StackRadar

CVE-2026-42014

Medium

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.6
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,621
of 17,787 indexed, latest versions
Container images
1,686
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,621 of 17,787 indexed charts deploy, on 1,686 images.

Affected packageAffected versionsFixed inImages
gnutls28deb3.6.13-2ubuntu1.2, 3.6.13-2ubuntu1.3, 3.6.13-2ubuntu1.6, 3.6.13-2ubuntu1.7+33 more3.6.13-2ubuntu1.12+esm3, 3.7.3-4ubuntu1.9, 3.7.9-2+deb12u7, 3.8.3-1.1ubuntu3.6+4 more1,645
gnutlsapk3.8.5-r0, 3.8.8-r0, 3.8.11-r0, 3.8.12-r03.8.13-r041
OSV records
ALPINE-CVE-2026-42014DEBIAN-CVE-2026-42014UBUNTU-CVE-2026-42014
Also known as
USN-8284-1, USN-8539-1

Charts affected

1,621 by stars
ChartLatestAffected imagesRadar Score
netbirdjaconiVerified publisher0.15.11 of 4See more

netbird jaconi 0.15.1

1 of the 4 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
netbirdio/management:0.45.10c9994b393ea
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.6

Open the chart page →

8,473
litellm-helmlitellm1.101.01 of 2See more

litellm-helm litellm 1.101.0

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.2.0-debian-12-r6ea55532b6f75
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7

Open the chart page →

4,574
oneuptimeoneuptimeOfficialVerified publisher13.0.41 of 7See more

oneuptime oneuptime 13.0.4

1 of the 7 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:26.701b81d1432c4
gnutls28@3.7.3-4ubuntu1.9
no fix listed

Open the chart page →

10,896
openclawopenclaw-helmVerified publisher1.5.401 of 2See more

openclaw openclaw-helm 1.5.40

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
ghcr.io/openclaw/openclaw:2026.5.22dcfd14877740
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7

Open the chart page →

5,679
prometheus-cloudwatch-exporterprometheus-communityVerified publisher0.28.21 of 1See more

prometheus-cloudwatch-exporter prometheus-community 0.28.2

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
prom/cloudwatch-exporter:v0.16.071c2e988af06
gnutls28@3.8.3-1.1ubuntu3.1
3.8.3-1.1ubuntu3.6

Open the chart page →

3,422
jellyfinutkuozdemirVerified publisher2.0.01 of 1See more

jellyfin utkuozdemir 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
linuxserver/jellyfin:10.7.72427dde159a2
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.12+esm3

Open the chart page →

7,917
glasskube-operatorglasskubeOfficialVerified publisher0.12.21 of 3See more

glasskube-operator glasskube 0.12.2

1 of the 3 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
glasskube/operator:0.12.2be5133100d63
gnutls28@3.7.3-4ubuntu1.2
3.7.3-4ubuntu1.9

Open the chart page →

11,971
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7

Open the chart page →

5,364
milvusmilvus-helm5.0.282 of 4See more

milvus milvus-helm 5.0.28

2 of the 4 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.0.79c9947de139d
gnutls28@3.7.3-4ubuntu1.5
3.7.3-4ubuntu1.9
milvusdb/etcd:3.5.25-r1fededb2f2d63
gnutls28@3.7.3-4ubuntu1.7
3.7.3-4ubuntu1.9

Open the chart page →

10,764
prefect-serverprefectVerified publisher2026.9.141419101 of 2See more

prefect-server prefect 2026.9.14141910

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7

Open the chart page →

5,448
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6

Open the chart page →

6,385
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
gnutls28@3.6.13-2ubuntu1.7
3.6.13-2ubuntu1.12+esm3

Open the chart page →

18,570
bitbucketatlassian-data-centerVerified publisher2.0.151 of 1See more

bitbucket atlassian-data-center 2.0.15

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
atlassian/bitbucket:10.2.705933f2b1cfd
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

1,492
zookeepercloudpirates-zookeeperVerified publisher0.13.111 of 1See more

zookeeper cloudpirates-zookeeper 0.13.11

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
library/zookeeper:3.9.5cab8944a33a1
gnutls28@3.7.3-4ubuntu1.9
no fix listed

