StackRadar

CVE-2026-42533

Critical

Advisory

Published 15 Jul 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.2
base score, highest
EPSS
0.045
91st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
119
of 17,781 indexed, latest versions
Container images
119
deployed by those charts
Fix available
6 of 6
affected packages

NGINX Map directive and Regex matching vulnerability

Carried by container images the latest versions of 119 of 17,781 indexed charts deploy, on 119 images.

Affected packageAffected versionsFixed inImages
nginxdeb1.4.6-1ubuntu3.8ppa1, 1.18.0-0ubuntu1.2, 1.18.0-0ubuntu1.3, 1.18.0-0ubuntu1.4+35 more1.18.0-6ubuntu14.20, 1.24.0-2ubuntu7.17, 1.26.3-3+deb13u888
nginxapk1.26.2-r4, 1.26.3-r0, 1.28.0-r3, 1.28.1-r1+4 more1.26.3-r2, 1.28.3-r614
nginxbitnami1.25.5-0, 1.27.1-2, 1.28.0-0, 1.31.3-01.30.44
nginx-mainlineapk1.27.4-r0, 1.27.4-r2, 1.29.8-r11.31.3-r03
NGINX Open Sourcebitnami1.25.5-01.30.41
nginxrpm1:1.20.1-13.el9, 1:1.22.1-5.module+el9.3.0.z+20438+032561a0, 1:1.22.1-8.module+el9.5.0+22953+b175c265.1, 1:1.24.0-7.module+el9.8.0+24502+c9b9ab67.3+3 more1.21.5-150600.10.27.1, 2:1.20.1-28.el9_8.610
OSV records
ALPINE-CVE-2026-42533BIT-nginx-2026-42533CGA-3cc9-j23w-933vDEBIAN-CVE-2026-42533RHSA-2026:66542UBUNTU-CVE-2026-42533SUSE-SU-2026:3469-1
Also known as
BIT-nginx-gateway-2026-42533, CGA-x99p-pq5w-pxj6, USN-8563-1, USN-8563-2, USN-8563-3, USN-8563-4

Charts affected

119 by stars
ChartLatestAffected imagesRadar Score
synapse-adminschoenwald1.0.11 of 1See more

synapse-admin schoenwald 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
awesometechnologies/synapse-admin:0.11.4a1c1f4662875
nginx@1.28.2-r1
1.28.3-r6

Open the chart page →

1,802
tabixsinextraVerified publisher0.2.21 of 1See more

tabix sinextra 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/sergelogvinov/tabix:22.05.17a6e3e996a4ae
nginx@1.28.0-r3
1.28.3-r6

Open the chart page →

1,249
cost-analyzersoftonic2.5.51 of 6See more

cost-analyzer softonic 2.5.5

1 of the 6 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
gcr.io/kubecost1/frontend:prod-2.5.5991c1465c658
nginx-mainline@1.27.4-r2
1.31.3-r0

Open the chart page →

7,901
substra-frontendsubstraVerified publisher1.2.31 of 1See more

substra-frontend substra 1.2.3

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
nginx@1.25.4-1~bookworm
no fix listed

Open the chart page →

3,032
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
nginx@1.26.3-3+deb13u6
1.26.3-3+deb13u8

Open the chart page →

4,674
tarkatarkaOfficialVerified publisher0.4.11 of 4See more

tarka tarka 0.4.1

1 of the 4 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/tarkyaio/tarka-ui:0.4.1b2dfabe13cfe
nginx-mainline@1.29.8-r1
1.31.3-r0

Open the chart page →

1,556
super-mariotechpreta0.1.11 of 1See more

super-mario techpreta 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
nirmalnaveen/supermario:latest8541a39162f3
nginx@1.25.3-1~bookworm
no fix listed

Open the chart page →

6,297
mrasiftech-thinker1.0.41 of 1See more

mrasif tech-thinker 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
nginx@1.28.1-r1
1.28.3-r6

Open the chart page →

2,043
tensor_apptensor-app0.2.22 of 3See more

tensor_app tensor-app 0.2.2

2 of the 3 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
xeladock/mysql_dns:latest4baf531453f1
nginx@1.18.0-6ubuntu14
1.18.0-6ubuntu14.20
xeladock/nginx2:latestc259a67b1dff
nginx@1.18.0-6ubuntu14
1.18.0-6ubuntu14.20

