StackRadar

CVE-2026-18220

High

Advisory

Published 29 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.003
22nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
233
of 17,781 indexed, latest versions
Container images
233
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 233 of 17,781 indexed charts deploy, on 233 images.

Affected packageAffected versionsFixed inImages
binutilsdeb2.40-2, 2.44-3no fix listed233
OSV records
DEBIAN-CVE-2026-18220

Charts affected

233 by stars
ChartLatestAffected imagesRadar Score
devtron-enterprisedevtron-labs48.0.02 of 28See more

devtron-enterprise devtron-labs 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
binutils@2.40-2
no fix listed

Open the chart page →

68,240
devtron-operatordevtron-labs0.23.31 of 11See more

devtron-operator devtron-labs 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
binutils@2.40-2
no fix listed

Open the chart page →

32,902
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
binutils@2.40-2
no fix listed

Open the chart page →

7,141
wizarrdjjudas21Verified publisher0.1.51 of 1See more

wizarr djjudas21 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
binutils@2.40-2
no fix listed

Open the chart page →

14,627
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
binutils@2.44-3
no fix listed

Open the chart page →

13,391
esphomeegebackVerified publisher2.0.251 of 1See more

esphome egeback 2.0.25

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
esphome/esphome:2026.7.44866347cb5b4
binutils@2.44-3
no fix listed

Open the chart page →

3,121
wordpresseoc-chartsVerified publisher0.14.41 of 1See more

wordpress eoc-charts 0.14.4

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
library/wordpress:6.8.3-apache30bff39330d1
binutils@2.44-3
no fix listed

Open the chart page →

7,233
matomoeosc-lot-1Verified publisher0.2.01 of 1See more

matomo eosc-lot-1 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
library/matomo:5.1.2-apache2415789e1602
binutils@2.40-2
no fix listed

Open the chart page →

5,290
espocrmespocrmVerified publisher1.0.11 of 2See more

espocrm espocrm 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
espocrm/espocrm:9.3.101b5a24504ed9
binutils@2.44-3
no fix listed

Open the chart page →

6,431
beeport-uiethersphereVerified publisher0.76.21 of 3See more

beeport-ui ethersphere 0.76.2

1 of the 3 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed

Open the chart page →

7,368
multichain-uiethersphereVerified publisher0.73.11 of 3See more

multichain-ui ethersphere 0.73.1

1 of the 3 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
library/node:ltsbe23f54a88d3
binutils@2.40-2
no fix listed

Open the chart page →

7,368
static-siteethersphereVerified publisher0.73.11 of 2See more

static-site ethersphere 0.73.1

1 of the 2 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
library/node:latestf5d1cc40abc1
binutils@2.44-3
no fix listed

Open the chart page →

6,851
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
binutils@2.40-2
no fix listed

Open the chart page →

10,741
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
binutils@2.44-3
no fix listed

Open the chart page →

5,039
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
binutils@2.44-3
no fix listed
fireflyiii/data-importer:version-2.2.3ab52bf932546
binutils@2.44-3
no fix listed

Open the chart page →

10,260
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
binutils@2.44-3
no fix listed

Open the chart page →

4,829
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed

Open the chart page →

5,704
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
binutils@2.40-2
no fix listed

Open the chart page →

64,489
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed

Open the chart page →

5,704
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
binutils@2.40-2
no fix listed

Open the chart page →

3,463
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latest000c5ee5ee96
binutils@2.44-3
no fix listed

Open the chart page →

3,112
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
binutils@2.40-2
no fix listed

Open the chart page →

9,077
mopidygeek-cookbookVerified publisher0.1.21 of 1See more

mopidy geek-cookbook 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
jaedb/iris:latest048cfbf58d57
binutils@2.40-2
no fix listed

Open the chart page →

12,958
skypilotgeek-cookbookVerified publisher0.0.11 of 3See more

skypilot geek-cookbook 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
binutils@2.44-3
no fix listed

Open the chart page →

8,923
glpiglpi-chart0.1.12 of 3See more

glpi glpi-chart 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
library/phpmyadmin:latest3a8a8d6b5289
binutils@2.44-3
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
binutils@2.40-2
no fix listed

Open the chart page →

12,170
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
binutils@2.40-2
no fix listed

Open the chart page →

49,025
heliconehelicone0.1.421 of 14See more

helicone helicone 0.1.42

1 of the 14 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
binutils@2.40-2
no fix listed

Open the chart page →

24,995
castopodhelmforgeVerified publisher1.2.71 of 3See more

castopod helmforge 1.2.7

1 of the 3 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
castopod/castopod:1.15.54e4f0440520f
binutils@2.44-3
no fix listed

