StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,977
of 17,781 indexed, latest versions
Container images
2,118
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,977 of 17,781 indexed charts deploy, on 2,118 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,811
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0295
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,977 by stars
ChartLatestAffected imagesRadar Score
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,240
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,987
pypiservercommunity-chartsVerified publisher0.1.91 of 1See more

pypiserver community-charts 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
pypiserver/pypiserver:v2.4.1e935e19433ef
xz@5.6.2-r1
5.8.3-r0

Open the chart page →

584
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

12,746
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

2,993
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

8,390
litellm-helmlitellm1.100.11 of 2See more

litellm-helm litellm 1.100.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,003
openclawopenclaw-helmVerified publisher1.5.402 of 2See more

openclaw openclaw-helm 1.5.40

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,660
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,382
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

15,592
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

7,880
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
xz@5.6.3-r0
5.8.3-r0

Open the chart page →

1,023
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

11,933
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,352
plane-cemakeplaneOfficialVerified publisher1.8.12 of 11See more

plane-ce makeplane 1.8.1

2 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
xz@5.6.1-r3
5.8.3-r0
library/rabbitmq:3.13.6-management-alpine611107e29cce
xz@5.6.2-r0
5.8.3-r0

Open the chart page →

4,854
milvusmilvus-helm5.0.272 of 4See more

milvus milvus-helm 5.0.27

2 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
milvusdb/etcd:3.5.25-r1fededb2f2d63
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

10,670
prefect-serverprefectVerified publisher2026.9.32126051 of 2See more

prefect-server prefect 2026.9.3212605

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,786
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

6,328
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

18,509
codefreshcodefresh-onpremOfficialVerified publisher2.12.134 of 42See more

codefresh codefresh-onprem 2.12.13

4 of the 42 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/rabbitmq:4.1.39e635efba431
xz-utils@5.4.1-1
5.4.1-1+deb12u1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

14,956
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2api:3.86f56d239d280
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2auth:3.833ecfda16608
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2notifier:3.8f190a6212195
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2rulesengine:3.8259503496ff9
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2scheduler:3.8b1de2055c362
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2sensorcontainer:3.8b1a338f64773
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2stream:3.81c8904a3bf67
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2timersengine:3.81bf35bfaf00c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2web:3.809989a26c8b7
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2workflowengine:3.819fdfffdbba8
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

96,419
supabasetokens-studioVerified publisher1.0.06 of 14See more

supabase tokens-studio 1.0.0

6 of the 14 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
supabase/edge-runtime:v1.59.0eff9c554d649
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/postgres-meta:v0.84.2d0a96973e9f1
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/realtime:v2.33.8d207e6e23ad3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/storage-api:v1.12.0f983fb50bd95
xz@5.6.2-r0
5.8.3-r0
supabase/studio:20241021-9f9b08326d8070c55e9
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

23,123
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,493
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

10,775
krokicowboysysopVerified publisher6.1.04 of 5See more

kroki cowboysysop 6.1.0

4 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.29.1444805c4b917
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-excalidraw:0.29.157917319ea70
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

6,743
excalidrawexcalidrawVerified publisher0.18.01 of 1See more

excalidraw excalidraw 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
pmoscode/excalidraw:v0.18.08ee61554699c
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,109
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

3,454
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,025
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

7,857
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

1,240
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

3,480
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

11,405
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,938
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

4,244
camunda-bpm-platformcamunda-community-hub7.6.111 of 1See more

camunda-bpm-platform camunda-community-hub 7.6.11

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
camunda/camunda-bpm-platform:latestbcc5bb0542df
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,154
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,012
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/postgres:14.91b594392f7cb
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

32,902
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,606
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,357
ilumilumOfficialVerified publisher6.7.35 of 19See more

ilum ilum 6.7.3

5 of the 19 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/postgresql:16233f361c5819
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
gitea/gitea:1.22.376f516a1a8c2
xz@5.6.2-r0
5.8.3-r0
ilum/api:6.7.3624fd09528c8
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ilum/marquez:0.54.06e1d709d41f8
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

