StackRadar

CVE-2026-4105

Medium

Advisory

Published 13 Mar 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.7
base score, highest
EPSS
0.001
4th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
739
of 17,787 indexed, latest versions
Container images
816
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 739 of 17,787 indexed charts deploy, on 816 images.

Affected packageAffected versionsFixed inImages
systemddeb252.6-1, 252.12-1~deb12u1, 252.17-1~deb12u1, 252.19-1~deb12u1+12 more252.39-1~deb12u2, 257.13-1~deb13u1816
OSV records
DEBIAN-CVE-2026-4105

Charts affected

739 by stars
ChartLatestAffected imagesRadar Score
speecht5test-opea1.0.01 of 1See more

speecht5 test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
opea/speecht5:1.0249afad3d268
systemd@252.30-1~deb12u2
252.39-1~deb12u2

Open the chart page →

9,616
teitest-opea1.0.01 of 1See more

tei test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
systemd@252.26-1~deb12u2
252.39-1~deb12u2

Open the chart page →

2,277
teireranktest-opea1.0.01 of 1See more

teirerank test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
ghcr.io/huggingface/text-embeddings-inference:cpu-1.50502794a4d86
systemd@252.26-1~deb12u2
252.39-1~deb12u2

Open the chart page →

2,277
ttstest-opea1.0.01 of 1See more

tts test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
opea/tts:1.0257ae94709e9
systemd@252.30-1~deb12u2
252.39-1~deb12u2

Open the chart page →

4,377
web-retrievertest-opea1.0.01 of 1See more

web-retriever test-opea 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
opea/web-retriever-chroma:1.0fe08165d7770
systemd@252.30-1~deb12u2
252.39-1~deb12u2

Open the chart page →

5,350
codeth-chartsVerified publisher0.1.01 of 1See more

code th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
collabora/code:24.04.13.2.101dc4ab83977
systemd@252.33-1~deb12u1
252.39-1~deb12u2

Open the chart page →

3,261
jellyfinth-chartsVerified publisher0.1.01 of 1See more

jellyfin th-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.10.77ae36aab93ef
systemd@252.36-1~deb12u1
252.39-1~deb12u2

Open the chart page →

3,958
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
systemd@252.38-1~deb12u1
252.39-1~deb12u2

Open the chart page →

10,086
thingsboardthingsboardVerified publisher0.1.31 of 12See more

thingsboard thingsboard 0.1.3

1 of the 12 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
systemd@252.33-1~deb12u1
252.39-1~deb12u2

Open the chart page →

25,394
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
systemd@252.38-1~deb12u1
252.39-1~deb12u2

Open the chart page →

5,535
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
erenozcan17/flask_analytics:v3.1c9b6f0dfbffc
systemd@257.7-1
257.13-1~deb13u1

Open the chart page →

6,973
saleor-appstrieb-work0.6.01 of 5See more

saleor-apps trieb-work 0.6.0

1 of the 5 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
library/redis:8.2.2f0957bcaa75f
systemd@252.39-1~deb12u1
252.39-1~deb12u2

Open the chart page →

6,994
trowtrow0.13.01 of 1See more

trow trow 0.13.0

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
ghcr.io/trow-registry/trow:0.10.075b7d2dcdb91
systemd@257.9-1~deb13u1
257.13-1~deb13u1

Open the chart page →

1,269
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
systemd@252.19-1~deb12u1
252.39-1~deb12u2

Open the chart page →

17,323
bobby-apitumogroup1.0.11 of 1See more

bobby-api tumogroup 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
sondresjo/bobby-api:latestfe534731909a
systemd@252.38-1~deb12u1
252.39-1~deb12u2

Open the chart page →

2,293
umbrella-chartumbrella-chartVerified publisher0.1.13 of 5See more

umbrella-chart umbrella-chart 0.1.1

3 of the 5 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
hassroutyyoussef/accountservice:latest1f01edf1ee0c
systemd@252.31-1~deb12u1
252.39-1~deb12u2
hassroutyyoussef/orderservice:latest2fc3d1617928
systemd@252.31-1~deb12u1
252.39-1~deb12u2
hassroutyyoussef/userservice:lateste0392e2b4a90
systemd@252.31-1~deb12u1
252.39-1~deb12u2

Open the chart page →

7,440
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
bitnamilegacy/kubectl:1.301249fc292e84
systemd@252.31-1~deb12u1
252.39-1~deb12u2

Open the chart page →

8,607
kenerunxwaresVerified publisher2026.2.51 of 1See more

kener unxwares 2026.2.5

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
systemd@252.33-1~deb12u1
252.39-1~deb12u2

Open the chart page →

5,228
opencloudunxwaresVerified publisher0.2.36 of 13See more

opencloud unxwares 0.2.3

6 of the 13 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
systemd@252.33-1~deb12u1
252.39-1~deb12u2
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
systemd@252.33-1~deb12u1
252.39-1~deb12u2
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
systemd@252.33-1~deb12u1
252.39-1~deb12u2
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
systemd@252.33-1~deb12u1
252.39-1~deb12u2
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
systemd@252.33-1~deb12u1
252.39-1~deb12u2
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
systemd@252.33-1~deb12u1
252.39-1~deb12u2

