StackRadar

CVE-2026-42250

Medium

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,389
of 17,797 indexed, latest versions
Container images
2,370
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-42250 affecting package bzip2 for versions less than 1.0.8-2

Carried by container images the latest versions of 2,389 of 17,797 indexed charts deploy, on 2,370 images.

Affected packageAffected versionsFixed inImages
bzip2deb1.0.6-5, 1.0.6-8, 1.0.6-8.1, 1.0.6-8.1ubuntu0.2+11 more1.0.6-5ubuntu0.1~esm3, 1.0.6-8.1ubuntu0.2+esm1, 1.0.6-8ubuntu0.2+esm1, 1.0.8-2ubuntu0.1~esm1+4 more2,357
bzip2rpm1.0.8-1.azl3, 1.0.8-150400.1.1221.0.8-2, 1.0.8-150400.3.4.113
OSV records
DEBIAN-CVE-2026-42250UBUNTU-CVE-2026-42250AZL-88809ECHO-dfc7-0c27-52d8SUSE-SU-2026:4055-1
Also known as
USN-8685-1

Charts affected

2,389 by stars
ChartLatestAffected imagesRadar Score
db-backupoleds-helm-chartsVerified publisher0.1.01 of 1See more

db-backup oleds-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
oled01/db-backup:0.1.06302fd2b5333
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

8,140
pulsarolehrgfVerified publisher0.0.51 of 2See more

pulsar olehrgf 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
apachepulsar/pulsar:3.1.016f9fdab3fa6
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

9,083
laravel-appoli-the-devVerified publisher2.0.171 of 1See more

laravel-app oli-the-dev 2.0.17

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
serversideup/php:8.5-fpm-nginx8f8c2f010ac5
bzip2@1.0.8-6
no fix listed

Open the chart page →

2,841
node-appoli-the-devVerified publisher1.0.01 of 1See more

node-app oli-the-dev 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/node:22-bookworm-slim83f487e0a634
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

1,179
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
bzip2@1.0.8-6
no fix listed

Open the chart page →

4,664
cron-jobonechart-slVerified publisher0.73.71 of 1See more

cron-job onechart-sl 0.73.7

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/debian:stable-slim04634311a8d5
bzip2@1.0.8-6
no fix listed

Open the chart page →

985
onedevonedev11.9.01 of 1See more

onedev onedev 11.9.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
1dev/server:11.9.0cd5b12fe5471
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

6,108
ontoserverontoserverVerified publisher0.5.21 of 2See more

ontoserver ontoserver 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
bzip2@1.0.8-6
no fix listed

Open the chart page →

1,667
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
onyxdotapp/onyx-backend:latest473fdffe4e67
bzip2@1.0.8-6
no fix listed

Open the chart page →

6,422
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

9,766
opentickopenchartVerified publisher0.1.01 of 1See more

opentick openchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/nginx:1.25.5a484819eb602
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

5,716
jobopen-charts2.0.01 of 1See more

job open-charts 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

749
bbsimopencord4.8.111 of 1See more

bbsim opencord 4.8.11

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
voltha/bbsim:1.16.7d90403d58016
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

3,915
bbsim-sadis-serveropencord0.3.51 of 1See more

bbsim-sadis-server opencord 0.3.5

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
voltha/bbsim-sadis-server:0.4.0762b272d439e
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

3,729
cdn-remoteopencord0.2.42 of 3See more

cdn-remote opencord 0.2.4

2 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
bzip2@1.0.6-8.1
1.0.6-8.1ubuntu0.2+esm1
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1

Open the chart page →

63,509
comacopencord1.0.03 of 9See more

comac opencord 1.0.0

3 of the 9 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
omecproject/onos-progran:1.0.05715e5648aa0
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1

Open the chart page →

88,857
comac-cuopencord0.1.11 of 4See more

comac-cu opencord 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
bzip2@1.0.6-8.1
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

8,065
comac-platformopencord0.0.171 of 11See more

comac-platform opencord 0.0.17

1 of the 11 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1

Open the chart page →

26,316
freeradiusopencord1.0.41 of 1See more

freeradius opencord 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

15,738
mcord-cdn-remoteopencord0.1.62 of 2See more

mcord-cdn-remote opencord 0.1.6

2 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
woojoong/wowza:latestec230db19652
bzip2@1.0.6-8.1
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

