StackRadar

CVE-2026-41991

Medium

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,251
of 17,797 indexed, latest versions
Container images
2,207
deployed by those charts
Fix available
2 of 2
affected packages

Security update for gzip

Carried by container images the latest versions of 2,251 of 17,797 indexed charts deploy, on 2,207 images.

Affected packageAffected versionsFixed inImages
gzipdeb1.6-3ubuntu1, 1.6-4ubuntu1, 1.6-5ubuntu1, 1.6-5ubuntu1.1+11 more1.6-4ubuntu1+esm2, 1.10-4ubuntu4.2, 1.12-1ubuntu3.2, 1.13-1+deb13u1+2 more2,198
gziprpm1.10-150200.10.1, 1.13-160000.2.21.10-150200.13.1, 1.13-160000.3.19
OSV records
DEBIAN-CVE-2026-41991UBUNTU-CVE-2026-41991ECHO-233f-78f2-a73bSUSE-SU-2026:22818-1SUSE-SU-2026:3269-1
Also known as
USN-8512-1, USN-8733-1

Charts affected

2,251 by stars
ChartLatestAffected imagesRadar Score
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
gzip@1.6-5ubuntu1.1
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
gzip@1.10-0ubuntu4
no fix listed

Open the chart page →

9,272

Container images carrying it

2,207 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/neo4j:2026.02.25ab4ab0358cf
gzip@1.13-1
1.13-1+deb13u1
1
library/neo4j:2026.05.06c162e2432f8
gzip@1.13-1
1.13-1+deb13u1
1
library/nextcloud:31.0.6-apache588609d76b21
gzip@1.12-1
no fix listed
1
library/nextcloud:34.0.4:34.0.4-apache8418c398d767
gzip@1.13-1
1.13-1+deb13u1
1
library/nextcloud:31.0.10-apacheb7faa1653c39
gzip@1.13-1
1.13-1+deb13u1
1
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
gzip@1.13-1
1.13-1+deb13u1
1
library/nextcloud:34.0.4-apachede4ad9389386
gzip@1.13-1
1.13-1+deb13u1
1
library/nginx:1.27.409369da6b103
gzip@1.12-1
no fix listed
1
library/nginx:1.291881968aff6f
gzip@1.13-1
1.13-1+deb13u1
1
library/nginx:1.276784fb0834aa
gzip@1.12-1
no fix listed
1
library/nginx:1.25.167f9a4f10d14
gzip@1.12-1
no fix listed
1
library/nginx:1.25.49ff236ed47fe
gzip@1.12-1
no fix listed
1
library/nginx:1.31a53fc6c27208
gzip@1.13-1
1.13-1+deb13u1
1
library/nginx:1.27.3fb197595ebe7
gzip@1.12-1
no fix listed
1
library/node:22-bookworm-slim83f487e0a634
gzip@1.12-1
no fix listed
1
library/node:208f693eaa7e0a
gzip@1.12-1
no fix listed
1
library/node:latestf5d1cc40abc1
gzip@1.13-1
1.13-1+deb13u1
1
library/php:8.4-fpm59fa733c9af6
gzip@1.13-1
1.13-1+deb13u1
1
library/postgres:18.0073e7c8b84e2
gzip@1.13-1
1.13-1+deb13u1
1
library/postgres:17.4304ab8135187
gzip@1.12-1
no fix listed
1
library/postgres:18.43a82e1f56c8f
gzip@1.13-1
1.13-1+deb13u1
1
library/postgres:16.11468e1f126ca5
gzip@1.13-1
1.13-1+deb13u1
1
library/postgres:16.6557fea37a744
gzip@1.12-1
no fix listed
1
library/postgres:18.369e8582b781c
gzip@1.13-1
1.13-1+deb13u1
1
library/postgres:15.186eb0add3b77c
gzip@1.13-1
1.13-1+deb13u1
1
library/postgres:15.38775adb39f0d
gzip@1.12-1
no fix listed
1
library/postgres:18.48ff36f3c6637
gzip@1.13-1
1.13-1+deb13u1
1
library/postgres:18.3a9abf4275f9e
gzip@1.13-1
1.13-1+deb13u1
1
library/postgres:17.5aadf2c0696f5
gzip@1.13-1
1.13-1+deb13u1
1
library/postgres:13.12ced3ba927f4c
gzip@1.12-1
no fix listed
1
library/postgres:15.18-bookworme8db9bd3e9e1
gzip@1.12-1
no fix listed
1
library/postgres:14.22eba8ddbdd837
gzip@1.13-1
1.13-1+deb13u1
1
library/postgres:17.10ebba4f4de37f
gzip@1.13-1
1.13-1+deb13u1
1
library/postgres:17.5-bookwormfbcea1bd13b6
gzip@1.12-1
no fix listed
1
library/python:3.1070c9cc675605
gzip@1.13-1
1.13-1+deb13u1
1
library/python:3.11-slim9534e5a8e315
gzip@1.13-1
1.13-1+deb13u1
1
library/python:3.8d41127070014
gzip@1.12-1
no fix listed
1
library/python:3.9da5aee29682d
gzip@1.13-1
1.13-1+deb13u1
1
library/rabbitmq:3.12.100742852455ad
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
library/rabbitmq:3.11.5-management1b0f675d2f24
gzip@1.10-0ubuntu4.1
no fix listed
1
library/rabbitmq:4.2.87561d672fae4
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
library/rabbitmq:3.7-managementb6dd45cc35b3
gzip@1.6-5ubuntu1
no fix listed
1
library/redis:8.6.2009cc37796fb
gzip@1.13-1
1.13-1+deb13u1
1
library/redis:8.8.0234c902a2db4
gzip@1.13-1
1.13-1+deb13u1
1
library/redis:8.4.03906b477e4b6
gzip@1.12-1
no fix listed
1
library/redis:8.8.1-trixie3eafabb4c93f
gzip@1.13-1
1.13-1+deb13u1
1
library/redis:8.2.24521b581dbdd
gzip@1.12-1
no fix listed
1
library/redis:8.6.34d25e2fe601f
gzip@1.13-1
1.13-1+deb13u1
1
library/redis:8.2.15fa2edb1e408
gzip@1.12-1
no fix listed
1
library/redis83edc2b8e9ff
gzip@1.12-1
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.