StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,975
of 17,792 indexed, latest versions
Container images
2,107
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,975 of 17,792 indexed charts deploy, on 2,107 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,802
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0293
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,975 by stars
ChartLatestAffected imagesRadar Score
oom-event-generatorfairwinds-incubator0.2.21 of 1See more

oom-event-generator fairwinds-incubator 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
xingse/kubernetes-oom-event-generator:v1.2.09f9d5492e4bf
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2

Open the chart page →

4,647
event-generatorfalcosecurity0.4.01 of 1See more

event-generator falcosecurity 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
falcosecurity/event-generator:latest932956d86c99
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,796
farm-observabilityfarm-observabilityOfficialVerified publisher0.27.22 of 18See more

farm-observability farm-observability 0.27.2

2 of the 18 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

13,409
activityrelayfedihost0.1.41 of 2See more

activityrelay fedihost 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

13,502
rospoferama0.4.31 of 1See more

rospo ferama 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/ferama/rospo:v0.12.0ab40c1745534
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

6,049
vipienferama0.2.81 of 1See more

vipien ferama 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/ferama/vipien:v0.5.3923a3f704b21
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

7,523
azure-pipelines-agentfermosit0.0.11 of 1See more

azure-pipelines-agent fermosit 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jmferrer/azure-devops-agent:latest030f68ec6998
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2

Open the chart page →

14,692
ferriscompanyferriscompany0.1.01 of 1See more

ferriscompany ferriscompany 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/libreconnect/ferriscompany:0.1.0-rc6ed86db9f0efe
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

10,814
fibfibonacci-cluster-appsVerified publisher1.0.03 of 5See more

fib fibonacci-cluster-apps 1.0.0

3 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

17,003
infrafibonacci-cluster-infraVerified publisher1.0.03 of 4See more

infra fibonacci-cluster-infra 1.0.0

3 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apache/activemq-artemis:2.37.0bae523439ee3
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3
library/postgres:16.4e62fbf9d3e2b
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
library/redis:7.4.1bb142a9c18ac
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

12,538
findery-marketfindery-market0.1.01 of 7See more

findery-market findery-market 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
chandanteekinavar/findery-market-frontend:1.06de5bd44a325
xz@5.6.3-r0
5.8.3-r0

Open the chart page →

7,696
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

5,107
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
xz-utils@5.8.1-1
5.8.1-1+deb13u1
fireflyiii/data-importer:version-2.2.3ab52bf932546
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

10,396
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

4,897
firefox-browserfirefox-browserVerified publisher1.1.01 of 1See more

firefox-browser firefox-browser 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jlesage/firefox:v25.03.1055c28defe31
xz@5.6.3-r0
5.8.3-r0

Open the chart page →

1,395
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,789
business-api-ecosystemfiware1.1.02 of 4See more

business-api-ecosystem fiware 1.1.0

2 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-charging-backend:11.7.029456835bb2c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

64,668
apm-hubflanksourceVerified publisher0.0.471 of 2See more

apm-hub flanksource 0.0.47

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
flanksource/apm-hub:v0.0.471dacc3195bf9
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

6,150
batchrunnerflanksourceVerified publisher1.0.441 of 1See more

batchrunner flanksource 1.0.44

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
flanksource/batch-runner:v1.0.44689687a7cf95
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,355
canary-checkerflanksourceVerified publisher1.2.01 of 2See more

canary-checker flanksource 1.2.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
flanksource/canary-checker-ui:v1.4.281764c84e550db
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

4,672
flanksource-uiflanksourceVerified publisher1.4.3181 of 1See more

flanksource-ui flanksource 1.4.318

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
flanksource/incident-manager-ui:v1.4.318891f21df54fb
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

2,580
mission-controlflanksourceVerified publisher0.1.3382See more

mission-control flanksource 0.1.338

2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/flanksource/postgres:17.6-497383cebcf66281fc1
xz-utils@5.4.1-1
5.4.1-1+deb12u1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

mission-control-ai-assistantflanksourceVerified publisher1.0.121 of 1See more

mission-control-ai-assistant flanksource 1.0.12

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/flanksource/mission-control-ai-assistant:1.0.1229a635cbeeb5
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

1,315
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
shashkist/flask-contacts-app:latest581de1fd6084
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,789
flask-appflask-mysqlVerified publisher1.0.11 of 2See more

flask-app flask-mysql 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jjorozco20/flask-mysql-app:1.0.0b5e44e3ba09c
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

4,089
flinkflink0.5.11 of 1See more

flink flink 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/flink:1.14.6-scala_2.122461f02672b3
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

5,693
floriapp-mongodbfloriapp1.0.01 of 1See more

floriapp-mongodb floriapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mongo:4.4.66efa05203990
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

8,049
flyteconnectorflyte2.0.01 of 1See more

flyteconnector flyte 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,544
dump1090fnzv0.2.81 of 1See more

dump1090 fnzv 0.2.8

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
fnzv/dump1090:latestb3079b95c336
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

4,126
mod-z3950folio-org0.1.31 of 1See more

mod-z3950 folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
folioci/mod-z3950:latest2493041ce880
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,465
ledgerformance1.2.01 of 1See more

ledger formance 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/formancehq/ledger:v1.9.203c1ddbda33b
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

