StackRadar

CVE-2026-42015

Medium

Advisory

Published 30 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.007
53rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1,821
of 17,821 indexed, latest versions
Container images
1,899
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 1,821 of 17,821 indexed charts deploy, on 1,899 images.

Affected packageAffected versionsFixed inImages
gnutls28deb3.4.10-4ubuntu1.3, 3.4.10-4ubuntu1.4, 3.4.10-4ubuntu1.5, 3.4.10-4ubuntu1.7+47 more3.4.10-4ubuntu1.9+esm4, 3.5.18-1ubuntu1.6+esm4, 3.6.13-2ubuntu1.12+esm3, 3.7.3-4ubuntu1.9+6 more1,857
gnutlsapk3.8.5-r0, 3.8.8-r0, 3.8.11-r0, 3.8.12-r03.8.13-r042
OSV records
ALPINE-CVE-2026-42015DEBIAN-CVE-2026-42015UBUNTU-CVE-2026-42015
Also known as
USN-8284-1, USN-8539-1

Charts affected

1,821 by stars
ChartLatestAffected imagesRadar Score
data-ingestion-serviceakto0.1.61 of 1See more

data-ingestion-service akto 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
aktosecurity/data-ingestion-servicedigest-pinned213aded7adc5
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6

Open the chart page →

58,289
browserlessalekcVerified publisher1.2.71 of 1See more

browserless alekc 1.2.7

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ghcr.io/browserless/chrome:v2.56.7d600eac6283f
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

2,138
esphomealexmorbo-esphomeVerified publisher1.0.01 of 1See more

esphome alexmorbo-esphome 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
esphome/esphome:2024.12.2b2c6322700ac
gnutls28@3.7.9-2
3.7.9-2+deb12u7

Open the chart page →

6,401
flaresolverralexmorbo-flaresolverrVerified publisher0.2.01 of 1See more

flaresolverr alexmorbo-flaresolverr 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7

Open the chart page →

27,831
slskdalexmorbo-slskdVerified publisher0.3.01 of 1See more

slskd alexmorbo-slskd 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ghcr.io/slskd/slskd:0.25.1ab9ed50e028b
gnutls28@3.8.3-1.1ubuntu3.5
3.8.3-1.1ubuntu3.6

Open the chart page →

1,756
redisalexvanderberkelVerified publisher2.2.01 of 1See more

redis alexvanderberkel 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
library/redis:8.2.15fa2edb1e408
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7

Open the chart page →

1,903
alibaba-rsocket-brokeralibaba-rsocket-brokerVerified publisher0.1.31 of 1See more

alibaba-rsocket-broker alibaba-rsocket-broker 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
linuxchina/alibaba-rsocket-broker:1.1.3-k8sf758e2e567ee
gnutls28@3.5.18-1ubuntu1.5
3.5.18-1ubuntu1.6+esm4

Open the chart page →

92,754
allure-docker-helm-chartallure-service-chartVerified publisher0.1.01 of 2See more

allure-docker-helm-chart allure-service-chart 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
frankescobar/allure-docker-service:latestdc171ec796d5
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

3,718
katalogalpineworks0.1.21 of 5See more

katalog alpineworks 0.1.2

1 of the 5 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ghcr.io/alpineworks/katalog-migrations:v1.0.562c44a384e13
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7

Open the chart page →

4,577
pagesalstom-pages-app1.0.02 of 3See more

pages alstom-pages-app 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.12+esm3
flyway/flyway:6.4.422d97ceb0c47
gnutls28@3.5.18-1ubuntu1.3
3.5.18-1ubuntu1.6+esm4

Open the chart page →

20,287
amorphieamorphie0.1.22 of 18See more

amorphie amorphie 0.1.2

2 of the 18 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
camunda/zeebe:8.4.5ab5abc09e407
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.9
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
gnutls28@3.7.3-4ubuntu1.3
3.7.3-4ubuntu1.9

Open the chart page →

28,438
anchore-admission-controlleranchore-charts0.9.01 of 2See more

anchore-admission-controller anchore-charts 0.9.0

1 of the 2 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
cfssl/cfssl:v1.6.5c9018c2ddf0b
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u7

Open the chart page →

7,547
pagesandrei-pages1.0.02 of 3See more

pages andrei-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.12+esm3
flyway/flyway:6.4.422d97ceb0c47
gnutls28@3.5.18-1ubuntu1.3
3.5.18-1ubuntu1.6+esm4

