StackRadar

CVE-2026-23745

High

Advisory

Published 16 Jan 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.2
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
765
of 17,787 indexed, latest versions
Container images
790
deployed by those charts
Fix available
1 of 2
affected packages

node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization

Carried by container images the latest versions of 765 of 17,787 indexed charts deploy, on 790 images.

Affected packageAffected versionsFixed inImages
tarnpm1.0.3, 2.2.1, 2.2.2, 4.0.2+23 more7.5.3790
node-tardeb1.0.3-2, 2.2.1-1, 4.4.10+ds1-2ubuntu1, 6.1.13+~cs7.0.5-3no fix listed6
OSV records
GHSA-8qq5-rm4j-mr97UBUNTU-CVE-2026-23745

Charts affected

765 by stars
ChartLatestAffected imagesRadar Score
mongodb-admin-interfacemongo-db-admin-interfaceVerified publisher0.1.01 of 2See more

mongodb-admin-interface mongo-db-admin-interface 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
library/mongo-express:latest1b23d7976f02
tar@6.2.1
7.5.3

Open the chart page →

5,179
sample-appmongodb-helm-charts0.1.01 of 2See more

sample-app mongodb-helm-charts 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
tar@6.1.11
7.5.3

Open the chart page →

6,438
monocularmonocular1.4.151 of 5See more

monocular monocular 1.4.15

1 of the 5 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
migmartri/prerender:latest486aacfd5aa9
tar@2.2.1
7.5.3

Open the chart page →

7,048
monopolymonopolypackage0.1.01 of 1See more

monopoly monopolypackage 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
gonzague/monopoly:latest70465995deea
tar@6.1.11
7.5.3

Open the chart page →

1,130
api-proxymoreillonVerified publisher0.1.41 of 1See more

api-proxy moreillon 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
moreillon/api-proxy:2373c1953739ef6956b5
tar@6.1.11
7.5.3

Open the chart page →

1,712
camera-viewermoreillonVerified publisher0.2.11 of 4See more

camera-viewer moreillon 0.2.1

1 of the 4 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
moreillon/camera-proxy:latestce60056b50c2
tar@6.1.11
7.5.3

Open the chart page →

11,643
face-recognitionmoreillonVerified publisher0.2.41 of 3See more

face-recognition moreillon 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
moreillon/face-recognition-fastapi-front:latestc1072f4ab6aa
tar@4.4.19
7.5.3

Open the chart page →

8,556
group-managermoreillonVerified publisher0.4.41 of 3See more

group-manager moreillon 0.4.4

1 of the 3 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
moreillon/group-manager:v4.9.0d5a0ec8394c0
tar@6.1.11
7.5.3

Open the chart page →

9,835
mqtt-loggermoreillonVerified publisher0.3.11 of 5See more

mqtt-logger moreillon 0.3.1

1 of the 5 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
moreillon/mqtt-logger:9ffbf7180a8a7daf56f6
tar@6.1.11
7.5.3

Open the chart page →

10,959
user-manager-mongodbmoreillonVerified publisher0.6.21 of 4See more

user-manager-mongodb moreillon 0.6.2

1 of the 4 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
tar@6.2.0
7.5.3

Open the chart page →

25,704
user-manager-neo4jmoreillonVerified publisher0.9.72 of 6See more

user-manager-neo4j moreillon 0.9.7

2 of the 6 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
moreillon/group-manager:v4.9.0d5a0ec8394c0
tar@6.1.11
7.5.3
moreillon/user-manager:v5.0.2e1c9bfab5c16
tar@6.1.13
7.5.3

Open the chart page →

30,363
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
tar@4.4.13
7.5.3

Open the chart page →

6,684
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
tar@6.1.15
7.5.3

Open the chart page →

4,560
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
tar@6.1.14
7.5.3

Open the chart page →

4,960
nightscoutmt1905021.1.01 of 3See more

nightscout mt190502 1.1.0

1 of the 3 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
tar@6.1.11
7.5.3

