StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,981
of 17,790 indexed, latest versions
Container images
2,121
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,981 of 17,790 indexed charts deploy, on 2,121 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,813
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0296
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,981 by stars
ChartLatestAffected imagesRadar Score
voimain-participationbiatec-repoVerified publisher4.4.11 of 1See more

voimain-participation biatec-repo 4.4.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
scholtz2/algorand-participation-voimain-extended:4.4.1-stable64966de56d9f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

7,246
self-hostbitwarden2.4.11 of 11See more

self-host bitwarden 2.4.1

1 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
mcr.microsoft.com/mssql/server:2025-CU5-ubuntu-24.04cee0f4db03b5
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,269
prometheus-airbyte-exporterbotify-helm-chartsVerified publisher0.7.11 of 1See more

prometheus-airbyte-exporter botify-helm-charts 0.7.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

2,919
brightdata-exporterbrightdata-chartsVerified publisher0.2.171 of 1See more

brightdata-exporter brightdata-charts 0.2.17

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/danielgines/brightdata-exporter:0.2.176920d17cf6ff
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

1,306
pgvectorcagriekinVerified publisher2.1.01 of 3See more

pgvector cagriekin 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

4,056
geoserver-cloudcamptocamp20.0.56 of 11See more

geoserver-cloud camptocamp2 0.0.5

6 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

84,710
geoserverCloudcamptocamp20.0.66 of 11See more

geoserverCloud camptocamp2 0.0.6

6 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
geoservercloud/geoserver-cloud-gateway:1.0-RC3756559ee788a
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
geoservercloud/geoserver-cloud-rest:1.0-RC399540eef78ad
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
geoservercloud/geoserver-cloud-wcs:1.0-RC35c254c53a357
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
geoservercloud/geoserver-cloud-webui:1.0-RC3c687b1cbc891
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
geoservercloud/geoserver-cloud-wfs:1.0-RC35288f320cf36
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
geoservercloud/geoserver-cloud-wms:1.0-RC3a30a60ac6cd0
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

84,710
cbioportalcbioportalOfficialVerified publisher1.1.01 of 1See more

cbioportal cbioportal 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
cbioportal/cbioportal:6.4.1-web-shenandoah08debbd2dbf9
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,745
finops-stackcert-managerVerified publisher0.0.51 of 12See more

finops-stack cert-manager 0.0.5

1 of the 12 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/kiwigrid/k8s-sidecar:1.27.4f6ed71d0f9f1
xz@5.6.1-r3
5.8.3-r0

Open the chart page →

12,611
cert-vaultcert-vaultOfficialVerified publisher2.12.05 of 7See more

cert-vault cert-vault 2.12.0

5 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgres-exporter:0.17.1-debian-12-r20cca9d93a617
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/postgresql:17.4.0-debian-12-r11fb3806e823c2
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/redis:7.4.2-debian-12-r66a5b1d0b5942
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/redis-exporter:1.69.0-debian-12-r1a006df1fd47e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
ghcr.io/gregperlinli/certvault:2.12.0a7d0cc9e260a
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

16,056
passbolt-hachristianhuthVerified publisher6.0.12 of 4See more

passbolt-ha christianhuth 6.0.1

2 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/os-shell:12-debian-12-r50e328cff6e450
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

10,931
squestchristianhuthVerified publisher6.6.73 of 4See more

squest christianhuth 6.6.7

3 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:12.0.2-debian-12-r0888cdaae3cb9
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/rabbitmq:4.1.3-debian-12-r19e635efba431
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

10,039
typo3christianhuthVerified publisher7.7.12 of 2See more

typo3 christianhuth 7.7.1

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
xz-utils@5.4.1-1
5.4.1-1+deb12u1
martinhelmich/typo3:12.4c83a4f3fd7ae
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,597
chromadbchromadb-helmVerified publisher0.2.21 of 1See more

chromadb chromadb-helm 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/chroma-core/chroma:1.5.3cfd193653bd6
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

1,454
nethermindchronicleVerified publisher0.0.131 of 1See more

nethermind chronicle 0.0.13

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
nethermind/nethermind:1.31.9aeca3b55bda5
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

2,076
cloudflared-ingress-operatorcloudflared-ingress-operatorVerified publisher0.3.21 of 1See more

cloudflared-ingress-operator cloudflared-ingress-operator 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/livepeer/cloudflared-ingress-operator:latestc179cdcaa050
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

