StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,985
of 17,787 indexed, latest versions
Container images
2,125
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,985 of 17,787 indexed charts deploy, on 2,125 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,816
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0297
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,985 by stars
ChartLatestAffected imagesRadar Score
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,278
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

6,012
pypiservercommunity-chartsVerified publisher0.1.91 of 1See more

pypiserver community-charts 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
pypiserver/pypiserver:v2.4.1e935e19433ef
xz@5.6.2-r1
5.8.3-r0

Open the chart page →

583
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

12,830
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,031
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

8,473
litellm-helmlitellm1.101.01 of 2See more

litellm-helm litellm 1.101.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

4,574
openclawopenclaw-helmVerified publisher1.5.402 of 2See more

openclaw openclaw-helm 1.5.40

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,679
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,422
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

15,607
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

7,917
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
xz@5.6.3-r0
5.8.3-r0

Open the chart page →

1,023
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

11,971
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,364
plane-cemakeplaneOfficialVerified publisher1.8.12 of 11See more

plane-ce makeplane 1.8.1

2 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
xz@5.6.1-r3
5.8.3-r0
library/rabbitmq:3.13.6-management-alpine611107e29cce
xz@5.6.2-r0
5.8.3-r0

Open the chart page →

4,854
milvusmilvus-helm5.0.282 of 4See more

milvus milvus-helm 5.0.28

2 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
milvusdb/etcd:3.5.25-r1fededb2f2d63
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

10,764
prefect-serverprefectVerified publisher2026.9.141419101 of 2See more

prefect-server prefect 2026.9.14141910

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,448
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

6,385
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

18,570
codefreshcodefresh-onpremOfficialVerified publisher2.12.134 of 42See more

codefresh codefresh-onprem 2.12.13

4 of the 42 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/rabbitmq:4.1.39e635efba431
xz-utils@5.4.1-1
5.4.1-1+deb12u1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

14,615
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2api:3.86f56d239d280
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2auth:3.833ecfda16608
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2notifier:3.8f190a6212195
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2rulesengine:3.8259503496ff9
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2scheduler:3.8b1de2055c362
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2sensorcontainer:3.8b1a338f64773
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2stream:3.81c8904a3bf67
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2timersengine:3.81bf35bfaf00c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2web:3.809989a26c8b7
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2workflowengine:3.819fdfffdbba8
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

96,984
supabasetokens-studioVerified publisher1.0.06 of 14See more

supabase tokens-studio 1.0.0

6 of the 14 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
supabase/edge-runtime:v1.59.0eff9c554d649
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/postgres-meta:v0.84.2d0a96973e9f1
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/realtime:v2.33.8d207e6e23ad3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/storage-api:v1.12.0f983fb50bd95
xz@5.6.2-r0
5.8.3-r0
supabase/studio:20241021-9f9b08326d8070c55e9
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

23,263
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,530
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

10,810
krokicowboysysopVerified publisher6.1.04 of 5See more

kroki cowboysysop 6.1.0

4 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.29.1444805c4b917
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-excalidraw:0.29.157917319ea70
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

6,743
excalidrawexcalidrawVerified publisher0.18.01 of 1See more

excalidraw excalidraw 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
pmoscode/excalidraw:v0.18.08ee61554699c
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,110
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

3,493
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,037
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

7,896
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

1,279
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

3,492
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

11,453
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,951
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

4,281
camunda-bpm-platformcamunda-community-hub7.6.111 of 1See more

camunda-bpm-platform camunda-community-hub 7.6.11

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
camunda/camunda-bpm-platform:latestbcc5bb0542df
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,154
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,024
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/postgres:14.91b594392f7cb
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

31,447
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,645
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,396
ilumilumOfficialVerified publisher6.7.35 of 19See more

ilum ilum 6.7.3

5 of the 19 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/postgresql:16233f361c5819
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
gitea/gitea:1.22.376f516a1a8c2
xz@5.6.2-r0
5.8.3-r0
ilum/api:6.7.3624fd09528c8
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ilum/marquez:0.54.06e1d709d41f8
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

23,289
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,434
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

7,031
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

5,665
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

4,344
netris-controllernetrisai2.8.25 of 14See more

netris-controller netrisai 2.8.2

5 of the 14 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-telescope:4.6.0.00414d82948a8b2
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-web-service-frontend:4.6.0-0138c5074f55ae5
xz@5.8.2-r0
5.8.3-r0
netrisai/controller-web-session-generator:0.2.0a030a31289f4
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

30,481
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,257
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

