StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,981
of 17,790 indexed, latest versions
Container images
2,121
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,981 of 17,790 indexed charts deploy, on 2,121 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,813
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0296
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,981 by stars
ChartLatestAffected imagesRadar Score
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

11,827
unifiunifiVerified publisher1.16.01 of 1See more

unifi unifi 1.16.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jacobalberty/unifi:v10.0.162896c0ab82d33
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

7,360
plexutkuozdemirVerified publisher2.1.11 of 1See more

plex utkuozdemir 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
linuxserver/plex:1.25.24a13ced2326c
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

6,390
elasticsearch-clusterwiremindVerified publisher4.5.21 of 2See more

elasticsearch-cluster wiremind 4.5.2

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/elasticsearch:8.19.1289729a95066a
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

2,327
istio-operatorwiremindVerified publisher1.18.21 of 1See more

istio-operator wiremind 1.18.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
istio/operator:1.18.270f9d1fe5fff
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

5,679
zabbix-serveraekondratievVerified publisher1.0.63 of 4See more

zabbix-server aekondratiev 1.0.6

3 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
zabbix/zabbix-agent:ubuntu-5.4.62127168cab03
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
zabbix/zabbix-server-pgsql:ubuntu-5.4.66c946b1f45cd
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

30,813
wazuh-agentavistoVerified publisher4.12.21 of 1See more

wazuh-agent avisto 4.12.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

6,531
hadoopbigdata-chartsVerified publisher1.0.11 of 2See more

hadoop bigdata-charts 1.0.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
5200710/hadoop:3.2.3-java8092d3088a5fb
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

12,166
cluster-secretclutersecretVerified publisher0.7.01 of 1See more

cluster-secret clutersecret 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

3,050
convoyconvoyVerified publisher3.7.132 of 3See more

convoy convoy 3.7.13

2 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,943
emqx-operatoremqx-operator2.3.21 of 2See more

emqx-operator emqx-operator 2.3.2

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
alpine/k8s:1.31.49c4976d47656
xz@5.6.3-r0
5.8.3-r0

Open the chart page →

4,548
bookstackgabe565Verified publisher0.20.01 of 1See more

bookstack gabe565 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
xz@5.6.3-r0
5.8.3-r0

Open the chart page →

2,812
hasurahasura-extraVerified publisher3.0.11 of 1See more

hasura hasura-extra 3.0.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
hasura/graphql-engine:v2.34.0-ce0111b0204136
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

4,954
coturnjaconiVerified publisher1.0.51 of 1See more

coturn jaconi 1.0.5

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
coturn/coturn:4.10.0-r1f4c2af06c3c5
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,924
mongooseimmongoose0.4.111 of 1See more

mongooseim mongoose 0.4.11

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
erlangsolutions/mongooseim:6.6.0cc5bf032931f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

1,307
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

8,692
passboltpassbolt2.1.15 of 6See more

passbolt passbolt 2.1.1

5 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/redis-sentinel:8.2.1-debian-12-r00ca3ea1d2f82
xz-utils@5.4.1-1
5.4.1-1+deb12u1
library/haproxy:3.4.10f597665a2a6
xz-utils@5.8.1-1
5.8.1-1+deb13u1
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

13,523
py-kube-downscalerpy-kube-downscalerVerified publisher0.3.121 of 1See more

py-kube-downscaler py-kube-downscaler 0.3.12

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/caas-team/py-kube-downscaler:26.4.0af05a098b0d2
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

732
swo-k8s-collectorsolarwindsOfficialVerified publisher5.3.01 of 3See more

swo-k8s-collector solarwinds 5.3.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
solarwinds/solarwinds-otel-collector:0.152.3-k8s3c1110e8bdfb
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

2,377
thehivestrangebee-helmOfficialVerified publisher1.0.73 of 7See more

thehive strangebee-helm 1.0.7

3 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

16,220
uffizzi-controlleruffizzi-controller2.4.61 of 11See more

uffizzi-controller uffizzi-controller 2.4.6

1 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

14,327
cloudflaredartur9010Verified publisher1.0.91 of 3See more

cloudflared artur9010 1.0.9

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
registry.k8s.io/ingress-nginx/controller:v1.15.1594ceea76b01
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

3,008
baserowbaserow-chartVerified publisher1.0.563 of 6See more

baserow baserow-chart 1.0.56

3 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2024.7.4-debian-12-r0952f86d1116c
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/redis:7.2.5-debian-12-r05261cae9e407
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

17,413
fadicetic0.3.12 of 25See more

fadi cetic 0.3.1

2 of the 25 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jupyterhub/k8s-hub:0.11.1b6b4a1a34bf0
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
jupyterhub/k8s-singleuser-sample:0.11.1e3e6f3051df8
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

53,052
headwind-mdmchristianhuthVerified publisher5.10.21 of 2See more

headwind-mdm christianhuth 5.10.2

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,929
dolibarrcowboysysopVerified publisher9.0.32 of 3See more

dolibarr cowboysysop 9.0.3

2 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
dolibarr/dolibarr:22.0.47ad88fc9b13c
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

9,208
daskhubdask2024.1.11 of 9See more

daskhub dask 2024.1.1

1 of the 9 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
pangeo/base-notebook:2024.01.155fbe688a4f80
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

14,151
seafiledatamateVerified publisher0.6.04 of 6See more

seafile datamate 0.6.0

4 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb-galera:11.4.3-debian-12-r0cb8beb6dbb58
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/memcached:1.6.29-debian-12-r4ff0e7239c17c
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/minio:2024.8.3-debian-12-r15501c419f42e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
datamate/seafile-professional:11.0.202dd66b722464
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

