StackRadar

CVE-2026-42250

Medium

Advisory

Published 28 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.8
base score, highest
EPSS
0.001
3rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
2,442
of 17,828 indexed, latest versions
Container images
2,461
deployed by those charts
Fix available
2 of 2
affected packages

CVE-2026-42250 affecting package bzip2 for versions less than 1.0.8-2

Carried by container images the latest versions of 2,442 of 17,828 indexed charts deploy, on 2,461 images.

Affected packageAffected versionsFixed inImages
bzip2deb1.0.6-5, 1.0.6-8, 1.0.6-8.1, 1.0.6-8.1ubuntu0.2+11 more1.0.6-5ubuntu0.1~esm3, 1.0.6-8.1ubuntu0.2+esm1, 1.0.6-8ubuntu0.2+esm1, 1.0.8-2ubuntu0.1~esm1+4 more2,448
bzip2rpm1.0.8-1.azl3, 1.0.8-150400.1.1221.0.8-2, 1.0.8-150400.3.4.113
OSV records
DEBIAN-CVE-2026-42250UBUNTU-CVE-2026-42250AZL-88809ECHO-dfc7-0c27-52d8SUSE-SU-2026:4055-1
Also known as
USN-8685-1

Charts affected

2,442 by stars
ChartLatestAffected imagesRadar Score
calertromholdings0.0.11 of 1See more

calert romholdings 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
quay.io/devtron/google-chat-alert-manager:v2.0.239f2c6e0af38
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1

Open the chart page →

4,733
devtron-enterpriseromholdings48.0.08 of 28See more

devtron-enterprise romholdings 48.0.0

8 of the 28 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
quay.io/devtron/casbin:172ef62b-9450794d-464-394225bf041aacadd
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
quay.io/devtron/chart-sync:94237c18-1021-3941960566529446a
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
quay.io/devtron/devtron:9450794d-930-394159795f3f9f031
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
bzip2@1.0.8-5+b1
no fix listed
quay.io/devtron/inception:7beef376-948-313784c3b91bebd3d
bzip2@1.0.6-8ubuntu0.2
1.0.6-8ubuntu0.2+esm1
quay.io/devtron/kubelink:94237c18-314-394179d25865295af
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
bzip2@1.0.8-5+b1
no fix listed
quay.io/devtron/postgres:14.91b594392f7cb
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

69,736
devtron-logs-dumpromholdings0.1.01 of 1See more

devtron-logs-dump romholdings 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
quay.io/devtron/k8s-utils:807ca3c2-488-14005f296c2ec5db7
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

5,015
devtron-operatorromholdings0.23.35 of 11See more

devtron-operator romholdings 0.23.3

5 of the 11 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
quay.io/devtron/chart-sync:3b3d6d0e-836-39296721b5c9634d4
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
quay.io/devtron/devtron-utils:dup-chart-repo-v1.1.095d6f0e05636
bzip2@1.0.8-5+b1
no fix listed
quay.io/devtron/hyperion:0874dcaf-280-3928701d5d8c4cecb
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
quay.io/devtron/kubelink:09867a9c-564-39289ea6dd1e4ce71
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1
quay.io/devtron/postgres:14.91b594392f7cb
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

33,471
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1

Open the chart page →

12,033
migration-incluster-cdromholdings0.10.01 of 1See more

migration-incluster-cd romholdings 0.10.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/postgres:122f2a8c2a7d10
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

3,959
rommromm-helm-chartVerified publisher1.5.51 of 3See more

romm romm-helm-chart 1.5.5

1 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/mariadb:112439dcd7d140
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

3,505
pagesronan-pages1.0.02 of 3See more

pages ronan-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
flyway/flyway:6.4.422d97ceb0c47
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

20,350
endeavorrotationalVerified publisher1.3.12 of 2See more

endeavor rotational 1.3.1

2 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
rotationalio/endeavor:1.3.0ac566baddc06
bzip2@1.0.8-5+b1
no fix listed
rotationalio/quarterdeck:0.16.00e7ad3a031dc
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

2,298
genoarotationalVerified publisher1.4.01 of 1See more

genoa rotational 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
rotationalio/genoa:1.2.03ab583519215
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

1,019
honurotationalVerified publisher0.5.31 of 1See more

honu rotational 0.5.3

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
rotationalio/honu:0.5.069fd30c2e31c
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

2,204
imgtagrotationalVerified publisher0.2.01 of 1See more

imgtag rotational 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
gcr.io/rotationalio-habanero/imgtag:89ec287a534a3170d03
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

