StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,971
of 17,787 indexed, latest versions
Container images
2,112
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,971 of 17,787 indexed charts deploy, on 2,112 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,806
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0294
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,971 by stars
ChartLatestAffected imagesRadar Score
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

10,701
jdownloader2jdownloader2Verified publisher1.10.01 of 1See more

jdownloader2 jdownloader2 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jlesage/jdownloader-2:v26.03.13d6cb102bd9b
xz@5.6.2-r1
5.8.3-r0

Open the chart page →

539
jellyfinjellyfinVerified publisher0.3.301 of 1See more

jellyfin jellyfin 0.3.30

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/jellyfin/jellyfin:10.11.1145f648c382a0
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,604
jenkinsjkimVerified publisher5.5.142 of 2See more

jenkins jkim 5.5.14

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
kiwigrid/k8s-sidecar:1.27.6db85bd553253
xz@5.6.2-r0
5.8.3-r0

Open the chart page →

7,387
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.322 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

2 of the 17 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
grafana/alloy:v1.14.0f50931848bd8
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

15,418
ombik8s-home-lab-repo12.2.11 of 1See more

ombi k8s-home-lab-repo 12.2.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/ombi:4.53.50caadf03b804
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

1,421
tautullik8s-home-lab-repo12.3.01 of 1See more

tautulli k8s-home-lab-repo 12.3.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/home-operations/tautulli:2.17.12183820d45a1
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

1,129
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.03 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

3 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
kafkakraft/kafka-controller:3.7.0f261ad288fce
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
kafkakraft/kafkakraft:3.7.02e4b593b878b
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

14,130
kdiffkdiff-snapshotsVerified publisher0.0.2031 of 2See more

kdiff kdiff-snapshots 0.0.203

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,508
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,789
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,228
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

5,264
nginx-php-fpmkokuwa0.1.42 of 2See more

nginx-php-fpm kokuwa 0.1.4

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/php:8.5.2-fpm-alpine3.22a2482c398d60
xz@5.8.1-r0
5.8.3-r0
nginxinc/nginx-unprivileged:1.29.0-alpine3.2282dcf28da5a8
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,838
difykubeblocksVerified publisher0.5.12 of 5See more

dify kubeblocks 0.5.1

2 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
langgenius/dify-sandbox:0.2.009b7e8705673
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

20,403
pgbouncerkubernetes-helm-chart-pgbouncer1.0.151 of 1See more

pgbouncer kubernetes-helm-chart-pgbouncer 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
cradlepoint/pgbouncer:1.0.18f5720b0cd03
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

5,802
owncloudkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

owncloud kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
owncloud/server:10.16.274c53d341076
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

9,858
kubeseal-webguikubeseal-webgui6.0.42 of 2See more

kubeseal-webgui kubeseal-webgui 6.0.4

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
xz-utils@5.4.1-1
5.4.1-1+deb12u1
ghcr.io/jaydee94/kubeseal-webgui/ui:4.5.34447636e8102
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

4,095
kubesendkubesend0.1.91 of 1See more

kubesend kubesend 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
v3xl/kubesend:0.1.06f62ca96be82
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

1,374
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

7,710
kuma-ingress-watcherkuma-ingress-watcherVerified publisher1.4.01 of 1See more

kuma-ingress-watcher kuma-ingress-watcher 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

2,662
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

12,422
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

113,791
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

5,654
lagoon-remotelagoon-chartsVerified publisher0.106.01 of 1See more

lagoon-remote lagoon-charts 0.106.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

2,113
langflow-idelangflow0.1.22 of 2See more

langflow-ide langflow 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
langflowai/langflow:latest65796601f3fc
xz@1:5.6.2-4.el10_0
1:5.6.2-4.el10_2.1
langflowai/langflow-frontend:latest54f67f1961fe
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,980
langflow-runtimelangflow0.1.11 of 1See more

langflow-runtime langflow 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
langflowai/langflow:latest65796601f3fc
xz@1:5.6.2-4.el10_0
1:5.6.2-4.el10_2.1

Open the chart page →

144
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

35,050
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

4,418
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

7,874
clickhouseliwenhe1.0.11 of 3See more

clickhouse liwenhe 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.14ccf9c2b5e3f2
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

6,761
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

7,201
locustlocustVerified publisher0.1.41 of 1See more

locust locust 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
hansehe/locust:1.1.0bc8e45262bc4
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

2,757
voice-biometricslumenvox2.0.112 of 26See more

voice-biometrics lumenvox 2.0.1

12 of the 26 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-assure-identity:2.0.0147854a3c916
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-audit:2.0.079428add7f38
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-binary-storage:2.0.053decadc102d
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-deployment:2.0.0ea8110886d38
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-management-api:2.0.0b9a23345eabd
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-reporting:2.0.07a9ffdc2178a
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-reporting-api:2.0.0dbbaf5462ad6
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-transaction:2.0.08b74f9d3ba09
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-voice-verifier:2.0.014170ad34903
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

70,741
dnsbl-exporterluzillaVerified publisher0.5.01 of 2See more

dnsbl-exporter luzilla 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/luzilla/unbound:v0.12.04fd8da9dc13c
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

1,146
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,734
magentomagento3.2.32 of 12See more

magento magento 3.2.3

2 of the 12 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
library/rabbitmq:4.1.0-management935b3f84c1e4
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

