GHSA-9c5c-9qcx-q35q
HighAdvisory
Published 30 Sept 2026In the index since 1 Oct 2026
- Severity
- High
- worst across findings
- CVSS
- 7.4
- base score, highest
- EPSS
- —
- probability of exploitation
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 7
- of 18,035 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 1 of 1
- affected package
@nestjs/platform-fastify: Path-scoped middleware bypass via absolute-form request targets
Carried by container images the latest versions of 7 of 18,035 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| @nestjs/ | 8.0.6, 8.2.3, 8.4.4, 11.1.24+2 more | 11.2.4, 12.0.2 | 6 |
- OSV records
- GHSA-9c5c-9qcx-q35q
Charts affected
7 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| docmosthelmforgeVerified publisher | 1.4.1 | 1 of 4See more | 4,393 |
| betterdb-monitorbetterdb-monitorOfficialVerified publisher | 0.49.0 | 1 of 1See more | 421 |
| homebridgegeek-cookbookVerified publisher | 5.3.2 | 1 of 1See more | 88,184 |
| authfcryptexlabsVerified publisher | 0.12.13 | 1 of 4See more | 4,125 |
| homebridgehomeenterpriseinc | 0.5.0 | 1 of 1See more | 81,206 |
| homebridgejespernohrVerified publisher | 0.2.0 | 1 of 1See more | 37,091 |
| homebridgelbenicio-communityVerified publisher | 0.1.15 | 1 of 1See more | 37,091 |
Container images carrying it
6 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| homebridge/ | 22cdfca31934 | @nestjs/ | 12.0.2 | 2 |
| betterdb/ | 97dcd2d2192f | @nestjs/ | 11.2.4 | 1 |
| cryptexlabs/ | 189c07411d7c | @nestjs/ | 11.2.4 | 1 |
| docmost/ | b56947fcfd08 | @nestjs/ | 11.2.4 | 1 |
| oznu/ | 2e12d0e2dcce | @nestjs/ | 11.2.4 | 1 |
| ghcr.io/ | ff2af53897e7 | @nestjs/ | 11.2.4 | 1 |