StackRadar

GHSA-rgj7-g3m4-5g8c

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
8.9
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
151
of 17,781 indexed, latest versions
Container images
150
deployed by those charts
Fix available
1 of 1
affected package

sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545

Carried by container images the latest versions of 151 of 17,781 indexed charts deploy, on 150 images.

Affected packageAffected versionsFixed inImages
sharpnpm0.27.2, 0.28.1, 0.29.0, 0.29.2+19 more0.35.4150
OSV records
GHSA-rgj7-g3m4-5g8c

Charts affected

151 by stars
ChartLatestAffected imagesRadar Score
websitewaldo-visionVerified publisher0.33.01 of 2See more

website waldo-vision 0.33.0

1 of the 2 container images this version deploys carry GHSA-rgj7-g3m4-5g8c.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
sharp@0.32.0
0.35.4

Open the chart page →

3,474

Container images carrying it

150 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
langgenius/dify-web:1.0.0d64914ff0d6d
sharp@0.33.5
0.35.4
1
lbenicio/helm-pilot:0.2.54594a2632510
sharp@0.34.5
0.35.4
1
library/ghost:6.37.01ef2e532ca4d
sharp@0.34.5
0.35.4
1
library/ghost:6.25.12654b1e90413
sharp@0.34.5
0.35.4
1
library/ghost:6.41.129773d6be407
sharp@0.34.5
0.35.4
1
library/ghost:4.37.0767230c0f263
sharp@0.29.3
0.35.4
1
library/ghost:6.39.0-alpine77196da4b0df
sharp@0.34.5
0.35.4
1
library/ghost:5.79.083f7bf209844
sharp@0.32.6
0.35.4
1
library/ghost:6.62.0a7a268bbfb7f
sharp@0.35.3
0.35.4
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
sharp@0.34.2
0.35.4
1
lobehub/lobe-chat:1.96.9da0c21fefcd3
sharp@0.33.5
0.35.4
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
sharp@0.30.7
0.35.4
1
misskey/misskey:12.110.1e08b7c478093
sharp@0.30.3
0.35.4
1
moreillon/food-manager:lateste8fd856e593d
sharp@0.29.3
0.35.4
1
neoskop/ixy:2.1.125152b474f54
sharp@0.34.5
0.35.4
1
nocodb/nocodb:latest4b760f0d2547
sharp@0.35.3
0.35.4
1
nocodb/nocodb:0.258.06779a4ddedf2
sharp@0.33.5
0.35.4
1
nocodb/nocodb:0.301.5d9516f0bf546
sharp@0.33.4
0.35.4
1
onyxdotapp/onyx-web-server:latest30d0adaa0fa0
sharp@0.35.3
0.35.4
1
penpotapp/mcp:2.17.284f3f07ead11
sharp@0.35.2
0.35.4
1
prowlercloud/prowler-ui:5.31.179ee83c8e702
sharp@0.33.5
0.35.4
1
rahulbhiwagade122/desishowbiz:latest08490b70998c
sharp@0.33.5
0.35.4
1
rocketchat/ddp-streamer-service:8.6.1819771c4abe4
sharp@0.33.5
0.35.4
1
sondresjo/garge-app:v1.20.691767c10ad0e
sharp@0.35.3
0.35.4
1
sondresjo/nstuning-app:v1.6.10ffca294f10ba
sharp@0.35.3
0.35.4
1
speckle/speckle-frontend-2:2.21.3-branch.testing5.219631-2153befd4ca6ebf09b9
sharp@0.32.6
0.35.4
1
speckle/speckle-preview-service:2.20.2-branch.testing4.134160-9fad4b21f897ca906ea
sharp@0.32.6
0.35.4
1
speckle/speckle-preview-service:2.21.3-branch.testing5.219631-2153bef52cad5e3293e
sharp@0.32.6
0.35.4
1
speckle/speckle-preview-service:2.17.14-branch.testing.72707.921a5f884fc39bca0c8
sharp@0.32.6
0.35.4
1
speckle/speckle-preview-service:2.20.6-branch.testing1.154030-9b091148f3c1ea153ba
sharp@0.32.6
0.35.4
1
speckle/speckle-preview-service:2.19.2-branch.hotfix-2.19.1.124125-665e7e1c102b087481a
sharp@0.32.6
0.35.4
1
speckle/speckle-preview-service:2.20.3-branch.hotfix-2.20.2.149555-37ea0cbd3da0a84de98
sharp@0.32.6
0.35.4
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
sharp@0.32.6
0.35.4
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
sharp@0.32.6
0.35.4
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
sharp@0.32.6
0.35.4
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
sharp@0.32.6
0.35.4
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
sharp@0.34.3
0.35.4
1
speckle/speckle-server:2.26.379f14a2bf931
sharp@0.34.4
0.35.4
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
sharp@0.32.6
0.35.4
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
sharp@0.32.6
0.35.4
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
sharp@0.32.6
0.35.4
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
sharp@0.32.6
0.35.4
1
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
sharp@0.34.5
0.35.4
1
supabase/studio:latest94a2a9d2906e
sharp@0.34.5
0.35.4
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
sharp@0.33.4
0.35.4
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
sharp@0.32.6
0.35.4
1
wsjbr/duplistatus:1.4.25e594f5f09f6
sharp@0.34.5
0.35.4
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
sharp@0.34.2
0.35.4
1
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
sharp@0.33.5
0.35.4
1
ghcr.io/bulwarkmail/webmail:1.6.0f0a266506fcf
sharp@0.34.5
0.35.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.