3,370
quarterdeckrotationalVerified publisher0.16.01 of 1See more

quarterdeck rotational 0.16.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
rotationalio/quarterdeck:0.16.00e7ad3a031dc
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

1,190
routehub-serverroutehub-helm1.0.12 of 3See more

routehub-server routehub-helm 1.0.1

2 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
eqalpha/keydb:latest6537505c4235
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
library/postgres:latest4ef4dbc939d6
bzip2@1.0.8-6
no fix listed

Open the chart page →

7,040
agentdatarss30.1.01 of 1See more

agentdata rss3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

3,588
noderss30.7.21 of 3See more

node rss3 0.7.2

1 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/rss3-network/agentdata:0.1.0fd8d3e6e4cdf
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

4,795
prepull-daemonsetrstudioVerified publisher0.0.51 of 2See more

prepull-daemonset rstudio 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/ubuntu:bionic152dc042452c
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

1,763
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

7,885
paperless-ngxrtomik-helm-chartsVerified publisher0.0.51 of 1See more

paperless-ngx rtomik-helm-charts 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
bzip2@1.0.8-6
no fix listed

Open the chart page →

10,846
flaresolverrrubxkubeVerified publisher0.1.11 of 1See more

flaresolverr rubxkube 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
flaresolverr/flaresolverr:v3.5.0139dfee1c6f8
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

27,797
jellyfinrubxkubeVerified publisher1.3.11 of 1See more

jellyfin rubxkube 1.3.1

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
jellyfin/jellyfin:10.11.11aefb67e6a7ff
bzip2@1.0.8-6
no fix listed

Open the chart page →

2,681
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.2.0-debian-12-r2e6fa49bb0347
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

7,516
komgarubxkubeVerified publisher0.1.31 of 1See more

komga rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
gotson/komga:1.26.36c2a967bbe9a
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1

Open the chart page →

35,004
linkdingrubxkubeVerified publisher1.2.41 of 1See more

linkding rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
sissbruecker/linkding:1.47.0e35cb50e0581
bzip2@1.0.8-6
no fix listed

Open the chart page →

2,098
simple-coffeerubxkubeVerified publisher0.1.01 of 1See more

simple-coffee rubxkube 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
qjoly/kubernetes-coffee-image:simpleec94d3bdc035
bzip2@1.0.8-6
no fix listed

Open the chart page →

2,606
stirling-pdfrubxkubeVerified publisher0.1.21 of 1See more

stirling-pdf rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

6,428
suwayomirubxkubeVerified publisher0.1.21 of 1See more

suwayomi rubxkube 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/suwayomi/suwayomi-server:v2.3.2320d2c3218c7f9f
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

1,726
trmnl-serverrubxkubeVerified publisher0.1.01 of 2See more

trmnl-server rubxkube 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/python:3.14-slimcad9a2c87176
bzip2@1.0.8-6
no fix listed

Open the chart page →

2,954
uptime-kumarubxkubeVerified publisher1.2.11 of 1See more

uptime-kuma rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
louislam/uptime-kuma:2.4.091e963bfda56
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

30,911
vaultwardenrubxkubeVerified publisher1.2.41 of 1See more

vaultwarden rubxkube 1.2.4

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
vaultwarden/server:1.37.2094b5689ed81
bzip2@1.0.8-6
no fix listed

Open the chart page →

1,789
your-spotifyrubxkubeVerified publisher1.0.11 of 3See more

your-spotify rubxkube 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
bitnamilegacy/mongodb:latestb0652af9c8d0
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

5,467
runwhen-localrunwhen-contribVerified publisher0.6.171 of 3See more

runwhen-local runwhen-contrib 0.6.17

1 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.0533ce58c6e02
bzip2@1.0.8-6
no fix listed

Open the chart page →

3,841
rybbitrybbit-helm1.3.21 of 7See more

rybbit rybbit-helm 1.3.2

1 of the 7 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
valkey/valkey:9.1.164e361b630ec
bzip2@1.0.8-6
no fix listed

Open the chart page →

6,224
nadekobotryuunosukeds30.1.22 of 2See more

nadekobot ryuunosukeds3 0.1.2

2 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/ubuntu:latest2260313b31c8
bzip2@1.0.8-6build2
1.0.8-6ubuntu0.1
ryuunosukeds3/nadeko-bot-docker:latestc0398f13e8a9
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

8,891
orbitalryuunosukeds30.2.01 of 1See more

orbital ryuunosukeds3 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ryuunosukeds3/orbital:latest0879f7261b10
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

2,704
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
bzip2@1.0.8-6
no fix listed

