0.2
21.5.1

Open the chart page →

5,564
redisinsightheywood8-helm-chartsVerified publisher0.4.51 of 1See more

redisinsight heywood8-helm-charts 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
heywood8/redisinsight:2.28.00bc9ab313d37
pacote@15.1.0
21.5.1

Open the chart page →

2,828
redisinsightredisinsight-guiVerified publisher1.3.51 of 1See more

redisinsight redisinsight-gui 1.3.5

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
redis/redisinsight:3.8b5e19ee240ab
pacote@20.0.0
21.5.1

Open the chart page →

1,038
redisinsight-secureredisinsight-secureVerified publisher1.0.21 of 1See more

redisinsight-secure redisinsight-secure 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
redis/redisinsight:2.68019fcf774631
pacote@18.0.3
21.5.1

Open the chart page →

1,721
servarrservarr1.0.21 of 10See more

servarr servarr 1.0.2

1 of the 10 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
pacote@13.6.1
21.5.1

Open the chart page →

14,238
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
pacote@12.0.2
21.5.1

Open the chart page →

5,251
kuttchristianhuthVerified publisher9.10.11 of 3See more

kutt christianhuth 9.10.1

1 of the 3 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
kutt/kutt:v3.2.6fa3d24a89b04
pacote@19.0.2
21.5.1

Open the chart page →

454
foundry-vttfoundry-vttVerified publisher12.343.01 of 1See more

foundry-vtt foundry-vtt 12.343.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
felddy/foundryvtt:12.343.06c5e3e9ffbb0
pacote@18.0.3
21.5.1

Open the chart page →

723
graphql-gatewaygraphql-gatewayVerified publisher0.1.51 of 1See more

graphql-gateway graphql-gateway 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
hansehe/graphql-gateway:1.0.458e09540afbc
pacote@17.0.4
21.5.1

Open the chart page →

1,660
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
pacote@21.5.0
21.5.1

Open the chart page →

9,460
openctihelm-openctiVerified publisher3.0.91 of 8See more

opencti helm-opencti 3.0.9

1 of the 8 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
opencti/platform:7.260910.0186fc757c3eb
pacote@20.0.1
21.5.1

Open the chart page →

3,383
klusterviewklusterviewVerified publisher0.1.01 of 4See more

klusterview klusterview 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
kyleslugg/klusterview:latestba8c36dfdfbd
pacote@13.6.2
21.5.1

Open the chart page →

3,795
librechatlibrechat1.8.101 of 3See more

librechat librechat 1.8.10

1 of the 3 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
pacote@18.0.6
21.5.1

Open the chart page →

2,654
musicocielmusicocielVerified publisher0.0.01 of 3See more

musicociel musicociel 0.0.0

1 of the 3 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
davdiv/musicociel:deva85f99be882c
pacote@17.0.4
21.5.1

Open the chart page →

4,406
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/tale/headplane:0.5.50dbc52cffc19
pacote@19.0.1
21.5.1

Open the chart page →

7,949
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
gradiant/open5gs-webui:2.7.5fbd10c017541
pacote@17.0.4
21.5.1

Open the chart page →

9,261
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
pacote@17.0.4
21.5.1

Open the chart page →

9,746
ghostcloudpirates-ghostVerified publisher0.20.221 of 3See more

ghost cloudpirates-ghost 0.20.22

1 of the 3 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
library/ghost:6.63.0e05bc1169fb2
pacote@19.0.2
21.5.1

Open the chart page →

7,146
community-solid-servercommunity-solid-server3.0.01 of 1See more

community-solid-server community-solid-server 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
solidproject/community-server:6.0.2ccc4acb7e9a1
pacote@15.1.3
21.5.1

Open the chart page →

1,613
foremancontane-githubOfficialVerified publisher0.6.01 of 1See more

foreman contane-github 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-9496.

