StackRadar

CVE-2026-41035

High

Advisory

Published 16 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.8
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
127
of 17,781 indexed, latest versions
Container images
121
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: rsync security update

Carried by container images the latest versions of 127 of 17,781 indexed charts deploy, on 121 images.

Affected packageAffected versionsFixed inImages
rsyncdeb3.1.0-2ubuntu0.1, 3.1.0-2ubuntu0.4, 3.1.1-3ubuntu1.1, 3.1.1-3ubuntu1.2+22 more3.1.0-2ubuntu0.4+esm3, 3.1.1-3ubuntu1.3+esm5, 3.1.2-2.1ubuntu1.6+esm3, 3.1.3-8ubuntu0.9+esm1+5 more68
rsyncapk3.4.1-r13.4.1-r22
rsyncrpm3.1.2-6.el7_6.1, 3.1.3-7.el8, 3.1.3-7.el8_2.2, 3.1.3-12.el8+6 more0:3.1.2-12.el7_9.3, 0:3.1.3-25.el8_1051
OSV records
ALPINE-CVE-2026-41035DEBIAN-CVE-2026-41035RHSA-2026:17481RHSA-2026:25172UBUNTU-CVE-2026-41035
Also known as
RHSA-2026:25149, RHSA-2026:25170, RHSA-2026:25190, USN-8283-1, USN-8349-1, USN-8349-2, USN-8349-3

Charts affected

127 by stars
ChartLatestAffected imagesRadar Score
dgbuildersmo-helm-chart6.0.01 of 3See more

dgbuilder smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

28,470
dmaap-listenersmo-helm-chart6.0.01 of 3See more

dmaap-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

25,769
elasticsearchsmo-helm-chart6.0.01 of 5See more

elasticsearch smo-helm-chart 6.0.0

1 of the 5 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

24,776
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

29,220
mariadb-initsmo-helm-chart6.0.01 of 2See more

mariadb-init smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

24,776
msbsmo-helm-chart6.0.01 of 6See more

msb smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

27,477
pndasmo-helm-chart6.0.01 of 3See more

pnda smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

27,477
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

29,220
portalsmo-helm-chart6.0.01 of 8See more

portal smo-helm-chart 6.0.0

1 of the 8 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.07daa08b81954
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

27,477
sdcsmo-helm-chart6.0.01 of 14See more

sdc smo-helm-chart 6.0.0

1 of the 14 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

25,769
sdnc-ansible-serversmo-helm-chart6.0.01 of 3See more

sdnc-ansible-server smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

25,769
sdnc-portalsmo-helm-chart6.0.01 of 3See more

sdnc-portal smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

25,769
sdnc-promsmo-helm-chart6.0.01 of 2See more

sdnc-prom smo-helm-chart 6.0.0

1 of the 2 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

24,776
sdnc-websmo-helm-chart6.0.01 of 3See more

sdnc-web smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

24,776
ueb-listenersmo-helm-chart6.0.01 of 3See more

ueb-listener smo-helm-chart 6.0.0

1 of the 3 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
oomk8s/readiness-check:2.0.2875814cc853d
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5

Open the chart page →

25,769
allurestakaterVerified publisher1.0.11 of 1See more

allure stakater 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
rsync@3.1.3-12.el8
0:3.1.3-25.el8_10

Open the chart page →

28,165
nordmart-reviewstakaterVerified publisher0.0.61 of 3See more

nordmart-review stakater 0.0.6

1 of the 3 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
rsync@3.1.3-14.el8_6.2
0:3.1.3-25.el8_10

Open the chart page →

11,554
nordmart-review-instancestakaterVerified publisher1.0.01 of 3See more

nordmart-review-instance stakater 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
stakater/stakater-nordmart-review:1.0.35954d2be66e95
rsync@3.1.3-14.el8_6.2
0:3.1.3-25.el8_10

Open the chart page →

11,554
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
rsync@3.2.7-1
3.2.7-1+deb12u5

Open the chart page →

9,102
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
rsync@3.1.3-8ubuntu0.7
3.1.3-8ubuntu0.9+esm1

Open the chart page →

18,756
swr-cache-proxyswr-cache-proxy0.2.01 of 1See more

swr-cache-proxy swr-cache-proxy 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
rsync@3.1.3-19.el8_7.1
0:3.1.3-25.el8_10