Open the chart page →

9,883
vrisingryuunosukeds30.1.01 of 1See more

vrising ryuunosukeds3 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
trueosiris/vrising:latest9356f98ad561
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

7,516
test-helm-app1saam-helm-test0.1.01 of 1See more

test-helm-app1 saam-helm-test 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
hamidyousefi93/saam-test:latestc34f071f6ed0
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

3,966
hivechart-1sabryp3-charts0.2.01 of 2See more

hivechart-1 sabryp3-charts 0.2.0

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
valkey/valkey:latestc123e3715db6
bzip2@1.0.8-6
no fix listed

Open the chart page →

858
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
bzip2@1.0.8-6
no fix listed

Open the chart page →

1,635
safe-stacksafe-global0.1.03 of 9See more

safe-stack safe-global 0.1.0

3 of the 9 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
bzip2@1.0.8-5+b1
no fix listed
safeglobal/safe-config-service:latest09a5e495c219
bzip2@1.0.8-6
no fix listed
safeglobal/safe-transaction-service:latest80db836cc5d5
bzip2@1.0.8-6
no fix listed

Open the chart page →

19,931
safe-transaction-servicesafe-global0.1.02 of 6See more

safe-transaction-service safe-global 0.1.0

2 of the 6 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
bzip2@1.0.8-5+b1
no fix listed
safeglobal/safe-transaction-service:latest80db836cc5d5
bzip2@1.0.8-6
no fix listed

Open the chart page →

16,927
sagawisesagawiseVerified publisher0.1.01 of 3See more

sagawise sagawise 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
venturenox/redis:latest83b471c193ba
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

4,393
fmtok8s-conference-chartsalaboy0.1.41 of 6See more

fmtok8s-conference-chart salaboy 0.1.4

1 of the 6 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

16,343
fmtok8s-frontendsalaboy0.1.31 of 1See more

fmtok8s-frontend salaboy 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
ghcr.io/salaboy/fmtok8s-frontend:v0.1.103fd01b4f56e
bzip2@1.0.8-5build1
1.0.8-5ubuntu0.1

Open the chart page →

8,203
pagessamanvithkaranth1.0.02 of 3See more

pages samanvithkaranth 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
flyway/flyway:6.4.422d97ceb0c47
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

20,350
samplesample0.1.01 of 2See more

sample sample 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/mongo:noble6ede2806c78e
bzip2@1.0.8-5.1build0.1
1.0.8-5.1ubuntu0.1

Open the chart page →

2,404
evsantisbon0.2.02 of 5See more

ev santisbon 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
santisbon/evwatcher:latestc4e994ca4540
bzip2@1.0.8-5+b1
no fix listed
santisbon/evworker:lateste807283f8d69
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

14,523
speedtestsantisbon0.1.02 of 3See more

speedtest santisbon 0.1.0

2 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
library/influxdb:2.7b8d940ca9376
bzip2@1.0.8-5+b1
no fix listed
santisbon/speedtest:latest8ee3a1697227
bzip2@1.0.8-5+b1
no fix listed

Open the chart page →

12,916
pagessarubits-pages1.0.02 of 3See more

pages sarubits-pages 1.0.0

2 of the 3 container images this version deploys carry CVE-2026-42250.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
flyway/flyway:6.4.422d97ceb0c47
bzip2@1.0.6-8.1ubuntu0.2
1.0.6-8.1ubuntu0.2+esm1

Open the chart page →

20,350

Container images carrying it

2,461 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
bzip2@1.0.8-2
1.0.8-2ubuntu0.1~esm1
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
bzip2@1.0.8-5+b1
no fix listed
1
registry.k8s.io/csi-secrets-store/driver:v1.6.1b48d7d13dd06
bzip2@1.0.8-5+b1
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.5.00e64aedb0d0a
bzip2@1.0.8-6
no fix listed
1
registry.k8s.io/git-sync/git-sync:v4.1.0fd9722fd02e3
bzip2@1.0.8-5+b1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v0.8.2052f0618e9bc2
bzip2@1.0.8-5+b1
no fix listed
1
registry.k8s.io/node-problem-detector/node-problem-detector:v1.35.1c380751accc5
bzip2@1.0.8-5+b1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.8.03e2bf2eaef9f
bzip2@1.0.8-5+b1
no fix listed
1
registry.k8s.io/sig-storage/local-volume-provisioner:v2.9.0f9d65db8bda2
bzip2@1.0.8-5+b1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.13.41eb5a85180a4
bzip2@1.0.8-5+b1
no fix listed
1
registry.k8s.io/sig-storage/nfsplugin:v4.11.0ce5b5ccd5eb0
bzip2@1.0.8-5+b1
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.