1,747
tensorflow-notebookcloudnativeapp0.1.21 of 1See more

tensorflow-notebook cloudnativeapp 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
tensorflow/tensorflow:1.6.0-devel1e3172090703
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2

Open the chart page →

36,143
bastioncloudposse0.2.01 of 2See more

bastion cloudposse 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
cloudposse/bastion:latest0d9507e8a760
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

1,579
cloudttycloudtty0.8.91 of 2See more

cloudtty cloudtty 0.8.9

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/cloudtty/cloudshell:v0.8.900984ba0f0eb
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

3,985
clustereye-stackclustereyeVerified publisher0.1.11 of 5See more

clustereye-stack clustereye 0.1.1

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.31.02bf7f042e396
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

4,906
cluster-setupcluster-setup1.5.01 of 8See more

cluster-setup cluster-setup 1.5.0

1 of the 8 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

10,111
commonground-gatewaycommonground-gateway1.5.41 of 7See more

commonground-gateway commonground-gateway 1.5.4

1 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

9,747
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

11,283
paperless-ngxcrystalnetVerified publisher0.2.221 of 3See more

paperless-ngx crystalnet 0.2.22

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

13,792
nifid4nVerified publisher2.0.01 of 5See more

nifi d4n 2.0.0

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apache/nifi-registry:1.26.07cdfd8deec92
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

5,440
aibrixdanchevVerified publisher0.7.01 of 5See more

aibrix danchev 0.7.0

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
aibrix/metadata-service:v0.7.063fb81a64377
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,343
data-fairdata354-helmVerified publisher1.1.22 of 12See more

data-fair data354-helm 1.1.2

2 of the 12 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/mongo:4.44be76f674fc4
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
ghcr.io/data-fair/elasticsearch:7.17.1aa45adaf59a7
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

38,441
datacube-explorerdatacube-charts0.5.321 of 1See more

datacube-explorer datacube-charts 0.5.32

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
opendatacube/explorer:latest120457ffcd69
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

4,915
dbrepodbrepo1.13.315 of 25See more

dbrepo dbrepo 1.13.3

15 of the 25 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/mariadb:11.4.5-debian-12-r128bc50a0961a7
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/mariadb-galera:11.3.2-debian-12-r9aee9c668098f
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/mysqld-exporter:0.15.1-debian-12-r2611a5f0b79e79
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/nginx:1.28.0-debian-12-r0eaf9066e86f6
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/openldap:2.6.8-debian-12-r16e412c178ef9
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/os-shell:12-debian-12-r3217444b4b2c96
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/postgres-exporter:0.15.0-debian-12-r44e7e1b3a90682
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/postgresql:17.0.0-debian-12-r9d885ac277163
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/rabbitmq:3.13.7-debian-12-r2cd593809e359
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/seaweedfs:3.87.0-debian-12-r10cb31d0fc356
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/valkey:latest0384ca2eec63
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

53,108
mealiedeimosfr-charts1.0.151 of 1See more

mealie deimosfr-charts 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/mealie-recipes/mealie:v3.24.00b08ac3a9f0a
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

4,059
kubedashdevopstalesOfficialVerified publisher4.0.03 of 8See more

kubedash devopstales 4.0.0

3 of the 8 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
devopstales/kubedash:3.1.08bb837da5aec
xz@5.6.2-r1
5.8.3-r0
library/postgres:18.3a9abf4275f9e
xz-utils@5.8.1-1
5.8.1-1+deb13u1
library/redis:8.6.2009cc37796fb
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

9,271
dial-coredialOfficialVerified publisher6.0.01 of 2See more

dial-core dial 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
valkey/valkey:9.0.2930b41430fb7
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

1,543
powershelluniversaldigitalhubVerified publisher0.1.21 of 1See more

powershelluniversal digitalhub 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ironmansoftware/universal:3.3.1-ubuntu-20.041943c73cce31
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

6,982
directusdirectus-io2.1.02 of 3See more

directus directus-io 2.1.0

2 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mysql:9.4.0-debian-12-r1ec13e229247a
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/redis:8.2.1-debian-12-r025bf63f3caf7
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

7,565
jellystatdjjudas21Verified publisher0.1.121 of 1See more

jellystat djjudas21 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

1,743
dominodominoVerified publisher0.1.112 of 3See more

domino domino 0.1.11

2 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ghcr.io/tauffer-consulting/domino-rest:latest8bf880fe8c73
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

