StackRadar

CVE-2026-102473

Medium

Advisory

Published 29 Sept 2026In the index since 1 Oct 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.001
2nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,660
of 18,035 indexed, latest versions
Container images
2,664
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,660 of 18,035 indexed charts deploy, on 2,664 images.

Affected packageAffected versionsFixed inImages
dashdeb0.5.7-4ubuntu1, 0.5.8-2.1ubuntu2, 0.5.8-2.10, 0.5.10.2-6+6 moreno fix listed2,664
OSV records
DEBIAN-CVE-2026-102473ECHO-f9f7-0739-3421UBUNTU-CVE-2026-102473
Trending
Rank 12 in indexed charts, since 1 Oct 2026. See the ranking →

Charts affected

2,660 by stars
ChartLatestAffected imagesRadar Score
penpotpenpotOfficialVerified publisher1.11.32 of 5See more

penpot penpot 1.11.3

2 of the 5 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
penpotapp/exporter:2.18.3418232d6ca31
dash@0.5.12-12+dhi2
no fix listed
penpotapp/frontend:2.18.3bb8abe27d53d
dash@0.5.12-12+dhi2
no fix listed

Open the chart page →

6,130
signozsignoz0.145.01 of 5See more

signoz signoz 0.145.0

1 of the 5 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
signoz/signoz-otel-collector:v0.144.12deb566a7a3c0
dash@0.5.12-2
no fix listed

Open the chart page →

10,008
weblateweblateOfficialVerified publisher0.5.413 of 3See more

weblate weblate 0.5.41

3 of the 3 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
dash@0.5.12-2
no fix listed
bitnamilegacy/redis:latest5927ff3702df
dash@0.5.12-2
no fix listed
weblate/weblate:2026.10.0.16084353e0b28
dash@0.5.12-12ubuntu3
no fix listed

Open the chart page →

7,119
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
dash@0.5.12-2
no fix listed

Open the chart page →

3,080
postgresgroundhog2k1.6.81 of 1See more

postgres groundhog2k 1.6.8

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
library/postgres:18.65a5a84b19854
dash@0.5.12-12
no fix listed

Open the chart page →

1,689
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
dash@0.5.12-2
no fix listed

Open the chart page →

5,494
dragonflydragonflyVerified publisher1.8.51 of 3See more

dragonfly dragonfly 1.8.5

1 of the 3 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.59fe2a1d6206f
dash@0.5.12-2
no fix listed

Open the chart page →

4,990
emqxemqx-operator5.8.91 of 1See more

emqx emqx-operator 5.8.9

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
emqx/emqx:5.8.935b46f7aa7a0
dash@0.5.12-12
no fix listed

Open the chart page →

3,005
mariadbcloudpirates-mariadbVerified publisher0.16.161 of 1See more

mariadb cloudpirates-mariadb 0.16.16

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
library/mariadb:13.0.2f1bba652ba57
dash@0.5.12-12ubuntu3
no fix listed

Open the chart page →

1,688
difydoubanVerified publisher0.10.03 of 6See more

dify douban 0.10.0

3 of the 6 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
dash@0.5.12-2
no fix listed
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
dash@0.5.12-2
no fix listed
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

82,241
secrets-store-csi-driversecret-store-csi-driver1.6.11 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

1 of the 4 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
dash@0.5.12-2
no fix listed

Open the chart page →

2,404
mongodbcloudpirates-mongodbVerified publisher0.20.01 of 1See more

mongodb cloudpirates-mongodb 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
library/mongo:9.0.2bac22ea7710d
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

1,105
code-servernicholaswildeVerified publisher1.1.11 of 1See more

code-server nicholaswilde 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
dash@0.5.8-2.10
no fix listed

Open the chart page →

18,097
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
dash@0.5.12-12ubuntu3
no fix listed

Open the chart page →

2,045
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

4,167
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
dash@0.5.12-2
no fix listed

Open the chart page →

8,459
difydify-helmVerified publisher0.38.05 of 11See more

dify dify-helm 0.38.0

5 of the 11 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
dash@0.5.12-2
no fix listed
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
dash@0.5.12-2
no fix listed
langgenius/dify-api:1.16.1dcefa5f7c47c
dash@0.5.12-2
no fix listed
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
dash@0.5.12-6ubuntu5
no fix listed
library/nginx:latestabe47724e466
dash@0.5.12-12
no fix listed

Open the chart page →

72,711
pyroscopegrafana2.3.11 of 3See more

pyroscope grafana 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

4,076
plantumlstevehipwellVerified publisher3.49.01 of 1See more

plantuml stevehipwell 3.49.0

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

2,268
rabbitmqgroundhog2k2.3.91 of 2See more

rabbitmq groundhog2k 2.3.9

1 of the 2 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.6446551b26c0b
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

1,208
stacks-blockchainhirosystemsVerified publisher2.2.21 of 1See more

stacks-blockchain hirosystems 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
dash@0.5.12-2
no fix listed

Open the chart page →

1,539
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
library/kong:3.992035d16d7ff
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

702
oktetooktetoOfficialVerified publisher0.0.0-2026-08-311 of 10See more

okteto okteto 0.0.0-2026-08-31

1 of the 10 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-313e56bdd1b90d
dash@0.5.12-12
no fix listed

Open the chart page →

6,848
yourlsyourlsOfficialVerified publisher8.10.51 of 2See more

yourls yourls 8.10.5

1 of the 2 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
ghcr.io/yourls/yourls:1.10.62f2879125903
dash@0.5.12-12
no fix listed

