StackRadar

CVE-2026-44283

Medium

Advisory

Published 7 May 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.002
13th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
126
of 17,781 indexed, latest versions
Container images
107
deployed by those charts
Fix available
3 of 3
affected packages

etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks

Carried by container images the latest versions of 126 of 17,781 indexed charts deploy, on 107 images.

Affected packageAffected versionsFixed inImages
etcdbitnami3.5.7-0, 3.6.1-1, 3.6.4-03.4.444
go.etcd.io/etcd/server/v3golangv3.5.5, v3.5.6, v3.5.7, v3.5.9+8 more3.5.3024
go.etcd.io/etcdgolangv0.0.0-20190215181705-784daa04988c, v0.0.0-20190228193606-a943ad0ee4c9, v0.0.0-20191023171146-3cf2f69b5738, v0.0.0-20200401174654-e694b7bb0875+14 more3.4.4479
OSV records
BIT-etcd-2026-44283GHSA-x35m-3gp4-4fh5GO-2026-5736

Charts affected

126 by stars
ChartLatestAffected imagesRadar Score
voltha-stackopencord2.14.04 of 4See more

voltha-stack opencord 2.14.0

4 of the 4 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
voltha/voltha-ofagent-go:2.1.68feb9ef89e97
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44
voltha/voltha-openolt-adapter:4.5.16d6d79c08350a
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44
voltha/voltha-openonu-adapter-go:2.12.25d8f2eb5f2a7e
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44
voltha/voltha-rw-core:3.4.87a325316fe59
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44

Open the chart page →

5,539
harikubeopenshift0.16.31 of 3See more

harikube openshift 0.16.3

1 of the 3 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
go.etcd.io/etcd/server/v3@v3.6.5
3.5.30

Open the chart page →

2,525
kubedb-certifiedopenshift2026.7.102 of 8See more

kubedb-certified openshift 2026.7.10

2 of the 8 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
ghcr.io/kubedb/kubedb-ops-manager:v0.53.06d4c9fe66e4f
go.etcd.io/etcd/server/v3@v3.6.4
3.5.30
ghcr.io/kubedb/kubedb-provisioner:v0.66.0824d6d78d451
go.etcd.io/etcd/server/v3@v3.6.4
3.5.30

Open the chart page →

4,016
opscruiseopenshift0.35.1002 of 11See more

opscruise openshift 0.35.100

2 of the 11 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
grafana/loki:2.0.077e138f81a8e
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200520232829-54ba9589114f
3.4.44
grafana/promtail:2.0.05fd12edcc694
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200520232829-54ba9589114f
3.4.44

Open the chart page →

8,201
scaleway-webhookparticuleio0.0.11 of 1See more

scaleway-webhook particuleio 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.4.44

Open the chart page →

2,347
loki-stackphntom2.10.22 of 2See more

loki-stack phntom 2.10.2

2 of the 2 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
grafana/loki:2.4.2b3af8ead67d7
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44
grafana/promtail:2.4.2626900031c4e
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44

Open the chart page →

5,708
npre-essentialsphntom0.1.601 of 22See more

npre-essentials phntom 0.1.60

1 of the 22 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
grafana/loki:2.6.11ee60f980950
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44

Open the chart page →

26,840
loki-stackpyalive-cdmswebappVerified publisher2.6.52 of 4See more

loki-stack pyalive-cdmswebapp 2.6.5

2 of the 4 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
grafana/loki:2.5.0f9ef133793af
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44
grafana/promtail:2.4.2626900031c4e
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44

Open the chart page →

6,525
ansible-automation-platformredhat-cop0.0.91 of 1See more

ansible-automation-platform redhat-cop 0.0.9

1 of the 1 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.4.44

Open the chart page →

15,291
argocd-operatorredhat-cop1.2.21 of 1See more

argocd-operator redhat-cop 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.7464a3af4dfe0
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.4.44

Open the chart page →

15,291
ploigosredhat-cop0.0.91 of 2See more

ploigos redhat-cop 0.0.9

1 of the 2 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
quay.io/openshift/origin-cli:4.66722d5041b47
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.4.44

Open the chart page →

11,437
argocdromholdings1.8.11 of 3See more

argocd romholdings 1.8.1

1 of the 3 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
quay.io/dexidp/dex:v2.25.07bcf286807b8
go.etcd.io/etcd@v0.0.0-20191023171146-3cf2f69b5738
3.4.44

Open the chart page →

10,466
calicoromholdings0.1.13 of 4See more

calico romholdings 0.1.1

3 of the 4 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
quay.io/devtron/calico-networking:kube-controllers-v3.19.12ff71ba65cd7
go.etcd.io/etcd@v0.5.0-alpha.5.0.20201125193152-8a03d2e9614b
3.4.44
quay.io/devtron/calico-networking:cni-v3.19.151f294c56842
go.etcd.io/etcd@v0.5.0-alpha.5.0.20201125193152-8a03d2e9614b
3.4.44
quay.io/devtron/calico-networking:node-v3.19.1bc4aa22272ef
go.etcd.io/etcd@v0.5.0-alpha.5.0.20201125193152-8a03d2e9614b
3.4.44