Container imageDigestPackageFixed in
contane/foreman:0.5.2efb98bdcc4e9
pacote@19.0.1
21.5.1

Open the chart page →

1,152

Container images carrying it

677 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
langgenius/dify-web:1.10.1-fix.1c306ac577912
pacote@20.0.0
21.5.1
1
langgenius/dify-web:1.0.0d64914ff0d6d
pacote@18.0.6
21.5.1
1
lbenicio/helm-pilot:0.2.54594a2632510
pacote@19.0.2
21.5.1
1
lbenicio/stremio-web:latest732f9003de33
pacote@20.0.1
21.5.1
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
pacote@18.0.6
21.5.1
1
library/ghost:6.37.01ef2e532ca4d
pacote@20.0.1
21.5.1
1
library/ghost:6.25.12654b1e90413
pacote@20.0.1
21.5.1
1
library/ghost:6.41.129773d6be407
pacote@20.0.1
21.5.1
1
library/ghost:6.39.0-alpine77196da4b0df
pacote@19.0.2
21.5.1
1
library/ghost:5.79.083f7bf209844
pacote@17.0.4
21.5.1
1
library/ghost:6.62.0a7a268bbfb7f
pacote@19.0.2
21.5.1
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
pacote@19.0.1
21.5.1
1
library/mongo-express:1.0.2-20-alpine3.191aae00775251
pacote@18.0.6
21.5.1
1
library/node:16.13.0-alpine60ef0bed1dc2
pacote@12.0.2
21.5.1
1
library/node:22-bookworm-slim83f487e0a634
pacote@20.0.1
21.5.1
1
library/node:18-alpine8d6421d663b4
pacote@18.0.6
21.5.1
1
library/node:208f693eaa7e0a
pacote@18.0.6
21.5.1
1
library/node:16.20f77a1aef2da8
pacote@13.6.2
21.5.1
1
lissy93/dashy:2.0.51991f7be5ed0
pacote@12.0.2
21.5.1
1
lissy93/domain-locker:latestd3c95edc0a8b
pacote@18.0.6
21.5.1
1
lissy93/networking-toolbox:latest700862839553
pacote@19.0.1
21.5.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
pacote@21.0.4
21.5.1
1
litlyx/litlyx-consumer:latest02225e77d316
pacote@19.0.1
21.5.1
1
litlyx/litlyx-dashboard:lateste64ff2d52385
pacote@20.0.0
21.5.1
1
litlyx/litlyx-producer:latest10407f36613f
pacote@19.0.1
21.5.1
1
localstack/localstack:3.19d278167f2b7
pacote@17.0.4
21.5.1
1
loftsh/jspolicy:0.2.225deb9bd2683
pacote@13.6.2
21.5.1
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
pacote@19.0.1
21.5.1
1
louislam/uptime-kuma:1.22.10b55bcb83a1c
pacote@13.6.2
21.5.1
1
louislam/uptime-kuma:13d632903e6af
pacote@18.0.3
21.5.1
1
louislam/uptime-kuma:2.5.33e24e96c89ef
pacote@19.0.2
21.5.1
1
louislam/uptime-kuma:2.0.24c364ef96aad
pacote@18.0.6
21.5.1
1
louislam/uptime-kuma:2.4.091e963bfda56
pacote@19.0.2
21.5.1
1
louislam/uptime-kuma:1.23.1396510915e6be
pacote@17.0.6
21.5.1
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
pacote@18.0.6
21.5.1
1
louislam/uptime-kuma:1.17.1a4eab252e5a2
pacote@13.0.5
21.5.1
1
louislam/uptime-kuma:1.18.5a84767d7934f
pacote@13.6.1
21.5.1
1
louislam/uptime-kuma:1.23.12bc6f244ecf27
pacote@17.0.6
21.5.1
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
npm@6.14.4+ds-1ubuntu2
no fix listed
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
pacote@13.6.2
21.5.1
1
luligu/matterbridge:3.0.28f97884bebc2
pacote@20.0.0
21.5.1
1
maildev/maildev:2.2.1180ef51f65ee
pacote@19.0.0
21.5.1
1
maissacrement/pock8snodejs:0.0.16da0db1159da
pacote@15.1.1
21.5.1
1
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
pacote@13.6.2
21.5.1
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
pacote@13.6.2
21.5.1
1
mauricenino/dashdot:5.9.2236997816917
pacote@18.0.6
21.5.1
1
mautic/mautic:7-apacheeb8cc73d97e1
pacote@21.5.0
21.5.1
1
mcpuse/inspector:latest91b25e3eb604
pacote@20.0.1
21.5.1
1
middlewareeng/middleware:0.3.1747d880812f1
pacote@19.0.1
21.5.1
1
milesmcc/shynet:v0.13.1ba54f7797a6b
pacote@11.3.4
21.5.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.