StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,979
of 17,790 indexed, latest versions
Container images
2,118
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,979 of 17,790 indexed charts deploy, on 2,118 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,812
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0294
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,979 by stars
ChartLatestAffected imagesRadar Score
operatoristio1.10.31 of 1See more

operator istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
istio/operator:1.10.3655eefa11c84
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

10,716
jdownloader2jdownloader2Verified publisher1.10.01 of 1See more

jdownloader2 jdownloader2 1.10.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jlesage/jdownloader-2:v26.03.13d6cb102bd9b
xz@5.6.2-r1
5.8.3-r0

Open the chart page →

539
jellyfinjellyfinVerified publisher0.3.301 of 1See more

jellyfin jellyfin 0.3.30

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/jellyfin/jellyfin:10.11.1145f648c382a0
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,571
jenkinsjkimVerified publisher5.5.142 of 2See more

jenkins jkim 5.5.14

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jenkins/jenkins:2.462.2-jdk1795313257a8cd
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
kiwigrid/k8s-sidecar:1.27.6db85bd553253
xz@5.6.2-r0
5.8.3-r0

Open the chart page →

7,393
k8s-grafana-stackk8s-grafana-stackVerified publisher0.2.322 of 17See more

k8s-grafana-stack k8s-grafana-stack 0.2.32

2 of the 17 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
grafana/alloy:v1.14.0f50931848bd8
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

15,459
ombik8s-home-lab-repo12.2.11 of 1See more

ombi k8s-home-lab-repo 12.2.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/ombi:4.53.50caadf03b804
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

1,460
tautullik8s-home-lab-repo12.3.01 of 1See more

tautulli k8s-home-lab-repo 12.3.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/home-operations/tautulli:2.17.12183820d45a1
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

1,130
kafka-kraft-on-k8skafka-kraft-on-k8sVerified publisher1.1.03 of 3See more

kafka-kraft-on-k8s kafka-kraft-on-k8s 1.1.0

3 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
kafkakraft/kafka-connect:3.7.0062d697db7e5
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
kafkakraft/kafka-controller:3.7.0f261ad288fce
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
kafkakraft/kafkakraft:3.7.02e4b593b878b
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

14,250
kdiffkdiff-snapshotsVerified publisher0.0.2031 of 2See more

kdiff kdiff-snapshots 0.0.203

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,515
kdiff-snapshotskdiff-snapshotsVerified publisher0.0.551 of 1See more

kdiff-snapshots kdiff-snapshots 0.0.55

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,795
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,234
keydbkeydb-helmVerified publisher1.0.61 of 1See more

keydb keydb-helm 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.4eceb1806730c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

5,302
nginx-php-fpmkokuwa0.1.42 of 2See more

nginx-php-fpm kokuwa 0.1.4

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/php:8.5.2-fpm-alpine3.22a2482c398d60
xz@5.8.1-r0
5.8.3-r0
nginxinc/nginx-unprivileged:1.29.0-alpine3.2282dcf28da5a8
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,840
difykubeblocksVerified publisher0.5.12 of 5See more

dify kubeblocks 0.5.1

2 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
langgenius/dify-api:0.6.11fca918260dd6
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
langgenius/dify-sandbox:0.2.009b7e8705673
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

20,424
pgbouncerkubernetes-helm-chart-pgbouncer1.0.151 of 1See more

pgbouncer kubernetes-helm-chart-pgbouncer 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
cradlepoint/pgbouncer:1.0.18f5720b0cd03
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

5,808
owncloudkubernetes-homelab-helm-chartsVerified publisher0.1.01 of 3See more

owncloud kubernetes-homelab-helm-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
owncloud/server:10.16.274c53d341076
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

9,975
kubeseal-webguikubeseal-webgui6.0.42 of 2See more

kubeseal-webgui kubeseal-webgui 6.0.4

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/jaydee94/kubeseal-webgui/api:4.5.33cceb9462ae1
xz-utils@5.4.1-1
5.4.1-1+deb12u1
ghcr.io/jaydee94/kubeseal-webgui/ui:4.5.34447636e8102
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

4,101
kubesendkubesend0.1.91 of 1See more

kubesend kubesend 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
v3xl/kubesend:0.1.06f62ca96be82
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

1,385
hertzbeatkubesphere-testVerified publisher1.4.11 of 4See more

hertzbeat kubesphere-test 1.4.1

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apache/iotdb:0.13.3-nodeafa47bf1692a
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

7,749
kuma-ingress-watcherkuma-ingress-watcherVerified publisher1.4.01 of 1See more

kuma-ingress-watcher kuma-ingress-watcher 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/squent/kuma-ingress-watcher:1.7.014d45b2a1f00
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