Open the chart page →

17,461
chatqnatest-opea1.0.01 of 11See more

chatqna test-opea 1.0.0

1 of the 11 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

39,090
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
library/nginx:1.27.1287ff321f9e3
nginx@1.27.1-1~bookworm
no fix listed

Open the chart page →

28,858
orchestra-login-portaltremolo2.3.971 of 1See more

orchestra-login-portal tremolo 2.3.97

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
nginx@1.18.0-6ubuntu14.7
1.18.0-6ubuntu14.20

Open the chart page →

2,956
opencloudunxwaresVerified publisher0.2.36 of 13See more

opencloud unxwares 0.2.3

6 of the 13 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
opencloudeu/web-extensions:unzip-1.0.01691ad6612a3
nginx@1.27.4-1~bookworm
no fix listed
opencloudeu/web-extensions:draw-io-1.0.027cb9b952f0d
nginx@1.27.4-1~bookworm
no fix listed
opencloudeu/web-extensions:external-sites-1.0.05b176baa3694
nginx@1.27.4-1~bookworm
no fix listed
opencloudeu/web-extensions:importer-1.0.06e8b2df6c5a4
nginx@1.27.4-1~bookworm
no fix listed
opencloudeu/web-extensions:progress-bars-1.0.082f888a34440
nginx@1.27.4-1~bookworm
no fix listed
opencloudeu/web-extensions:json-viewer-1.0.0e0ac35a9576e
nginx@1.27.4-1~bookworm
no fix listed

Open the chart page →

45,239
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
nginx@1.22.1-9+deb12u2
no fix listed

Open the chart page →

5,984
webhookiewebhookie0.1.21 of 1See more

webhookie webhookie 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nginx@1.20.1-1~focal
no fix listed

Open the chart page →

14,364
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
hookiesolutions/webhookie:latest0629694246ba
nginx@1.20.1-1~focal
no fix listed

Open the chart page →

28,605
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2026-42533.

Container imageDigestPackageFixed in
library/nginx:1.25a484819eb602
nginx@1.25.5-1~bookworm
no fix listed

Open the chart page →

7,673

Container images carrying it

119 by charts deploying them

A fixed version is listed for 6 of the 6 affected packages.

