StackRadar

CVE-2026-41568

Medium

Advisory

Published 18 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.1
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
587
of 17,787 indexed, latest versions
Container images
578
deployed by those charts
Fix available
1 of 3
affected packages

Docker: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap

Carried by container images the latest versions of 587 of 17,787 indexed charts deploy, on 578 images.

Affected packageAffected versionsFixed inImages
github.com/docker/dockergolangv0.0.0-20180620051407-e2593239d949, v0.7.3-0.20190327010347-be7ac8be2ae0, v1.4.2-0.20190924003213-a8608b5b67c7, v1.4.2-0.20191121165722-d1d5f6476656+84 moreno fix listed553
github.com/moby/mobygolangv0.7.3-0.20190826074503-38ab9da00309, v1.4.2-0.20170731201646-1009e6a40b29, v1.13.1, v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible+4 moreno fix listed30
docker.iodeb20.10.24+dfsg1-1+deb12u1+b6, 26.1.5+dfsg1-9+b1326.1.5+dfsg1-9+deb13u12
OSV records
DEBIAN-CVE-2026-41568GHSA-vp62-88p7-qqf5
Also known as
GO-2026-5668

Charts affected

587 by stars
ChartLatestAffected imagesRadar Score
cost-analyzerstatcan1.82.21 of 9See more

cost-analyzer statcan 1.82.2

1 of the 9 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
prom/prometheus:v2.22.2f7ffebdd428b
github.com/docker/docker@v17.12.0-ce-rc1.0.20200706150819-a40b877fbb9e+incompatible
no fix listed

Open the chart page →

16,508
minio-operatorstatcan4.1.01 of 2See more

minio-operator statcan 4.1.0

1 of the 2 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
minio/operator:v4.1.02adc5be088f5
github.com/docker/docker@v1.4.2-0.20190924003213-a8608b5b67c7
no fix listed

Open the chart page →

6,595
sn-platform-slimstreamnative1.11.441 of 6See more

sn-platform-slim streamnative 1.11.44

1 of the 6 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.43.0f5c29683a301
github.com/docker/docker@v23.0.1+incompatible
no fix listed

Open the chart page →

10,182
switchbladeswitchblade0.0.191 of 1See more

switchblade switchblade 0.0.19

1 of the 1 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/docker/docker@v24.0.7+incompatible
no fix listed

Open the chart page →

1,360
explorersynapse0.2.161 of 6See more

explorer synapse 0.2.16

1 of the 6 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/docker/docker@v26.1.3+incompatible
no fix listed

Open the chart page →

8,556
taalhuizen-servicetaalhuizen-service1.0.01 of 3See more

taalhuizen-service taalhuizen-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,480
act-runnertektonops0.1.22 of 2See more

act-runner tektonops 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
gitea/act_runner:nightly7940221bcfc9
github.com/docker/docker@v25.0.15+incompatible
no fix listed
library/docker:23.0.6-dindafa5d5134900
github.com/docker/docker@v24.0.6+incompatible
no fix listed

Open the chart page →

4,213
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
github.com/docker/docker@v20.10.6+incompatible
no fix listed

Open the chart page →

3,764
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
github.com/docker/docker@v20.10.9+incompatible
no fix listed

Open the chart page →

21,004
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

7,336
mc-routerthl-chartsVerified publisher0.1.01 of 1See more

mc-router thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
itzg/mc-router:1.16.1bb552b59fb53
github.com/docker/docker@v20.10.17+incompatible
no fix listed

Open the chart page →

1,855
monitoringthl-chartsVerified publisher0.1.12 of 10See more

monitoring thl-charts 0.1.1

2 of the 10 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
grafana/promtail:2.4.2626900031c4e
github.com/docker/docker@v20.10.8+incompatible
no fix listed
quay.io/prometheus/prometheus:v2.34.0b37103e03399
github.com/docker/docker@v20.10.12+incompatible
no fix listed

Open the chart page →

18,908
netbirdtotmicro1.8.21 of 4See more

netbird totmicro 1.8.2

1 of the 4 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
netbirdio/management:0.60.252682e5f48f9
github.com/docker/docker@v26.1.5+incompatible
no fix listed

