StackRadar

CVE-2026-33630

High

Advisory

Published 9 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.005
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
416
of 17,781 indexed, latest versions
Container images
384
deployed by those charts
Fix available
2 of 3
affected packages

Important: c-ares security update

Carried by container images the latest versions of 416 of 17,781 indexed charts deploy, on 384 images.

Affected packageAffected versionsFixed inImages
c-aresapk1.34.3-r0, 1.34.4-r0, 1.34.5-r0, 1.34.6-r01.34.8-r0358
c-aresdeb1.14.0-1, 1.14.0-1ubuntu0.2, 1.15.0-1ubuntu0.1, 1.15.0-1ubuntu0.4+6 moreno fix listed25
c-aresrpm1.34.6-1.el100:1.34.6-2.el10_21
OSV records
ALPINE-CVE-2026-33630DEBIAN-CVE-2026-33630RLSA-2026:42096UBUNTU-CVE-2026-33630

Charts affected

416 by stars
ChartLatestAffected imagesRadar Score
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
grafana/grafana:12.3.070d9599b186c
c-ares@1.34.5-r0
1.34.8-r0

Open the chart page →

4,526
twentytwenty-crm0.1.111 of 4See more

twenty twenty-crm 0.1.11

1 of the 4 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
twentycrm/twenty:v2.22.0e7d9948bf284
c-ares@1.34.6-r0
1.34.8-r0

Open the chart page →

5,550
deep-learning-toolsuninettsigma29.1.21 of 3See more

deep-learning-tools uninettsigma2 9.1.2

1 of the 3 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
library/nginx:1.29.3-alpineb3c656d55d7a
c-ares@1.34.5-r0
1.34.8-r0

Open the chart page →

1,567
excalidashunxwaresVerified publisher2026.2.51 of 2See more

excalidash unxwares 2026.2.5

1 of the 2 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
zimengxiong/excalidash-frontend:0.4.27242629350b06
c-ares@1.34.6-r0
1.34.8-r0

Open the chart page →

2,620
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
evoapicloud/evolution-manager:latestcbfeb314afb9
c-ares@1.34.5-r0
1.34.8-r0

Open the chart page →

3,746
simple-prima-notavcnngrVerified publisher0.5.32 of 4See more

simple-prima-nota vcnngr 0.5.3

2 of the 4 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
vcnngr/pnbackend:latesteaf44ad0ad1f
c-ares@1.34.5-r0
1.34.8-r0
vcnngr/pnfrontend:latest4e4979ab8c41
c-ares@1.34.5-r0
1.34.8-r0

Open the chart page →

4,768
colanodevictorlane0.3.31 of 3See more

colanode victorlane 0.3.3

1 of the 3 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
ghcr.io/colanode/web:latestbcad696f03ee
c-ares@1.34.5-r0
1.34.8-r0

Open the chart page →

2,076
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
c-ares@1.18.1-1ubuntu0.22.04.2
no fix listed

Open the chart page →

13,459
squawkvojtechpastyrikVerified publisher0.1.101 of 1See more

squawk vojtechpastyrik 0.1.10

1 of the 1 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
c-ares@1.34.6-r0
1.34.8-r0

Open the chart page →

400
aih-scannerwallarmVerified publisher2.7.111 of 2See more

aih-scanner wallarm 2.7.11

1 of the 2 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.7.11f1cb26db1f5b
c-ares@1.34.5-1+deb13u1
no fix listed

Open the chart page →

3,911
wexa-studiowexa-studio1.2.03 of 15See more

wexa-studio wexa-studio 1.2.0

3 of the 15 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
c-ares@1.34.5-r0
1.34.8-r0
temporalio/server:1.29.1c1e3326b2ce1
c-ares@1.34.5-r0
1.34.8-r0
temporalio/ui:2.44.00b36e00aad30
c-ares@1.34.6-r0
1.34.8-r0

Open the chart page →

14,983
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
c-ares@1.34.6-r0
1.34.8-r0

