StackRadar

CVE-2026-29167

Critical

Advisory

Published 8 Jun 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.007
51st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
58
of 17,781 indexed, latest versions
Container images
56
deployed by those charts
Fix available
4 of 4
affected packages

Apache HTTP Server: mod_ldap per-dir use-after-free

Carried by container images the latest versions of 58 of 17,781 indexed charts deploy, on 56 images.

Affected packageAffected versionsFixed inImages
apache2deb2.4.41-4ubuntu3.11, 2.4.41-4ubuntu3.12, 2.4.41-4ubuntu3.14, 2.4.41-4ubuntu3.17+17 more2.4.41-4ubuntu3.23+esm6, 2.4.52-1ubuntu4.23, 2.4.58-1ubuntu8.15, 2.4.68-1~deb12u1+1 more43
apachebitnami2.4.54-157, 2.4.65-1, 2.4.68-1, 2.4.68-82.4.684
httpdrpm2.4.37-43.module+el8.5.0+13806+b30d9eec.1, 2.4.37-56.module+el8.8.0+18758+b3a9c8da.6, 2.4.37-65.module+el8.10.0+23815+1b5e1c66.7, 2.4.57-8.el9+4 more0:2.4.37-65.module+el8.10.0+24755+06195b95.10, 0:2.4.62-13.el9_8.69
mod_http2rpm1.15.7-10.module+el8.10.0+23369+11a81384.40:1.15.7-10.module+el8.10.0+24521+219dcfc5.71
OSV records
BIT-apache-2026-29167DEBIAN-CVE-2026-29167UBUNTU-CVE-2026-29167RHSA-2026:59347RHSA-2026:64794
Also known as
USN-8516-1, USN-8589-1

Charts affected

58 by stars
ChartLatestAffected imagesRadar Score
typo3schoolguys-helmcharts0.4.21 of 1See more

typo3 schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
apache2@2.4.67-1~deb12u2
2.4.68-1~deb12u1

Open the chart page →

4,836
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apache2@2.4.41-4ubuntu3.11
2.4.41-4ubuntu3.23+esm6

Open the chart page →

30,687
workshop-operatorstakaterVerified publisher0.0.381 of 2See more

workshop-operator stakater 0.0.38

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
stakater/workshop-operator:v0.0.3897bf456cc97c
httpd@2.4.37-43.module+el8.5.0+13806+b30d9eec.1
0:2.4.37-65.module+el8.10.0+24755+06195b95.10

Open the chart page →

6,671
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
apache2@2.4.57-2
2.4.68-1~deb12u1

Open the chart page →

9,102
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
apache2@2.4.41-4ubuntu3.17
2.4.41-4ubuntu3.23+esm6

Open the chart page →

18,756
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
apache2@2.4.62-1~deb12u2
2.4.68-1~deb12u1

Open the chart page →

10,086
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
apache2@2.4.41-4ubuntu3.21
2.4.41-4ubuntu3.23+esm6

Open the chart page →

10,006
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-29167.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
apache2@2.4.57-2
2.4.68-1~deb12u1

Open the chart page →

10,001

Container images carrying it

56 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
httpd@2.4.62-7.el9
0:2.4.62-13.el9_8.6
1
quay.io/maximilianopizarro/neuroface-backend:v1.4.13194d46df0f9
httpd@2.4.62-13.el9_8.1
0:2.4.62-13.el9_8.6
1
quay.io/maximilianopizarro/neuroface-backend:latestcba71dc08c8a
httpd@2.4.62-13.el9_8.1
0:2.4.62-13.el9_8.6
1
quay.io/maximilianopizarro/nfl-wallet-webapp:1.0.13fead5702be7
httpd@2.4.37-65.module+el8.10.0+23815+1b5e1c66.7
mod_http2@1.15.7-10.module+el8.10.0+23369+11a81384.4
0:2.4.37-65.module+el8.10.0+24755+06195b95.10
0:1.15.7-10.module+el8.10.0+24521+219dcfc5.7
1
quay.io/redhat-ai-dev/chatbot:latest59fe607dfdf2
httpd@2.4.57-8.el9
0:2.4.62-13.el9_8.6
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
apache2@2.4.67-1~deb12u2
2.4.68-1~deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.