StackRadar

CVE-2026-41991

Medium

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,251
of 17,797 indexed, latest versions
Container images
2,207
deployed by those charts
Fix available
2 of 2
affected packages

Security update for gzip

Carried by container images the latest versions of 2,251 of 17,797 indexed charts deploy, on 2,207 images.

Affected packageAffected versionsFixed inImages
gzipdeb1.6-3ubuntu1, 1.6-4ubuntu1, 1.6-5ubuntu1, 1.6-5ubuntu1.1+11 more1.6-4ubuntu1+esm2, 1.10-4ubuntu4.2, 1.12-1ubuntu3.2, 1.13-1+deb13u1+2 more2,198
gziprpm1.10-150200.10.1, 1.13-160000.2.21.10-150200.13.1, 1.13-160000.3.19
OSV records
DEBIAN-CVE-2026-41991UBUNTU-CVE-2026-41991ECHO-233f-78f2-a73bSUSE-SU-2026:22818-1SUSE-SU-2026:3269-1
Also known as
USN-8512-1, USN-8733-1

Charts affected

2,251 by stars
ChartLatestAffected imagesRadar Score
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
gzip@1.6-5ubuntu1.1
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
gzip@1.10-0ubuntu4
no fix listed

Open the chart page →

9,272

Container images carrying it

2,207 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/haproxy:2.8.288baa7d29a27a
gzip@1.13-1
1.13-1+deb13u1
1
library/haproxy:2.9.6fc5748ff7c72
gzip@1.12-1
no fix listed
1
library/httpd:2.4.631ae8051591a5
gzip@1.12-1
no fix listed
1
library/influxdb:2.8571eb4514977
gzip@1.12-1
no fix listed
1
library/influxdb:1.12.3-meta8812029260b5
gzip@1.12-1
no fix listed
1
library/influxdb:1.12.3-datab0f9fc41ed79
gzip@1.12-1
no fix listed
1
library/influxdb:latestf75e48af0598
gzip@1.12-1
no fix listed
1
library/kibana:7.17.150172f1c538e7
gzip@1.10-0ubuntu4.1
no fix listed
1
library/kibana:8.18.004c0fc150f3a
gzip@1.10-0ubuntu4.1
no fix listed
1
library/kibana:7.17.8c5781ba340ef
gzip@1.10-0ubuntu4.1
no fix listed
1
library/kibana:7.17.3e2e2031c15be
gzip@1.10-0ubuntu4.1
no fix listed
1
library/logstash:7.17.817a4f64e9cf5
gzip@1.10-0ubuntu4.1
no fix listed
1
library/mariadb:10.7.307e06f2e7ae9
gzip@1.10-0ubuntu4.1
no fix listed
1
library/mariadb:10.11.21c33370a599c
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
library/mariadb:10.422edfe1c7834
gzip@1.10-0ubuntu4.1
no fix listed
1
library/mariadb:10.8.2-focal490f01279be1
gzip@1.10-0ubuntu4
no fix listed
1
library/mariadb:12.0.25b6a1eac15b8
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
library/mariadb:12.3.2628f228f0fd5
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
library/mariadb:10.6.218a16204dc96c
gzip@1.10-0ubuntu4.1
no fix listed
1
library/mariadb:10.79a48ac9f196f
gzip@1.10-0ubuntu4.1
no fix listed
1
library/mariadb:12.2.2b1cb255a9939
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
library/mariadb:10.10.2bfc25a68e113
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
library/mariadb:10.6.15e22328f4d714
gzip@1.10-0ubuntu4.1
no fix listed
1
library/mariadb:10.9.4fbb8456ebdb1
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
library/mariadb:11.7.2fcc7fcd7114a
gzip@1.12-1ubuntu3
1.12-1ubuntu3.2
1
library/matomo:5.1.2-apache2415789e1602
gzip@1.12-1
no fix listed
1
library/matomo:5.13.0-apache8e6bdd396496
gzip@1.13-1
1.13-1+deb13u1
1
library/memcached:1.6.4226983a43c918
gzip@1.13-1
1.13-1+deb13u1
1
library/memcached:1.6.409ae868852d0b
gzip@1.13-1
1.13-1+deb13u1
1
library/memcached:1.6.40cc523a19da58
gzip@1.13-1
1.13-1+deb13u1
1
library/memcached:1.6.45dc561d52bb8a
gzip@1.13-1
1.13-1+deb13u1
1
library/memcached:1.6.42-trixiee2a8683c7fbb
gzip@1.13-1
1.13-1+deb13u1
1
library/mongo:7.0.140032d2ca20db
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
library/mongo:4.4.1305678ae4e5e1
gzip@1.10-0ubuntu4.1
no fix listed
1
library/mongo:3.6146c1fd999a6
gzip@1.6-4ubuntu1
1.6-4ubuntu1+esm2
1
library/mongo:5.0.32-focal3b6c281e1c08
gzip@1.10-0ubuntu4.1
no fix listed
1
library/mongo:4.4-bionic3d0e6df9fd5b
gzip@1.6-5ubuntu1
no fix listed
1
library/mongo:5.0.14-focal50cae5081ab4
gzip@1.10-0ubuntu4.1
no fix listed
1
library/mongo:6.0.12646902910d6a
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
library/mongo:4.2699d652ed674
gzip@1.6-5ubuntu1.2
no fix listed
1
library/mongo:4.2.16ca49afbcb2b
gzip@1.6-5ubuntu1
no fix listed
1
library/mongo:6.0.271a63fc2438e
gzip@1.10-0ubuntu4.1
no fix listed
1
library/mongo:5.0.217c81758cb295
gzip@1.10-0ubuntu4.1
no fix listed
1
library/mongo:7.0.28-jammy88785f6f665a
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
library/mongo:4.2.21-bionic9cb28f7291d9
gzip@1.6-5ubuntu1.2
no fix listed
1
library/mongo:7.0.12ae1cf99fa7bf
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
library/mongo:4.4.18d23ec07162ca
gzip@1.10-0ubuntu4.1
no fix listed
1
library/mongo:8.0.11dca8d11fe467
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
library/mysql:8.0-debian9382e4f6f7f0
gzip@1.12-1
no fix listed
1
library/neo4j:2026.05.0-enterprise2caf944aa4a5
gzip@1.13-1
1.13-1+deb13u1
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.