StackRadar

CVE-2026-18477

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,481
of 17,828 indexed, latest versions
Container images
2,473
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,481 of 17,828 indexed charts deploy, on 2,473 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,473
OSV records
DEBIAN-CVE-2026-18477UBUNTU-CVE-2026-18477ECHO-b8d2-238f-d46b

Charts affected

2,481 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,473 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hiboxsystems/marge-bot:0.16.0b59f01bc0418
tar@1.35+dfsg-3.1
no fix listed
1
hiboxsystems/marge-bot:0.14.0dcffb926e563
tar@1.34+dfsg-1.2
no fix listed
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
hivemq/hivemq-edge:2026.14d8250a233cea
tar@1.35+dfsg-3build1
no fix listed
1
hivemq/hivemq-operator:4.7.10241d6a8e1963
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
hivemq/hivemq-platform-operator:2.2.2a919f990141b
tar@1.35+dfsg-4ubuntu0.4
no fix listed
1
hivemq/hivemq-swarm:4.54.0f9746d5d70fa
tar@1.35+dfsg-3build1
no fix listed
1
hiversh/antigravity:0.1.45-microvm0e36d98402bc
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
hiversh/browser:0.1.45-microvmb5048c6342ce
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
hiversh/claude:0.1.45-microvm2fbf9f264498
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
hiversh/codex:0.1.45-microvm4f43130f51e5
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
hiversh/controller:0.1.45b0b85f8942c7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
hiversh/copilot:0.1.45-microvm50c07b84f298
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
hiversh/gateway:0.1.45839226cc6e41
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
hiversh/node:0.1.45-alpine-microvm836a37641941
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
hiversh/openclaw:0.1.45-microvm958b7ebb4eb4
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
hiversh/python:0.1.45-3.13-alpine-microvm63a5ae179a9f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
hjacobs/kube-janitor:23.7.0fbb303ed463c
tar@1.34+dfsg-1.2
no fix listed
1
hjacobs/kube-web-view:23.8.0431f1bf013d0
tar@1.34+dfsg-1.2
no fix listed
1
hmediade/printserver:latest481a552c8e1c
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
hmediade/printserver-init:latest7f005eb6c718
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
housewrecker/gaps:latestf417dd0a7547
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
huginn/huginn-single-process:4d17829cf6b15b004ad3f4be196303dca4944810c794eddc7b47
tar@1.29b-2ubuntu0.2
no fix listed
1
hugohg34/toposervice:0.0.2812a03b3f274
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
hyperglance/init:wildfly467ad8491bc3
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
hyperglance/init:postgres9fd5faf1fe80
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
hyperglance/init:apacheb2f8c6d52623
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
hyperglance/postgresql-v2:10.0.8a05d73bb30e7
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed
1
hyperledger/besu:latest6f3f21ce5333
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
tar@1.28-2.1ubuntu0.1
no fix listed
1
hyperledger/fabric-orderer:1.3.06ee1abcfd840
tar@1.28-2.1ubuntu0.1
no fix listed
1
hyperledger/fabric-peer:1.3.06756c7c48234
tar@1.28-2.1ubuntu0.1
no fix listed
1
ibmcom/ibm-workload-scheduler-agent-dynamic-dev:9.4.0.047e4dc1e27cdf
tar@1.28-2.1ubuntu0.1
no fix listed
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
tar@1.28-2.1ubuntu0.1
no fix listed
1
ibmcom/microclimate-theia:lateste17bdccc5030
tar@1.28-2.1ubuntu0.1
no fix listed
1
ibmcom/skydive:0.22.0395e60cc6e3d
tar@1.29b-2ubuntu0.1
no fix listed
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
tar@1.34+dfsg-1.2
no fix listed
1
ilum/streamlit-example:1.0.0ce5dcdeb22ba
tar@1.35+dfsg-3.1
no fix listed
1
improwised/proxysql:master-6b26e59-171765063828940522e8b7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
infiniflow/infinity:v0.7.0992c87a68612
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
infisical/infisical:latest:v0.165.602082bf13163
tar@1.35+dfsg-3.1
no fix listed
1
inseefrlab/shelly:cloudshell31f04ca7436b
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
instill/artifact-backend:b28766ac4a393e601ed
tar@1.35+dfsg-3.1
no fix listed
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
tar@1.35+dfsg-3.1
no fix listed
1
instill/model-backend:611f0f2e980125e5ba5
tar@1.35+dfsg-3.1
no fix listed
1
instructure/kinesalite:latest34400d82f28f
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
1
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
intel/multimodal-data-visualization-streaming:3.01a89327e499b
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
tar@1.34+dfsg-1.2
no fix listed
1
intel/trusted-certificate-issuer:0.5.0591a9db4a427
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.