StackRadar

CVE-2026-41991

Medium

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.7
base score, highest
EPSS
0.002
8th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,258
of 17,803 indexed, latest versions
Container images
2,216
deployed by those charts
Fix available
2 of 2
affected packages

Security update for gzip

Carried by container images the latest versions of 2,258 of 17,803 indexed charts deploy, on 2,216 images.

Affected packageAffected versionsFixed inImages
gzipdeb1.6-3ubuntu1, 1.6-4ubuntu1, 1.6-5ubuntu1, 1.6-5ubuntu1.1+11 more1.6-4ubuntu1+esm2, 1.10-4ubuntu4.2, 1.12-1ubuntu3.2, 1.13-1+deb13u1+2 more2,207
gziprpm1.10-150200.10.1, 1.13-160000.2.21.10-150200.13.1, 1.13-160000.3.19
OSV records
DEBIAN-CVE-2026-41991UBUNTU-CVE-2026-41991ECHO-233f-78f2-a73bSUSE-SU-2026:22818-1SUSE-SU-2026:3269-1
Also known as
USN-8512-1, USN-8733-1

Charts affected

2,258 by stars
ChartLatestAffected imagesRadar Score
mongodb-backupsinextraVerified publisher1.1.01 of 1See more

mongodb-backup sinextra 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
gzip@1.12-1
no fix listed

Open the chart page →

4,637
postgresql-singlesinextraVerified publisher1.15.11 of 1See more

postgresql-single sinextra 1.15.1

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
gzip@1.12-1
no fix listed

Open the chart page →

4,971
gitlab-omnibusslamdev0.1.61 of 2See more

gitlab-omnibus slamdev 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
daedalusproject/base_kubectl:latest6f72b5119eda
gzip@1.10-0ubuntu4
no fix listed

Open the chart page →

2,864
slo-reportingslo-reportingVerified publisher0.3.341 of 2See more

slo-reporting slo-reporting 0.3.34

1 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/colenio/slo-reporting:0.3.316b64d194a27d
gzip@1.12-1
no fix listed

Open the chart page →

2,971
smarter-demosmarterOfficialVerified publisher0.1.53 of 7See more

smarter-demo smarter 0.1.5

3 of the 7 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
gzip@1.10-0ubuntu4.1
no fix listed
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
gzip@1.10-0ubuntu4.1
no fix listed
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
gzip@1.10-0ubuntu4.1
no fix listed

Open the chart page →

237,432
snappasssnappassVerified publisher0.4.32 of 3See more

snappass snappass 0.4.3

2 of the 3 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
lmacka/snappass:2.1.293f5c048b7d4
gzip@1.13-1
1.13-1+deb13u1
valkey/valkey:8.1.61f84517eca8e
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

3,092
artifact-hubsoftonic1.19.01 of 8See more

artifact-hub softonic 1.19.0

1 of the 8 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
artifacthub/postgres:latest4fd34fa635cc
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

14,605
redis-shardedsoftonic0.5.01 of 2See more

redis-sharded softonic 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

2,356
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

7,342
postgresql-ha-chartsoldevelo-postgresql-ha-chart16.3.42 of 2See more

postgresql-ha-chart soldevelo-postgresql-ha-chart 16.3.4

2 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
soldevelo/pgpool:4.6.3-debian-12-r0044d16a65129
gzip@1.12-1
no fix listed
soldevelo/postgresql-repmgr:17.6.0-debian-12-r03eaab21e40e5
gzip@1.12-1
no fix listed

Open the chart page →

4,674
nginx-chartsomnath-chartVerified publisher0.1.91 of 1See more

nginx-chart somnath-chart 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
somnathmore/custom-nginx:v2bdfc06cad4ec
gzip@1.12-1
no fix listed

Open the chart page →

5,674
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
speckle/speckle-preview-service:2.26.3092384dba45d
gzip@1.12-1
no fix listed

Open the chart page →

10,541
squidsquid-helmVerified publisher0.1.01 of 1See more

squid squid-helm 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ubuntu/squid:5.2-22.04_beta723891b5bc74
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

2,650
graph-nodestakewise3.1.01 of 3See more

graph-node stakewise 3.1.0

1 of the 3 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
graphprotocol/graph-node:v0.37.0f4452cdedd68
gzip@1.12-1
no fix listed

