StackRadar

CVE-2026-18477

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,481
of 17,828 indexed, latest versions
Container images
2,473
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,481 of 17,828 indexed charts deploy, on 2,473 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,473
OSV records
DEBIAN-CVE-2026-18477UBUNTU-CVE-2026-18477ECHO-b8d2-238f-d46b

Charts affected

2,481 by stars
ChartLatestAffected imagesRadar Score
ms-licenses-grpccodedesignplus-chartsVerified publisher0.0.241 of 1See more

ms-licenses-grpc codedesignplus-charts 0.0.24

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
codedesignplus/ms-licenses-grpc:latest794a9b8cca1b
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,136
ms-modules-grpccodedesignplus-chartsVerified publisher0.0.241 of 1See more

ms-modules-grpc codedesignplus-charts 0.0.24

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
codedesignplus/ms-modules-grpc:latest95b620b601d9
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,136
codehubcodehubVerified publisher6.2.183 of 5See more

codehub codehub 6.2.18

3 of the 5 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/postgresql:latest42a8200d3597
tar@1.34+dfsg-1.2+deb12u1
no fix listed
jupyterhub/jupyterhub:5.4.63974ba945e65
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

13,273
cohdicohdi0.2.21 of 3See more

cohdi cohdi 0.2.2

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/cohdi/composable-dra-driver:v0.2.28c05f7366981
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,854
web3-prometheus-exportercoinpri-helm-chartsVerified publisher0.1.31 of 1See more

web3-prometheus-exporter coinpri-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
guillh/web3-prometheus-exporter:0.3.04fb99dbc32b2
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,445
genericcolearendt0.2.71 of 1See more

generic colearendt 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,887
loki-stackcommon-chartsVerified publisher1.0.31 of 12See more

loki-stack common-charts 1.0.3

1 of the 12 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
grafana/alloy:v1.18.0491b0578c049
tar@1.35+dfsg-3ubuntu0.3
no fix listed

Open the chart page →

5,515
opencloudcommunity-opencloud3.0.01 of 11See more

opencloud community-opencloud 3.0.0

1 of the 11 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
apache/tika:latest-full80072bb73dd3
tar@1.35+dfsg-4ubuntu0.4
no fix listed

Open the chart page →

3,864
sumo-besu-genesisconsensys0.1.751 of 1See more

sumo-besu-genesis consensys 0.1.75

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed

Open the chart page →

8,073
sumo-besu-nodeconsensys0.1.751 of 4See more

sumo-besu-node consensys 0.1.75

1 of the 4 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
hyperledger/besu:22.4-openjdk-latesta674d35eec9a
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed

Open the chart page →

8,073
filesystem-exportercontainerooVerified publisher1.5.21 of 1See more

filesystem-exporter containeroo 1.5.2

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/containeroo/filesystem-exporter:v1.5.2a66121e16d4e
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,213
ConvertServiceWeb-Helm-Buildconvertserviceweb-helm-build0.1.12 of 7See more

ConvertServiceWeb-Helm-Build convertserviceweb-helm-build 0.1.1

2 of the 7 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/rabbitmq:3.11.5-management1b0f675d2f24
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
library/redis:latest298e5b3bc566
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

10,172
cortezacorteza1.1.02 of 3See more

corteza corteza 1.1.0

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.4cb9f200de5d2
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

8,514
corteza-all-in-onecorteza0.1.01 of 2See more

corteza-all-in-one corteza 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
cortezaproject/corteza:2024.9.08eb7a26605c9
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed

Open the chart page →

4,711
cosanetcosanet1.0.01 of 1See more

cosanet cosanet 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/cosanet/cosanet:1.0.098cb5d9fa215
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,255
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

57,919
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

14,677
cospacecospace0.0.341 of 3See more

cospace cospace 0.0.34

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/twigex/cospace:lateste5ecfd607e42
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,317
grafana-mcpcowboysysopVerified publisher2.0.01 of 1See more

grafana-mcp cowboysysop 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
mcp/grafana:latest9362bcf6aa0e
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

