StackRadar

CVE-2026-18477

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,453
of 17,803 indexed, latest versions
Container images
2,429
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,453 of 17,803 indexed charts deploy, on 2,429 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,429
OSV records
DEBIAN-CVE-2026-18477UBUNTU-CVE-2026-18477ECHO-b8d2-238f-d46b

Charts affected

2,453 by stars
ChartLatestAffected imagesRadar Score
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,879
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
tar@1.29b-2ubuntu0.2
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed

Open the chart page →

9,280
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed

Open the chart page →

7,949

Container images carrying it

2,429 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
jodogne/orthanc-plugins:latest6ff510aa29c2
tar@1.35+dfsg-3.1
no fix listed
1
johly/airtrail:v3.11.19f702b91e0e7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
joplin/server:latest3f7b852959aa
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
josh5/unmanic:0.2.64d49c4816260
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
journeyapps/powersync-service:latestbf46f66e5dcc
tar@1.35+dfsg-3.1
no fix listed
1
jpgouin/openldap:2.6.9-fixbfdd0088c776
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
juicedata/juicefs-csi-driver:v0.33.0f918e7331c05
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
tar@1.35+dfsg-3build1
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
tar@1.30+dfsg-7
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
tar@1.30+dfsg-7
no fix listed
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
tar@1.35+dfsg-3build1
no fix listed
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kayrosuno/kping:latestf3bd44b29b0d
tar@1.35+dfsg-3build1
no fix listed
1
kennethreitz/httpbin:latest599fe5e50731
tar@1.29b-2
no fix listed
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
kimai/kimai2:2.67.03084f1e5ecdc
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
tar@1.35+dfsg-3.1
no fix listed
1
kixote/typemill4e9dff179519
tar@1.35+dfsg-3.1
no fix listed
1
kixote/typemill628f79a08cc7
tar@1.35+dfsg-3.1
no fix listed
1
knspar/phronetis:0.1.4609499d2dc91a
tar@1.35+dfsg-3build1
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kong/httpbin:latesta6ac46531193
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kong/kong:3.9.16addf50e6bd8
tar@1.35+dfsg-3build1
no fix listed
1
kong/kong-ai-gateway:2.0.3367ed5985b76
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
1
krontechnology/aapm-service:1.1.39dd602db8baa
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kserve/models-web-app:v0.13.073486345a602
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kubeflownotebookswg/jupyter-web-app:v1.9.2afb52057c997
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kubeflownotebookswg/tensorboards-web-app:v1.9.277f07f52a84a
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kubeflownotebookswg/volumes-web-app:v1.9.2f63c3e550af3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kubegems/redis:7.2.5-debian-12-r2870ee3a77add
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
tar@1.29b-2ubuntu0.1
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
tar@1.35+dfsg-3build1
no fix listed
1
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
kubeshop/testkube-minio:2025.10d8e1af6aca99
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kubesphere/examples-bookinfo-reviews-v2:1.13.06d93129beb32
tar@1.28-2.1ubuntu0.1
no fix listed
1
kudobuilder/controller:v0.9.069072d979708
tar@1.29b-2ubuntu0.1
no fix listed
1
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kuzwolka/aws9:main1ad759b961b1
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.