8,864
seafiledr300481Verified publisher0.12.11 of 1See more

seafile dr300481 0.12.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:11.0.12d0c66e4621bd
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

10,911
dragonfly-stackdragonflyVerified publisher0.1.21 of 7See more

dragonfly-stack dragonfly 0.1.2

1 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
dragonflyoss/client:v0.1.82edf3e921f4e0
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

18,480
rstudiodsri-helm-charts0.1.281 of 1See more

rstudio dsri-helm-charts 0.1.28

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/maastrichtu-ids/rstudio:latest981aa4c109e1
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,754
dyff-orchestratordyff-orchestratorVerified publisher0.22.191 of 1See more

dyff-orchestrator dyff-orchestrator 0.22.19

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/dyff-orchestrator:0.22.199bd5d93aaff7
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

1,371
glpieftechcombr-glpiVerified publisher2.12.01 of 5See more

glpi eftechcombr-glpi 2.12.0

1 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
eftechcombr/glpi:php-fpm-12.0.0-rc1f3d0ed01709e
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

4,415
elchi-stackelchi1.13.03 of 10See more

elchi-stack elchi 1.13.0

3 of the 10 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.81ffa82edee00
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
envoyproxy/envoy:v1.33.056da5afd7df3
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
library/mongo:6.0.12646902910d6a
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

15,540
enbuildenbuildVerified publisher0.0.503 of 6See more

enbuild enbuild 0.0.50

3 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
xz-utils@5.8.1-1
5.8.1-1+deb13u1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
xz-utils@5.4.1-1
5.4.1-1+deb12u1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

31,674
roundcubeencircle360-ossVerified publisher0.8.31 of 1See more

roundcube encircle360-oss 0.8.3

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

5,662
eoapieoapiOfficialVerified publisher0.16.21 of 7See more

eoapi eoapi 0.16.2

1 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
nginxinc/nginx-unprivileged:1.27.4-alpine62a904036bfc
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

6,453
copypartyernail-copyparty2.0.01 of 1See more

copyparty ernail-copyparty 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
copyparty/ac:1.19.200a0a8605062c
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,692
beaconchain-explorerethereum-helm-chartsVerified publisher0.1.61 of 2See more

beaconchain-explorer ethereum-helm-charts 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

3,096
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

11,530
vulnz-nvd-mirroreugen1.0.01 of 1See more

vulnz-nvd-mirror eugen 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/jeremylong/open-vulnerability-data-mirror:v9.0.49a69aa14dc3e
xz@5.8.2-r0
5.8.3-r0

Open the chart page →

1,676
mcrouterevryfs-ossVerified publisher0.4.01 of 2See more

mcrouter evryfs-oss 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

6,511

Container images carrying it

2,121 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
public.ecr.aws/decisiveai/valkey:9.0.159c7e728fb3a
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
public.ecr.aws/flanksource/incident-manager-ui:v1.4.317fea799d4fb2f
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
public.ecr.aws/groundcovercom/postgres:18.1-20260208b7d7910c0bb0
xz-utils@5.8.1-1
5.8.1-1+e1
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/aerokube/keygen:1.0.1578934444f04
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/ceph/ceph:v21.1.05ff3692d2f3f
xz@1:5.6.2-4.el10_0
1:5.6.2-4.el10_2.1
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/deployhub/ms-nginx:svccat-v11.0.815-g717581d2d3400664e8
xz@5.8.1-r0
5.8.3-r0
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
xz-utils@5.2.2-1.3ubuntu0.1
5.2.2-1.3ubuntu0.1+esm1
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/kiwigrid/k8s-sidecar:1.30.349dcce269568
xz@5.6.3-r0
5.8.3-r0
1
quay.io/kiwigrid/k8s-sidecar:1.30.10835d79d8fbae
xz@5.8.1-r0
5.8.3-r0
1
quay.io/kiwigrid/k8s-sidecar:2.6.0a6c101156d42
xz@5.8.2-r0
5.8.3-r0
1
quay.io/maxiv/pieeat:0.9.3099715479210
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/mittwald/kube-mail:latest04f1099241fc
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
quay.io/shivering-isles/dovecot:2.3.214599ada9aa06
xz@5.6.1-r3
5.8.3-r0
1

syft 1.42.1 · advisories as of 16 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.