StackRadar

CVE-2026-42356

Low

Advisory

Published 1 Oct 2026In the index since 2 Oct 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.002
12th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
92
of 17,985 indexed, latest versions
Container images
86
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 92 of 17,985 indexed charts deploy, on 86 images.

Affected packageAffected versionsFixed inImages
apache2deb2.4.41-4ubuntu3.11, 2.4.41-4ubuntu3.12, 2.4.41-4ubuntu3.14, 2.4.41-4ubuntu3.17+22 moreno fix listed74
apache2apk2.4.62-r0, 2.4.63-r4, 2.4.66-r0, 2.4.67-r0+1 more2.4.69-r012
OSV records
ALPINE-CVE-2026-42356DEBIAN-CVE-2026-42356UBUNTU-CVE-2026-42356

Charts affected

92 by stars
ChartLatestAffected imagesRadar Score
flask-contactsfirst-idror-chart1.0.11 of 3See more

flask-contacts first-idror-chart 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/phpmyadmin:latest9e915766488a
apache2@2.4.68-1~deb13u1
no fix listed

Open the chart page →

6,382
flask-contactsflask-contacts-generic1.0.11 of 3See more

flask-contacts flask-contacts-generic 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/phpmyadmin:latest9e915766488a
apache2@2.4.68-1~deb13u1
no fix listed

Open the chart page →

6,382
apache-musicindexgeek-cookbookVerified publisher2.4.21 of 1See more

apache-musicindex geek-cookbook 2.4.2

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
apache2@2.4.41-4ubuntu3.12
no fix listed

Open the chart page →

16,026
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
apache2@2.4.67-1~deb12u3
no fix listed

Open the chart page →

10,593
glpiglpi-chart0.1.12 of 3See more

glpi glpi-chart 0.1.1

2 of the 3 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/phpmyadmin:latest9e915766488a
apache2@2.4.68-1~deb13u1
no fix listed
vdiogov/glpi-conteiner:latest6945f84f0058
apache2@2.4.61-1~deb12u1
no fix listed

Open the chart page →

12,966
drupalhelmforgeVerified publisher1.2.151 of 2See more

drupal helmforge 1.2.15

1 of the 2 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/drupal:11.4.7-php8.5-apache-bookworm6d5a1c0837a1
apache2@2.4.68-1~deb12u1
no fix listed

Open the chart page →

4,278
heimdallhelmforgeVerified publisher1.1.141 of 1See more

heimdall helmforge 1.1.14

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
linuxserver/heimdall:2.8.34c2b77d7e391
apache2@2.4.68-r0
2.4.69-r0

Open the chart page →

360
moodlehelmforgeVerified publisher1.1.21 of 2See more

moodle helmforge 1.1.2

1 of the 2 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
apache2@2.4.68-1~deb12u1
no fix listed

Open the chart page →

6,917
nextcloudhelmforgeVerified publisher2.0.01 of 3See more

nextcloud helmforge 2.0.0

1 of the 3 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/nextcloud:35.0.1-apache276547e033df
apache2@2.4.68-1~deb13u1
no fix listed

Open the chart page →

7,102
phpmyadminhelmforgeVerified publisher2.0.11 of 1See more

phpmyadmin helmforge 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
phpmyadmin/phpmyadmin:5.2.342a200db07b4
apache2@2.4.65-2
no fix listed

Open the chart page →

5,479
nominatimheywood8-helm-chartsVerified publisher3.10.81 of 3See more

nominatim heywood8-helm-charts 3.10.8

1 of the 3 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
mediagis/nominatim:4.2d0eae7b51374
apache2@2.4.52-1ubuntu4.7
no fix listed

Open the chart page →

15,424
intelowlintelowl-helm6.6.1-01-06-20261 of 5See more

intelowl intelowl-helm 6.6.1-01-06-2026

1 of the 5 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
intelowlproject/intelowl:v6.6.10b22e547ea6b
apache2@2.4.66-1~deb12u1
no fix listed

Open the chart page →

20,352
freshrssk8s-home-lab-repo7.3.01 of 1See more

freshrss k8s-home-lab-repo 7.3.0

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/freshrss:1.29.17f7f276244da
apache2@2.4.68-r0
2.4.69-r0

Open the chart page →

462
kc-chartkc-chart1.0.01 of 3See more

kc-chart kc-chart 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
jhoncytech/bookworm-apache-wordpress:latest18c3ca1f411e
apache2@2.4.57-2
no fix listed

Open the chart page →

9,986
phppgadminkfirfer0.1.121 of 1See more

phppgadmin kfirfer 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
kfirfer/phppgadmin:7.13.0-22efb4a5d74a3
apache2@2.4.41-4ubuntu3.12
no fix listed

Open the chart page →

11,038
cdashkitwareVerified publisher0.20.01 of 3See more

cdash kitware 0.20.0

1 of the 3 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
kitware/cdash:v5.4.0da5abe941506
apache2@2.4.68-1~deb13u1
no fix listed