Open the chart page →

5,459
metabasewiremindVerified publisher2.27.5-wiremind01 of 1See more

metabase wiremind 2.27.5-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
metabase/metabase:v0.61.1.x9491ed11c901
c-ares@1.34.6-r0
1.34.8-r0

Open the chart page →

1,639
postgres-operatorwiremindVerified publisher1.14.0-wiremind01 of 1See more

postgres-operator wiremind 1.14.0-wiremind0

1 of the 1 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
ghcr.io/zalando/postgres-operator:v1.14.04f40cfc2283b
c-ares@1.34.3-r0
1.34.8-r0

Open the chart page →

1,286
language-toolzekker6Verified publisher1.12.11 of 2See more

language-tool zekker6 1.12.1

1 of the 2 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
erikvl87/languagetool:6.7-dockerupdate-3e1ea6a975388
c-ares@1.34.6-r0
1.34.8-r0

Open the chart page →

1,571
zoo-project-druzoo-projectOfficialVerified publisher0.10.42 of 6See more

zoo-project-dru zoo-project 0.10.4

2 of the 6 container images this version deploys carry CVE-2026-33630.

Container imageDigestPackageFixed in
curlimages/curl:8.21.07c12af72ceb3
c-ares@1.34.6-r0
1.34.8-r0
library/postgres:18.4-alpine3.249a8afca54e78
c-ares@1.34.6-r0
1.34.8-r0

