StackRadar

CVE-2026-33997

High

Advisory

Published 27 Mar 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.004
32nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
573
of 17,787 indexed, latest versions
Container images
567
deployed by those charts
Fix available
1 of 3
affected packages

Moby has an Off-by-one error in its plugin privilege validation

Carried by container images the latest versions of 573 of 17,787 indexed charts deploy, on 567 images.

Affected packageAffected versionsFixed inImages
docker.iodeb20.10.24+dfsg1-1+deb12u1+b6, 26.1.5+dfsg1-9+b1326.1.5+dfsg1-9+deb13u12
github.com/docker/dockergolangv0.0.0-20180620051407-e2593239d949, v0.7.3-0.20190327010347-be7ac8be2ae0, v1.4.2-0.20190924003213-a8608b5b67c7, v1.4.2-0.20191121165722-d1d5f6476656+84 moreno fix listed542
github.com/moby/mobygolangv0.7.3-0.20190826074503-38ab9da00309, v1.4.2-0.20170731201646-1009e6a40b29, v1.13.1, v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible+4 moreno fix listed30
OSV records
DEBIAN-CVE-2026-33997GHSA-pxq6-2prw-chj9
Also known as
GO-2026-4883

Charts affected

573 by stars
ChartLatestAffected imagesRadar Score
retromretsamedocVerified publisher2026.2.51 of 1See more

retrom retsamedoc 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
ghcr.io/jmberesford/retrom-service:retrom-v0.7.144d763d58f11d
github.com/docker/docker@v27.1.2+incompatible
no fix listed

Open the chart page →

7,084
review-componentreview-component1.0.01 of 3See more

review-component review-component 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/review-component-php:latestafe623824b82
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,491
krr-enforcerrobusta0.3.51 of 2See more

krr-enforcer robusta 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
alpine/k8s:1.30.0bd01dae02676
github.com/docker/docker@v20.10.24+incompatible
no fix listed

Open the chart page →

4,038
gitlab-operatorrock8sVerified publisher0.7.01 of 2See more

gitlab-operator rock8s 0.7.0

1 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
github.com/docker/docker@v17.12.1-ce+incompatible
no fix listed

Open the chart page →

5,422
mailserverrock8sVerified publisher0.1.21 of 1See more

mailserver rock8s 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
github.com/docker/docker@v24.0.6+incompatible
no fix listed

Open the chart page →

1,946
monitoringrocketchat-server0.0.171 of 9See more

monitoring rocketchat-server 0.0.17

1 of the 9 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.143.03bc07732530c
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

6,859
ai-agentromholdings0.0.11 of 1See more

ai-agent romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/devtron/ai-agent:0.0.16545dac92173
github.com/docker/docker@v27.1.1+incompatible
no fix listed

Open the chart page →

9,607
argocdromholdings1.8.11 of 3See more

argocd romholdings 1.8.1

1 of the 3 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
argoproj/argocd:v1.8.1830e86cacefd
github.com/docker/docker@v0.7.3-0.20190327010347-be7ac8be2ae0
no fix listed

Open the chart page →

10,466
argocd-certificate-refreshromholdings0.10.81 of 1See more

argocd-certificate-refresh romholdings 0.10.8

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
github.com/docker/docker@v20.10.17+incompatible
no fix listed

Open the chart page →

12,949
argo-workflowromholdings0.1.61 of 1See more

argo-workflow romholdings 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/argoproj/workflow-controller:v3.4.7f0c6fba81a24
github.com/docker/docker@v20.10.24+incompatible
no fix listed

Open the chart page →

1,580
clairromholdings0.1.141 of 2See more

clair romholdings 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/devtron/clair:4.3.675fb847ac045
github.com/docker/docker@v20.10.7+incompatible
no fix listed

Open the chart page →

6,237
devtron-enterpriseromholdings48.0.02 of 28See more

devtron-enterprise romholdings 48.0.0

2 of the 28 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:94237c18-109-3942098580969b333
github.com/docker/docker@v24.0.5+incompatible
no fix listed
quay.io/devtron/kubectl:latest2ad610626658
github.com/docker/docker@v20.10.17+incompatible
no fix listed

Open the chart page →

68,240
devtron-operatorromholdings0.23.31 of 11See more

devtron-operator romholdings 0.23.3

1 of the 11 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/devtron/kubectl:latest2ad610626658
github.com/docker/docker@v20.10.17+incompatible
no fix listed

Open the chart page →

32,902
securityromholdings0.2.21 of 1See more

security romholdings 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/devtron/image-scanner:b278f42b-334-1111988c64b1b6ec8
github.com/docker/docker@v20.10.7+incompatible
no fix listed

