StackRadar

CVE-2021-39208

Medium

Advisory

Published 20 Sept 2021In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.012
66th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
9
of 17,781 indexed, latest versions
Container images
14
deployed by those charts
Fix available
1 of 1
affected package

Partial path traversal in sharpcompress

Carried by container images the latest versions of 9 of 17,781 indexed charts deploy, on 14 images.

Affected packageAffected versionsFixed inImages
SharpCompressnuget0.18.2, 0.22.0, 0.23.0, 0.24.0+1 more0.2914
OSV records
GHSA-jp7f-grcv-6mjf

Charts affected

9 by stars
ChartLatestAffected imagesRadar Score
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2021-39208.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
SharpCompress@0.26.0
0.29

Open the chart page →

7,880
eshoponabpabp-charts1.0.06 of 15See more

eshoponabp abp-charts 1.0.0

6 of the 15 container images this version deploys carry CVE-2021-39208.

Container imageDigestPackageFixed in
ghcr.io/volosoft/eshoponabp/service-administration:1.0.0206a9bee17a8
SharpCompress@0.23.0
0.29
ghcr.io/volosoft/eshoponabp/service-basket:1.0.0dd5ce454072e
SharpCompress@0.23.0
0.29
ghcr.io/volosoft/eshoponabp/service-catalog:1.0.07ecb00f53d99
SharpCompress@0.23.0
0.29
ghcr.io/volosoft/eshoponabp/service-identity:1.0.0e53bf47b62d0
SharpCompress@0.23.0
0.29
ghcr.io/volosoft/eshoponabp/service-ordering:1.0.15e836b17337f
SharpCompress@0.23.0
0.29
ghcr.io/volosoft/eshoponabp/service-payment:1.0.02ca91145099c
SharpCompress@0.23.0
0.29

Open the chart page →

19,799
duplicaticronce0.1.01 of 1See more

duplicati cronce 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-39208.

Container imageDigestPackageFixed in
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
SharpCompress@0.24.0
0.29

Open the chart page →

3,026
voice-biometricslumenvox2.0.11 of 26See more

voice-biometrics lumenvox 2.0.1

1 of the 26 container images this version deploys carry CVE-2021-39208.

Container imageDigestPackageFixed in
lumenvox/cloud-binary-storage:2.0.053decadc102d
SharpCompress@0.23.0
0.29

Open the chart page →

70,741
embybryanalves0.1.01 of 1See more

emby bryanalves 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-39208.

Container imageDigestPackageFixed in
emby/embyserver:3.6.0.8128a492828e93
SharpCompress@0.22.0
0.29

Open the chart page →

276
ombibryanalves0.4.01 of 1See more

ombi bryanalves 0.4.0

1 of the 1 container images this version deploys carry CVE-2021-39208.

Container imageDigestPackageFixed in
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
SharpCompress@0.18.2
0.29

Open the chart page →

10,776
embygeek-cookbookVerified publisher3.4.21 of 1See more

emby geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2021-39208.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
SharpCompress@0.26.0
0.29

Open the chart page →

8,545
middleware-odigosmiddleware-labsVerified publisher0.2.411 of 6See more

middleware-odigos middleware-labs 0.2.41

1 of the 6 container images this version deploys carry CVE-2021-39208.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
SharpCompress@0.23.0
0.29

Open the chart page →

8,370
middleware-visionmiddleware-labsVerified publisher0.2.651 of 6See more

middleware-vision middleware-labs 0.2.65

1 of the 6 container images this version deploys carry CVE-2021-39208.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
SharpCompress@0.23.0
0.29

Open the chart page →

8,361

Container images carrying it

14 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
duplicati/duplicati:2.0.5.111_canary_2020-09-268660f0eda7c9
SharpCompress@0.24.0
0.29
1
emby/embyserver:3.6.0.8128a492828e93
SharpCompress@0.22.0
0.29
1
linuxserver/jellyfin:10.7.72427dde159a2
SharpCompress@0.26.0
0.29
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
SharpCompress@0.18.2
0.29
1
lumenvox/cloud-binary-storage:2.0.053decadc102d
SharpCompress@0.23.0
0.29
1
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
SharpCompress@0.26.0
0.29
1
ghcr.io/middleware-labs/odigos-odiglet:middleware-test-0.0.103c8c835ecee
SharpCompress@0.23.0
0.29
1
ghcr.io/middleware-labs/vision-odiglet:middleware-test-0.0.3bce34c98668e
SharpCompress@0.23.0
0.29
1
ghcr.io/volosoft/eshoponabp/service-administration:1.0.0206a9bee17a8
SharpCompress@0.23.0
0.29
1
ghcr.io/volosoft/eshoponabp/service-basket:1.0.0dd5ce454072e
SharpCompress@0.23.0
0.29
1
ghcr.io/volosoft/eshoponabp/service-catalog:1.0.07ecb00f53d99
SharpCompress@0.23.0
0.29
1
ghcr.io/volosoft/eshoponabp/service-identity:1.0.0e53bf47b62d0
SharpCompress@0.23.0
0.29
1
ghcr.io/volosoft/eshoponabp/service-ordering:1.0.15e836b17337f
SharpCompress@0.23.0
0.29
1
ghcr.io/volosoft/eshoponabp/service-payment:1.0.02ca91145099c
SharpCompress@0.23.0
0.29
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.