StackRadar

CVE-2026-102474

Medium

Advisory

Published 29 Sept 2026In the index since 1 Oct 2026
Severity
Medium
worst across findings
CVSS
4.0
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,656
of 17,985 indexed, latest versions
Container images
2,632
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,656 of 17,985 indexed charts deploy, on 2,632 images.

Affected packageAffected versionsFixed inImages
dashdeb0.5.7-4ubuntu1, 0.5.8-2.1ubuntu2, 0.5.8-2.10, 0.5.10.2-6+6 moreno fix listed2,632
OSV records
DEBIAN-CVE-2026-102474ECHO-a40f-fcbc-6816UBUNTU-CVE-2026-102474
Trending
Rank 12 in indexed charts, since 1 Oct 2026. See the ranking →

Charts affected

2,656 by stars
ChartLatestAffected imagesRadar Score
changedetection-iozekker6Verified publisher1.103.01 of 1See more

changedetection-io zekker6 1.103.0

1 of the 1 container images this version deploys carry CVE-2026-102474.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.834df3680db1c
dash@0.5.12-2
no fix listed

Open the chart page →

2,932
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-102474.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
dash@0.5.12-12
no fix listed

Open the chart page →

1,859
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-102474.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
dash@0.5.12-2
no fix listed

Open the chart page →

5,018
zimagizimagi2.7.171 of 6See more

zimagi zimagi 2.7.17

1 of the 6 container images this version deploys carry CVE-2026-102474.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.15.331407c0e8e32
dash@0.5.12-2
no fix listed

Open the chart page →

2,135
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-102474.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
dash@0.5.8-2.10
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
dash@0.5.10.2-6
no fix listed

Open the chart page →

9,696
zoo-project-druzoo-projectOfficialVerified publisher0.10.81 of 6See more

zoo-project-dru zoo-project 0.10.8

1 of the 6 container images this version deploys carry CVE-2026-102474.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-51e7d55383f24594959b69e58518961c6aa66740da112e8d03f1
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

6,744

Container images carrying it

2,632 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dragonflyoss/client:v1.5.59fe2a1d6206f
dash@0.5.12-2
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
dash@0.5.12-2
no fix listed
1
dremio/dremio-oss:24.1.080ed2e3b7c43
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
drorivry4/rego:lateste035d49b15ca
dash@0.5.12-2
no fix listed
1
drpcorg/dshackle:0.54.08858fae1859d
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
drumsergio/genieacs:1.2.16.6ffbf8bd1340d
dash@0.5.12-2
no fix listed
1
dserio83/velero-api:0.3.16b3d9115fee2
dash@0.5.12-2
no fix listed
1
dserio83/velero-watchdog:0.1.8d5deae589229
dash@0.5.12-2
no fix listed
1
duck1123/cert-downloader:latest0e29f19fa67c
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
duck1123/lnd-fileserver:latest9d6fb247b714
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
eceasy/cli-proxy-api:v7.3.20c1b692f17607
dash@0.5.12-2
no fix listed
1
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
dash@0.5.12-12
no fix listed
1
eclipseaerios/hlo-allocator:v3.0.03cc1d94cfe96
dash@0.5.12-12
no fix listed
1
eclipseaerios/hlo-data-aggregator:v3.0.0b433c2b9f5dc
dash@0.5.12-12
no fix listed
1
eclipseaerios/hlo-deployment-engine:v3.0.0d582d39208c7
dash@0.5.12-12
no fix listed
1
eclipseaerios/hlo-fe-engine:v3.0.08ed2df4ca692
dash@0.5.12-12
no fix listed
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
dash@0.5.12-12
no fix listed
1
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
dash@0.5.12-12
no fix listed
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
dash@0.5.12-2
no fix listed
1
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
dash@0.5.12-12
no fix listed
1
egorz/netology-diploma-web-app:4.05627a54bd1ad
dash@0.5.12-2
no fix listed
1
elastic/apm-server:7.17.6c7a1c63257d0
dash@0.5.10.2-6
no fix listed
1
elastictranscoder/media:627e21dc963ab3858c6b
dash@0.5.8-2.10
no fix listed
1
elastictranscoder/media-storage:f6d861a026208b8c2359
dash@0.5.8-2.10
no fix listed
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
dash@0.5.8-2.10
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
dash@0.5.8-2.10
no fix listed
1
elastiflow/flow-collector:7.26.0fee67842e16b
dash@0.5.12-6ubuntu5
no fix listed
1
electriccoinco/lightwalletd:v0.5.42ae3a551e111
dash@0.5.12-12
no fix listed
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
dash@0.5.10.2-6
no fix listed
1
emqx/ecp-ui:2.5.1e33e9816f147
dash@0.5.12-2
no fix listed
1
emqx/emqx:5.8.935b46f7aa7a0
dash@0.5.12-12
no fix listed
1
emqx/emqx:5.8.0b37886391e1f
dash@0.5.12-2
no fix listed
1
enclavenetworks/enclave:latest0a99759300d1
dash@0.5.10.2-6
no fix listed
1
engrmth/bnkr:2.1.06d8464e6f0e8
dash@0.5.10.2-6
no fix listed
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
dash@0.5.8-2.10
no fix listed
1
envoyproxy/envoy:v1.30.92956bd9de830
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
envoyproxy/envoy:v1.38.4447f857a0146
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
envoyproxy/envoy:v1.31-latestcaa5b411be16
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
envoyproxy/envoy:v1.34-latestcfc0678bc03c
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
envoyproxy/envoy:v1.39.0d59f7f5fa10c
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
envoyproxy/envoy:v1.30.1e596fda6a0ce
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
envoyproxy/envoy:v1.18.2e8b37c1d7578
dash@0.5.8-2.10
no fix listed
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
dash@0.5.8-2.10
no fix listed
1
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
dash@0.5.12-12
no fix listed
1
erigontech/erigon:v2.61.288706754b627
dash@0.5.12-2
no fix listed
1
erigontech/erigon:latest8cd3fbcbb35d
dash@0.5.12-2
no fix listed
1
erlangsolutions/mongooseim:6.6.0cc5bf032931f
dash@0.5.12-6ubuntu5
no fix listed
1
erudikaltd/para:latest_stable235e0bc53da2
dash@0.5.12-12ubuntu3
no fix listed
1
escaping/core-keeper-dedicated:latest87fa79255962
dash@0.5.12-12
no fix listed
1
esphome/esphome:2026.7.44866347cb5b4
dash@0.5.12-12
no fix listed
1

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.