StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,981
of 17,790 indexed, latest versions
Container images
2,121
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,981 of 17,790 indexed charts deploy, on 2,121 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,813
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0296
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,981 by stars
ChartLatestAffected imagesRadar Score
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

6,049
pypiservercommunity-chartsVerified publisher0.1.91 of 1See more

pypiserver community-charts 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
pypiserver/pypiserver:v2.4.1e935e19433ef
xz@5.6.2-r1
5.8.3-r0

Open the chart page →

584
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

12,838
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,044
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

8,567
litellm-helmlitellm1.101.01 of 2See more

litellm-helm litellm 1.101.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

4,991
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,293
openclawopenclaw-helmVerified publisher1.5.402 of 2See more

openclaw openclaw-helm 1.5.40

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,710
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,428
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

15,602
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

7,920
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
xz@5.6.3-r0
5.8.3-r0

Open the chart page →

1,030
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

11,987
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,375
plane-cemakeplaneOfficialVerified publisher1.8.12 of 11See more

plane-ce makeplane 1.8.1

2 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
xz@5.6.1-r3
5.8.3-r0
library/rabbitmq:3.13.6-management-alpine611107e29cce
xz@5.6.2-r0
5.8.3-r0

Open the chart page →

4,885
milvusmilvus-helm5.0.282 of 4See more

milvus milvus-helm 5.0.28

2 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
milvusdb/etcd:3.5.25-r1fededb2f2d63
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

10,782
prefect-serverprefectVerified publisher2026.9.141419101 of 2See more

prefect-server prefect 2026.9.14141910

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,556
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

6,400
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

18,589
codefreshcodefresh-onpremOfficialVerified publisher2.12.144 of 42See more

codefresh codefresh-onprem 2.12.14

4 of the 42 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/rabbitmq:4.1.39e635efba431
xz-utils@5.4.1-1
5.4.1-1+deb12u1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

15,093
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2api:3.86f56d239d280
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2auth:3.833ecfda16608
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2notifier:3.8f190a6212195
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2rulesengine:3.8259503496ff9
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2scheduler:3.8b1de2055c362
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2sensorcontainer:3.8b1a338f64773
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2stream:3.81c8904a3bf67
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2timersengine:3.81bf35bfaf00c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2web:3.809989a26c8b7
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2workflowengine:3.819fdfffdbba8
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

96,933
supabasetokens-studioVerified publisher1.0.06 of 14See more

supabase tokens-studio 1.0.0

6 of the 14 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
supabase/edge-runtime:v1.59.0eff9c554d649
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/postgres-meta:v0.84.2d0a96973e9f1
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/realtime:v2.33.8d207e6e23ad3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/storage-api:v1.12.0f983fb50bd95
xz@5.6.2-r0
5.8.3-r0
supabase/studio:20241021-9f9b08326d8070c55e9
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

23,365
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,586
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

10,856
krokicowboysysopVerified publisher6.1.04 of 5See more

kroki cowboysysop 6.1.0

4 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.29.1444805c4b917
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-excalidraw:0.29.157917319ea70
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

6,764
excalidrawexcalidrawVerified publisher0.18.01 of 1See more

excalidraw excalidraw 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
pmoscode/excalidraw:v0.18.08ee61554699c
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,110
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

3,496
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,048
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

7,923
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

1,284
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

3,503
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

11,449
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,962
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

4,284
camunda-bpm-platformcamunda-community-hub7.6.111 of 1See more

camunda-bpm-platform camunda-community-hub 7.6.11

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
camunda/camunda-bpm-platform:latestbcc5bb0542df
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,156
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,041
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/postgres:14.91b594392f7cb
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

33,180
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,675
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,403
ilumilumOfficialVerified publisher6.7.35 of 19See more

ilum ilum 6.7.3

5 of the 19 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/postgresql:16233f361c5819
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
gitea/gitea:1.22.376f516a1a8c2
xz@5.6.2-r0
5.8.3-r0
ilum/api:6.7.3624fd09528c8
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ilum/marquez:0.54.06e1d709d41f8
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