Open the chart page →

4,732
starwhalestarwhaleVerified publisher0.6.151 of 4See more

starwhale starwhale 0.6.15

1 of the 4 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/star-whale/server:0.6.158368359c8dd0
gzip@1.10-0ubuntu4.1
no fix listed

Open the chart page →

13,577
ckanstatcan0.0.351 of 8See more

ckan statcan 0.0.35

1 of the 8 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
statcan/ckan:2.93921305425b8
gzip@1.10-0ubuntu4
no fix listed

Open the chart page →

98,121
stornxstornxVerified publisher1.1.13 of 9See more

stornx stornx 1.1.1

3 of the 9 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
alazidis/kube-netlag:1.1.00e8c84152201
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
alazidis/stornx:1.1.1602d4f7f090c
gzip@1.12-1
no fix listed
istio/pilot:1.29.1f8b0e412ac4a
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2

Open the chart page →

11,826
streamvisorstreamvisorVerified publisher4.1.61 of 1See more

streamvisor streamvisor 4.1.6

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/streamvisor/streamvisor:4.1.40bc598b2ac9a
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2

Open the chart page →

2,906
supabasesupabse0.8.06 of 11See more

supabase supabse 0.8.0

6 of the 11 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.30.13b709e4a0e5e
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
kong/kong:3.9.16addf50e6bd8
gzip@1.12-1ubuntu3
1.12-1ubuntu3.2
supabase/edge-runtime:v1.74.02781daf92394
gzip@1.12-1
no fix listed
supabase/postgres-meta:v0.96.6a84cc713585e
gzip@1.12-1
no fix listed
supabase/realtime:v2.102.3aa1c92c0cf32
gzip@1.12-1
no fix listed
supabase/studio:2026.08.03-sha-022b374606aca9fdaa7
gzip@1.12-1
no fix listed

Open the chart page →

18,434
supersonicsupersonicVerified publisher0.3.11 of 2See more

supersonic supersonic 0.3.1

1 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.30.92956bd9de830
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

2,153
app-fullsynkubeVerified publisher1.0.01 of 1See more

app-full synkube 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/nginx:latest6e23479198b9
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

3,295
mumblesyntaxerror404Verified publisher1.0.41 of 1See more

mumble syntaxerror404 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/mumble-voip/mumble-server:v1.6.87002fd613b6a35
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2

Open the chart page →

2,161
kubedeploysysbee1.2.21 of 1See more

kubedeploy sysbee 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,879
apptaxmd-helm-chart0.0.21 of 1See more

app taxmd-helm-chart 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,879
teamcity-serverteamcity-server3.3.51 of 2See more

teamcity-server teamcity-server 3.3.5

1 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/haproxy:3.2de601ccc9a79
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

872
jenkinstestchart0.1.91 of 2See more

jenkins testchart 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
gzip@1.12-1
no fix listed

Open the chart page →

9,131
jenkinstest-jenkins9.1.01 of 2See more

jenkins test-jenkins 9.1.0

1 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
jenkins/jenkins:2.426.1-jdk11b470bcdc4ecd
gzip@1.12-1
no fix listed

Open the chart page →

9,131
tocktock0.6.31 of 9See more

tock tock 0.6.3

1 of the 9 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
tock/gen-ai-orchestrator-server:25.10.7abf7880e0449
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

13,678
guardrails-agent-kubernetesturbotVerified publisher0.3.01 of 1See more

guardrails-agent-kubernetes turbot 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
gzip@1.12-1ubuntu3
1.12-1ubuntu3.2

Open the chart page →

4,095
typemilltypemill-helm-chart2.2.02 of 2See more

typemill typemill-helm-chart 2.2.0

2 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
kixote/typemilldigest-pinned4e9dff179519
gzip@1.13-1
1.13-1+deb13u1
kixote/typemilldigest-pinned628f79a08cc7
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

5,564
typesensetypesenseVerified publisher1.1.41 of 1See more

typesense typesense 1.1.4

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
typesense/typesense:30.191604dc128e2
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

1,922
ueransim-gnbueransim-gnbVerified publisher0.2.61 of 1See more

ueransim-gnb ueransim-gnb 0.2.6

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

3,938
ueransim-uesueransim-uesVerified publisher0.1.21 of 1See more

ueransim-ues ueransim-ues 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
gradiant/ueransim:3.2.6015b30d5fa0f
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

