StackRadar

CVE-2026-102473

Medium

Advisory

Published 29 Sept 2026In the index since 1 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,653
of 17,985 indexed, latest versions
Container images
2,628
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,653 of 17,985 indexed charts deploy, on 2,628 images.

Affected packageAffected versionsFixed inImages
dashdeb0.5.7-4ubuntu1, 0.5.8-2.1ubuntu2, 0.5.8-2.10, 0.5.10.2-6+6 moreno fix listed2,628
OSV records
DEBIAN-CVE-2026-102473UBUNTU-CVE-2026-102473ECHO-f9f7-0739-3421
Trending
Rank 5 in indexed charts, since 1 Oct 2026. See the ranking →

Charts affected

2,653 by stars
ChartLatestAffected imagesRadar Score
zimagizimagi2.7.171 of 6See more

zimagi zimagi 2.7.17

1 of the 6 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.15.331407c0e8e32
dash@0.5.12-2
no fix listed

Open the chart page →

2,129
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
dash@0.5.8-2.10
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
dash@0.5.10.2-6
no fix listed

Open the chart page →

9,659
zoo-project-druzoo-projectOfficialVerified publisher0.10.81 of 6See more

zoo-project-dru zoo-project 0.10.8

1 of the 6 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-51e7d55383f24594959b69e58518961c6aa66740da112e8d03f1
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

6,257

Container images carrying it

2,628 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jacobalberty/unifi:v10.0.162896c0ab82d33
dash@0.5.10.2-6
no fix listed
3
joplin/server:3.7.2:latest3f7b852959aa
dash@0.5.12-2
no fix listed
3
library/mongo:4.2.16ca49afbcb2b
dash@0.5.8-2.10
no fix listed
3
library/nginx:1.25:1.25.5a484819eb602
dash@0.5.12-2
no fix listed
3
library/node:lts64af3819f927
dash@0.5.12-2
no fix listed
3
library/ubuntu:24.04008173c23f95
dash@0.5.12-6ubuntu5
no fix listed
3
library/zookeeper:3.9.57d0f24ebb67b
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3
mcp/grafana:latest9362bcf6aa0e
dash@0.5.12-2
no fix listed
3
meshery/meshery:stable-latest44b64ee128fb
dash@0.5.12-2
no fix listed
3
omecproject/cdn-video-repo:1.0.0:remote-v3d59ccb138ffb
dash@0.5.8-2.1ubuntu2
no fix listed
3
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
dash@0.5.12-2
no fix listed
3
opencsghq/postgres:15.19b98600564e07
dash@0.5.12-12
no fix listed
3
openebs/node-disk-manager:2.1.0f6c18b0f8c8a
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3
openebs/node-disk-operator:2.1.06afe2123c457
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3
selenium/hub:3.141.5902f251d48d5f
dash@0.5.10.2-6
no fix listed
3
sigp/lighthouse:latest-amd6450f66cfebb6d
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3
vaultwarden/server:1.37.3:latest1587c45feaa4
dash@0.5.12-12
no fix listed
3
vaultwarden/server:1.37.1ebdfe70701c6
dash@0.5.12-12
no fix listed
3
ghcr.io/api7/adc:0.27.1f65f53dd9668
dash@0.5.12-2
no fix listed
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
dash@0.5.12-2
no fix listed
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
dash@0.5.12-2
no fix listed
3
ghcr.io/dgtlmoon/changedetection.io:0.60.834df3680db1c
dash@0.5.12-2
no fix listed
3
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
dash@0.5.12-2
no fix listed
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
dash@0.5.12-2
no fix listed
3
ghcr.io/linuxserver/plex:1.43.4:latestbe083133dfe0
dash@0.5.12-12ubuntu3
no fix listed
3
ghcr.io/paperless-ngx/paperless-ngx:3.2.15fa76604a81d
dash@0.5.12-12
no fix listed
3
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
dash@0.5.12-2
no fix listed
3
ghcr.io/tremolosecurity/kube-oidc-proxy:1.0.13c5153b5f079c
dash@0.5.12-6ubuntu5
no fix listed
3
public.ecr.aws/aktosecurity/akto-api-security-mini-runtime:1.74.6_local:latest8b9208c09d76
dash@0.5.12-12ubuntu3
no fix listed
3
quay.io/cilium/cilium:v1.20.22939231d0d3e
dash@0.5.12-12ubuntu3
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
dash@0.5.12-2
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
dash@0.5.12-6ubuntu5
no fix listed
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
dash@0.5.12-6ubuntu5
no fix listed
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
dash@0.5.12-6ubuntu5
no fix listed
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
dash@0.5.12-6ubuntu5
no fix listed
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
dash@0.5.10.2-6
no fix listed
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
dash@0.5.12-6ubuntu5
no fix listed
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
dash@0.5.8-2.1ubuntu2
no fix listed
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
dash@0.5.12-6ubuntu5
no fix listed
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
dash@0.5.12-6ubuntu5
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
dash@0.5.12-2
no fix listed
3
actualbudget/actual-server:26.9.0552beab3dec8
dash@0.5.12-2
no fix listed
2
alazidis/kube-netlag:1.1.00e8c84152201
dash@0.5.12-6ubuntu5
no fix listed
2
alexandreroman/hello:latest4b79473442be
dash@0.5.8-2.10
no fix listed
2
apache/iotdb:0.13.3-nodeafa47bf1692a
dash@0.5.10.2-6
no fix listed
2
apache/nifi-registry:1.26.07cdfd8deec92
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
2
apache/rocketmq:5.4.0319cd8a81ed1
dash@0.5.12-6ubuntu5
no fix listed
2
apache/tika:2.9.0.092d055a84e9e
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
2

syft 1.42.1 · advisories as of 2 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.