StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,980
of 17,803 indexed, latest versions
Container images
2,118
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,980 of 17,803 indexed charts deploy, on 2,118 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,810
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0296
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,980 by stars
ChartLatestAffected imagesRadar Score
servicexssl-hep1.8.51 of 16See more

servicex ssl-hep 1.8.5

1 of the 16 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ncsa/checks:main0b738bbc8d70
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

68,698
stakefishstakefish0.1.01 of 8See more

stakefish stakefish 0.1.0

1 of the 8 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
thongngo3301/stakefish:latesta341af5976e3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

20,351
erigonstakewise2.61.21 of 3See more

erigon stakewise 2.61.2

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
erigontech/erigon:v2.61.288706754b627
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

2,994
lighthouse-validatorstakewise7.0.11 of 2See more

lighthouse-validator stakewise 7.0.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
sigp/lighthouse:v7.0.12cae720e9a35
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

2,034
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

4,110
nethermindstakewise2.8.21 of 3See more

nethermind stakewise 2.8.2

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
nethermind/nethermind:1.31.893e57917371a
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

2,091
operatorstakewise2.1.11 of 5See more

operator stakewise 2.1.1

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
sigp/lighthouse:v2.1.2ad501f02cfef
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

6,601
rethstakewise1.2.11 of 3See more

reth stakewise 1.2.1

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/paradigmxyz/reth:v1.3.121e5290e8b743
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

2,030
ssv-nodestakewise2.2.01 of 2See more

ssv-node stakewise 2.2.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bloxstaking/ssv-node:v2.2.0bf6d7d2fdc93
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

7,028
teku-validatorstakewise4.3.21 of 2See more

teku-validator stakewise 4.3.2

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
consensys/teku:25.4.1bf6ecd2ea716
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,209
verostakewise0.8.31 of 2See more

vero stakewise 0.8.3

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

3,503
open-appsec-injectorstartechnicaVerified publisher1.1.21 of 3See more

open-appsec-injector startechnica 1.1.2

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/openappsec/openappsec-waf-webhook:1.1.345b979b962043
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

4,354
unifistartechnicaVerified publisher0.1.31 of 2See more

unifi startechnica 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jacobalberty/unifi:v7.1.664a3616625dda
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

14,619
trinostatcan1.23.41 of 2See more

trino statcan 1.23.4

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
trinodb/trino:405ee80ab5eeab2
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

13,927
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.51 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mongo:4.4.18d23ec07162ca
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

13,669
pagesstephendillondell1.0.02 of 3See more

pages stephendillondell 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
flyway/flyway:6.4.422d97ceb0c47
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

20,261
sn-consolestreamnative1.13.01 of 1See more

sn-console streamnative 1.13.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
streamnative/private-cloud-console:v2.3.27-all91e54375e154
xz@5.6.2-r1
5.8.3-r0

Open the chart page →

1,844
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

62,314
wonder-mesh-netstrrl-helm2026.629.01 of 3See more

wonder-mesh-net strrl-helm 2026.629.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/strrl/wonder-mesh-net:v2026.629.0625b140372fd
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,158
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

12,746
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
kurento/kurento-media-server:latest03c0d34d0828
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

12,746
artifactory-cleanupsubshellVerified publisher1.0.11 of 1See more

artifactory-cleanup subshell 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
devopshq/artifactory-cleanup:1.0.1830e093bffa91
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

2,577
group-challengesubshell-labVerified publisher2.1.01 of 2See more

group-challenge subshell-lab 2.1.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.29.17d12c7c8fc66
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

2,617
substra-backendsubstraVerified publisher26.15.31 of 7See more

substra-backend substra 26.15.3

1 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-backend:1.0.121967f54ec86
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

4,851
substra-frontendsubstraVerified publisher1.2.31 of 1See more

substra-frontend substra 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

3,029
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

13,500
3d-printing-cost-calculatorssudo-kraken-3d-printing-cost-calculatorsVerified publisher0.1.41 of 1See more

3d-printing-cost-calculators sudo-kraken-3d-printing-cost-calculators 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/3d-printing-cost-calculators:v1.1.1220c5e4e1a3d
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