17,306
paperless-ngxpaperless-ngxVerified publisher0.3.221 of 3See more

paperless-ngx paperless-ngx 0.3.22

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,510
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/api-gateway:latest40a4970de568
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/customers-service:latest2089811e5cc6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/vets-service:latestd1165c94dfb3
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/visits-service:latest8d11b50368c6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

41,902
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

14,276

Container images carrying it

2,125 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
openthread/otbr:latestf307f59f6432
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
openvino/model_server:2025.2.11e7cd1d70cc1
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
openwhisk/ow-utils:1.0.0c80dba0de3aa
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
1
operaton/operaton:1.0.0-beta-4b35867ffe4d8
xz@5.6.3-r1
5.8.3-r0
1
opsmx11/issuegen:v2.1.05c50ca123d88
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2
1
orbitalreg/orbitalreg-frontend:0.1.04fd449582a3c
xz@5.6.3-r1
5.8.3-r0
1
outlinewiki/outline:0.82.0494dfb9249a6
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
outlinewiki/outline:1.10.1832051f039b4
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
owncloud/ocis:7.1.388e7c854517d
xz@5.6.2-r1
5.8.3-r0
1
owncloud/ocis:8.0.1b38fd8fdd58f
xz@5.8.2-r0
5.8.3-r0
1
owncloud/server:10.15.051d9b74fc2a8
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
owncloud/server:10.16.274c53d341076
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
oxfordsemantic/rdfox:5.6db17910eb855
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
oxfordsemantic/rdfox-init:5.6baf570ff968d
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
pangeo/base-notebook:2024.01.155fbe688a4f80
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
payara/server-full:7.2026.2-jdk2531f1253f0cf8
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
penpotapp/backend:2.2.147853d9bb9dd
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
penpotapp/exporter:2.2.15c835ffd87ab
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
percona/percona-server-mongodb-operator:1.23.0feaff989e253
xz@1:5.6.2-4.el10_0
1:5.6.2-4.el10_2.1
1
peterdavehello/tor-socks-proxy:latest0cc12d36d312
xz@5.8.2-r0
5.8.3-r0
1
phan2410/dummy-service:0.0.89c6ed6de26ca
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
phan2410/falcon-asgi-server:0.1.04a86d138832d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
photoprism/photoprism:220629-jammy2954334adbda
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
photoprism/photoprism:251130db16ee6b1ba3
xz-utils@5.8.1-1build2
5.8.1-1ubuntu0.1
1
photoprism/photoprism:240711-cefc6fd632ca74
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3
1
phpipam/phpipam-cron:v1.7.354468713454e
xz@5.6.2-r0
5.8.3-r0
1
phpipam/phpipam-www:v1.7.3ace0efd24830
xz@5.6.2-r0
5.8.3-r0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
pk910/powfaucet:v2-stable3dcae6a62896
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
platform9community/admin-server:latestde3fa9b70df1
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
1
platform9community/api-gateway:latest40a4970de568
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
1
platform9community/customers-service:latest2089811e5cc6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
1
platform9community/vets-service:latestd1165c94dfb3
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
1
platform9community/visits-service:latest8d11b50368c6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
1
platzio/backend:v0.6.5d5e5972f344b
xz@5.8.1-r0
5.8.3-r0
1
plexinc/pms-docker:1.25.4.5487-648a8f9f946ea59b96f2b
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
pmoscode/excalidraw:v0.18.08ee61554699c
xz@5.8.1-r0
5.8.3-r0
1
pnnlmiscscripts/k8s-node-image9:1.28.15-nginx-72b91d6a46e06
xz@5.6.2-r0
5.8.3-r0
1
pnnlmiscscripts/k8s-node-image9:1.25.16-nginx-772c202c43c0aa
xz@5.6.2-r0
5.8.3-r0
1
pnnlmiscscripts/k8s-node-image9:1.24.17-nginx-882c8dc938b2f9
xz@5.6.2-r0
5.8.3-r0
1
pnnlmiscscripts/k8s-node-image9:1.27.16-nginx-306e1a36d646a3
xz@5.6.2-r0
5.8.3-r0
1
pnnlmiscscripts/k8s-node-image9:1.26.15-nginx-579785e5b82334
xz@5.6.2-r0
5.8.3-r0
1
pnnlmiscscripts/k8s-node-image9:1.31.7-nginx-7e3e189d9d519
xz@5.6.2-r0
5.8.3-r0
1
pnnlmiscscripts/k8s-node-image9:1.30.11-nginx-7f9297eea817d
xz@5.6.2-r0
5.8.3-r0
1
pnnlmiscscripts/k8s-node-image9:1.29.10-nginx-7fcd82530bc8b
xz@5.6.2-r0
5.8.3-r0
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.