StackRadar

CVE-2026-18508

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,451
of 17,790 indexed, latest versions
Container images
2,431
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,451 of 17,790 indexed charts deploy, on 2,431 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,431
OSV records
DEBIAN-CVE-2026-18508UBUNTU-CVE-2026-18508ECHO-94ec-2dbe-8b73

Charts affected

2,451 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed

Open the chart page →

7,929

Container images carrying it

2,431 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
tar@1.34+dfsg-1.2+deb12u1
no fix listed
3
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
tar@1.34+dfsg-1.2
no fix listed
3
ghcr.io/donkie/spoolman:0.26.1cf9b41e17b93
tar@1.34+dfsg-1.2+deb12u1
no fix listed
3
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
tar@1.34+dfsg-1.2+deb12u1
no fix listed
3
ghcr.io/smarter-project/hydra/crismux:main673d5229df1f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
3
ghcr.io/tremolosecurity/kube-oidc-proxy:1.0.13a89736c586ba
tar@1.35+dfsg-3ubuntu0.4
no fix listed
3
quay.io/argoproj/argocd:v3.5.3dd3f47d5a5e4
tar@1.35+dfsg-4ubuntu0.4
no fix listed
3
quay.io/devtron/ai-agent:0.0.16545dac92173
tar@1.34+dfsg-1.2+deb12u1
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
tar@1.34+dfsg-1build3
no fix listed
3
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
tar@1.35+dfsg-3build1
no fix listed
3
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
tar@1.35+dfsg-3build1
no fix listed
3
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
tar@1.35+dfsg-3build1
no fix listed
3
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
tar@1.35+dfsg-3build1
no fix listed
3
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
3
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
tar@1.35+dfsg-3build1
no fix listed
3
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
tar@1.28-2.1ubuntu0.2
no fix listed
3
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
3
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
tar@1.35+dfsg-3build1
no fix listed
3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
tar@1.35+dfsg-3build1
no fix listed
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
tar@1.34+dfsg-1.2+deb12u1
no fix listed
3
actualbudget/actual-server:26.9.0552beab3dec8
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
alazidis/kube-netlag:1.1.00e8c84152201
tar@1.35+dfsg-3build1
no fix listed
2
apache/apisix:3.18.0-ubuntu9ee5df1611f9
tar@1.35+dfsg-3ubuntu0.4
no fix listed
2
apache/nifi-registry:1.26.07cdfd8deec92
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
2
apache/rocketmq:5.4.0319cd8a81ed1
tar@1.35+dfsg-3build1
no fix listed
2
apache/tika:2.9.2.1-fullae0b86d3c4d0
tar@1.35+dfsg-3build1
no fix listed
2
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/etcd:latest99b408c15272
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/redis:latest5927ff3702df
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
bitnami/minideb:latestab4d5b45116e
tar@1.35+dfsg-3.1
no fix listed
2
blockstack/stacks-core:3.2.0.0.0f79944317326
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
cagriekin/pg-ha:2.0.1-pg1899e17aa165df
tar@1.35+dfsg-3.1
no fix listed
2
cfssl/cfssl:latest:v1.6.5c9018c2ddf0b
tar@1.34+dfsg-1.2
no fix listed
2
chromedp/headless-shell:148.0.7778.97313ed7255ae1
tar@1.35+dfsg-3.1
no fix listed
2
clickhouse/clickhouse-server:24.2ed9640bfff07
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
2
cribl/cribl:4.19.2044f9a5fac9a
tar@1.35+dfsg-3ubuntu0.4
no fix listed
2
dagster/user-code-example:1.13.225947f9ae481c
tar@1.35+dfsg-3.1
no fix listed
2
datagrok/grok_connect:latestf5876d3aebb8
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed
2
emberstack/kubernetes-reflector:10.0.6551dbd5880929
tar@1.35+dfsg-3ubuntu0.4
no fix listed
2
eqalpha/keydb:latest6537505c4235
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
2
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
tar@1.35+dfsg-3.1
no fix listed
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
tar@1.35+dfsg-3.1
no fix listed
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
tar@1.29b-2ubuntu0.1
no fix listed
2
freikin/dawarich:1.14.511826c67e4b1
tar@1.35+dfsg-3.1
no fix listed
2

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.