Open the chart page →

45,239
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
systemd@252.12-1~deb12u1
252.39-1~deb12u2

Open the chart page →

14,358
telegram-rebotvcnngrVerified publisher1.0.02 of 3See more

telegram-rebot vcnngr 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
vcnngr/telegram-login:latest1a849a997b6d
systemd@252.36-1~deb12u1
252.39-1~deb12u2
vcnngr/telegram-rebot:latest30f1f05e57a6
systemd@252.36-1~deb12u1
252.39-1~deb12u2

Open the chart page →

5,026
scrutinyvhdirkVerified publisher0.1.31 of 1See more

scrutiny vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
systemd@252.39-1~deb12u1
252.39-1~deb12u2

Open the chart page →

4,382
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
systemd@252.33-1~deb12u1
252.39-1~deb12u2

Open the chart page →

10,795
api-gatewaywallarmVerified publisher0.2.01 of 1See more

api-gateway wallarm 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
wallarm/api-gateway:0.2.0a3d4d2f780e8
systemd@252.39-1~deb12u1
252.39-1~deb12u2

Open the chart page →

2,288
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
systemd@252.36-1~deb12u1
252.39-1~deb12u2

Open the chart page →

5,984
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
systemd@252.22-1~deb12u1
252.39-1~deb12u2

Open the chart page →

7,085
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
systemd@252.6-1
252.39-1~deb12u2

Open the chart page →

10,001
welcome-elos-webappwelcome-elos-webappVerified publisher2.0.01 of 1See more

welcome-elos-webapp welcome-elos-webapp 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
pococze/python-hello-elos:2.0.07a1aab425e51
systemd@252.30-1~deb12u2
252.39-1~deb12u2

Open the chart page →

2,678
apisixwenerme2.17.01 of 3See more

apisix wenerme 2.17.0

1 of the 3 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
systemd@252.38-1~deb12u1
252.39-1~deb12u2

Open the chart page →

3,045
giteawenerme12.7.03 of 4See more

gitea wenerme 12.7.0

3 of the 4 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
systemd@252.38-1~deb12u1
252.39-1~deb12u2
bitnamilegacy/postgresql-repmgr:17.6.0-debian-12-r2f12387ec882b
systemd@252.38-1~deb12u1
252.39-1~deb12u2
bitnamilegacy/valkey-cluster:8.1.3-debian-12-r332869e769b7e
systemd@252.38-1~deb12u1
252.39-1~deb12u2

Open the chart page →

8,811
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
qdrant/qdrant:v1.7.45f2a56b95266
systemd@252.19-1~deb12u1
252.39-1~deb12u2

Open the chart page →

14,983
keycloakwiremindVerified publisher25.3.12 of 2See more

keycloak wiremind 25.3.1

2 of the 2 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
systemd@252.38-1~deb12u1
252.39-1~deb12u2
ghcr.io/wiremind/bitnami/keycloak:26.5.0-debian-12-r38622ea9e43c0
systemd@252.39-1~deb12u1
252.39-1~deb12u2

Open the chart page →

7,624
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
systemd@252.19-1~deb12u1
252.39-1~deb12u2

Open the chart page →

5,542
rabbitmqwiremindVerified publisher16.0.171 of 1See more

rabbitmq wiremind 16.0.17

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/rabbitmq:4.2.2-debian-12-r11572e12bc93c
systemd@252.39-1~deb12u1
252.39-1~deb12u2

Open the chart page →

2,473
rediswiremindVerified publisher23.0.61 of 1See more

redis wiremind 23.0.6

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
ghcr.io/wiremind/bitnami/redis:8.4.0-debian-12-r31f0f7ddc4370
systemd@252.39-1~deb12u1
252.39-1~deb12u2

Open the chart page →

2,113
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
systemd@252.31-1~deb12u1
252.39-1~deb12u2

Open the chart page →

11,577
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
systemd@252.22-1~deb12u1
252.39-1~deb12u2

Open the chart page →

7,673
xkopsxkops0.1.03 of 5See more

xkops xkops 0.1.0

3 of the 5 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
systemd@252.30-1~deb12u2
252.39-1~deb12u2
hamzaarshad10/querypodpy:1.7154f38e8668e
systemd@252.30-1~deb12u2
252.39-1~deb12u2
murtazashah46/helmfile:latest4d11726cf803
systemd@252.30-1~deb12u2
252.39-1~deb12u2

Open the chart page →

13,677
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-4105.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
systemd@252.22-1~deb12u1
252.39-1~deb12u2