1,177
mariadbcowboysysopVerified publisher20.4.21 of 1See more

mariadb cowboysysop 20.4.2

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,014
mongodbcowboysysopVerified publisher15.1.51 of 1See more

mongodb cowboysysop 15.1.5

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:7.0.8-debian-12-r23163c3842bfd
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

6,799
postgresqlcowboysysopVerified publisher15.5.71 of 1See more

postgresql cowboysysop 15.5.7

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r14cc55da2fa366
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

4,850
qdrantcowboysysopVerified publisher3.0.01 of 1See more

qdrant cowboysysop 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.4.166ee661d5241
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

3,084
rediscowboysysopVerified publisher21.2.61 of 1See more

redis cowboysysop 21.2.6

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/redis:8.0.2-debian-12-r4cdc2efa9c306
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,681
logstream-leadercriblio4.20.01 of 1See more

logstream-leader criblio 4.20.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
cribl/cribl:4.20.0dddc9c0f2a52
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

887
logstream-mastercriblio2.9.91 of 1See more

logstream-master criblio 2.9.9

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
cribl/cribl:3.0.2762747cb6796
tar@1.29b-2ubuntu0.2
no fix listed

Open the chart page →

9,319
logstream-workergroupcriblio4.20.01 of 1See more

logstream-workergroup criblio 4.20.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
cribl/cribl:4.20.0dddc9c0f2a52
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

887
iam-zencryptexlabsVerified publisher0.12.231 of 4See more

iam-zen cryptexlabs 0.12.23

1 of the 4 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,866
pagescrypticcode-helmchart1.0.02 of 3See more

pages crypticcode-helmchart 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
tar@1.29b-2ubuntu0.1
no fix listed

Open the chart page →

20,287
csghubcsghubVerified publisher2.5.010 of 34See more

csghub csghub 2.5.0

10 of the 34 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/redis:7.4.1171da9275c5f3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
opencsghq/agenticflow:ee-v0.6.5-241cba9c366f1
tar@1.34+dfsg-1.2+deb12u1
no fix listed
opencsghq/csgbot:v0.6.9-ee7d0271e26521
tar@1.35+dfsg-3.1
no fix listed
opencsghq/csghub-portal:v2.5.0-ee1cb36b49151e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
opencsghq/csghub-server:v2.5.0-ee587046575c2c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
opencsghq/csghub-xnet:v2.5.0-ee86ea22f495c7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
tar@1.34+dfsg-1.2+deb12u1
no fix listed
opencsghq/gitlab-shell:v19.2.580a65ac370da
tar@1.34+dfsg-1.2+deb12u1
no fix listed
opencsghq/label-studio:v2.5.047e22aa71870
tar@1.35+dfsg-3.1
no fix listed
opencsghq/postgres:15.19b98600564e07
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

49,856
csgshipcsghubVerified publisher0.4.62 of 10See more

csgship csghub 0.4.6

2 of the 10 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/redis:7.4.1171da9275c5f3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
opencsghq/postgres:15.19b98600564e07
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

11,884
dataflowcsghubVerified publisher2.5.02 of 7See more

dataflow csghub 2.5.0

2 of the 7 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
opencsghq/label-studio:v2.5.047e22aa71870
tar@1.35+dfsg-3.1
no fix listed
opencsghq/postgres:15.19b98600564e07
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

6,941
rtcsic-charts0.1.11 of 5See more

rt csic-charts 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
firefart/requesttracker:5.0.40d6249906d8c
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

15,510
wazuhcsic-charts0.1.02 of 4See more

wazuh csic-charts 0.1.0

2 of the 4 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
wazuh/wazuh-manager:4.4.121994f40e0da
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed

Open the chart page →

14,010
cspconsolecspconsole1.3.114 of 5See more

cspconsole cspconsole 1.3.11

4 of the 5 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
cspconsole/config-provider:1.0.365524a26a6c23
tar@1.34+dfsg-1.2+deb12u1
no fix listed
cspconsole/csp-control-center:1.0.1046dda4a31bd6
tar@1.34+dfsg-1.2+deb12u1
no fix listed
cspconsole/report-collector:1.0.15839750248193b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
cspconsole/report-processor:1.0.279a2d8840bfdf
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

12,596
cypikcypik-app0.1.02 of 2See more

cypik cypik-app 0.1.0

2 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tar@1.35+dfsg-3.1
no fix listed
library/nginx:1.25a484819eb602
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,658
view-cadvisorcypik-helm-chart0.1.01 of 1See more

view-cadvisor cypik-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,887
irods-csi-drivercyverse0.12.01 of 4See more

irods-csi-driver cyverse 0.12.0

1 of the 4 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
cyverse/irods-csi-driver:v0.12.0aa69d105b292
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed

Open the chart page →

5,309
jupyterhubd4nVerified publisher3.3.71 of 7See more

jupyterhub d4n 3.3.7

1 of the 7 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
aristidetm/basic-notebook:3.6.5469dbc951224
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

16,726
nifi-registryd4nVerified publisher1.0.01 of 2See more

nifi-registry d4n 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed

Open the chart page →

5,501
nginx-chartdaeho12Verified publisher0.1.01 of 1See more

nginx-chart daeho12 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,593
dakeradakera-helmVerified publisher0.11.1072 of 3See more

dakera dakera-helm 0.11.107

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/dakera-ai/dakera:0.11.101af610992a416
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/dakera-ai/dakera-mcp:0.10.11a3d48418b14a
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,876
pagesdalston-pages1.0.02 of 3See more

pages dalston-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
tar@1.29b-2ubuntu0.1
no fix listed

Open the chart page →

20,287
pagesdaman-dell-kuber1.0.02 of 3See more

pages daman-dell-kuber 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
flyway/flyway:6.4.422d97ceb0c47
tar@1.29b-2ubuntu0.1
no fix listed

Open the chart page →

20,287
damap-chartdamapVerified publisher0.3.04 of 5See more

damap-chart damap 0.3.0

4 of the 5 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
gotenberg/gotenberg:8f29984bd1e22
tar@1.35+dfsg-3.1
no fix listed
library/postgres:16f1c3376c26f2
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/damap-org/damap-backend:5.0.0f3d0c7d35498
tar@1.35+dfsg-3build1
no fix listed
ghcr.io/damap-org/damap-frontend:5.0.1609f48af4efc
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

14,925
nvidia-gpu-exporterdanchevVerified publisher1.0.31 of 1See more

nvidia-gpu-exporter danchev 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/utkuozdemir/nvidia_gpu_exporter:1.5.0d75967a4dd72
tar@1.35+dfsg-4
no fix listed

Open the chart page →

1,250
dapr-agentsdapr-agents-devVerified publisher0.1.52 of 31See more

dapr-agents dapr-agents-dev 0.1.5

2 of the 31 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/redis:6.2e7b96daa9a18
tar@1.34+dfsg-1.2+deb12u1
no fix listed
mcp/grafana:latest9362bcf6aa0e
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

22,571
dara-chartsdara-charts0.1.01 of 2See more

dara-charts dara-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/postgres:16a3b7f434b2dc
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,595
helm-chart-testdasmeta0.1.41 of 1See more

helm-chart-test dasmeta 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/nginx:stable0aa2d81d65bc
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,887
mongodb-bi-connectordasmeta1.0.31 of 1See more

mongodb-bi-connector dasmeta 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
tar@1.29b-2ubuntu0.3
no fix listed

Open the chart page →

5,865

Container images carrying it

2,473 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

No deployed image carries CVE-2026-18477.

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.