StackRadar

CVE-2026-34743

Medium

Advisory

Published 1 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,977
of 17,781 indexed, latest versions
Container images
2,118
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: xz security update

Carried by container images the latest versions of 1,977 of 17,781 indexed charts deploy, on 2,118 images.

Affected packageAffected versionsFixed inImages
xz-utilsdeb5.1.1alpha+20120614-2ubuntu2, 5.2.2-1.3, 5.2.2-1.3ubuntu0.1, 5.2.4-1+10 more5.1.1alpha+20120614-2ubuntu2.14.04.1+esm2, 5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2, 5.2.2-1.3ubuntu0.1+esm1, 5.2.4-1ubuntu1.1+esm1+6 more1,811
xzapk5.4.3-r1, 5.6.1-r3, 5.6.2-r0, 5.6.2-r1+4 more5.8.3-r0295
xzrpm1:5.6.2-4.el10_0, 5.2.3-lp151.4.3.11:5.6.2-4.el10_2.1, 5.8.3-1.112
OSV records
ALPINE-CVE-2026-34743DEBIAN-CVE-2026-34743RHSA-2026:64787RLSA-2026:64787UBUNTU-CVE-2026-34743ECHO-54f0-42da-6974openSUSE-SU-2026:10492-1
Also known as
USN-8362-1

Charts affected

1,977 by stars
ChartLatestAffected imagesRadar Score
argocdnicklasfrahm-argocdVerified publisher0.3.01 of 2See more

argocd nicklasfrahm-argocd 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,240
redashredash4.2.01 of 3See more

redash redash 4.2.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
redash/redash:25.8.000d813437db5
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,987
pypiservercommunity-chartsVerified publisher0.1.91 of 1See more

pypiserver community-charts 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
pypiserver/pypiserver:v2.4.1e935e19433ef
xz@5.6.2-r1
5.8.3-r0

Open the chart page →

584
daskdask2024.1.12 of 2See more

dask dask 2024.1.1

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/dask/dask:2024.1.0080150de7d86
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
ghcr.io/dask/dask-notebook:2024.1.0f53bde3acd4f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

12,746
dgraphdgraph24.1.41 of 1See more

dgraph dgraph 24.1.4

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
dgraph/dgraph:v24.1.4b57fa31f9b7f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

2,993
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

8,390
litellm-helmlitellm1.100.11 of 2See more

litellm-helm litellm 1.100.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,003
openclawopenclaw-helmVerified publisher1.5.402 of 2See more

openclaw openclaw-helm 1.5.40

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
chromedp/headless-shell:148.0.7778.97313ed7255ae1
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

5,660
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,382
openvpn-asstenicVerified publisher0.1.91 of 1See more

openvpn-as stenic 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

15,592
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

7,880
amd-gpuamd-gpu-helmOfficialVerified publisher0.22.01 of 1See more

amd-gpu amd-gpu-helm 0.22.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
rocm/k8s-device-plugin:1.31.0.926212c665aab
xz@5.6.3-r0
5.8.3-r0

Open the chart page →

1,023
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

11,933
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,352
plane-cemakeplaneOfficialVerified publisher1.8.12 of 11See more

plane-ce makeplane 1.8.1

2 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:15.7-alpine468d34fefd63
xz@5.6.1-r3
5.8.3-r0
library/rabbitmq:3.13.6-management-alpine611107e29cce
xz@5.6.2-r0
5.8.3-r0

Open the chart page →

4,854
milvusmilvus-helm5.0.272 of 4See more

milvus milvus-helm 5.0.27

2 of the 4 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
milvusdb/etcd:3.5.25-r1fededb2f2d63
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

10,670
prefect-serverprefectVerified publisher2026.9.32126051 of 2See more

prefect-server prefect 2026.9.3212605

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

5,786
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

6,328
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

18,509
codefreshcodefresh-onpremOfficialVerified publisher2.12.134 of 42See more

codefresh codefresh-onprem 2.12.13

4 of the 42 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/rabbitmq:4.1.39e635efba431
xz-utils@5.4.1-1
5.4.1-1+deb12u1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