Open the chart page →

6,608
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
tar@7.5.2
7.5.3

Open the chart page →

4,016
cloudcmdmy0nVerified publisher0.0.31 of 1See more

cloudcmd my0n 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
coderaiser/cloudcmd:16.6.1b34a9775c7ce
tar@6.1.11
7.5.3

Open the chart page →

3,128
danboorumy0nVerified publisher0.0.21 of 1See more

danbooru my0n 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
tar@4.4.13
7.5.3

Open the chart page →

12,791
danbooru-stackmy0nVerified publisher0.0.31 of 4See more

danbooru-stack my0n 0.0.3

1 of the 4 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
tar@4.4.13
7.5.3

Open the chart page →

12,791
myawesomeappmyawesomapp-mitchxxx0.1.11 of 1See more

myawesomeapp myawesomapp-mitchxxx 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
mitchxxx/amazon:214e72480ec63a
tar@6.2.0
7.5.3

Open the chart page →

2,116
myawesomeappmyawesomeapp1.1.01 of 1See more

myawesomeapp myawesomeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebapp:latestea5b71588a76
tar@6.1.13
7.5.3

Open the chart page →

1,267
myawesomeapp14myawesomeapp140.1.11 of 1See more

myawesomeapp14 myawesomeapp14 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ccjacobs14/amazon:59a9b14a6f09e
tar@6.2.0
7.5.3

Open the chart page →

2,116
myawesomeappmyawesomeapp20.1.01 of 1See more

myawesomeapp myawesomeapp2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
mpopoola1/nodejsapp:latest061fc532de7d
tar@6.2.0
7.5.3

Open the chart page →

1,118
myawesomeapp-feb24myawesomeapp-feb240.1.11 of 1See more

myawesomeapp-feb24 myawesomeapp-feb24 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
josepht05/nodejs-feb24:latest36cb0c618c94
tar@6.2.0
7.5.3

Open the chart page →

1,070
myawesomeapp-janmyawesomeapp-jan0.1.11 of 1See more

myawesomeapp-jan myawesomeapp-jan 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ooghenekaro/amazon:latest03394ba1d6d8
tar@6.1.13
7.5.3

Open the chart page →

2,144
myawesomeapp-marmyawesomeapp-mar0.1.11 of 1See more

myawesomeapp-mar myawesomeapp-mar 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
winfred008/amazon:910a68de5b398
tar@6.2.0
7.5.3

Open the chart page →

2,116
myawesomeappoctmyawesomeappoct0.1.11 of 1See more

myawesomeappoct myawesomeappoct 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
tar@6.1.15
7.5.3

Open the chart page →

1,164
myawesomeappoctmyawesomeappoct20230.1.11 of 1See more

myawesomeappoct myawesomeappoct2023 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
hamid2021/nodejs-dockercli:latest429d99890c3c
tar@6.2.0
7.5.3

Open the chart page →

1,118
mydannyappmydannyapp1.1.01 of 1See more

mydannyapp mydannyapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
danny1dockerhub/nodejswebapp:lateste434683fcc89
tar@6.1.13
7.5.3

Open the chart page →

1,267
mygreatappmygreatapp0.1.01 of 1See more

mygreatapp mygreatapp 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ktitilayo2/nodejswebapp:latest8bac28058688
tar@6.1.15
7.5.3

Open the chart page →

1,164
myhelmappmyhelm-app1.1.01 of 1See more

myhelmapp myhelm-app 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
patdada/bella-docker:v1.0.075127147a624
tar@4.4.19
7.5.3

Open the chart page →

1,625
myhelmappmyhelmapp0.1.11 of 1See more

myhelmapp myhelmapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
tobirachel/node-project3:v17d9f37154994
tar@6.1.14
7.5.3

Open the chart page →

3,359
myhelmappmyhelmapp11.1.01 of 1See more

myhelmapp myhelmapp1 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
josepht05/titajo-docker:v1.0.0d94024965d78
tar@6.1.15
7.5.3

Open the chart page →

1,164
myhelmappmyhelmpapp1.1.01 of 1See more

myhelmapp myhelmpapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
tar@6.1.14
7.5.3

