StackRadar

CVE-2026-42250

Medium

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,412
of 17,787 indexed, latest versions
Container images
2,399
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-42250 affecting package bzip2 for versions less than 1.0.8-2

Carried by container images the latest versions of 2,412 of 17,787 indexed charts deploy, on 2,399 images.

Affected packageAffected versionsFixed inImages
bzip2deb1.0.6-5, 1.0.6-8, 1.0.6-8.1, 1.0.6-8.1ubuntu0.2+11 more1.0.6-5ubuntu0.1~esm3, 1.0.6-8.1ubuntu0.2+esm1, 1.0.6-8ubuntu0.2+esm1, 1.0.8-2ubuntu0.1~esm1+4 more2,380
bzip2rpm1.0.8-1.azl3, 1.0.8-150400.1.1221.0.8-2, 1.0.8-150400.3.4.119
OSV records
DEBIAN-CVE-2026-42250UBUNTU-CVE-2026-42250AZL-88809ECHO-dfc7-0c27-52d8SUSE-SU-2026:4055-1
Also known as
USN-8685-1

Charts affected

2,412 by stars
ChartLatestAffected imagesRadar Score
prefect-serverprefectVerified publisher2026.9.141419102 of 2See more

prefect-server prefect 2026.9.14141910

2 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
bzip2@1.0.8-5+b1
no fix listed
prefecthq/prefect:3.8.6-python3.11f518ebb9c353
bzip2@1.0.8-6
no fix listed

Open the chart page →

5,448
rocketmqrocketmq12.6.01 of 2See more

rocketmq rocketmq 12.6.0

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
apache/rocketmq:5.4.0319cd8a81ed1
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

6,385
snipeitt3n3.4.11 of 2See more

snipeit t3n 3.4.1

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
snipe/snipe-it:v6.0.1455fb7636a98c
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1

Open the chart page →

18,570
codefreshcodefresh-onpremOfficialVerified publisher2.12.134 of 42See more

codefresh codefresh-onprem 2.12.13

4 of the 42 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
bitnamilegacy/consul:1.21.4-debian-12-r133ae872fc99d
bzip2@1.0.8-5+b1
no fix listed
bitnamilegacy/mongodb:7.0.14-debian-12-r321e8f8baa432
bzip2@1.0.8-5+b1
no fix listed
bitnamilegacy/rabbitmq:4.1.39e635efba431
bzip2@1.0.8-5+b1
no fix listed
quay.io/codefresh/redis:7.4.3-debian-12-r0935f97598255
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

14,615
contourcontour0.8.01 of 2See more

contour contour 0.8.0

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
envoyproxy/envoy:v1.38.4447f857a0146
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

1,521
apim3graviteeioVerified publisher4.12.192 of 4See more

apim3 graviteeio 4.12.19

2 of the 4 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
bzip2@1.0.8-6
no fix listed
graviteeio/apim-management-api:4.12.19-debian27374522cd04
bzip2@1.0.8-6
no fix listed

Open the chart page →

4,747
redisgroundhog2k2.4.71 of 1See more

redis groundhog2k 2.4.7

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/redis:8.10.1298e5b3bc566
bzip2@1.0.8-6
no fix listed

Open the chart page →

968
wordpressgroundhog2k0.16.41 of 1See more

wordpress groundhog2k 0.16.4

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/wordpress:7.1.0-apache5a93c470ae82
bzip2@1.0.8-6
no fix listed

Open the chart page →

3,716
memcachedkubelauncherVerified publisher0.1.321 of 1See more

memcached kubelauncher 0.1.32

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/memcacheddigest-pinnedb599ca6b3ff3
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

634
mysqlkubelauncherVerified publisher0.4.41 of 1See more

mysql kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mysqldigest-pinnede9609bd50416
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

977
postgresqlkubelauncherVerified publisher0.4.31 of 1See more

postgresql kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/postgresqldigest-pinned1a27e11e5925
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