Open the chart page →

9,342
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
binutils@2.44-3
no fix listed

Open the chart page →

10,849
discount-bandithelmforgeVerified publisher2.0.81 of 3See more

discount-bandit helmforge 2.0.8

1 of the 3 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
cybrarist/discount-bandit:v4.0.4e9e2447ac666
binutils@2.44-3
no fix listed

Open the chart page →

29,817
drupalhelmforgeVerified publisher1.2.131 of 2See more

drupal helmforge 1.2.13

1 of the 2 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
library/drupal:11.4.6-php8.5-apache-bookworm28f7931ecbcb
binutils@2.40-2
no fix listed

Open the chart page →

3,802
middlewarehelmforgeVerified publisher1.2.61 of 4See more

middleware helmforge 1.2.6

1 of the 4 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
middlewareeng/middleware:0.3.1747d880812f1
binutils@2.40-2
no fix listed

Open the chart page →

9,653
moodlehelmforgeVerified publisher1.1.01 of 2See more

moodle helmforge 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
binutils@2.40-2
no fix listed

Open the chart page →

6,103
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
binutils@2.44-3
no fix listed

Open the chart page →

4,751
myapphelmingapp0.1.01 of 1See more

myapp helmingapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
muhammedgamal/fp23:latest74b4cd69b6fa
binutils@2.40-2
no fix listed

Open the chart page →

12,607
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
binutils@2.40-2
no fix listed

Open the chart page →

25,017
ilum-unity-catalogilumVerified publisher0.1.01 of 4See more

ilum-unity-catalog ilum 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
binutils@2.40-2
no fix listed

Open the chart page →

11,812
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
binutils@2.40-2
no fix listed

Open the chart page →

17,852
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
binutils@2.40-2
no fix listed

Open the chart page →

10,780
jasperjasperVerified publisher1.0.2021 of 2See more

jasper jasper 1.0.202

1 of the 2 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
binutils@2.40-2
no fix listed

Open the chart page →

5,998
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
binutils@2.40-2
no fix listed

Open the chart page →

5,040
image-storage-servicejtektVerified publisher0.4.31 of 4See more

image-storage-service jtekt 0.4.3

1 of the 4 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
binutils@2.40-2
no fix listed

Open the chart page →

22,589
shinsei-managerjtektVerified publisher0.2.04 of 8See more

shinsei-manager jtekt 0.2.0

4 of the 8 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
moreillon/api-proxy:latestd7d4a5463525
binutils@2.40-2
no fix listed
moreillon/group-manager:latest3caa8f710ee0
binutils@2.40-2
no fix listed
moreillon/user-manager:v5.0.2e1c9bfab5c16
binutils@2.40-2
no fix listed
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
binutils@2.40-2
no fix listed

Open the chart page →

63,461
time-series-storagejtektVerified publisher0.1.101 of 2See more

time-series-storage jtekt 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
binutils@2.40-2
no fix listed

Open the chart page →

16,600
cdashkitwareVerified publisher0.19.01 of 3See more

cdash kitware 0.19.0

1 of the 3 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
kitware/cdash:v5.3.0d7767d9b9da4
binutils@2.44-3
no fix listed

Open the chart page →

12,062
rspamdklicktippVerified publisher1.6.01 of 1See more

rspamd klicktipp 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
rspamd/rspamd:4.1.4e870599c970d
binutils@2.44-3
no fix listed

Open the chart page →

1,775
kubeflowkromanow94-kubeflow0.5.12 of 30See more

kubeflow kromanow94-kubeflow 0.5.1

2 of the 30 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
library/python:3.7eedf63967cdb
binutils@2.40-2
no fix listed
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
binutils@2.40-2
no fix listed

Open the chart page →

70,530
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
binutils@2.44-3
no fix listed

Open the chart page →

9,620
firefly-iiikubernetes-homelab-helm-chartsVerified publisher0.1.31 of 3See more

firefly-iii kubernetes-homelab-helm-charts 0.1.3

1 of the 3 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.6.6ae69fdd95cde
binutils@2.44-3
no fix listed

Open the chart page →

4,382
kube-httpcachekubernetes-replicator0.9.11 of 1See more

kube-httpcache kubernetes-replicator 0.9.1

1 of the 1 container images this version deploys carry CVE-2026-18220.

