CVE-2026-41991
MediumAdvisory
Published 29 Jun 2026In the index since 5 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 4.7
- base score, highest
- EPSS
- 0.002
- 8th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,236
- of 17,792 indexed, latest versions
- Container images
- 2,185
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Security update for gzip
Carried by container images the latest versions of 2,236 of 17,792 indexed charts deploy, on 2,185 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| gzipdeb | 1.6-3ubuntu1, 1.6-4ubuntu1, 1.6-5ubuntu1, 1.6-5ubuntu1.1+11 more | 1.6-4ubuntu1+esm2, 1.10-4ubuntu4.2, 1.12-1ubuntu3.2, 1.13-1+deb13u1+2 more | 2,176 |
| gziprpm | 1.10-150200.10.1, 1.13-160000.2.2 | 1.10-150200.13.1, 1.13-160000.3.1 | 9 |
- OSV records
- DEBIAN-CVE-2026-41991UBUNTU-CVE-2026-41991ECHO-233f-78f2-a73bSUSE-SU-2026:22818-1SUSE-SU-2026:3269-1
- Also known as
- USN-8512-1, USN-8733-1
Charts affected
2,236 by stars
| Chart | Latest | Affected images | Radar Score |
|---|
Container images carrying it
2,185 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.