Open the chart page →

2,435
spindlerubxkubeVerified publisher0.1.12 of 2See more

spindle rubxkube 0.1.1

2 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
library/docker:29.7.2-dind3ef33f2e220b
github.com/docker/docker@v28.5.2+incompatible
no fix listed
ghcr.io/qjoly/spindle:v1.16.1-alphaaab0c99d313f
github.com/docker/docker@v28.2.2+incompatible
no fix listed

Open the chart page →

1,438
harborsb-helm-charts0.3.01 of 2See more

harbor sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
goharbor/harbor-core:v2.11.1c017dd84ee96
github.com/docker/docker@v24.0.9+incompatible
no fix listed

Open the chart page →

1,680
opentelemetry-collectorsb-helm-charts0.3.01 of 1See more

opentelemetry-collector sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/docker/docker@v24.0.9+incompatible
no fix listed

Open the chart page →

1,721
promtailsb-helm-charts0.4.01 of 1See more

promtail sb-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
grafana/promtail:3.6.18dcfdf466da0
github.com/docker/docker@v28.5.0+incompatible
no fix listed

Open the chart page →

2,202
ed-traefik2scaleway-charts0.2.01 of 1See more

ed-traefik2 scaleway-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
library/traefik:2.5.62f603f8d3abe
github.com/docker/docker@v20.10.7+incompatible
no fix listed

Open the chart page →

3,160
centralbrainsciencemeshVerified publisher0.0.31 of 5See more

centralbrain sciencemesh 0.0.3

1 of the 5 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.22.1b899dbd1b901
github.com/docker/docker@v17.12.0-ce-rc1.0.20200706150819-a40b877fbb9e+incompatible
no fix listed

Open the chart page →

9,754
semaphoresemaphore-light1.0.01 of 1See more

semaphore semaphore-light 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
semaphoreui/semaphore:latest3996804607eb
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

1,674
ccx-monitoringseveralnines0.6.211 of 7See more

ccx-monitoring severalnines 0.6.21

1 of the 7 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
grafana/grafana:12.3.12175aaa91c96
github.com/moby/moby@v27.5.1+incompatible
no fix listed

Open the chart page →

7,708
loggensikalabs0.1.01 of 1See more

loggen sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
sikalabs/slu:v0.72.07bd267f30247
github.com/docker/docker@v24.0.7+incompatible
no fix listed

Open the chart page →

2,314
olmsikalabs0.3.01 of 2See more

olm sikalabs 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/operator-framework/olmdigest-pinned40d0363f4aa6
github.com/docker/docker@v25.0.5+incompatible
no fix listed

Open the chart page →

1,146
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
github.com/docker/docker@v27.1.0+incompatible
no fix listed

Open the chart page →

2,429
network-observerskupper-network-observerVerified publisher2.2.21 of 3See more

network-observer skupper-network-observer 2.2.2

1 of the 3 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v3.11.3c0b857aead0d
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

601
skypilot-prometheus-serverskypilotVerified publisher0.11.11 of 3See more

skypilot-prometheus-server skypilot 0.11.1

1 of the 3 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v3.4.19abc6cf6aea7
github.com/docker/docker@v28.1.1+incompatible
no fix listed

Open the chart page →

2,344
gitlab-runnerslamdev0.0.11 of 1See more

gitlab-runner slamdev 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
github.com/docker/docker@v20.10.12+incompatible
no fix listed

Open the chart page →

9,196
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
github.com/docker/docker@v20.10.7+incompatible
no fix listed

Open the chart page →

3,462
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v3.2.16927e0919a14
github.com/docker/docker@v27.4.1+incompatible
no fix listed

Open the chart page →

7,901
harborsoftonic1.13.01 of 8See more

harbor softonic 1.13.0

1 of the 8 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
goharbor/trivy-adapter-photon:v2.9.0dc5b882a7db4
github.com/docker/docker@v23.0.7-0.20230714215826-f00e7af96042+incompatible
no fix listed

Open the chart page →

7,672
kube-prometheus-stacksoftonic81.5.11 of 6See more

kube-prometheus-stack softonic 81.5.1

1 of the 6 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
grafana/grafana:12.3.2ba93c9d192e5
github.com/moby/moby@v27.5.1+incompatible
no fix listed

Open the chart page →

4,974
trivy-operatorsoftonic0.18.01 of 1See more

trivy-operator softonic 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
ghcr.io/aquasecurity/trivy-operator:0.16.0a608b798fda5
github.com/docker/docker@v24.0.5+incompatible
no fix listed

Open the chart page →

2,505
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
github.com/docker/docker@v20.10.12+incompatible
no fix listed

Open the chart page →

30,687
datadogspartan0.1.01 of 1See more

datadog spartan 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
gcr.io/datadoghq/cluster-agent:7.61.06efe04ba4e06
github.com/docker/docker@v27.3.1+incompatible
no fix listed

Open the chart page →

3,232
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/docker/docker@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
no fix listed