Container imageDigestPackageFixed inUsed by
longhornio/longhorn-ui:v1.12.03870d52a2b0a
nginx@1.21.5-150600.10.18.1
1.21.5-150600.10.27.1
1
longhornio/longhorn-ui:v1.10.0e60f36161511
nginx@1.21.5-150600.10.9.1
1.21.5-150600.10.27.1
1
moreillon/camera-viewer:lateste418cc694bd5
nginx@1.29.0-1~bookworm
no fix listed
1
moreillon/user-manager-front:v5.1.06597e6b98d21
nginx@1.27.0-2~bookworm
no fix listed
1
mrasif/mrasif.in:v4.6.0375a1ed8fdc0
nginx@1.28.1-r1
1.28.3-r6
1
nirmalnaveen/supermario:latest8541a39162f3
nginx@1.25.3-1~bookworm
no fix listed
1
opencsghq/label-studio:v2.5.047e22aa71870
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8
1
opencsghq/label-studio:v2.4.0b4e849fcf94a
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8
1
passbolt/passbolt:5.13.0-1-ceaf3a620902a0
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8
1
pk910/powfaucet:v2-stable3dcae6a62896
nginx@1.27.5-1~bookworm
no fix listed
1
polyaxon/polyaxon-api:2.16.42b55c3265a90
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8
1
polyaxon/polyaxon-streams:2.16.4c186bd9834c0
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8
1
praravind1801/helmimages:3.0.0f29d637b9ce1
nginx@1.25.3-1~bookworm
no fix listed
1
pretix/standalone:2026.7.05df3b7aa852e
nginx@1.26.3-3+deb13u7
1.26.3-3+deb13u8
1
redimp/otterwiki:2778bf30da3da
nginx@1.22.1-9+deb12u9
no fix listed
1
rocketadmin/rocketadmin:1.17.710955ef540b9
nginx@1.22.1-9+deb12u4
no fix listed
1
seafileltd/seafile-mc:9.0.106693911bcc40
nginx@1.18.0-0ubuntu1.4
no fix listed
1
seafileltd/seafile-mc:10.0.170628f29c663
nginx@1.24.0-1~focal
no fix listed
1
seafileltd/seafile-mc:9.0.97ac833196f60
nginx@1.18.0-0ubuntu1.3
no fix listed
1
seafileltd/seafile-mc:11.0.12d0c66e4621bd
nginx@1.26.1-2~jammy
no fix listed
1
seafileltd/seafile-mc:8.0.7ed0fcda5e6a9
nginx@1.18.0-0ubuntu1.2
no fix listed
1
shamimkuet/nginx:1.0.2b82902a76a04
nginx@1.27.0-2~bookworm
no fix listed
1
sigp/siren:v3.0.42c219b04758e
nginx@1.22.1-9+deb12u2
no fix listed
1
somnathmore/custom-nginx:v2bdfc06cad4ec
nginx@1.27.0-2~bookworm
no fix listed
1
stackstorm/st2web:3.809989a26c8b7
nginx@1.24.0-1~focal
no fix listed
1
tinymediamanager/tinymediamanager:5.3.22b34dc85099e
nginx@1.26.3-3+deb13u2
1.26.3-3+deb13u8
1
vabene1111/recipes:2.3.50f8d061895e9
nginx@1.28.0-r3
1.28.3-r6
1
weblate/weblate:2026.9.1.0990720d1737a
nginx@1.28.3-2ubuntu1.10
no fix listed
1
wiktorn/overpass-api:latest9bb5f4a9b54c
nginx@1.29.1-1~bookworm
no fix listed
1
xeladock/mysql_dns:latest4baf531453f1
nginx@1.18.0-6ubuntu14
1.18.0-6ubuntu14.20
1
xeladock/nginx2:latestc259a67b1dff
nginx@1.18.0-6ubuntu14
1.18.0-6ubuntu14.20
1
zabbix/zabbix-web-nginx-mysql:ubuntu-6.4-latest0e5f69c4c54e
nginx@1.24.0-2ubuntu7.1
1.24.0-2ubuntu7.17
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-5.4.601de79c31391
nginx@1.20.1-1~focal
no fix listed
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-7.0.237d4d58086515
nginx@1.24.0-2ubuntu7.5
1.24.0-2ubuntu7.17
1
zabbix/zabbix-web-nginx-pgsql:ubuntu-6.0.899e9a090b516
nginx@1.22.0-1~jammy
no fix listed
1
gcr.io/kasten-images/frontend:9.0.54b36f413cabb
nginx@1:1.22.1-8.module+el9.5.0+22953+b175c265.1
2:1.20.1-28.el9_8.6
1
gcr.io/kubecost1/frontend:prod-2.5.5991c1465c658
nginx-mainline@1.27.4-r2
1.31.3-r0
1
gcr.io/kubecost1/frontend:prod-2.6.3a535f7de024b
nginx-mainline@1.27.4-r0
1.31.3-r0
1
ghcr.io/angelnu/tt-rss:2.0.10068d332ae2410f8
nginx@1.28.3-2ubuntu1.10
no fix listed
1
ghcr.io/ashvinbambhaniya/nexus-tasks-frontend:2.0.0fcbab3a24880
nginx@1.28.3-r0
1.28.3-r6
1
ghcr.io/beslovas/duckdb-ui:1.3.272f35584026d
nginx@1.22.1-9+deb12u3
no fix listed
1
ghcr.io/drogue-iot/console-frontend:0.11.0558972f9374c
nginx@1:1.20.1-13.el9
2:1.20.1-28.el9_8.6
1
ghcr.io/ellite/wallos:2.46.09ce55520e7bd
nginx@1.26.2-r4
1.26.3-r2
1
ghcr.io/iisas/domino-frontend:k8s8e53861be292
nginx@1.29.1-1~bookworm
no fix listed
1
ghcr.io/it-at-m/wjh-rechner:1.0.0bc70cdb5a01a
nginx@1:1.22.1-5.module+el9.3.0.z+20438+032561a0
2:1.20.1-28.el9_8.6
1
ghcr.io/krateoplatformops/frontend:1.0.2733b6b5cab19d
nginx@1.31.3-0
1.30.4
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
nginx@1.18.0-0ubuntu1.2
no fix listed
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
nginx@1.26.2-r4
1.26.3-r2
1
ghcr.io/opencatalogi/web-app:deva1a7f507f6ae
nginx@1.27.1-1~bookworm
no fix listed
1
ghcr.io/openrelik/openrelik-ui:latest7f91594d5eb3
nginx@1.28.3-r1
1.28.3-r6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.