CVE-2026-18477
MediumAdvisory
Published 3 Aug 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 4.4
- base score, highest
- EPSS
- 0.001
- 0th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,453
- of 17,803 indexed, latest versions
- Container images
- 2,429
- deployed by those charts
- Fix available
- 1 of 1
- affected package
The matching OSV records carry no description.
Carried by container images the latest versions of 2,453 of 17,803 indexed charts deploy, on 2,429 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| tardeb | 1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more | 1.35+dfsg-3.1+e5 | 2,429 |
Charts affected
2,453 by stars
Container images carrying it
2,429 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| public.ecr.aws/ | f4925b15ce94 | tar | no fix listed | 1 |
| public.ecr.aws/ | bda08753668d | tar | no fix listed | 1 |
| public.ecr.aws/ | 59c7e728fb3a | tar | no fix listed | 1 |
| public.ecr.aws/ | fea799d4fb2f | tar | no fix listed | 1 |
| public.ecr.aws/ | ee9d973e3952 | tar | no fix listed | 1 |
| public.ecr.aws/ | b7d7910c0bb0 | tar | 1.35+dfsg-3.1+e5 | 1 |
| public.ecr.aws/ | af8cea3b8538 | tar | 1.35+dfsg-3.1+e5 | 1 |
| public.ecr.aws/ | b1493760c716 | tar | no fix listed | 1 |
| public.ecr.aws/ | 34823c8abe00 | tar | no fix listed | 1 |
| public.ecr.aws/ | 5cd62142d6ed | tar | no fix listed | 1 |
| public.ecr.aws/ | f8fb4eea4071 | tar | no fix listed | 1 |
| public.ecr.aws/ | 046ef5c9ed50 | tar | no fix listed | 1 |
| public.ecr.aws/ | dc5a516c2333 | tar | no fix listed | 1 |
| public.ecr.aws/ | 36d051110158 | tar | no fix listed | 1 |
| public.ecr.aws/ | 9e14a72b066d | tar | no fix listed | 1 |
| public.ecr.aws/ | f7567ce3419d | tar | no fix listed | 1 |
| public.ecr.aws/ | 86380a01587d | tar | no fix listed | 1 |
| public.ecr.aws/ | efcecf98b912 | tar | no fix listed | 1 |
| public.ecr.aws/ | 573779e57fae | tar | no fix listed | 1 |
| public.ecr.aws/ | f74851ce31f5 | tar | no fix listed | 1 |
| quay.io/ | 70fd7c00418d | tar | no fix listed | 1 |
| quay.io/ | 578934444f04 | tar | no fix listed | 1 |
| quay.io/ | 0deb1a1c9176 | tar | no fix listed | 1 |
| quay.io/ | 5b6701d8fb31 | tar | no fix listed | 1 |
| quay.io/ | 95b5cf7ba6fe | tar | no fix listed | 1 |
| quay.io/ | a36ab0c0860c | tar | no fix listed | 1 |
| quay.io/ | acaf37352569 | tar | no fix listed | 1 |
| quay.io/ | daf2e7650d61 | tar | no fix listed | 1 |
| quay.io/ | 351d6685dc6f | tar | no fix listed | 1 |
| quay.io/ | 858f807ea4e2 | tar | no fix listed | 1 |
| quay.io/ | cdcfab5b4466 | tar | no fix listed | 1 |
| quay.io/ | 60031f396695 | tar | no fix listed | 1 |
| quay.io/ | 7932d656b63f | tar | no fix listed | 1 |
| quay.io/ | a9f835d1b241 | tar | no fix listed | 1 |
| quay.io/ | 935f97598255 | tar | no fix listed | 1 |
| quay.io/ | d9f0bec83ef0 | tar | no fix listed | 1 |
| quay.io/ | a2d3a4c67b0f | tar | no fix listed | 1 |
| quay.io/ | 60950ef63764 | tar | no fix listed | 1 |
| quay.io/ | 93889c3d8a34 | tar | no fix listed | 1 |
| quay.io/ | 2c324c9789f5 | tar | no fix listed | 1 |
| quay.io/ | d78cd113b2bc | tar | no fix listed | 1 |
| quay.io/ | b705e0cbe171 | tar | 1.35+dfsg-3.1+e5 | 1 |
| quay.io/ | 7bba7083dfa0 | tar | no fix listed | 1 |
| quay.io/ | 108fbb01c3fe | tar | no fix listed | 1 |
| quay.io/ | 113e372cf71b | tar | no fix listed | 1 |
| quay.io/ | 92f883d09270 | tar | no fix listed | 1 |
| quay.io/ | 65e1b09fc8c9 | tar | no fix listed | 1 |
| quay.io/ | 099715479210 | tar | no fix listed | 1 |
| quay.io/ | 2169032c5840 | tar | no fix listed | 1 |
| quay.io/ | 04f1099241fc | tar | no fix listed | 1 |