StackRadar

CVE-2026-9679

Medium

Advisory

Published 17 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.9
base score, highest
EPSS
0.003
17th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
163
of 17,781 indexed, latest versions
Container images
150
deployed by those charts
Fix available
3 of 4
affected packages

undici vulnerable to HTTP header injection via Set-Cookie percent-decoding

Carried by container images the latest versions of 163 of 17,781 indexed charts deploy, on 150 images.

Affected packageAffected versionsFixed inImages
undicinpm4.15.0, 5.6.0, 5.11.0, 5.12.0+38 more6.27.0, 7.28.0, 8.5.0150
node-undicideb5.26.3+dfsg1+~cs23.10.12-2, 7.3.0+dfsg1+~cs24.12.11-1no fix listed2
node-gypapk13.0.0-r013.0.0-r11
npmapk11.17.0-r011.17.0-r11
OSV records
CGA-5mx2-gq8r-3v7qCGA-gvrp-v4p2-65f2DEBIAN-CVE-2026-9679GHSA-p88m-4jfj-68fvUBUNTU-CVE-2026-9679
Also known as
CGA-86v8-3h7f-7vw6, CGA-j25g-hhpp-x3wr

Charts affected

163 by stars
ChartLatestAffected imagesRadar Score
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.27.0

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.27.0

Open the chart page →

919
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
undici@5.24.0
6.27.0

Open the chart page →

13,719
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
undici@5.6.0
6.27.0

Open the chart page →

4,017
tensorzerotensorzero2026.6.01 of 2See more

tensorzero tensorzero 2026.6.0

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
tensorzero/ui:2026.6.0f2563d54724e
undici@6.26.0
6.27.0

Open the chart page →

3,972
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
undici@5.28.4
6.27.0

Open the chart page →

28,814
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
undici@5.29.0
6.27.0

Open the chart page →

3,576
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
undici@6.21.1
6.27.0

Open the chart page →

5,228
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.28.0

Open the chart page →

3,746
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
undici@5.29.0
6.27.0

Open the chart page →

1,787
apisix-ingress-controllerwenerme1.3.11 of 2See more

apisix-ingress-controller wenerme 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
undici@6.25.0
6.27.0

Open the chart page →

1,616
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
undici@6.25.0
6.27.0

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-9679.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
undici@6.19.2
6.27.0

Open the chart page →

6,285

Container images carrying it

150 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
undici@5.12.0
6.27.0
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
undici@6.25.0
6.27.0
3
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
undici@6.26.0
6.27.0
3
ethersphere/bee-localchain:latest0558799ca992
undici@5.28.3
6.27.0
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
undici@5.28.4
6.27.0
2
louislam/uptime-kuma:2.3.29aeb4e51d038
undici@6.25.0
6.27.0
2
mojaloop/reporting-events-processor-svc:v3.5.11e0d24d28512
undici@7.11.0
7.28.0
2
mojaloop/reporting-hub-bop-experience-api-svc:v2.0.4265102a049d6
undici@7.10.0
7.28.0
2
mojaloop/security-role-perm-operator-svc:v3.0.212af60892c75
undici@7.16.0
7.28.0
2
rajnandan1/kener:3.2.1930407afca731
undici@6.21.1
6.27.0
2
requarks/wiki:2:latest68f0d1848261
undici@6.25.0
6.27.0
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
undici@6.26.0
6.27.0
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
undici@5.22.0
6.27.0
2
ghcr.io/api7/adc:0.27.1f65f53dd9668
undici@6.25.0
6.27.0
2
ghcr.io/wg-easy/wg-easy:15:15.4.00e7bc9d34e86
undici@6.26.0
6.27.0
2
aaronshaf/dynamodb-admin:latestac41724cd997
undici@6.25.0
6.27.0
1
adeptiainc/adeptia-automate-observe:1.0.031f295e948e6
undici@7.24.1
7.28.0
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
undici@5.28.3
6.27.0
1
archivebox/archivebox:0.7.41a5a37331091
undici@6.25.0
6.27.0
1
budibase/apps:3.41.344fe6feab985
undici@6.21.3
6.27.0
1
catalysm/csmm:latestf003b35f54d9
undici@5.29.0
6.27.0
1
chatwoot/chatwoot:v4.15.167ebc751c171
undici@6.25.0
6.27.0
1
chocobozzz/peertube:v8.1.5052712130691
undici@6.24.1
6.27.0
1
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
undici@6.26.0
6.27.0
1
cryptexlabs/authf:0.12.11189c07411d7c
undici@6.19.8
6.27.0
1
cspconsole/report-processor:1.0.279a2d8840bfdf
undici@5.29.0
6.27.0
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
undici@6.26.0
6.27.0
1
deconzcommunity/deconz:2.29.2062de2362641
undici@5.15.0
6.27.0
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
undici@6.26.0
6.27.0
1
directus/directus:12.0.29c8470ea465c
undici@7.24.5
7.28.0
1
directus/directus:11.1.0e3c8bb975350
undici@6.19.5
6.27.0
1
diygod/rsshub:2025-11-097a6312cac0d5
undici@6.22.0
6.27.0
1
drumsergio/lynxprompt:2.0.75c6afb6679301
undici@6.25.0
6.27.0
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
undici@6.24.1
6.27.0
1
eclipseaerios/benchmarking-tool:1.0.0a4b4c2e7fe62
undici@6.26.0
6.27.0
1
epam/ai-dial-admin-frontend:0.20.021d91ad74755
undici@6.26.0
6.27.0
1
epam/ai-dial-chat:0.49.0bd6b13695cdc
undici@6.26.0
6.27.0
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
undici@4.15.0
6.27.0
1
etherpad/etherpad:2.7.2b723fe5f2594
undici@7.25.0
7.28.0
1
ethpandaops/assertoor:latest1efa2fba6711
undici@6.26.0
6.27.0
1
evoapicloud/evolution-api:latest966625532d90
undici@7.16.0
7.28.0
1
fallenbagel/jellyseerr:latest4538137bc5af
undici@7.3.0
7.28.0
1
felddy/foundryvtt:12.343.06c5e3e9ffbb0
undici@6.19.7
6.27.0
1
fosrl/pangolin:latest83a55f933b4d
undici@6.26.0
6.27.0
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
undici@7.24.4
7.28.0
1
globalping/globalping-probe:latest8acbd23009fd
undici@5.29.0
6.27.0
1
haohanyang/compass-web:0.5.054f2112602ee
undici@6.25.0
6.27.0
1
helmforge/opencut:v0.3.0bf11156e0ab5
undici@6.26.0
6.27.0
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
undici@6.21.2
6.27.0
1
journeyapps/powersync-service:latestbf46f66e5dcc
undici@6.26.0
6.27.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.