StackRadar

CVE-2026-42536

High

Advisory

Published 8 Jun 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.010
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
54
of 17,781 indexed, latest versions
Container images
51
deployed by those charts
Fix available
3 of 3
affected packages

Apache HTTP Server: mod_xml2enc heap overflow

Carried by container images the latest versions of 54 of 17,781 indexed charts deploy, on 51 images.

Affected packageAffected versionsFixed inImages
apache2deb2.4.41-4ubuntu3.11, 2.4.41-4ubuntu3.12, 2.4.41-4ubuntu3.14, 2.4.41-4ubuntu3.17+17 more2.4.41-4ubuntu3.23+esm5, 2.4.52-1ubuntu4.23, 2.4.58-1ubuntu8.15, 2.4.68-1~deb12u1+1 more43
apachebitnami2.4.54-157, 2.4.65-1, 2.4.68-1, 2.4.68-82.4.684
apache2apk2.4.62-r0, 2.4.63-r4, 2.4.66-r0, 2.4.67-r02.4.68-r04
OSV records
ALPINE-CVE-2026-42536BIT-apache-2026-42536DEBIAN-CVE-2026-42536UBUNTU-CVE-2026-42536
Also known as
USN-8516-1, USN-8571-1

Charts affected

54 by stars
ChartLatestAffected imagesRadar Score
rundecksvtech-public-helm-charts1.0.01 of 2See more

rundeck svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42536.

Container imageDigestPackageFixed in
svtechnmaa/svtech_rundeck:v1.2.26e368ace0977
apache2@2.4.41-4ubuntu3.17
2.4.41-4ubuntu3.23+esm5

Open the chart page →

18,756
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-42536.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
apache2@2.4.62-1~deb12u2
2.4.68-1~deb12u1

Open the chart page →

10,086
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-42536.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
apache2@2.4.41-4ubuntu3.21
2.4.41-4ubuntu3.23+esm5

Open the chart page →

10,006
web-dvwaweb-dvwa1.16.01 of 2See more

web-dvwa web-dvwa 1.16.0

1 of the 2 container images this version deploys carry CVE-2026-42536.

Container imageDigestPackageFixed in
gulacedia/web-dvwa-new:v367b467d961ca
apache2@2.4.57-2
2.4.68-1~deb12u1

Open the chart page →

10,001

Container images carrying it

51 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
registry.gitlab.com/school_guy/docker-typo3:13.4.30-197d868ed76185d7270d
apache2@2.4.67-1~deb12u2
2.4.68-1~deb12u1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.