StackRadar

CVE-2026-9679

Medium

Advisory

Published 17 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
163
of 17,781 indexed, latest versions
Container images
150
deployed by those charts
Fix available
3 of 4
affected packages

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

Carried by container images the latest versions of 163 of 17,781 indexed charts deploy, on 150 images.

Affected packageAffected versionsFixed inImages
undicinpm4.15.0, 5.6.0, 5.11.0, 5.12.0+38 more6.27.0, 7.28.0, 8.5.0150
node-undicideb5.26.3+dfsg1+~cs23.10.12-2, 7.3.0+dfsg1+~cs24.12.11-1no fix listed2
node-gypapk13.0.0-r013.0.0-r11
npmapk11.17.0-r011.17.0-r11
OSV records
CGA-5mx2-gq8r-3v7qCGA-gvrp-v4p2-65f2DEBIAN-CVE-2026-9679GHSA-p88m-4jfj-68fvUBUNTU-CVE-2026-9679
Also known as
CGA-86v8-3h7f-7vw6, CGA-j25g-hhpp-x3wr

Charts affected

163 by stars
ChartLatestAffected imagesRadar Score
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.27.0

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.27.0

Open the chart page →

919
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
undici@5.24.0
6.27.0

Open the chart page →

13,719
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
undici@5.6.0
6.27.0

Open the chart page →

4,017
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
undici@6.26.0
6.27.0

Open the chart page →

3,972
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
undici@5.28.4
6.27.0

Open the chart page →

28,814
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
undici@5.29.0
6.27.0

Open the chart page →

3,576
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
undici@6.21.1
6.27.0

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.28.0

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
undici@5.29.0
6.27.0

Open the chart page →

1,787
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
undici@6.25.0
6.27.0

Open the chart page →

1,616
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
undici@6.25.0
6.27.0

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
undici@6.19.2
6.27.0

Open the chart page →

6,285

Container images carrying it

150 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
jupyterhub/jupyterhub:5.4.63974ba945e65
node-undici@5.26.3+dfsg1+~cs23.10.12-2
undici@5.26.3
no fix listed
6.27.0
1
kitware/cdash:v5.3.0d7767d9b9da4
undici@6.26.0
6.27.0
1
kubebb/component-store:latestfd8ecbd73213
undici@5.22.1
6.27.0
1
langgenius/dify-api:1.0.0066035f93856
undici@5.15.0
6.27.0
1
langgenius/dify-api:0.6.11fca918260dd6
undici@5.15.0
6.27.0
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
undici@6.26.0
6.27.0
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
undici@6.26.0
6.27.0
1
library/ghost:6.37.01ef2e532ca4d
undici@7.25.0
7.28.0
1
library/ghost:6.25.12654b1e90413
undici@5.22.1
6.27.0
1
library/ghost:6.41.129773d6be407
undici@6.25.0
6.27.0
1
library/ghost:6.39.0-alpine77196da4b0df
undici@6.25.0
6.27.0
1
library/ghost:5.79.083f7bf209844
undici@5.22.1
6.27.0
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
undici@5.22.1
6.27.0
1
library/kibana:8.18.004c0fc150f3a
undici@6.19.2
6.27.0
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
undici@6.23.0
6.27.0
1
louislam/uptime-kuma:2.0.24c364ef96aad
undici@6.22.0
6.27.0
1
louislam/uptime-kuma:2.4.091e963bfda56
undici@6.26.0
6.27.0
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
undici@6.22.0
6.27.0
1
mautic/mautic:7-apacheeb8cc73d97e1
undici@6.26.0
6.27.0
1
n8nio/n8n:2.25.7761374d4eb84
undici@7.24.6
7.28.0
1
n8nio/n8n:1.86.08b39ed5a2de9
undici@5.28.5
6.27.0
1
n8nio/n8n:1.33.1dd171d45102a
undici@6.9.0
6.27.0
1
nocodb/nocodb:0.301.5d9516f0bf546
undici@7.24.4
7.28.0
1
nodered/node-red:5.0.410f40d0a83e7
undici@6.26.0
6.27.0
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
undici@6.26.0
6.27.0
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
undici@5.15.0
6.27.0
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
undici@5.15.0
6.27.0
1
opea/codegen-ui:1.02bee4eb66f3e
undici@5.28.4
6.27.0
1
openhab/openhab:5.2.1bfd4a60e90da
node-undici@7.3.0+dfsg1+~cs24.12.11-1
undici@7.3.0
no fix listed
7.28.0
1
openmined/syft-frontend:0.9.5d11524a3854a
undici@6.11.1
6.27.0
1
outlinewiki/outline:1.10.1832051f039b4
undici@6.26.0
6.27.0
1
penpotapp/exporter:2.17.272a8061e8806
undici@6.26.0
6.27.0
1
penpotapp/mcp:2.17.284f3f07ead11
undici@6.26.0
6.27.0
1
polonel/trudesk:1.2.60cf6513f6fe3
undici@5.6.0
6.27.0
1
rocketadmin/rocketadmin:1.17.710955ef540b9
undici@6.25.0
6.27.0
1
saidsef/aws-kinesis-local:v2026.0667025e3a163e
undici@6.26.0
6.27.0
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
undici@5.15.0
6.27.0
1
shieldsio/shields:nextfa194b446e42
undici@6.26.0
6.27.0
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
undici@5.26.3
6.27.0
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
undici@5.28.4
6.27.0
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
undici@5.28.4
6.27.0
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
undici@5.28.4
6.27.0
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
undici@5.28.4
6.27.0
1
speckle/speckle-server:2.26.379f14a2bf931
undici@5.29.0
6.27.0
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
undici@5.28.3
6.27.0
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
undici@5.28.4
6.27.0
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
undici@5.28.3
6.27.0
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
undici@5.28.4
6.27.0
1
supabase/storage-api:v1.60.4c8eb9858eafe
undici@7.24.6
7.28.0
1
tensorzero/ui:2026.6.0f2563d54724e
undici@6.26.0
6.27.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.