4,650
plexfydrah-charts2.2.01 of 1See more

plex fydrah-charts 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.19.5.3112-b23ab3896b598abb134ad
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2

Open the chart page →

8,974
passboltg0dscookie0.5.21 of 2See more

passbolt g0dscookie 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mariadb:10.79a48ac9f196f
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

7,986
borgmaticgabe565Verified publisher0.10.11 of 1See more

borgmatic gabe565 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
xz@5.6.3-r0
5.8.3-r0

Open the chart page →

2,438
esphomegabe565Verified publisher0.15.01 of 1See more

esphome gabe565 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:latest000c5ee5ee96
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

3,179
scanservjsgabe565Verified publisher0.9.21 of 1See more

scanservjs gabe565 0.9.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
sbs20/scanservjs:release-v3.0.3dad1fd6e9a98
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

13,250
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

6,437
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
xz-utils@5.2.4-1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

5,982
accumulogaffer2.2.12 of 4See more

accumulo gaffer 2.2.1

2 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
gchq/accumulo:2.0.1c460bb587d6d
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3
gchq/hdfs:3.3.35ec58edbb2db
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

16,984
gaffer-road-trafficgaffer2.2.11 of 8See more

gaffer-road-traffic gaffer 2.2.1

1 of the 8 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

9,389
garge-appgargeVerified publisher0.1.471 of 1See more

garge-app garge 0.1.47

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
sondresjo/garge-app:v1.20.70382ebf9dfc8
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

1,855
pagesgary-pages1.0.02 of 3See more

pages gary-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
flyway/flyway:6.4.422d97ceb0c47
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

20,242
airsonicgeek-cookbookVerified publisher6.4.21 of 1See more

airsonic geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
airsonicadvanced/airsonic-advanced:latestf7cbafac2806
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

18,203
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

14,705
booksonic-airgeek-cookbookVerified publisher6.4.21 of 1See more

booksonic-air geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

19,246
calibre-webgeek-cookbookVerified publisher8.4.21 of 1See more

calibre-web geek-cookbook 8.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
linuxserver/calibre-web:version-0.6.12938810eca3d3
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

16,176
delugegeek-cookbookVerified publisher5.4.21 of 1See more

deluge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

13,568
dizquetvgeek-cookbookVerified publisher4.4.21 of 1See more

dizquetv geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
vexorian/dizquetv:1.4.37e2b99844a5c
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

4,888
double-takegeek-cookbookVerified publisher2.3.21 of 1See more

double-take geek-cookbook 2.3.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jakowenko/double-take:1.6.0b858bac9e32a
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

12,290
embygeek-cookbookVerified publisher3.4.21 of 1See more

emby geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/emby:v4.6.1.05c6b8f91f1c4
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

8,587

Container images carrying it

2,107 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/linuxserver/radarr:6.0.4c8a55bd83672
xz@5.8.2-r0
5.8.3-r0
1
ghcr.io/linuxserver/resilio-sync:version-2.7.2.1375605b6d544028
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
1
ghcr.io/linuxserver/sonarr:4.0.16.2944-ls3008b9f2138ec50
xz@5.8.1-r0
5.8.3-r0
1
ghcr.io/liturgical-app/calendar-api:0.0.9688a685e2bde
xz@5.8.1-r0
5.8.3-r0
1
ghcr.io/liturgical-app/liturgical-api:1.0.12637bdcebdd8d
xz@5.8.2-r0
5.8.3-r0
1
ghcr.io/liturgical-app/liturgical-app:1.2.041f25aded572
xz@5.8.1-r0
5.8.3-r0
1
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/luzilla/unbound:v0.12.04fd8da9dc13c
xz@5.8.2-r0
5.8.3-r0
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
xz@5.6.1-r3
5.8.3-r0
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/manyfold3d/manyfold:0.136.0d14ca4d82475
xz@5.8.2-r0
5.8.3-r0
1
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/mcwarman/backstage-sample-app/app:mainfae3c1f04311
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/mealie-recipes/mealie:v3.2.1322369a5b748
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/mealie-recipes/mealie:v3.25.16066c29eca95
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/mealie-recipes/mealie:v1.4.0b56da41cf178
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/mealie-recipes/mealie:v3.7.0bb2939094eed
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/media-streaming-mesh/msm-admission-webhook:latest3e811d67189c
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/media-streaming-mesh/msm-cni:latestfe0b89b818a6
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/media-streaming-mesh/msm-cp:latest8cb08fc7010b
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/media-streaming-mesh/msm-dp:latest7ffcb25b4cfc
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/media-streaming-mesh/msm-nc:latest296fe4970e38
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/microboxlabs/miot-harness:0.1.0d548e9ae4b84
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/mollyim/mollysocket:1.1.12a687393f8c8
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/monicahq/monica-next:main8be69156acbb
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
ghcr.io/music-assistant/server:2.7.53522e8a7a8f0
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/music-assistant/server:2.9.950666a6f8d7f
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/music-assistant/server:2.8.7eef3ee7810d0
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/mweinelt/kea-exporter:v0.7.1d7b77020e924
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/mydecisive/octant-ui:0.0.1-testing61e4066b22fb
xz@5.8.2-r0
5.8.3-r0
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/nefelim4ag/k8s-ssh-bastion:0.5.04d337e14c80b
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-173e56bdd1b90d
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.