StackRadar

CVE-2026-44170

Critical

Advisory

Published 12 Jun 2026In the index since 5 Sept 2026
Severity
Critical
worst across findings
CVSS
9.9
base score, highest
EPSS
0.013
70th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
23
of 17,781 indexed, latest versions
Container images
23
deployed by those charts
Fix available
4 of 5
affected packages

MariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URL

Carried by container images the latest versions of 23 of 17,781 indexed charts deploy, on 23 images.

Affected packageAffected versionsFixed inImages
mariadbbitnami10.6.12-2, 10.6.12-3, 10.11.4-1, 11.4.3-0+3 more10.6.268
mysql-clientbitnami10.6.11-1, 10.11.10-0, 12.3.2-110.6.263
mariadbdeb1:11.8.3-1build1no fix listed1
MariaDBbitnami10.11.410.6.261
mariadbapk10.11.8-r0, 10.11.10-r0, 10.11.16-r0, 11.4.4-r1+4 more10.11.17-r0, 11.4.11-r011
OSV records
ALPINE-CVE-2026-44170BIT-mariadb-2026-44170BIT-mysql-client-2026-44170UBUNTU-CVE-2026-44170
Also known as
BIT-mariadb-min-2026-44170, GHSA-f835-cfjq-wf73

Charts affected

23 by stars
ChartLatestAffected imagesRadar Score
semaphoresemaphoreuiOfficialVerified publisher16.2.21 of 1See more

semaphore semaphoreui 16.2.2

1 of the 1 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
semaphoreui/semaphore:v2.18.3e9260bfa8255
mariadb@11.4.10-r0
11.4.11-r0

Open the chart page →

2,221
netris-controllernetrisai2.8.21 of 14See more

netris-controller netrisai 2.8.2

1 of the 14 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
netrisai/mariadb:10.11.4-debian-11-r460aa742a0b906
mariadb@10.11.4-1
MariaDB@10.11.4
10.6.26
10.6.26

Open the chart page →

30,326
bookstackgabe565Verified publisher0.20.01 of 1See more

bookstack gabe565 0.20.0

1 of the 1 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
mariadb@11.4.5-r0
11.4.11-r0

Open the chart page →

2,811
dolibarrcowboysysopVerified publisher9.0.31 of 3See more

dolibarr cowboysysop 9.0.3

1 of the 3 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
mariadb@11.4.5-2
10.6.26

Open the chart page →

9,106
healthchecksgabe565Verified publisher0.17.01 of 1See more

healthchecks gabe565 0.17.0

1 of the 1 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
mariadb@11.4.5-r0
11.4.11-r0

Open the chart page →

2,286
coreinstill-aiOfficialVerified publisher0.1.751 of 15See more

core instill-ai 0.1.75

1 of the 15 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.28cfde8170c92f
mariadb@11.4.9-r0
11.4.11-r0

Open the chart page →

30,816
mysqldumpkokuwa7.0.31 of 1See more

mysqldump kokuwa 7.0.3

1 of the 1 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
ghcr.io/kokuwaio/gcloud-mysql:v3.2.1963098135c550
mariadb@10.11.16-r0
10.11.17-r0

Open the chart page →

847
dbrepodbrepo1.13.32 of 25See more

dbrepo dbrepo 1.13.3

2 of the 25 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
mysql-client@10.11.10-0
10.6.26
bitnamilegacy/mariadb:11.4.5-debian-12-r128bc50a0961a7
mariadb@11.4.5-2
10.6.26

Open the chart page →

52,635
akauntingf3k-techVerified publisher1.3121.01 of 4See more

akaunting f3k-tech 1.3121.0

1 of the 4 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:latestbbd4e17f1ef8
mariadb@11.8.2-0
10.6.26

Open the chart page →

4,333
leantimegissilabs1.3.01 of 2See more

leantime gissilabs 1.3.0

1 of the 2 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
leantime/leantime:3.3.3ad4bfb0699d3
mariadb@10.11.10-r0
10.11.17-r0

Open the chart page →

6,416
photoprismmmontesVerified publisher0.14.01 of 1See more

photoprism mmontes 0.14.0

1 of the 1 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
photoprism/photoprism:251130db16ee6b1ba3
mariadb@1:11.8.3-1build1
no fix listed

Open the chart page →

11,103
phpipamphpipam-helmVerified publisher1.0.122 of 3See more

phpipam phpipam-helm 1.0.12

2 of the 3 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
phpipam/phpipam-cron:v1.7.354468713454e
mariadb@10.11.10-r0
10.11.17-r0
phpipam/phpipam-www:v1.7.3ace0efd24830
mariadb@10.11.10-r0
10.11.17-r0

Open the chart page →

3,778
dev-feedrm3lVerified publisher3.1.21 of 3See more

dev-feed rm3l 3.1.2

1 of the 3 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
mariadb@11.4.3-0
10.6.26

Open the chart page →

9,837
kimai2robjuz5.0.131 of 2See more

kimai2 robjuz 5.0.13

1 of the 2 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:10.6.12-debian-11-r1678847062532a
mariadb@10.6.12-3
10.6.26

