StackRadar

CVE-2026-41992

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,258
of 17,813 indexed, latest versions
Container images
2,251
deployed by those charts
Fix available
3 of 3
affected packages

Security update for gzip

Carried by container images the latest versions of 2,258 of 17,813 indexed charts deploy, on 2,251 images.

Affected packageAffected versionsFixed inImages
gzipdeb1.6-3ubuntu1, 1.6-4ubuntu1, 1.6-5ubuntu1, 1.6-5ubuntu1.1+11 more1.6-4ubuntu1+esm2, 1.10-4ubuntu4.2, 1.12-1ubuntu3.2, 1.13-1+deb13u1+2 more2,242
gzipapk1.13-r0, 1.14-r21.13-r1, 1.14-r33
gziprpm1.10-150200.10.11.10-150200.16.16
OSV records
ALPINE-CVE-2026-41992DEBIAN-CVE-2026-41992UBUNTU-CVE-2026-41992ECHO-fad9-e6ab-e1e3SUSE-SU-2026:3592-1
Also known as
USN-8512-1, USN-8733-1

Charts affected

2,258 by stars
ChartLatestAffected imagesRadar Score
pgcatxxl-job-adminVerified publisher0.3.31 of 1See more

pgcat xxl-job-admin 0.3.3

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
ghcr.io/postgresml/pgcat:v1.2.0627761f6dcbc
gzip@1.12-1
no fix listed

Open the chart page →

3,196
nginx-chartxxoznge-nginx0.1.01 of 1See more

nginx-chart xxoznge-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,956
helm-demoyahoon-helm-demoVerified publisher1.0.01 of 1See more

helm-demo yahoon-helm-demo 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
ghcr.io/yahoon/helm-demo:1.0.02930290a758c
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,338
my-nginx-appyasser-nginx-app0.1.01 of 1See more

my-nginx-app yasser-nginx-app 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,956
api-snapyoukadevVerified publisher0.1.11 of 1See more

api-snap youkadev 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
youkadev/api-snap:0.1.14db0f9428e67
gzip@1.12-1
no fix listed

Open the chart page →

2,718
changedetection-iozekker6Verified publisher1.102.01 of 1See more

changedetection-io zekker6 1.102.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
ghcr.io/dgtlmoon/changedetection.io:0.60.7096dae27b5d6
gzip@1.12-1
no fix listed

Open the chart page →

2,697
NEW_APPzekker6Verified publisher0.0.01 of 1See more

NEW_APP zekker6 0.0.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,956
clickhousezloi-space1.2.02 of 3See more

clickhouse zloi-space 1.2.0

2 of the 3 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
yandex/clickhouse-client:21.3863f94a0f607
gzip@1.6-5ubuntu1.1
no fix listed
yandex/clickhouse-server:21.3.204eccfffb01d7
gzip@1.10-0ubuntu4
no fix listed

Open the chart page →

9,296

Container images carrying it

2,251 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:2.10.1a132c2ac7c57
gzip@1.12-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
gzip@1.12-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/papra-hq/papra:26.6.2-rootlessa281cb44176d
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/paradigmxyz/reth:v1.3.121e5290e8b743
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
ghcr.io/paradigmxyz/reth:v2.2.0505fca5e87d6
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
ghcr.io/parmincloud/arvancloud-certmanager-issuer:v1.0.00b97452674a3
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/parmincloud/haproxy-redis-sentinel:1.0.040a00a6456ae
gzip@1.12-1
no fix listed
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
gzip@1.6-5ubuntu1.2
no fix listed
1
ghcr.io/platformrelay/kollect:v0.20.0c95fa31ead03
gzip@1.12-1
no fix listed
1
ghcr.io/privacyengineering/hawk-service:latestbfedf47bb5e0
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
ghcr.io/pschichtel/s3-backup:0.7.017666811f6a7
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/qovery/iam-eks-user-mapper:mainc41e3efc6097
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/radar-base/managementportal/management-portal:3.0.0c1b37e821f72
gzip@1.14-1~exp2ubuntu1
1.14-1~exp2ubuntu1.1
1
ghcr.io/radar-base/radar-app-config/radar-app-config:0.6.24431db7b486b
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
ghcr.io/radar-base/radar-data-dashboard-backend/radar-data-dashboard-backend:0.2.4d1e55350923c
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
ghcr.io/radar-base/radar-gateway/radar-gateway:0.9.4219d894aa7a6
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
ghcr.io/radar-base/radar-output-restructure/radar-output-restructure:3.0.67fb9c70e96a4
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
ghcr.io/radar-base/radar-schemas/radar-schemas-tools:0.8.16c442e8bfe6b4
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
ghcr.io/radar-base/radar-upload-source-connector/radar-upload-connect-backend:0.6.46a04b43b8d9a
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
ghcr.io/rajnandan1/kener:3.2.182b993cb232eb
gzip@1.12-1
no fix listed
1
ghcr.io/reitermarkus/7d2d:main39953b387b61
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/retyc/retyc-k8s-csi:v0.2.01521d4baeb85
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/rodg/rtmp-controller:latest67f99a5beab7
gzip@1.12-1
no fix listed
1
ghcr.io/rss-bridge/rss-bridge:latest606896116558
gzip@1.12-1
no fix listed
1
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
gzip@1.12-1
no fix listed
1
ghcr.io/sdr-enthusiasts/docker-flightradar24:latest917e53402d51
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
gzip@1.12-1
no fix listed
1
ghcr.io/seanmorley15/adventurelog-backend:v0.13.00250d9cb0d74
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/securo-finance/securo-backend:0.16.0f452147e07f1
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/serenita-org/vero:v0.8.3e5a7ec714acc
gzip@1.12-1
no fix listed
1
ghcr.io/sergelogvinov/fluentd:1.19.33273d13f1e75
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/sergelogvinov/mongodb:8.0.101eee8e20a87f
gzip@1.12-1
no fix listed
1
ghcr.io/sergelogvinov/mongosqld:2.14.230b826375ed42
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2
1
ghcr.io/sergelogvinov/mongosync:1.15.0fa99ed475f03
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
gzip@1.12-1
no fix listed
1
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
gzip@1.12-1
no fix listed
1
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
gzip@1.12-1
no fix listed
1
ghcr.io/siafoundation/s3d:bf33bf3b3fcc85f7282
gzip@1.12-1
no fix listed
1
ghcr.io/sikalabs/hello-world-server:latestcf8538bf6489
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/sissbruecker/linkding:1.45.061b2eb9eed8e
gzip@1.13-1
1.13-1+deb13u1
1
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
gzip@1.10-0ubuntu4.1
no fix listed
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
gzip@1.10-0ubuntu4.1
no fix listed
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
gzip@1.10-0ubuntu4.1
no fix listed
1
ghcr.io/spidernet-io/egressgateway-agent:v0.6.9a8ec2f74c9d0
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1
ghcr.io/spidernet-io/egressgateway-controller:v0.6.99deda7b68c34
gzip@1.12-1ubuntu3.1
1.12-1ubuntu3.2
1

syft 1.42.1 · advisories as of 20 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.