StackRadar

GHSA-x565-32qp-m3vf

Medium

Advisory

Published 11 Apr 2024In the index since 8 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
probability of exploitation
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
10
deployed by those charts
Fix available
1 of 1
affected package

phin may include sensitive headers in subsequent requests after redirect

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 10 images.

Affected packageAffected versionsFixed inImages
phinnpm2.9.33.7.110
OSV records
GHSA-x565-32qp-m3vf

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
portraitportraitVerified publisher0.2.131 of 8See more

portrait portrait 0.2.13

1 of the 8 container images this version deploys carry GHSA-x565-32qp-m3vf.

Container imageDigestPackageFixed in
treskon/portrait-ui:DEV-lateste7970783bc8d
phin@2.9.3
3.7.1

Open the chart page →

31,844
linkwardenadnoctemVerified publisher0.5.11 of 2See more

linkwarden adnoctem 0.5.1

1 of the 2 container images this version deploys carry GHSA-x565-32qp-m3vf.

Container imageDigestPackageFixed in
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
phin@2.9.3
3.7.1

Open the chart page →

3,820
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry GHSA-x565-32qp-m3vf.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
phin@2.9.3
3.7.1
countly/frontend:25.05.42acbc11499b6
phin@2.9.3
3.7.1

Open the chart page →

7,295
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry GHSA-x565-32qp-m3vf.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
phin@2.9.3
3.7.1

Open the chart page →

5,488
picolorsealenn0.1.01 of 1See more

picolors ealenn 0.1.0

1 of the 1 container images this version deploys carry GHSA-x565-32qp-m3vf.

Container imageDigestPackageFixed in
ealen/picolors:0.1.03cb01dcbf652
phin@2.9.3
3.7.1

Open the chart page →

576
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry GHSA-x565-32qp-m3vf.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
phin@2.9.3
3.7.1

Open the chart page →

3,159
countlyhelmforgeVerified publisher1.2.61 of 3See more

countly helmforge 1.2.6

1 of the 3 container images this version deploys carry GHSA-x565-32qp-m3vf.

Container imageDigestPackageFixed in
countly/countly-server:25.05.4e3c238248f99
phin@2.9.3
3.7.1

Open the chart page →

18,813
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry GHSA-x565-32qp-m3vf.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
phin@2.9.3
3.7.1

Open the chart page →

22,589
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry GHSA-x565-32qp-m3vf.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
phin@2.9.3
3.7.1

Open the chart page →

4,230

Container images carrying it

10 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
countly/api:25.05.4f4cc7447c4f5
phin@2.9.3
3.7.1
1
countly/countly-server:25.05.4e3c238248f99
phin@2.9.3
3.7.1
1
countly/frontend:25.05.42acbc11499b6
phin@2.9.3
3.7.1
1
ealen/picolors:0.1.03cb01dcbf652
phin@2.9.3
3.7.1
1
fiware/idm:8.3.3a1b6ed4ae84f
phin@2.9.3
3.7.1
1
ianw/quickchart:v1.7.1dc49dd460c37
phin@2.9.3
3.7.1
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
phin@2.9.3
3.7.1
1
treskon/portrait-ui:DEV-lateste7970783bc8d
phin@2.9.3
3.7.1
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
phin@2.9.3
3.7.1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
phin@2.9.3
3.7.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.