42,879
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1

Open the chart page →

29,359
mcord-control-planeopencord0.2.22 of 5See more

mcord-control-plane opencord 0.2.2

2 of the 5 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ngick8stesting/c3po-mme:mwca-mme-debug8dd6dea45be4
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
ngick8stesting/c3po-mmeinit:latest1e764eab77b4
bzip2@1.0.6-8.1
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

15,684
oaisimopencord0.1.72 of 3See more

oaisim opencord 0.1.7

2 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

14,574
omec-control-planeopencord0.1.315 of 8See more

omec-control-plane opencord 0.1.31

5 of the 8 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
omecproject/c3po-hss:master-latest638671ef4842
bzip2@1.0.6-8ubuntu0.2
1.0.6-8ubuntu0.2+esm1
omecproject/c3po-hssdb:master-latest28a90cc26716
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
omecproject/mme-exporter:paging-latestbcc5f19fd676
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
omecproject/ngic-cp:central-cp-multi-upfs-latest24a389a0a4fe
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
omecproject/openmme:master-latest64776cb9edb3
bzip2@1.0.6-8ubuntu0.2
1.0.6-8ubuntu0.2+esm1

Open the chart page →

40,941
onosopencord3.0.21 of 1See more

onos opencord 3.0.2

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
onosproject/onos:2.2.144914a8d4b3f
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

12,953
onos-progranopencord1.2.71 of 2See more

onos-progran opencord 1.2.7

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
muluder/prograncontrollermcord:0.1.843b597a93da7
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1

Open the chart page →

38,966
ovspluginopencord1.0.21 of 1See more

ovsplugin opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
gopinatht/ovs-plugin-installer:latest632cb2e9c399
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1

Open the chart page →

4,180
ponsimv2opencord1.2.31 of 2See more

ponsimv2 opencord 1.2.3

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
voltha/voltha-tester:1.7.0655c3048a602
bzip2@1.0.6-8ubuntu0.1
1.0.6-8ubuntu0.2+esm1

Open the chart page →

12,646
sebaopencord1.0.06 of 17See more

seba opencord 1.0.0

6 of the 17 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
tpdock/freeradius:2.2.93da600c95a49
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
voltha/voltha-cli:1.6.0c4e41e92f046
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
voltha/voltha-envoy:1.6.059ab2a00f712
bzip2@1.0.6-5
1.0.6-5ubuntu0.1~esm3
voltha/voltha-netconf:1.6.037f80524c207
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
voltha/voltha-ofagent:1.6.09ee8c1f4428c
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
voltha/voltha-voltha:1.6.0ff596b62de59
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1

Open the chart page →

94,117
voltha-infraopencord2.14.04 of 10See more

voltha-infra opencord 2.14.0

4 of the 10 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.0.2121c8bfa904d8
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
library/ubuntu:16.041f1a2d56de1d
bzip2@1.0.6-8ubuntu0.2
1.0.6-8ubuntu0.2+esm1
voltha/bbsim-sadis-server:0.3.5259fc3a03f4e
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
voltha/voltha-onos:5.1.8e038acb950d3
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

41,148
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

11,064
dokuopenlit0.1.41 of 3See more

doku openlit 0.1.4

1 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:latestfa394da808cc
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

1,744
openlitopenlit1.24.01 of 3See more

openlit openlit 1.24.0

1 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:24.4.12e6587b81a26
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1

Open the chart page →

5,083
openlit-controlleropenlit0.10.01 of 1See more

openlit-controller openlit 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/openlit/openlit-controller:0.10.0165efd4469ea
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

1,384
openpanelopenpanel0.9.01 of 6See more

openpanel openpanel 0.9.0

1 of the 6 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

3,472
llm-stackopenproject-helm-chartsVerified publisher1.1.02 of 2See more

llm-stack openproject-helm-charts 1.1.0

2 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
apache/apisix:3.16.0-ubuntu5e47692cac00
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
library/python:3.12-slim78387bc3881b
bzip2@1.0.8-6
no fix listed

Open the chart page →

2,009
fineractopenshift0.1.12 of 4See more

fineract openshift 0.1.1

2 of the 4 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/mariadb:11.4611a2fcc5fa7
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
library/nginx:latest05b8cb60c354
bzip2@1.0.8-6
no fix listed

Open the chart page →

7,889
sohaopensohaVerified publisher0.1.91 of 2See more

soha opensoha 0.1.9

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
bzip2@1.0.8-6
no fix listed

