StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,977
of 17,781 indexed, latest versions
Container images
2,118
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,977 of 17,781 indexed charts deploy, on 2,118 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,811
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0295
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,977 by stars
ChartLatestAffected imagesRadar Score
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,240
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,987
pypiservercommunity-chartsVerified publisher0.1.91 of 1See more

pypiserver community-charts 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
pypiserver/pypiserver:v2.4.1e935e19433ef
xz@5.6.2-r1
5.8.3-r0

Open the chart page →

584
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

12,746
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

2,993
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

8,390
litellm-helmlitellm1.100.11 of 2See more

litellm-helm litellm 1.100.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,003
openclawopenclaw-helmVerified publisher1.5.402 of 2See more

openclaw openclaw-helm 1.5.40

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,660
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,382
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

15,592
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

7,880
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
xz@5.6.3-r0
5.8.3-r0

Open the chart page →

1,023
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

11,933
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,352
plane-cemakeplaneOfficialVerified publisher1.8.12 of 11See more

plane-ce makeplane 1.8.1

2 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
xz@5.6.1-r3
5.8.3-r0
library/rabbitmq:3.13.6-management-alpine611107e29cce
xz@5.6.2-r0
5.8.3-r0

Open the chart page →

4,854
milvusmilvus-helm5.0.272 of 4See more

milvus milvus-helm 5.0.27

2 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
milvusdb/etcd:3.5.25-r1fededb2f2d63
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

10,670
prefect-serverprefectVerified publisher2026.9.32126051 of 2See more

prefect-server prefect 2026.9.3212605

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,786
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

6,328
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

18,509
codefreshcodefresh-onpremOfficialVerified publisher2.12.134 of 42See more

codefresh codefresh-onprem 2.12.13

4 of the 42 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/rabbitmq:4.1.39e635efba431
xz-utils@5.4.1-1
5.4.1-1+deb12u1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

14,956
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2api:3.86f56d239d280
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2auth:3.833ecfda16608
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2notifier:3.8f190a6212195
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2rulesengine:3.8259503496ff9
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2scheduler:3.8b1de2055c362
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2sensorcontainer:3.8b1a338f64773
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2stream:3.81c8904a3bf67
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2timersengine:3.81bf35bfaf00c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2web:3.809989a26c8b7
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2workflowengine:3.819fdfffdbba8
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

96,419
supabasetokens-studioVerified publisher1.0.06 of 14See more

supabase tokens-studio 1.0.0

6 of the 14 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
supabase/edge-runtime:v1.59.0eff9c554d649
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/postgres-meta:v0.84.2d0a96973e9f1
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/realtime:v2.33.8d207e6e23ad3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/storage-api:v1.12.0f983fb50bd95
xz@5.6.2-r0
5.8.3-r0
supabase/studio:20241021-9f9b08326d8070c55e9
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

23,123
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,493
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

10,775
krokicowboysysopVerified publisher6.1.04 of 5See more

kroki cowboysysop 6.1.0

4 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.29.1444805c4b917
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-excalidraw:0.29.157917319ea70
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

6,743
excalidrawexcalidrawVerified publisher0.18.01 of 1See more

excalidraw excalidraw 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
pmoscode/excalidraw:v0.18.08ee61554699c
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,109
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

3,454
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,025
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

7,857
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

1,240
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

3,480
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

11,405
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,938
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

4,244
camunda-bpm-platformcamunda-community-hub7.6.111 of 1See more

camunda-bpm-platform camunda-community-hub 7.6.11

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
camunda/camunda-bpm-platform:latestbcc5bb0542df
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,154
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,012
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/postgres:14.91b594392f7cb
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

32,902
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,606
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,357
ilumilumOfficialVerified publisher6.7.35 of 19See more

ilum ilum 6.7.3

5 of the 19 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/postgresql:16233f361c5819
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
gitea/gitea:1.22.376f516a1a8c2
xz@5.6.2-r0
5.8.3-r0
ilum/api:6.7.3624fd09528c8
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ilum/marquez:0.54.06e1d709d41f8
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

23,228
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,395
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

7,007
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

5,634
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

4,332
netris-controllernetrisai2.8.25 of 14See more

netris-controller netrisai 2.8.2

5 of the 14 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-telescope:4.6.0.00414d82948a8b2
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-web-service-frontend:4.6.0-0138c5074f55ae5
xz@5.8.2-r0
5.8.3-r0
netrisai/controller-web-session-generator:0.2.0a030a31289f4
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

30,326
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,244
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

17,245
paperless-ngxpaperless-ngxVerified publisher0.3.221 of 3See more

paperless-ngx paperless-ngx 0.3.22

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,489
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/api-gateway:latest40a4970de568
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/customers-service:latest2089811e5cc6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/vets-service:latestd1165c94dfb3
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/visits-service:latest8d11b50368c6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

41,872
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

14,184

Container images carrying it

2,118 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
dannielkil/book-frontend:latest937993927694
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
darthsim/imgproxy:v3.30.13b709e4a0e5e
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
darthsim/imgproxy:v3.26476cb08c816a
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
daskdev/dask-notebook:1.1.0052630f5ca04
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
datadog/agent:6aad9994de6a7
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
1
datafuselabs/databend-meta:v1.2.279ba877ee6cb4d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
datafuselabs/databend-query:v1.2.279a936843b85b4
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
datalayers/datalayers:v2.2.1017b292079239
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
datalust/seq:5.0.832-pre9c731bb207a6
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
datalust/seq-input-gelf:3.0.441-x643de34aed5642
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
datamate/seafile-professional:11.0.202dd66b722464
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
davidy/giphy-app:1.0.2-arm41b2355cc23a
xz@5.6.2-r0
5.8.3-r0
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
ddosify/alaz:v0.12.0ea602056d9ce
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ddosify/selfhosted_backend:3.2.93c11e3182652
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
deconzcommunity/deconz:2.29.2062de2362641
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
defactops/defactops-backend:1.0.2307b663c0092a
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
dellcloud/category:distributed02fc234353a9
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
dellcloud/pages:1.04d2eb25b9225
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
deluan/navidrome:0.61.29fa40b3d8dec
xz@5.6.2-r1
5.8.3-r0
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
dependencytrack/frontend:4.14.200560b57a6cf
xz@5.8.2-r0
5.8.3-r0
1
devopsgoofy/k8s-platform:latestad865312099f
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
devopstales/kubedash:3.1.08bb837da5aec
xz@5.6.2-r1
5.8.3-r0
1
dgraph/dgraph:v24.1.4b57fa31f9b7f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
diygod/rsshub:2025-11-097a6312cac0d5
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
djjudas21/alertify:0.1.0ba22be670c37
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
djjudas21/bearhugmugs:0.1.14fa898a52d97
xz@5.6.2-r0
5.8.3-r0
1
djjudas21/ecowitt-exporter:2.2.073aab45ef10d
xz@5.8.1-r0
5.8.3-r0
1
djjudas21/liturgical-colour-app:0.7.2954935971d42
xz@5.8.1-r0
5.8.3-r0
1
djjudas21/nova-exporter:0.0.10e9094580885c
xz@5.8.1-r0
5.8.3-r0
1
dniel/api-posts:master45a667852f2a
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
1
dobtc/bitcoin:25.1a870f7cb1105
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
docmost/docmost:0.95.041c8d777cf23
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
docuseal/docuseal:2.4.17493fd7f6728
xz@5.8.2-r0
5.8.3-r0
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
domainmod/domainmod:4.23.04017bfe4c597
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
dpage/pgadmin4:9.11.050700ac17936
xz@5.8.1-r0
5.8.3-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.