StackRadar

CVE-2026-42306

High

Advisory

Published 18 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
573
of 17,787 indexed, latest versions
Container images
567
deployed by those charts
Fix available
1 of 3
affected packages

Docker: Race condition in docker cp allows bind mount redirection to host path

Carried by container images the latest versions of 573 of 17,787 indexed charts deploy, on 567 images.

Affected packageAffected versionsFixed inImages
github.com/docker/dockergolangv0.0.0-20180620051407-e2593239d949, v0.7.3-0.20190327010347-be7ac8be2ae0, v1.4.2-0.20190924003213-a8608b5b67c7, v1.4.2-0.20191121165722-d1d5f6476656+84 moreno fix listed542
github.com/moby/mobygolangv0.7.3-0.20190826074503-38ab9da00309, v1.4.2-0.20170731201646-1009e6a40b29, v1.13.1, v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible+4 moreno fix listed30
docker.iodeb20.10.24+dfsg1-1+deb12u1+b6, 26.1.5+dfsg1-9+b1326.1.5+dfsg1-9+deb13u12
OSV records
DEBIAN-CVE-2026-42306GHSA-rg2x-37c3-w2rh
Also known as
GO-2026-5617

Charts affected

573 by stars
ChartLatestAffected imagesRadar Score
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/docker/docker@v26.1.2+incompatible
no fix listed

Open the chart page →

2,477
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
github.com/docker/docker@v20.10.24+incompatible
no fix listed
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/docker/docker@v20.10.24+incompatible
no fix listed

Open the chart page →

4,815
traceetrivy-operator0.24.11 of 1See more

tracee trivy-operator 0.24.1

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
aquasec/tracee:0.24.1cfbbfee972e6
github.com/docker/docker@v28.1.1+incompatible
no fix listed

Open the chart page →

1,074
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,510
tfy-lokitruefoundryVerified publisher0.1.61 of 2See more

tfy-loki truefoundry 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
grafana/promtail:2.9.1063a2e57a5b14
github.com/docker/docker@v23.0.8+incompatible
no fix listed

Open the chart page →

2,813
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
grafana/grafana:12.3.070d9599b186c
github.com/moby/moby@v27.5.1+incompatible
no fix listed

Open the chart page →

4,526
devportalveecode-platform-nextVerified publisher0.1.221See more

devportal veecode-platform-next 0.1.22

1 container image this version deploys carries CVE-2026-42306.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
github.com/docker/docker@v28.5.1+incompatible
no fix listed

Open the chart page →

verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,429
vulcanvulcan0.2.21 of 2See more

vulcan vulcan 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
mitre/vulcan:latest2bc4dfb8150f
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

1,516
aih-scannerwallarmVerified publisher2.7.111 of 2See more

aih-scanner wallarm 2.7.11

1 of the 2 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.7.11f1cb26db1f5b
github.com/docker/docker@v28.3.3+incompatible
no fix listed

Open the chart page →

3,911
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
wallarm/node-native-processing:0.23.07db2da8fce0b
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

2,824
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
github.com/docker/docker@v23.0.0-rc.2+incompatible
no fix listed

Open the chart page →

6,232
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,552
gitlab-runnerwenerme0.92.11 of 1See more

gitlab-runner wenerme 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

904
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/docker/docker@v25.0.15-0.20260325154711-d2dbc0547253+incompatible
no fix listed

Open the chart page →

1,456
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/docker/docker@v24.0.5+incompatible
no fix listed

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/docker/docker@v24.0.2+incompatible
no fix listed

Open the chart page →

2,022
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
github.com/docker/docker@v1.13.1
no fix listed

Open the chart page →

2,745
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
github.com/docker/docker@v20.10.21+incompatible
no fix listed

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
github.com/docker/docker@v27.4.1+incompatible
no fix listed

