StackRadar

CVE-2026-42250

Medium

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,382
of 17,803 indexed, latest versions
Container images
2,359
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-42250 affecting package bzip2 for versions less than 1.0.8-2

Carried by container images the latest versions of 2,382 of 17,803 indexed charts deploy, on 2,359 images.

Affected packageAffected versionsFixed inImages
bzip2deb1.0.6-5, 1.0.6-8, 1.0.6-8.1, 1.0.6-8.1ubuntu0.2+11 more1.0.6-5ubuntu0.1~esm3, 1.0.6-8.1ubuntu0.2+esm1, 1.0.6-8ubuntu0.2+esm1, 1.0.8-2ubuntu0.1~esm1+4 more2,346
bzip2rpm1.0.8-1.azl3, 1.0.8-150400.1.1221.0.8-2, 1.0.8-150400.3.4.113
OSV records
DEBIAN-CVE-2026-42250UBUNTU-CVE-2026-42250AZL-88809ECHO-dfc7-0c27-52d8SUSE-SU-2026:4055-1
Also known as
USN-8685-1

Charts affected

2,382 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,359 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
continuoussecuritytooling/keycloak-reporting-cli:1.3.3f04ecefab64e
bzip2@1.0.8-5+b1
no fix listed
1
cortezaproject/corteza:2024.9.60bcdcbcd3c63
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
cortezaproject/corteza:2024.9.08eb7a26605c9
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
1
cortezaproject/corteza:2024.9.4cb9f200de5d2
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
bzip2@1.0.8-5+b1
no fix listed
1
coturn/coturn:4.10.0-r1f4c2af06c3c5
bzip2@1.0.8-6
no fix listed
1
countly/countly-server:25.05.4e3c238248f99
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
1
cradlepoint/pgbouncer:1.0.18f5720b0cd03
bzip2@1.0.6-8.1
1.0.6-8.1ubuntu0.2+esm1
1
cribl/cribl:3.0.2762747cb6796
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
1
csiplugin/csi-neonsan:v1.2.21fa83d45417f
bzip2@1.0.6-8ubuntu0.2
1.0.6-8ubuntu0.2+esm1
1
cspconsole/config-provider:1.0.365524a26a6c23
bzip2@1.0.8-5+b1
no fix listed
1
cspconsole/csp-control-center:1.0.1046dda4a31bd6
bzip2@1.0.8-5+b1
no fix listed
1
cspconsole/report-collector:1.0.15839750248193b
bzip2@1.0.8-5+b1
no fix listed
1
cspconsole/report-processor:1.0.279a2d8840bfdf
bzip2@1.0.8-5+b1
no fix listed
1
cubejs/cubestore:v1.5.334ac523a9bab
bzip2@1.0.8-5+b1
no fix listed
1
cybrarist/discount-bandit:v4.0.4e9e2447ac666
bzip2@1.0.8-6
no fix listed
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
bzip2@1.0.8-5+b1
no fix listed
1
cznic/knot-resolver:v6.4.2fe71c5214fdc
bzip2@1.0.8-6
no fix listed
1
dachichang/basic-auth-s3-nginx:1.0.07ccac90a935e
bzip2@1.0.8-5+b1
no fix listed
1
daedalusproject/base_kubectl:latest6f72b5119eda
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
1
dagster/dagster-celery-k8s:1.13.230505973033e1
bzip2@1.0.8-6
no fix listed
1
dagster/dagster-cloud-agent:1.13.2322036fc83927
bzip2@1.0.8-6
no fix listed
1
danialnabiyan1382/lsdisk:v2.0.8f96a7ebf1f42
bzip2@1.0.8-5+b1
no fix listed
1
dannielkil/book-frontend:latest937993927694
bzip2@1.0.8-5+b1
no fix listed
1
darthsim/imgproxy:v3.30.13b709e4a0e5e
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
darthsim/imgproxy:v3.26476cb08c816a
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
darthsim/imgproxy:v3.29.17d12c7c8fc66
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
daskdev/dask-notebook:1.1.0052630f5ca04
bzip2@1.0.6-8.1
1.0.6-8.1ubuntu0.2+esm1
1
dasmeta/mongodb-bi-connector:1.0.3fa657960dfec
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
1
datadog/agent:6aad9994de6a7
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
datafuselabs/databend-meta:v1.2.279ba877ee6cb4d
bzip2@1.0.8-5+b1
no fix listed
1
datafuselabs/databend-query:v1.2.279a936843b85b4
bzip2@1.0.8-5+b1
no fix listed
1
datalayers/datalayers:v2.2.1017b292079239
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
datalust/seq:5.0.832-pre9c731bb207a6
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
1
datalust/seq-input-gelf:3.0.441-x643de34aed5642
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
1
datamate/seafile-professional:11.0.202dd66b722464
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
dbeaver/cloudbeaver:26.1.287ab86d00f8c
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
dbgate/dbgate:7.2.3f2dc7423ea88
bzip2@1.0.8-5+b1
no fix listed
1
dblaci/ubuntu-ssh-rsync:20231020eea697611af4
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
ddosify/alaz:v0.12.0ea602056d9ce
bzip2@1.0.8-5+b1
no fix listed
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
bzip2@1.0.8-5+b1
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
bzip2@1.0.8-5+b1
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
bzip2@1.0.8-5+b1
no fix listed
1
ddosify/selfhosted_hammermanager:2.0.2b796b8c73011
bzip2@1.0.8-5+b1
no fix listed
1
decisionrules/ai-engine:latest38c377e7c01e
bzip2@1.0.8-6
no fix listed
1
deconzcommunity/deconz:2.29.2062de2362641
bzip2@1.0.8-5+b1
no fix listed
1
deepflowce/clickhouse-server:22.8.6.71bc1882f75c18
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
defactops/defactops-backend:1.0.2307b663c0092a
bzip2@1.0.8-5+b1
no fix listed
1
defectdojo/defectdojo-django:3.3.100c597abdbb535
bzip2@1.0.8-6
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.