1,154
velero-uiotwldVerified publisher0.15.01 of 1See more

velero-ui otwld 0.15.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
otwld/velero-ui:0.10.2d1954b759e47
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

1,344
stackstorm-hastackstormVerified publisher1.1.012 of 17See more

stackstorm-ha stackstorm 1.1.0

12 of the 17 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
stackstorm/st2actionrunner:3.888235ba70cad
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
stackstorm/st2api:3.86f56d239d280
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
stackstorm/st2auth:3.833ecfda16608
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
stackstorm/st2garbagecollector:3.84e3f8c7ca52d
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
stackstorm/st2notifier:3.8f190a6212195
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
stackstorm/st2rulesengine:3.8259503496ff9
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
stackstorm/st2scheduler:3.8b1de2055c362
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
stackstorm/st2sensorcontainer:3.8b1a338f64773
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
stackstorm/st2stream:3.81c8904a3bf67
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
stackstorm/st2timersengine:3.81bf35bfaf00c
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
stackstorm/st2web:3.809989a26c8b7
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
stackstorm/st2workflowengine:3.819fdfffdbba8
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1

Open the chart page →

96,984
supabasetokens-studioVerified publisher1.0.06 of 14See more

supabase tokens-studio 1.0.0

6 of the 14 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
darthsim/imgproxy:v3.26476cb08c816a
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
library/kong:3.8.0712e407b20ea
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
supabase/edge-runtime:v1.59.0eff9c554d649
bzip2@1.0.8-5+b1
no fix listed
supabase/postgres-meta:v0.84.2d0a96973e9f1
bzip2@1.0.8-5+b1
no fix listed
supabase/realtime:v2.33.8d207e6e23ad3
bzip2@1.0.8-5+b1
no fix listed
supabase/studio:20241021-9f9b08326d8070c55e9
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

23,263
wekanwekanVerified publisher11.79.02 of 3See more

wekan wekan 11.79.0

2 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/wekan/ferretdb:latest6cb94aa01999
bzip2@1.0.8-6
no fix listed
ghcr.io/wekan/wekan:v11.79039ef2b811cf
bzip2@1.0.8-6
no fix listed

Open the chart page →

1,570
renterdartur9010Verified publisher1.4.42 of 2See more

renterd artur9010 1.4.4

2 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
artur9010/wait-for:v1.0.06b4de3ce8b0e
bzip2@1.0.8-5+b1
no fix listed
ghcr.io/siafoundation/renterd:2.9.0e0334f124863
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

8,530
cloudbeaveravistoVerified publisher1.1.71 of 1See more

cloudbeaver avisto 1.1.7

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
dbeaver/cloudbeaver:26.1.287ab86d00f8c
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

1,749
budibasebudibase0.0.0-master3 of 7See more

budibase budibase 0.0.0-master

3 of the 7 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
budibase/database:2.1.0d90f656261c9
bzip2@1.0.8-5+b1
no fix listed
budibase/proxy:3.41.38d780b6ee602
bzip2@1.0.8-6
no fix listed
library/redis:latest298e5b3bc566
bzip2@1.0.8-6
no fix listed

Open the chart page →

10,810
csi-secrets-store-provider-azurecsi-secrets-store-provider-azureVerified publisher1.8.23 of 5See more

csi-secrets-store-provider-azure csi-secrets-store-provider-azure 1.8.2

3 of the 5 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
mcr.microsoft.com/oss/v2/kubernetes-csi/livenessprobe:v2.15.059b9d0348428
bzip2@1.0.8-1.azl3
1.0.8-2
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver:v1.5.65f91243cfd60
bzip2@1.0.8-1.azl3
1.0.8-2
mcr.microsoft.com/oss/v2/kubernetes-csi/secrets-store/driver-crds:v1.5.6cb0112636dc4
bzip2@1.0.8-1.azl3
1.0.8-2

