CVE-2026-41992
HighAdvisory
Published 29 Jun 2026In the index since 5 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.5
- base score, highest
- EPSS
- 0.004
- 35th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 2,258
- of 17,803 indexed, latest versions
- Container images
- 2,216
- deployed by those charts
- Fix available
- 3 of 3
- affected packages
Security update for gzip
Carried by container images the latest versions of 2,258 of 17,803 indexed charts deploy, on 2,216 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| gzipdeb | 1.6-3ubuntu1, 1.6-4ubuntu1, 1.6-5ubuntu1, 1.6-5ubuntu1.1+11 more | 1.6-4ubuntu1+esm2, 1.10-4ubuntu4.2, 1.12-1ubuntu3.2, 1.13-1+deb13u1+2 more | 2,207 |
| gzipapk | 1.13-r0, 1.14-r2 | 1.13-r1, 1.14-r3 | 3 |
| gziprpm | 1.10-150200.10.1 | 1.10-150200.16.1 | 6 |
- OSV records
- ALPINE-CVE-2026-41992DEBIAN-CVE-2026-41992UBUNTU-CVE-2026-41992ECHO-fad9-e6ab-e1e3SUSE-SU-2026:3592-1
- Also known as
- USN-8512-1, USN-8733-1
Charts affected
2,258 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| xlinexline | 0.0.1 | 1 of 1See more | 2,156 |
| nginx-chartxxoznge-nginx | 0.1.0 | 1 of 1See more | 1,879 |
| helm-demoyahoon-helm-demoVerified publisher | 1.0.0 | 1 of 1See more | 1,330 |
| my-nginx-appyasser-nginx-app | 0.1.0 | 1 of 1See more | 1,879 |
| api-snapyoukadevVerified publisher | 0.1.1 | 1 of 1See more | 2,710 |
| changedetection-iozekker6Verified publisher | 1.101.0 | 1 of 1See more | 2,649 |
| NEW_APPzekker6Verified publisher | 0.0.0 | 1 of 1See more | 1,879 |
| clickhousezloi-space | 1.2.0 | 2 of 3See more | 9,280 |
Container images carrying it
2,216 by charts deploying them
A fixed version is listed for 3 of the 3 affected packages.