StackRadar

CVE-2026-14164

High

Advisory

Published 30 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
166
of 17,781 indexed, latest versions
Container images
195
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libarchive security update

Carried by container images the latest versions of 166 of 17,781 indexed charts deploy, on 195 images.

Affected packageAffected versionsFixed inImages
libarchiverpm3.5.3-3.el9, 3.5.3-4.el9, 3.5.3-4.el9.0.1, 3.5.3-5.el9_6+4 more0:3.5.3-11.el9_8, 0:3.7.7-10.el10_2148
libarchivedeb3.4.0-2ubuntu1, 3.4.0-2ubuntu1.2, 3.4.0-2ubuntu1.5, 3.6.0-1ubuntu1+16 more3.4.0-2ubuntu1.5+esm3, 3.6.0-1ubuntu1.8, 3.6.2-1+deb12u5, 3.7.2-2ubuntu0.8+1 more47
OSV records
DEBIAN-CVE-2026-14164RHSA-2026:52674RHSA-2026:52675RLSA-2026:52674RLSA-2026:52675UBUNTU-CVE-2026-14164
Also known as
RHSA-2026:58558, RHSA-2026:58573, RHSA-2026:58574, USN-8581-1

Charts affected

166 by stars
ChartLatestAffected imagesRadar Score
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
libarchive@3.7.4-4
no fix listed

Open the chart page →

10,605
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
libarchive@3.7.2-2ubuntu0.6
3.7.2-2ubuntu0.8

Open the chart page →

6,207
photoprismschoolguys-helmcharts0.3.81 of 1See more

photoprism schoolguys-helmcharts 0.3.8

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
photoprism/photoprism:260601650c6ad5a651
libarchive@3.8.5-1ubuntu2.1
3.8.5-1ubuntu2.2

Open the chart page →

10,348
shopwareshopware-storeVerified publisher2.1.11 of 5See more

shopware shopware-store 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8

Open the chart page →

4,876
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8

Open the chart page →

5,201
infisicalsinextraVerified publisher0.6.01 of 1See more

infisical sinextra 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
infisical/infisical:v0.165.602082bf13163
libarchive@3.7.4-4+deb13u1
no fix listed

Open the chart page →

3,014
cost-analyzersoftonic2.5.52 of 6See more

cost-analyzer softonic 2.5.5

2 of the 6 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8

Open the chart page →

7,901
strimzi-user-operatorspartan0.4.01 of 1See more

strimzi-user-operator spartan 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.45.158c727cd2e68
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8

Open the chart page →

1,836
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
libarchive@3.7.4-4+deb13u1
no fix listed

Open the chart page →

66,266
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
libarchive@3.7.2-2ubuntu0.4
3.7.2-2ubuntu0.8

Open the chart page →

8,193
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.5+esm3

Open the chart page →

10,006
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
libarchive@3.7.2-2
3.7.2-2ubuntu0.8

Open the chart page →

45,239
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

1,787
velero-clientvelero-clientVerified publisher1.4.21 of 1See more

velero-client velero-client 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/velero-client/velero-client:1.4.203015f863a3e
libarchive@3.7.7-8.el10_1
0:3.7.7-10.el10_2

Open the chart page →

513
myweatherhelmwebapp11.3.501 of 8See more

myweatherhelm webapp1 1.3.50

1 of the 8 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.5+esm3

Open the chart page →

9,130
myweatherhelm-schedulingwebapp11.3.921 of 9See more

myweatherhelm-scheduling webapp1 1.3.92

1 of the 9 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
mcr.microsoft.com/azure-sql-edge:latest902628a8be89
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.5+esm3

Open the chart page →

9,130

Container images carrying it

195 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
nutanix/cn-rwx-operator:1.1.00082e0cebd42
libarchive@3.7.7-8.el10_1
0:3.7.7-10.el10_2
1
openkm/openkm-ce:6.3.113bc465a7461b
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.5+esm3
1
opennms/sentinel:36.0.288869082a14f
libarchive@3.7.7-8.el10_1
0:3.7.7-10.el10_2
1
openproject/openproject:17.8.0-slim48952034215d
libarchive@3.7.4-4+deb13u1
no fix listed
1
owncloud/server:10.15.051d9b74fc2a8
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.5+esm3
1
percona/percona-postgresql-operator:2.8.06cce2698d3f5
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
percona/percona-server-mongodb-operator:1.20.1d09453ce7886
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
percona/percona-server-mongodb-operator:1.23.0feaff989e253
libarchive@3.7.7-8.el10_1
0:3.7.7-10.el10_2
1
percona/percona-server-mysql-operator:1.2.028bfc38c1d4b
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
percona/percona-xtradb-cluster-operator:1.14.03232ae01d0ff
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
percona/percona-xtradb-cluster-operator:1.20.0ac4d0995c71e
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
photoprism/photoprism:260601650c6ad5a651
libarchive@3.8.5-1ubuntu2.1
3.8.5-1ubuntu2.2
1
photoprism/photoprism:251130db16ee6b1ba3
libarchive@3.7.7-0ubuntu3
no fix listed
1
photoprism/photoprism:240711-cefc6fd632ca74
libarchive@3.7.2-2ubuntu0.1
3.7.2-2ubuntu0.8
1
pschiffe/pdns-admin:0.4.137ebba8c2b8f
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
razzy10/product-service:latest702e411956db
libarchive@3.5.3-5.el9_6
0:3.5.3-11.el9_8
1
redislabs/operator:8.0.18-119078e713bb6a
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
rm3l/dev-feed-api:latest9a7f732245a3
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
rspamd/rspamd:4.1.4e870599c970d
libarchive@3.7.4-4+deb13u1
no fix listed
1
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
libarchive@3.6.2-1
3.6.2-1+deb12u5
1
seldonio/seldon-core-operator:1.19.0544e3bf71bd1
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
sslhep/servicex-did-finder-xrootd:v1.8.5c284442b44e3
libarchive@3.7.4-4+deb13u1
no fix listed
1
stashapp/stash-box:latesta534c8afdf39
libarchive@3.7.2-2ubuntu0.4
3.7.2-2ubuntu0.8
1
trinodb/trino:45038c6f24ab1a4
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
veecode/devportalc443520aebf7
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
gcr.io/kasten-images/restorectl:8.0.145a0884f9a90c
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
gcr.io/kubecost1/cost-model:prod-2.5.502b90651367f
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
gcr.io/kubecost1/cost-model:prod-2.6.39e507ac0aebb
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
gcr.io/kubecost1/kubecost-modeling:v0.1.24a2259b098b13
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
gcr.io/kubecost1/kubecost-modeling:v0.1.22a461dc5cb96a
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
ghcr.io/adfinis/kubernetes-etcd-backup:v1.4.68ec6c4812a7e
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
ghcr.io/afairgiant/medikeep:v0.69.0766699daa9ac
libarchive@3.6.2-1+deb12u4
3.6.2-1+deb12u5
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
libarchive@3.6.2-1+deb12u1
3.6.2-1+deb12u5
1
ghcr.io/chmouel/gosmee:v0.32.060b8db1f68cc
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/containers/kubernetes-mcp-server:v0.0.666d650f4bd6ac
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/deltabadger/deltabadger:2.23.3bffe3c22fabc
libarchive@3.7.4-4+deb13u1
no fix listed
1
ghcr.io/devops-ia/cp-schema-registry:8.1.1-msk-iam-auth2.3.530d1a445acc7
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.