StackRadar

CVE-2026-33997

High

Advisory

Published 27 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
574
of 17,787 indexed, latest versions
Container images
568
deployed by those charts
Fix available
1 of 3
affected packages

Moby has an Off-by-one error in its plugin privilege validation

Carried by container images the latest versions of 574 of 17,787 indexed charts deploy, on 568 images.

Affected packageAffected versionsFixed inImages
docker.iodeb20.10.24+dfsg1-1+deb12u1+b6, 26.1.5+dfsg1-9+b1326.1.5+dfsg1-9+deb13u12
github.com/docker/dockergolangv0.0.0-20180620051407-e2593239d949, v0.7.3-0.20190327010347-be7ac8be2ae0, v1.4.2-0.20190924003213-a8608b5b67c7, v1.4.2-0.20191121165722-d1d5f6476656+84 moreno fix listed543
github.com/moby/mobygolangv0.7.3-0.20190826074503-38ab9da00309, v1.4.2-0.20170731201646-1009e6a40b29, v1.13.1, v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible+4 moreno fix listed30
OSV records
DEBIAN-CVE-2026-33997GHSA-pxq6-2prw-chj9
Also known as
GO-2026-4883

Charts affected

574 by stars
ChartLatestAffected imagesRadar Score
monitoringthl-chartsVerified publisher0.1.12 of 10See more

monitoring thl-charts 0.1.1

2 of the 10 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
grafana/promtail:2.4.2626900031c4e
github.com/docker/docker@v20.10.8+incompatible
no fix listed
quay.io/prometheus/prometheus:v2.34.0b37103e03399
github.com/docker/docker@v20.10.12+incompatible
no fix listed

Open the chart page →

18,908
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/docker/docker@v26.1.2+incompatible
no fix listed

Open the chart page →

2,477
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
github.com/docker/docker@v20.10.24+incompatible
no fix listed
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/docker/docker@v20.10.24+incompatible
no fix listed

Open the chart page →

4,815
traceetrivy-operator0.24.11 of 1See more

tracee trivy-operator 0.24.1

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
aquasec/tracee:0.24.1cfbbfee972e6
github.com/docker/docker@v28.1.1+incompatible
no fix listed

Open the chart page →

1,074
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,510
tfy-lokitruefoundryVerified publisher0.1.61 of 2See more

tfy-loki truefoundry 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
grafana/promtail:2.9.1063a2e57a5b14
github.com/docker/docker@v23.0.8+incompatible
no fix listed

Open the chart page →

2,813
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
grafana/grafana:12.3.070d9599b186c
github.com/moby/moby@v27.5.1+incompatible
no fix listed

Open the chart page →

4,526
devportalveecode-platform-nextVerified publisher0.1.221See more

devportal veecode-platform-next 0.1.22

1 container image this version deploys carries CVE-2026-33997.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
github.com/docker/docker@v28.5.1+incompatible
no fix listed

Open the chart page →

verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,429
vulcanvulcan0.2.21 of 2See more

vulcan vulcan 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
mitre/vulcan:latest2bc4dfb8150f
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

1,516
aih-scannerwallarmVerified publisher2.7.111 of 2See more

aih-scanner wallarm 2.7.11

1 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.7.11f1cb26db1f5b
github.com/docker/docker@v28.3.3+incompatible
no fix listed

Open the chart page →

3,911
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
wallarm/node-native-processing:0.23.07db2da8fce0b
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

2,824
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
github.com/docker/docker@v23.0.0-rc.2+incompatible
no fix listed

Open the chart page →

6,232
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,552
gitlab-runnerwenerme0.92.11 of 1See more

gitlab-runner wenerme 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

904
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/docker/docker@v25.0.15-0.20260325154711-d2dbc0547253+incompatible
no fix listed

Open the chart page →

1,456
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/docker/docker@v24.0.5+incompatible
no fix listed

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/docker/docker@v24.0.2+incompatible
no fix listed

Open the chart page →

2,022
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
github.com/docker/docker@v1.13.1
no fix listed

Open the chart page →

2,745
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
github.com/docker/docker@v20.10.21+incompatible
no fix listed

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
github.com/docker/docker@v27.4.1+incompatible
no fix listed

