StackRadar

CVE-2026-18477

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
0th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,541
of 17,828 indexed, latest versions
Container images
2,543
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,541 of 17,828 indexed charts deploy, on 2,543 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,543
OSV records
DEBIAN-CVE-2026-18477UBUNTU-CVE-2026-18477ECHO-b8d2-238f-d46b

Charts affected

2,541 by stars
ChartLatestAffected imagesRadar Score
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,012
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed

Open the chart page →

4,339
penpotcodechemVerified publisher1.0.102 of 3See more

penpot codechem 1.0.10

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
penpotapp/backend:1.16.0-betae978e871be07
tar@1.34+dfsg-1build3
no fix listed
penpotapp/exporter:1.16.0-betafa7086ad92b1
tar@1.34+dfsg-1build3
no fix listed

Open the chart page →

28,655
connaisseurconnaisseurVerified publisher2.13.01 of 2See more

connaisseur connaisseur 2.13.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

2,951
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

36,042
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
tar@1.35+dfsg-3build1
no fix listed
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
tar@1.34+dfsg-1.2
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
tar@1.35+dfsg-3build1
no fix listed
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
tar@1.35+dfsg-3build1
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

33,471
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

3,860
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

5,506
grayloggroundhog2k0.13.101 of 1See more

graylog groundhog2k 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
graylog/graylog:7.1.9598bd41fefd5
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

1,192
nextcloudgroundhog2k0.22.71 of 3See more

nextcloud groundhog2k 0.22.7

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/nextcloud:35.0.0:35.0.0-apache3e9f6eaa5dc8
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,979
ilumilumOfficialVerified publisher6.7.34 of 19See more

ilum ilum 6.7.3

4 of the 19 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/postgresql:16233f361c5819
tar@1.34+dfsg-1.2+deb12u1
no fix listed
ilum/api:6.7.3624fd09528c8
tar@1.35+dfsg-3.1
no fix listed
ilum/marquez:0.54.06e1d709d41f8
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

22,724
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

3,499
lakekeeperlakekeeperVerified publisher0.12.01 of 2See more

lakekeeper lakekeeper 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,015
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

7,442
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

5,784
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

4,518
netris-controllernetrisai2.8.24 of 14See more

netris-controller netrisai 2.8.2

4 of the 14 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
netrisai/controller-telescope:4.6.0.00414d82948a8b2
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
netrisai/controller-web-session-generator:0.2.0a030a31289f4
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed

Open the chart page →

30,680
hedgedocnicholaswildeVerified publisher1.1.01 of 1See more

hedgedoc nicholaswilde 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/hedgedoc:version-1.9.0792a12ee976a
tar@1.29b-2ubuntu0.2
no fix listed

Open the chart page →

12,750
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,414
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
tar@1.34+dfsg-1.2
no fix listed

Open the chart page →

17,512
paperless-ngxpaperless-ngxVerified publisher0.3.223 of 3See more

paperless-ngx paperless-ngx 0.3.22

3 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
tar@1.34+dfsg-1.2+deb12u1
no fix listed
valkey/valkey:9.1.2c123e3715db6
tar@1.35+dfsg-3.1
no fix listed
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

8,685
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
tar@1.29b-2ubuntu0.2
no fix listed
platform9community/api-gateway:latest40a4970de568
tar@1.29b-2ubuntu0.2
no fix listed
platform9community/customers-service:latest2089811e5cc6
tar@1.29b-2ubuntu0.2
no fix listed
platform9community/vets-service:latestd1165c94dfb3
tar@1.29b-2ubuntu0.2
no fix listed
platform9community/visits-service:latest8d11b50368c6
tar@1.29b-2ubuntu0.2
no fix listed

Open the chart page →

42,122
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed

Open the chart page →

14,648
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
tar@1.30+dfsg-7
no fix listed

Open the chart page →

11,923
tbmq-clustertbmq-helm-chartOfficialVerified publisher2.1.02 of 3See more

tbmq-cluster tbmq-helm-chart 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
thingsboard/tbmq-integration-executor:2.4.0b5a9c1addf80
tar@1.35+dfsg-3.1
no fix listed
thingsboard/tbmq-node:2.4.070661025dba5
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,615
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed

Open the chart page →

7,523
plexutkuozdemirVerified publisher2.1.11 of 1See more

plex utkuozdemir 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
linuxserver/plex:1.25.24a13ced2326c
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed

Open the chart page →

6,431
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

2,401
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed

Open the chart page →

5,714
zabbix-serveraekondratievVerified publisher1.0.63 of 4See more

zabbix-server aekondratiev 1.0.6

3 of the 4 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed

Open the chart page →

30,982
phpmyadminalekcVerified publisher0.3.11 of 1See more

phpmyadmin alekc 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.3-apache9e915766488a
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

2,221
crowdatlassian-data-centerVerified publisher2.0.151 of 2See more

crowd atlassian-data-center 2.0.15

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
atlassian/crowd:7.2.3c81cc7d6bc9e
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

