StackRadar

CVE-2026-18477

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,481
of 17,828 indexed, latest versions
Container images
2,473
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,481 of 17,828 indexed charts deploy, on 2,473 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,473
OSV records
DEBIAN-CVE-2026-18477UBUNTU-CVE-2026-18477ECHO-b8d2-238f-d46b

Charts affected

2,481 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,473 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
cyverse/irods-csi-driver:v0.12.0aa69d105b292
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed
1
cznic/knot-resolver:v6.4.24ad2e1894b78
tar@1.35+dfsg-3.1
no fix listed
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
tar@1.34+dfsg-1.2
no fix listed
1
daedalusproject/base_kubectl:latest6f72b5119eda
tar@1.30+dfsg-7
no fix listed
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
dannielkil/book-frontend:latest937993927694
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
darthsim/imgproxy:v3.30.13b709e4a0e5e
tar@1.35+dfsg-3build1
no fix listed
1
darthsim/imgproxy:v3.26476cb08c816a
tar@1.35+dfsg-3build1
no fix listed
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
tar@1.35+dfsg-3build1
no fix listed
1
darthsim/imgproxy:latestf247c72df1d7
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
daskdev/dask-notebook:1.1.0052630f5ca04
tar@1.29b-2
no fix listed
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
tar@1.29b-2ubuntu0.3
no fix listed
1
datadog/agent:6aad9994de6a7
tar@1.35+dfsg-3build1
no fix listed
1
datafuselabs/databend-meta:v1.2.279ba877ee6cb4d
tar@1.34+dfsg-1.2
no fix listed
1
datafuselabs/databend-query:v1.2.279a936843b85b4
tar@1.34+dfsg-1.2
no fix listed
1
datalayers/datalayers:v2.2.1017b292079239
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
datalust/seq:5.0.832-pre9c731bb207a6
tar@1.28-2.1ubuntu0.1
no fix listed
1
datalust/seq-input-gelf:3.0.441-x643de34aed5642
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
datamate/seafile-professional:11.0.202dd66b722464
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
dbeaver/cloudbeaver:21.3.00c0985098263
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
dbeaver/cloudbeaver:26.1.287ab86d00f8c
tar@1.35+dfsg-3ubuntu0.1
no fix listed
1
dbgate/dbgate:7.2.3f2dc7423ea88
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
ddosify/alaz:v0.12.0ea602056d9ce
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
decisionrules/ai-engine:latest557dea1373aa
tar@1.35+dfsg-3.1
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
defactops/defactops-backend:1.0.2307b663c0092a
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
tar@1.35+dfsg-3.1
no fix listed
1
dellcloud/category:distributed02fc234353a9
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
dellcloud/pages:1.04d2eb25b9225
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
dellnoantechnp/cloudeye-exporter:v2.0.316873356c882d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
tar@1.35+dfsg-3.1
no fix listed
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
tar@1.35+dfsg-3.1
no fix listed
1
dessalines/lemmy:0.19.2079e9f02c286c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
tar@1.35+dfsg-3.1
no fix listed
1
devopsgoofy/k8s-platform:latestad865312099f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
dgraph/dgraph:v24.1.4b57fa31f9b7f
tar@1.35+dfsg-3build1
no fix listed
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
diygod/rsshub:latest22845ada2f14
tar@1.35+dfsg-3.1
no fix listed
1
diygod/rsshub:2025-11-097a6312cac0d5
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
djjudas21/alertify:0.1.0ba22be670c37
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
dniel/api-posts:master45a667852f2a
tar@1.29b-2ubuntu0.1
no fix listed
1
dobtc/bitcoin:25.1a870f7cb1105
tar@1.34+dfsg-1.2
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.