Open the chart page →

9,381

Container images carrying it

568 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
github.com/docker/docker@v27.4.1+incompatible
no fix listed
1
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/docker/docker@v24.0.7+incompatible
no fix listed
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
github.com/docker/docker@v28.5.1+incompatible
no fix listed
1
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
github.com/docker/docker@v28.3.3+incompatible
no fix listed
1
public.ecr.aws/n8h5y2v5/rad-security/rad-sbom:v1.1.34e97e0e7a2088
github.com/docker/docker@v27.1.2+incompatible
no fix listed
1
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
github.com/docker/docker@v27.2.1+incompatible
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/docker/docker@v20.10.12+incompatible
no fix listed
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
github.com/docker/docker@v25.0.6+incompatible
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
github.com/docker/docker@v24.0.0+incompatible
no fix listed
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
github.com/docker/docker@v20.10.14+incompatible
no fix listed
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/docker/docker@v20.10.3+incompatible
no fix listed
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/docker/docker@v20.10.3+incompatible
no fix listed
1
quay.io/codefresh/dind:3.0.250885ab519dac
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/docker/docker@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
no fix listed
1
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
github.com/docker/docker@v20.10.2+incompatible
no fix listed
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
github.com/docker/docker@v24.0.2+incompatible
no fix listed
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/docker/docker@v25.0.6+incompatible
no fix listed
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
github.com/docker/docker@v1.4.2-0.20191121165722-d1d5f6476656
no fix listed
1
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
github.com/docker/docker@v20.10.8+incompatible
no fix listed
1
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
github.com/docker/docker@v23.0.3+incompatible
no fix listed
1
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
github.com/docker/docker@v20.10.12+incompatible
no fix listed
1
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
github.com/docker/docker@v20.10.12+incompatible
no fix listed
1
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
github.com/docker/docker@v0.7.3-0.20190327010347-be7ac8be2ae0
no fix listed
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/docker/docker@v23.0.3+incompatible
no fix listed
1
quay.io/kube-ops/promtail:2.2.134de6387233b
github.com/docker/docker@v20.10.1+incompatible
no fix listed
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
quay.io/kubescape/kubescape:v4.0.1358651dce3376
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/kubescape/kubevuln:v0.3.4309bed2f723ea0
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
github.com/docker/docker@v28.5.2+incompatible
github.com/moby/moby@v28.5.2+incompatible
no fix listed
no fix listed
1
quay.io/kubescape/operator:v0.2.16901b2694425e9
github.com/docker/docker@v28.5.2+incompatible
github.com/moby/moby@v28.5.2+incompatible
no fix listed
no fix listed
1
quay.io/kubescape/storage:v0.0.33101f2b053ace1
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
quay.io/mittwald/harbor-operator:v1.6.365a38180e27a
github.com/docker/docker@v24.0.9+incompatible
no fix listed
1
quay.io/nuclio/dashboard:1.17.8-amd64b5f5bd4efbee
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
github.com/docker/docker@v20.10.12+incompatible
no fix listed
1
quay.io/openshift/origin-cli:4.66722d5041b47
github.com/docker/docker@v1.4.2-0.20191121165722-d1d5f6476656
no fix listed
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
no fix listed
1
quay.io/openshift/origin-jenkins-agent-base:latestc241c971aef8
github.com/docker/docker@v24.0.7+incompatible
no fix listed
1
quay.io/operator-framework/catalogd:v1.8.06ff40fa6257f
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/operator-framework/olm1b6002156f56
github.com/docker/docker@v24.0.7+incompatible
no fix listed
1
quay.io/operator-framework/olm40d0363f4aa6
github.com/docker/docker@v25.0.5+incompatible
no fix listed
1
quay.io/operator-framework/olmf9ea8cef95ac
github.com/docker/docker@v20.10.21+incompatible
no fix listed
1
quay.io/operator-framework/operator-controller:v1.8.0bca5dfcc67ca
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/opstree/grafana:12.4.3b61c1ed2f015
github.com/moby/moby@v28.0.1+incompatible
no fix listed
1
quay.io/prometheus/prometheus:v3.0.03b9b2a15d376
github.com/docker/docker@v27.3.1+incompatible
no fix listed
1
quay.io/prometheus/prometheus:v2.39.14748e26f9369
github.com/docker/docker@v20.10.18+incompatible
no fix listed
1
quay.io/prometheus/prometheus:v2.37.056e7f18e05dd
github.com/docker/docker@v20.10.17+incompatible
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.