Open the chart page →

20,287
omada-controllerandrelote-k8sVerified publisher4.5.01 of 1See more

omada-controller andrelote-k8s 4.5.0

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
mbentley/omada-controller:4.3f4e682274bed
gnutls28@3.5.18-1ubuntu1.6
3.5.18-1ubuntu1.6+esm4

Open the chart page →

11,623
speech-to-phraseandrenarchyVerified publisher1.3.01 of 1See more

speech-to-phrase andrenarchy 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
rhasspy/wyoming-speech-to-phrase:1.4.3e532f0dbc6b2
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7

Open the chart page →

4,107
games-on-whalesangelnu2.0.04 of 7See more

games-on-whales angelnu 2.0.0

4 of the 7 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
andrewmackrodt/firefox-x11:142.0.1-r133f9080470c9
gnutls28@3.7.3-4ubuntu1.7
3.7.3-4ubuntu1.9
ghcr.io/games-on-whales/pulseaudio:1.0.0f34f98405c10
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.12+esm3
ghcr.io/games-on-whales/retroarch:1.0.0103fbcec2314
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.12+esm3
ghcr.io/games-on-whales/steam:1.0.09b6105be7ad0
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.12+esm3

Open the chart page →

118,418
ansible-inspecansible-inspec0.2.171 of 2See more

ansible-inspec ansible-inspec 0.2.17

1 of the 2 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ghcr.io/htunn/ansible-inspec:0.2.12cd25a5cc3f1b
gnutls28@3.8.9-3+deb13u1
3.8.9-3+deb13u4

Open the chart page →

5,697
ddosifyanteonVerified publisher1.7.52 of 13See more

ddosify anteon 1.7.5

2 of the 13 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7

Open the chart page →

26,169
antmediaantmediaVerified publisher3.1.01 of 4See more

antmedia antmedia 3.1.0

1 of the 4 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
library/mongo:8.002a0cc7939f5
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

4,644
antrea-uiantreaVerified publisher0.8.01 of 2See more

antrea-ui antrea 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
antrea/antrea-ui-frontend:v0.8.0ee9686bcefb8
gnutls28@3.8.9-3+deb13u2
3.8.9-3+deb13u4

Open the chart page →

3,385
flow-aggregatorantreaVerified publisher2.7.01 of 1See more

flow-aggregator antrea 2.7.0

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
antrea/flow-aggregator:v2.7.0065193e7572f
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

794
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
gnutls28@3.7.3-4ubuntu1.3
3.7.3-4ubuntu1.9

Open the chart page →

6,304
d.vazquezm.2021_helmapphelmVerified publisher1.0.01 of 6See more

d.vazquezm.2021_helm apphelm 1.0.0

1 of the 6 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
library/mongo:5.0.6-focal8e70544b6c76
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.12+esm3

Open the chart page →

19,832
inbox-serverappscodeVerified publisher2025.12.251 of 1See more

inbox-server appscode 2025.12.25

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ghcr.io/appscode/inbox-server:postgres-latest536358d7b17e
gnutls28@3.7.3-4ubuntu1.7
3.7.3-4ubuntu1.9

Open the chart page →

4,073
inbox-server-distributedappscodeVerified publisher2025.12.253 of 4See more

inbox-server-distributed appscode 2025.12.25

3 of the 4 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.9
library/rabbitmq:3.12.1-managementf020c06da226
gnutls28@3.7.3-4ubuntu1.2
3.7.3-4ubuntu1.9
ghcr.io/appscode/inbox-server:latest536358d7b17e
gnutls28@3.7.3-4ubuntu1.7
3.7.3-4ubuntu1.9

Open the chart page →

15,896
james-komposeappscodeVerified publisher0.1.03 of 4See more

james-kompose appscode 0.1.0

3 of the 4 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
library/cassandra:4.1.37cbcec0086ac
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.9
library/rabbitmq:3.12.1-managementf020c06da226
gnutls28@3.7.3-4ubuntu1.2
3.7.3-4ubuntu1.9
ghcr.io/appscode/inbox-server:MailetGroup4a2824296412
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.9

Open the chart page →

17,278
platform-apiappscodeVerified publisher2026.9.111 of 3See more

platform-api appscode 2026.9.11

1 of the 3 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ghcr.io/appscode/gotenberg:8.25f9104080d9a7
gnutls28@3.8.9-3
3.8.9-3+deb13u4