13,479
plane-enterprisemakeplaneOfficialVerified publisher3.7.22See more

plane-enterprise makeplane 3.7.2

2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
xz@5.6.1-r3
5.8.3-r0
library/rabbitmq:3.13.6-management-alpine611107e29cce
xz@5.6.2-r0
5.8.3-r0

Open the chart page →

maptiler-servermaptilerOfficialVerified publisher1.3.01 of 1See more

maptiler-server maptiler 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
maptiler/server:4.8.07e206140057b
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

2,975
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

19,187
mcpmcp-chartsVerified publisher0.0.232 of 7See more

mcp mcp-charts 0.0.23

2 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

6,929
jellyfinmedia-servarrVerified publisher0.16.01 of 2See more

jellyfin media-servarr 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,753
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

4,137
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
xz-utils@5.8.1-1build2
5.8.1-1ubuntu0.1

Open the chart page →

11,103
model-manager-loadermodel-manager-loader1.27.01 of 1See more

model-manager-loader model-manager-loader 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,680
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

13,738
redminemt1905027.3.41 of 3See more

redmine mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/redmine:6.1.204ac44a2595b
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

7,527
n3uronn3uronVerified publisher0.3.51 of 1See more

n3uron n3uron 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
n3uronhub/n3uron:v1.22.4423a0bdd9cb9
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

1,879
satisfactorynaj981.1.11 of 1See more

satisfactory naj98 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.1199be1064b18
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

3,689
clowder2ncsaVerified publisher1.9.76 of 12See more

clowder2 ncsa 1.9.7

6 of the 12 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
xz-utils@5.4.1-1
5.4.1-1+deb12u1
clowder/clowder2-frontend:2.0.0-beta.4fe97882672ca
xz@5.8.1-r0
5.8.3-r0
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
xz-utils@5.4.1-1
5.4.1-1+deb12u1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

37,373
helm-composenousefreakVerified publisher0.1.31 of 2See more

helm-compose nousefreak 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mariadb:10.8.2-focal490f01279be1
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

14,250

Container images carrying it

2,112 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
bitnamilegacy/redis-sentinel:8.2.1-debian-12-r00ca3ea1d2f82
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnamilegacy/valkey:latest0384ca2eec63
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnamilegacy/valkey:8.1.3-debian-12-r34f0191fba7d3
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnamilegacy/valkey:8.1.3-debian-12-r1a185655855b3
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnami/mariadb:11.7.216a7dae804fb
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
bitnami/memcached:1.6.38dd8f2cba9a5b
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnami/mongodb:8.0.8b3bd5b6be9a0
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
bitnami/redis:7.4.24e65bf641805
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
blackducksoftware/blackduck-alert-db:8.4.06310fac39d53
xz@5.8.2-r0
5.8.3-r0
1
blakeblackshear/frigate:0.10.0-amd64ae269270ad9e
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
blockstream/bitcoind:27.29472492530e3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
bmeares/meerschaum:2.8.48e9c5bacaa82
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
bnjbvr/kresus:0.22.137e216b182c8
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
boky/postfix:5.1.0aafc77238423
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
boky/postfix:4.4.0f3f247fd4252
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
boxcutter/meshcmd:1.1.384e13f01bcab
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
btcpayserver/tor:0.4.8.10e9585b68dc6b
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
budibase/database:2.1.0d90f656261c9
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
calltelemetry/web:0.8.1-rc7205d13269e350
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
camunda/camunda-bpm-platform:latestbcc5bb0542df
xz@5.8.1-r0
5.8.3-r0
1
camunda/zeebe:8.4.5ab5abc09e407
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
carlosmz87/test_helm_frontend:latest79f4b528f42a
xz@5.6.2-r0
5.8.3-r0
1
castlemock/castlemock:latestb7f3f1527ba9
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
1
castopod/castopod:1.12.101fd37280cbb2
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
castopod/castopod:1.15.54e4f0440520f
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
cfcontainerization/cf-operator:v2.3.0-0.g27a91cdf82fa261c18a8
xz@5.2.3-lp151.4.3.1
5.8.3-1.1
1
cfcontainerization/quarks-job:v0.0.0-0.g70ae34b58fb1c173a46
xz@5.2.3-lp151.4.3.1
5.8.3-1.1
1
chaerr/kridge:demo-operator-v0.1.266833deec017
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
chandanteekinavar/findery-market-frontend:1.06de5bd44a325
xz@5.6.3-r0
5.8.3-r0
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2
1
chetangautamm/repo:sipp.v3e7f7049e1544
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
cheveo/azp-agent:1.0.282240f890884
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
cheyang/distributed-tf:1.6.046cc34755493
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
xz@5.8.1-r0
5.8.3-r0
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
chocobozzz/peertube:v8.1.5052712130691
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
chriseaton/adventureworks:latest54c3384ce701
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
chromadb/chroma:1.5.7fc8dc8e11fb2
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
circleci/runner:launch-agent9bdc62f02162
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
ciscolabs/msm-nc:0710202336d02faad958
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
citizenstig/httpbin:latestb81c818ccb86
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
ciuse99/suggestarr:v1.0.20d72768245ef5
xz@5.6.3-r0
5.8.3-r0
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.