StackRadar

CVE-2026-41991

Medium

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,251
of 17,797 indexed, latest versions
Container images
2,207
deployed by those charts
Fix available
2 of 2
affected packages

Security update for gzip

Carried by container images the latest versions of 2,251 of 17,797 indexed charts deploy, on 2,207 images.

Affected packageAffected versionsFixed inImages
gzipdeb1.6-3ubuntu1, 1.6-4ubuntu1, 1.6-5ubuntu1, 1.6-5ubuntu1.1+11 more1.6-4ubuntu1+esm2, 1.10-4ubuntu4.2, 1.12-1ubuntu3.2, 1.13-1+deb13u1+2 more2,198
gziprpm1.10-150200.10.1, 1.13-160000.2.21.10-150200.13.1, 1.13-160000.3.19
OSV records
DEBIAN-CVE-2026-41991UBUNTU-CVE-2026-41991ECHO-233f-78f2-a73bSUSE-SU-2026:22818-1SUSE-SU-2026:3269-1
Also known as
USN-8512-1, USN-8733-1

Charts affected

2,251 by stars
ChartLatestAffected imagesRadar Score
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
gzip@1.6-5ubuntu1.1
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
gzip@1.10-0ubuntu4
no fix listed

Open the chart page →

9,272

Container images carrying it

2,207 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
library/redis:8.48df317692c59
gzip@1.13-1
1.13-1+deb13u1
1
library/redis:8.0.2b43d2dcbbdb1
gzip@1.12-1
no fix listed
1
library/redis:7.4.1bb142a9c18ac
gzip@1.12-1
no fix listed
1
library/redis:8.0.3be0a135f1955
gzip@1.12-1
no fix listed
1
library/redis:8.2.3d31852005202
gzip@1.12-1
no fix listed
1
library/redmine:6.1.204ac44a2595b
gzip@1.13-1
1.13-1+deb13u1
1
library/sonarqube:10.7.0-community0842dcd4c8f8
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
library/sonarqube:10.0.0-communityef9723cf4fe4
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
library/telegraf:1.27507a3eecf809
gzip@1.12-1
no fix listed
1
library/ubuntu:bionic152dc042452c
gzip@1.6-5ubuntu1.2
no fix listed
1
library/varnish:7.5.04d0bb287d87b
gzip@1.12-1
no fix listed
1
library/wordpress:6.4.3-apache8ae66efb09a2
gzip@1.12-1
no fix listed
1
library/wordpress:6.9.4-fpmad4a8bae2eb4
gzip@1.13-1
1.13-1+deb13u1
1
library/wordpress:php8.1-apachef73396626d2f
gzip@1.13-1
1.13-1+deb13u1
1
library/zookeeper:3.8-temurin55d1e5b2e601
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
library/zookeeper:3.9.4dfa9ba46d14b
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
libretranslate/libretranslate:v1.9.61de2d7056bb8
gzip@1.12-1
no fix listed
1
lightbend/curl:7.47.0b0c9894ac8dd
gzip@1.6-4ubuntu1
1.6-4ubuntu1+esm2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
gzip@1.6-5ubuntu1
no fix listed
1
linuxserver/calibre-web:0.6.24241009026e6f
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
linuxserver/calibre-web:version-0.6.12938810eca3d3
gzip@1.10-0ubuntu4
no fix listed
1
linuxserver/cloud9:latest45c5fe102ff3
gzip@1.6-5ubuntu1.1
no fix listed
1
linuxserver/code-server:4.10.1a5e43a05ae79
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
linuxserver/codimd:latestb801bbcf6386
gzip@1.6-5ubuntu1
no fix listed
1
linuxserver/deluge:18.04.10ac871624394
gzip@1.6-5ubuntu1.1
no fix listed
1
linuxserver/deluge:version-2.0.3-2201906121747ubuntu18.04.12ce561a95e7b
gzip@1.6-5ubuntu1.1
no fix listed
1
linuxserver/foldingathome:7.6.219a997426d71e
gzip@1.12-1ubuntu3
1.12-1ubuntu3.2
1
linuxserver/jellyfin:10.7.72427dde159a2
gzip@1.10-0ubuntu4
no fix listed
1
linuxserver/lazylibrarian:version-1152df82f93d2560e233
gzip@1.6-5ubuntu1
no fix listed
1
linuxserver/ombi:3.0.4572-ls452fbb21fb4903
gzip@1.6-5ubuntu1
no fix listed
1
linuxserver/plex:1.25.24a13ced2326c
gzip@1.10-0ubuntu4
no fix listed
1
linuxserver/unifi-controller:8.0.240ae315a3a456
gzip@1.10-0ubuntu4.1
no fix listed
1
linuxserver/unifi-controller:7.3.83ab105cc50322
gzip@1.10-0ubuntu4.1
no fix listed
1
lis314/project-zomboid-docker:latestaa2089c37920
gzip@1.12-1
no fix listed
1
litmuschaos/mongo:4.2.899961210d467
gzip@1.6-5ubuntu1
no fix listed
1
livekit/ingress:v1.2.21ab01641b366
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
lmacka/snappass:2.1.293f5c048b7d4
gzip@1.13-1
1.13-1+deb13u1
1
localstack/localstack:latest4abc29e923e5
gzip@1.13-1
1.13-1+deb13u1
1
localstack/localstack:3.19d278167f2b7
gzip@1.12-1
no fix listed
1
locustio/locust:2.24.151d866285170
gzip@1.12-1
no fix listed
1
logiqai/flash:v3.10.265b996bc7bdc
gzip@1.12-1
no fix listed
1
longhornio/longhorn-manager:v1.10.05b0bc1b88f0c
gzip@1.10-150200.10.1
1.10-150200.13.1
1
longhornio/longhorn-manager:v1.2.3dca34321452c
gzip@1.10-0ubuntu4
no fix listed
1
longhornio/longhorn-manager:v1.1.1ede61fe2a472
gzip@1.6-5ubuntu1
no fix listed
1
longhornio/longhorn-manager:v1.12.0fd245bae2e82
gzip@1.10-150200.10.1
1.10-150200.13.1
1
longhornio/longhorn-share-manager:v1.10.09f6e5e3be8ab
gzip@1.10-150200.10.1
1.10-150200.13.1
1
longhornio/longhorn-share-manager:v1.12.0cb9d6863e4c6
gzip@1.10-150200.10.1
1.10-150200.13.1
1
longhornio/longhorn-ui:v1.12.03870d52a2b0a
gzip@1.10-150200.10.1
1.10-150200.13.1
1
longhornio/longhorn-ui:v1.10.0e60f36161511
gzip@1.10-150200.10.1
1.10-150200.13.1
1
longhornio/upgrade-responder:v0.2.05875cef29348
gzip@1.10-0ubuntu4.1
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.