StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,981
of 17,790 indexed, latest versions
Container images
2,121
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,981 of 17,790 indexed charts deploy, on 2,121 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,813
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0296
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,981 by stars
ChartLatestAffected imagesRadar Score
ingress-nginxingress-nginx4.15.11 of 2See more

ingress-nginx ingress-nginx 4.15.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

1,548
metallbmetallbVerified publisher0.16.11 of 4See more

metallb metallb 0.16.1

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/frrouting/frr:10.4.38745af1f9bbb
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

2,149
giteagiteaOfficialVerified publisher12.7.03 of 4See more

gitea gitea 12.7.0

3 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,874
sonarqubesonarqubeVerified publisher10.0.0+5211 of 3See more

sonarqube sonarqube 10.0.0+521

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/sonarqube:10.0.0-communityef9723cf4fe4
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

6,623
artifact-hubartifact-hubVerified publisher1.23.02 of 7See more

artifact-hub artifact-hub 1.23.0

2 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
xz-utils@5.8.1-1
5.8.1-1+deb13u1
artifacthub/tracker:v1.23.05368d21a6e5c
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

10,840
uptime-kumauptime-kumaVerified publisher4.2.01 of 1See more

uptime-kuma uptime-kuma 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.5.0a8610b3b4c38
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

30,217
airflowairflow-helmVerified publisher8.9.01 of 4See more

airflow airflow-helm 8.9.0

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apache/airflow:2.8.4-python3.964e58748b6b9
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

11,394
falcofalcosecurity9.1.01 of 3See more

falco falcosecurity 9.1.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
falcosecurity/falco-driver-loader:0.44.17df783d5269a
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,398
openebsopenebsOfficialVerified publisher4.6.13 of 35See more

openebs openebs 4.6.1

3 of the 35 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
grafana/alloy:v1.8.17790f6f7fbd8
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
kiwigrid/k8s-sidecar:1.30.2cdb361e67b1b
xz@5.6.3-r0
5.8.3-r0
openebs/etcd:3.6.4-debian-12-r0c86c06f1ce6a
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

24,128
apisixapisix2.17.01 of 3See more

apisix apisix 2.17.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,118
zabbixzabbix-communityVerified publisher7.1.04 of 5See more

zabbix zabbix-community 7.1.0

4 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-7.0.237322a94c5d7a
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
zabbix/zabbix-server-pgsql:ubuntu-7.0.237e8c8e059533
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
zabbix/zabbix-web-service:ubuntu-7.0.23915b3183e054
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

13,880
keycloakcloudpirates-keycloakVerified publisher0.21.371 of 3See more

keycloak cloudpirates-keycloak 0.21.37

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:18.0073e7c8b84e2
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

4,428
node-problem-detectordeliveryheroVerified publisher2.4.11 of 1See more

node-problem-detector deliveryhero 2.4.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

1,984
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

5,399
keydbenapter0.48.01 of 1See more

keydb enapter 0.48.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
eqalpha/keydb:x86_64_v6.3.2fd9351ce27a7
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

5,560
openldap-stack-hahelm-openldapVerified publisher4.3.31 of 5See more

openldap-stack-ha helm-openldap 4.3.3

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jpgouin/openldap:2.6.9-fixbfdd0088c776
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,968
csi-driver-nfscsi-driver-nfsVerified publisher4.13.41 of 6See more

csi-driver-nfs csi-driver-nfs 4.13.4

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,391
clamavwiremindVerified publisher3.7.31 of 1See more

clamav wiremind 3.7.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
clamav/clamav:1.4.3_base629a3050df6a
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

1,060
netboxbootcVerified publisher4.1.11 of 4See more

netbox bootc 4.1.1

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
netboxcommunity/netbox:v3.2.83d652dca5351
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

9,197
grafana-agentgrafana0.44.21 of 2See more

grafana-agent grafana 0.44.2

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
grafana/agent:v0.44.23364714a2f64
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,526
milvusmilvus4.0.312 of 5See more

milvus milvus 4.0.31

2 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apachepulsar/pulsar:2.8.2d538416d5afe
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
milvusdb/milvus:v2.2.13a3a55e1c1497
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

32,420
cockroachdbcockroachdbVerified publisher22.0.31 of 3See more

cockroachdb cockroachdb 22.0.3

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
cockroachdb/cockroach:v26.3.1204f131510c7
xz@1:5.6.2-4.el10_0
1:5.6.2-4.el10_2.1

Open the chart page →

763
clearmlallegroaiOfficialVerified publisher7.15.01 of 4See more

clearml allegroai 7.15.0

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
allegroai/clearml:2.0.0-613713ae38f7daf
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

10,695
signozsignoz0.141.11 of 5See more

signoz signoz 0.141.1

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
signoz/signoz-otel-collector:v0.144.972aa1e4c1ec5
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

7,607
weblateweblateOfficialVerified publisher0.5.362 of 3See more

weblate weblate 0.5.36

2 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/redis:latest5927ff3702df
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

6,787
locustdeliveryheroVerified publisher0.35.01 of 1See more

locust deliveryhero 0.35.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
locustio/locust:2.32.2a0d4b88e42c1
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

2,817
node-rednode-redVerified publisher0.40.21 of 1See more

node-red node-red 0.40.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
nodered/node-red:4.1.2216e7403aab9
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

2,173
emqxemqx-operator5.8.91 of 1See more

emqx emqx-operator 5.8.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
emqx/emqx:5.8.935b46f7aa7a0
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,728
bitcoin-corehirosystemsVerified publisher2.1.71 of 1See more

bitcoin-core hirosystems 2.1.7

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
dobtc/bitcoin:25.1a870f7cb1105
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

