StackRadar

CVE-2026-29170

Medium

Advisory

Published 8 Jun 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.005
43rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
54
of 17,781 indexed, latest versions
Container images
51
deployed by those charts
Fix available
3 of 3
affected packages

Apache HTTP Server: mod_proxy_ftp XSS

Carried by container images the latest versions of 54 of 17,781 indexed charts deploy, on 51 images.

Affected packageAffected versionsFixed inImages
apache2deb2.4.41-4ubuntu3.11, 2.4.41-4ubuntu3.12, 2.4.41-4ubuntu3.14, 2.4.41-4ubuntu3.17+17 more2.4.41-4ubuntu3.23+esm6, 2.4.52-1ubuntu4.23, 2.4.58-1ubuntu8.15, 2.4.68-1~deb12u1+1 more43
apachebitnami2.4.54-157, 2.4.65-1, 2.4.68-1, 2.4.68-82.4.684
apache2apk2.4.62-r0, 2.4.63-r4, 2.4.66-r0, 2.4.67-r02.4.68-r04
OSV records
ALPINE-CVE-2026-29170BIT-apache-2026-29170DEBIAN-CVE-2026-29170UBUNTU-CVE-2026-29170
Also known as
USN-8516-1, USN-8589-1

Charts affected

54 by stars
ChartLatestAffected imagesRadar Score
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-29170.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
apache2@2.4.41-4ubuntu3.17
2.4.41-4ubuntu3.23+esm6

Open the chart page →

18,756
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-29170.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
apache2@2.4.62-1~deb12u2
2.4.68-1~deb12u1

Open the chart page →

10,086
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-29170.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
apache2@2.4.41-4ubuntu3.21
2.4.41-4ubuntu3.23+esm6

Open the chart page →

10,006
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-29170.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
apache2@2.4.57-2
2.4.68-1~deb12u1

Open the chart page →

10,001

Container images carrying it

51 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
apache2@2.4.67-1~deb12u2
2.4.68-1~deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.