Open the chart page →

10,071
dgraphromholdings0.0.201 of 1See more

dgraph romholdings 0.0.20

1 of the 1 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
dgraph/dgraph:v21.12.03b55ea83fffe
go.etcd.io/etcd@v0.0.0-20190228193606-a943ad0ee4c9
3.4.44

Open the chart page →

11,909
teamcitysinextraVerified publisher1.0.21 of 3See more

teamcity sinextra 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
library/docker:26.1-dinddd43b430341a
go.etcd.io/etcd/server/v3@v3.5.6
3.5.30

Open the chart page →

2,429
vaultstakaterVerified publisher0.8.41 of 2See more

vault stakater 0.8.4

1 of the 2 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
hashicorp/vault:1.8.4dfc3500beb0e
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200425165423-262c93980547
3.4.44

Open the chart page →

5,864
scaleway-webhooksudaVerified publisher0.0.21 of 1See more

scaleway-webhook suda 0.0.2

1 of the 1 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
scaleway/cert-manager-webhook-scaleway:v0.0.1dcc14608d000
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.4.44

Open the chart page →

2,347
lokit3n1.0.01 of 1See more

loki t3n 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
grafana/loki:1.5.0922b3f412fdd
go.etcd.io/etcd@v0.0.0-20200401174654-e694b7bb0875
3.4.44

Open the chart page →

2,869
monitoringthl-chartsVerified publisher0.1.12 of 10See more

monitoring thl-charts 0.1.1

2 of the 10 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
grafana/loki:2.5.0f9ef133793af
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44
grafana/promtail:2.4.2626900031c4e
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44

Open the chart page →

18,908
vineyard-operatorvineyardVerified publisher0.24.21 of 2See more

vineyard-operator vineyard 0.24.2

1 of the 2 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.4.44

Open the chart page →

4,525
cert-manager-webhook-vultrvultrVerified publisher1.0.01 of 1See more

cert-manager-webhook-vultr vultr 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.4.44

Open the chart page →

2,500
apisixwenerme2.17.01 of 3See more

apisix wenerme 2.17.0

1 of the 3 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
bitnamilegacy/etcd:latest99b408c15272
etcd@3.6.1-1
3.4.44

Open the chart page →

3,045
athens-proxywenerme0.5.21 of 2See more

athens-proxy wenerme 0.5.2

1 of the 2 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
gomods/athens:v0.11.0efb811df7844
go.etcd.io/etcd@v0.0.0-20190215181705-784daa04988c
3.4.44

Open the chart page →

4,984
juicefs-csi-driverwenerme0.32.51 of 5See more

juicefs-csi-driver wenerme 0.32.5

1 of the 5 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
juicedata/juicefs-csi-driver:v0.32.595008ba63318
go.etcd.io/etcd@v3.3.27+incompatible
3.4.44

Open the chart page →

9,117
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
go.etcd.io/etcd@v0.0.0-20201125193152-8a03d2e9614b
3.4.44

Open the chart page →

6,915
traefikwenerme9.1.11 of 1See more

traefik wenerme 9.1.1

1 of the 1 container images this version deploys carry CVE-2026-44283.

Container imageDigestPackageFixed in
library/traefik:2.2.8f5af5a5ce17f
go.etcd.io/etcd@v3.3.13+incompatible
3.4.44