Open the chart page →

1,235
myweatherhelmmyweather1.3.111 of 7See more

myweatherhelm myweather 1.3.11

1 of the 7 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
tar@6.2.1
7.5.3

Open the chart page →

17,929
dashynas-helm-chartsVerified publisher1.0.41 of 1See more

dashy nas-helm-charts 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
lissy93/dashy:2.0.51991f7be5ed0
tar@6.1.11
7.5.3

Open the chart page →

3,269
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
tar@4.4.2
7.5.3
socialmediamacroscope/smile_server:0.3.31a528c794270
tar@6.1.0
7.5.3

Open the chart page →

109,294
uptime-kumancsaVerified publisher1.7.21 of 1See more

uptime-kuma ncsa 1.7.2

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.4917318f9d7be
tar@6.2.1
7.5.3

Open the chart page →

30,028
papergirlneoskop3.2.61 of 5See more

papergirl neoskop 3.2.6

1 of the 5 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
neoskop/papergirl:3.2.67f52b5949f03
tar@6.1.15
7.5.3

Open the chart page →

6,982
neosyncneosyncVerified publisher0.5.411 of 3See more

neosync neosync 0.5.41

1 of the 3 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
tar@6.2.1
7.5.3

Open the chart page →

7,184
appneosync-appVerified publisher0.5.411 of 1See more

app neosync-app 0.5.41

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ghcr.io/nucleuscloud/neosync/app:0.5.41ca31ec35b829
tar@6.2.1
7.5.3

Open the chart page →

1,569
bluesky-pdsnerkho-helm-charts0.4.21 of 1See more

bluesky-pds nerkho-helm-charts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.204cbc6e3ea157d
tar@6.2.1
7.5.3

Open the chart page →

2,383
nexus-tasksnexus-tasks2.0.01 of 5See more

nexus-tasks nexus-tasks 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
tar@6.2.1
7.5.3

Open the chart page →

3,798
wireguardnicklasfrahm-wireguard0.2.01 of 1See more

wireguard nicklasfrahm-wireguard 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ghcr.io/wg-easy/wg-easy:145f26407fd2ed
tar@7.4.3
7.5.3

Open the chart page →

1,157
nodeapp-chartnodeapp-chart0.1.01 of 1See more

nodeapp-chart nodeapp-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
laly9999/node-app-dockerized:latest75ae77a20c6c
tar@6.2.0
7.5.3

Open the chart page →

1,118
node-appnode-app-charts0.1.01 of 1See more

node-app node-app-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
eameti/node-app:latestf36642affa86
tar@4.4.13
7.5.3

Open the chart page →

1,444
node-appnode-app-lili1.0.01 of 1See more

node-app node-app-lili 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
laly9999/node-app:1dd0e503913e1
tar@6.2.1
7.5.3

Open the chart page →

10,218
node-hostnamenode-hostnameVerified publisher1.0.11 of 1See more

node-hostname node-hostname 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
christianhuth/node-hostname:1.0.1c07f414a3e4b
tar@7.4.3
7.5.3

Open the chart page →

884
indexer-toolsnodeifyVerified publisher2.1.11 of 1See more

indexer-tools nodeify 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
ghcr.io/vincenttaglia/indexer-tools:v3.4.45bae30456ddb
tar@6.1.11
7.5.3

Open the chart page →

2,919
servernodejs0.0.21 of 1See more

server nodejs 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-23745.

Container imageDigestPackageFixed in
maissacrement/pock8snodejs:0.0.16da0db1159da
tar@6.1.13
7.5.3

