StackRadar

CVE-2026-41992

High

Advisory

Published 29 Jun 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,258
of 17,803 indexed, latest versions
Container images
2,216
deployed by those charts
Fix available
3 of 3
affected packages

Security update for gzip

Carried by container images the latest versions of 2,258 of 17,803 indexed charts deploy, on 2,216 images.

Affected packageAffected versionsFixed inImages
gzipdeb1.6-3ubuntu1, 1.6-4ubuntu1, 1.6-5ubuntu1, 1.6-5ubuntu1.1+11 more1.6-4ubuntu1+esm2, 1.10-4ubuntu4.2, 1.12-1ubuntu3.2, 1.13-1+deb13u1+2 more2,207
gzipapk1.13-r0, 1.14-r21.13-r1, 1.14-r33
gziprpm1.10-150200.10.11.10-150200.16.16
OSV records
ALPINE-CVE-2026-41992DEBIAN-CVE-2026-41992UBUNTU-CVE-2026-41992ECHO-fad9-e6ab-e1e3SUSE-SU-2026:3592-1
Also known as
USN-8512-1, USN-8733-1

Charts affected

2,258 by stars
ChartLatestAffected imagesRadar Score
impulseimpulse1.0.161 of 1See more

impulse impulse 1.0.16

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
ghcr.io/eslupmi/impulse:v3.7.03ded1b7ebca0
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,396
infisicalinfisical-charts0.4.21 of 3See more

infisical infisical-charts 0.4.2

1 of the 3 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
infisical/infisical:latest02082bf13163
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

3,085
influxdb-enterpriseinfluxdata0.2.12 of 2See more

influxdb-enterprise influxdata 0.2.1

2 of the 2 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/influxdb:1.12.3-meta8812029260b5
gzip@1.12-1
no fix listed
library/influxdb:1.12.3-datab0f9fc41ed79
gzip@1.12-1
no fix listed

Open the chart page →

6,026
influxdbinfluxdb20.1.01 of 1See more

influxdb influxdb2 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/influxdb:latestf75e48af0598
gzip@1.12-1
no fix listed

Open the chart page →

2,383
ai-stackinfracloud-chartsVerified publisher0.6.01 of 3See more

ai-stack infracloud-charts 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,317
chromadbinfracloud-chartsVerified publisher0.3.01 of 1See more

chromadb infracloud-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
ghcr.io/chroma-core/chroma:1.5.91e0b73a187a2
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,317
guardrails-usvcinfracloud-chartsVerified publisher1.0.11 of 1See more

guardrails-usvc infracloud-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
opea/guardrails-tgi:latestf68bec6a1271
gzip@1.12-1
no fix listed

Open the chart page →

5,120
erigoninfradao0.0.51 of 2See more

erigon infradao 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
testinprod/op-erigon:latest0a125bd77a2d
gzip@1.12-1
no fix listed

Open the chart page →

2,924
op-stackinfradao0.0.11 of 1See more

op-stack infradao 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,879
cloudshellinseefrlab4.3.01 of 2See more

cloudshell inseefrlab 4.3.0

1 of the 2 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
inseefrlab/shelly:cloudshell31f04ca7436b
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

10,583
gmaintelVerified publisher0.1.01 of 1See more

gma intel 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
gzip@1.10-0ubuntu4.1
no fix listed

Open the chart page →

71,556
itm-servicesintelVerified publisher2.0.01 of 8See more

itm-services intel 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
intel/dlstreamer-pipeline-server:2022.1.1-ubuntu20aa8f5483a2ef
gzip@1.10-0ubuntu4.1
no fix listed

Open the chart page →

84,573
map5gintelVerified publisher1.0.01 of 1See more

map5g intel 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
smartedge/generic-multi-access-network-virtualization:1.04cd63c22ce36
gzip@1.10-0ubuntu4.1
no fix listed

Open the chart page →

71,556
multimodal-data-visualizationintelVerified publisher3.0.01 of 2See more

multimodal-data-visualization intel 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
intel/multimodal-data-visualization-streaming:3.01a89327e499b
gzip@1.10-0ubuntu4.1
no fix listed

Open the chart page →

77,320
tcs-issuerintelVerified publisher0.5.01 of 2See more

tcs-issuer intel 0.5.0

1 of the 2 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
intel/trusted-certificate-issuer:0.5.0591a9db4a427
gzip@1.10-0ubuntu4.1
no fix listed

Open the chart page →

6,010
intelowlintelowl-helm6.6.1-01-06-20262 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

