StackRadar

CVE-2026-42534

High

Advisory

Published 20 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.006
46th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
33
of 17,781 indexed, latest versions
Container images
36
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 33 of 17,781 indexed charts deploy, on 36 images.

Affected packageAffected versionsFixed inImages
unbounddeb1.9.4-2ubuntu1.1, 1.9.4-2ubuntu1.2, 1.13.1-1ubuntu5.8, 1.13.1-1ubuntu5.11+8 more1.13.1-1ubuntu5.15, 1.19.2-1ubuntu3.8, 1.22.0-2+deb13u3, 1.22.0-2ubuntu2.336
OSV records
UBUNTU-CVE-2026-42534DEBIAN-CVE-2026-42534
Also known as
USN-8282-1

Charts affected

33 by stars
ChartLatestAffected imagesRadar Score
maildocker-postfixVerified publisher5.1.01 of 1See more

mail docker-postfix 5.1.0

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
boky/postfix:5.1.0aafc77238423
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3

Open the chart page →

5,366
nautobotnautobotOfficialVerified publisher3.1.21 of 1See more

nautobot nautobot 3.1.2

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
networktocode/nautobot:3.0-py3.13ed484336b1ad
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3

Open the chart page →

4,332
smtpntppoolVerified publisher2.4.01 of 1See more

smtp ntppool 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3

Open the chart page →

2,244
dask-kubernetes-operatordask2026.3.01 of 1See more

dask-kubernetes-operator dask 2026.3.0

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3

Open the chart page →

9,316
part-dbpart-dbVerified publisher0.1.21 of 1See more

part-db part-db 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
jbtronics/part-db1:latest5db71f6db59d
unbound@1.17.1-2+deb12u4
no fix listed

Open the chart page →

3,327
freeradiusstartechnicaVerified publisher1.2.01 of 1See more

freeradius startechnica 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
freeradius/freeradius-server:3.2.8af6fd34a5b78
unbound@1.13.1-1ubuntu5.11
1.13.1-1ubuntu5.15

Open the chart page →

5,751
anteonanteonVerified publisher2.6.41 of 13See more

anteon anteon 2.6.4

1 of the 13 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
ddosify/selfhosted_backend:3.2.93c11e3182652
unbound@1.17.1-2+deb12u2
no fix listed

Open the chart page →

22,202
cosmotech-copilot-apicosmotech-apiVerified publisher0.1.11 of 1See more

cosmotech-copilot-api cosmotech-api 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3

Open the chart page →

11,205
iris-webappiris-webapp0.2.41 of 2See more

iris-webapp iris-webapp 0.2.4

1 of the 2 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
unbound@1.22.0-2
1.22.0-2+deb13u3

Open the chart page →

11,764
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
unbound@1.22.0-2ubuntu2.1
1.22.0-2ubuntu2.3

Open the chart page →

11,103
prowlerprowler-appVerified publisher0.0.91 of 5See more

prowler prowler-app 0.0.9

1 of the 5 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
prowlercloud/prowler-api:5.31.14f252d579be2
unbound@1.17.1-2+deb12u4
no fix listed

Open the chart page →

8,158
napcatredish101Verified publisher0.1.31 of 1See more

napcat redish101 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
mlikiowa/napcat-docker:latest1336a777f9a4
unbound@1.13.1-1ubuntu5.8
1.13.1-1ubuntu5.15

Open the chart page →

7,405
sogosogoVerified publisher0.3.51 of 2See more

sogo sogo 0.3.5

1 of the 2 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3

Open the chart page →

7,126
varnish-cachevarnishVerified publisher1.1.11 of 1See more

varnish-cache varnish 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
library/varnish:7.5.04d0bb287d87b
unbound@1.17.1-2+deb12u2
no fix listed

Open the chart page →

4,249
open5gsadaptivenetlabVerified publisher1.0.31 of 3See more

open5gs adaptivenetlab 1.0.3

1 of the 3 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
unbound@1.9.4-2ubuntu1.1
no fix listed

Open the chart page →

25,443
ddosifyanteonVerified publisher1.7.52 of 13See more

ddosify anteon 1.7.5

2 of the 13 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
unbound@1.17.1-2+deb12u2
no fix listed
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
unbound@1.17.1-2+deb12u2
no fix listed