Open the chart page →

2,235
bitcoindfold0.3.21 of 2See more

bitcoind fold 0.3.2

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
thesisrobot/bitcoind:v23.016b368e4d52c
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

3,493
cubestoregadsme1.2.01 of 3See more

cubestore gadsme 1.2.0

1 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
cubejs/cubestore:v1.5.334ac523a9bab
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

3,037
hivemq-operatorhivemqOfficialVerified publisher0.11.621 of 2See more

hivemq-operator hivemq 0.11.62

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
hivemq/hivemq-operator:4.7.10241d6a8e1963
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

7,896
cassandrakubelauncherVerified publisher0.1.271 of 1See more

cassandra kubelauncher 0.1.27

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/cassandradigest-pinnedb66aba320083
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

1,490
etcdkubelauncherVerified publisher0.4.31 of 1See more

etcd kubelauncher 0.4.3

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/etcddigest-pinned8ab954711fb9
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

806
kafkakubelauncherVerified publisher0.1.261 of 1See more

kafka kubelauncher 0.1.26

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kafkadigest-pinned43e1085cd0a8
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

1,399
keycloakkubelauncherVerified publisher0.4.41 of 1See more

keycloak kubelauncher 0.4.4

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/keycloakdigest-pinnedafe3bd73d7cf
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

1,291
kubectlkubelauncherVerified publisher0.2.111 of 1See more

kubectl kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/kubectldigest-pinned7280594a2f18
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

1,255
mariadbkubelauncherVerified publisher0.5.71 of 1See more

mariadb kubelauncher 0.5.7

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mariadbdigest-pinnede25056a6ec52
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

1,101
mongodbkubelauncherVerified publisher0.4.51 of 1See more

mongodb kubelauncher 0.4.5

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/mongodbdigest-pinned9bc37ed78a8b
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

1,380
openldapkubelauncherVerified publisher0.2.01 of 1See more

openldap kubelauncher 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/openldapdigest-pinned8978aa002bc0
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

1,279
rabbitmqkubelauncherVerified publisher0.2.111 of 1See more

rabbitmq kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/rabbitmqdigest-pinnedff5a36a457f1
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

1,118
rediskubelauncherVerified publisher0.5.11 of 1See more

redis kubelauncher 0.5.1

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/redisdigest-pinnedbcd8e9a6224f
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

809
zookeeperkubelauncherVerified publisher0.2.111 of 1See more

zookeeper kubelauncher 0.2.11

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/kubelauncher/zookeeperdigest-pinned7826e9caa461
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

1,027
minecraft-proxyminecraft-server-chartsVerified publisher3.10.01 of 1See more

minecraft-proxy minecraft-server-charts 3.10.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
itzg/bungeecord:latest1c59f9631f3b
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

3,128
quickwitquickwit0.8.161 of 1See more

quickwit quickwit 0.8.16

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
quickwit/quickwit:v0.8.2363ff56ce456
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

3,492
transmission-openvpnutkuozdemirVerified publisher2.5.01 of 1See more

transmission-openvpn utkuozdemir 2.5.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
haugene/transmission-openvpn:4.0059216cfae4b
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1

Open the chart page →

11,453
zillazillaOfficialVerified publisher2.4.21 of 1See more

zilla zilla 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/aklivity/zilla:2.4.289c4a2e74863
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

1,737
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/postgres:18.48ff36f3c6637
bzip2@1.0.8-6
no fix listed

Open the chart page →

2,951
jellyfinbeluga-cloudVerified publisher2.3.01 of 1See more

jellyfin beluga-cloud 2.3.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/jellyfin/jellyfin:10.8.1368f52b993a7f
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

4,281
connaisseurconnaisseurVerified publisher2.12.01 of 2See more

connaisseur connaisseur 2.12.0

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/redisdigest-pinned83edc2b8e9ff
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