Open the chart page →

5,966
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/docker/docker@v26.1.2+incompatible
no fix listed

Open the chart page →

2,478
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
github.com/docker/docker@v20.10.24+incompatible
no fix listed
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/docker/docker@v20.10.24+incompatible
no fix listed

Open the chart page →

4,815
traceetrivy-operator0.24.11 of 1See more

tracee trivy-operator 0.24.1

1 of the 1 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
aquasec/tracee:0.24.1cfbbfee972e6
github.com/docker/docker@v28.1.1+incompatible
no fix listed

Open the chart page →

1,074
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,510
tfy-lokitruefoundryVerified publisher0.1.61 of 2See more

tfy-loki truefoundry 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
grafana/promtail:2.9.1063a2e57a5b14
github.com/docker/docker@v23.0.8+incompatible
no fix listed

Open the chart page →

2,813
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
grafana/grafana:12.3.070d9599b186c
github.com/moby/moby@v27.5.1+incompatible
no fix listed

Open the chart page →

4,529
devportalveecode-platform-nextVerified publisher0.1.221 of 1See more

devportal veecode-platform-next 0.1.22

1 of the 1 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
github.com/docker/docker@v28.5.1+incompatible
no fix listed

Open the chart page →

1,806
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,527
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,429
vulcanvulcan0.2.21 of 2See more

vulcan vulcan 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
mitre/vulcan:latest2bc4dfb8150f
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

1,535
aih-scannerwallarmVerified publisher2.7.111 of 2See more

aih-scanner wallarm 2.7.11

1 of the 2 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.7.11f1cb26db1f5b
github.com/docker/docker@v28.3.3+incompatible
no fix listed

Open the chart page →

3,906
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
wallarm/node-native-processing:0.23.07db2da8fce0b
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

2,824
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
github.com/docker/docker@v23.0.0-rc.2+incompatible
no fix listed

Open the chart page →

6,272
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,552
gitlab-runnerwenerme0.92.11 of 1See more

gitlab-runner wenerme 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

905
mesherywenerme1.0.701 of 1See more

meshery wenerme 1.0.70

1 of the 1 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest44b64ee128fb
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

1,356
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/docker/docker@v25.0.15-0.20260325154711-d2dbc0547253+incompatible
no fix listed

Open the chart page →

1,456
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/docker/docker@v24.0.5+incompatible
no fix listed

Open the chart page →

14,618
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/docker/docker@v24.0.2+incompatible
no fix listed

Open the chart page →

2,022
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
github.com/docker/docker@v1.13.1
no fix listed

Open the chart page →

2,745
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
github.com/docker/docker@v20.10.21+incompatible
no fix listed

Open the chart page →

13,197
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-41568.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
github.com/docker/docker@v27.4.1+incompatible
no fix listed

