StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,981
of 17,790 indexed, latest versions
Container images
2,121
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,981 of 17,790 indexed charts deploy, on 2,121 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,813
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0296
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,981 by stars
ChartLatestAffected imagesRadar Score
akauntingf3k-techVerified publisher1.3121.01 of 4See more

akaunting f3k-tech 1.3121.0

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:latestbbd4e17f1ef8
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

4,357
cap-captcha-serverf3k-techVerified publisher0.21.01 of 1See more

cap-captcha-server f3k-tech 0.21.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
tiago2/cap:2.159f5ae4e261e
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

1,686
fastapi-microservice-appfast-api-microservice-app1.3.03 of 4See more

fastapi-microservice-app fast-api-microservice-app 1.3.0

3 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
omkara25/simple-microservice-app-order-service:v2.18327546c7aac
xz-utils@5.4.1-1
5.4.1-1+deb12u1
omkara25/simple-microservice-app-payment-service:v2afff40172b6b
xz-utils@5.4.1-1
5.4.1-1+deb12u1
omkara25/simple-microservice-app-user-service:v2d62cba548580
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

9,655
federidfederidOfficialVerified publisher0.1.21 of 1See more

federid federid 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
federid/webhook:0.1.0fbfb7c6510a7
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

2,086
taigafermosit0.0.112 of 7See more

taiga fermosit 0.0.11

2 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
xz-utils@5.8.1-1
5.8.1-1+deb13u1
taigaio/taiga-protected:latestfd4568a97a59
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

8,541
zabbix-server-mysqlfermosit3.0.23 of 4See more

zabbix-server-mysql fermosit 3.0.2

3 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-6.4-latest349b924472a7
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
zabbix/zabbix-server-mysql:ubuntu-6.4-latest55d074b6b031
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

12,989
flink-operatorflink-operator0.1.11 of 2See more

flink-operator flink-operator 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
gcr.io/flink-operator/deployer:webhook-cert809338a69bd5
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

12,941
bazarrgeek-cookbookVerified publisher10.6.21 of 1See more

bazarr geek-cookbook 10.6.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/bazarr:v1.0.3fdb5501cdfb9
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

17,440
games-on-whalesgeek-cookbookVerified publisher1.8.23 of 7See more

games-on-whales geek-cookbook 1.8.2

3 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

35,444
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

15,728
lazylibrariangeek-cookbookVerified publisher7.4.21 of 1See more

lazylibrarian geek-cookbook 7.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
linuxserver/lazylibrarian:version-1152df82f93d2560e233
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

11,680
omada-controllergeek-cookbookVerified publisher4.4.21 of 1See more

omada-controller geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

11,582
ombigeek-cookbookVerified publisher11.5.21 of 1See more

ombi geek-cookbook 11.5.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/ombi:4.16.124c1b67cf39af
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

5,178
protonmail-bridgegeek-cookbookVerified publisher5.4.21 of 1See more

protonmail-bridge geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
shenxn/protonmail-bridge:1.8.7-1acf31af7c111
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

8,038
prowlarrgeek-cookbookVerified publisher4.5.21 of 1See more

prowlarr geek-cookbook 4.5.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/prowlarr:v0.3.0.1710c863aa9875fa
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

11,602
sabnzbdgeek-cookbookVerified publisher9.4.21 of 1See more

sabnzbd geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sabnzbd:v3.3.1c2d6e775db5a
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

10,275
sonarrgeek-cookbookVerified publisher16.3.21 of 1See more

sonarr geek-cookbook 16.3.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/sonarr:v3.0.8.15070eb230e2381a
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

13,098
stashgeek-cookbookVerified publisher3.4.21 of 1See more

stash geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
stashapp/stash:latest24dbd7607174
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

15,917
tdarrgeek-cookbookVerified publisher4.6.22 of 2See more

tdarr geek-cookbook 4.6.2

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
haveagitgat/tdarr:2.00.181256348872ce
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
haveagitgat/tdarr_node:2.00.101e3f9328327d
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

31,185
valheimgeek-cookbookVerified publisher4.4.21 of 1See more

valheim geek-cookbook 4.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/lloesche/valheim-server:latest20fde516ce31
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

