StackRadar

CVE-2026-41991

Medium

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,258
of 17,803 indexed, latest versions
Container images
2,216
deployed by those charts
Fix available
2 of 2
affected packages

Security update for gzip

Carried by container images the latest versions of 2,258 of 17,803 indexed charts deploy, on 2,216 images.

Affected packageAffected versionsFixed inImages
gzipdeb1.6-3ubuntu1, 1.6-4ubuntu1, 1.6-5ubuntu1, 1.6-5ubuntu1.1+11 more1.6-4ubuntu1+esm2, 1.10-4ubuntu4.2, 1.12-1ubuntu3.2, 1.13-1+deb13u1+2 more2,207
gziprpm1.10-150200.10.1, 1.13-160000.2.21.10-150200.13.1, 1.13-160000.3.19
OSV records
DEBIAN-CVE-2026-41991UBUNTU-CVE-2026-41991ECHO-233f-78f2-a73bSUSE-SU-2026:22818-1SUSE-SU-2026:3269-1
Also known as
USN-8512-1, USN-8733-1

Charts affected

2,258 by stars
ChartLatestAffected imagesRadar Score
xlinexline0.0.11 of 1See more

xline xline 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/liangyuanpeng/xline:latest3d2eceb44a3b
gzip@1.12-1ubuntu3
1.12-1ubuntu3.2

Open the chart page →

2,156
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,879
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,330
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,879
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
gzip@1.12-1
no fix listed

Open the chart page →

2,710
changedetection-iozekker6Verified publisher1.101.01 of 1See more

changedetection-io zekker6 1.101.0

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.6eb4a9f718801
gzip@1.12-1
no fix listed

Open the chart page →

2,649
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,879
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
gzip@1.6-5ubuntu1.1
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
gzip@1.10-0ubuntu4
no fix listed

Open the chart page →

9,280

Container images carrying it

2,216 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
typesense/typesense:28.0.rc35dea1b62b7b6e
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
gzip@1.10-0ubuntu4.1
no fix listed
1
ubuntu/squid:5.2-22.04_beta723891b5bc74
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
unitycatalog/unitycatalog-ui:main-aadc6fc3a688197b218
gzip@1.12-1
no fix listed
1
utkuozdemir/nvidia_gpu_exporter:0.3.0149f9e7e7aa3
gzip@1.10-0ubuntu4
no fix listed
1
v3xl/kubesend:0.1.06f62ca96be82
gzip@1.12-1
no fix listed
1
valkey/valkey:8.1.61f84517eca8e
gzip@1.13-1
1.13-1+deb13u1
1
valkey/valkey:9.0.54c64dfeae602
gzip@1.13-1
1.13-1+deb13u1
1
valkey/valkey:8.0.1c5d4f082b76d
gzip@1.12-1
no fix listed
1
vaultwarden/server:1.35.443498a94b22f
gzip@1.13-1
1.13-1+deb13u1
1
vaultwarden/server:1.34.384fd8a47f58d
gzip@1.12-1
no fix listed
1
vaultwarden/server:1.35.79a8eec71f4a5
gzip@1.13-1
1.13-1+deb13u1
1
vcnngr/telegram-login:latest1a849a997b6d
gzip@1.12-1
no fix listed
1
vcnngr/telegram-rebot:latest30f1f05e57a6
gzip@1.12-1
no fix listed
1
veecode/devportal-admin-ui:0.4.30c69fd286b489
gzip@1.12-1
no fix listed
1
venturenox/redis:latest83b471c193ba
gzip@1.12-1
no fix listed
1
vexorian/dizquetv:1.4.37e2b99844a5c
gzip@1.6-5ubuntu1
no fix listed
1
vientoprojects/kubernetes-monitoring-telegram-bot:latesteb2a71531741
gzip@1.6-5ubuntu1.1
no fix listed
1
vinanrra/7dtd-server:v0.4.4f9534490bd2b
gzip@1.6-5ubuntu1.2
no fix listed
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
gzip@1.12-1
no fix listed
1
vlebediantsev/notes-admin-front:latest007c6670ff48
gzip@1.12-1
no fix listed
1
vlebediantsev/notes-project-front:latest945675fd2636
gzip@1.12-1
no fix listed
1
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
gzip@1.12-1
no fix listed
1
voltha/bbsim:1.16.7d90403d58016
gzip@1.6-5ubuntu1.2
no fix listed
1
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
gzip@1.6-5ubuntu1.2
no fix listed
1
voltha/bbsim-sadis-server:0.4.0762b272d439e
gzip@1.6-5ubuntu1.2
no fix listed
1
voltha/voltha-cli:1.6.0c4e41e92f046
gzip@1.6-4ubuntu1
1.6-4ubuntu1+esm2
1
voltha/voltha-envoy:1.6.059ab2a00f712
gzip@1.6-3ubuntu1
no fix listed
1
voltha/voltha-netconf:1.6.037f80524c207
gzip@1.6-4ubuntu1
1.6-4ubuntu1+esm2
1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
gzip@1.6-4ubuntu1
1.6-4ubuntu1+esm2
1
voltha/voltha-onos:5.1.8e038acb950d3
gzip@1.6-5ubuntu1
no fix listed
1
voltha/voltha-tester:1.7.0655c3048a602
gzip@1.6-4ubuntu1
1.6-4ubuntu1+esm2
1
voltha/voltha-voltha:1.6.0ff596b62de59
gzip@1.6-4ubuntu1
1.6-4ubuntu1+esm2
1
wallarm/aih-scanner:2.7.11f1cb26db1f5b
gzip@1.13-1
1.13-1+deb13u1
1
wallarm/api-gateway:0.2.0a3d4d2f780e8
gzip@1.12-1
no fix listed
1
wallarm/gateway-controller:0.4.09c6ed23e2f0e
gzip@1.13-1
1.13-1+deb13u1
1
wallarm/kong:3.1.0-ubuntu-4.6.0ea9608c82e40
gzip@1.10-0ubuntu4.1
no fix listed
1
wasmcloud/wasmcloud:0.81.05c7acfe7e8e1
gzip@1.12-1
no fix listed
1
wateim/lighthouse-launch:latest2520149ee574
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
wavefronthq/proxy:9.2d1064d28f6eb
gzip@1.6-5ubuntu1
no fix listed
1
wazuh/wazuh-dashboard:4.4.11787550d2358
gzip@1.10-0ubuntu4.1
no fix listed
1
wazuh/wazuh-manager:4.4.121994f40e0da
gzip@1.10-0ubuntu4.1
no fix listed
1
wekanteam/wekan:v4.2268a51f0327df
gzip@1.10-0ubuntu4
no fix listed
1
wger/server:2.6997ead43aabd
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
wiktorn/overpass-api:latest9bb5f4a9b54c
gzip@1.12-1
no fix listed
1
wistefan/mvf:lateste0887302b2d8
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
wolveix/satisfactory-server:v1.9.1199be1064b18
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
wolveix/satisfactory-server:v1.9.9464d11e36e10
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
woojoong/wowza:latestec230db19652
gzip@1.6-5ubuntu1
no fix listed
1
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.