Open the chart page →

1,902

Container images carrying it

790 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ethersphere/onboarding-faucet:0.3.0513154aab230
tar@6.1.11
7.5.3
1
ethpandaops/blobscan:latest7a9ab6370657
tar@6.1.11
7.5.3
1
ethpandaops/blobscan-indexer:latestc58eb9ffe446
tar@4.4.19
7.5.3
1
ethpandaops/ethereumjs:masterfb84b718500f
tar@6.2.1
7.5.3
1
factly/mande-web:0.34.1742355964b0e
tar@6.1.11
7.5.3
1
fallenbagel/jellyseerr:latest4538137bc5af
tar@7.4.3
7.5.3
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
tar@6.1.11
7.5.3
1
fanzynoodle/smeejas:0.0.15f9916c1a287
tar@6.1.11
7.5.3
1
felddy/foundryvtt:0.8.36c5d90b90349
tar@6.1.0
7.5.3
1
felddy/foundryvtt:12.343.06c5e3e9ffbb0
tar@6.2.1
7.5.3
1
felipecs8/app-movies-series:v14e51693fcdf5
tar@4.4.19
7.5.3
1
felipecs8/conversor-temperatura:v1f945423be36d
tar@6.2.1
7.5.3
1
felipecs8/landing-page:v1db6d44e325a1
tar@6.2.1
7.5.3
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
tar@6.2.1
7.5.3
1
fiware/idm:8.3.3a1b6ed4ae84f
tar@4.4.19
7.5.3
1
fiware/iotagent-json:3.1.0879b21a0d36d
tar@6.1.11
7.5.3
1
fiware/iotagent-ul:1.14.0fe11f55a926d
tar@4.4.13
7.5.3
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
tar@4.4.13
7.5.3
1
flanksource/canary-checker-ui:v1.4.281764c84e550db
tar@7.4.3
7.5.3
1
flanksource/incident-manager-ui:v1.4.318891f21df54fb
tar@7.4.3
7.5.3
1
folioci/mod-graphql:latestf0655a6a08fd
tar@6.2.1
7.5.3
1
fonoster/routr-pgdata-migrations:2.13.6c7b1dba81eb3
tar@6.2.1
7.5.3
1
fosrl/pangolin:1.13.0c32ad797ab96
tar@7.5.2
7.5.3
1
frappe/frappe-socketio:v13.4.12095767a9e82
tar@6.1.0
7.5.3
1
galaxy/galaxy-init:v18.010267bad550e6
tar@4.0.2
7.5.3
1
gethue/hue:4.11.011b649636e68
tar@4.4.19
7.5.3
1
gethue/hue:4.10.05702b2c37ff9
tar@4.4.13
7.5.3
1
glenndehaan/api-mapper:latest6ff6310683bf
tar@6.2.0
7.5.3
1
glenndehaan/contentbridge:latest99b9e4f73848
tar@6.1.13
7.5.3
1
glenndehaan/kube-hook:latest0a7116f48bfe
tar@7.4.3
7.5.3
1
gonzague/monopoly:latest70465995deea
tar@6.1.11
7.5.3
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
tar@4.4.19
7.5.3
1
graphiteapp/graphite-statsd:1.1.7-604a0037cc2ae
tar@4.4.13
7.5.3
1
gristlabs/grist:0.7.96e71b1914a7e
tar@4.4.13
7.5.3
1
gtato/demo-multiclus-registrator:1.0.09a744588fab3
tar@6.1.11
7.5.3
1
gtato/demo-multiclus-registry:1.0.02df5174f3cfd
tar@6.1.11
7.5.3
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
tar@4.4.13
7.5.3
1
halkeye/hubot:latest9764d2202130
tar@4.4.13
7.5.3
1
halkeye/irslackd:latest7638bfba70b0
tar@2.2.1
7.5.3
1
hamid2021/nodejs-dockercli:latest429d99890c3c
tar@6.2.0
7.5.3
1
hansehe/graphql-gateway:1.0.458e09540afbc
tar@6.1.15
7.5.3
1
haveagitgat/tdarr_node:2.00.101e3f9328327d
tar@4.4.13
7.5.3
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
tar@6.1.14
7.5.3
1
hecrom/myweatherprocessingreactclient:1.3.115454b54d5b28
tar@6.2.1
7.5.3
1
helga09/shoes_ukr:v1.1.17999bc8b77c0
tar@6.1.14
7.5.3
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
tar@6.1.15
7.5.3
1
heywood8/redisinsight:2.28.00bc9ab313d37
tar@6.1.13
7.5.3
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
tar@4.4.13
7.5.3
1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
tar@7.4.3
7.5.3
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
tar@6.1.11
7.5.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.