StackRadar

CVE-2026-18477

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,450
of 17,805 indexed, latest versions
Container images
2,405
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,450 of 17,805 indexed charts deploy, on 2,405 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,405
OSV records
DEBIAN-CVE-2026-18477UBUNTU-CVE-2026-18477ECHO-b8d2-238f-d46b

Charts affected

2,450 by stars
ChartLatestAffected imagesRadar Score
web-checkrm3lVerified publisher0.1.01 of 1See more

web-check rm3l 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/lissy93/web-check:latesta4e021c0f6a9
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

9,541
pagesroccohiggins-pages1.0.02 of 3See more

pages roccohiggins-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
tar@1.29b-2ubuntu0.1
no fix listed

Open the chart page →

20,261
matrix-stackrock8sVerified publisher0.8.11 of 7See more

matrix-stack rock8s 0.8.1

1 of the 7 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.127.1c3c4a9de2a0b
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

9,498
reviewboardrock8sVerified publisher0.0.12 of 3See more

reviewboard rock8s 0.0.1

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
beanbag/reviewboard:latest6b840f546e1c
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed
library/nginx:latest05b8cb60c354
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

6,226
rocketchat-voiprocketchat-server0.1.01 of 1See more

rocketchat-voip rocketchat-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
rocketchat/freeswitch:stablecfba5c20a5cc
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,785
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

9,743
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
tar@1.34+dfsg-1build3
no fix listed

Open the chart page →

13,159
calertromholdings0.0.11 of 1See more

calert romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed

Open the chart page →

4,704
devtron-enterpriseromholdings48.0.08 of 28See more

devtron-enterprise romholdings 48.0.0

8 of the 28 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
tar@1.35+dfsg-3build1
no fix listed
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
tar@1.35+dfsg-3build1
no fix listed
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
tar@1.35+dfsg-3build1
no fix listed
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
tar@1.34+dfsg-1.2
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
tar@1.28-2.1ubuntu0.2
no fix listed
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
tar@1.35+dfsg-3build1
no fix listed
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@1.34+dfsg-1.2+deb12u1
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

69,552
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed

Open the chart page →

4,983
devtron-operatorromholdings0.23.35 of 11See more

devtron-operator romholdings 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
tar@1.35+dfsg-3build1
no fix listed
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
tar@1.34+dfsg-1.2
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
tar@1.35+dfsg-3build1
no fix listed
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
tar@1.35+dfsg-3build1
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

33,352
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed

Open the chart page →

11,990
migration-incluster-cdromholdings0.10.01 of 1See more

migration-incluster-cd romholdings 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,947
rommromm-helm-chartVerified publisher1.5.51 of 3See more

romm romm-helm-chart 1.5.5

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/mariadb:112439dcd7d140
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

3,441
pagesronan-pages1.0.02 of 3See more

pages ronan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
tar@1.29b-2ubuntu0.1
no fix listed

Open the chart page →

20,261
endeavorrotationalVerified publisher1.3.12 of 2See more

endeavor rotational 1.3.1

2 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
rotationalio/endeavor:1.3.0ac566baddc06
tar@1.34+dfsg-1.2+deb12u1
no fix listed
rotationalio/quarterdeck:0.16.00e7ad3a031dc
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,291
genoarotationalVerified publisher1.4.01 of 1See more

genoa rotational 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
rotationalio/genoa:1.2.03ab583519215
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,015
honurotationalVerified publisher0.5.31 of 1See more

honu rotational 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
rotationalio/honu:0.5.069fd30c2e31c
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,206
imgtagrotationalVerified publisher0.2.01 of 1See more

imgtag rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,355
quarterdeckrotationalVerified publisher0.16.01 of 1See more

quarterdeck rotational 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
rotationalio/quarterdeck:0.16.00e7ad3a031dc
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,187
routehub-serverroutehub-helm1.0.12 of 3See more

routehub-server routehub-helm 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
library/postgres:latest4ef4dbc939d6
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

7,002
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,566
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

4,772
prepull-daemonsetrstudioVerified publisher0.0.51 of 2See more

prepull-daemonset rstudio 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/ubuntu:bionic152dc042452c
tar@1.29b-2ubuntu0.4
no fix listed

Open the chart page →

1,732
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed

Open the chart page →

7,759
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

10,680
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

27,754
jellyfinrubxkubeVerified publisher1.3.11 of 1See more

jellyfin rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,658
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,500
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
tar@1.35+dfsg-4ubuntu0.4
no fix listed

Open the chart page →

29,969
linkdingrubxkubeVerified publisher1.2.41 of 1See more

linkding rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.47.0e35cb50e0581
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,088
simple-coffeerubxkubeVerified publisher0.1.01 of 1See more

simple-coffee rubxkube 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,573
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

6,296
suwayomirubxkubeVerified publisher0.1.21 of 1See more

suwayomi rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

1,677
trmnl-serverrubxkubeVerified publisher0.1.01 of 2See more

trmnl-server rubxkube 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/python:3.14-slimcad9a2c87176
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,950
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

30,706
vaultwardenrubxkubeVerified publisher1.2.41 of 1See more

vaultwarden rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,785
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:latestb0652af9c8d0
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,463
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,818
rybbitrybbit-helm1.3.01 of 7See more

rybbit rybbit-helm 1.3.0

1 of the 7 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
valkey/valkey:9.1.164e361b630ec
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

5,903
nadekobotryuunosukeds30.1.22 of 2See more

nadekobot ryuunosukeds3 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
tar@1.35+dfsg-4ubuntu0.4
no fix listed
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed

Open the chart page →

8,790
orbitalryuunosukeds30.2.01 of 1See more

orbital ryuunosukeds3 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ryuunosukeds3/orbital:latest0879f7261b10
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,699
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

9,763
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed

Open the chart page →

7,478
test-helm-app1saam-helm-test0.1.01 of 1See more

test-helm-app1 saam-helm-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
hamidyousefi93/saam-test:latestc34f071f6ed0
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

3,932
hivechart-1sabryp3-charts0.2.01 of 2See more

hivechart-1 sabryp3-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
valkey/valkey:latestc123e3715db6
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

854
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,631
safe-stacksafe-global0.1.03 of 9See more

safe-stack safe-global 0.1.0

3 of the 9 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
tar@1.34+dfsg-1.2
no fix listed
safeglobal/safe-config-service:latest09a5e495c219
tar@1.35+dfsg-3.1
no fix listed
safeglobal/safe-transaction-service:latest80db836cc5d5
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

19,777
safe-transaction-servicesafe-global0.1.02 of 6See more

safe-transaction-service safe-global 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
tar@1.34+dfsg-1.2
no fix listed
safeglobal/safe-transaction-service:latest80db836cc5d5
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

16,779
sagawisesagawiseVerified publisher0.1.01 of 3See more

sagawise sagawise 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
venturenox/redis:latest83b471c193ba
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

4,383

Container images carrying it

2,405 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.