14,956
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2api:3.86f56d239d280
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2auth:3.833ecfda16608
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2notifier:3.8f190a6212195
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2rulesengine:3.8259503496ff9
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2scheduler:3.8b1de2055c362
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2sensorcontainer:3.8b1a338f64773
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2stream:3.81c8904a3bf67
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2timersengine:3.81bf35bfaf00c
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2web:3.809989a26c8b7
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
stackstorm/st2workflowengine:3.819fdfffdbba8
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

96,419
supabasetokens-studioVerified publisher1.0.06 of 14See more

supabase tokens-studio 1.0.0

6 of the 14 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
supabase/edge-runtime:v1.59.0eff9c554d649
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/postgres-meta:v0.84.2d0a96973e9f1
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/realtime:v2.33.8d207e6e23ad3
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
supabase/storage-api:v1.12.0f983fb50bd95
xz@5.6.2-r0
5.8.3-r0
supabase/studio:20241021-9f9b08326d8070c55e9
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

23,123
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,493
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

10,775
krokicowboysysopVerified publisher6.1.04 of 5See more

kroki cowboysysop 6.1.0

4 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.29.1444805c4b917
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-excalidraw:0.29.157917319ea70
xz@5.6.3-r1
5.8.3-r0
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
xz@5.6.3-r1
5.8.3-r0

Open the chart page →

6,743
excalidrawexcalidrawVerified publisher0.18.01 of 1See more

excalidraw excalidraw 0.18.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
pmoscode/excalidraw:v0.18.08ee61554699c
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,109
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

3,454
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,025
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

7,857
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

1,240
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

3,480
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

11,405
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,938
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

4,244
camunda-bpm-platformcamunda-community-hub7.6.111 of 1See more

camunda-bpm-platform camunda-community-hub 7.6.11

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
camunda/camunda-bpm-platform:latestbcc5bb0542df
xz@5.8.1-r0
5.8.3-r0

Open the chart page →

1,154
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

3,012
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
quay.io/devtron/postgres:14.91b594392f7cb
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

32,902
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,606
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

5,357
ilumilumOfficialVerified publisher6.7.35 of 19See more

ilum ilum 6.7.3

5 of the 19 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
bitnamilegacy/postgresql:16233f361c5819
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
gitea/gitea:1.22.376f516a1a8c2
xz@5.6.2-r0
5.8.3-r0
ilum/api:6.7.3624fd09528c8
xz-utils@5.8.1-1
5.8.1-1+deb13u1
ilum/marquez:0.54.06e1d709d41f8
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

23,228
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3

Open the chart page →

3,395
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
xz-utils@5.4.1-1
5.4.1-1+deb12u1
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

7,007
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

5,634
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

4,332
netris-controllernetrisai2.8.25 of 14See more

netris-controller netrisai 2.8.2

5 of the 14 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-telescope:4.6.0.00414d82948a8b2
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
netrisai/controller-web-service-frontend:4.6.0-0138c5074f55ae5
xz@5.8.2-r0
5.8.3-r0
netrisai/controller-web-session-generator:0.2.0a030a31289f4
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1

Open the chart page →

30,326
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
xz-utils@5.8.1-1
5.8.1-1+deb13u1

Open the chart page →

2,244
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1

Open the chart page →

17,245
paperless-ngxpaperless-ngxVerified publisher0.3.221 of 3See more

paperless-ngx paperless-ngx 0.3.22

1 of the 3 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
xz-utils@5.4.1-1
5.4.1-1+deb12u1

Open the chart page →

8,489
spring-petclinic-cloudplatform9-communityVerified publisher0.2.05 of 6See more

spring-petclinic-cloud platform9-community 0.2.0

5 of the 6 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
platform9community/admin-server:latestde3fa9b70df1
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/api-gateway:latest40a4970de568
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/customers-service:latest2089811e5cc6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/vets-service:latestd1165c94dfb3
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1
platform9community/visits-service:latest8d11b50368c6
xz-utils@5.2.2-1.3
5.2.2-1.3ubuntu0.1+esm1

Open the chart page →

41,872
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-34743.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1

