StackRadar

CVE-2026-18508

Medium

Advisory

Published 3 Aug 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.4
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,451
of 17,790 indexed, latest versions
Container images
2,431
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 2,451 of 17,790 indexed charts deploy, on 2,431 images.

Affected packageAffected versionsFixed inImages
tardeb1.27.1-1, 1.27.1-1ubuntu0.1, 1.28-2.1ubuntu0.1, 1.28-2.1ubuntu0.2+31 more1.35+dfsg-3.1+e52,431
OSV records
DEBIAN-CVE-2026-18508UBUNTU-CVE-2026-18508ECHO-94ec-2dbe-8b73

Charts affected

2,451 by stars
ChartLatestAffected imagesRadar Score
zoo-project-druzoo-projectOfficialVerified publisher0.10.41 of 6See more

zoo-project-dru zoo-project 0.10.4

1 of the 6 container images this version deploys carry CVE-2026-18508.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-19f3c4eed7c9ec9d1f0375bbe59f9d204a42bd3a9a507cb7e2dd
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed

Open the chart page →

7,929

Container images carrying it

2,431 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
apachepulsar/pulsar:2.8.2d538416d5afe
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
apache/rocketmq:5.3.0434d8398f996
tar@1.35+dfsg-3build1
no fix listed
1
apache/rocketmq-exporter:0.0.2c8fb51195444
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
apache/skywalking-oap-server:9.2.0133d35d2c263
tar@1.34+dfsg-1build3
no fix listed
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
apache/skywalking-ui:9.2.0295f1dc87d98
tar@1.34+dfsg-1build3
no fix listed
1
apache/skywalking-ui:8.9.180530f0308a5
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
apache/superset:4.0.1ab9467fd712c
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
apache/tika:latest-full80072bb73dd3
tar@1.35+dfsg-4ubuntu0.4
no fix listed
1
apache/tika:3.3.1.090b7fa1dc018
tar@1.35+dfsg-4
no fix listed
1
apache/tika:2.9.0.092d055a84e9e
tar@1.34+dfsg-1ubuntu0.1.22.04.1
no fix listed
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
tar@1.35+dfsg-3.1
no fix listed
1
appwrite/new:1.1.96-self-hostedaf65a77db50e
tar@1.35+dfsg-3.1
no fix listed
1
archivebox/archivebox:0.7.41a5a37331091
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
arilot/docker-bitcoind:0.17.127a4f7e0f9f1
tar@1.28-2.1ubuntu0.1
no fix listed
1
aristidetm/basic-notebook:3.6.5469dbc951224
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
artifacthub/tracker:v1.23.05368d21a6e5c
tar@1.35+dfsg-3.1
no fix listed
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
arunvelsriram/utils:latest655ad18fd8d6
tar@1.35+dfsg-3build1
no fix listed
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
1
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
assistiot/identity-manager_db:latest0d3e6d35f168
tar@1.34+dfsg-1.2
no fix listed
1
assistiot/location_processing:lateste9bae124095f
tar@1.34+dfsg-1build3
no fix listed
1
assistiot/open_api_backend:1.1.230812ba93555
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
assistiot/sdn_controller:2.4.0ea254b6d8a31
tar@1.30+dfsg-7ubuntu0.20.04.2
no fix listed
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
tar@1.34+dfsg-1.2
no fix listed
1
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
tar@1.30+dfsg-7ubuntu0.20.04.3
no fix listed
1
athou/commafeed:6.2.0-postgresql5e388351df1a
tar@1.35+dfsg-3.1
no fix listed
1
atlassian/bamboo:12.1.114af4bb6c8d46
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
atlassian/bamboo-agent-base:12.1.1151c2d7274eef
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
atlassian/bitbucket:10.2.705933f2b1cfd
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
atlassian/confluence-server:7.10.03b9222ab32ef
tar@1.34+dfsg-1build3
no fix listed
1
atlassian/crowd:7.2.3c81cc7d6bc9e
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
atlassian/crowd:5.2.2ebf761c7d437
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
atlassian/jira-software:8.14.037bc46cbec1a
tar@1.34+dfsg-1ubuntu0.1.22.04.2
no fix listed
1
atlassian/jira-software:9.7.264a75aa4ec4e
tar@1.35+dfsg-3build1
no fix listed
1
atlassian/jira-software:11.3.11e5548cd4eea8
tar@1.35+dfsg-3ubuntu0.4
no fix listed
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
avinash263/pyredis263:latestaa2b8727f1a6
tar@1.34+dfsg-1.2
no fix listed
1
avzini/web-app:latestf40b30210ed0
tar@1.34+dfsg-1.2
no fix listed
1
baserow/backend:2.3.37c00549b3a6f
tar@1.35+dfsg-3.1
no fix listed
1
baserow/backend:1.31.1e0b3c8130b91
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
tar@1.34+dfsg-1.2+deb12u1
no fix listed
1
baserow/web-frontend:2.3.3566d24c7d9f5
tar@1.35+dfsg-3.1
no fix listed
1
bbernhard/signal-cli-rest-api:0.57549ad08d7e14
tar@1.30+dfsg-7ubuntu0.20.04.1
no fix listed
1
beanbag/reviewboard:latest6b840f546e1c
tar@1.34+dfsg-1ubuntu0.1.22.04.6
no fix listed
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.