Open the chart page →

9,381

Container images carrying it

578 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/substra/fabric-peer:0.2.4f681e0343a31
github.com/docker/docker@v20.10.0-beta1.0.20201113105859-b6bfff2a628f+incompatible
no fix listed
1
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
github.com/docker/docker@v20.10.0-beta1.0.20201113105859-b6bfff2a628f+incompatible
no fix listed
1
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/docker/docker@v26.1.3+incompatible
no fix listed
1
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
github.com/docker/docker@v27.2.1+incompatible
no fix listed
1
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
github.com/docker/docker@v20.10.21+incompatible
no fix listed
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
github.com/docker/docker@v25.0.6+incompatible
no fix listed
1
ghcr.io/voyagermesh/gateway:v1.6.223f4da194134
github.com/docker/docker@v28.3.3+incompatible
no fix listed
1
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
github.com/docker/docker@v27.1.1+incompatible
no fix listed
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
github.com/docker/docker@v26.1.3+incompatible
no fix listed
1
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
github.com/docker/docker@v27.3.1+incompatible
no fix listed
1
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
github.com/docker/docker@v27.4.1+incompatible
no fix listed
1
public.ecr.aws/boundless-software/switchblade:release-v0.0.19-lcm01d8413d5075
github.com/docker/docker@v24.0.7+incompatible
no fix listed
1
public.ecr.aws/datadog/agent:7.73.0f4925b15ce94
github.com/docker/docker@v28.5.1+incompatible
no fix listed
1
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
github.com/docker/docker@v28.3.3+incompatible
no fix listed
1
public.ecr.aws/n8h5y2v5/rad-security/rad-sbom:v1.1.34e97e0e7a2088
github.com/docker/docker@v27.1.2+incompatible
no fix listed
1
public.ecr.aws/r3m4q3r9/pleco:0.24.0651739583336
github.com/docker/docker@v27.2.1+incompatible
no fix listed
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
github.com/docker/docker@v20.10.12+incompatible
no fix listed
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
github.com/docker/docker@v25.0.6+incompatible
no fix listed
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
github.com/docker/docker@v24.0.0+incompatible
no fix listed
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
github.com/docker/docker@v20.10.14+incompatible
no fix listed
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
github.com/docker/docker@v20.10.3+incompatible
no fix listed
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/docker/docker@v20.10.3+incompatible
no fix listed
1
quay.io/codefresh/dind:3.0.250885ab519dac
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/eformat/jenkins-agent-graalvm:latesta3b9a07648b6
github.com/docker/docker@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
no fix listed
1
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
github.com/docker/docker@v20.10.2+incompatible
no fix listed
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
github.com/docker/docker@v24.0.2+incompatible
no fix listed
1
quay.io/go-skynet/local-ai:latestd78cd113b2bc
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/docker/docker@v25.0.6+incompatible
no fix listed
1
quay.io/ibmgaragecloud/cli-tools:v0.159663f06adcb1
github.com/docker/docker@v1.4.2-0.20191121165722-d1d5f6476656
no fix listed
1
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
github.com/docker/docker@v20.10.8+incompatible
no fix listed
1
quay.io/jetstack/cert-manager-ctl:v1.13.24d9fce2c050e
github.com/docker/docker@v23.0.3+incompatible
no fix listed
1
quay.io/jetstack/cert-manager-ctl:v1.8.0595c548dee6f
github.com/docker/docker@v20.10.12+incompatible
no fix listed
1
quay.io/jetstack/cert-manager-ctl:v1.8.281b2d775edad
github.com/docker/docker@v20.10.12+incompatible
no fix listed
1
quay.io/jetstack/cert-manager-ctl:v1.12.08d54fe9d0c0d
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
quay.io/jetstack/kube-oidc-proxy:v0.3.0e045b26eb6df
github.com/docker/docker@v0.7.3-0.20190327010347-be7ac8be2ae0
no fix listed
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
github.com/docker/docker@v23.0.3+incompatible
no fix listed
1
quay.io/kube-ops/promtail:2.2.134de6387233b
github.com/docker/docker@v20.10.1+incompatible
no fix listed
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
quay.io/kubescape/kubescape:v4.0.1358651dce3376
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/kubescape/kubevuln:v0.3.4309bed2f723ea0
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/kubescape/node-agent:v0.3.2192044ed750f5e
github.com/docker/docker@v28.5.2+incompatible
github.com/moby/moby@v28.5.2+incompatible
no fix listed
no fix listed
1
quay.io/kubescape/operator:v0.2.16901b2694425e9
github.com/docker/docker@v28.5.2+incompatible
github.com/moby/moby@v28.5.2+incompatible
no fix listed
no fix listed
1
quay.io/kubescape/storage:v0.0.33101f2b053ace1
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
quay.io/mittwald/harbor-operator:v1.6.365a38180e27a
github.com/docker/docker@v24.0.9+incompatible
no fix listed
1
quay.io/nuclio/dashboard:1.17.8-amd64b5f5bd4efbee
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
quay.io/open-cluster-management/multicluster-mesh-addon:latest3e010e1188f1
github.com/docker/docker@v20.10.12+incompatible
no fix listed
1
quay.io/openshift/origin-cli:4.66722d5041b47
github.com/docker/docker@v1.4.2-0.20191121165722-d1d5f6476656
no fix listed
1
quay.io/openshift/origin-console:4.10.00bbe8b451fa3
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.