StackRadar

CVE-2026-14164

High

Advisory

Published 30 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
166
of 17,781 indexed, latest versions
Container images
195
deployed by those charts
Fix available
2 of 2
affected packages

Red Hat Security Advisory: libarchive security update

Carried by container images the latest versions of 166 of 17,781 indexed charts deploy, on 195 images.

Affected packageAffected versionsFixed inImages
libarchiverpm3.5.3-3.el9, 3.5.3-4.el9, 3.5.3-4.el9.0.1, 3.5.3-5.el9_6+4 more0:3.5.3-11.el9_8, 0:3.7.7-10.el10_2148
libarchivedeb3.4.0-2ubuntu1, 3.4.0-2ubuntu1.2, 3.4.0-2ubuntu1.5, 3.6.0-1ubuntu1+16 more3.4.0-2ubuntu1.5+esm3, 3.6.0-1ubuntu1.8, 3.6.2-1+deb12u5, 3.7.2-2ubuntu0.8+1 more47
OSV records
DEBIAN-CVE-2026-14164RHSA-2026:52674RHSA-2026:52675RLSA-2026:52674RLSA-2026:52675UBUNTU-CVE-2026-14164
Also known as
RHSA-2026:58558, RHSA-2026:58573, RHSA-2026:58574, USN-8581-1

Charts affected

166 by stars
ChartLatestAffected imagesRadar Score
akto-central-setupakto1.1.101 of 5See more

akto-central-setup akto 1.1.10

1 of the 5 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

4,905
akto-hybrid-redactakto1.44.41 of 5See more

akto-hybrid-redact akto 1.44.4

1 of the 5 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.1-1-ubi9d20bd62f0182
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8

Open the chart page →

4,777
akto-mini-runtimeakto0.7.221 of 3See more

akto-mini-runtime akto 0.7.22

1 of the 3 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

2,741
akto-mini-runtime-shaakto0.7.231 of 3See more

akto-mini-runtime-sha akto 0.7.23

1 of the 3 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafkadigest-pinnedd20bd62f0182
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8

Open the chart page →

3,217
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

6,486
akto-mrs-runtime-combinedakto0.0.21 of 2See more

akto-mrs-runtime-combined akto 0.0.2

1 of the 2 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8

Open the chart page →

1,826
akto-regional-setupakto1.3.11 of 9See more

akto-regional-setup akto 1.3.1

1 of the 9 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.28e01c0305844
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

7,603
akto-runtimeakto0.1.81 of 2See more

akto-runtime akto 0.1.8

1 of the 2 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

1,411
akto-threat-backendakto0.1.51 of 2See more

akto-threat-backend akto 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

1,490
akto-threat-clientakto0.2.01 of 2See more

akto-threat-client akto 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.2.2-1-ubi98e01c0305844
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

1,523
games-on-whalesangelnu2.0.01 of 7See more

games-on-whales angelnu 2.0.0

1 of the 7 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
libarchive@3.4.0-2ubuntu1
3.4.0-2ubuntu1.5+esm3

Open the chart page →

42,126
apishiftapishiftVerified publisher0.3.02 of 4See more

apishift apishift 0.3.0

2 of the 4 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
quay.io/everythingascode/apishift:v0.3.08fbbcd23b902
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
quay.io/everythingascode/apishift-backend:v0.3.014ff275b2e61
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8

Open the chart page →

2,902
cluster-gatewayappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway:v1.12.158bed8d1e7fc
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

621
cluster-gateway-managerappscodeVerified publisher2026.6.261 of 1See more

cluster-gateway-manager appscode 2026.6.26

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/cluster-gateway-manager:v1.12.1f22cae0e6cf3
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

621
cluster-manager-hubappscodeVerified publisher2026.2.161 of 1See more

cluster-manager-hub appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8

Open the chart page →

1,038
managed-serviceaccount-managerappscodeVerified publisher2026.2.161 of 1See more

managed-serviceaccount-manager appscode 2026.2.16

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/kluster-manager/managed-serviceaccount:v0.10.0fc256885915b
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8