Open the chart page →

2,453
apisix-ingress-controllerapisix1.4.01 of 2See more

apisix-ingress-controller apisix 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
dash@0.5.12-2
no fix listed

Open the chart page →

2,085
istiocloudposse1.1.02 of 8See more

istio cloudposse 1.1.0

2 of the 8 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
dash@0.5.8-2.1ubuntu2
no fix listed
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
dash@0.5.8-2.1ubuntu2
no fix listed

Open the chart page →

134,780
actualbudgetcommunity-chartsVerified publisher1.9.51 of 1See more

actualbudget community-charts 1.9.5

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.10.024645e971da6
dash@0.5.12-2
no fix listed

Open the chart page →

1,464
concourseconcourseVerified publisher20.3.11 of 2See more

concourse concourse 20.3.1

1 of the 2 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
library/postgres:17d74eeac9a635
dash@0.5.12-12
no fix listed

Open the chart page →

1,907
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
dash@0.5.8-2.10
no fix listed

Open the chart page →

5,205
openprojectopenproject-helm-chartsOfficialVerified publisher13.13.14 of 5See more

openproject openproject-helm-charts 13.13.1

4 of the 5 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
dash@0.5.12-2
no fix listed
library/postgres:161a6ab3f5345e
dash@0.5.12-12
no fix listed
openproject/hocuspocus:release-338001b288dc1359dfb5
dash@0.5.12-2
no fix listed
openproject/openproject:17.9.1-slim2beeecac788d
dash@0.5.12-12
no fix listed

Open the chart page →

20,916
sftpgosftpgoOfficialVerified publisher0.48.01 of 1See more

sftpgo sftpgo 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.59011fe608d33
dash@0.5.12-12
no fix listed

Open the chart page →

1,545
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
dash@0.5.12-2
no fix listed

Open the chart page →

13,565
lemmyananace-chartsVerified publisher0.6.152 of 5See more

lemmy ananace-charts 0.6.15

2 of the 5 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
dessalines/lemmy:0.19.2079e9f02c286c
dash@0.5.12-2
no fix listed
dessalines/lemmy-ui:0.19.20ee4c620d8e93
dash@0.5.12-12
no fix listed

Open the chart page →

8,004
zabbixcetic3.1.35 of 5See more

zabbix cetic 3.1.3

5 of the 5 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
library/postgres:14c2427de38f99
dash@0.5.12-12
no fix listed
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

37,114
csi-driver-smbcsi-driver-smbVerified publisher1.20.31 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

1 of the 6 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
dash@0.5.12-2
no fix listed

Open the chart page →

3,798
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
dash@0.5.12-2
no fix listed

Open the chart page →

4,645
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
dash@0.5.12-2
no fix listed

Open the chart page →

7,401
stacks-blockchain-apihirosystemsVerified publisher6.5.12 of 5See more

stacks-blockchain-api hirosystems 6.5.1

2 of the 5 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
dash@0.5.12-2
no fix listed
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
dash@0.5.12-2
no fix listed

Open the chart page →

8,733
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

2,938
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

3,703
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
dash@0.5.12-2
no fix listed

Open the chart page →

6,700
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
dash@0.5.10.2-6
no fix listed
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

14,198
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

3,639
factorio-server-chartsfactorio-server-chartsVerified publisher2.5.21 of 1See more

factorio-server-charts factorio-server-charts 2.5.2

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
factoriotools/factorio:lateste91a03290ef8
dash@0.5.12-12
no fix listed

Open the chart page →

1,302
netbirdjaconiVerified publisher0.15.12 of 4See more

netbird jaconi 0.15.1

2 of the 4 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
library/golang:lateste0174e51e812
dash@0.5.12-12
no fix listed
netbirdio/management:0.45.10c9994b393ea
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

9,739
litellm-helmlitellm1.104.01 of 2See more

litellm-helm litellm 1.104.0

1 of the 2 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
dash@0.5.12-2
no fix listed

Open the chart page →

5,308
localstacklocalstack0.7.11 of 1See more

localstack localstack 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
localstack/localstack-pro:latest801a3dff7f6a
dash@0.5.12-12
no fix listed

Open the chart page →

1,986
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
dash@0.5.12-12
no fix listed

Open the chart page →

14,270
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
dash@0.5.12-6ubuntu5
no fix listed

Open the chart page →

6,961
oneuptimeoneuptimeOfficialVerified publisher14.0.144 of 7See more

oneuptime oneuptime 14.0.14

4 of the 7 container images this version deploys carry CVE-2026-102473.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.73c9dfa2ec939
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
library/postgres:latest5a5a84b19854
dash@0.5.12-12
no fix listed
oneuptime/probe:release45988479c7fc
dash@0.5.12-2
no fix listed
oneuptime/runner:releasef2da6b9fd1a2
dash@0.5.12-12
no fix listed

Open the chart page →

9,037

Container images carrying it

2,664 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3180688274b2c
dash@0.5.12-12
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.17419aa33eb17
dash@0.5.12-12
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.1a072f0a41f28
dash@0.5.12-12
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
dash@0.5.10.2-6
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
dash@0.5.12-2
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
dash@0.5.12-2
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
dash@0.5.12-12
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
dash@0.5.12-2
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
dash@0.5.12-2
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
dash@0.5.12-2
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
dash@0.5.12-2
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
dash@0.5.12-2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
dash@0.5.12-2
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
dash@0.5.12-2
no fix listed
1

syft 1.42.1 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.