Open the chart page →

14,184

Container images carrying it

2,118 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
alpine/k8s:1.32.47e1e7d5b7a96
xz@5.6.3-r1
5.8.3-r0
1
alpine/k8s:1.31.49c4976d47656
xz@5.6.3-r0
5.8.3-r0
1
alpine/k8s:1.30.2cd560fce90f7
xz@5.6.1-r3
5.8.3-r0
1
alpine/k8s:1.28.13e5c0b053fed7
xz@5.6.2-r0
5.8.3-r0
1
alpine/k8s:1.32.3eec354133193
xz@5.6.3-r0
5.8.3-r0
1
altinity/clickhouse-server:25.3.6.10034.altinitystable3396b15c51a2
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
andrewgaul/s3proxy:sha-85b0f987dc1d34174a5
xz-utils@5.6.1+really5.4.5-1build0.1
5.6.1+really5.4.5-1ubuntu0.3
1
andrewgolikov55/intel-gpu-exporter:latestfcc001b61c0e
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
anguda/ant-media:2.5c435285fc241
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
anujdatar/cups:25.07.01685df04a643b
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
apache/activemq-artemis:2.44.00305c26f19ed
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
apache/activemq-artemis:2.37.0bae523439ee3
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3
1
apache/airflow:2.8.4-python3.964e58748b6b9
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
apache/airflow:2.8.1e5560ad0b86e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
apache/apisix:3.16.0-ubuntu5e47692cac00
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
apache/gravitino-iceberg-rest:1.3.080136ae753ee
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
apache/hertzbeat:1.8.075d48a62748f
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
apache/iotdb:0.13.3-nodeafa47bf1692a
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1
apache/nifi-registry:1.27.063b8e3e40742
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
apachepulsar/pulsar:3.1.016f9fdab3fa6
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
apachepulsar/pulsar:2.10.03b262ab7a7d9
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
apachepulsar/pulsar:3.0.79c9947de139d
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
apachepulsar/pulsar:2.9.0d056c89b7131
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
apachepulsar/pulsar:2.8.2d538416d5afe
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
apache/ranger:2.7.076c176e8a0e4
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
apache/rocketmq:5.3.0434d8398f996
xz-utils@5.6.1+really5.4.5-1
5.6.1+really5.4.5-1ubuntu0.3
1
apache/rocketmq-exporter:0.0.2c8fb51195444
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
apache/skywalking-oap-server:9.2.0133d35d2c263
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
apache/skywalking-oap-server:8.9.1b4ec8c18d079
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
apache/skywalking-ui:9.2.0295f1dc87d98
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
apache/skywalking-ui:8.9.180530f0308a5
xz-utils@5.2.4-1ubuntu1
5.2.4-1ubuntu1.1+esm1
1
apache/superset:4.0.1ab9467fd712c
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
apache/tika:2.9.0.092d055a84e9e
xz-utils@5.2.5-2ubuntu1
5.2.5-2ubuntu1.1
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
appwrite/appwrite:1.9.01aaa70127114
xz@5.8.2-r0
5.8.3-r0
1
appwrite/console:8.7.383dcdc8492ac6
xz@5.8.2-r0
5.8.3-r0
1
appwrite/console:7.5.7aaa11ceab999
xz@5.6.2-r1
5.8.3-r0
1
archivebox/archivebox:0.7.41a5a37331091
xz-utils@5.4.1-1
5.4.1-1+deb12u1
1
arilot/docker-bitcoind:0.17.127a4f7e0f9f1
xz-utils@5.1.1alpha+20120614-2ubuntu2
5.1.1alpha+20120614-2ubuntu2.16.04.1+esm2
1
aristidetm/basic-notebook:3.6.5469dbc951224
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
artifacthub/tracker:v1.23.05368d21a6e5c
xz-utils@5.8.1-1
5.8.1-1+deb13u1
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
xz-utils@5.4.1-0.2
5.4.1-1+deb12u1
1
arunvelsriram/utils:latest655ad18fd8d6
xz-utils@5.6.1+really5.4.5-1ubuntu0.2
5.6.1+really5.4.5-1ubuntu0.3
1
assistiot/cybersecurity-monitoring_ir-cas:latest6a107f224c34
xz-utils@5.2.4-1ubuntu1.1
5.2.4-1ubuntu1.1+esm1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.