StackRadar

CVE-2026-42306

High

Advisory

Published 18 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.2
base score, highest
EPSS
0.001
1st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
579
of 17,781 indexed, latest versions
Container images
572
deployed by those charts
Fix available
1 of 3
affected packages

Docker: Race condition in docker cp allows bind mount redirection to host path

Carried by container images the latest versions of 579 of 17,781 indexed charts deploy, on 572 images.

Affected packageAffected versionsFixed inImages
github.com/docker/dockergolangv0.0.0-20180620051407-e2593239d949, v0.7.3-0.20190327010347-be7ac8be2ae0, v1.4.2-0.20190924003213-a8608b5b67c7, v1.4.2-0.20191121165722-d1d5f6476656+84 moreno fix listed547
github.com/moby/mobygolangv0.7.3-0.20190826074503-38ab9da00309, v1.4.2-0.20170731201646-1009e6a40b29, v1.13.1, v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible+4 moreno fix listed30
docker.iodeb20.10.24+dfsg1-1+deb12u1+b6, 26.1.5+dfsg1-9+b1326.1.5+dfsg1-9+deb13u12
OSV records
DEBIAN-CVE-2026-42306GHSA-rg2x-37c3-w2rh
Also known as
GO-2026-5617

Charts affected

579 by stars
ChartLatestAffected imagesRadar Score
telegraf-ds-k3stelegraf-ds-k3s1.0.01 of 1See more

telegraf-ds-k3s telegraf-ds-k3s 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
library/telegraf:1.19.0-alpine794079a7f241
github.com/docker/docker@v20.10.6+incompatible
no fix listed

Open the chart page →

3,764
temporaltemporal0.28.91 of 13See more

temporal temporal 0.28.9

1 of the 13 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v2.31.1a8779cfe553e
github.com/docker/docker@v20.10.9+incompatible
no fix listed

Open the chart page →

21,005
the0the0Verified publisher0.9.81 of 9See more

the0 the0 0.9.8

1 of the 9 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/alexanderwanyoike/the0/runtime:1.14.7459010a02aff
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

7,248
mc-routerthl-chartsVerified publisher0.1.01 of 1See more

mc-router thl-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
itzg/mc-router:1.16.1bb552b59fb53
github.com/docker/docker@v20.10.17+incompatible
no fix listed

Open the chart page →

1,855
monitoringthl-chartsVerified publisher0.1.12 of 10See more

monitoring thl-charts 0.1.1

2 of the 10 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
grafana/promtail:2.4.2626900031c4e
github.com/docker/docker@v20.10.8+incompatible
no fix listed
quay.io/prometheus/prometheus:v2.34.0b37103e03399
github.com/docker/docker@v20.10.12+incompatible
no fix listed

Open the chart page →

18,908
harbor-scanner-trivytrivy-operator0.31.21 of 1See more

harbor-scanner-trivy trivy-operator 0.31.2

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/docker/docker@v26.1.2+incompatible
no fix listed

Open the chart page →

2,477
posteetrivy-operator2.14.02 of 3See more

postee trivy-operator 2.14.0

2 of the 3 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
aquasec/postee:2.12.0-amd640795cba777e7
github.com/docker/docker@v20.10.24+incompatible
no fix listed
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/docker/docker@v20.10.24+incompatible
no fix listed

Open the chart page →

4,815
traceetrivy-operator0.24.11 of 1See more

tracee trivy-operator 0.24.1

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
aquasec/tracee:0.24.1cfbbfee972e6
github.com/docker/docker@v28.1.1+incompatible
no fix listed

Open the chart page →

1,074
trouw-servicetrouw-service1.0.01 of 3See more

trouw-service trouw-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/trouw-service-php:latestf745e2870692
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,510
tfy-lokitruefoundryVerified publisher0.1.61 of 2See more

tfy-loki truefoundry 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
grafana/promtail:2.9.1063a2e57a5b14
github.com/docker/docker@v23.0.8+incompatible
no fix listed

Open the chart page →

2,813
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
grafana/grafana:12.3.070d9599b186c
github.com/moby/moby@v27.5.1+incompatible
no fix listed

Open the chart page →

4,526
devportalveecode-platform-nextVerified publisher0.1.211 of 1See more

devportal veecode-platform-next 0.1.21

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnedc443520aebf7
github.com/docker/docker@v28.5.1+incompatible
no fix listed