Open the chart page →

13,171
kube-wordpress-mysqlkube-wordpress-mysql0.1.01 of 2See more

kube-wordpress-mysql kube-wordpress-mysql 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/wordpress:php8.1-apachef73396626d2f
apache2@2.4.65-2
no fix listed

Open the chart page →

10,412
mauticmautic-chartVerified publisher1.0.21 of 3See more

mautic mautic-chart 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
mautic/mautic:7-apacheeb8cc73d97e1
apache2@2.4.67-1~deb12u2
no fix listed

Open the chart page →

9,604
mediawikimediawiki0.4.11 of 1See more

mediawiki mediawiki 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/mediawiki:1.43.08b19e819f2e1
apache2@2.4.62-1~deb12u2
no fix listed

Open the chart page →

9,723
akauntingnas-helm-chartsVerified publisher1.0.31 of 2See more

akaunting nas-helm-charts 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
akaunting/akaunting:3.0.1552811b36ec3a
apache2@2.4.57-2
no fix listed

Open the chart page →

13,805
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
apache2@2.4.41-4ubuntu3.12
no fix listed

Open the chart page →

25,027
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
apache2@2.4.41-4ubuntu3.12
no fix listed

Open the chart page →

81,421
wp-chartprojet-devops0.1.01 of 2See more

wp-chart projet-devops 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/wordpress:latest8746e7e072e3
apache2@2.4.68-1~deb13u1
no fix listed

Open the chart page →

5,773
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
apache2@2.4.52-1ubuntu4.21
no fix listed

Open the chart page →

9,123
simple-coffeerubxkubeVerified publisher0.1.01 of 1See more

simple-coffee rubxkube 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
qjoly/kubernetes-coffee-image:simple9f0c5ce8b5d7
apache2@2.4.68-1~deb13u1
no fix listed

Open the chart page →

2,445
smokepingrubxkubeVerified publisher1.2.11 of 1See more

smokeping rubxkube 1.2.1

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
linuxserver/smokeping:2.9.00c8b547eda88
apache2@2.4.68-r0
2.4.69-r0

Open the chart page →

1,145
nextcloudsb-helm-charts0.4.01 of 2See more

nextcloud sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/nextcloud:31.0.10-apacheb7faa1653c39
apache2@2.4.65-2
no fix listed

Open the chart page →

10,990
phpmyadminsb-helm-charts0.3.01 of 1See more

phpmyadmin sb-helm-charts 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/phpmyadmin:5.2.16e75aa8f767c
apache2@2.4.62-1~deb12u2
no fix listed

Open the chart page →

5,942
wordpresssb-helm-charts0.4.01 of 2See more

wordpress sb-helm-charts 0.4.0

1 of the 2 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/wordpress:6.4.3-apache8ae66efb09a2
apache2@2.4.57-2
no fix listed

Open the chart page →

14,915
snipeitschmitzis6.1.01 of 2See more

snipeit schmitzis 6.1.0

1 of the 2 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
snipe/snipe-it:v8.3.1141ebf2386fe
apache2@2.4.58-1ubuntu8.8
no fix listed

Open the chart page →

68,678
restic-serverschoolguys-helmcharts0.3.11 of 1See more

restic-server schoolguys-helmcharts 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
restic/rest-server:0.14.0d2aff06f47eb
apache2@2.4.63-r4
2.4.69-r0

Open the chart page →

2,757
typo3schoolguys-helmcharts0.4.21 of 1See more

typo3 schoolguys-helmcharts 0.4.2

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
apache2@2.4.67-1~deb12u2
no fix listed

Open the chart page →

5,616
wordpress-mysqlsikalabs0.1.21 of 2See more

wordpress-mysql sikalabs 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/wordpress:latesta85a30d9e752
apache2@2.4.68-1~deb13u1
no fix listed

Open the chart page →

3,846
testing-multitoolsomeblackmagic0.1.21 of 1See more

testing-multitool someblackmagic 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apache2@2.4.41-4ubuntu3.11
no fix listed

Open the chart page →

105,005
nagvissvtech-public-helm-charts1.0.01 of 1See more

nagvis svtech-public-helm-charts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
apache2@2.4.57-2
no fix listed

Open the chart page →

9,938
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
apache2@2.4.41-4ubuntu3.17
no fix listed

Open the chart page →

78,665
flask-contactstest-configmap1.0.11 of 3See more

flask-contacts test-configmap 1.0.1

1 of the 3 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/phpmyadmin:latest9e915766488a
apache2@2.4.68-1~deb13u1
no fix listed

Open the chart page →

6,382
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
apache2@2.4.62-1~deb12u2
no fix listed

Open the chart page →

11,180
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
apache2@2.4.41-4ubuntu3.21
no fix listed

Open the chart page →

11,326
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
apache2@2.4.57-2
no fix listed

Open the chart page →

10,989
Wordpresswordpress-mariadb1.0.21 of 2See more

Wordpress wordpress-mariadb 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
library/wordpress:latest8746e7e072e3
apache2@2.4.68-1~deb13u1
no fix listed

Open the chart page →

5,571
zoo-project-druzoo-projectOfficialVerified publisher0.10.81 of 6See more

zoo-project-dru zoo-project 0.10.8

1 of the 6 container images this version deploys carry CVE-2026-42356.