3,938
unitycatalogunitycatalogVerified publisher0.0.21 of 4See more

unitycatalog unitycatalog 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
gzip@1.12-1
no fix listed

Open the chart page →

12,682
taigaunxwaresVerified publisher2026.3.82 of 6See more

taiga unxwares 2026.3.8

2 of the 6 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
taigaio/taiga-back:latest4beed8f62c9f
gzip@1.13-1
1.13-1+deb13u1
taigaio/taiga-protected:latestfd4568a97a59
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

9,248
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
gzip@1.12-1
no fix listed

Open the chart page →

4,424
varnish-ingress-controllervarnish-ingress-controllerVerified publisher0.5.01 of 1See more

varnish-ingress-controller varnish-ingress-controller 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
mariusm/vingress:0.5.0b3db186c3d72
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

2,353
vaultwarden-kubernetes-secretsvaultwarden-kubernetes-secrets0.0.0-main1 of 2See more

vaultwarden-kubernetes-secrets vaultwarden-kubernetes-secrets 0.0.0-main

1 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2

Open the chart page →

4,093
devportal-admin-uiveecode-platformVerified publisher0.5.41 of 1See more

devportal-admin-ui veecode-platform 0.5.4

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
veecode/devportal-admin-ui:0.4.30c69fd286b489
gzip@1.12-1
no fix listed

Open the chart page →

5,284
phpipamvquieVerified publisher1.0.31 of 3See more

phpipam vquie 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/mariadb:10.11.21c33370a599c
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

7,083
waldurwaldur-chartsVerified publisher8.1.22 of 3See more

waldur waldur-charts 8.1.2

2 of the 3 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/postgres:1767f41722b7a8
gzip@1.13-1
1.13-1+deb13u1
opennode/waldur-mastermind:8.1.24c82b15d9042
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

5,066
wavefront-adapter-for-istiowavefront0.1.41 of 2See more

wavefront-adapter-for-istio wavefront 0.1.4

1 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
wavefronthq/proxy:9.2d1064d28f6eb
gzip@1.6-5ubuntu1
no fix listed

Open the chart page →

16,037
kafka-devwikimedia0.2.01 of 1See more

kafka-dev wikimedia 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
wurstmeister/zookeeper:latest7a7fd44a7210
gzip@1.6-3ubuntu1
no fix listed

Open the chart page →

41,473
spark-operatorwikimedia2.2.71 of 1See more

spark-operator wikimedia 2.2.7

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
ghcr.io/kubeflow/spark-operator/controller:2.2.1865ff4da5686
gzip@1.10-0ubuntu4.1
no fix listed

Open the chart page →

51,717
wordpress-e2e-setupwoocommerce-e2e-setup0.1.11 of 2See more

wordpress-e2e-setup woocommerce-e2e-setup 0.1.1

1 of the 2 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/wordpress:6.8-apache30bff39330d1
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

7,814
wordpress-helmwordpress-helm0.2.91 of 4See more

wordpress-helm wordpress-helm 0.2.9

1 of the 4 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
aapjeisbaas/wp-frankenphp:v0.2.26b261abc7fb0
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

8,368
workflows-sinkworkflows-sinkVerified publisher0.16.31 of 1See more

workflows-sink workflows-sink 0.16.3

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
gzip@1.12-1
no fix listed

Open the chart page →

1,440
wraftwraft0.1.121 of 9See more

wraft wraft 0.1.12

1 of the 9 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
typesense/typesense:28.0.rc35dea1b62b7b6e
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

10,311
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

9,865
yugawareyugabyteVerified publisher2026.1.11 of 3See more

yugaware yugabyte 2026.1.1

1 of the 3 container images this version deploys carry CVE-2026-41991.

Container imageDigestPackageFixed in
library/postgres:14.22eba8ddbdd837
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

2,687

Container images carrying it

2,216 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
gzip@1.12-1
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
gzip@1.13-1
1.13-1+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
gzip@1.13-1
1.13-1+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
gzip@1.12-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
gzip@1.12-1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
gzip@1.13-1
1.13-1+deb13u1
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
gzip@1.10-0ubuntu4
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
gzip@1.12-1
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
gzip@1.12-1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
gzip@1.13-1
1.13-1+deb13u1
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
gzip@1.12-1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
gzip@1.12-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
gzip@1.12-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
gzip@1.12-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
gzip@1.12-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
gzip@1.12-1
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.