StackRadar

CVE-2026-18477

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,481
of 17,828 indexed, latest versions
Container images
2,473
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,481 of 17,828 indexed charts deploy, on 2,473 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,473
OSV records
DEBIAN-CVE-2026-18477UBUNTU-CVE-2026-18477ECHO-b8d2-238f-d46b

Charts affected

2,481 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,473 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
docmost/docmost:0.96.0b56947fcfd08
tar@1.35+dfsg-3.1
no fix listed
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
tar@1.35+dfsg-3.1
no fix listed
1
dolibarr/dolibarr:24.0.069ec52e3b7ef
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
domainmod/domainmod:4.23.04017bfe4c597
tar@1.34+dfsg-1.2
no fix listed
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
1
dragonflyoss/client:v1.5.59fe2a1d6206f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
dremio/dremio-oss:24.1.080ed2e3b7c43
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
drorivry4/rego:lateste035d49b15ca
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
drpcorg/dshackle:0.54.08858fae1859d
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
drumsergio/genieacs:1.2.16.028244054e1bf
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
dserio83/velero-api:0.3.16b3d9115fee2
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
dserio83/velero-watchdog:0.1.8d5deae589229
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
duck1123/cert-downloader:latest0e29f19fa67c
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
duck1123/lnd-fileserver:latest9d6fb247b714
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
dzikoysk/reposilite:3.5.264128c2d7a6ba
tar@1.35+dfsg-3build1
no fix listed
1
dzikoysk/reposilite:3.6.390de4c8e6c0e
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
tar@1.35+dfsg-3.1
no fix listed
1
eclipseaerios/hlo-allocator:v3.0.03cc1d94cfe96
tar@1.35+dfsg-3.1
no fix listed
1
eclipseaerios/hlo-data-aggregator:v3.0.0b433c2b9f5dc
tar@1.35+dfsg-3.1
no fix listed
1
eclipseaerios/hlo-deployment-engine:v3.0.0d582d39208c7
tar@1.35+dfsg-3.1
no fix listed
1
eclipseaerios/hlo-fe-engine:v3.0.08ed2df4ca692
tar@1.35+dfsg-3.1
no fix listed
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
tar@1.35+dfsg-3.1
no fix listed
1
eclipseaerios/self-awareness-hardware-info:1.4.434b72f45b46a
tar@1.35+dfsg-3.1
no fix listed
1
eclipseaerios/self-orchestrator:1.2.08b123bec5679
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
eclipseaerios/trust-manager:1.0.0f55442e2c0ed
tar@1.35+dfsg-3.1
no fix listed
1
elastic/apm-server:7.17.6c7a1c63257d0
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
elastictranscoder/media:627e21dc963ab3858c6b
tar@1.29b-2ubuntu0.1
no fix listed
1
elastictranscoder/media-storage:f6d861a026208b8c2359
tar@1.29b-2ubuntu0.1
no fix listed
1
elastictranscoder/transcoder:627e21dcb4a0327029e6
tar@1.29b-2ubuntu0.1
no fix listed
1
elastictranscoder/transcoder-handler:627e21dc5b75d19e2733
tar@1.29b-2ubuntu0.1
no fix listed
1
elastiflow/flow-collector:7.26.0fee67842e16b
tar@1.35+dfsg-3build1
no fix listed
1
electriccoinco/lightwalletd:v0.5.42ae3a551e111
tar@1.35+dfsg-3.1
no fix listed
1
empathyco/elasticsearch:7.17.2-memlock03e724e41eeb
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
emqx/ecp-ui:2.5.1e33e9816f147
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
emqx/emqx:5.8.935b46f7aa7a0
tar@1.35+dfsg-3.1
no fix listed
1
emqx/emqx-enterprise:6.3.15ecbf93d04e3
tar@1.35+dfsg-3.1+dhi1
no fix listed
1
enclavenetworks/enclave:latest0a99759300d1
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
1
engrmth/bnkr:2.1.06d8464e6f0e8
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
enix/san-iscsi-csi:v4.0.2f963da81ecf7
tar@1.29b-2ubuntu0.2
no fix listed
1
envoyproxy/envoy:v1.30.92956bd9de830
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
envoyproxy/envoy:v1.38.4447f857a0146
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed
1
envoyproxy/envoy:v1.33.056da5afd7df3
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
envoyproxy/envoy:v1.31-latestcaa5b411be16
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
envoyproxy/envoy:v1.34-latestcfc0678bc03c
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
envoyproxy/envoy:v1.30.1e596fda6a0ce
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
envoyproxy/envoy:v1.18.2e8b37c1d7578
tar@1.29b-2ubuntu0.2
no fix listed
1
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
tar@1.29b-2ubuntu0.3
no fix listed
1
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
tar@1.35+dfsg-3.1
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.