Open the chart page →

25,669
datumcosmicrocks1.0.51 of 2See more

datum cosmicrocks 1.0.5

1 of the 2 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
unbound@1.19.2-1ubuntu3.7
1.19.2-1ubuntu3.8

Open the chart page →

2,944
domainmoddjjudas21Verified publisher1.0.01 of 1See more

domainmod djjudas21 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
domainmod/domainmod:4.23.04017bfe4c597
unbound@1.17.1-2+deb12u2
no fix listed

Open the chart page →

7,141
iotaeclipse-aeriosVerified publisher1.0.21 of 4See more

iota eclipse-aerios 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
unbound@1.22.0-2
1.22.0-2+deb13u3

Open the chart page →

13,391
firefly-iiifirefly-iii1.10.11 of 1See more

firefly-iii firefly-iii 1.10.1

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3

Open the chart page →

5,039
firefly-iii-stackfirefly-iii0.10.22 of 4See more

firefly-iii-stack firefly-iii 0.10.2

2 of the 4 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
fireflyiii/core:version-6.5.9fe4ecec4c2ba
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3
fireflyiii/data-importer:version-2.2.3ab52bf932546
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3

Open the chart page →

10,260
importerfirefly-iii1.6.01 of 1See more

importer firefly-iii 1.6.0

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
fireflyiii/data-importer:version-2.2.3ab52bf932546
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3

Open the chart page →

4,829
business-api-ecosystemfiware1.1.01 of 4See more

business-api-ecosystem fiware 1.1.0

1 of the 4 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
unbound@1.17.1-2+deb12u4
no fix listed

Open the chart page →

64,489
mod-z3950folio-org0.1.31 of 1See more

mod-z3950 folio-org 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
folioci/mod-z3950:latest2493041ce880
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3

Open the chart page →

2,442
icinga2geek-cookbookVerified publisher4.2.01 of 1See more

icinga2 geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
jordan/icinga2:latestf75025fe8ea8
unbound@1.17.1-2+deb12u4
no fix listed

Open the chart page →

9,077
chiefonboardinghelmforgeVerified publisher1.1.141 of 3See more

chiefonboarding helmforge 1.1.14

1 of the 3 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3

Open the chart page →

10,849
moodlehelmforgeVerified publisher1.1.01 of 2See more

moodle helmforge 1.1.0

1 of the 2 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
unbound@1.17.1-2+deb12u4
no fix listed

Open the chart page →

6,103
ibexaibexaVerified publisher3.11.11 of 10See more

ibexa ibexa 3.11.1

1 of the 10 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
boky/postfix:4.4.0f3f247fd4252
unbound@1.17.1-2+deb12u2
no fix listed

Open the chart page →

5,959
mindsdbkronkltdVerified publisher0.1.01 of 1See more

mindsdb kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
mindsdb/mindsdb:latest163011c09299
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3

Open the chart page →

9,620
kube-ovnkube-ovn-test1.14.01 of 1See more

kube-ovn kube-ovn-test 1.14.0

1 of the 1 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
kubeovn/kube-ovn:v1.14.06722b54eb5c0
unbound@1.19.2-1ubuntu3.4
1.19.2-1ubuntu3.8

Open the chart page →

4,940
MINTmint8.0.21 of 15See more

MINT mint 8.0.2

1 of the 15 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
unbound@1.9.4-2ubuntu1.2
no fix listed

Open the chart page →

43,341
smilencsaVerified publisher1.1.04 of 23See more

smile ncsa 1.1.0

4 of the 23 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
unbound@1.17.1-2
no fix listed
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
unbound@1.17.1-2
no fix listed
socialmediamacroscope/preprocessing:0.1.3ca863306314b
unbound@1.17.1-2
no fix listed
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
unbound@1.17.1-2
no fix listed

Open the chart page →

109,294
transmissionryuunosukeds31.6.21 of 2See more

transmission ryuunosukeds3 1.6.2

1 of the 2 container images this version deploys carry CVE-2026-42534.