Open the chart page →

894
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
libarchive@3.6.2-1
3.6.2-1+deb12u5

Open the chart page →

9,412
paperless-ngxcharts-derwitt-devVerified publisher2.1.41 of 1See more

paperless-ngx charts-derwitt-dev 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
libarchive@3.7.4-4+deb13u1
no fix listed

Open the chart page →

4,626
keycloak-mcp-serverchristianhuthVerified publisher1.2.01 of 1See more

keycloak-mcp-server christianhuth 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
quay.io/sshaaf/keycloak-mcp-server:0.4.0b7e9cba72f8a
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8

Open the chart page →

1,423
kubernetes-mcpcowboysysopVerified publisher2.0.01 of 1See more

kubernetes-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
libarchive@3.5.3-5.el9_6
0:3.5.3-11.el9_8

Open the chart page →

1,797
custom-rhcl-consolecustom-rhcl-consoleVerified publisher0.1.22 of 3See more

custom-rhcl-console custom-rhcl-console 0.1.2

2 of the 3 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/custom-rhcl-console:dns-prober-v0.1.21a592ee6651a
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
quay.io/maximilianopizarro/custom-rhcl-console:v0.1.270bb0cabd653
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

1,885
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
razzy10/product-service:latest702e411956db
libarchive@3.5.3-5.el9_6
0:3.5.3-11.el9_8

Open the chart page →

3,547
dellhw_exporterdellhw-exporterVerified publisher1.0.11 of 1See more

dellhw_exporter dellhw-exporter 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
libarchive@3.5.3-4.el9.0.1
0:3.5.3-11.el9_8

Open the chart page →

3,191
prometheus-dellhw-exporterdellhw-exporterVerified publisher1.3.01 of 1See more

prometheus-dellhw-exporter dellhw-exporter 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
quay.io/galexrt/dellhw_exporter:v2.0.0b3a5806d73b5
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8

Open the chart page →

1,812
photoprismdjjudas21Verified publisher99.99.991 of 1See more

photoprism djjudas21 99.99.99

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
photoprism/photoprism:240711-cefc6fd632ca74
libarchive@3.7.2-2ubuntu0.1
3.7.2-2ubuntu0.8

Open the chart page →

16,954
doris-foundationdbdorisVerified publisher25.8.01 of 4See more

doris-foundationdb doris 25.8.0

1 of the 4 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
foundationdb/fdb-kubernetes-operator:v2.3.07d7b6985291e
libarchive@3.5.3-4.el9.0.1
0:3.5.3-11.el9_8

Open the chart page →

3,167
drogue-cloud-coredrogue-iotVerified publisher0.7.1118 of 22See more

drogue-cloud-core drogue-iot 0.7.11

18 of the 22 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/drogue-iot/authentication-service:0.11.0857b137fc7b3
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/coap-endpoint:0.11.044790b71aa22
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/command-endpoint:0.11.06dce3158b851
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/console-backend:0.11.025d229ae5bde
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/database-migration:0.11.057072c72a7cd
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/device-management-controller:0.11.0200aea1a2b42
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/device-management-service:0.11.0f4a5bfc06a74
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/device-state-service:0.11.0fbf0738cfc7e
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/http-endpoint:0.11.0b612c18479e0
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/knative-operator:0.11.0e2d927639f6e
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/mqtt-endpoint:0.11.032c6d2f5eab9
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/mqtt-integration:0.11.07ac2adb6ca49
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8

Open the chart page →

55,666
elk-stackelk-stack-test1.0.21 of 9See more

elk-stack elk-stack-test 1.0.2

1 of the 9 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
library/logstash:9.1.233eae14f0867
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8

Open the chart page →

2,942
extended-ceph-exporterextended-ceph-exporterVerified publisher1.10.01 of 2See more

extended-ceph-exporter extended-ceph-exporter 1.10.0

1 of the 2 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
libarchive@3.7.7-8.el10_1
0:3.7.7-10.el10_2

Open the chart page →

2,885
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
libarchive@3.4.0-2ubuntu1.5
3.4.0-2ubuntu1.5+esm3