Open the chart page →

38,045
s3proxyappscodeVerified publisher2026.9.111 of 1See more

s3proxy appscode 2026.9.11

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ghcr.io/appscode/s3proxy:sha-a82ca6820518335f9f9
gnutls28@3.7.3-4ubuntu1.5
3.7.3-4ubuntu1.9

Open the chart page →

3,336
haproxyappuio2.7.21 of 1See more

haproxy appuio 2.7.2

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ghcr.io/vshn/haproxy-with-mysql:1.0.0a3c27ee3fb2f
gnutls28@3.7.9-2
3.7.9-2+deb12u7

Open the chart page →

5,731
chart-app-vidapp-vid-chartVerified publisher0.0.71 of 2See more

chart-app-vid app-vid-chart 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
library/mongo:latest5d7043a4ffe0
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2

Open the chart page →

8,552
dokuwikiarea-42Verified publisher0.1.81 of 1See more

dokuwiki area-42 0.1.8

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
dokuwiki/dokuwiki:2025-05-14af08ecfdda239
gnutls28@3.8.9-3
3.8.9-3+deb13u4

Open the chart page →

7,641
argocdargo-helm-charts1.0.01 of 3See more

argocd argo-helm-charts 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
quay.io/argoproj/argocd:v2.14.115fc69e31c755
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.6

Open the chart page →

7,711
arlas-aiasarlas-stackVerified publisher28.9.09 of 22See more

arlas-aias arlas-stack 28.9.0

9 of the 22 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
bitnamilegacy/elasticsearch:9.0.1-debian-12-r0e6f6ddcce2f1
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
bitnamilegacy/keycloak:26.3.3-debian-12-r0da3df0976a9f
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
bitnamilegacy/minio:2024.12.18-debian-12-r1c0ede65eb88e
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
bitnamilegacy/minio:2025.4.22-debian-12-r1d7cd0e172c4c
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
bitnamilegacy/os-shell:12-debian-12-r439ba5d16f9c64
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
bitnamilegacy/rabbitmq:4.1.2-debian-12-r074a3d7c747eb
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
bitnamilegacy/redis:8.0.3-debian-12-r1189aae381e7f
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
ghcr.io/developmentseed/titiler:0.22.48ac53eb38393
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7

Open the chart page →

38,946
arma-reforgerarma-reforger0.5.31 of 8See more

arma-reforger arma-reforger 0.5.3

1 of the 8 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ghcr.io/brittonhayes/arma-reforger:latest6fde1edc0983
gnutls28@3.6.13-2ubuntu1.8
3.6.13-2ubuntu1.12+esm3

Open the chart page →

23,479
bind9artem-shestakov1.0.11 of 1See more

bind9 artem-shestakov 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ubuntu/bind9:9.16-20.04_beta5ee73f44e5d0
gnutls28@3.6.13-2ubuntu1.12
3.6.13-2ubuntu1.12+esm3

Open the chart page →

3,745
keystonearzu0.2.293 of 4See more

keystone arzu 0.2.29

3 of the 4 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
library/rabbitmq:3.7-managementb6dd45cc35b3
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6+esm4
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
gnutls28@3.6.13-2ubuntu1.8
3.6.13-2ubuntu1.12+esm3
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
gnutls28@3.6.13-2ubuntu1.8
3.6.13-2ubuntu1.12+esm3

Open the chart page →

22,801
dltkvassist-iot-data-integrity-verification0.2.03 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
gnutls28@3.7.3-4ubuntu1.9
no fix listed
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
gnutls28@3.4.10-4ubuntu1.4
3.4.10-4ubuntu1.9+esm4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
gnutls28@3.4.10-4ubuntu1.4
3.4.10-4ubuntu1.9+esm4

Open the chart page →

194,576
dltflassist-iot-dlt-based-fl0.2.03 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

3 of the 9 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
hyperledger/fabric-ca:latesta70b6ba64a08
gnutls28@3.7.3-4ubuntu1.9
no fix listed
hyperledger/fabric-ca-tools:latest4ce6f43ded2e
gnutls28@3.4.10-4ubuntu1.4
3.4.10-4ubuntu1.9+esm4
hyperledger/fabric-couchdb:0.4.15f6c724592abf
gnutls28@3.4.10-4ubuntu1.4
3.4.10-4ubuntu1.9+esm4

Open the chart page →

194,576
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:dbmongo4-latestd157fbe150e3
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.12+esm3

Open the chart page →

9,453
idmassist-iot-identity-manager0.1.01 of 2See more

idm assist-iot-identity-manager 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
assistiot/identity-manager_db:latest0d3e6d35f168
gnutls28@3.7.9-2
3.7.9-2+deb12u7