Open the chart page →

1,787
verhuis-serviceverhuis-service1.0.01 of 3See more

verhuis-service verhuis-service 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verhuis-service-php:latest66bbaf95a123
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,510
verzoekconversieserviceverzoekconversieservice1.0.01 of 3See more

verzoekconversieservice verzoekconversieservice 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekconversieservice-php:lateste918014fb8d3
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,528
verzoekregistratiecomponentverzoekregistratiecomponent1.1.01 of 4See more

verzoekregistratiecomponent verzoekregistratiecomponent 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoekregistratiecomponent-php:latestc4f6c03af5d3
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,429
verzoektypecatalogusverzoektypecatalogus1.1.01 of 4See more

verzoektypecatalogus verzoektypecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/verzoektypecatalogus-php:latest64f5eb7a398b
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,429
vulcanvulcan0.2.21 of 2See more

vulcan vulcan 0.2.2

1 of the 2 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
mitre/vulcan:latest2bc4dfb8150f
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

1,516
aih-scannerwallarmVerified publisher2.7.111 of 2See more

aih-scanner wallarm 2.7.11

1 of the 2 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
wallarm/aih-scanner:2.7.11f1cb26db1f5b
github.com/docker/docker@v28.3.3+incompatible
no fix listed

Open the chart page →

3,911
wallarm-oobwallarmVerified publisher0.23.01 of 3See more

wallarm-oob wallarm 0.23.0

1 of the 3 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
wallarm/node-native-processing:0.23.07db2da8fce0b
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

2,824
istio-service-meshwbstack0.0.11 of 1See more

istio-service-mesh wbstack 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
istio/pilot:1.17.1ce9d87606701
github.com/docker/docker@v23.0.0-rc.2+incompatible
no fix listed

Open the chart page →

6,232
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-php:latest8f1bbd5cda85
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed

Open the chart page →

7,552
gitlab-runnerwenerme0.92.11 of 1See more

gitlab-runner wenerme 0.92.1

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
registry.gitlab.com/gitlab-org/gitlab-runner:alpine-v19.3.1af0325804248
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

904
mesherywenerme1.0.691 of 1See more

meshery wenerme 1.0.69

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
meshery/meshery:stable-latest9b68e81d392e
github.com/docker/docker@v28.5.2+incompatible
no fix listed

Open the chart page →

1,407
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/docker/docker@v25.0.15-0.20260325154711-d2dbc0547253+incompatible
no fix listed

Open the chart page →

1,456
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/docker/docker@v24.0.5+incompatible
no fix listed

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/docker/docker@v24.0.2+incompatible
no fix listed

Open the chart page →

2,022
wireguardwireguard-bananas1.5.01 of 1See more

wireguard wireguard-bananas 1.5.0

1 of the 1 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
place1/wg-access-server:v0.4.62b2f3ea80ed6
github.com/docker/docker@v1.13.1
no fix listed

Open the chart page →

2,745
xkopsxkops0.1.01 of 5See more

xkops xkops 0.1.0

1 of the 5 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
murtazashah46/helmfile:latest4d11726cf803
github.com/docker/docker@v20.10.21+incompatible
no fix listed

Open the chart page →

13,677
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-42306.

Container imageDigestPackageFixed in
quay.io/prometheus/prometheus:v3.1.06559acbd5d77
github.com/docker/docker@v27.4.1+incompatible
no fix listed

