StackRadar

CVE-2026-9679

Medium

Advisory

Published 17 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
163
of 17,781 indexed, latest versions
Container images
150
deployed by those charts
Fix available
3 of 4
affected packages

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

Carried by container images the latest versions of 163 of 17,781 indexed charts deploy, on 150 images.

Affected packageAffected versionsFixed inImages
undicinpm4.15.0, 5.6.0, 5.11.0, 5.12.0+38 more6.27.0, 7.28.0, 8.5.0150
node-undicideb5.26.3+dfsg1+~cs23.10.12-2, 7.3.0+dfsg1+~cs24.12.11-1no fix listed2
node-gypapk13.0.0-r013.0.0-r11
npmapk11.17.0-r011.17.0-r11
OSV records
CGA-5mx2-gq8r-3v7qCGA-gvrp-v4p2-65f2DEBIAN-CVE-2026-9679GHSA-p88m-4jfj-68fvUBUNTU-CVE-2026-9679
Also known as
CGA-86v8-3h7f-7vw6, CGA-j25g-hhpp-x3wr

Charts affected

163 by stars
ChartLatestAffected imagesRadar Score
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.27.0

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.27.0

Open the chart page →

919
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
undici@5.24.0
6.27.0

Open the chart page →

13,719
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
undici@5.6.0
6.27.0

Open the chart page →

4,017
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
undici@6.26.0
6.27.0

Open the chart page →

3,972
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
undici@5.28.4
6.27.0

Open the chart page →

28,814
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
undici@5.29.0
6.27.0

Open the chart page →

3,576
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
undici@6.21.1
6.27.0

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.28.0

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
undici@5.29.0
6.27.0

Open the chart page →

1,787
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
undici@6.25.0
6.27.0

Open the chart page →

1,616
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
undici@6.25.0
6.27.0

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
undici@6.19.2
6.27.0

Open the chart page →

6,285

Container images carrying it

150 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
tenureai/tenure:v1.0.285f5b222df9a5
undici@6.26.0
6.27.0
1
veecode/devportalc443520aebf7
undici@5.29.0
6.27.0
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
undici@5.24.0
6.27.0
1
wsjbr/duplistatus:1.4.25e594f5f09f6
undici@6.26.0
6.27.0
1
xxczaki/discord-bot:e9f46b6aebac02e7b96ed41a3f62b26e871cf009bb919aac45dc
undici@8.3.0
8.5.0
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
undici@5.28.3
6.27.0
1
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
undici@6.23.0
6.27.0
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
undici@6.23.0
6.27.0
1
ghcr.io/bluesky-social/pds:0.4d95725b24dbe
undici@6.26.0
6.27.0
1
ghcr.io/calesthio/crucix:latest67c5244b6acf
undici@7.24.4
7.28.0
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
undici@6.21.2
6.27.0
1
ghcr.io/drewburr-labs/evobot:3.0.04ddbb244c82f
undici@5.27.2
6.27.0
1
ghcr.io/duyet/clickhouse-monitoring:latest84edfe8a67a8
undici@6.26.0
6.27.0
1
ghcr.io/elk-zone/elk:v1.0.1236faedcb68a
undici@6.26.0
6.27.0
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
undici@7.3.0
7.28.0
1
ghcr.io/firecrawl/firecrawl:2.11.33092ee28c20a0d
undici@6.26.0
6.27.0
1
ghcr.io/formancehq/console:console-on.v1.1.1a4d32c2f68b3
undici@6.21.0
6.27.0
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
undici@6.21.3
6.27.0
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
undici@6.21.3
6.27.0
1
ghcr.io/harish2k01/portfolio-tracker:0.1.056efa3085895
undici@6.25.0
6.27.0
1
ghcr.io/homarr-labs/homarr:v1.77.11f5b892aeef4
undici@6.26.0
6.27.0
1
ghcr.io/homarr-labs/homarr:v1.77.0f23ad77a681b
undici@6.26.0
6.27.0
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
undici@5.15.0
6.27.0
1
ghcr.io/immich-app/immich-server:v3.2.0ae13784ffcfc
undici@6.26.0
6.27.0
1
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
undici@6.26.0
6.27.0
1
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
undici@6.21.3
6.27.0
1
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
undici@6.26.0
6.27.0
1
ghcr.io/karakeep-app/karakeep:0.26.0f575a34ed3f8
undici@6.21.3
6.27.0
1
ghcr.io/manzil-infinity180/backend-dumpstore:226f28ca3efa6d3691044813cd09085e28d4a7b496c90cf82fdd
undici@7.11.0
7.28.0
1
ghcr.io/matter-js/matterjs-server:1.4.054232d0d3e7d
undici@6.26.0
6.27.0
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
undici@6.25.0
6.27.0
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
undici@8.3.0
8.5.0
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
undici@6.26.0
6.27.0
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
undici@6.21.1
6.27.0
1
ghcr.io/seanmorley15/adventurelog-frontend:v0.13.051ee22428b41
node-gyp@13.0.0-r0
npm@11.17.0-r0
undici@6.26.0
13.0.0-r1
11.17.0-r1
6.27.0
1
ghcr.io/seerr-team/seerr:v3.2.0c4cbd5121236
undici@7.18.2
7.28.0
1
ghcr.io/tale/headplane:0.5.50dbc52cffc19
undici@6.21.0
6.27.0
1
ghcr.io/theduffman85/crowdsec-web-ui:2026.8.3bfadbab9a72c
undici@6.26.0
6.27.0
1
ghcr.io/wgbh-mla/dream-aapb:main288a4774aa90
undici@6.26.0
6.27.0
1
ghcr.io/wgbh-mla/ov-frontend:v1.1.0bfc3118f6565
undici@6.21.2
6.27.0
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
undici@5.28.2
6.27.0
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
undici@5.28.4
6.27.0
1
ghcr.io/zazuko/trifid:v6.0.159bda2bf65d4
undici@6.26.0
6.27.0
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
undici@7.12.0
7.28.0
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
undici@6.25.0
6.27.0
1
quay.io/kuberay/dashboard:v1.7.07e43d4b4fd9f
undici@6.26.0
6.27.0
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
undici@6.26.0
6.27.0
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
undici@5.11.0
6.27.0
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
undici@5.29.0
6.27.0
1
registry.gitlab.com/xrow-public/helm-openclaw/openclaw:1.91.3ed44d81a65de
undici@6.26.0
6.27.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.