1,602
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

6,588
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed

Open the chart page →

12,268
memcachedcloudpirates-memcachedVerified publisher0.14.91 of 1See more

memcached cloudpirates-memcached 0.14.9

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/memcached:1.6.4575c93cc91e76
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,104
cluster-secretclutersecretVerified publisher0.7.01 of 1See more

cluster-secret clutersecret 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

3,075
convoyconvoyVerified publisher3.7.132 of 3See more

convoy convoy 3.7.13

2 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

6,142
cortexcortex3.4.02 of 4See more

cortex cortex 3.4.0

2 of the 4 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/memcached:1.6.45d956c0a57fd7
tar@1.35+dfsg-3.1
no fix listed
library/nginx:1.31abe47724e466
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,204
grayloggraylog2OfficialVerified publisher2.0.01 of 2See more

graylog graylog2 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
graylog/graylog-enterprise:7.1.88a1f641cd7aa
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

1,619
valkeygroundhog2k2.3.41 of 1See more

valkey groundhog2k 2.3.4

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
valkey/valkey:9.1.2c123e3715db6
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

858
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed

Open the chart page →

5,023
docmosthelmforgeVerified publisher1.2.123 of 4See more

docmost helmforge 1.2.12

3 of the 4 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
docmost/docmost:0.96.0b56947fcfd08
tar@1.35+dfsg-3.1
no fix listed
library/postgres:18.6-trixie4ef4dbc939d6
tar@1.35+dfsg-3.1
no fix listed
library/redis:8.10.1298e5b3bc566
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

4,224
wordpresshelmforgeVerified publisher3.0.61 of 3See more

wordpress helmforge 3.0.6

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apacheedeeae67330a
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,494
coturnjaconiVerified publisher1.0.51 of 1See more

coturn jaconi 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
coturn/coturn:4.10.0-r1f4c2af06c3c5
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

3,147
mongooseimmongoose0.4.111 of 1See more

mongooseim mongoose 0.4.11

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
erlangsolutions/mongooseim:6.6.0cc5bf032931f
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

1,354
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
tar@1.35+dfsg-3build1
no fix listed

Open the chart page →

8,740
nginx-ingressnginx-ingress-chartVerified publisher0.0.0-edge1 of 1See more

nginx-ingress nginx-ingress-chart 0.0.0-edge

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
nginx/nginx-ingress:edge520d439f9a9a
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,419
technitium-dnsserverobeoneVerified publisher1.13.11 of 1See more

technitium-dnsserver obeone 1.13.1

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
technitium/dns-server:15.5.02502fd4993d1
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

737
passboltpassbolt2.1.16 of 6See more

passbolt passbolt 2.1.1

6 of the 6 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
bitnamilegacy/redis-sentinel:8.2.1-debian-12-r00ca3ea1d2f82
tar@1.34+dfsg-1.2+deb12u1
no fix listed
library/haproxy:3.4.10f597665a2a6
tar@1.35+dfsg-3.1
no fix listed
library/mariadb:latestd4fdec0510ad
tar@1.35+dfsg-4ubuntu0.4
no fix listed
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

13,284
reposilitereposilite1.4.21 of 1See more

reposilite reposilite 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-18477.

Container imageDigestPackageFixed in
dzikoysk/reposilite:3.6.390de4c8e6c0e
tar@1.35+dfsg-3ubuntu0.4
no fix listed

Open the chart page →

1,092

Container images carrying it

2,543 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/jupyterhub/k8s-singleuser-sample:4.4.265e1b09fc8c9
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/maxiv/pieeat:0.9.3099715479210
tar@1.35+dfsg-3.1
no fix listed
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/mittwald/kube-mail:latest04f1099241fc
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
tar@1.28-2.1ubuntu0.1
no fix listed
1
quay.io/ocellusai/operator:v0.10.59ff01f642e2b
tar@1.35+dfsg-3.1
no fix listed
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
tar@1.35+dfsg-3build1
no fix listed
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
tar@1.28-2.1ubuntu0.1
no fix listed
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
tar@1.35+dfsg-3.1
no fix listed
1
quay.io/poundex/tekton-stash-and-cache:0.2.2e854423caa09
tar@1.35+dfsg-4ubuntu0.4
no fix listed
1
quay.io/seamware/onboarding:0.2.2b406475f9f00
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
tar@1.34+dfsg-1.2
no fix listed
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
registry.gitlab.com/dyff/dyff-api:0.57.5b6c44d969163
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/dyff/workflows-aggregator:0.16.9b7984253b128
tar@1.35+dfsg-4ubuntu0.4
no fix listed
1
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/certificates:v19.4.01c38ad710b0c
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitaly:v19.4.0704cd68566af
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-base:v19.4.0696d798a5c85
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-container-registry:v4.40.2-gitlabdc1a8972c640
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-exporter:17.0.26645e014f75d
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-shell:v14.57.3aca1bb3d5b7e
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-workhorse-ee:v19.4.02256b49461fa
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/kubectl:v19.4.048ee51dd67d4
tar@1.35+dfsg-3.1
no fix listed
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
tar@1.35+dfsg-3.1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.