2 of the 5 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
gzip@1.12-1
no fix listed
library/redis:8.6.34d25e2fe601f
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

18,066
interbtc-parachaininterlay0.4.131 of 1See more

interbtc-parachain interlay 0.4.13

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
interlayhq/interbtc:latesta66d0e35e70f
gzip@1.10-0ubuntu4.1
no fix listed

Open the chart page →

3,208
interbtc-vaultinterlay0.1.131 of 1See more

interbtc-vault interlay 0.1.13

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
interlayhq/interbtc-clients:vault-masterc3e311de67da
gzip@1.10-0ubuntu4
no fix listed

Open the chart page →

3,886
polkabtc-parachaininterlay0.2.411 of 4See more

polkabtc-parachain interlay 0.2.41

1 of the 4 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
interlayhq/interbtc:latesta66d0e35e70f
gzip@1.10-0ubuntu4.1
no fix listed

Open the chart page →

3,951
polkabtc-vaultinterlay0.1.111 of 1See more

polkabtc-vault interlay 0.1.11

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
interlayhq/interbtc-clients:vault-masterc3e311de67da
gzip@1.10-0ubuntu4
no fix listed

Open the chart page →

3,886
inventreeinventreeOfficialVerified publisher0.4.282 of 2See more

inventree inventree 0.4.28

2 of the 2 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
inventree/inventree:1.5.4a946ec09da3e
gzip@1.13-1
1.13-1+deb13u1
library/nginx:stabled5792f71a949
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

5,920
istio-aws-private-ingress-customizedistio-aws-private-ingress-customized1.0.01 of 1See more

istio-aws-private-ingress-customized istio-aws-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

5,590
istio-azure-private-ingress-customizedistio-azure-private-ingress-customized1.0.01 of 1See more

istio-azure-private-ingress-customized istio-azure-private-ingress-customized 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
istio/proxyv2:1.18.0757d28c24100
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

5,590
istio-bookinfoistio-bookinfo1.2.23 of 6See more

istio-bookinfo istio-bookinfo 1.2.2

3 of the 6 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
istio/examples-bookinfo-reviews-v1:1.15.040e8aba77c1b
gzip@1.6-4ubuntu1
1.6-4ubuntu1+esm2
istio/examples-bookinfo-reviews-v2:1.15.0e86d247b7ac2
gzip@1.6-4ubuntu1
1.6-4ubuntu1+esm2
istio/examples-bookinfo-reviews-v3:1.15.0e454cab754cf
gzip@1.6-4ubuntu1
1.6-4ubuntu1+esm2

Open the chart page →

19,058
ztunnelistio-ztunnelVerified publisher1.25.01 of 1See more

ztunnel istio-ztunnel 1.25.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
istio/ztunnel:1.25.005f3972d80a9
gzip@1.12-1ubuntu3
1.12-1ubuntu3.2

Open the chart page →

2,514
appswitcher-serverit-at-mOfficialVerified publisher2.0.21 of 1See more

appswitcher-server it-at-m 2.0.2

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

3,819
daveit-at-mOfficialVerified publisher0.2.162 of 11See more

dave it-at-m 0.2.16

2 of the 11 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.1.2-debian-12-r000176a47afa0
gzip@1.12-1
no fix listed
bitnamilegacy/postgresql:latest42a8200d3597
gzip@1.12-1
no fix listed

Open the chart page →

12,337
dynamic-ip-loadbalancer-controlleritsmethemojoVerified publisher0.1.01 of 1See more

dynamic-ip-loadbalancer-controller itsmethemojo 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/buildpack-deps:curl04907bdd423b
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,721
tekton-git-listeneritsmethemojoVerified publisher0.1.11 of 1See more

tekton-git-listener itsmethemojo 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/buildpack-deps:scmac978b783657
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

2,219
thehiveittrident-oss0.1.02 of 6See more

thehive ittrident-oss 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/cassandra:4.0093ee8ee5eb2
gzip@1.12-1
no fix listed
library/debian:stable-slim04634311a8d5
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

6,331
opencloudjacobcolvinVerified publisher0.2.37 of 13See more

opencloud jacobcolvin 0.2.3

7 of the 13 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
gzip@1.12-1ubuntu3
1.12-1ubuntu3.2
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
gzip@1.12-1
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
gzip@1.12-1
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
gzip@1.12-1
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
gzip@1.12-1
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
gzip@1.12-1
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
gzip@1.12-1
no fix listed