Open the chart page →

1,799
open-vpnopenvpn0.0.11 of 1See more

open-vpn openvpn 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/openvpn-as:version-2.8.6-916f8e7d-ubuntu184ee0764310e7
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

15,622
terminalsopen-webui0.7.02 of 2See more

terminals open-webui 0.7.0

2 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/open-webui/terminals:latest5d2fd44366a4
bzip2@1.0.8-6
no fix listed
ghcr.io/open-webui/terminals-operator:latest6287ce8be502
bzip2@1.0.8-6
no fix listed

Open the chart page →

2,060
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
openwhisk/ow-utils:1.0.0c80dba0de3aa
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

36,335
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
bzip2@1.0.6-5
1.0.6-5ubuntu0.1~esm3

Open the chart page →

26,374
hiveopstty0.1.91 of 4See more

hive opstty 0.1.9

1 of the 4 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

4,569
grrosdfir-infrastructureVerified publisher1.0.32 of 5See more

grr osdfir-infrastructure 1.0.3

2 of the 5 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/mariadb:11.3.2e101f9db3191
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

11,020
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.025 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

25 of the 40 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
bitnamilegacy/git:latest4b08d0c5af8d
bzip2@1.0.8-5+b1
no fix listed
chromadb/chroma:1.5.7fc8dc8e11fb2
bzip2@1.0.8-6
no fix listed
library/mariadb:11.3.2e101f9db3191
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
yetiplatform/yeti:2.9.09bcbe2650a14
bzip2@1.0.8-6
no fix listed
yetiplatform/yeti-frontend:2.9.0873ef15d267b
bzip2@1.0.8-6
no fix listed
ghcr.io/google/fleetspeak:v0.1.17cd264d33efd4
bzip2@1.0.8-5+b1
no fix listed
ghcr.io/openrelik/openrelik-mediator:latest42efc445b19e
bzip2@1.0.8-5+b1
no fix listed
ghcr.io/openrelik/openrelik-metrics:latest3d0f1ddeebf5
bzip2@1.0.8-5+b1
no fix listed
ghcr.io/openrelik/openrelik-server:latestce1132261523
bzip2@1.0.8-5+b1
no fix listed
ghcr.io/openrelik/openrelik-worker-analyzer-config:latest1269d3d8d2c2
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-analyzer-logs:latestb175cc61959a
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-bulkextractor:latest67498ee2e639
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-capa:latest71323a4f3fc5
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-chromecreds:latest76d4fbcc6ff0
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-cloud-logs:latesta5d7e3cf71d3
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-dfindexeddb:latest31966a825782
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-extraction:latestec9fc5864cd5
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-floss:latest7a331eb83c6a
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-grep:latest470ff3529746
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-os-creds:latest7fc7ec101f08
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-plaso:latest75537ea8c851
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-strings:latest6e05055b701f
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-timesketch:latest4cb88b603cdc
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
ghcr.io/openrelik/openrelik-worker-yara:latestbd7fbf4505b5
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

72,857
yetiosdfir-infrastructureVerified publisher1.0.52 of 4See more

yeti osdfir-infrastructure 1.0.5

2 of the 4 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
yetiplatform/yeti:latest9c3006cedcca
bzip2@1.0.8-6
no fix listed
yetiplatform/yeti-frontend:latest709064278c7e
bzip2@1.0.8-6
no fix listed

Open the chart page →

6,707
webot-container-kit0.1.01 of 1See more

web ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
bzip2@1.0.8-6
no fix listed

Open the chart page →

1,861
workerot-container-kit0.1.01 of 1See more

worker ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
bzip2@1.0.8-6
no fix listed

Open the chart page →

1,861
lens-metric-proxyowan-charts0.1.01 of 1See more

lens-metric-proxy owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
bzip2@1.0.8-6
no fix listed

Open the chart page →

1,861
automatap2p-avs0.1.01 of 2See more

automata p2p-avs 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/foundry-rs/foundry:latest0c00cb0bda1a
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