Open the chart page →

13,719
vehicle-dashboardtest-vehi-dash0.1.01 of 7See more

vehicle-dashboard test-vehi-dash 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
rsync@3.2.7-0ubuntu0.22.04.2
3.2.7-0ubuntu0.22.04.6

Open the chart page →

20,270
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
rsync@3.2.7-1+deb12u2
3.2.7-1+deb12u5

Open the chart page →

10,086
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
rsync@3.1.3-12.el8
0:3.1.3-25.el8_10

Open the chart page →

12,455
bugsinkvictorlane0.3.71 of 2See more

bugsink victorlane 0.3.7

1 of the 2 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
library/mariadb:12.0-noble607835cd628b
rsync@3.2.7-1ubuntu1.2
3.2.7-1ubuntu1.4

Open the chart page →

4,054
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
rsync@3.2.7-0ubuntu0.22.04.2
3.2.7-0ubuntu0.22.04.6

Open the chart page →

13,459
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-41035.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
rsync@3.1.3-12.el8
0:3.1.3-25.el8_10

Open the chart page →

11,577

Container images carrying it

121 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
library/mariadb:10.6.218a16204dc96c
rsync@3.1.3-8ubuntu0.9
3.1.3-8ubuntu0.9+esm1
1
library/mariadb:10.79a48ac9f196f
rsync@3.1.3-8ubuntu0.5
3.1.3-8ubuntu0.9+esm1
1
library/mariadb:12.2.2b1cb255a9939
rsync@3.2.7-1ubuntu1.2
3.2.7-1ubuntu1.4
1
library/mariadb:10.10.2bfc25a68e113
rsync@3.2.3-8ubuntu3.1
3.2.7-0ubuntu0.22.04.6
1
library/mariadb:10.6.15e22328f4d714
rsync@3.1.3-8ubuntu0.7
3.1.3-8ubuntu0.9+esm1
1
library/mariadb:10.9.4fbb8456ebdb1
rsync@3.2.3-8ubuntu3.1
3.2.7-0ubuntu0.22.04.6
1
library/mariadb:11.7.2fcc7fcd7114a
rsync@3.2.7-1ubuntu1.2
3.2.7-1ubuntu1.4
1
library/nextcloud:31.0.6-apache588609d76b21
rsync@3.2.7-1+deb12u2
3.2.7-1+deb12u5
1
library/nextcloud:31.0.10-apacheb7faa1653c39
rsync@3.4.1+ds1-5
3.4.1+ds1-5+deb13u2
1
louislam/uptime-kuma:2.0.24c364ef96aad
rsync@3.2.7-1+deb12u2
3.2.7-1+deb12u5
1
muluder/prograncontrollermcord:0.1.843b597a93da7
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5
1
offchainlabs/nitro-node:v3.7.6-c0fe95e9f779fa84b7b
rsync@3.2.7-1+deb12u2
3.2.7-1+deb12u5
1
offchainlabs/nitro-node:v3.1.0-7d1d84ce95865866129
rsync@3.2.7-1
3.2.7-1+deb12u5
1
oled01/db-backup:0.1.06302fd2b5333
rsync@3.2.3-8ubuntu3.1
3.2.7-0ubuntu0.22.04.6
1
omecproject/onos-progran:1.0.05715e5648aa0
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5
1
photoprism/photoprism:251130db16ee6b1ba3
rsync@3.4.1+ds1-5ubuntu1
3.4.1+ds1-5ubuntu1.2
1
photoprism/photoprism:240711-cefc6fd632ca74
rsync@3.2.7-1ubuntu1
3.2.7-1ubuntu1.4
1
resouer/redis-slave:v2e2f198b49ba7
rsync@3.1.0-2ubuntu0.1
3.1.0-2ubuntu0.4+esm3
1
scrapinghub/splash:3.4.1a5f89bc84606
rsync@3.1.2-2.1ubuntu1
3.1.2-2.1ubuntu1.6+esm3
1
seldonio/locust-core:0.81d0da98a2d76
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5
1
seldonio/seldon-request-logger:1.11.24e985d2006a8