4,913
wireguardgeek-cookbookVerified publisher1.4.21 of 1See more

wireguard geek-cookbook 1.4.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/wireguard:v1.0.20210424448045c4270b
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

7,701
gentrace-self-hostedgentrace-self-hostedVerified publisher0.1.32 of 9See more

gentrace-self-hosted gentrace-self-hosted 0.1.3

2 of the 9 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:23.8512bb8a21483
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
library/postgres:15.38775adb39f0d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

15,635
geo-checkergeo-checkerVerified publisher5.0.01 of 1See more

geo-checker geo-checker 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ymuski/geo-checker:5.0.05ba7fd8c7bdc
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,456
ghostfolioghostfolioVerified publisher0.5.41 of 3See more

ghostfolio ghostfolio 0.5.4

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,145
leantimegissilabs1.3.02 of 2See more

leantime gissilabs 1.3.0

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
leantime/leantime:3.3.3ad4bfb0699d3
xz@5.6.2-r0
5.8.3-r0
library/mariadb:10.6.218a16204dc96c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

6,462
meta-monitoringgrafana1.3.01 of 2See more

meta-monitoring grafana 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
grafana/alloy:v1.4.306bdcbb51fc2
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,569
IMgrycapOfficialVerified publisher1.8.01 of 3See more

IM grycap 1.8.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/grycap/im:latest06a16d4f279f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

4,186
castopodh2mVerified publisher1.12.101 of 3See more

castopod h2m 1.12.10

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
castopod/castopod:1.12.101fd37280cbb2
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

10,169
haproxy-redis-sentinelhaproxy-redis-sentinelVerified publisher0.1.32 of 2See more

haproxy-redis-sentinel haproxy-redis-sentinel 0.1.3

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/haproxy:3.1-bookworm49a0a0d6f0b8
xz-utils@5.4.1-1
5.4.1-1+deb12u1
ghcr.io/parmincloud/haproxy-redis-sentinel:1.0.040a00a6456ae
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

4,317
harp-proxyharp0.8.11 of 1See more

harp-proxy harp 0.8.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
makersquad/harp-proxy:0.8.1a40dd258c527
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

6,464
hawkhawk1.1.52 of 4See more

hawk hawk 1.1.5

2 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

13,676
clickstackhdx-oss-v21.1.11 of 5See more

clickstack hdx-oss-v2 1.1.1

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mongo:5.0.32-focal3b6c281e1c08
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

4,754
app-blueprinthelm-app-blueprintVerified publisher0.2.11 of 1See more

app-blueprint helm-app-blueprint 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.27-alpine65e3e85dbaed
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

840
guacamolehelmforgeVerified publisher1.5.22 of 5See more

guacamole helmforge 1.5.2

2 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
library/postgres:17.5-bookwormfbcea1bd13b6
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,825
helmuphelmupVerified publisher0.1.03 of 3See more

helmup helmup 0.1.0

3 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
sirrend/helmup-engine:0.1.13699e79e3d4e2
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
sirrend/helmup-github-scraper:0.1.47ca688c7abf5
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
sirrend/helmup-notifications-service:0.1.3997866417011
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

16,574
hiverhiverVerified publisher0.1.451 of 10See more

hiver hiver 0.1.45

1 of the 10 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
hiversh/gateway:0.1.45839226cc6e41
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

21,935
htnn-controllerhtnnVerified publisher0.5.01 of 1See more

htnn-controller htnn 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

4,349
huehue1.0.31 of 3See more

hue hue 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
gethue/hue:latest7d5c1b9f8a79
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

12,481
cyberchefhv-helm-repo0.3.31 of 1See more

cyberchef hv-helm-repo 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/gchq/cyberchef:11.0.045082a0ac41d
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

1,110
iceberg-resticeberg-rest-fixture0.0.11 of 2See more

iceberg-rest iceberg-rest-fixture 0.0.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ahmetfurkandemir/iceberg-rest-fixture-postgresql:1.10.0142231a0b8b7
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

3,512
backendikusi-bk-chart1.0.32 of 3See more

backend ikusi-bk-chart 1.0.3

2 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
xz-utils@5.8.1-1
5.8.1-1+deb13u1
kyovint/kyoimgusers:1.0.080084149156e
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