Open the chart page →

64,489
trusted-issuers-listfiware0.18.71 of 1See more

trusted-issuers-list fiware 0.18.7

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
quay.io/fiware/trusted-issuers-list:0.9.13c886ce5c056
libarchive@3.5.3-5.el9_6
0:3.5.3-11.el9_8

Open the chart page →

1,701
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
libarchive@3.6.2-1
3.6.2-1+deb12u5

Open the chart page →

13,241
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.5+esm3

Open the chart page →

14,659
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
libarchive@3.6.2-1+deb12u4
3.6.2-1+deb12u5

Open the chart page →

9,077
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.5+esm3

Open the chart page →

27,949
xtevegeek-cookbookVerified publisher8.4.21 of 1See more

xteve geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.5+esm3

Open the chart page →

17,929
gosmee-clientgosmee-clientVerified publisher0.1.31 of 1See more

gosmee-client gosmee-client 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/chmouel/gosmee:v0.32.060b8db1f68cc
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

228
grafana-cloud-onboardinggrafana0.4.71 of 5See more

grafana-cloud-onboarding grafana 0.4.7

1 of the 5 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8

Open the chart page →

4,637
pyroscope-monitoringgrafana0.1.11 of 6See more

pyroscope-monitoring grafana 0.1.1

1 of the 6 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
libarchive@3.5.3-5.el9_6
0:3.5.3-11.el9_8

Open the chart page →

8,188
kubernetes-mcp-serverhelmforgeVerified publisher1.0.61 of 1See more

kubernetes-mcp-server helmforge 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/containers/kubernetes-mcp-server:v0.0.666d650f4bd6ac
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

252
medikeephelmforgeVerified publisher2.0.01 of 3See more

medikeep helmforge 2.0.0

1 of the 3 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/afairgiant/medikeep:v0.69.0766699daa9ac
libarchive@3.6.2-1+deb12u4
3.6.2-1+deb12u5

Open the chart page →

6,022
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
libarchive@3.6.0-1ubuntu1
3.6.0-1ubuntu1.8

Open the chart page →

14,290
paperlesshomelabcihelmchartstestVerified publisher9.1.91 of 1See more

paperless homelabcihelmchartstest 9.1.9

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libarchive@3.6.2-1
3.6.2-1+deb12u5

Open the chart page →

16,384
paperlesshpVerified publisher0.1.11 of 5See more

paperless hp 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
libarchive@3.7.4-4+deb13u1
no fix listed

Open the chart page →

26,612
hammerspace-csihscsi1.2.81 of 6See more

hammerspace-csi hscsi 1.2.8

1 of the 6 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
hammerspaceinc/csi-plugin:v1.2.8-rc2395bee4504fc
libarchive@3.5.3-5.el9_6
0:3.5.3-11.el9_8

Open the chart page →

4,441
monitoring-stackict-platformVerified publisher0.4.01 of 13See more

monitoring-stack ict-platform 0.4.0

1 of the 13 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8

Open the chart page →

9,573
iframelyiframelyVerified publisher2.3.51 of 1See more

iframely iframely 2.3.5

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
registry.gitlab.com/xrow-public/helm-iframely/iframely:2.3.5fcf07d5ff7e2
libarchive@3.5.3-7.el9_7
0:3.5.3-11.el9_8

Open the chart page →

3,154
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
libarchive@3.7.4-4+deb13u1
no fix listed

Open the chart page →

3,014
daveit-at-mOfficialVerified publisher0.2.157 of 11See more

dave it-at-m 0.2.15

7 of the 11 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8

Open the chart page →

15,089
kf-app-eaiit-at-mOfficialVerified publisher0.1.71 of 1See more

kf-app-eai it-at-m 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-14164.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8