rsync@3.1.3-12.el8
0:3.1.3-25.el8_10
1
stackstorm/st2actionrunner:3.888235ba70cad
rsync@3.1.3-8ubuntu0.7
3.1.3-8ubuntu0.9+esm1
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
rsync@3.2.7-1
3.2.7-1+deb12u5
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
rsync@3.1.3-8ubuntu0.7
3.1.3-8ubuntu0.9+esm1
1
tensorflow/tensorflow:1.6.0-devel1e3172090703
rsync@3.1.1-3ubuntu1.2
3.1.1-3ubuntu1.3+esm5
1
twentycrm/twenty-postgres-spilo:latest2f78405a78be
rsync@3.2.7-0ubuntu0.22.04.2
3.2.7-0ubuntu0.22.04.6
1
viniciusfcf/gitops-quarkus-app-jvm:latestbba8ee1b5cd5
rsync@3.1.3-12.el8
0:3.1.3-25.el8_10
1
vividplanet/swr-cache-proxy:v1ae1c5b1cbecb
rsync@3.1.3-19.el8_7.1
0:3.1.3-25.el8_10
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
rsync@3.2.7-1
3.2.7-1+deb12u5
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
rsync@3.4.1+ds1-5
3.4.1+ds1-5+deb13u2
1
ghcr.io/k8s-at-home/transmission:v3.006011182e3946
rsync@3.1.3-8ubuntu0.3
3.1.3-8ubuntu0.9+esm1
1
ghcr.io/kvaps/opennebula:v5.12.0.4-1e28e0e7de11b
rsync@3.1.3-8
3.1.3-8ubuntu0.9+esm1
1
ghcr.io/kvaps/opennebula-flow:v5.12.0.4-1600221f0f43f
rsync@3.1.3-8
3.1.3-8ubuntu0.9+esm1
1
ghcr.io/lloesche/valheim-server:latest20fde516ce31
rsync@3.4.1+ds1-5+deb13u1
3.4.1+ds1-5+deb13u2
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
rsync@3.2.7-1ubuntu1.2
3.2.7-1ubuntu1.4
1
public.ecr.aws/perfectscale-io/kube-state-metrics:4.1.14-redhat849e235e2d3e
rsync@3.1.3-19.el8_7.1
0:3.1.3-25.el8_10
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
rsync@3.1.3-19.el8_7.1
0:3.1.3-25.el8_10
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
rsync@3.1.3-12.el8
0:3.1.3-25.el8_10
1
quay.io/fiware/apollo:0.0.1055330b1b60c1
rsync@3.1.3-14.el8_6.2
0:3.1.3-25.el8_10
1
quay.io/fiware/canis-major:1.5.15bb40472e4ff5
rsync@3.1.3-12.el8
0:3.1.3-25.el8_10
1
quay.io/fiware/contract-management:3.3.122bcfcf874451
rsync@3.1.3-19.el8_7.1
0:3.1.3-25.el8_10
1
quay.io/fiware/credentials-config-service:3.4.3f2fbced76da8
rsync@3.1.3-19.el8_7.1
0:3.1.3-25.el8_10
1
quay.io/fiware/endpoint-configuration-service:0.4.30dc38a87b844
rsync@3.1.3-14.el8_6.2
0:3.1.3-25.el8_10
1
quay.io/fiware/tmforum-account:1.18.06b25aac03414
rsync@3.1.3-23.el8_10
0:3.1.3-25.el8_10
1
quay.io/fiware/tmforum-agreement:1.18.081e7025dc16d
rsync@3.1.3-23.el8_10
0:3.1.3-25.el8_10
1
quay.io/fiware/tmforum-customer-bill-management:1.18.0dee901f1f75d
rsync@3.1.3-23.el8_10
0:3.1.3-25.el8_10
1
quay.io/fiware/tmforum-customer-management:1.18.0d3519cebecd0
rsync@3.1.3-23.el8_10
0:3.1.3-25.el8_10
1
quay.io/fiware/tmforum-party-catalog:1.18.07d6969a7393a
rsync@3.1.3-23.el8_10
0:3.1.3-25.el8_10
1
quay.io/fiware/tmforum-party-role:1.18.052db89f17863
rsync@3.1.3-23.el8_10
0:3.1.3-25.el8_10
1
quay.io/fiware/tmforum-product-catalog:1.18.0e409338726da
rsync@3.1.3-23.el8_10
0:3.1.3-25.el8_10
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.