StackRadar

CVE-2026-42250

Medium

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,397
of 17,803 indexed, latest versions
Container images
2,382
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-42250 affecting package bzip2 for versions less than 1.0.8-2

Carried by container images the latest versions of 2,397 of 17,803 indexed charts deploy, on 2,382 images.

Affected packageAffected versionsFixed inImages
bzip2deb1.0.6-5, 1.0.6-8, 1.0.6-8.1, 1.0.6-8.1ubuntu0.2+11 more1.0.6-5ubuntu0.1~esm3, 1.0.6-8.1ubuntu0.2+esm1, 1.0.6-8ubuntu0.2+esm1, 1.0.8-2ubuntu0.1~esm1+4 more2,369
bzip2rpm1.0.8-1.azl3, 1.0.8-150400.1.1221.0.8-2, 1.0.8-150400.3.4.113
OSV records
DEBIAN-CVE-2026-42250UBUNTU-CVE-2026-42250AZL-88809ECHO-dfc7-0c27-52d8SUSE-SU-2026:4055-1
Also known as
USN-8685-1

Charts affected

2,397 by stars
ChartLatestAffected imagesRadar Score

Container images carrying it

2,382 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
getsentry/relay:24.10.0ba7bf9163219
bzip2@1.0.8-5+b1
no fix listed
1
ghostfolio/ghostfolio:3.7.0e3c6ab53e49b
bzip2@1.0.8-5+b1
no fix listed
1
ghusta/postgres-world-db:latest879d0919fdcc
bzip2@1.0.8-6
no fix listed
1
gitlab/gitlab-runner:v15.3.0860d4a3fec7a
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
1
glasskube/operator:0.12.2be5133100d63
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
glpi/glpi:latest4b681082a79e
bzip2@1.0.8-6
no fix listed
1
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
bzip2@1.0.8-5+b1
no fix listed
1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
bzip2@1.0.8-5+b1
no fix listed
1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
bzip2@1.0.8-5+b1
no fix listed
1
gopinatht/ovs-plugin-installer:latest632cb2e9c399
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
1
gotenberg/gotenberg:8.30206a6c708fc6
bzip2@1.0.8-6
no fix listed
1
gotenberg/gotenberg:8.3467097317623a
bzip2@1.0.8-6
no fix listed
1
gotenberg/gotenberg:8-chromiuma40f92d7419a
bzip2@1.0.8-6
no fix listed
1
gotson/komga:0.99.49b15ea6bfc30
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
1
gradiant/open5gs-dbctl:0.10.3332031245fce
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
grafana/agent:v0.44.23364714a2f64
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
grafana/alloy:v1.5.101a63f4e032c
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
grafana/alloy:v1.4.306bdcbb51fc2
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
grafana/alloy:v1.18.10f4434c92b3e
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
grafana/alloy:v1.18.0491b0578c049
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
grafana/alloy:v1.16.384b76d56c594
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
grafana/alloy:v1.11.38c7256f412fe
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
grafana/alloy:v1.19.2b8ec653c4423
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
grafana/alloy:v1.14.0f50931848bd8
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
grafana/beyla:1.3.336d07f8d276e
bzip2@1.0.8-5+b1
no fix listed
1
grafana/fluent-plugin-loki:latest8a3882e8c28b
bzip2@1.0.8-5+b1
no fix listed
1
grafana/mcp-grafana:1.5.107c6614a8f8b
bzip2@1.0.8-5+b1
no fix listed
1
grafana/mcp-grafana:0.14.042f541f22063
bzip2@1.0.8-5+b1
no fix listed
1
grafana/promtail:3.5.165bfae480b57
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
grafana/promtail:3.6.18dcfdf466da0
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
graphprotocol/graph-node:latestb0436347fb24
bzip2@1.0.8-5+b1
no fix listed
1
graphprotocol/graph-node:v0.37.0f4452cdedd68
bzip2@1.0.8-5+b1
no fix listed
1
graylog/graylog:6.1.1019de1aff48c2
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
graylog/graylog-enterprise:7.1.88a1f641cd7aa
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
greenkube/greenkube:0.3.00c01932282a4
bzip2@1.0.8-5+b1
no fix listed
1
grpl/grapple-cli:0.2.127c00aafee6629
bzip2@1.0.8-5.1
1.0.8-5.1ubuntu0.1
1
guacamole/guacamole:1.5.50f62f6d17ab3
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
guillh/web3-prometheus-exporter:0.3.04fb99dbc32b2
bzip2@1.0.8-5+b1
no fix listed
1
gulacedia/web-dvwa-new:v367b467d961ca
bzip2@1.0.8-5+b1
no fix listed
1
hamidyousefi93/saam-test:latestc34f071f6ed0
bzip2@1.0.8-5+b1
no fix listed
1
hamzaarshad10/querybackend:1.6.22c1c3b86a8e7
bzip2@1.0.8-5+b1
no fix listed
1
hamzaarshad10/querypodpy:1.7154f38e8668e
bzip2@1.0.8-5+b1
no fix listed
1
hansehe/locust:1.1.0bc8e45262bc4
bzip2@1.0.8-5+b1
no fix listed
1
haohanyang/compass-web:0.5.054f2112602ee
bzip2@1.0.8-5+b1
no fix listed
1
haohanyang/compass-web:0.5.1f4f8fe4e21f1
bzip2@1.0.8-5+b1
no fix listed
1
hassroutyyoussef/accountservice:latest1f01edf1ee0c
bzip2@1.0.8-5+b1
no fix listed
1
hassroutyyoussef/orderservice:latest2fc3d1617928
bzip2@1.0.8-5+b1
no fix listed
1
hassroutyyoussef/userservice:lateste0392e2b4a90
bzip2@1.0.8-5+b1
no fix listed
1
hasura/graphql-engine:v2.34.0-ce0111b0204136
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1

syft 1.42.1 · advisories as of 18 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.