4,819
difydoubanVerified publisher0.10.03 of 6See more

dify douban 0.10.0

3 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/redis:7.2.4-debian-12-r139c6fecd24bf3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

19,544
pulsarapache4.7.02 of 10See more

pulsar apache 4.7.0

2 of the 10 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
alpine/k8s:1.32.12048f8d9c8cc7
xz@5.8.2-r0
5.8.3-r0
quay.io/kiwigrid/k8s-sidecar:2.5.0a6b3f707f883
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

9,891
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,675
vertical-pod-autoscalercowboysysopVerified publisher11.1.11 of 4See more

vertical-pod-autoscaler cowboysysop 11.1.1

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

6,960
difydify-helmVerified publisher0.38.01 of 11See more

dify dify-helm 0.38.0

1 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
langgenius/dify-sandbox:0.2.15750e1111426e
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

22,214
pyroscopegrafana2.3.11 of 3See more

pyroscope grafana 2.3.1

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
grafana/alloy:v1.12.2f94b1c82957a
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,214
stacks-blockchainhirosystemsVerified publisher2.2.21 of 1See more

stacks-blockchain hirosystems 2.2.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

1,396
oktetooktetoOfficialVerified publisher0.0.0-2026-08-171 of 10See more

okteto okteto 0.0.0-2026-08-17

1 of the 10 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/okteto/pipeline-runner:0.0.0-2026-08-173e56bdd1b90d
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

5,532
apisix-ingress-controllerapisix1.3.11 of 2See more

apisix-ingress-controller apisix 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/api7/adc:0.27.1f65f53dd9668
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

1,661
istiocloudposse1.1.02 of 8See more

istio cloudposse 1.1.0

2 of the 8 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
gcr.io/istio-release/pilot:release-1.0-latest-daily5ea7b7f3632a
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
gcr.io/istio-release/proxyv2:release-1.0-latest-daily8f9ff98fdbef
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2

Open the chart page →

23,984
san-iscsi-csienixOfficialVerified publisher4.0.21 of 7See more

san-iscsi-csi enix 4.0.2

1 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
enix/san-iscsi-csi:v4.0.2f963da81ecf7
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

4,168
oncallgrafana1.16.51 of 12See more

oncall grafana 1.16.5

1 of the 12 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
grafana/oncall:v1.16.5499851658393
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

16,282
openprojectopenproject-helm-chartsOfficialVerified publisher13.11.02 of 5See more

openproject openproject-helm-charts 13.11.0

2 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/memcached:1.6.24-debian-12-r01d80b6a96f00
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
openproject/hocuspocus:release-338001b288dc1359dfb5
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

20,067
sftpgosftpgoOfficialVerified publisher0.47.01 of 1See more

sftpgo sftpgo 0.47.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/drakkan/sftpgo:v2.7.46cb60f08fede
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

1,262
wazuhwazuh-helm-morgovedVerified publisher2.0.71 of 5See more

wazuh wazuh-helm-morgoved 2.0.7

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
kinseii/wazuh-agent:4.14.17160eb143728
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

11,431
zabbixcetic3.1.34 of 5See more

zabbix cetic 3.1.3

4 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
zabbix/zabbix-agent2:ubuntu-6.0.8e5b594057c9c
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
zabbix/zabbix-server-pgsql:ubuntu-6.0.8d59ffa07f615
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
zabbix/zabbix-web-service:ubuntu-6.0.8ee4baa872280
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

33,928
csi-driver-smbcsi-driver-smbVerified publisher1.20.31 of 6See more

csi-driver-smb csi-driver-smb 1.20.3

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
registry.k8s.io/sig-storage/smbplugin:v1.20.3dc7746bb081e
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,005
kube-downscalerdeliveryheroVerified publisher0.7.61 of 1See more

kube-downscaler deliveryhero 0.7.6

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
hjacobs/kube-downscaler:23.2.0-6-gc9b88e84b2147f47425
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

4,310
synapsehalkeye0.40.01 of 2See more

synapse halkeye 0.40.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/element-hq/synapse:v1.111.022ae556e0de4
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

6,562
stacks-blockchain-apihirosystemsVerified publisher6.5.12 of 5See more

stacks-blockchain-api hirosystems 6.5.1

2 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
blockstack/stacks-core:3.2.0.0.0f79944317326
xz-utils@5.4.1-1
5.4.1-1+deb12u1
hirosystems/stacks-blockchain-api:8.13.29c98b23c1515
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,409
imgproxyimgproxy1.1.01 of 1See more

imgproxy imgproxy 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/imgproxy/imgproxy:v3.30.074c1bee92e04
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

2,373

Container images carrying it

2,121 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
xz-utils@5.8.1-1
5.8.1-1+e1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/aerokube/keygen:1.0.1578934444f04
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
xz@1:5.6.2-4.el10_0
1:5.6.2-4.el10_2.1
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
xz@5.8.1-r0
5.8.3-r0
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/kiwigrid/k8s-sidecar:1.30.349dcce269568
xz@5.6.3-r0
5.8.3-r0
1
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
xz@5.8.1-r0
5.8.3-r0
1
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
xz@5.8.2-r0
5.8.3-r0
1
quay.io/maxiv/pieeat:0.9.3099715479210
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/mittwald/kube-mail:latest04f1099241fc
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
quay.io/shivering-isles/dovecot:2.3.214599ada9aa06
xz@5.6.1-r3
5.8.3-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.