Open the chart page →

13,438
locationprocessingassist-iot-location-processing1.0.01 of 3See more

locationprocessing assist-iot-location-processing 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
assistiot/location_processing:lateste9bae124095f
gnutls28@3.7.3-4ubuntu1.1
3.7.3-4ubuntu1.9

Open the chart page →

10,191
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
assistiot/open_api_backend:1.1.230812ba93555
gnutls28@3.7.3-4ubuntu1.3
3.7.3-4ubuntu1.9

Open the chart page →

88,292
sdn-controllerassist-iot-sdn-controller2.4.01 of 1See more

sdn-controller assist-iot-sdn-controller 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
assistiot/sdn_controller:2.4.0ea254b6d8a31
gnutls28@3.6.13-2ubuntu1.6
3.6.13-2ubuntu1.12+esm3

Open the chart page →

7,996
sd-wanassist-iot-sd-wan1.0.01 of 2See more

sd-wan assist-iot-sd-wan 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
library/mongo:4.2.21-bionic9cb28f7291d9
gnutls28@3.5.18-1ubuntu1.5
3.5.18-1ubuntu1.6+esm4

Open the chart page →

5,391
smartorchestratorassist-iot-smart-orchestrator4.0.04 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

4 of the 14 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_mcs:latest7d6a0d534c7f
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7
assistiot/smart-orchestrator_scheduler:latest38b003e55ff3
gnutls28@3.7.9-2+deb12u2
3.7.9-2+deb12u7
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
gnutls28@3.7.9-2
3.7.9-2+deb12u7
library/mongo:4.4.66efa05203990
gnutls28@3.5.18-1ubuntu1.4
3.5.18-1ubuntu1.6+esm4

Open the chart page →

46,188
videoaugmentationassist-iot-video-augmentation0.1.01 of 3See more

videoaugmentation assist-iot-video-augmentation 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
assistiot/video_augmentation:runner-cpu-lateste5ae539ce2cb
gnutls28@3.6.13-2ubuntu1.8
3.6.13-2ubuntu1.12+esm3

Open the chart page →

77,444
account-monitorastria0.0.11 of 1See more

account-monitor astria 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/account-monitor:latest4c8b42890035
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7

Open the chart page →

1,987
astrotrekastria0.0.22 of 4See more

astrotrek astria 0.0.2

2 of the 4 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
timescale/timescaledb-ha:pg15-latesta8e3322e1cf9
gnutls28@3.7.3-4ubuntu1.2
3.7.3-4ubuntu1.9
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7

Open the chart page →

32,881
auctioneerastria0.0.21 of 1See more

auctioneer astria 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/auctioneer:pr-18391386b7b5e555
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7

Open the chart page →

2,236
evm-bridge-withdrawerastria1.0.61 of 1See more

evm-bridge-withdrawer astria 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-42015.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/evm-bridge-withdrawer:1.0.29c88e1aff357
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7

