StackRadar

CVE-2026-18508

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,554
of 17,832 indexed, latest versions
Container images
2,553
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,554 of 17,832 indexed charts deploy, on 2,553 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,553
OSV records
DEBIAN-CVE-2026-18508UBUNTU-CVE-2026-18508ECHO-94ec-2dbe-8b73

Charts affected

2,554 by stars
ChartLatestAffected imagesRadar Score
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
library/nginx:latestabe47724e466
tar@1.35+dfsg-3.1
no fix listed

Open the chart page →

1,623
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
tar@1.34+dfsg-1.2+deb12u1
no fix listed

Open the chart page →

4,628
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
tar@1.29b-2ubuntu0.2
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed

Open the chart page →

9,357
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed

Open the chart page →

8,128

Container images carrying it

2,553 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
redis/redis-stack-server:7.2.0-v10e44b2b49d059
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
2
rotationalio/quarterdeck:0.16.00e7ad3a031dc
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
safeglobal/safe-config-service:latest09a5e495c219
tar@1.35+dfsg-3.1
no fix listed
2
safeglobal/safe-transaction-service:latest80db836cc5d5
tar@1.35+dfsg-3.1
no fix listed
2
sigp/lighthouse:v8.1.344aa773dcf27
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
2
sigp/lighthouse:latest9a62bb870545
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed
2
sikalabs/hello-world-server:latest5f49bf889a64
tar@1.35+dfsg-3.1
no fix listed
2
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
tar@1.30+dfsg-7ubuntu0.20.04.4
no fix listed
2
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
tar@1.34+dfsg-1build3
no fix listed
2
taigaio/taiga-back:latest4beed8f62c9f
tar@1.35+dfsg-3.1
no fix listed
2
taigaio/taiga-protected:latestfd4568a97a59
tar@1.35+dfsg-3.1
no fix listed
2
testinprod/op-erigon:latest0a125bd77a2d
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
2
uffizzi/controller:latest0344805f267b
tar@1.34+dfsg-1.2
no fix listed
2
valkey/valkey:9.0.1546304417fea
tar@1.35+dfsg-3.1
no fix listed
2
valkey/valkey:8.1.481db6d39e1bb
tar@1.35+dfsg-3.1
no fix listed
2
valkey/valkey:9.1.08e8d64b405ce
tar@1.35+dfsg-3.1
no fix listed
2
vaultwarden/server:1.37.31587c45feaa4
tar@1.35+dfsg-3.1
no fix listed
2
vdiogov/glpi-conteiner:latest6945f84f0058
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
wolveix/satisfactory-server:latest:v1.9.10e103700ae6ae
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
2
wurstmeister/zookeeper:latest7a7fd44a7210
tar@1.27.1-1
no fix listed
2
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
tar@1.35+dfsg-3build1
no fix listed
2
gcr.io/google_containers/kubernetes-dashboard-init-amd64:v1.0.0fbe12aa24de6
tar@1.28-2.1ubuntu0.1
no fix listed
2
ghcr.io/appscode/inbox-server:latest:postgres-latest536358d7b17e
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
2
ghcr.io/astriaorg/conductor:latest3ea8164b0eae
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
tar@1.35+dfsg-3ubuntu0.4
no fix listed
2
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
tar@1.35+dfsg-3build1
no fix listed
2
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
tar@1.35+dfsg-3.1
no fix listed
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
tar@1.34+dfsg-1build3
no fix listed
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
tar@1.34+dfsg-1build3
no fix listed
2
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
2
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
2
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
2
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
ghcr.io/immich-app/immich-machine-learning:v3.1.05a0839dc5303
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
ghcr.io/immich-app/immich-server:v3.1.0b434cb9287ee
tar@1.35+dfsg-3.1
no fix listed
2
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
ghcr.io/libredb/libredb-studio:0.16.2c398419c29a7
tar@1.35+dfsg-3.1
no fix listed
2
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
tar@1.29b-2ubuntu0.1
no fix listed
2
ghcr.io/linuxserver/plex:latestbe083133dfe0
tar@1.35+dfsg-4ubuntu0.4
no fix listed
2
ghcr.io/lissy93/web-check:latest7e2ef5261764
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
ghcr.io/nginxinc/nginx-s3-gateway/nginx-oss-s3-gateway:unprivileged-oss:unprivileged-oss-202503313db8145349a3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2
ghcr.io/openunison/openunison-kubernetes-operator:1.0.1392bd6c526c50
tar@1.35+dfsg-3ubuntu0.4
no fix listed
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
tar@1.34+dfsg-1.2
no fix listed
2
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
tar@1.34+dfsg-1.2+deb12u1
no fix listed
2

syft 1.42.1 · advisories as of 23 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.