6,009
odooimioVerified publisher3.0.21 of 3See more

odoo imio 3.0.2

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/nginx:1.29.8-alpine5616878291a2
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

3,091
immichimmich-helm0.3.04 of 4See more

immich immich-helm 0.3.0

4 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
valkey/valkey:8.1.481db6d39e1bb
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ghcr.io/immich-app/immich-machine-learning:v2.3.1379e31b8c751
xz-utils@5.4.1-1
5.4.1-1+deb12u1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0bcf63357191b
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

15,793
valkey-clusterinnagoVerified publisher1.1.01 of 2See more

valkey-cluster innago 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
valkey/valkey:8.0.1c5d4f082b76d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

2,645
elasticinseefrlab2.2.02 of 2See more

elastic inseefrlab 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/elasticsearch:7.17.35e6ac15bf6a5
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
library/kibana:7.17.3e2e2031c15be
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

17,372
iris-webappiris-webapp0.2.42 of 2See more

iris-webapp iris-webapp 0.2.4

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/rabbitmq:3.12-management-alpine0b44fbcc3a4b
xz@5.6.2-r0
5.8.3-r0
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

11,842
cniistio1.10.31 of 1See more

cni istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
istio/install-cni:1.10.32232f365aed6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

10,417
discoveryistio1.10.31 of 1See more

discovery istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
istio/pilot:1.10.3e7e110a421c2
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

10,492
egressistio1.10.31 of 1See more

egress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

10,438
ingressistio1.10.31 of 1See more

ingress istio 1.10.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
istio/proxyv2:1.10.3a78b7a165744
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

10,438

Container images carrying it

2,121 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/nicolargo/klances:0.1.374d6d33376eb
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/noahburrell0/sealed-secrets-ui:v0.1.47e7368fb472d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/oguzhan-yilmaz/argocd-backup-s3:latestb61c750ade19
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-03:0.0.0-2026-08-173e56bdd1b90d
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/ondrejsika/counter-frontend:latestc4166d2eb8eb
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/openclaw/openclaw:2026.6.10af7ea052cf21
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/opencost/opencost-ui:1.118.0571f87e528ea
xz@5.8.1-r0
5.8.3-r0
1
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
xz@5.8.2-r0
5.8.3-r0
1
ghcr.io/open-telemetry/demo:1.12.0-imageprovider4e322858fe56
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/open-telemetry/demo:1.12.0-accountingservice6d051840bb29
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/open-telemetry/demo:1.12.0-loadgenerator85c9935ff31b
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/open-telemetry/demo:1.12.0-quoteservice87eb325d306f
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/open-telemetry/demo:3.0.0-image-provider93e1585e97ac
xz@5.8.1-r0
5.8.3-r0
1
ghcr.io/open-telemetry/demo:1.12.0-frontendproxy9fdec1be03e4
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
ghcr.io/open-telemetry/demo:1.12.0-emailservicea1f5cebb5240
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/open-telemetry/demo:1.12.0-shippingservicea3ca4c02a5df
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/open-telemetry/demo:1.12.0-adservicea59e5eead495
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/open-telemetry/demo:1.12.0-recommendationserviceb294a4278407
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/open-telemetry/demo:3.0.0-ade6c593fe75eb
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
ghcr.io/pabloromeo/clusterplex_orchestrator:1.4.160fe80de2d22c
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/paradigmxyz/reth:v1.3.121e5290e8b743
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
ghcr.io/paradigmxyz/reth:v2.2.0505fca5e87d6
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/parmincloud/haproxy-redis-sentinel:1.0.040a00a6456ae
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
xz@5.8.2-r0
5.8.3-r0
1
ghcr.io/plausible/community-edition:v3.0.114c1afde21d6
xz@5.6.3-r1
5.8.3-r0
1
ghcr.io/plausible/community-edition:v2.1.51f9d3fb861e1
xz@5.6.2-r0
5.8.3-r0
1
ghcr.io/plausible/community-edition:v2.1.44c2553516d09
xz@5.6.2-r0
5.8.3-r0
1
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.