Open the chart page →

3,369

Container images carrying it

107 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
grafana/promtail:2.0.05fd12edcc694
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200520232829-54ba9589114f
3.4.44
1
hashicorp/vault:1.8.4dfc3500beb0e
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200425165423-262c93980547
3.4.44
1
hbahadorzadeh/cert-manager-webhook-arvan:latestbf9756b3bc47
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.4.44
1
hyperledger/fabric-orderer:2.2.137294e05209b
go.etcd.io/etcd@v0.5.0-alpha.5.0.20181228115726-23731bf9ba55
3.4.44
1
instill/artifact-backend:b28766ac4a393e601ed
go.etcd.io/etcd/server/v3@v3.5.5
3.5.30
1
iomesh/operator:v1.1.060081c9b2f52
go.etcd.io/etcd@v0.5.0-alpha.5.0.20231101163153-1eb276c33dd7
3.4.44
1
iomesh/operator:v1.2.0ba4dd6be7e59
go.etcd.io/etcd@v0.5.0-alpha.5.0.20231101163153-1eb276c33dd7
3.4.44
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
go.etcd.io/etcd@v3.3.27+incompatible
3.4.44
1
juicedata/juicefs-csi-driver:v0.32.595008ba63318
go.etcd.io/etcd@v3.3.27+incompatible
3.4.44
1
kiosksh/kiosk:0.2.11501725ba2025
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.4.44
1
kubedb/kubedb-enterprise:v0.11.05829bcedcb0d
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.4.44
1
kubedb/kubedb-ui-server:v0.0.1_linux_amd647d27865514ee
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.4.44
1
kubedb/operator:v0.24.01a06ff0bda52
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.4.44
1
library/docker:28.5.2-dind2a232a42256f
go.etcd.io/etcd/server/v3@v3.5.16
3.5.30
1
library/docker:27-dindaa3df78ecf32
go.etcd.io/etcd/server/v3@v3.5.6
3.5.30
1
library/docker:26.1-dinddd43b430341a
go.etcd.io/etcd/server/v3@v3.5.6
3.5.30
1
library/traefik:2.4.8eda951fd29a8
go.etcd.io/etcd@v3.3.13+incompatible
3.4.44
1
library/traefik:2.2.8f5af5a5ce17f
go.etcd.io/etcd@v3.3.13+incompatible
3.4.44
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.4.44
1
loftsh/virtual-cluster:0.0.28023b13bf5898
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.4.44
1
megaease/easegress:latestfad1c7452958
go.etcd.io/etcd/server/v3@v3.5.27
3.5.30
1
mesosphere/kommander-federation-authorizedlister:v0.21.263bc411b930b
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.4.44
1
mesosphere/kommander-federation-controller-manager:v0.21.2b036785a8862
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.4.44
1
mesosphere/kommander-federation-webhook:v0.21.294af41b6dd9a
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.4.44
1
mesosphere/kubefed:proxyurl4fd8889195fe
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.4.44
1
milvusdb/etcd:3.5.5-r2102aac62827b
etcd@3.5.7-0
3.4.44
1
milvusdb/etcd:3.5.25-r1fededb2f2d63
etcd@3.5.7-0
3.4.44
1
milvusdb/milvus:v2.2.13a3a55e1c1497
go.etcd.io/etcd/server/v3@v3.5.5
3.5.30
1
minio/mc:RELEASE.2021-02-14T04-28-06Z2a374c124d44
go.etcd.io/etcd@v0.0.0-20201125193152-8a03d2e9614b
3.4.44
1
otel/opentelemetry-collector-contrib:0.63.1dfb3a55ea8c9
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44
1
sorintlab/stolon:v0.16.0-pg1236b45c0f97fc
go.etcd.io/etcd@v0.0.0-20191023171146-3cf2f69b5738
3.4.44
1
thanosio/thanos:v0.15.0b12d5c31bf5a
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200520232829-54ba9589114f
3.4.44
1
thesisrobot/lnd:v0.16.4-beta-c287129953689
go.etcd.io/etcd/server/v3@v3.5.7
3.5.30
1
thmmniii/fbs-runner:v1.27.186105349c1a3
go.etcd.io/etcd/server/v3@v3.5.6
3.5.30
1
traefik/traefikee:v2.12.10acc7fcca5f1c
go.etcd.io/etcd/server/v3@v3.6.5
3.5.30
1
vineyardcloudnative/vineyard-operator:latest9d419aa18faa
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.4.44
1
vultr/cert-manager-webhook-vultr:v0.1.0541c3e0aec58
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200819165624-17cef6e3e9d5
3.4.44
1
vultr/vultr-cloud-controller-manager:v0.3.01806f17d620c
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.4.44
1
ghcr.io/comet-ml/opik/opik-python-backend:2.2.59269d0e55ea97
go.etcd.io/etcd/server/v3@v3.6.6
3.5.30
1
ghcr.io/dapr/scheduler:1.17.0-rc.36c62e01e736b
go.etcd.io/etcd/server/v3@v3.5.21
3.5.30
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
go.etcd.io/etcd@v3.3.27+incompatible
3.4.44
1
ghcr.io/kluster-manager/multicluster-controlplane:latest6de40f528be9
go.etcd.io/etcd/server/v3@v3.5.10
3.5.30
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
go.etcd.io/etcd/server/v3@v3.5.6
3.5.30
1
ghcr.io/loft-sh/kubernetes:v1.35.090097a08b87c
go.etcd.io/etcd/server/v3@v3.6.7
3.5.30
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
go.etcd.io/etcd/server/v3@v3.5.6
3.5.30
1
ghcr.io/luisico/cert-manager-webhook-infoblox-wapi:1.5ded797477896
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200910180754-dd1b699fc489
3.4.44
1
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
go.etcd.io/etcd@v3.3.25+incompatible
3.4.44
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
go.etcd.io/etcd@v0.5.0-alpha.5.0.20210428180535-15715dcf1ace
3.4.44
1
quay.io/cortexproject/cortex:v1.9.05d1c2cf4c538
go.etcd.io/etcd@v0.5.0-alpha.5.0.20200520232829-54ba9589114f
3.4.44
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
go.etcd.io/etcd/server/v3@v3.6.5
3.5.30
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.