Open the chart page →

2,661

Container images carrying it

816 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
48n6e/camellia-redis-proxy:1.4.0-jdk-21-0.0.1a6ed886fddfc
systemd@252.12-1~deb12u1
252.39-1~deb12u2
1
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
systemd@257.9-1~deb13u1
257.13-1~deb13u1
1
aboogie/login_test_backend:new9c41a4483ac8
systemd@252.26-1~deb12u2
252.39-1~deb12u2
1
actualbudget/actual-server:25.3.158fecd9088b7
systemd@252.33-1~deb12u1
252.39-1~deb12u2
1
aibrix/metadata-service:v0.7.063fb81a64377
systemd@252.36-1~deb12u1
252.39-1~deb12u2
1
airbyte/manifest-server:7.23.73b3a670af168
systemd@252.39-1~deb12u1
252.39-1~deb12u2
1
airbyte/pod-sweeper:1.5.198d2c39d512e
systemd@252.31-1~deb12u1
252.39-1~deb12u2
1
akaunting/akaunting:3.0.1552811b36ec3a
systemd@252.6-1
252.39-1~deb12u2
1
alazidis/stornx:1.1.1602d4f7f090c
systemd@252.39-1~deb12u1
252.39-1~deb12u2
1
allegroai/clearml:2.0.0-613713ae38f7daf
systemd@252.31-1~deb12u1
252.39-1~deb12u2
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
systemd@252.12-1~deb12u1
252.39-1~deb12u2
1
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
systemd@257.9-1~deb13u1
257.13-1~deb13u1
1
anujdatar/cups:25.07.01685df04a643b
systemd@252.38-1~deb12u1
252.39-1~deb12u2
1
apache/airflow:2.8.4-python3.964e58748b6b9
systemd@252.22-1~deb12u1
252.39-1~deb12u2
1
apache/airflow:2.10.2-python3.9ce90bdc3d2af
systemd@252.30-1~deb12u2
252.39-1~deb12u2
1
apache/airflow:2.8.1e5560ad0b86e
systemd@252.22-1~deb12u1
252.39-1~deb12u2
1
apache/superset:4.0.1ab9467fd712c
systemd@252.22-1~deb12u1
252.39-1~deb12u2
1
apecloud/aperag:v0.0.0-nightly8ac9947a2c84
systemd@257.8-1~deb13u2
257.13-1~deb13u1
1
archivebox/archivebox:0.7.41a5a37331091
systemd@252.39-1~deb12u1
252.39-1~deb12u2
1
aristidetm/basic-notebook:3.6.5469dbc951224
systemd@252.22-1~deb12u1
252.39-1~deb12u2
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
systemd@252.26-1~deb12u2
252.39-1~deb12u2
1
artur9010/wait-for:v1.0.06b4de3ce8b0e
systemd@252.22-1~deb12u1
252.39-1~deb12u2
1
assistiot/identity-manager_db:latest0d3e6d35f168
systemd@252.17-1~deb12u1
252.39-1~deb12u2
1
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
systemd@252.22-1~deb12u1
252.39-1~deb12u2
1
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
systemd@252.22-1~deb12u1
252.39-1~deb12u2
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
systemd@252.12-1~deb12u1
252.39-1~deb12u2
1
athou/commafeed:6.2.0-postgresql5e388351df1a
systemd@257.9-1~deb13u1
257.13-1~deb13u1
1
avaprotocol/ap-avs:1.2.0c430ea5c37d6
systemd@252.26-1~deb12u2
252.39-1~deb12u2
1
avinash263/pyredis263:latestaa2b8727f1a6
systemd@252.6-1
252.39-1~deb12u2
1
avzini/web-app:latestf40b30210ed0
systemd@252.17-1~deb12u1
252.39-1~deb12u2
1
baserow/backend:1.31.1e0b3c8130b91
systemd@252.33-1~deb12u1
252.39-1~deb12u2
1
baserow/baserow:1.30.1df0c42eb67e8
systemd@252.31-1~deb12u1
252.39-1~deb12u2
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
systemd@257.8-1~deb13u2
257.13-1~deb13u1
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
systemd@252.36-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/cassandra:4.1.7-debian-12-r32b7a217999a1
systemd@252.31-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/clickhouse:24.12.3-debian-12-r13cf6544f6c6c
systemd@252.33-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/clickhouse:24.12.4c7e70bf1d3fb
systemd@252.33-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/clickhouse:24.6.2-debian-12-r3dcc172c6c55f
systemd@252.26-1~deb12u2
252.39-1~deb12u2
1
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
systemd@252.38-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/elasticsearch:8.12.215d4647fd491
systemd@252.22-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
systemd@252.36-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/git:latest4b08d0c5af8d
systemd@252.38-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
systemd@252.31-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/keycloak:24.0.4cc599cbd15ff
systemd@252.22-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
systemd@252.38-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/kubectl:1.301249fc292e84
systemd@252.31-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/kubectl:1.3164614ef8290f
systemd@252.31-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/kubectl:1.30.5744f84cf7493
systemd@252.30-1~deb12u2
252.39-1~deb12u2
1
bitnamilegacy/kubectl:1.29.3f5fc0d561d9e
systemd@252.22-1~deb12u1
252.39-1~deb12u2
1
bitnamilegacy/kube-state-metrics:204a3044b384b
systemd@252.38-1~deb12u1
252.39-1~deb12u2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.