3,024
dependabot-gitlabdependabot-gitlabVerified publisher6.3.01 of 3See more

dependabot-gitlab dependabot-gitlab 6.3.0

1 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
andrcuns/dependabot-gitlab:7.7.0-alpha.143060f159f4c
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

4,604
devtron-operatordevtron0.23.35 of 11See more

devtron-operator devtron 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
bzip2@1.0.8-5+b1
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
quay.io/devtron/postgres:14.91b594392f7cb
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

31,447
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

3,645
hdfsgaffer2.2.11 of 2See more

hdfs gaffer 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
gchq/hdfs:3.3.35ec58edbb2db
bzip2@1.0.8-5.1
1.0.8-5.1ubuntu0.1

Open the chart page →

5,396
nextcloudgroundhog2k0.22.51 of 3See more

nextcloud groundhog2k 0.22.5

1 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
bzip2@1.0.8-6
no fix listed

Open the chart page →

4,538
ilumilumOfficialVerified publisher6.7.34 of 19See more

ilum ilum 6.7.3

4 of the 19 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
bitnamilegacy/minio:2025.3.12-debian-12-r0ba9f3b4b0b00
bzip2@1.0.8-5+b1
no fix listed
bitnamilegacy/postgresql:16233f361c5819
bzip2@1.0.8-5+b1
no fix listed
ilum/api:6.7.3624fd09528c8
bzip2@1.0.8-6
no fix listed
ilum/marquez:0.54.06e1d709d41f8
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

23,289
kafkakafka18.0.11 of 1See more

kafka kafka 18.0.1

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

3,434
lakekeeperlakekeeperVerified publisher0.12.01 of 2See more

lakekeeper lakekeeper 0.12.0

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/postgres:18.4a02db8cac496
bzip2@1.0.8-6
no fix listed

Open the chart page →

1,935
litmuslitmuschaos3.30.02 of 6See more

litmus litmuschaos 3.30.0

2 of the 6 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:8.0.13-debian-12-r02579e968033e
bzip2@1.0.8-5+b1
no fix listed
bitnamilegacy/os-shell:12-debian-12-r5177e65e9d633e
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

7,031
monicamonicaOfficialVerified publisher1.0.151 of 1See more

monica monica 1.0.15

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/monicahq/monica-next:main8be69156acbb
bzip2@1.0.8-6
no fix listed

