StackRadar

CVE-2026-44705

High

Advisory

Published 27 May 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
178
of 17,781 indexed, latest versions
Container images
174
deployed by those charts
Fix available
1 of 1
affected package

tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape

Carried by container images the latest versions of 178 of 17,781 indexed charts deploy, on 174 images.

Affected packageAffected versionsFixed inImages
tmpnpm0.0.23, 0.0.28, 0.0.29, 0.0.30+6 more0.2.6174
OSV records
GHSA-ph9p-34f9-6g65

Charts affected

178 by stars
ChartLatestAffected imagesRadar Score
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
tmp@0.0.33
0.2.6

Open the chart page →

16,620
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
tmp@0.0.33
0.2.6

Open the chart page →

5,582
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
tmp@0.0.33
0.2.6

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
tmp@0.0.33
0.2.6

Open the chart page →

3,638
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
tmp@0.2.3
0.2.6

Open the chart page →

5,497
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
tmp@0.0.33
0.2.6

Open the chart page →

3,143
skoonerskooner0.2.21 of 1See more

skooner skooner 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
tmp@0.2.1
0.2.6

Open the chart page →

1,341
k8soketisoketi1.0.11 of 1See more

k8soketi soketi 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
tmp@0.2.1
0.2.6

Open the chart page →

2,267
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
tmp@0.0.33
0.2.6

Open the chart page →

2,121
alert-mappersomeblackmagic0.2.01 of 1See more

alert-mapper someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
someblackmagic/alert-mapper:v0.1.088351d85c04c
tmp@0.0.33
0.2.6

Open the chart page →

1,890
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
tmp@0.2.3
0.2.6

Open the chart page →

1,313
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
tmp@0.2.1
0.2.6

Open the chart page →

4,052
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
tmp@0.0.33
0.2.6

Open the chart page →

3,881
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
tmp@0.0.33
0.2.6

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
tmp@0.0.33
0.2.6

Open the chart page →

919
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
tmp@0.0.28
0.2.6

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
tmp@0.0.28
0.2.6

Open the chart page →

12,460
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
tmp@0.2.1
0.2.6

Open the chart page →

3,576
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-44705.

Open the chart page →

17,323
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
tmp@0.0.33
0.2.6

Open the chart page →

3,746
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
tmp@0.2.1
0.2.6

Open the chart page →

3,129
skoonervhdirkVerified publisher0.1.41 of 1See more

skooner vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
tmp@0.2.1
0.2.6

Open the chart page →

1,341
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
tmp@0.0.33
0.2.6

Open the chart page →

5,984
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
tmp@0.2.3
0.2.6

Open the chart page →

5,484
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
tmp@0.2.5
0.2.6

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
tmp@0.0.33
0.2.6

Open the chart page →

6,285
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
tmp@0.2.1
0.2.6

Open the chart page →

1,752
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
tmp@0.2.1
0.2.6

Open the chart page →

9,381

Container images carrying it

174 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ethersphere/bzz-token-service:latest7624f11a72ad
tmp@0.0.33
0.2.6
1
ethpandaops/ethereumjs:masterfb84b718500f
tmp@0.0.33
0.2.6
1
evoapicloud/evolution-api:latest966625532d90
tmp@0.0.33
0.2.6
1
fanzynoodle/smeejas:0.0.15f9916c1a287
tmp@0.2.1
0.2.6
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
tmp@0.0.33
0.2.6
1
getferdi/ferdi-server:1.3.26e620b85afaa
tmp@0.0.33
0.2.6
1
globalping/globalping-probe:latest8acbd23009fd
tmp@0.0.33
0.2.6
1
governify/collector-dynamic:v1.3.06d3d1a5b46a9
tmp@0.2.1
0.2.6
1
gristlabs/grist:0.7.96e71b1914a7e
tmp@0.2.1
0.2.6
1
halkeye/irslackd:latest7638bfba70b0
tmp@0.0.33
0.2.6
1
heywood8/redisinsight:2.28.00bc9ab313d37
tmp@0.0.33
0.2.6
1
hkotel/mealie:frontend-v1.0.0beta-23c04c0e85039
tmp@0.0.33
0.2.6
1
hugohg34/server:0.0.2503e5d8960ff
tmp@0.2.1
0.2.6
1
ianw/quickchart:v1.7.1dc49dd460c37
tmp@0.0.33
0.2.6
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
tmp@0.0.30
0.2.6
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
tmp@0.0.33
0.2.6
1
ibmcom/microclimate-portal:latested5505e5c7ec
tmp@0.0.29
0.2.6
1
jayfong/yapi:1.10.2163e5d621910
tmp@0.0.33
0.2.6
1
konradkleine/docker-registry-frontend:v2181aad54ee64
tmp@0.0.23
0.2.6
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
tmp@0.2.1
0.2.6
1
kubebb/component-store:latestfd8ecbd73213
tmp@0.2.1
0.2.6
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
tmp@0.2.1
0.2.6
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
tmp@0.2.1
0.2.6
1
kubevious/backend:1.2.22d9ba6eb46b6
tmp@0.2.1
0.2.6
1
kubevious/parser:1.2.299ae7a5168c2
tmp@0.2.1
0.2.6
1
kyleslugg/klusterview:latestba8c36dfdfbd
tmp@0.2.1
0.2.6
1
kyso/kyso-front:lateste52595c5c16f
tmp@0.0.33
0.2.6
1
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
tmp@0.2.3
0.2.6
1
library/ghost:4.37.0767230c0f263
tmp@0.0.33
0.2.6
1
library/ghost:5.79.083f7bf209844
tmp@0.0.33
0.2.6
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
tmp@0.0.33
0.2.6
1
library/kibana:8.18.004c0fc150f3a
tmp@0.0.33
0.2.6
1
linuxserver/cloud9:latest45c5fe102ff3
tmp@0.0.33
0.2.6
1
linuxserver/codimd:latestb801bbcf6386
tmp@0.0.33
0.2.6
1
lissy93/dashy:2.0.51991f7be5ed0
tmp@0.0.33
0.2.6
1
ltdstudio/terraforming-mars:latest0e76c6f4eac0
tmp@0.0.33
0.2.6
1
lukasreining/open-api-schema-collector:0.1.050e021c42e33
tmp@0.2.1
0.2.6
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
tmp@0.0.33
0.2.6
1
mautic/mautic:7-apacheeb8cc73d97e1
tmp@0.2.5
0.2.6
1
minddocdev/hubot:0.1.96c60b11a4fa7
tmp@0.0.33
0.2.6
1
mishtinetwork/operator:latestbb3fe67a5f7c
tmp@0.0.33
0.2.6
1
misskey/misskey:12.110.1e08b7c478093
tmp@0.2.1
0.2.6
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
tmp@0.0.33
0.2.6
1
mozilla/sentencecollector:2.0.91da6ff5c4895
tmp@0.0.33
0.2.6
1
n8nio/n8n:2.25.7761374d4eb84
tmp@0.2.4
0.2.6
1
n8nio/n8n:1.86.08b39ed5a2de9
tmp@0.2.3
0.2.6
1
n8nio/n8n:0.212.0a9195bc499a3
tmp@0.2.1
0.2.6
1
n8nio/n8n:1.33.1dd171d45102a
tmp@0.0.33
0.2.6
1
nocodb/nocodb:0.258.06779a4ddedf2
tmp@0.0.33
0.2.6
1
nocodb/nocodb:0.301.5d9516f0bf546
tmp@0.2.5
0.2.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.