Open the chart page →

7,849

Container images carrying it

384 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
nginxinc/nginx-unprivileged:1.29-alpine0c79d56aee56
c-ares@1.34.6-r0
1.34.8-r0
6
alpine/kubectl:1.34.18413f8890d19
c-ares@1.34.5-r0
1.34.8-r0
5
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
c-ares@1.34.6-r0
1.34.8-r0
5
curlimages/curl:8.21.07c12af72ceb3
c-ares@1.34.6-r0
1.34.8-r0
4
grafana/grafana:13.1.0121a7a9ece6d
c-ares@1.34.6-r0
1.34.8-r0
4
library/httpd:2.4-alpine:alpine1b766f17b840
c-ares@1.34.6-r0
1.34.8-r0
4
pihole/pihole:2026.07.2:latestf7d1be836e3b
c-ares@1.34.6-r0
1.34.8-r0
4
natsio/nats-box:0.19.28031d190c7ee
c-ares@1.34.5-r0
1.34.8-r0
3
natsio/nats-box:0.19.7ffce8bd10338
c-ares@1.34.6-r0
1.34.8-r0
3
quay.io/jupyterhub/configurable-http-proxy:5.2.0522738d5285e
c-ares@1.34.6-r0
1.34.8-r0
3
alpine/git:2.47.2062a01ad7a0e
c-ares@1.34.5-r0
1.34.8-r0
2
alpine/k8s:1.32.12048f8d9c8cc7
c-ares@1.34.6-r0
1.34.8-r0
2
alpine/kubectl:1.35.49ccd82364762
c-ares@1.34.6-r0
1.34.8-r0
2
alpine/kubectl:1.35.2ec8f734b0a10
c-ares@1.34.6-r0
1.34.8-r0
2
clamav/clamav:1.4.3_base629a3050df6a
c-ares@1.34.6-r0
1.34.8-r0
2
curlimages/curl:8.20.0b3f1fb2a51d9
c-ares@1.34.6-r0
1.34.8-r0
2
dunglas/mercure:v0:v0.24.2916834e49961
c-ares@1.34.6-r0
1.34.8-r0
2
excalidraw/excalidraw:latestf7ee194addd6
c-ares@1.34.5-r0
1.34.8-r0
2
gisaia/arlas-wui:28.0.3b83b3e067173
c-ares@1.34.6-r0
1.34.8-r0
2
gisaia/arlas-wui-builder:28.0.1a35977a5bb7d
c-ares@1.34.6-r0
1.34.8-r0
2
gisaia/arlas-wui-hub:28.0.21a3cc43d822f
c-ares@1.34.6-r0
1.34.8-r0
2
grafana/grafana:12.3.12175aaa91c96
c-ares@1.34.6-r0
1.34.8-r0
2
grafana/grafana:12.3.39e1e77ade304
c-ares@1.34.6-r0
1.34.8-r0
2
grafana/grafana:12.4.1e932bd6ed0e0
c-ares@1.34.6-r0
1.34.8-r0
2
helmforge/kubectl:1.35.3c3f97e954c47
c-ares@1.34.6-r0
1.34.8-r0
2
ilum/ui:6.7.3998937726679
c-ares@1.34.6-r0
1.34.8-r0
2
jupyterhub/configurable-http-proxy:5.3.0:latest69a7170eeeda
c-ares@1.34.6-r0
1.34.8-r0
2
kurento/kurento-media-server:latest03c0d34d0828
c-ares@1.27.0-1.0ubuntu1
no fix listed
2
library/caddy:2.11.4-alpine:2-alpine5f5c8640aae0
c-ares@1.34.6-r0
1.34.8-r0
2
library/caddy:latestdf7f1c2fb114
c-ares@1.34.6-r0
1.34.8-r0
2
mesosphere/kubectl:v1.35.0-alpineea01a9387771
c-ares@1.34.6-r0
1.34.8-r0
2
metabase/metabase:v0.61.1.x9491ed11c901
c-ares@1.34.6-r0
1.34.8-r0
2
netapp/trident-protect-utils:v2.0.0cd0c18d8f9ec
c-ares@1.34.6-r0
1.34.8-r0
2
nginxinc/nginx-unprivileged:1.27-alpine65e3e85dbaed
c-ares@1.34.5-r0
1.34.8-r0
2
requarks/wiki:2:latest68f0d1848261
c-ares@1.34.6-r0
1.34.8-r0
2
shlinkio/shlink:5.1.6:stable666cc24edf72
c-ares@1.34.6-r0
1.34.8-r0
2
syncthing/syncthing:2.1.1775c4aac4862
c-ares@1.34.6-r0
1.34.8-r0
2
uselagoon/docker-host:v3.6.12c89ed939b8b
c-ares@1.34.5-r0
1.34.8-r0
2
ghcr.io/cinnyapp/cinny:v4.12.6a7805a8a60ff
c-ares@1.34.6-r0
1.34.8-r0
2
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
c-ares@1.34.5-r0
1.34.8-r0
2
ghcr.io/grafana/helm-chart-toolbox-kubectl:0.1.1c137478627cc
c-ares@1.34.5-r0
1.34.8-r0
2
ghcr.io/home-assistant/home-assistant:2026.9.1:latest612d76760b54
c-ares@1.34.6-r0
1.34.8-r0
2
ghcr.io/home-assistant/home-assistant:2026.9.2a1bc133af84e
c-ares@1.34.6-r0
1.34.8-r0
2
ghcr.io/home-operations/readarr:0.4.18:0.4.18.28058f7551205fbd
c-ares@1.34.5-r0
1.34.8-r0
2
quay.io/frrouting/frr:10.4.38745af1f9bbb
c-ares@1.34.6-r0
1.34.8-r0
2
registry.gitlab.com/prisme.ai/prisme.ai/prisme.ai-infra:latestb1198ea741d1
c-ares@1.34.6-r0
1.34.8-r0
2
registry.gitlab.com/shortlink-org/shortlink/ui:main9bdb1062d960
c-ares@1.34.6-r0
1.34.8-r0
2
registry.k8s.io/ingress-nginx/controller:v1.11.8695d79381ee6
c-ares@1.34.5-r0
1.34.8-r0
2
registry.k8s.io/ingress-nginx/controller:v1.12.1d2fbc4ec70d8
c-ares@1.34.3-r0
1.34.8-r0
2
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
c-ares@1.34.5-r0
1.34.8-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.