Open the chart page →

1,947

Container images carrying it

195 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/drogue-iot/outbox-controller:0.11.01a958edafdb1
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/topic-strimzi-operator:0.11.05253fbf8d04c
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/ttn-operator:0.11.07dd5ac80c8f1
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/user-auth-service:0.11.0adebc40ddf98
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/drogue-iot/websocket-integration:0.11.0372dcd370945
libarchive@3.5.3-3.el9
0:3.5.3-11.el9_8
1
ghcr.io/grafana/alloy-operator:1.3.02088dcb22aaa
libarchive@3.5.3-5.el9_6
0:3.5.3-11.el9_8
1
ghcr.io/grafana/alloy-operator:1.7.02ce23f948e02
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
ghcr.io/grafana/alloy-operator:1.12.14ee4b71cf16a
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/grafana/alloy-operator:1.8.1ae85d68749c7
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
ghcr.io/haveagitgat/tdarr:2.00.18.23fbe4c29d14c
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.5+esm3
1
ghcr.io/it-at-m/dave-admin-portal/dave-adminportal:10.0.0cbff8141302f
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/it-at-m/dave-backend/dave-backend:10.0.0f66413e62afc
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/it-at-m/dave-document-storage/dave-document-storage:10.0.09c7fc07330c9
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
ghcr.io/it-at-m/dave-eai/dave-eai:10.0.0fd93e0d125b3
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/it-at-m/dave-frontend/dave-frontend:10.0.0a49fdb8d6f1b
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/it-at-m/dave-geodata-eai/dave-geodata-eai:10.0.06a3fe3136856
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/it-at-m/dave-selfservice-portal/dave-selfserviceportal:10.0.0d352df1b94b6
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/it-at-m/kf-app-eai:1.0.65de339b3d537
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.5+esm3
1
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.5+esm3
1
ghcr.io/kanisterio/controller:0.118.0d22616a5998b
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
ghcr.io/kluster-manager/cluster-gateway:v1.12.158bed8d1e7fc
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/kluster-manager/cluster-gateway-manager:v1.12.1f22cae0e6cf3
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/kluster-manager/managed-serviceaccount:v0.10.0fc256885915b
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
ghcr.io/kluster-manager/registration-operator:v1.2.00cbced8e6240
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
ghcr.io/llm-d/llm-d-model-service:v0.0.158b99a8104a2f
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
ghcr.io/microboxlabs/miot-calendar:latest-jvm7157cdc0bf5b
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
ghcr.io/microboxlabs/miot-srv:latest4ec11d229028
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
ghcr.io/microboxlabs/miot-srv:latest5796553b41ae
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
libarchive@3.6.2-1+deb12u1
3.6.2-1+deb12u5
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
libarchive@3.7.4-4
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
libarchive@3.7.4-4
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
libarchive@3.7.4-4
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libarchive@3.6.2-1
3.6.2-1+deb12u5
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
libarchive@3.7.4-4
no fix listed
1
ghcr.io/projectnessie/nessie:0.92.19efe3c74d55f
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
ghcr.io/projectnessie/nessie:0.108.4c0f42874c810
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
libarchive@3.7.2-2ubuntu0.6
3.7.2-2ubuntu0.8
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
libarchive@3.4.0-2ubuntu1.2
3.4.0-2ubuntu1.5+esm3
1
mcr.microsoft.com/mssql/server:2022-latestba4c8329f48f
libarchive@3.6.0-1ubuntu1.7
3.6.0-1ubuntu1.8
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
libarchive@3.7.2-2ubuntu0.6
3.7.2-2ubuntu0.8
1
public.ecr.aws/aktosecurity/confluentinc-cp-kafka:8.1.0-1-ubi99026dbbf280d
libarchive@3.5.3-6.el9_6
0:3.5.3-11.el9_8
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
public.ecr.aws/perfectscale-io/ubi9/ubi:9.5d7c3def9252b
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
public.ecr.aws/v0r6c2e2/trino:latestc265156b00d1
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
quay.io/ai-lab/llamacpp_python:latest70d138997acd
libarchive@3.5.3-4.el9
0:3.5.3-11.el9_8
1
quay.io/backube/volsync:0.16.00d03a6aad575
libarchive@3.5.3-9.el9_7
0:3.5.3-11.el9_8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.