2,668
kubefarmkvaps0.13.41 of 6See more

kubefarm kvaps 0.13.4

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

12,477
opennebulakvaps2.1.15 of 9See more

opennebula kvaps 2.1.1

5 of the 9 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.401563adc95fd
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
ghcr.io/kvaps/opennebula-exporter:v5.12.0.4-12b92df1143b9
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
ghcr.io/kvaps/opennebula-gate:v5.12.0.4-1a85e03d8bc1d
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

114,025
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

5,657
lagoon-remotelagoon-chartsVerified publisher0.106.01 of 1See more

lagoon-remote lagoon-charts 0.106.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
uselagoon/docker-host:v3.6.12c89ed939b8b
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

2,113
langflow-idelangflow0.1.22 of 2See more

langflow-ide langflow 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
langflowai/langflow:latest65796601f3fc
xz@1:5.6.2-4.el10_0
1:5.6.2-4.el10_2.1
langflowai/langflow-frontend:latest54f67f1961fe
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

4,011
langflow-runtimelangflow0.1.11 of 1See more

langflow-runtime langflow 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
langflowai/langflow:latest65796601f3fc
xz@1:5.6.2-4.el10_0
1:5.6.2-4.el10_2.1

Open the chart page →

163
flaresolverrlib42Verified publisher2.0.01 of 1See more

flaresolverr lib42 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.0ab535d1fef5d
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

35,058
kube-iptables-tailerlifen-chartsVerified publisher0.2.31 of 1See more

kube-iptables-tailer lifen-charts 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
honestica/kube-iptables-tailer:master-91a393242fb939
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

4,456
litlyxlitlyx0.2.01 of 5See more

litlyx litlyx 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mongo:8.0.11dca8d11fe467
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

7,915
clickhouseliwenhe1.0.11 of 3See more

clickhouse liwenhe 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
yandex/clickhouse-server:19.14ccf9c2b5e3f2
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

6,766
music-assistant-serverlmatfyVerified publisher0.1.91 of 1See more

music-assistant-server lmatfy 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

7,216
locustlocustVerified publisher0.1.41 of 1See more

locust locust 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
hansehe/locust:1.1.0bc8e45262bc4
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

2,763
voice-biometricslumenvox2.0.112 of 26See more

voice-biometrics lumenvox 2.0.1

12 of the 26 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
lumenvox/cloud-assure-api:2.0.0fcb9fb54a9fd
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-assure-identity:2.0.0147854a3c916
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-audit:2.0.079428add7f38
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-binary-storage:2.0.053decadc102d
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-configuration:2.0.017fbce1a8bc6
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-deployment:2.0.0ea8110886d38
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-engine-resource:2.0.0e2e5abe27abc
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-management-api:2.0.0b9a23345eabd
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-reporting:2.0.07a9ffdc2178a
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-reporting-api:2.0.0dbbaf5462ad6
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-transaction:2.0.08b74f9d3ba09
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
lumenvox/cloud-voice-verifier:2.0.014170ad34903
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

71,216
dnsbl-exporterluzillaVerified publisher0.5.01 of 2See more

dnsbl-exporter luzilla 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/luzilla/unbound:v0.12.04fd8da9dc13c
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

1,147
drillmagasin-drill0.9.01 of 3See more

drill magasin-drill 0.9.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
merlos/zookeeper:3.9.3a38fc7e09ed7
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,741
magentomagento3.2.32 of 12See more

magento magento 3.2.3

2 of the 12 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mariadb:10.422edfe1c7834
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
library/rabbitmq:4.1.0-management935b3f84c1e4
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

13,582
plane-enterprisemakeplaneOfficialVerified publisher3.7.22 of 13See more

plane-enterprise makeplane 3.7.2

2 of the 13 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
xz@5.6.1-r3
5.8.3-r0
library/rabbitmq:3.13.6-management-alpine611107e29cce
xz@5.6.2-r0
5.8.3-r0

Open the chart page →

4,942
maptiler-servermaptilerOfficialVerified publisher1.3.01 of 1See more

maptiler-server maptiler 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
maptiler/server:4.8.07e206140057b
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

3,014
Practica_4_Recuperacion_helmmca-03-02-practica4-recuperacionVerified publisher1.0.11 of 6See more

Practica_4_Recuperacion_helm mca-03-02-practica4-recuperacion 1.0.1

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mongo:4.2.358b25d51baa1
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

19,192
mcpmcp-chartsVerified publisher0.0.232 of 7See more

mcp mcp-charts 0.0.23

2 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/gla-rad/mc-mms-edgerouter:latest3620d5680775
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ghcr.io/gla-rad/mc-mms-router:latest032e977d9adf
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

6,994
jellyfinmedia-servarrVerified publisher0.16.01 of 2See more

jellyfin media-servarr 0.16.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,764
mw-kube-agent-v2middleware-labsVerified publisher2.8.61 of 1See more

mw-kube-agent-v2 middleware-labs 2.8.6

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

4,184
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
xz-utils@5.8.1-1build2
5.8.1-1ubuntu0.1

