StackRadar

CVE-2026-18477

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,541
of 17,828 indexed, latest versions
Container images
2,543
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,541 of 17,828 indexed charts deploy, on 2,543 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,543
OSV records
DEBIAN-CVE-2026-18477UBUNTU-CVE-2026-18477ECHO-b8d2-238f-d46b

Charts affected

2,541 by stars
ChartLatestAffected imagesRadar Score
penpotpenpotOfficialVerified publisher1.9.02 of 4See more

penpot penpot 1.9.0

2 of the 4 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
penpotapp/exporter:2.17.272a8061e8806
tar@1.35+dfsg-4ubuntu0.4
no fix listed
penpotapp/mcp:2.17.284f3f07ead11
tar@1.35+dfsg-4ubuntu0.4
no fix listed

Open the chart page →

4,646
signozsignoz0.142.11 of 5See more

signoz signoz 0.142.1

1 of the 5 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
signoz/signoz-otel-collector:v0.144.1034ecb436b687
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,632
weblateweblateOfficialVerified publisher0.5.383 of 3See more

weblate weblate 0.5.38

3 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/redis:latest5927ff3702df
tar@1.34+dfsg-1.2+deb12u1
no fix listed
weblate/weblate:2026.9.1.2f0be5b122b38
tar@1.35+dfsg-4ubuntu0.4
no fix listed

Open the chart page →

6,707
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,849
postgresgroundhog2k1.6.81 of 1See more

postgres groundhog2k 1.6.8

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/postgres:18.686c951e05bf5
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,268
emqxemqx-operator5.8.91 of 1See more

emqx emqx-operator 5.8.9

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
emqx/emqx:5.8.935b46f7aa7a0
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,752
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

4,840
mariadbcloudpirates-mariadbVerified publisher0.16.151 of 1See more

mariadb cloudpirates-mariadb 0.16.15

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/mariadb:13.0.2d4fdec0510ad
tar@1.35+dfsg-4ubuntu0.4
no fix listed

Open the chart page →

1,435
difydoubanVerified publisher0.10.03 of 6See more

dify douban 0.10.0

3 of the 6 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

74,142
dragonflydragonflyVerified publisher1.8.51 of 3See more

dragonfly dragonfly 1.8.5

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
dragonflyoss/client:v1.5.59fe2a1d6206f
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

4,187
secrets-store-csi-driversecret-store-csi-driver1.6.11 of 4See more

secrets-store-csi-driver secret-store-csi-driver 1.6.1

1 of the 4 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,821
mongodbcloudpirates-mongodbVerified publisher0.18.151 of 1See more

mongodb cloudpirates-mongodb 0.18.15

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/mongo:8.3.115d7043a4ffe0
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

958
code-servernicholaswildeVerified publisher1.1.11 of 1See more

code-server nicholaswilde 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/code-server:version-v3.11.1a385ba5cb161
tar@1.29b-2ubuntu0.2
no fix listed

Open the chart page →

16,393
akhqakhq0.28.01 of 1See more

akhq akhq 0.28.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
tchiotludo/akhq:0.28.0c2824dc2ae44
tar@1.35+dfsg-4ubuntu0.4
no fix listed

Open the chart page →

1,663
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

3,860
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,014
difydify-helmVerified publisher0.38.06 of 11See more

dify dify-helm 0.38.0

6 of the 11 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
langgenius/dify-api:1.16.1dcefa5f7c47c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
tar@1.35+dfsg-3build1
no fix listed
langgenius/dify-sandbox:0.2.15750e1111426e
tar@1.35+dfsg-3.1
no fix listed
library/nginx:latestabe47724e466
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

63,436
pyroscopegrafana2.3.11 of 3See more

pyroscope grafana 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

3,298
plantumlstevehipwellVerified publisher3.49.01 of 1See more

plantuml stevehipwell 3.49.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
plantuml/plantuml-server:jetty-v1.2026.85f6f99ec2fc1
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

2,087
rabbitmqgroundhog2k2.3.91 of 2See more

rabbitmq groundhog2k 2.3.9

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/rabbitmq:4.3.667bad329974a
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

848
stacks-blockchainhirosystemsVerified publisher2.2.21 of 1See more

stacks-blockchain hirosystems 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,418
ingresskongOfficialVerified publisher0.24.01 of 2See more

ingress kong 0.24.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/kong:3.912972ce1ab63
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

867
oktetooktetoOfficialVerified publisher0.0.0-2026-08-241 of 10See more

okteto okteto 0.0.0-2026-08-24

1 of the 10 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-243e56bdd1b90d
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

5,587
yourlsyourlsOfficialVerified publisher8.10.21 of 2See more

yourls yourls 8.10.2

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/yourls/yourls:1.10.67550ff86b15f
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,990
apisix-ingress-controllerapisix1.4.01 of 2See more

apisix-ingress-controller apisix 1.4.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,705
istiocloudposse1.1.02 of 8See more

istio cloudposse 1.1.0

2 of the 8 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
tar@1.28-2.1ubuntu0.1
no fix listed
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
tar@1.28-2.1ubuntu0.1
no fix listed