Open the chart page →

9,381

Container images carrying it

567 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/kyverno/kyverno:v1.7.19c73f1841ebc
github.com/docker/docker@v20.10.12+incompatible
no fix listed
1
ghcr.io/kyverno/kyverno:v1.12.5a61c7022abcf
github.com/docker/docker@v25.0.5+incompatible
no fix listed
1
ghcr.io/kyverno/kyverno-cli:v1.12.5832a32779e6d
github.com/docker/docker@v25.0.5+incompatible
no fix listed
1
ghcr.io/kyverno/kyvernopre:v1.7.1185d2eebc60c
github.com/docker/docker@v20.10.12+incompatible
no fix listed
1
ghcr.io/kyverno/kyvernopre:v1.12.563f7eaf5aa8a
github.com/docker/docker@v25.0.5+incompatible
no fix listed
1
ghcr.io/kyverno/reports-controller:v1.12.5c62e3347611c
github.com/docker/docker@v25.0.5+incompatible
no fix listed
1
ghcr.io/lockdep/stackradar-scanner:0.3.0dd8a35d50c2d
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
ghcr.io/loft-sh/agent:3.2.45c109914ff73
github.com/docker/docker@v20.10.21+incompatible
no fix listed
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
github.com/docker/docker@v24.0.7+incompatible
no fix listed
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
github.com/docker/docker@v20.10.21+incompatible
no fix listed
1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
github.com/docker/docker@v23.0.0-rc.1+incompatible
no fix listed
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
github.com/docker/docker@v24.0.7+incompatible
no fix listed
1
ghcr.io/loft-sh/vcluster-platform:4.12.0ef92da4621e6
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
ghcr.io/loft-sh/vnode-runtime:0.3.3b065ec5a5239
github.com/docker/docker@v27.1.1+incompatible
no fix listed
1
ghcr.io/m9sweeper/trawler:1.6.0df917c5a7e54
github.com/docker/docker@v24.0.7+incompatible
no fix listed
1
ghcr.io/manzil-infinity180/deploydefender:ea3ab0bb646cdbeddd1aca483ecf650f9ac0d0847fbc6855c8b3
github.com/docker/docker@v27.1.1+incompatible
no fix listed
1
ghcr.io/middleware-labs/agent-kube-go:dev17369c4cd390
github.com/docker/docker@v20.10.22+incompatible
no fix listed
1
ghcr.io/middleware-labs/mw-kube-agent:master056f0953763d
github.com/docker/docker@v24.0.5+incompatible
no fix listed
1
ghcr.io/middleware-labs/mw-kube-agent:1.12.09c7bc0f9bb35
github.com/docker/docker@v27.3.1+incompatible
no fix listed
1
ghcr.io/mosn/htnn-controller:v0.3.1c379e66246be
github.com/docker/docker@v25.0.5+incompatible
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.2035bc5ca66d55a
github.com/docker/docker@v25.0.6+incompatible
no fix listed
1
ghcr.io/oguzhan-yilmaz/kdiff-snapshots:0.0.55d7f93d2182fe
github.com/docker/docker@v25.0.6+incompatible
no fix listed
1
ghcr.io/oguzhan-yilmaz/steampipe-powerpipe-kubernetes--steampipe:latestc0c8d53df9f3
github.com/docker/docker@v25.0.6+incompatible
no fix listed
1
ghcr.io/openclarity/grype-server:v0.6.079412399f301
github.com/docker/docker@v24.0.5+incompatible
no fix listed
1
ghcr.io/openclarity/kubeclarity:v2.23.314450f52a708
github.com/docker/docker@v24.0.7+incompatible
no fix listed
1
ghcr.io/openconfig/gnmic:0.45.0d422a9ebd4a2
github.com/docker/docker@v28.5.1+incompatible
no fix listed
1
ghcr.io/openfaasltd/pro-builder:0.6.06c17297f9098
github.com/docker/docker@v25.0.6+incompatible
no fix listed
1
ghcr.io/openlit/openlit:1.24.02434560e8f0e
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
ghcr.io/openrelik/openrelik-worker-containers:latesta6d5abe94706
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.148.0590e50477b76
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.132.05e331c925091
github.com/docker/docker@v28.0.0+incompatible
no fix listed
1
ghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:0.144.079b81912f1fb
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
ghcr.io/parca-dev/parca:v0.24.23776500fde82
github.com/docker/docker@v28.2.2+incompatible
no fix listed
1
ghcr.io/parca-dev/parca-agent:v0.28.06d6794f45f3e
github.com/docker/docker@v24.0.7+incompatible
no fix listed
1
ghcr.io/parca-dev/parca-agent:v0.42.0adc0eeb4dd05
github.com/docker/docker@v28.0.4+incompatible
no fix listed
1
ghcr.io/qjoly/spindle:v1.16.1-alphaaab0c99d313f
github.com/docker/docker@v28.2.2+incompatible
no fix listed
1
ghcr.io/samr037/node-debug-dashboard:0.3.0c79b2e64a211
github.com/docker/docker@v27.3.1+incompatible
no fix listed
1
ghcr.io/spiffe/spire-agent:1.6.062517726d0c4
github.com/docker/docker@v23.0.1+incompatible
no fix listed
1
ghcr.io/stashed/stash:v0.42.03a98245a7667
github.com/docker/docker@v28.0.0+incompatible
no fix listed
1
ghcr.io/substra/fabric-peer:0.2.4f681e0343a31
github.com/docker/docker@v20.10.0-beta1.0.20201113105859-b6bfff2a628f+incompatible
no fix listed
1
ghcr.io/substra/fabric-tools:0.2.43491a0f31c4a
github.com/docker/docker@v20.10.0-beta1.0.20201113105859-b6bfff2a628f+incompatible
no fix listed
1
ghcr.io/synapsecns/sanguine/explorer:latest00131e3d1eaf
github.com/docker/docker@v26.1.3+incompatible
no fix listed
1
ghcr.io/tjm/vault-gcp-secrets:v1.19.59f157fe035f1
github.com/docker/docker@v27.2.1+incompatible
no fix listed
1
ghcr.io/traefik/traefik-hub:v2.11.0322f5f8cc105
github.com/docker/docker@v20.10.21+incompatible
no fix listed
1
ghcr.io/turbot/guardrails-agent-kubernetes:0.3.09d01bf9c9224
github.com/docker/docker@v25.0.6+incompatible
no fix listed
1
ghcr.io/voyagermesh/gateway:v1.6.223f4da194134
github.com/docker/docker@v28.3.3+incompatible
no fix listed
1
ghcr.io/warpstreamlabs/bento:1.8.121715979aefa
github.com/docker/docker@v27.1.1+incompatible
no fix listed
1
ghcr.io/wundergraph/cosmo/controlplane:0.133.149800ff775f3
github.com/docker/docker@v26.1.3+incompatible
no fix listed
1
public.ecr.aws/aktosecurity/keelhq-keel:akto_v1.0.01eb61443d68e
github.com/docker/docker@v27.3.1+incompatible
no fix listed
1
public.ecr.aws/aws-observability/aws-otel-collector:v0.43.38aa9ea5f67b8
github.com/docker/docker@v27.4.1+incompatible
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.