StackRadar

CVE-2026-102474

Medium

Advisory

Published 29 Sept 2026In the index since 1 Oct 2026
Severity
Medium
worst across findings
CVSS
4.0
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,656
of 17,985 indexed, latest versions
Container images
2,632
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,656 of 17,985 indexed charts deploy, on 2,632 images.

Affected packageAffected versionsFixed inImages
dashdeb0.5.7-4ubuntu1, 0.5.8-2.1ubuntu2, 0.5.8-2.10, 0.5.10.2-6+6 moreno fix listed2,632
OSV records
DEBIAN-CVE-2026-102474ECHO-a40f-fcbc-6816UBUNTU-CVE-2026-102474
Trending
Rank 12 in indexed charts, since 1 Oct 2026. See the ranking →

Charts affected

2,656 by stars
ChartLatestAffected imagesRadar Score
changedetection-iozekker6Verified publisher1.103.01 of 1See more

changedetection-io zekker6 1.103.0

1 of the 1 container images this version deploys carry CVE-2026-102474.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.834df3680db1c
dash@0.5.12-2
no fix listed

Open the chart page →

2,932
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-102474.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
dash@0.5.12-12
no fix listed

Open the chart page →

1,859
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-102474.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
dash@0.5.12-2
no fix listed

Open the chart page →

5,018
zimagizimagi2.7.171 of 6See more

zimagi zimagi 2.7.17

1 of the 6 container images this version deploys carry CVE-2026-102474.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.15.331407c0e8e32
dash@0.5.12-2
no fix listed

Open the chart page →

2,135
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-102474.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
dash@0.5.8-2.10
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
dash@0.5.10.2-6
no fix listed

Open the chart page →

9,696
zoo-project-druzoo-projectOfficialVerified publisher0.10.81 of 6See more

zoo-project-dru zoo-project 0.10.8

1 of the 6 container images this version deploys carry CVE-2026-102474.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-51e7d55383f24594959b69e58518961c6aa66740da112e8d03f1
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed

Open the chart page →

6,744

Container images carrying it

2,632 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
esphome/esphome:2026.9.14ad55931c018
dash@0.5.12-12
no fix listed
1
esphome/esphome:2024.3.09ab8cc88b28c
dash@0.5.12-2
no fix listed
1
esphome/esphome:2024.12.2b2c6322700ac
dash@0.5.12-2
no fix listed
1
esphome/esphome:2025.3.0def8b6e4f517
dash@0.5.12-2
no fix listed
1
espocrm/espocrm:9.3.101b5a24504ed9
dash@0.5.12-12
no fix listed
1
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
dash@0.5.10.2-6
no fix listed
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
dash@0.5.8-2.1ubuntu2
no fix listed
1
ethersphere/bee:2.2.0a884fd84b72f
dash@0.5.12-2
no fix listed
1
ethersphere/beekeeper:lateste3bc0da9ffde
dash@0.5.12-2
no fix listed
1
ethpandaops/assertoor:latest1efa2fba6711
dash@0.5.12-12
no fix listed
1
ethpandaops/buildoor:mainb3dc726f8ba5
dash@0.5.12-12
no fix listed
1
ethpandaops/dora:mastere7c0ed360365
dash@0.5.12-12
no fix listed
1
ethpandaops/eleel:mainb8f1b707aee0
dash@0.5.12-6ubuntu5
no fix listed
1
ethpandaops/forky:debian-latestc937f4ba737c
dash@0.5.12-12
no fix listed
1
ethpandaops/observoor:masterc7e5055defcb
dash@0.5.12-2
no fix listed
1
ethpandaops/rpc-snooper:latestc0b30fcf64bc
dash@0.5.12-12
no fix listed
1
ethpandaops/spamoor:latestc8c6ab0816c4
dash@0.5.12-12
no fix listed
1
fabriziosalmi/certmate:2.47.18891fc2becd0
dash@0.5.12-12
no fix listed
1
factoriotools/factorio:latest18c07a80cacc
dash@0.5.12-12
no fix listed
1
factoriotools/factorio:stable4ec5fea2e06b
dash@0.5.12-12
no fix listed
1
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
dash@0.5.12-12
no fix listed
1
falcosecurity/event-generator:latest932956d86c99
dash@0.5.12-2
no fix listed
1
falcosecurity/falco-driver-loader:0.45.0d7d287d4dcee
dash@0.5.12-2
no fix listed
1
federid/webhook:0.1.0fbfb7c6510a7
dash@0.5.12-2
no fix listed
1
felipecs8/app-db-connection-test:v129e06c9c6385
dash@0.5.12-2
no fix listed
1
filegator/filegator:latest34bf565a11a4
dash@0.5.12-12
no fix listed
1
firefart/requesttracker:5.0.40d6249906d8c
dash@0.5.12-2
no fix listed
1
fireflyiii/core:version-6.6.6ae69fdd95cde
dash@0.5.12-12
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
dash@0.5.10.2-6
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
dash@0.5.12-2
no fix listed
1
flanksource/apm-hub:v0.0.471dacc3195bf9
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
flanksource/batch-runner:v1.0.44689687a7cf95
dash@0.5.12-6ubuntu5
no fix listed
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
dash@0.5.12-2
no fix listed
1
flanksource/incident-manager-ui:v1.4.321dcc01382340e
dash@0.5.12-2
no fix listed
1
flashcatcloud/nightingale:8.5.1421acb36181b
dash@0.5.12-12
no fix listed
1
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
dash@0.5.12-2
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
dash@0.5.12-2
no fix listed
1
fluent/fluentd-kubernetes-daemonset:v1.19.3-debian-elasticsearch7-1.1de9cf5f1127a
dash@0.5.12-12
no fix listed
1
fluent/fluentd-kubernetes-daemonset:v1-debian-graylogfda93f768f98
dash@0.5.12-12
no fix listed
1
flyway/flyway:9.1545b5d7cdc75a
dash@0.5.10.2-6
no fix listed
1
fnzv/dump1090:latestb3079b95c336
dash@0.5.11+git20210903+057cd650a4ed-3build1
no fix listed
1
foldingathome/fah-gpu:latest5ef7742d1eb4
dash@0.5.8-2.10
no fix listed
1
folioci/mod-z3950:latest2493041ce880
dash@0.5.12-12
no fix listed
1
fosrl/pangolin:latest00cfb631097a
dash@0.5.12-2
no fix listed
1
frankescobar/allure-docker-service:2.27.00815040339a9
dash@0.5.8-2.10
no fix listed
1
frankescobar/allure-docker-service:2.35.14154286c0209
dash@0.5.12-6ubuntu5
no fix listed
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
dash@0.5.8-2.10
no fix listed
1
frankescobar/allure-docker-service:2.19.0cafa03b94dac
dash@0.5.8-2.10
no fix listed
1
frankescobar/allure-docker-service:latestdc171ec796d5
dash@0.5.12-6ubuntu5
no fix listed
1
free5gmano/nextepc-mongodb:latest36f806935519
dash@0.5.8-2.1ubuntu2
no fix listed
1

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.