23,228
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,395
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

7,007
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

5,634
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

4,332
netris-controllernetrisai2.8.25 of 14See more

netris-controller netrisai 2.8.2

5 of the 14 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-telescope:4.6.0.00414d82948a8b2
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-web-service-frontend:4.6.0-0138c5074f55ae5
xz@5.8.2-r0
5.8.3-r0
netrisai/controller-web-session-generator:0.2.0a030a31289f4
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

30,326
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,244
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

17,245
paperless-ngxpaperless-ngxVerified publisher0.3.221 of 3See more

paperless-ngx paperless-ngx 0.3.22

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,489
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/api-gateway:latest40a4970de568
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/customers-service:latest2089811e5cc6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/vets-service:latestd1165c94dfb3
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/visits-service:latest8d11b50368c6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

41,872
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

14,184

Container images carrying it

2,118 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/redis-cluster:7.4.3-debian-12-r0a53d023fdfaf
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
bitnamilegacy/redis-sentinel:8.2.1-debian-12-r00ca3ea1d2f82
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnamilegacy/valkey:latest0384ca2eec63
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnamilegacy/valkey:8.1.3-debian-12-r34f0191fba7d3
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnamilegacy/valkey:8.1.3-debian-12-r1a185655855b3
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnami/mariadb:11.7.216a7dae804fb
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
bitnami/memcached:1.6.38dd8f2cba9a5b
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnami/mongodb:8.0.8b3bd5b6be9a0
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnami/redis:7.4.24e65bf641805
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
blackducksoftware/blackduck-alert-db:8.4.06310fac39d53
xz@5.8.2-r0
5.8.3-r0
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
blockstream/bitcoind:27.29472492530e3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
bmeares/meerschaum:2.8.48e9c5bacaa82
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
bnjbvr/kresus:0.22.137e216b182c8
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
boky/postfix:5.1.0aafc77238423
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
boky/postfix:4.4.0f3f247fd4252
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
boxcutter/meshcmd:1.1.384e13f01bcab
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
btcpayserver/tor:0.4.8.10e9585b68dc6b
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
budibase/database:2.1.0d90f656261c9
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
calltelemetry/web:0.8.1-rc7205d13269e350
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
camunda/camunda-bpm-platform:latestbcc5bb0542df
xz@5.8.1-r0
5.8.3-r0
1
camunda/zeebe:8.4.5ab5abc09e407
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
carlosmz87/test_helm_frontend:latest79f4b528f42a
xz@5.6.2-r0
5.8.3-r0
1
castlemock/castlemock:latestb7f3f1527ba9
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
1
castopod/castopod:1.12.101fd37280cbb2
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
castopod/castopod:1.15.54e4f0440520f
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
xz@5.2.3-lp151.4.3.1
5.8.3-1.1
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
xz@5.2.3-lp151.4.3.1
5.8.3-1.1
1
chaerr/kridge:demo-operator-v0.1.266833deec017
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
chandanteekinavar/findery-market-frontend:1.06de5bd44a325
xz@5.6.3-r0
5.8.3-r0
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2
1
chetangautamm/repo:sipp.v3e7f7049e1544
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
cheveo/azp-agent:1.0.282240f890884
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
cheyang/distributed-tf:1.6.046cc34755493
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
xz@5.8.1-r0
5.8.3-r0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
chocobozzz/peertube:v8.1.5052712130691
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
chriseaton/adventureworks:latest54c3384ce701
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
chromadb/chroma:1.5.7fc8dc8e11fb2
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
circleci/runner:launch-agent9bdc62f02162
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
ciscolabs/msm-nc:0710202336d02faad958
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
citizenstig/httpbin:latestb81c818ccb86
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
ciuse99/suggestarr:v1.0.20d72768245ef5
xz@5.6.3-r0
5.8.3-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.