Open the chart page →

45,468
web-chartjaeeyun-ktcloudlab0.1.01 of 1See more

web-chart jaeeyun-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,879
nginx-chartjaeki-nginx0.1.01 of 1See more

nginx-chart jaeki-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,879
deconzjanip81-helm-chartsVerified publisher0.1.11 of 1See more

deconz janip81-helm-charts 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
deconzcommunity/deconz:2.29.2062de2362641
gzip@1.12-1
no fix listed

Open the chart page →

10,922
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
gzip@1.12-1
no fix listed

Open the chart page →

3,496
janus-shieldjanus-shield1.0.01 of 2See more

janus-shield janus-shield 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
seoulorigin/janus-ml-sidecar:v3.192cbaad0c540
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

2,435
jasperjasperVerified publisher1.0.2032 of 2See more

jasper jasper 1.0.203

2 of the 2 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:latest42a8200d3597
gzip@1.12-1
no fix listed
ghcr.io/cjmalloy/jasper:v1.3.282726a947bb65b
gzip@1.12-1
no fix listed

Open the chart page →

9,273
jasper-uijasperVerified publisher1.0.341 of 1See more

jasper-ui jasper 1.0.34

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
ghcr.io/cjmalloy/jasper-ui:v1.3.623246dc2160efe
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

2,614
esphomejeffrescVerified publisher0.2.21 of 1See more

esphome jeffresc 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
ghcr.io/esphome/esphome:2026.4.078a82d810709
gzip@1.12-1
no fix listed

Open the chart page →

5,150
jellyfinjellyfin-helm10.9.101 of 1See more

jellyfin jellyfin-helm 10.9.10

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.9.1079fb3d73a3e9
gzip@1.12-1
no fix listed

Open the chart page →

4,548
jellyfinjellyfin--jellyfin-helm3.0.01 of 1See more

jellyfin jellyfin--jellyfin-helm 3.0.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.717285f9cce63
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

3,054
jx-app-datadogjenkins-x0.0.101 of 2See more

jx-app-datadog jenkins-x 0.0.10

1 of the 2 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
datadog/agent:6aad9994de6a7
gzip@1.12-1ubuntu3
1.12-1ubuntu3.2

Open the chart page →

4,087
jx-app-jenkinsjenkins-x0.0.151 of 2See more

jx-app-jenkins jenkins-x 0.0.15

1 of the 2 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
jenkins/jenkins:ltsc1e4c349365f
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

2,517
dayz-dedicated-server-razorbladex401jespernohrVerified publisher1.0.31 of 1See more

dayz-dedicated-server-razorbladex401 jespernohr 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
razorbladex401/dayz:latest6a4d79248e7d
gzip@1.10-4ubuntu4.1
1.10-4ubuntu4.2

Open the chart page →

5,405
discord-experiencebotjfwenischVerified publisher0.7.41 of 1See more

discord-experiencebot jfwenisch 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/discord-experiencebot:latestb52ff07f9f0c
gzip@1.6-5ubuntu1.2
no fix listed

Open the chart page →

7,896
steamcmd-managerjfwenischVerified publisher0.4.51 of 1See more

steamcmd-manager jfwenisch 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
gzip@1.12-1ubuntu3
1.12-1ubuntu3.2

Open the chart page →

6,657
webtoolsjfwenischVerified publisher0.1.41 of 1See more

webtools jfwenisch 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
gzip@1.12-1ubuntu3
1.12-1ubuntu3.2

Open the chart page →

6,638
nginx-chartjinbok-nginx0.1.01 of 1See more

nginx-chart jinbok-nginx 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,879
nginx-chartjiungVerified publisher0.1.01 of 1See more

nginx-chart jiung 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,879
nginx-chartjongh09160.1.01 of 1See more

nginx-chart jongh0916 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-41992.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
gzip@1.13-1
1.13-1+deb13u1

Open the chart page →

1,879

Container images carrying it

2,216 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/dyff/workflows-sink:0.16.3564718e28931
gzip@1.12-1
no fix listed
1
registry.gitlab.com/egos-tech/smtp:latestdf842ed79211
gzip@1.13-1
1.13-1+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
gzip@1.13-1
1.13-1+deb13u1
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
gzip@1.12-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
gzip@1.12-1
no fix listed
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
gzip@1.13-1
1.13-1+deb13u1
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
gzip@1.10-0ubuntu4
no fix listed
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
gzip@1.12-1
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
gzip@1.12-1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
gzip@1.13-1
1.13-1+deb13u1
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
gzip@1.12-1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
gzip@1.12-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
gzip@1.12-1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
gzip@1.12-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
gzip@1.12-1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
gzip@1.12-1
no fix listed
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.