Open the chart page →

4,693
appwriteappwrite-helmVerified publisher1.3.21 of 8See more

appwrite appwrite-helm 1.3.2

1 of the 8 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
mariadb@10.6.12-2
10.6.26

Open the chart page →

9,847
temporalcastaiVerified publisher0.54.21 of 14See more

temporal castai 0.54.2

1 of the 14 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.26.237e2e33dbd7b
mariadb@10.11.8-r0
10.11.17-r0

Open the chart page →

16,198
mariadbcowboysysopVerified publisher20.4.21 of 1See more

mariadb cowboysysop 20.4.2

1 of the 1 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
mariadb@11.4.5-2
10.6.26

Open the chart page →

3,009
equizequiz0.0.11 of 3See more

equiz equiz 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
mysql-client@10.6.11-1
10.6.26

Open the chart page →

7,541
equizequiz-chart0.0.11 of 3See more

equiz equiz-chart 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
yzhou442/equiz:latesta3f7ca69e28d
mysql-client@10.6.11-1
10.6.26

Open the chart page →

7,541
borgmaticgabe565Verified publisher0.10.11 of 1See more

borgmatic gabe565 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
mariadb@11.4.4-r1
11.4.11-r0

Open the chart page →

2,438
moodlemoodle1.0.31 of 2See more

moodle moodle 1.0.3

1 of the 2 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
cloudtooling/moodle:5.2.3f4f04e0fc401
mysql-client@12.3.2-1
10.6.26

Open the chart page →

3,954
cmsmsoleds-helm-chartsVerified publisher0.1.61 of 1See more

cmsms oleds-helm-charts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
bitnamilegacy/mariadb:11.4.7-debian-12-r290dc6acb7b2e
mariadb@11.4.7-0
10.6.26

Open the chart page →

2,838
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-44170.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
mariadb@11.4.5-r2
11.4.11-r0

Open the chart page →

14,983

Container images carrying it

23 by charts deploying them

A fixed version is listed for 4 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/mariadb:11.4.5-debian-12-r933ce23601fc9
mariadb@11.4.5-2
10.6.26
2
yzhou442/equiz:latesta3f7ca69e28d
mysql-client@10.6.11-1
10.6.26
2
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
mysql-client@10.11.10-0
10.6.26
1
bitnamilegacy/mariadb:10.6.12-debian-11-r1315edb5643b73
mariadb@10.6.12-2
10.6.26
1
bitnamilegacy/mariadb:10.6.12-debian-11-r1678847062532a
mariadb@10.6.12-3
10.6.26
1
bitnamilegacy/mariadb:11.4.3-debian-12-r08b3778160e34
mariadb@11.4.3-0
10.6.26
1
bitnamilegacy/mariadb:11.4.5-debian-12-r128bc50a0961a7
mariadb@11.4.5-2
10.6.26
1
bitnamilegacy/mariadb:11.4.7-debian-12-r290dc6acb7b2e
mariadb@11.4.7-0
10.6.26
1
bitnamilegacy/mariadb:latestbbd4e17f1ef8
mariadb@11.8.2-0
10.6.26
1
cloudtooling/moodle:5.2.3f4f04e0fc401
mysql-client@12.3.2-1
10.6.26
1
leantime/leantime:3.3.3ad4bfb0699d3
mariadb@10.11.10-r0
10.11.17-r0
1
netrisai/mariadb:10.11.4-debian-11-r460aa742a0b906
mariadb@10.11.4-1
MariaDB@10.11.4
10.6.26
10.6.26
1
photoprism/photoprism:251130db16ee6b1ba3
mariadb@1:11.8.3-1build1
no fix listed
1
phpipam/phpipam-cron:v1.7.354468713454e
mariadb@10.11.10-r0
10.11.17-r0
1
phpipam/phpipam-www:v1.7.3ace0efd24830
mariadb@10.11.10-r0
10.11.17-r0
1
semaphoreui/semaphore:v2.18.3e9260bfa8255
mariadb@11.4.10-r0
11.4.11-r0
1
temporalio/admin-tools:1.26.237e2e33dbd7b
mariadb@10.11.8-r0
10.11.17-r0
1
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
mariadb@11.4.5-r2
11.4.11-r0
1
temporalio/admin-tools:1.28cfde8170c92f
mariadb@11.4.9-r0
11.4.11-r0
1
ghcr.io/borgmatic-collective/borgmatic:1.9.9835b72878606
mariadb@11.4.4-r1
11.4.11-r0
1
ghcr.io/kokuwaio/gcloud-mysql:v3.2.1963098135c550
mariadb@10.11.16-r0
10.11.17-r0
1
ghcr.io/linuxserver/bookstack:version-v24.12.1cc795b254b73
mariadb@11.4.5-r0
11.4.11-r0
1
ghcr.io/linuxserver/healthchecks:version-v3.9b5c6bfb00b03
mariadb@11.4.5-r0
11.4.11-r0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.