3,679

Container images carrying it

2,370 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
knspar/phronetis-operator:0.1.60c4f0543ee58
bzip2@1.0.8-5+b1
no fix listed
1
kong/httpbin:latesta6ac46531193
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
kong/kong:3.9.16addf50e6bd8
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
kong/kong-ai-gateway:2.0.3367ed5985b76
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
krontechnology/aapm-agent:1.8.41cc7d5be6529
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
krontechnology/aapm-agent:1.1.07feef7d2ab42
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
1
krontechnology/aapm-service:1.1.39dd602db8baa
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
kserve/models-web-app:v0.13.073486345a602
bzip2@1.0.8-5+b1
no fix listed
1
kubeflownotebookswg/jupyter-web-app:v1.9.2afb52057c997
bzip2@1.0.8-5+b1
no fix listed
1
kubeflownotebookswg/tensorboards-web-app:v1.9.277f07f52a84a
bzip2@1.0.8-5+b1
no fix listed
1
kubeflownotebookswg/volumes-web-app:v1.9.2f63c3e550af3
bzip2@1.0.8-5+b1
no fix listed
1
kubegems/redis:7.2.5-debian-12-r2870ee3a77add
bzip2@1.0.8-5+b1
no fix listed
1
kubeoperator/webkubectl:v2.4.0be8f0d624640
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
kubeshop/bitnami-mongodb:8.3.8d48b172d99d8
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
kubeshop/testkube-minio:2025.10d8e1af6aca99
bzip2@1.0.8-5+b1
no fix listed
1
kubesphere/examples-bookinfo-reviews-v2:1.13.06d93129beb32
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
1
kudobuilder/controller:v0.9.069072d979708
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
1
kusionstack/ctrlmesh-manager:v0.2.065e3c32b64d7
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
1
kusionstack/kusion:v0.14.0126c8f0b0976
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
kuzwolka/aws9:main1ad759b961b1
bzip2@1.0.8-5+b1
no fix listed
1
kuzwolka/aws9:news3e8880fbbb96
bzip2@1.0.8-5+b1
no fix listed
1
kuzwolka/aws9:blog4a7707410bf1
bzip2@1.0.8-5+b1
no fix listed
1
kuzwolka/aws9:shop84a9d9766345
bzip2@1.0.8-5+b1
no fix listed
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
kyovint/kyoimgtransactions:1.0.048c19e3ae9a3
bzip2@1.0.8-6
no fix listed
1
kyovint/kyoimgusers:1.0.080084149156e
bzip2@1.0.8-6
no fix listed
1
labs64/auditflowc7b26d3ca11c
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1
1
labs64/payment-gateway:0.0.10c66feefca17
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1
1
labs64/traefik-authproxy:0.0.3dfc6086dfbce
bzip2@1.0.8-6
no fix listed
1
laly9999/node-app:1dd0e503913e1
bzip2@1.0.8-5+b1
no fix listed
1
langflowai/langflow-frontend:latest54f67f1961fe
bzip2@1.0.8-5+b1
no fix listed
1
langgenius/dify-agent-backend:1.16.1097d3fd27a7b
bzip2@1.0.8-5+b1
no fix listed
1
langgenius/dify-agent-local-sandbox:1.16.1bf8027ddccf3
bzip2@1.0.8-5+b1
no fix listed
1
langgenius/dify-api:1.0.0066035f93856
bzip2@1.0.8-5+b1
no fix listed
1
langgenius/dify-api:1.16.1dcefa5f7c47c
bzip2@1.0.8-5+b1
no fix listed
1
langgenius/dify-api:0.6.11fca918260dd6
bzip2@1.0.8-5+b1
no fix listed
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
langgenius/dify-sandbox:0.2.15750e1111426e
bzip2@1.0.8-6
no fix listed
1
lib42/jackett:latesta55596cda383
bzip2@1.0.8-5+b1
no fix listed
1
library/buildpack-deps:scmac978b783657
bzip2@1.0.8-6
no fix listed
1
library/cassandra:4.0093ee8ee5eb2
bzip2@1.0.8-5+b1
no fix listed
1
library/cassandra:3.11.10b095ff3248c6
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
1
library/convertigo:8.4.3ae605bfcda05
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
library/couchdb:3.4.22817ad50b5c5
bzip2@1.0.8-5+b1
no fix listed
1
library/debian:12.5-slim67f3931ad8cb
bzip2@1.0.8-5+b1
no fix listed
1
library/debian:bookworm6ebd97fa83de
bzip2@1.0.8-5+b1
no fix listed
1
library/debian:12.12-slimd5d3f9c23164
bzip2@1.0.8-5+b1
no fix listed
1
library/debian:latestf324c7ff5432
bzip2@1.0.8-6
no fix listed
1

syft 1.42.1 · advisories as of 17 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.