Open the chart page →

2,963
codefreshcodefresh-onpremOfficialVerified publisher2.12.134 of 42See more

codefresh codefresh-onprem 2.12.13

4 of the 42 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
bitnamilegacy/rabbitmq:4.1.39e635efba431
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7

Open the chart page →

14,615
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.38.4447f857a0146
gnutls28@3.7.3-4ubuntu1.9
no fix listed

Open the chart page →

1,521
memgraphmemgraphVerified publisher1.0.71 of 2See more

memgraph memgraph 1.0.7

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
memgraph/memgraph:3.13.1bd3fe13228f4
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

1,208
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
gnutls28@3.6.13-2ubuntu1.9
3.6.13-2ubuntu1.12+esm3
stackstorm/st2api:3.86f56d239d280
gnutls28@3.6.13-2ubuntu1.9
3.6.13-2ubuntu1.12+esm3
stackstorm/st2auth:3.833ecfda16608
gnutls28@3.6.13-2ubuntu1.9
3.6.13-2ubuntu1.12+esm3
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
gnutls28@3.6.13-2ubuntu1.9
3.6.13-2ubuntu1.12+esm3
stackstorm/st2notifier:3.8f190a6212195
gnutls28@3.6.13-2ubuntu1.9
3.6.13-2ubuntu1.12+esm3
stackstorm/st2rulesengine:3.8259503496ff9
gnutls28@3.6.13-2ubuntu1.9
3.6.13-2ubuntu1.12+esm3
stackstorm/st2scheduler:3.8b1de2055c362
gnutls28@3.6.13-2ubuntu1.9
3.6.13-2ubuntu1.12+esm3
stackstorm/st2sensorcontainer:3.8b1a338f64773
gnutls28@3.6.13-2ubuntu1.9
3.6.13-2ubuntu1.12+esm3
stackstorm/st2stream:3.81c8904a3bf67
gnutls28@3.6.13-2ubuntu1.9
3.6.13-2ubuntu1.12+esm3
stackstorm/st2timersengine:3.81bf35bfaf00c
gnutls28@3.6.13-2ubuntu1.9
3.6.13-2ubuntu1.12+esm3
stackstorm/st2web:3.809989a26c8b7
gnutls28@3.6.13-2ubuntu1.9
3.6.13-2ubuntu1.12+esm3
stackstorm/st2workflowengine:3.819fdfffdbba8
gnutls28@3.6.13-2ubuntu1.9
3.6.13-2ubuntu1.12+esm3

Open the chart page →

96,984
supabasetokens-studioVerified publisher1.0.06 of 14See more

supabase tokens-studio 1.0.0

6 of the 14 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
library/kong:3.8.0712e407b20ea
gnutls28@3.7.3-4ubuntu1.9
no fix listed
supabase/edge-runtime:v1.59.0eff9c554d649
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
supabase/postgres-meta:v0.84.2d0a96973e9f1
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
supabase/realtime:v2.33.8d207e6e23ad3
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7
supabase/studio:20241021-9f9b08326d8070c55e9
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7

Open the chart page →

23,263
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7

Open the chart page →

8,530
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

1,749
budibasebudibase0.0.0-master1 of 7See more

budibase budibase 0.0.0-master

1 of the 7 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7

Open the chart page →

10,810
krokicowboysysopVerified publisher6.1.04 of 5See more

kroki cowboysysop 6.1.0

4 of the 5 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
yuzutech/kroki-bpmn:0.29.1444805c4b917
gnutls@3.8.8-r0
3.8.13-r0
yuzutech/kroki-diagramsnet:0.29.1b810edbf9c62
gnutls@3.8.8-r0
3.8.13-r0
yuzutech/kroki-excalidraw:0.29.157917319ea70
gnutls@3.8.8-r0
3.8.13-r0
yuzutech/kroki-mermaid:0.29.1963b4acfde6e
gnutls@3.8.8-r0
3.8.13-r0

Open the chart page →

6,743
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
gnutls28@3.7.3-4ubuntu1.1
3.7.3-4ubuntu1.9

Open the chart page →

3,493
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7

Open the chart page →

3,037
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
gnutls28@3.7.3-4ubuntu1.2
3.7.3-4ubuntu1.9