Open the chart page →

131,456
actualbudgetcommunity-chartsVerified publisher1.9.41 of 1See more

actualbudget community-charts 1.9.4

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
actualbudget/actual-server:26.9.0552beab3dec8
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,137
concourseconcourseVerified publisher20.3.01 of 2See more

concourse concourse 20.3.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/postgres:17f4c66b820c6f
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,670
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
tar@1.29b-2ubuntu0.2
no fix listed

Open the chart page →

4,212
openprojectopenproject-helm-chartsOfficialVerified publisher13.12.04 of 5See more

openproject openproject-helm-charts 13.12.0

4 of the 5 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
tar@1.34+dfsg-1.2+deb12u1
no fix listed
library/postgres:16f1c3376c26f2
tar@1.35+dfsg-3.1
no fix listed
openproject/hocuspocus:release-338001b288dc1359dfb5
tar@1.34+dfsg-1.2+deb12u1
no fix listed
openproject/openproject:17.8.0-slim48952034215d
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

20,190
sftpgosftpgoOfficialVerified publisher0.48.01 of 1See more

sftpgo sftpgo 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.59011fe608d33
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,250
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

11,588
lemmyananace-chartsVerified publisher0.6.152 of 5See more

lemmy ananace-charts 0.6.15

2 of the 5 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
dessalines/lemmy:0.19.2079e9f02c286c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
dessalines/lemmy-ui:0.19.20ee4c620d8e93
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

7,262
zabbixcetic3.1.35 of 5See more

zabbix cetic 3.1.3

5 of the 5 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/postgres:14816cf7d06ec3
tar@1.35+dfsg-3.1
no fix listed
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
tar@1.34+dfsg-1build3
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
tar@1.34+dfsg-1build3
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
tar@1.34+dfsg-1build3
no fix listed
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
tar@1.34+dfsg-1build3
no fix listed

Open the chart page →

33,799
csi-driver-smbcsi-driver-smbVerified publisher1.20.31 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

1 of the 6 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,027
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

4,356
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

6,622
stacks-blockchain-apihirosystemsVerified publisher6.5.12 of 5See more

stacks-blockchain-api hirosystems 6.5.1

2 of the 5 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
tar@1.34+dfsg-1.2+deb12u1
no fix listed
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,884
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

2,430
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

6,162
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed

Open the chart page →

13,005
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

3,089
factorio-server-chartsfactorio-server-chartsVerified publisher2.5.21 of 1See more

factorio-server-charts factorio-server-charts 2.5.2

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
factoriotools/factorio:latest18c07a80cacc
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,402
netbirdjaconiVerified publisher0.15.12 of 4See more

netbird jaconi 0.15.1

2 of the 4 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/golang:latest3680233e3204
tar@1.35+dfsg-3.1
no fix listed
netbirdio/management:0.45.10c9994b393ea
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

8,167
litellm-helmlitellm1.102.01 of 2See more

litellm-helm litellm 1.102.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,102
localstacklocalstack0.7.11 of 1See more

localstack localstack 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
localstack/localstack:latest4abc29e923e5
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,195
gotenbergmaikumoriVerified publisher1.25.01 of 1See more

gotenberg maikumori 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8.36.087c16b9f3642
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

10,277
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

5,527
oneuptimeoneuptimeOfficialVerified publisher14.0.14 of 7See more

oneuptime oneuptime 14.0.1

4 of the 7 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.7a50b4a1579a0
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed
library/postgres:latest86c951e05bf5
tar@1.35+dfsg-3.1
no fix listed
oneuptime/probe:releaseff73ab57aa59
tar@1.34+dfsg-1.2+deb12u1
no fix listed
oneuptime/runner:release8301892d9c17
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

11,243
openclawopenclaw-helmVerified publisher1.5.402 of 2See more

openclaw openclaw-helm 1.5.40

2 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

5,759

Container images carrying it

2,543 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/maxiv/pieeat:0.9.3099715479210
tar@1.35+dfsg-3.1
no fix listed
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/mittwald/kube-mail:latest04f1099241fc
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
tar@1.28-2.1ubuntu0.1
no fix listed
1
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
tar@1.35+dfsg-3.1
no fix listed
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
tar@1.35+dfsg-3build1
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
tar@1.28-2.1ubuntu0.1
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
tar@1.35+dfsg-3.1
no fix listed
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
tar@1.35+dfsg-4ubuntu0.4
no fix listed
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
tar@1.34+dfsg-1.2
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
tar@1.35+dfsg-4ubuntu0.4
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.01c38ad710b0c
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.0704cd68566af
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.0696d798a5c85
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabdc1a8972c640
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.26645e014f75d
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3aca1bb3d5b7e
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
tar@1.35+dfsg-3.1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.