Open the chart page →

11,108
model-manager-loadermodel-manager-loader1.27.01 of 1See more

model-manager-loader model-manager-loader 1.27.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
public.ecr.aws/cloudnatix/llmariner/model-manager-loader:1.27.026ac7263a823
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,678
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

13,763
redminemt1905027.3.41 of 3See more

redmine mt190502 7.3.4

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/redmine:6.1.204ac44a2595b
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

7,552
n3uronn3uronVerified publisher0.3.51 of 1See more

n3uron n3uron 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
n3uronhub/n3uron:v1.22.4423a0bdd9cb9
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

1,896
satisfactorynaj981.1.11 of 1See more

satisfactory naj98 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
wolveix/satisfactory-server:v1.9.1199be1064b18
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

3,729
clowder2ncsaVerified publisher1.9.76 of 12See more

clowder2 ncsa 1.9.7

6 of the 12 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:8.12.215d4647fd491
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/os-shell:12-debian-12-r16d24925821dd2
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
clowder/clowder2-backend:2.0.0-beta.411f3d844e4c0
xz-utils@5.4.1-1
5.4.1-1+deb12u1
clowder/clowder2-frontend:2.0.0-beta.4fe97882672ca
xz@5.8.1-r0
5.8.3-r0
clowder/clowder2-heartbeat:2.0.0-beta.414155326c7b9
xz-utils@5.4.1-1
5.4.1-1+deb12u1
clowder/clowder2-messages:2.0.0-beta.4bf146f1ca24f
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

37,441
helm-composenousefreakVerified publisher0.1.31 of 2See more

helm-compose nousefreak 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mariadb:10.8.2-focal490f01279be1
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

14,324

Container images carrying it

2,118 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
stackstorm/st2api:3.86f56d239d280
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
stackstorm/st2auth:3.833ecfda16608
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
stackstorm/st2notifier:3.8f190a6212195
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
stackstorm/st2rulesengine:3.8259503496ff9
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
stackstorm/st2scheduler:3.8b1de2055c362
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
stackstorm/st2sensorcontainer:3.8b1a338f64773
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
stackstorm/st2stream:3.81c8904a3bf67
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
stackstorm/st2timersengine:3.81bf35bfaf00c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
stackstorm/st2web:3.809989a26c8b7
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
stackstorm/st2workflowengine:3.819fdfffdbba8
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
stain/jena-fuseki:latestb1d0c96f19ad
xz@5.6.1-r3
5.8.3-r0
1
stalwartlabs/stalwart:v0.15.5dcf575db2d53
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
stashapp/stash:latest24dbd7607174
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
stashapp/stash:v0.31.1df744af5a0c9
xz@5.8.2-r0
5.8.3-r0
1
stashapp/stash-box:latesta534c8afdf39
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
statcan/ckan:2.93921305425b8
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
streamnative/apache-pulsar-grafana-dashboard-k8s:0.0.1611bceacec8fb
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
streamnative/private-cloud-console:v2.3.27-all91e54375e154
xz@5.6.2-r1
5.8.3-r0
1
structurizr/onpremises:2025.11.094b5ffb5119c8
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
substratusai/verba:v0.4.0-baseURL261695be635eb
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
supabase/edge-runtime:v1.74.02781daf92394
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
supabase/edge-runtime:v1.59.0eff9c554d649
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
supabase/logflare:latest49bfe526f1b4
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
supabase/postgres-meta:v0.96.6a84cc713585e
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
supabase/postgres-meta:v0.84.2d0a96973e9f1
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
supabase/realtime:v2.102.3aa1c92c0cf32
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
supabase/realtime:v2.33.8d207e6e23ad3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
supabase/storage-api:v1.12.0f983fb50bd95
xz@5.6.2-r0
5.8.3-r0
1
supabase/studio:20241021-9f9b08326d8070c55e9
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
svcosti/cidrapp:latest8428d87bc5d0
xz@5.6.3-r1
5.8.3-r0
1
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
sysnet4admin/colosseum-cms:loge74b43c7f492
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
sysnet4admin/colosseum-rwd:log74ded2d92f07
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
tdengine/tdengine:3.0.2.24140a4021ddb
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
teknas09/bird-pod:latest12a1fa85c4aa
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
temporalio/admin-tools:1.26.237e2e33dbd7b
xz@5.6.2-r0
5.8.3-r0
1
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
xz@5.8.1-r0
5.8.3-r0
1
temporalio/admin-tools:1.28cfde8170c92f
xz@5.8.2-r0
5.8.3-r0
1
tensorflow/serving:latest8a208c232297
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
tensorzero/gateway:2026.6.0c939db4f27e4
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
tensorzero/ui:2026.6.0f2563d54724e
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
testinprod/op-erigon:latest0a125bd77a2d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
thecampagnards/trafficlight-api:main7dca9d973837
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.