23,362
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,440
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

7,063
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

5,702
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

4,354
netris-controllernetrisai2.8.25 of 14See more

netris-controller netrisai 2.8.2

5 of the 14 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-telescope:4.6.0.00414d82948a8b2
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-web-service-frontend:4.6.0-0138c5074f55ae5
xz@5.8.2-r0
5.8.3-r0
netrisai/controller-web-session-generator:0.2.0a030a31289f4
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

30,504
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,267
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

17,370
paperless-ngxpaperless-ngxVerified publisher0.3.221 of 3See more

paperless-ngx paperless-ngx 0.3.22

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,553
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/api-gateway:latest40a4970de568
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/customers-service:latest2089811e5cc6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/vets-service:latestd1165c94dfb3
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/visits-service:latest8d11b50368c6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

41,926
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

14,281

Container images carrying it

2,121 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/thoroslives/zilean:v3.10.1bce6aca0f6ca
xz@5.4.3-r1
5.8.3-r0
1
ghcr.io/topolvm/topolvm-with-sidecar:0.35.0b354978c440d
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
ghcr.io/trow-registry/trow:0.10.075b7d2dcdb91
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/twigex/cospace:lateste5ecfd607e42
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/vinny1892/octantis:latest45459c0910fc
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/virtuos/librechat_exporter:2.0.050ea1cf0086f
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/vojtechpastyrik/squawk:0.1.104005df5f7229
xz@5.6.3-r1
5.8.3-r0
1
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
ghcr.io/voxpupuli/puppetserver:8.7.0-main63873f3f698e
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/wearefrank/frank-gateway:1.0.05ccf797ccdf1
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
ghcr.io/wgbh-mla/ov-wag:v1.1.06df27f944fe8
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/wmde/wbaas-backup:v0.1.78e6a9516eac0
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
ghcr.io/wolveix/satisfactory-server:v1.9.10e0f2f8c97598
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
ghcr.io/woodenmaiden/relfinderreformedfront:latest344f53763b25
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/wundergraph/cosmo/cdn:0.14.1d86fcf169f15
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/wundergraph/cosmo/otelcollector:0.18.15a6fe78d4d15
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/wyrihaximusnet/redirect:randombf5983d754d7
xz@5.6.2-r0
5.8.3-r0
1
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
ghcr.io/yurymkomarov/docker/kubernetes-kiosk-chromium:0.1.27bff29dcec72
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
ghcr.io/zazukoians/qlever-ui:v0.10.151a7ec1c2de4
xz@5.6.1-r3
5.8.3-r0
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/zoriya/kyoo_back:4.7.1416e980f76a6
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/zoriya/kyoo_migrations:4.7.1f7e607f24071
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
ghcr.io/zystem-io/zymtrace-pub-gateway:26.9.1da0b5eb7721a
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
ghcr.io/zystem-io/zymtrace-pub-ui:26.9.1e951adf792cd
xz@5.8.1-r0
5.8.3-r0
1
mcr.microsoft.com/azure-application-gateway/kubernetes-ingress:1.6.0bccaa701e2df
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
mcr.microsoft.com/mssql/server:2017-latest13221ac5f673
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
mcr.microsoft.com/mssql/server:2019-CU16-ubuntu-20.0449a57dc220b1
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
mcr.microsoft.com/mssql/server:2017-latestfbf79e0fea59
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.74.4_local1ed844ecab29
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
public.ecr.aws/aktosecurity/mirror-api-logging:k8s_ebpf_core_impd94ce715f051
xz@5.8.1-r0
5.8.3-r0
1
public.ecr.aws/aktosecurity/redis47200b041382
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
public.ecr.aws/aktosecurity/redis:latestV8.6.2832d7785830f
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.