2,716
authentik-webfinger-proxysudo-kraken-authentik-webfinger-proxyVerified publisher0.1.41 of 1See more

authentik-webfinger-proxy sudo-kraken-authentik-webfinger-proxy 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/authentik-webfinger-proxy:v1.1.1e1351a977607
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

2,796
fantasy-dice-chambersudo-kraken-fantasy-dice-chamberVerified publisher0.1.31 of 1See more

fantasy-dice-chamber sudo-kraken-fantasy-dice-chamber 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/fantasy-dice-chamber:v1.3.299fd4cb0f4fe
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

2,828
finances-trackersudo-kraken-finances-trackerVerified publisher0.1.51 of 1See more

finances-tracker sudo-kraken-finances-tracker 0.1.5

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/finances-tracker:v1.1.1c73527cde81c
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

2,796
flaresolverrsudo-kraken-flaresolverrVerified publisher2.1.41 of 1See more

flaresolverr sudo-kraken-flaresolverr 2.1.4

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/flaresolverr/flaresolverr:v3.4.67962759d99d7
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

34,069
jellyfinsudo-kraken-jellyfinVerified publisher2.1.31 of 1See more

jellyfin sudo-kraken-jellyfin 2.1.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.6333b64771663
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

3,443
jf-pushover-webhooksudo-kraken-jf-pushover-webhookVerified publisher0.1.31 of 1See more

jf-pushover-webhook sudo-kraken-jf-pushover-webhook 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/sudo-kraken/jf-pushover-webhook:v1.1.0ee9cf22a39ab
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

2,796
qbittorrentsudo-kraken-qbittorrentVerified publisher5.1.51 of 2See more

qbittorrent sudo-kraken-qbittorrent 5.1.5

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/home-operations/qbittorrent:5.1.4bb82ad6668f8
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

2,130
pagessunilb2590-pages1.0.02 of 3See more

pages sunilb2590-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
flyway/flyway:6.4.422d97ceb0c47
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

20,261
surogate-hubsurogate-hubVerified publisher2.1.51 of 1See more

surogate-hub surogate-hub 2.1.5

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,496
convert-datasvtechVerified publisher0.13.21 of 3See more

convert-data svtech 0.13.2

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.3a934ffd63d25
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

7,786
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

4,745
elasticsearchsvtech-public-helm-charts1.0.01 of 1See more

elasticsearch svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

12,248
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

12,739
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

10,997
icinga2svtech-public-helm-charts1.0.01 of 4See more

icinga2 svtech-public-helm-charts 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/redis:7.2.3a7cee7c8178f
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,561
maxscalesvtech-public-helm-charts1.0.01 of 2See more

maxscale svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
svtechnmaa/svtech_maxscale:v1.0.3410a25b51f9f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

71,130
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

9,217
preparationsvtech-public-helm-charts1.0.01 of 1See more

preparation svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
svtechnmaa/svtech_debuger:v1.0.0b2987abe57d3
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

12,248
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

71,563
stashswuuper-githubVerified publisher0.1.161 of 1See more

stash swuuper-github 0.1.16

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
stashapp/stash:v0.31.1df744af5a0c9
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

2,409
stash-boxswuuper-githubVerified publisher0.1.11 of 2See more

stash-box swuuper-github 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
stashapp/stash-box:latesta534c8afdf39
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

8,291
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
yandex/clickhouse-server:latest1cbf75aabe1e
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

8,606
app-startersynkubeVerified publisher1.4.11 of 1See more

app-starter synkube 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

3,295

Container images carrying it

2,118 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
xz-utils@5.8.1-1
5.8.1-1+e1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/aerokube/keygen:1.0.1578934444f04
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
xz@1:5.6.2-4.el10_0
1:5.6.2-4.el10_2.1
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
xz@5.8.1-r0
5.8.3-r0
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/kiwigrid/k8s-sidecar:1.30.349dcce269568
xz@5.6.3-r0
5.8.3-r0
1
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
xz@5.8.1-r0
5.8.3-r0
1
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
xz@5.8.2-r0
5.8.3-r0
1
quay.io/maxiv/pieeat:0.9.3099715479210
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/mittwald/kube-mail:latest04f1099241fc
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
quay.io/shivering-isles/dovecot:2.3.214599ada9aa06
xz@5.6.1-r3
5.8.3-r0
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
xz@5.6.3-r1
5.8.3-r0
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.