GHSA-9qr9-h5gf-34mp
CriticalAdvisory
Published 3 Dec 2025In the index since 6 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 10.0
- base score, highest
- EPSS
- —
- probability of exploitation
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 15
- of 17,781 indexed, latest versions
- Container images
- 16
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Next.js is vulnerable to RCE in React flight protocol
Carried by container images the latest versions of 15 of 17,781 indexed charts deploy, on 16 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| nextnpm | 15.2.3, 15.2.4, 15.3.1, 15.3.3+4 more | 15.2.6, 15.3.6, 15.4.8, 15.5.7+1 more | 16 |
- OSV records
- GHSA-9qr9-h5gf-34mp
Charts affected
15 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| cosmocosmo-platformOfficialVerified publisher | 0.20.0 | 1 of 10See more | 28,839 |
| coreinstill-aiOfficialVerified publisher | 0.1.75 | 1 of 15See more | 30,816 |
| kube-ingress-dash-chartkube-ingress-dashVerified publisher | 0.3.1 | 1 of 1See more | 1,505 |
| karakeepself-hosters-by-nightVerified publisher | 2.5.1 | 1 of 1See more | 5,213 |
| vuiseriohub | 1.0.6 | 1 of 3See more | 11,532 |
| kamaji-consoleclastixVerified publisher | 0.1.3 | 1 of 1See more | 2,759 |
| desishowbiz-frontenddesishowbiz | 1.0.0 | 1 of 1See more | 2,529 |
| lobe-chathelm-charts-darox | 0.1.56 | 1 of 1See more | 666 |
| magistralamagistrala-devopsVerified publisher | 0.16.2 | 1 of 42See more | 24,400 |
| neosyncneosyncVerified publisher | 0.5.41 | 1 of 3See more | 7,184 |
| appneosync-appVerified publisher | 0.5.41 | 1 of 1See more | 1,569 |
| alquimia-studioopenshift | 0.2.0 | 1 of 1See more | 2,370 |
| podscopepodscope | 0.2.3 | 1 of 1See more | 1,484 |
| radar-self-enrolment-uiradar-baseVerified publisher | 0.4.2 | 1 of 1See more | 1,506 |
| saleor-appstrieb-work | 0.6.0 | 3 of 5See more | 6,994 |
Container images carrying it
16 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.