Open the chart page →

7,896
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6

Open the chart page →

1,279
rabbitmqkubelauncherVerified publisher0.2.111 of 1See more

rabbitmq kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/rabbitmqdigest-pinnedff5a36a457f1
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

1,118
openclawopenclawVerified publisher1.91.31 of 2See more

openclaw openclaw 1.91.3

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.56.7b1ba7b054af2
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

3,050
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7

Open the chart page →

3,492
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.12+esm3

Open the chart page →

11,453
zillazillaOfficialVerified publisher2.4.21 of 1See more

zilla zilla 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
gnutls28@3.7.3-4ubuntu1.9
no fix listed

Open the chart page →

1,737
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
gnutls28@3.7.3-4ubuntu1.3
3.7.3-4ubuntu1.9

Open the chart page →

4,281
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7

Open the chart page →

3,024
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

4,604
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
gnutls28@3.7.9-2
3.7.9-2+deb12u7
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
quay.io/devtron/postgres:14.91b594392f7cb
gnutls28@3.7.9-2
3.7.9-2+deb12u7

Open the chart page →

31,447
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.6

Open the chart page →

3,645
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
gnutls28@3.8.3-1.1ubuntu3.1
3.8.3-1.1ubuntu3.6

Open the chart page →

5,396
grayloggroundhog2k0.13.101 of 1See more

graylog groundhog2k 0.13.10

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
graylog/graylog:7.1.9598bd41fefd5
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

1,112
ilumilumOfficialVerified publisher6.7.34 of 19See more

ilum ilum 6.7.3

4 of the 19 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
bitnamilegacy/postgresql:16233f361c5819
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
gitea/gitea:1.22.376f516a1a8c2
gnutls@3.8.5-r0
3.8.13-r0
ilum/marquez:0.54.06e1d709d41f8
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7

Open the chart page →

23,289
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6

Open the chart page →

3,434
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7

Open the chart page →

7,031
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
gnutls28@3.8.9-3
3.8.9-3+deb13u4

Open the chart page →

5,665
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
gnutls28@3.8.9-3+deb13u2
3.8.9-3+deb13u4

Open the chart page →

4,344
netris-controllernetrisai2.8.24 of 14See more

netris-controller netrisai 2.8.2

4 of the 14 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
netrisai/controller-grpc:4.6.0.00753178bf173c2
gnutls28@3.6.13-2ubuntu1.12
3.6.13-2ubuntu1.12+esm3
netrisai/controller-telescope:4.6.0.00414d82948a8b2
gnutls28@3.6.13-2ubuntu1.12
3.6.13-2ubuntu1.12+esm3
netrisai/controller-telescope-notifier:3.0.455e826ef9a5d
gnutls28@3.6.13-2ubuntu1.11
3.6.13-2ubuntu1.12+esm3
netrisai/controller-web-session-generator:0.2.0a030a31289f4
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.12+esm3

Open the chart page →

30,481
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
gnutls28@3.8.9-3+deb13u2
3.8.9-3+deb13u4

Open the chart page →

2,257
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
library/postgres:16.109f23e02d766
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u7

Open the chart page →

17,306
paperless-ngxpaperless-ngxVerified publisher0.3.221 of 3See more

paperless-ngx paperless-ngx 0.3.22

1 of the 3 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7

Open the chart page →

8,510
puppetserverpuppetserver9.5.22 of 5See more

puppetserver puppetserver 9.5.2

2 of the 5 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
ghcr.io/voxpupuli/container-puppetdb:7.18.0-v1.5.0a56dfe91f5b1
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.9
ghcr.io/voxpupuli/container-puppetserver:7.17.0-v1.5.0916746209ac5
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.9

Open the chart page →

14,276
selenium3selenium31.2.41 of 1See more

selenium3 selenium3 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-42014.

