StackRadar

CVE-2026-18508

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,554
of 17,832 indexed, latest versions
Container images
2,553
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,554 of 17,832 indexed charts deploy, on 2,553 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,553
OSV records
DEBIAN-CVE-2026-18508UBUNTU-CVE-2026-18508ECHO-94ec-2dbe-8b73

Charts affected

2,554 by stars
ChartLatestAffected imagesRadar Score
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,623
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

4,628
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
tar@1.29b-2ubuntu0.2
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed

Open the chart page →

9,357
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed

Open the chart page →

8,128

Container images carrying it

2,553 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
journeyapps/powersync-service:latest413a0c813e96
tar@1.35+dfsg-3.1
no fix listed
1
jpgouin/openldap:2.6.9-fixbfdd0088c776
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
jupyterhub/jupyterhub:5.4.63974ba945e65
tar@1.35+dfsg-3build1
no fix listed
1
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
tar@1.30+dfsg-7
no fix listed
1
jupyterhub/k8s-hub:1.2.0e4770285aaf7
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
jupyterhub/k8s-hub:0.9.1ec78bdae0fed
tar@1.29b-2ubuntu0.1
no fix listed
1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
tar@1.30+dfsg-7
no fix listed
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
tar@1.35+dfsg-3build1
no fix listed
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kayrosuno/kping:latestf3bd44b29b0d
tar@1.35+dfsg-3build1
no fix listed
1
kennethreitz/httpbin:latest599fe5e50731
tar@1.29b-2
no fix listed
1
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
kimai/kimai2:2.67.03084f1e5ecdc
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kinseii/wazuh-agent:4.14.17160eb143728
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kitware/cdash:v5.3.0d7767d9b9da4
tar@1.35+dfsg-3.1
no fix listed
1
kixote/typemill4e9dff179519
tar@1.35+dfsg-3.1
no fix listed
1
kixote/typemill628f79a08cc7
tar@1.35+dfsg-3.1
no fix listed
1
knspar/phronetis:0.1.4609499d2dc91a
tar@1.35+dfsg-3build1
no fix listed
1
knspar/phronetis-operator:0.1.60c4f0543ee58
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kong/httpbin:latesta6ac46531193
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kong/kong:3.9.16addf50e6bd8
tar@1.35+dfsg-3build1
no fix listed
1
kong/kong-ai-gateway:2.0.3367ed5985b76
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
1
krontechnology/aapm-service:1.1.39dd602db8baa
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kserve/models-web-app:v0.13.073486345a602
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kubeflownotebookswg/jupyter-web-app:v1.9.2afb52057c997
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kubeflownotebookswg/tensorboards-web-app:v1.9.277f07f52a84a
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kubeflownotebookswg/volumes-web-app:v1.9.2f63c3e550af3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kubegems/redis:7.2.5-debian-12-r2870ee3a77add
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
tar@1.29b-2ubuntu0.1
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
tar@1.35+dfsg-3build1
no fix listed
1
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
kubeshop/testkube-minio:2025.10d8e1af6aca99
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kubesphere/examples-bookinfo-reviews-v2:1.13.06d93129beb32
tar@1.28-2.1ubuntu0.1
no fix listed
1
kudobuilder/controller:v0.9.069072d979708
tar@1.29b-2ubuntu0.1
no fix listed
1
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
1
kusionstack/kusion:v0.14.0126c8f0b0976
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kuzwolka/aws9:main1ad759b961b1
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
tar@1.35+dfsg-3.1
no fix listed
1
kyovint/kyoimgusers:1.0.080084149156e
tar@1.35+dfsg-3.1
no fix listed
1
labs64/auditflowc7b26d3ca11c
tar@1.35+dfsg-4ubuntu0.4
no fix listed
1
labs64/payment-gateway:0.0.10c66feefca17
tar@1.35+dfsg-4ubuntu0.4
no fix listed
1
labs64/traefik-authproxy:0.0.3dfc6086dfbce
tar@1.35+dfsg-3.1
no fix listed
1

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.