Open the chart page →

5,665

Container images carrying it

2,399 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
omecproject/lte-softmodem:1.1.0b5ddd36ec20c
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
1
omecproject/lte-uesoftmodem:1.1.0686f8bc37d8c
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
1
omecproject/mme-exporter:paging-latestbcc5f19fd676
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
1
omecproject/ngic-cp:central-cp-multi-upfs-latest24a389a0a4fe
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
1
omecproject/onos-progran:1.0.05715e5648aa0
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
1
omecproject/openmme:master-latest64776cb9edb3
bzip2@1.0.6-8ubuntu0.2
1.0.6-8ubuntu0.2+esm1
1
omecproject/progran-synchronizer:comac-1.0.0d109a8e57e71
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
1
omkara25/simple-microservice-app-order-service:v2.18327546c7aac
bzip2@1.0.8-5+b1
no fix listed
1
omkara25/simple-microservice-app-payment-service:v2afff40172b6b
bzip2@1.0.8-5+b1
no fix listed
1
omkara25/simple-microservice-app-user-service:v2d62cba548580
bzip2@1.0.8-5+b1
no fix listed
1
ondrejsika/counter:latestd95eaeee2172
bzip2@1.0.8-6
no fix listed
1
oneuptime/probe:release6b2d98713711
bzip2@1.0.8-5+b1
no fix listed
1
oneuptime/runner:release4accc516d800
bzip2@1.0.8-6
no fix listed
1
onosproject/onos:2.2.144914a8d4b3f
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1
1
onyxdotapp/onyx-backend:latest473fdffe4e67
bzip2@1.0.8-6
no fix listed
1
oomk8s/ubuntu-init:1.0.03adf3d21ad3b
bzip2@1.0.6-8
1.0.6-8ubuntu0.2+esm1
1
opea/asr:1.025dd26d9cd09
bzip2@1.0.8-5+b1
no fix listed
1
opea/chatqna:1.038c51b791efa
bzip2@1.0.8-5+b1
no fix listed
1
opea/codegen:1.058f91683892d
bzip2@1.0.8-5+b1
no fix listed
1
opea/codegen-ui:1.02bee4eb66f3e
bzip2@1.0.8-5+b1
no fix listed
1
opea/codetrans:1.0e2436483b73d
bzip2@1.0.8-5+b1
no fix listed
1
opea/codetrans-ui:1.03ef121f34610
bzip2@1.0.8-5+b1
no fix listed
1
opea/docsum:1.03eaa91849512
bzip2@1.0.8-5+b1
no fix listed
1
opea/docsum-ui:1.07f854e9bffaf
bzip2@1.0.8-5+b1
no fix listed
1
opea/guardrails-tgi:1.0262c6048aab8
bzip2@1.0.8-5+b1
no fix listed
1
opea/guardrails-tgi:latestf68bec6a1271
bzip2@1.0.8-5+b1
no fix listed
1
opea/llm-docsum-tgi:1.002f9e8fa5d71
bzip2@1.0.8-5+b1
no fix listed
1
opea/speecht5:1.0249afad3d268
bzip2@1.0.8-5+b1
no fix listed
1
opea/tts:1.0257ae94709e9
bzip2@1.0.8-5+b1
no fix listed
1
opea/web-retriever-chroma:1.0fe08165d7770
bzip2@1.0.8-5+b1
no fix listed
1
openaev/platform:3.260904.00a12ce8b3db9
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
openbas/caldera-server:5.1.0a277796d9724
bzip2@1.0.8-5+b1
no fix listed
1
openbas/platform:2.0.5d986d80b0a75
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
opencsghq/agenticflow:ee-v0.6-52f03fead54db
bzip2@1.0.8-5+b1
no fix listed
1
opencsghq/csgbot:v0.6.7-eeaf7191a9cf8a
bzip2@1.0.8-6
no fix listed
1
opencsghq/csghub-portal:v2.4.0-ee93ad59164d87
bzip2@1.0.8-5+b1
no fix listed
1
opencsghq/csghub-server:v2.4.0-ee302c9d45d8a8
bzip2@1.0.8-5+b1
no fix listed
1
opencsghq/csghub-xnet:v2.4.0-ee04121fd19ef9
bzip2@1.0.8-5+b1
no fix listed
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
bzip2@1.0.8-5+b1
no fix listed
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
bzip2@1.0.8-5+b1
no fix listed
1
opencsghq/kubectl:latestb6d87e1048c2
bzip2@1.0.8-5+b1
no fix listed
1
opencsghq/label-studio:v2.5.047e22aa71870
bzip2@1.0.8-6
no fix listed
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
bzip2@1.0.8-6
no fix listed
1
opencsghq/postgres:15.1842578c9d3ebd
bzip2@1.0.8-6
no fix listed
1
opendatacube/explorer:latest120457ffcd69
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
1
opendatacube/pipelines:wofs-1.225d810e8504b8
bzip2@1.0.6-8.1
1.0.6-8.1ubuntu0.2+esm1
1
opendatacube/restcube:latest91870111837c
bzip2@1.0.6-8.1
1.0.6-8.1ubuntu0.2+esm1
1
opendatacube/wms:latest1b90cdf68831
bzip2@1.0.6-8.1
1.0.6-8.1ubuntu0.2+esm1
1
opendatacube/wps:latest80df355a660b
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1
1
openebs/rawfile-localpv:v0.15.2a39ef27ea28b
bzip2@1.0.8-6
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.