StackRadar

GHSA-rgj7-g3m4-5g8c

High

Advisory

Published 8 Sept 2026In the index since 9 Sept 2026
Severity
High
worst across findings
CVSS
8.9
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
151
of 17,781 indexed, latest versions
Container images
150
deployed by those charts
Fix available
1 of 1
affected package

sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545

Carried by container images the latest versions of 151 of 17,781 indexed charts deploy, on 150 images.

Affected packageAffected versionsFixed inImages
sharpnpm0.27.2, 0.28.1, 0.29.0, 0.29.2+19 more0.35.4150
OSV records
GHSA-rgj7-g3m4-5g8c

Charts affected

151 by stars
ChartLatestAffected imagesRadar Score
websitewaldo-visionVerified publisher0.33.01 of 2See more

website waldo-vision 0.33.0

1 of the 2 container images this version deploys carry GHSA-rgj7-g3m4-5g8c.

Container imageDigestPackageFixed in
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
sharp@0.32.0
0.35.4

Open the chart page →

3,474

Container images carrying it

150 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
assistiot/dlt_api:2.0.0e36a8922fa0c
sharp@0.27.2
0.35.4
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
sharp@0.32.0
0.35.4
3
ghcr.io/microboxlabs/miot-app:0.5.203cc10a496ced
sharp@0.34.5
0.35.4
3
ghcr.io/seerr-team/seerr:latest:v3.4.1f4768de5f616
sharp@0.34.5
0.35.4
3
library/ghost:6.63.0e05bc1169fb2
sharp@0.35.3
0.35.4
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
sharp@0.32.6
0.35.4
2
sysnet4admin/dashboard:bluec5bd3bb1b5a6
sharp@0.33.4
0.35.4
2
ghcr.io/gethomepage/homepage:latest:v2.2.0753eeb0cc22a
sharp@0.35.3
0.35.4
2
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
sharp@0.35.3
0.35.4
2
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
sharp@0.34.1
0.35.4
2
ghcr.io/unionai-oss/flyteconsole-v2:latestdb4362ec0d3b
sharp@0.35.3
0.35.4
2
agentarea/agentarea-frontend:latest2098a9d7b1fe
sharp@0.35.0
0.35.4
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
sharp@0.33.5
0.35.4
1
alquimiaai/studio:certification38a1f0341982
sharp@0.34.4
0.35.4
1
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
sharp@0.34.3
0.35.4
1
assistiot/dlt_api:2.1.0c8a170683be7
sharp@0.27.2
0.35.4
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
sharp@0.30.7
0.35.4
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
sharp@0.29.0
0.35.4
1
chibisafe/chibisafe:latest836467a50792
sharp@0.33.3
0.35.4
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
sharp@0.33.2
0.35.4
1
chocobozzz/peertube:v8.1.5052712130691
sharp@0.34.5
0.35.4
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
sharp@0.33.5
0.35.4
1
devopsiaci/self-learning-platform:1.1.3d9441c931f75
sharp@0.34.5
0.35.4
1
directus/directus:12.0.29c8470ea465c
sharp@0.34.5
0.35.4
1
directus/directus:11.1.0e3c8bb975350
sharp@0.33.5
0.35.4
1
documenso/documenso:v1.8.17f16a9449f18
sharp@0.32.6
0.35.4
1
drumsergio/lynxprompt:2.0.75c6afb6679301
sharp@0.34.5
0.35.4
1
drumsergio/pumperly:1.4.885bbc3915e9e
sharp@0.34.5
0.35.4
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
sharp@0.33.5
0.35.4
1
epam/ai-dial-admin-frontend:0.20.021d91ad74755
sharp@0.34.5
0.35.4
1
epam/ai-dial-chat:0.49.0bd6b13695cdc
sharp@0.35.0
0.35.4
1
evoapicloud/evolution-api:latest966625532d90
sharp@0.34.5
0.35.4
1
fallenbagel/jellyseerr:latest4538137bc5af
sharp@0.33.4
0.35.4
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
sharp@0.32.6
0.35.4
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
sharp@0.34.5
0.35.4
1
fosrl/pangolin:latest83a55f933b4d
sharp@0.35.3
0.35.4
1
fosrl/pangolin:1.13.0c32ad797ab96
sharp@0.34.4
0.35.4
1
helmforge/opencut:v0.3.0bf11156e0ab5
sharp@0.34.5
0.35.4
1
helmforge/strapi-base:5.52.270e9143d6d92
sharp@0.35.3
0.35.4
1
ianw/quickchart:v1.7.1dc49dd460c37
sharp@0.30.7
0.35.4
1
instill/console:0.68.54cd70e2df5c6
sharp@0.34.3
0.35.4
1
jakowenko/double-take:1.6.0b858bac9e32a
sharp@0.29.2
0.35.4
1
joplin/server:latest3f7b852959aa
sharp@0.34.5
0.35.4
1
joplin/server:3.0-beta52af57880c0e
sharp@0.33.3
0.35.4
1
joplin/server:2.14.2-betab87564ef34e9
sharp@0.33.1
0.35.4
1
langgenius/dify-ee-enterprise-frontend:3.9.8-ubi98dd9de6b6190
sharp@0.34.5
0.35.4
1
langgenius/dify-ee-web:3.9.8-ubi9ba1dd1d0bcea
sharp@0.34.5
0.35.4
1
langgenius/dify-web:1.16.187dd47e4e28f
sharp@0.35.3
0.35.4
1
langgenius/dify-web:0.6.11a2a294743634
sharp@0.33.2
0.35.4
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
sharp@0.34.4
0.35.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.