StackRadar

CVE-2026-18477

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,481
of 17,828 indexed, latest versions
Container images
2,473
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,481 of 17,828 indexed charts deploy, on 2,473 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,473
OSV records
DEBIAN-CVE-2026-18477UBUNTU-CVE-2026-18477ECHO-b8d2-238f-d46b

Charts affected

2,481 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,473 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
erigontech/erigon:v2.61.288706754b627
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
erigontech/erigon:latest8cd3fbcbb35d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
erlangsolutions/mongooseim:6.6.0cc5bf032931f
tar@1.35+dfsg-3build1
no fix listed
1
erudikaltd/para:latest_stable235e0bc53da2
tar@1.35+dfsg-4ubuntu0.4
no fix listed
1
escaping/core-keeper-dedicated:latest87fa79255962
tar@1.35+dfsg-3.1
no fix listed
1
esphome/esphome:2026.7.44866347cb5b4
tar@1.35+dfsg-3.1
no fix listed
1
esphome/esphome:2026.9.09959730a04c7
tar@1.35+dfsg-3.1
no fix listed
1
esphome/esphome:2024.3.09ab8cc88b28c
tar@1.34+dfsg-1.2
no fix listed
1
esphome/esphome:2024.12.2b2c6322700ac
tar@1.34+dfsg-1.2
no fix listed
1
esphome/esphome:2025.3.0def8b6e4f517
tar@1.34+dfsg-1.2
no fix listed
1
espocrm/espocrm:9.3.101b5a24504ed9
tar@1.35+dfsg-3.1
no fix listed
1
ethanbergstrom/duoauthproxy:5.5.0345c2a46c103
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
tar@1.28-2.1ubuntu0.1
no fix listed
1
ethersphere/bee:2.2.0a884fd84b72f
tar@1.34+dfsg-1.2
no fix listed
1
ethersphere/beekeeper:lateste3bc0da9ffde
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ethpandaops/assertoor:latest1efa2fba6711
tar@1.35+dfsg-3.1
no fix listed
1
ethpandaops/buildoor:mainb3dc726f8ba5
tar@1.35+dfsg-3.1
no fix listed
1
ethpandaops/dora:mastere7c0ed360365
tar@1.35+dfsg-3.1
no fix listed
1
ethpandaops/eleel:mainb8f1b707aee0
tar@1.35+dfsg-3build1
no fix listed
1
ethpandaops/forky:debian-latestc937f4ba737c
tar@1.35+dfsg-3.1
no fix listed
1
ethpandaops/observoor:masterc7e5055defcb
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
ethpandaops/rpc-snooper:latestc0b30fcf64bc
tar@1.35+dfsg-3.1
no fix listed
1
factoriotools/factorio:latest18c07a80cacc
tar@1.35+dfsg-3.1
no fix listed
1
factoriotools/factorio:stable4ec5fea2e06b
tar@1.35+dfsg-3.1
no fix listed
1
factoriotools/factorio:2.0.67-rootlessf7909f7361d6
tar@1.35+dfsg-3.1
no fix listed
1
falcosecurity/event-generator:latest932956d86c99
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
federid/webhook:0.1.0fbfb7c6510a7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
felipecs8/app-db-connection-test:v129e06c9c6385
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
filegator/filegator:latest34bf565a11a4
tar@1.35+dfsg-3.1
no fix listed
1
firefart/requesttracker:5.0.40d6249906d8c
tar@1.34+dfsg-1.2
no fix listed
1
fireflyiii/core:version-6.6.6ae69fdd95cde
tar@1.35+dfsg-3.1
no fix listed
1
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
flanksource/apm-hub:v0.0.471dacc3195bf9
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
flanksource/batch-runner:v1.0.44689687a7cf95
tar@1.35+dfsg-3build1
no fix listed
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
flanksource/incident-manager-ui:v1.4.319953948a194c9
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
flashcatcloud/nightingale:8.5.1421acb36181b
tar@1.35+dfsg-3.1
no fix listed
1
flashcatcloud/nightingale:8.0.0-beta.11ea1b0aaabe09
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
fluent/fluent-bit:4.0-debuge76397ef3983
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
fluent/fluentd-kubernetes-daemonset:v1.19.3-debian-elasticsearch7-1.1de9cf5f1127a
tar@1.35+dfsg-3.1
no fix listed
1
fluent/fluentd-kubernetes-daemonset:v1-debian-graylogfda93f768f98
tar@1.35+dfsg-3.1
no fix listed
1
flyway/flyway:9.1545b5d7cdc75a
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
1
fnzv/dump1090:latestb3079b95c336
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
foldingathome/fah-gpu:latest5ef7742d1eb4
tar@1.29b-2ubuntu0.2
no fix listed
1
folioci/mod-z3950:latest2493041ce880
tar@1.35+dfsg-3.1
no fix listed
1
fosrl/pangolin:latest83a55f933b4d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
frankescobar/allure-docker-service:2.27.00815040339a9
tar@1.29b-2ubuntu0.1
no fix listed
1
frankescobar/allure-docker-service:2.35.14154286c0209
tar@1.35+dfsg-3build1
no fix listed
1
frankescobar/allure-docker-service:2.21.08a4d7e9308de
tar@1.29b-2ubuntu0.1
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.