StackRadar

CVE-2026-18508

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,481
of 17,828 indexed, latest versions
Container images
2,473
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,481 of 17,828 indexed charts deploy, on 2,473 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,473
OSV records
DEBIAN-CVE-2026-18508UBUNTU-CVE-2026-18508ECHO-94ec-2dbe-8b73

Charts affected

2,481 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,473 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/wordpress:php8.1-apachef73396626d2f
tar@1.35+dfsg-3.1
no fix listed
1
library/xwiki:lts-postgres-tomcat56490ac14a31
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
library/zookeeper:3.8-temurin55d1e5b2e601
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
library/zookeeper:3.9.4dfa9ba46d14b
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
library/zookeeper:3.9.5f258365d4882
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed
1
libretranslate/libretranslate:v1.9.61de2d7056bb8
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
lightbend/curl:7.47.0b0c9894ac8dd
tar@1.28-2.1ubuntu0.1
no fix listed
1
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
tar@1.29b-2ubuntu0.3
no fix listed
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
tar@1.29b-2ubuntu0.2
no fix listed
1
linuxserver/calibre-web:0.6.24241009026e6f
tar@1.35+dfsg-3build1
no fix listed
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
linuxserver/code-server:4.10.1a5e43a05ae79
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
linuxserver/codimd:latestb801bbcf6386
tar@1.29b-2ubuntu0.1
no fix listed
1
linuxserver/deluge:18.04.10ac871624394
tar@1.29b-2ubuntu0.2
no fix listed
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
tar@1.29b-2ubuntu0.2
no fix listed
1
linuxserver/foldingathome:7.6.219a997426d71e
tar@1.35+dfsg-3build1
no fix listed
1
linuxserver/foldingathome:8.5.6ebb32940e4bb
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
linuxserver/jellyfin:10.7.72427dde159a2
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
tar@1.29b-2ubuntu0.2
no fix listed
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
tar@1.29b-2ubuntu0.1
no fix listed
1
linuxserver/plex:1.43.22785a6ad64d3
tar@1.35+dfsg-3ubuntu0.2
no fix listed
1
linuxserver/plex:1.25.24a13ced2326c
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
linuxserver/unifi-controller:8.0.240ae315a3a456
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
1
linuxserver/unifi-controller:7.3.83ab105cc50322
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
1
linuxserver/unifi-network-application:10.6.106-ls1467f15f34937ce
tar@1.35+dfsg-4ubuntu0.4
no fix listed
1
lis314/project-zomboid-docker:latestaa2089c37920
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
litmuschaos/mongo:4.2.899961210d467
tar@1.29b-2ubuntu0.1
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
lmacka/snappass:2.1.293f5c048b7d4
tar@1.35+dfsg-3.1
no fix listed
1
localstack/localstack:3.19d278167f2b7
tar@1.34+dfsg-1.2
no fix listed
1
locustio/locust:2.24.151d866285170
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
logiqai/flash:v3.10.265b996bc7bdc
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
tar@1.29b-2ubuntu0.2
no fix listed
1
longhornio/upgrade-responder:v0.2.05875cef29348
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
1
louislam/its-mytabs:1.7.02e478d3170bd
tar@1.35+dfsg-3.1
no fix listed
1
louislam/uptime-kuma:2.2.1-slim059b49d64739
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
louislam/uptime-kuma:2.0.24c364ef96aad
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
louislam/uptime-kuma:2.4.091e963bfda56
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
louislam/uptime-kuma:2.0.2-slim-rootless9865163f92c1
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
louislam/uptime-kuma:2.5.5c74379ac4509
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
lsstsqre/nublado2:2.0.1b75bf8aaafa4
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
luligu/matterbridge:3.0.28f97884bebc2
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
luligu/matterbridge:3.10.9c01108d904ec
tar@1.35+dfsg-3.1
no fix listed
1
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
lumenvox/cloud-assure-identity:2.0.0147854a3c916
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
lumenvox/cloud-audit:2.0.079428add7f38
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
lumenvox/cloud-binary-storage:2.0.053decadc102d
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
lumenvox/cloud-deployment:2.0.0ea8110886d38
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.