Open the chart page →

28,165
vaultstakaterVerified publisher0.8.41 of 2See more

vault stakater 0.8.4

1 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
github.com/docker/docker@v17.12.0-ce-rc1.0.20200309214505-aa6a9891b09c+incompatible
no fix listed

Open the chart page →

5,864
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
prom/prometheus:v2.52.05c435642ca4d
github.com/docker/docker@v26.0.1+incompatible
no fix listed

Open the chart page →

20,223
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
prom/prometheus:v2.22.2f7ffebdd428b
github.com/docker/docker@v17.12.0-ce-rc1.0.20200706150819-a40b877fbb9e+incompatible
no fix listed

Open the chart page →

16,506
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
github.com/docker/docker@v1.4.2-0.20190924003213-a8608b5b67c7
no fix listed

Open the chart page →

6,596
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
github.com/docker/docker@v23.0.1+incompatible
no fix listed

Open the chart page →

10,134
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/docker/docker@v24.0.7+incompatible
no fix listed

Open the chart page →

1,360
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/docker/docker@v26.1.3+incompatible
no fix listed

Open the chart page →

8,518
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,480
act-runnertektonops0.1.22 of 2See more

act-runner tektonops 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
github.com/docker/docker@v25.0.15+incompatible
no fix listed
library/docker:23.0.6-dindafa5d5134900
github.com/docker/docker@v24.0.6+incompatible
no fix listed

Open the chart page →

4,212
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
github.com/docker/docker@v20.10.6+incompatible
no fix listed

Open the chart page →

3,764
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
github.com/docker/docker@v20.10.9+incompatible
no fix listed

Open the chart page →

21,005
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

7,248
mc-routerthl-chartsVerified publisher0.1.01 of 1See more

mc-router thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
itzg/mc-router:1.16.1bb552b59fb53
github.com/docker/docker@v20.10.17+incompatible
no fix listed

Open the chart page →

1,855
monitoringthl-chartsVerified publisher0.1.12 of 10See more

monitoring thl-charts 0.1.1

2 of the 10 container images this version deploys carry CVE-2026-33997.

Container imageDigestPackageFixed in
grafana/promtail:2.4.2626900031c4e
github.com/docker/docker@v20.10.8+incompatible
no fix listed
quay.io/prometheus/prometheus:v2.34.0b37103e03399
github.com/docker/docker@v20.10.12+incompatible
no fix listed

Open the chart page →

18,908

Container images carrying it

567 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/prometheus/prometheus:v3.5.063805ebb8d2b
github.com/docker/docker@v28.2.2+incompatible
no fix listed
1
quay.io/prometheus/prometheus:v3.2.16927e0919a14
github.com/docker/docker@v27.4.1+incompatible
no fix listed
1
quay.io/prometheus/prometheus:v2.33.591100b06e86d
github.com/docker/docker@v20.10.12+incompatible
no fix listed
1
quay.io/prometheus/prometheus:v3.4.19abc6cf6aea7
github.com/docker/docker@v28.1.1+incompatible
no fix listed
1
quay.io/prometheus/prometheus:v2.34.0b37103e03399
github.com/docker/docker@v20.10.12+incompatible
no fix listed
1
quay.io/prometheus/prometheus:v3.11.3c0b857aead0d
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/prometheus/prometheus:v3.11.2cd37346c9745
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/prometheus/prometheus:v2.53.1f20d3127bf28
github.com/docker/docker@v26.1.3+incompatible
no fix listed
1
quay.io/redhat-appstudio/appstudio-utils:dbbdd82734232e6289e8fbae5b4c858481a7c0577b4202c25b67
github.com/docker/docker@v23.0.5+incompatible
no fix listed
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
github.com/docker/docker@v28.5.1+incompatible
no fix listed
1
quay.io/rht-labs/stack-do500:3.0.86ba82beff18e
github.com/docker/docker@v20.10.3+incompatible
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
no fix listed
no fix listed
1
quay.io/skopeo/stable:v1.134853591bd1d2
github.com/docker/docker@v24.0.2+incompatible
no fix listed
1
quay.io/solo-io/discovery:0.0.0-fork5b62aaade3c9
github.com/moby/moby@v20.10.14+incompatible
no fix listed
1
quay.io/solo-io/gloo:0.0.0-fork9a6c84560d44
github.com/moby/moby@v20.10.14+incompatible
no fix listed
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
github.com/docker/docker@v24.0.6+incompatible
no fix listed
1
registry.gitlab.com/gitlab-org/cloud-native/gitlab-operator:0.5.136b19b72120e
github.com/docker/docker@v17.12.1-ce+incompatible
no fix listed
1
registry.gitlab.com/xrow-public/ci-tools/tools:main9b9d1ed86b6a
github.com/docker/docker@v28.5.1+incompatible
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.