Container imageDigestPackageFixed in
library/python:3.9da5aee29682d
unbound@1.22.0-2
1.22.0-2+deb13u3

Open the chart page →

9,534

Container images carrying it

36 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
fireflyiii/core:version-6.5.9fe4ecec4c2ba
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3
2
boky/postfix:5.1.0aafc77238423
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3
1
boky/postfix:4.4.0f3f247fd4252
unbound@1.17.1-2+deb12u2
no fix listed
1
chiefonboarding/chiefonboarding:v2.4.159bc7aa60fe7
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3
1
ddosify/selfhosted_alaz_backend:1.0.6a43c5155fa1c
unbound@1.17.1-2+deb12u2
no fix listed
1
ddosify/selfhosted_backend:3.2.93c11e3182652
unbound@1.17.1-2+deb12u2
no fix listed
1
ddosify/selfhosted_backend:2.6.11ac323d52bfb4
unbound@1.17.1-2+deb12u2
no fix listed
1
domainmod/domainmod:4.23.04017bfe4c597
unbound@1.17.1-2+deb12u2
no fix listed
1
eclipseaerios/iota-messages-api:lateste7f5ba0bc64d
unbound@1.22.0-2
1.22.0-2+deb13u3
1
fiware/biz-ecosystem-logic-proxy:11.20.3d551a13e8278
unbound@1.17.1-2+deb12u4
no fix listed
1
folioci/mod-z3950:latest2493041ce880
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3
1
freeradius/freeradius-server:3.2.8af6fd34a5b78
unbound@1.13.1-1ubuntu5.11
1.13.1-1ubuntu5.15
1
jbtronics/part-db1:latest5db71f6db59d
unbound@1.17.1-2+deb12u4
no fix listed
1
jordan/icinga2:latestf75025fe8ea8
unbound@1.17.1-2+deb12u4
no fix listed
1
kubeovn/kube-ovn:v1.14.06722b54eb5c0
unbound@1.19.2-1ubuntu3.4
1.19.2-1ubuntu3.8
1
library/python:3.9da5aee29682d
unbound@1.22.0-2
1.22.0-2+deb13u3
1
library/varnish:7.5.04d0bb287d87b
unbound@1.17.1-2+deb12u2
no fix listed
1
mindsdb/mindsdb:latest163011c09299
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3
1
mintproject/graphql-engine:305c0dbeba1878eafe348f21fc300fbfc017d9dc83aade2c1855
unbound@1.9.4-2ubuntu1.2
no fix listed
1
mlikiowa/napcat-docker:latest1336a777f9a4
unbound@1.13.1-1ubuntu5.8
1.13.1-1ubuntu5.15
1
moodlehq/moodle-php-apache:8.4-bookworm922af5166835
unbound@1.17.1-2+deb12u4
no fix listed
1
networktocode/nautobot:3.0-py3.13ed484336b1ad
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3
1
photoprism/photoprism:251130db16ee6b1ba3
unbound@1.22.0-2ubuntu2.1
1.22.0-2ubuntu2.3
1
prowlercloud/prowler-api:5.31.14f252d579be2
unbound@1.17.1-2+deb12u4
no fix listed
1
socialmediamacroscope/histogram:0.1.26418f9bdb4d2
unbound@1.17.1-2
no fix listed
1
socialmediamacroscope/network_analysis:0.1.3b351c21422e6
unbound@1.17.1-2
no fix listed
1
socialmediamacroscope/preprocessing:0.1.3ca863306314b
unbound@1.17.1-2
no fix listed
1
socialmediamacroscope/topic_modeling:0.1.3fa490acac2f8
unbound@1.17.1-2
no fix listed
1
sonroyaalmerol/docker-sogo:5.12.43f60f3abe990
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3
1
ghcr.io/cosmicrocks/datum:v0.4.0beta76771c3cc8c3
unbound@1.19.2-1ubuntu3.7
1.19.2-1ubuntu3.8
1
ghcr.io/cosmo-tech/cosmotech-copilot-api:latesta2be95de450c
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3
1
ghcr.io/dask/dask-kubernetes-operator:2026.3.03225d2bc6b3c
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3
1
ghcr.io/dfir-iris/iriswebapp_app:v2.4.26e59ebde55709
unbound@1.22.0-2
1.22.0-2+deb13u3
1
ghcr.io/egos-tech/smtp:1.2.2b5451793ad91
unbound@1.22.0-2+deb13u1
1.22.0-2+deb13u3
1
registry.gitlab.com/infinitydon/registry/open5gs-aio:v2.2.2f6385712935f
unbound@1.9.4-2ubuntu1.1
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.