Container imageDigestPackageFixed in
quay.io/mittwald/kube-httpcache:stable2169032c5840
binutils@2.40-2
no fix listed

Open the chart page →

4,395

Container images carrying it

233 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/wordpress:6.4.3-apache8ae66efb09a2
binutils@2.40-2
no fix listed
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
binutils@2.44-3
no fix listed
1
library/wordpress:php8.1-apachef73396626d2f
binutils@2.44-3
no fix listed
1
makersquad/harp-proxy:0.8.1a40dd258c527
binutils@2.40-2
no fix listed
1
mariusm/vingress:0.5.0b3db186c3d72
binutils@2.44-3
no fix listed
1
martinhelmich/typo3:12.4c83a4f3fd7ae
binutils@2.40-2
no fix listed
1
mathesar/mathesar:0.12.0091757cb01fe
binutils@2.40-2
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
binutils@2.40-2
no fix listed
1
middlewareeng/middleware:0.3.1747d880812f1
binutils@2.40-2
no fix listed
1
mindsdb/mindsdb:latest163011c09299
binutils@2.44-3
no fix listed
1
mintproject/model-catalog-fastapi:7dd88dc5bf1fe6a6d4703ea0a077afee45cb256102260d20a21f
binutils@2.40-2
no fix listed
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
binutils@2.40-2
no fix listed
1
moreillon/api-proxy:latestd7d4a5463525
binutils@2.40-2
no fix listed
1
moreillon/food-manager:lateste8fd856e593d
binutils@2.40-2
no fix listed
1
moreillon/group-manager:latest3caa8f710ee0
binutils@2.40-2
no fix listed
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
binutils@2.40-2
no fix listed
1
muhammedgamal/fp23:latest74b4cd69b6fa
binutils@2.40-2
no fix listed
1
nousresearch/hermes-agent:v2026.8.27e0df6adebddf
binutils@2.44-3
no fix listed
1
oled01/automx2:2025.1.105d3e398e675
binutils@2.40-2
no fix listed
1
oneuptime/probe:release6b2d98713711
binutils@2.40-2
no fix listed
1
oneuptime/runner:release4accc516d800
binutils@2.44-3
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
binutils@2.40-2
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
binutils@2.40-2
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
binutils@2.40-2
no fix listed
1
openbas/caldera-server:5.1.0a277796d9724
binutils@2.40-2
no fix listed
1
openebs/rawfile-localpv:v0.15.2a39ef27ea28b
binutils@2.44-3
no fix listed
1
openproject/hocuspocus:release-338001b288dc1359dfb5
binutils@2.40-2
no fix listed
1
phan2410/dummy-service:0.0.89c6ed6de26ca
binutils@2.40-2
no fix listed
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
binutils@2.40-2
no fix listed
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
binutils@2.44-3
no fix listed
1
pockost/matomo:5.13.07f5d293cbe4e
binutils@2.44-3
no fix listed
1
polyaxon/polyaxon-api:2.16.42b55c3265a90
binutils@2.44-3
no fix listed
1
polyaxon/polyaxon-streams:2.16.4c186bd9834c0
binutils@2.44-3
no fix listed
1
prefecthq/prefect:3.8.5-python3.110018d02259bc
binutils@2.44-3
no fix listed
1
prefecthq/prefect:2.20.4-python3.101df4b5b6238a
binutils@2.40-2
no fix listed
1
pretix/standalone:2026.7.05df3b7aa852e
binutils@2.44-3
no fix listed
1
prowlercloud/prowler-api:5.31.14f252d579be2
binutils@2.40-2
no fix listed
1
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
binutils@2.44-3
no fix listed
1
redash/redash:25.8.000d813437db5
binutils@2.40-2
no fix listed
1
redash/redash:26.3.0c5c9148f5c38
binutils@2.40-2
no fix listed
1
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
binutils@2.40-2
no fix listed
1
rocketadmin/rocketadmin:1.17.710955ef540b9
binutils@2.40-2
no fix listed
1
rocketchat/freeswitch:stablecfba5c20a5cc
binutils@2.40-2
no fix listed
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
binutils@2.44-3
no fix listed
1
rspamd/rspamd:4.1.4e870599c970d
binutils@2.44-3
no fix listed
1
ryshe/terraria:latestb1c89f7f359a
binutils@2.40-2
no fix listed
1
santisbon/evwatcher:latestc4e994ca4540
binutils@2.40-2
no fix listed
1
santisbon/evworker:lateste807283f8d69
binutils@2.40-2
no fix listed
1
santisbon/speedtest:latest8ee3a1697227
binutils@2.40-2
no fix listed
1
sashafefler/spacecapybara_app:latestf96d7804c0ca
binutils@2.40-2
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.