Open the chart page →

9,381

Container images carrying it

572 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
aquasec/harbor-scanner-trivy:0.31.26e790e233872
github.com/docker/docker@v26.1.2+incompatible
no fix listed
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
github.com/docker/docker@v20.10.3+incompatible
no fix listed
1
aquasec/postee:2.12.0-amd640795cba777e7
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
aquasec/postee-ui:2.12.0-amd64c0467c3941dc
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
aquasec/tracee:0.24.1cfbbfee972e6
github.com/docker/docker@v28.1.1+incompatible
no fix listed
1
aquasec/trivy:0.43.1944a04445179
github.com/docker/docker@v23.0.5+incompatible
no fix listed
1
aquasec/trivy:0.32.0973d0df16189
github.com/docker/docker@v20.10.3-0.20220224222438-c78f6963a1c0+incompatible
no fix listed
1
aquasec/trivy:0.69.3bcc376de8d77
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
artifacthub/hub:v1.19.0111918d8c399
github.com/docker/docker@v26.1.3+incompatible
no fix listed
1
artifacthub/scanner:v1.23.02d8365601f0e
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/docker/docker@v26.1.3+incompatible
no fix listed
1
artifacthub/tracker:v1.23.05368d21a6e5c
github.com/docker/docker@v28.3.3+incompatible
no fix listed
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/docker/docker@v26.1.3+incompatible
no fix listed
1
assistiot/cybersecurity-monitoring_id-wzh:latest0aacefac9677
github.com/docker/docker@v1.13.1
no fix listed
1
beopenit/door-agent:v3.0.5d24c323fe7c3
github.com/docker/docker@v25.0.6+incompatible
no fix listed
1
beopenit/door-helm:v3.0.1b4d9f9bee224
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
bicarus/wg-access-server:v0.8.206cab48e9334
github.com/docker/docker@v20.10.8+incompatible
no fix listed
1
bitnamilegacy/prometheus:2.54.1-debian-12-r408b1b7cb6a5b
github.com/docker/docker@v27.0.3+incompatible
no fix listed
1
bsgrigorov/helm-operator:latest45ab095f09c8
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
coderenvs/coder-service:1.44.61deffc4670e6
github.com/docker/docker@v20.10.20+incompatible
no fix listed
1
conduction/agendaservice-php:latest9cfeeb6c7c20
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed
1
conduction/balance-registration-php:devc36094a41369
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed
1
conduction/betaalservice-php:latestece1ab544c57
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed
1
conduction/cgrc-php:dev25415534d245
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed
1
conduction/checkin-component-php:dev3423845692c1
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed
1
conduction/conduction-ui-php:dev2744565516e8
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed
1
conduction/docparser-php:devb6f95c8ead7d
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed
1
conduction/kvk-php:dev8f177f9f8a7b
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed
1
conduction/pan-php:dev24f03c57568f
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed
1
daprio/dashboard:0.15.04be696707bd1
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
no fix listed
1
daprio/dashboard:0.14.07ba5d51e5b97
github.com/moby/moby@v17.12.0-ce-rc1.0.20200618181300-9dc6525e6118+incompatible
no fix listed
1
datadog/agent:7.22.08f20e56b5311
github.com/docker/docker@v17.12.0-ce-rc1.0.20200309214505-aa6a9891b09c+incompatible
no fix listed
1
datadog/agent:6aad9994de6a7
github.com/docker/docker@v25.0.7+incompatible
no fix listed
1
datasaker/dsk-container-agent:latest08b52999f67b
github.com/docker/docker@v20.10.24+incompatible
no fix listed
1
datawire/ambassador-operator:v1.3.0f95ae710d75c
github.com/moby/moby@v0.7.3-0.20190826074503-38ab9da00309
no fix listed
1
devopstales/trivy-operator:2.575136aa7a26e
github.com/docker/docker@v23.0.0-rc.1+incompatible
no fix listed
1
devspacecloud/manager:0.3.349c397413f7b
github.com/docker/docker@v1.4.2-0.20200203170920-46ec8731fbce
no fix listed
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
github.com/docker/docker@v24.0.0+incompatible
no fix listed
1
douz/overlord:latestf2bc7fc068c1
github.com/docker/docker@v1.13.1
no fix listed
1
dragonflyoss/manager:v2.1.49c3ef7f10698d
github.com/docker/docker@v26.1.1+incompatible
no fix listed
1
dragonflyoss/scheduler:v2.5.2-rc.06d710dc2bae0
github.com/docker/docker@v25.0.16+incompatible
no fix listed
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
github.com/docker/docker@v20.10.21+incompatible
no fix listed
1
eginnovations/agent:7.5.4e4dfe242fe9f
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
emqx/ecp-main:2.5.1fa876f71e5d6
github.com/docker/docker@v27.3.1+incompatible
no fix listed
1
emqxecp/otelcol:2.5.04c31d9bec846
github.com/docker/docker@v27.0.3+incompatible
no fix listed
1
epamedp/edp-headlamp:0.25.093417e18bb1a
github.com/docker/docker@v24.0.7+incompatible
no fix listed
1
falcosecurity/event-generator:latest932956d86c99
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1
falcosecurity/falco:0.44.1d0cfe422d6ac
github.com/docker/docker@v28.5.2+incompatible
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.