StackRadar

CVE-2026-41991

Medium

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,251
of 17,797 indexed, latest versions
Container images
2,207
deployed by those charts
Fix available
2 of 2
affected packages

Security update for gzip

Carried by container images the latest versions of 2,251 of 17,797 indexed charts deploy, on 2,207 images.

Affected packageAffected versionsFixed inImages
gzipdeb1.6-3ubuntu1, 1.6-4ubuntu1, 1.6-5ubuntu1, 1.6-5ubuntu1.1+11 more1.6-4ubuntu1+esm2, 1.10-4ubuntu4.2, 1.12-1ubuntu3.2, 1.13-1+deb13u1+2 more2,198
gziprpm1.10-150200.10.1, 1.13-160000.2.21.10-150200.13.1, 1.13-160000.3.19
OSV records
DEBIAN-CVE-2026-41991UBUNTU-CVE-2026-41991ECHO-233f-78f2-a73bSUSE-SU-2026:22818-1SUSE-SU-2026:3269-1
Also known as
USN-8512-1, USN-8733-1

Charts affected

2,251 by stars
ChartLatestAffected imagesRadar Score
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
gzip@1.6-5ubuntu1.1
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
gzip@1.10-0ubuntu4
no fix listed

Open the chart page →

9,272

Container images carrying it

2,207 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
dbgate/dbgate:7.2.3f2dc7423ea88
gzip@1.12-1
no fix listed
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
ddosify/alaz:v0.12.0ea602056d9ce
gzip@1.12-1
no fix listed
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
gzip@1.12-1
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
gzip@1.12-1
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
gzip@1.12-1
no fix listed
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
gzip@1.12-1
no fix listed
1
decisionrules/ai-engine:latest38c377e7c01e
gzip@1.13-1
1.13-1+deb13u1
1
deconzcommunity/deconz:2.29.2062de2362641
gzip@1.12-1
no fix listed
1
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
gzip@1.10-0ubuntu4.1
no fix listed
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
defactops/defactops-backend:1.0.2307b663c0092a
gzip@1.12-1
no fix listed
1
defectdojo/defectdojo-django:3.3.100c597abdbb535
gzip@1.13-1
1.13-1+deb13u1
1
deimosfr/dnsmasq-k8s:1.4.1284c4040fc6d
gzip@1.13-1
1.13-1+deb13u1
1
dellcloud/category:distributed02fc234353a9
gzip@1.10-0ubuntu4
no fix listed
1
dellcloud/pages:1.04d2eb25b9225
gzip@1.10-0ubuntu4
no fix listed
1
dependencytrack/apiserver:4.14.21ba4f004e1ec
gzip@1.13-1
1.13-1+deb13u1
1
dependencytrack/apiserver:latestf1da63ed610a
gzip@1.13-1
1.13-1+deb13u1
1
dessalines/lemmy:0.19.2079e9f02c286c
gzip@1.12-1
no fix listed
1
dessalines/lemmy-ui:0.19.20ee4c620d8e93
gzip@1.13-1
1.13-1+deb13u1
1
devopsgoofy/k8s-platform:latestad865312099f
gzip@1.12-1
no fix listed
1
devopshq/artifactory-cleanup:1.0.1830e093bffa91
gzip@1.12-1
no fix listed
1
dgraph/dgraph:v24.1.4b57fa31f9b7f
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
gzip@1.10-0ubuntu4
no fix listed
1
diygod/rsshub:latest1d4b508b6357
gzip@1.13-1
1.13-1+deb13u1
1
diygod/rsshub:2025-11-097a6312cac0d5
gzip@1.12-1
no fix listed
1
djjudas21/alertify:0.1.0ba22be670c37
gzip@1.12-1
no fix listed
1
dniel/api-posts:master45a667852f2a
gzip@1.6-5ubuntu1
no fix listed
1
dobtc/bitcoin:25.1a870f7cb1105
gzip@1.12-1
no fix listed
1
docmost/docmost:0.96.0b56947fcfd08
gzip@1.13-1
1.13-1+deb13u1
1
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
gzip@1.13-1
1.13-1+deb13u1
1
dolibarr/dolibarr:24.0.069ec52e3b7ef
gzip@1.12-1
no fix listed
1
dolibarr/dolibarr:22.0.47ad88fc9b13c
gzip@1.12-1
no fix listed
1
domainmod/domainmod:4.23.04017bfe4c597
gzip@1.12-1
no fix listed
1
dongjiang1989/lxcfs:v6.0.34bf9ae391948
gzip@1.10-0ubuntu4.1
no fix listed
1
dragonflyoss/client:v1.5.59fe2a1d6206f
gzip@1.12-1
no fix listed
1
dragonflyoss/client:v0.1.82edf3e921f4e0
gzip@1.12-1
no fix listed
1
dremio/dremio-oss:24.1.080ed2e3b7c43
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
drorivry4/rego:lateste035d49b15ca
gzip@1.12-1
no fix listed
1
drpcorg/dshackle:0.54.08858fae1859d
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
drumsergio/genieacs:1.2.16.028244054e1bf
gzip@1.12-1
no fix listed
1
dserio83/velero-api:0.3.16b3d9115fee2
gzip@1.12-1
no fix listed
1
dserio83/velero-watchdog:0.1.8d5deae589229
gzip@1.12-1
no fix listed
1
duck1123/cert-downloader:latest0e29f19fa67c
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
duck1123/lnd-fileserver:latest9d6fb247b714
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
dzikoysk/reposilite:3.5.264128c2d7a6ba
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
eceasy/cli-proxy-api:v7.3.3f9abbf3fa5fe
gzip@1.12-1
no fix listed
1
eclipseaerios/aerios-k8s-shim:v1.0.0d4ed3d8e5db4
gzip@1.13-1
1.13-1+deb13u1
1
eclipseaerios/hlo-allocator:v3.0.03cc1d94cfe96
gzip@1.13-1
1.13-1+deb13u1
1
eclipseaerios/hlo-data-aggregator:v3.0.0b433c2b9f5dc
gzip@1.13-1
1.13-1+deb13u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.