27,426
dialdialOfficialVerified publisher7.2.01 of 4See more

dial dial 7.2.0

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,186
jellyfindjjudas21Verified publisher4.0.81 of 1See more

jellyfin djjudas21 4.0.8

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,626
plexgabe565Verified publisher0.5.11 of 1See more

plex gabe565 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/plex:version-1.41.4.9463-630c9f557e6d2775e77ec
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

2,583
geonode-k8sgeonode-k8sVerified publisher2.0.04 of 10See more

geonode-k8s geonode-k8s 2.0.0

4 of the 10 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
geonode/geoserver:2.28.4-latest81b1d431b7e9
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
geopython/pycsw:3.0.0-beta284662ea6b78b
xz-utils@5.4.1-1
5.4.1-1+deb12u1
library/memcached:1.6.40cc523a19da58
xz-utils@5.8.1-1
5.8.1-1+deb13u1
library/redis:8.4.03906b477e4b6
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

14,112
glpiglpi-conteiner0.1.01 of 3See more

glpi glpi-conteiner 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
vdiogov/glpi-conteiner:latest6945f84f0058
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

12,359
openctihelm-openctiVerified publisher3.0.91 of 8See more

opencti helm-opencti 3.0.9

1 of the 8 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/rabbitmq:4.1.2-debian-12-r1fac502149c40
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,407
hertzbeathertzbeatOfficialVerified publisher1.8.12 of 4See more

hertzbeat hertzbeat 1.8.1

2 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apache/hertzbeat:1.8.075d48a62748f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
apache/hertzbeat-collector:1.8.0a2bab1be574c
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

14,181
infrahubinfrahubVerified publisher4.33.24 of 5See more

infrahub infrahub 4.33.2

4 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
xz-utils@5.4.1-1
5.4.1-1+deb12u1
library/neo4j:2026.05.06c162e2432f8
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

10,522
plexk8s-home-lab-repo7.3.11 of 1See more

plex k8s-home-lab-repo 7.3.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/home-operations/plex:1.43.1a9c3723cb31c
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

1,729
kamu-api-serverkamuVerified publisher0.89.01 of 1See more

kamu-api-server kamu 0.89.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/kamu-data/kamu-api-server:0.89.04ed7a896dd2b
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

6,350
kubeflowkubeflow1.6.25 of 45See more

kubeflow kubeflow 1.6.2

5 of the 45 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
istio/proxyv2:1.9.687a9db561d2e
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
istio/proxyv2:1.14.1df69c1a7af7c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
library/python:3.7eedf63967cdb
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
gcr.io/ml-pipeline/metadata-envoy:2.0.0-alpha.5e8bc6cf08613
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
gcr.io/tfx-oss-public/ml_metadata_store_server:1.5.0db8691752b4c
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

97,217
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

10,573
testkubekubeshop2.13.21 of 5See more

testkube kubeshop 2.13.2

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
kubeshop/testkube-minio:2025.10d8e1af6aca99
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,151
librechatlibrechat-openshiftVerified publisher1.9.02 of 3See more

librechat librechat-openshift 1.9.0

2 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mongo:8.0.20098862b1339f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,849
radarrloeken-at-homeVerified publisher5.27.0-nightly1 of 1See more

radarr loeken-at-home 5.27.0-nightly

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
loeken/radarr:5.27.0-nightlya24409d3846d
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

586
headplanenbcloudVerified publisher0.1.21 of 4See more

headplane nbcloud 0.1.2

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:latestcd354d5b2556
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

7,997
open5gsopen5gsVerified publisher2.3.41 of 5See more

open5gs open5gs 2.3.4

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
gradiant/open5gs-dbctl:0.10.3332031245fce
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

9,305
mattermostphntom3.24.01 of 2See more

mattermost phntom 3.24.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
phntom/mattermost-team-edition:9.3.051cf9da4aa2e
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

8,777
unifi-controllerqonstruktVerified publisher2.6.11 of 1See more

unifi-controller qonstrukt 2.6.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:8.0.240ae315a3a456
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

10,563
steampipe-powerpipe-kubernetessteampipe-powerpipe-kubernetesVerified publisher0.13.12 of 2See more

steampipe-powerpipe-kubernetes steampipe-powerpipe-kubernetes 0.13.1

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--powerpipe:latesta16ab5ca10a7
xz-utils@5.4.1-1
5.4.1-1+deb12u1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,530
uffizzi-appuffizzi-app1.3.01 of 14See more

uffizzi-app uffizzi-app 1.3.0

1 of the 14 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
uffizzi/controller:latest0344805f267b
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

19,434
unboundunbound-helmchartVerified publisher0.2.21 of 1See more

unbound unbound-helmchart 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/pixelfederation/unbound:1.24.2_0fce820a03964
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

1,495

Container images carrying it

2,121 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
xz-utils@5.8.1-1
5.8.1-1+e1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/aerokube/keygen:1.0.1578934444f04
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
xz@1:5.6.2-4.el10_0
1:5.6.2-4.el10_2.1
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
xz@5.8.1-r0
5.8.3-r0
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/kiwigrid/k8s-sidecar:1.30.349dcce269568
xz@5.6.3-r0
5.8.3-r0
1
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
xz@5.8.1-r0
5.8.3-r0
1
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
xz@5.8.2-r0
5.8.3-r0
1
quay.io/maxiv/pieeat:0.9.3099715479210
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/mittwald/kube-mail:latest04f1099241fc
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
quay.io/shivering-isles/dovecot:2.3.214599ada9aa06
xz@5.6.1-r3
5.8.3-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.