Container imageDigestPackageFixed in
selenium/hub:3.141.5902f251d48d5f
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.12+esm3

Open the chart page →

11,831

Container images carrying it

1,686 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
gcr.io/ml-pipeline/api-server:2.3.039661bd823e8
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
gcr.io/ml-pipeline/metadata-envoy:2.3.0e8e263a919ff
gnutls28@3.6.13-2ubuntu1.10
3.6.13-2ubuntu1.12+esm3
1
gcr.io/ml-pipeline/metadata-writer:2.3.09bcfd2abc361
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
gcr.io/tfx-oss-public/ml_metadata_store_server:1.14.051404ef4419c
gnutls28@3.6.13-2ubuntu1.8
3.6.13-2ubuntu1.12+esm3
1
ghcr.io/abcdesktopio/mongo:safe8.0c4c1938a973b
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
ghcr.io/aetrius/msockperf-client/msockperf-client:main820af919c5e2
gnutls28@3.8.3-1.1ubuntu3.1
3.8.3-1.1ubuntu3.6
1
ghcr.io/aetrius/msockperf-server/msockperf-server:main46ae4ea003e0
gnutls28@3.8.3-1.1ubuntu3.1
3.8.3-1.1ubuntu3.6
1
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
gnutls28@3.7.3-4ubuntu1.9
no fix listed
1
ghcr.io/alethic/auth0-operator-image:1.4.122468990a8521
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
ghcr.io/alexmorbo/dell_idrac_fan_controller:v0.1.6-1d110504d551d
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
1
ghcr.io/almarklein/timetagger:v26.1.3-nonroot18a81afcb249
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
ghcr.io/analogj/scrutiny:master-omnibus18689773150d
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
ghcr.io/analogj/scrutiny:v0.9.2-web71be54e99608
gnutls28@3.8.9-3+deb13u2
3.8.9-3+deb13u4
1
ghcr.io/angelscloud/prometheus-optimizer:latest744bc929a579
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
1
ghcr.io/apache/flink-kubernetes-operator:c703255e9c2ce635b89
gnutls28@3.7.3-4ubuntu1.5
3.7.3-4ubuntu1.9
1
ghcr.io/appscode/csi-driver-cacerts:v0.5.0b6bf1888f9d5
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
gnutls28@3.8.9-3
3.8.9-3+deb13u4
1
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.9
1
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
gnutls28@3.7.3-4ubuntu1.5
3.7.3-4ubuntu1.9
1
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7
1
ghcr.io/astradns/astradns-agent:v0.2.9-unbound6ba69487f1b0
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7
1
ghcr.io/astriaorg/account-monitor:latest4c8b42890035
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
ghcr.io/astriaorg/conductor:1.1.01f97d131b1d1
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
ghcr.io/astriaorg/hermes:0.5.04f33a0a9f75e
gnutls28@3.8.3-1.1ubuntu3.2
3.8.3-1.1ubuntu3.6
1
ghcr.io/astriaorg/sequencer:latest44f82ee0b24c
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
ghcr.io/astriaorg/sequencer-relayer:latest5f6c74993f08
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
ghcr.io/atuinsh/atuin:18.12.0e953fa9e36ef
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
ghcr.io/avistotelecom/docker-wazuh-agent:4.12.08766ba08bf1a
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
ghcr.io/base/node-reth:v1.1.18eb6e492fe3c
gnutls28@3.8.3-1.1ubuntu3.5
3.8.3-1.1ubuntu3.6
1
ghcr.io/base-org/node:v0.11.11aba0ffe55ea
gnutls28@3.7.3-4ubuntu1.5
3.7.3-4ubuntu1.9
1
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
gnutls28@3.7.3-4ubuntu1.3
3.7.3-4ubuntu1.9
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
ghcr.io/blockscout/smart-contract-verifier:main9a43f0cc5797
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
ghcr.io/botify-labs/airbyte_exporter:2.3.02105b1f33013
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u7
1
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
gnutls28@3.6.13-2ubuntu1.8
3.6.13-2ubuntu1.12+esm3
1
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
ghcr.io/browserless/chromium:v2.55.42ed0183564d7
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
1
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
ghcr.io/camptocamp/tetragon-policy-builder:master0e99f12bb040
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
gnutls28@3.7.3-4ubuntu1.3
3.7.3-4ubuntu1.9
1
ghcr.io/caninehq/canine:latesta058034ca006
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
ghcr.io/cfi2017/opencve-scheduler:3.0.08d943799621b
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.