Open the chart page →

2,212

Container images carrying it

1,899 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
gnutls28@3.7.9-2
3.7.9-2+deb12u7
1
public.ecr.aws/k2x0t8t6/kubeadapt/app/kubeadapt-k8s-pulse:v3.0.1dc5a516c2333
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7
1
public.ecr.aws/k6v9y5g3/cluster-agent:master.57536d051110158
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
public.ecr.aws/k6v9y5g3/cluster-agent:cost_k8s_process.5769e14a72b066d
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
gnutls28@3.7.9-2
3.7.9-2+deb12u7
1
public.ecr.aws/spotinst/spot-network-client:1.0.1486380a01587d
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
1
public.ecr.aws/spotinst/spot-network-client:1.0.0-8-lb_endpoint-d0ec127efcecf98b912
gnutls28@3.5.18-1ubuntu1.5
3.5.18-1ubuntu1.6+esm4
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.12+esm3
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
gnutls28@3.7.9-2+deb12u1
3.7.9-2+deb12u7
1
quay.io/aerokube/jumphost:1.0.170fd7c00418d
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.9
1
quay.io/aerokube/keygen:1.0.1578934444f04
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.9
1
quay.io/argoproj/argocd:v2.4.115b6701d8fb31
gnutls28@3.7.3-4ubuntu1.1
3.7.3-4ubuntu1.9
1
quay.io/argoproj/argocd:v2.10.783c86003b781
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.9
1
quay.io/argoproj/argocd:v3.0.395b5cf7ba6fe
gnutls28@3.8.3-1.1ubuntu3.3
3.8.3-1.1ubuntu3.6
1
quay.io/argoproj/argocd:v3.1.1a36ab0c0860c
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
1
quay.io/argoproj/argocd:v2.8.6acaf37352569
gnutls28@3.7.3-4ubuntu1.2
3.7.3-4ubuntu1.9
1
quay.io/cilium/cilium:v1.15.1351d6685dc6f
gnutls28@3.7.3-4ubuntu1.4
3.7.3-4ubuntu1.9
1
quay.io/cilium/cilium:v1.18.2858f807ea4e2
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
1
quay.io/cilium/cilium:v1.17.14cdcfab5b4466
gnutls28@3.8.3-1.1ubuntu3.5
3.8.3-1.1ubuntu3.6
1
quay.io/cilium/cilium-envoy:v1.35.9-1773656288-7b052e66eb2cfc5ac130ce0a5be66202a10d83be60031f396695
gnutls28@3.8.3-1.1ubuntu3.5
3.8.3-1.1ubuntu3.6
1
quay.io/cilium/cilium-envoy:v1.34.7-1757592137-1a52bb680a956879722f48c591a2ca90f77913247932d656b63f
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
1
quay.io/clustersecret/clustersecret:0.0.14a9f835d1b241
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
quay.io/enix/topomatik:1.3.1d9f0bec83ef0
gnutls28@3.7.3-4ubuntu1.8
3.7.3-4ubuntu1.9
1
quay.io/evryfs/docker-mcrouter:0.40.0-9a2d3a4c67b0f
gnutls28@3.5.18-1ubuntu1.6
3.5.18-1ubuntu1.6+esm4
1
quay.io/evryfs/spring-boot-admin:2.7.1060950ef63764
gnutls28@3.7.3-4ubuntu1.1
3.7.3-4ubuntu1.9
1
quay.io/fiware/waltid:1.14.1-SNAPSHOT93889c3d8a34
gnutls28@3.7.3-4ubuntu1.1
3.7.3-4ubuntu1.9
1
quay.io/go-skynet/local-ai:latest0632c21ddbe4
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
quay.io/jupyterhub/k8s-hub:4.3.5113e372cf71b
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7
1
quay.io/jupyterhub/k8s-hub:4.3.492f883d09270
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7
1
quay.io/mittwald/kube-httpcache:stable2169032c5840
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
quay.io/mittwald/kube-mail:latest04f1099241fc
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
quay.io/mongodb/mongodb-enterprise-operator:1.8.2a1c3843b03bc
gnutls28@3.4.10-4ubuntu1.8
3.4.10-4ubuntu1.9+esm4
1
quay.io/opsmxpublic/rabbitmq:4.2-management3408107e5cc4
gnutls28@3.8.3-1.1ubuntu3.4
3.8.3-1.1ubuntu3.6
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
gnutls28@3.4.10-4ubuntu1.5
3.4.10-4ubuntu1.9+esm4
1
quay.io/opsmxpublic/ubi8-oes-datascience:isd-spin-2025.10.01-af26a30d4-202511261054d8f66f4117fe
gnutls28@3.8.9-3
3.8.9-3+deb13u4
1
quay.io/underndog/samba:1.2.0-not-recyclecca801de9fa5
gnutls@3.8.8-r0
3.8.13-r0
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
gnutls28@3.7.9-2
3.7.9-2+deb12u7
1
registry.gitlab.com/crafty-controller/crafty-4:latest7b6e87514259
gnutls28@3.8.3-1.1ubuntu3.6
3.8.3-1.1ubuntu3.6+Fips1.2
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
gnutls28@3.8.9-3+deb13u2
3.8.9-3+deb13u4
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
gnutls28@3.7.9-2+deb12u6
3.7.9-2+deb12u7
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/rabbitmq:3.12.145a9334f371f3
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
gnutls28@3.6.13-2ubuntu1.3
3.6.13-2ubuntu1.12+esm3
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
gnutls28@3.8.9-3
3.8.9-3+deb13u4
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
gnutls28@3.7.9-2
3.7.9-2+deb12u7
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
gnutls28@3.7.9-2+deb12u3
3.7.9-2+deb12u7
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
gnutls28@3.7.9-2+deb12u5
3.7.9-2+deb12u7
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
gnutls28@3.7.9-2+deb12u4
3.7.9-2+deb12u7
1

syft 1.42.1 · advisories as of 21 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.