Container imageDigestPackageFixed in
zooproject/zoo-project:dru-51e7d55383f24594959b69e58518961c6aa66740da112e8d03f1
apache2@2.4.52-1ubuntu4.23
no fix listed

Open the chart page →

6,744

Container images carrying it

86 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
martinhelmich/typo3:12.4c83a4f3fd7ae
apache2@2.4.66-1~deb12u1
no fix listed
1
mautic/mautic:7-apacheeb8cc73d97e1
apache2@2.4.67-1~deb12u2
no fix listed
1
mediagis/nominatim:3.7c15e941485ef
apache2@2.4.41-4ubuntu3.12
no fix listed
1
mediagis/nominatim:4.2d0eae7b51374
apache2@2.4.52-1ubuntu4.7
no fix listed
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
apache2@2.4.68-1~deb12u1
no fix listed
1
openstackhelm/heat:wallaby-ubuntu_focalf728510bab3c
apache2@2.4.41-4ubuntu3.14
no fix listed
1
openstackhelm/keystone:wallaby-ubuntu_focale07d75953d2e
apache2@2.4.41-4ubuntu3.14
no fix listed
1
owncloud/server:10.15.051d9b74fc2a8
apache2@2.4.41-4ubuntu3.21
no fix listed
1
owncloud/server:10.16.274c53d341076
apache2@2.4.52-1ubuntu4.20
no fix listed
1
owncloud/server:10.16.3b3f9efdcd7f7
apache2@2.4.52-1ubuntu4.23
no fix listed
1
phpipam/phpipam-cron:latest13a0c266ddd2
apache2@2.4.68-r0
2.4.69-r0
1
phpipam/phpipam-www:latestbaab8c632f4d
apache2@2.4.68-r0
2.4.69-r0
1
phpmyadmin/phpmyadmin:5.2.342a200db07b4
apache2@2.4.65-2
no fix listed
1
pockost/matomo:5.14.0134c35415788
apache2@2.4.68-1~deb13u1
no fix listed
1
qjoly/kubernetes-coffee-image:simple9f0c5ce8b5d7
apache2@2.4.68-1~deb13u1
no fix listed
1
qonstrukt/php:8.4-v8-apache089af7925aa1
apache2@2.4.58-1ubuntu8.15
no fix listed
1
restic/rest-server:0.14.0d2aff06f47eb
apache2@2.4.63-r4
2.4.69-r0
1
roundcube/roundcubemail:1.6.16-apache-nonroot17d9d9580962
apache2@2.4.67-1~deb13u3
no fix listed
1
snipe/snipe-it:v8.3.1141ebf2386fe
apache2@2.4.58-1ubuntu8.8
no fix listed
1
snipe/snipe-it:v6.0.1455fb7636a98c
apache2@2.4.41-4ubuntu3.12
no fix listed
1
someblackmagic/k8s-testing-multitool:v0.1.06eca64b6b440
apache2@2.4.41-4ubuntu3.11
no fix listed
1
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
apache2@2.4.66-1~deb13u1
no fix listed
1
svtechnmaa/svtech_nagvis:v1.2.118394b08e6c3
apache2@2.4.57-2
no fix listed
1
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
apache2@2.4.41-4ubuntu3.17
no fix listed
1
zooproject/zoo-project:dru-51e7d55383f24594959b69e58518961c6aa66740da112e8d03f1
apache2@2.4.52-1ubuntu4.23
no fix listed
1
ghcr.io/abcdesktopio/oc.speedtest:4.4763cc0d3a176
apache2@2.4.68-r0
2.4.69-r0
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
apache2@2.4.65-1~deb12u1
no fix listed
1
ghcr.io/k8s-at-home/apache-musicindex:v1.4.1-2c9bd82dc5fda
apache2@2.4.41-4ubuntu3.12
no fix listed
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
apache2@2.4.62-r0
2.4.69-r0
1
ghcr.io/linuxserver/freshrss:1.29.17f7f276244da
apache2@2.4.68-r0
2.4.69-r0
1
ghcr.io/monicahq/monica-next:main8be69156acbb
apache2@2.4.65-2
no fix listed
1
ghcr.io/nathanvaughn/webtrees:2.2.6034151b61a80
apache2@2.4.67-1~deb13u2
no fix listed
1
ghcr.io/yourls/yourls:1.10.62f2879125903
apache2@2.4.68-1~deb13u1
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
apache2@2.4.41-4ubuntu3.11
no fix listed
1
quay.io/nuclio/controller:1.17.9-amd646e3913a56ca5
apache2@2.4.68-r0
2.4.69-r0
1
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
apache2@2.4.67-1~deb12u2
no fix listed
1

syft 1.42.1 · advisories as of 3 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.