StackRadar

CVE-2026-44705

High

Advisory

Published 27 May 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
178
of 17,781 indexed, latest versions
Container images
174
deployed by those charts
Fix available
1 of 1
affected package

tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape

Carried by container images the latest versions of 178 of 17,781 indexed charts deploy, on 174 images.

Affected packageAffected versionsFixed inImages
tmpnpm0.0.23, 0.0.28, 0.0.29, 0.0.30+6 more0.2.6174
OSV records
GHSA-ph9p-34f9-6g65

Charts affected

178 by stars
ChartLatestAffected imagesRadar Score
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
tmp@0.0.33
0.2.6

Open the chart page →

16,620
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
tmp@0.0.33
0.2.6

Open the chart page →

5,582
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
tmp@0.0.33
0.2.6

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
tmp@0.0.33
0.2.6

Open the chart page →

3,638
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
tmp@0.2.3
0.2.6

Open the chart page →

5,497
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
tmp@0.0.33
0.2.6

Open the chart page →

3,143
skoonerskooner0.2.21 of 1See more

skooner skooner 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
tmp@0.2.1
0.2.6

Open the chart page →

1,341
k8soketisoketi1.0.11 of 1See more

k8soketi soketi 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
tmp@0.2.1
0.2.6

Open the chart page →

2,267
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
tmp@0.0.33
0.2.6

Open the chart page →

2,121
alert-mappersomeblackmagic0.2.01 of 1See more

alert-mapper someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
someblackmagic/alert-mapper:v0.1.088351d85c04c
tmp@0.0.33
0.2.6

Open the chart page →

1,890
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
tmp@0.2.3
0.2.6

Open the chart page →

1,313
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
tmp@0.2.1
0.2.6

Open the chart page →

4,052
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
tmp@0.0.33
0.2.6

Open the chart page →

3,881
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
tmp@0.0.33
0.2.6

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
tmp@0.0.33
0.2.6

Open the chart page →

919
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
tmp@0.0.28
0.2.6

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
tmp@0.0.28
0.2.6

Open the chart page →

12,460
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
tmp@0.2.1
0.2.6

Open the chart page →

3,576
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-44705.

Open the chart page →

17,323
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
tmp@0.0.33
0.2.6

Open the chart page →

3,746
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
tmp@0.2.1
0.2.6

Open the chart page →

3,129
skoonervhdirkVerified publisher0.1.41 of 1See more

skooner vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
tmp@0.2.1
0.2.6

Open the chart page →

1,341
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
tmp@0.0.33
0.2.6

Open the chart page →

5,984
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
tmp@0.2.3
0.2.6

Open the chart page →

5,484
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
tmp@0.2.5
0.2.6

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
tmp@0.0.33
0.2.6

Open the chart page →

6,285
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
tmp@0.2.1
0.2.6

Open the chart page →

1,752
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
tmp@0.2.1
0.2.6

Open the chart page →

9,381

Container images carrying it

174 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
obolnetwork/charon-dkg-sidecar:maine263be0a7440
tmp@0.2.1
0.2.6
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
tmp@0.0.33
0.2.6
1
openbas/caldera-server:5.1.0a277796d9724
tmp@0.0.33
0.2.6
1
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
tmp@0.2.1
0.2.6
1
opensearchproject/opensearch-dashboards:2.10.0485a0019e5d6
tmp@0.2.1
0.2.6
1
opensearchproject/opensearch-dashboards:2.15.0b7c26c60bfaf
tmp@0.2.1
0.2.6
1
outlinewiki/outline:0.82.0494dfb9249a6
tmp@0.0.33
0.2.6
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
tmp@0.1.0
0.2.6
1
pawelmalak/flame:2.1.193e7b0abb603
tmp@0.2.1
0.2.6
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
tmp@0.2.1
0.2.6
1
phntom/codimd:2.4.31b9aafbb62e6
tmp@0.0.33
0.2.6
1
plumdog/db-operator:latest0c2fa2db0357
tmp@0.2.1
0.2.6
1
qxip/qryn:3.2.3977acc9c7a9fd
tmp@0.0.33
0.2.6
1
roadiehq/community-backstage-image:latestef355bf5b639
tmp@0.0.33
0.2.6
1
safeglobal/safe-client-gateway-nest:v1.51.012ccfd93fcaf
tmp@0.0.33
0.2.6
1
sharanalwar/redchef-frontend:latest5e82950b16b7
tmp@0.2.3
0.2.6
1
sigp/siren:v3.0.42c219b04758e
tmp@0.0.33
0.2.6
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
tmp@0.0.33
0.2.6
1
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
tmp@0.0.33
0.2.6
1
someblackmagic/alert-mapper:v0.1.088351d85c04c
tmp@0.0.33
0.2.6
1
stanfordoval/almond-server:latest1a63cdccedaf
tmp@0.2.1
0.2.6
1
sysnet4admin/colosseum-cms:loge74b43c7f492
tmp@0.0.33
0.2.6
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
tmp@0.0.33
0.2.6
1
testhubio/testhub-frontend:on-preme86c2db53be8
tmp@0.0.33
0.2.6
1
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
tmp@0.0.33
0.2.6
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
tmp@0.2.1
0.2.6
1
vabene1111/recipes:1.0.5.2ec4e9e2905b0
tmp@0.0.33
0.2.6
1
visualregressiontracker/api:5.0.11941aeb8c8bf9
tmp@0.0.33
0.2.6
1
wazuh/wazuh-dashboard:4.11.10c58e7b47bb6
tmp@0.2.1
0.2.6
1
wazuh/wazuh-dashboard:4.4.11787550d2358
tmp@0.2.1
0.2.6
1
wazuh/wazuh-dashboard:4.14.491c8d793746f
tmp@0.2.3
0.2.6
1
wazuh/wazuh-dashboard:4.14.391e4f0a7feed
tmp@0.2.3
0.2.6
1
wekanteam/wekan:v4.2268a51f0327df
tmp@0.0.33
0.2.6
1
wiremind/scrapoxy:lateste7048929a676
tmp@0.0.33
0.2.6
1
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
tmp@0.0.33
0.2.6
1
ymuski/skooner:latest67819ca511b5
tmp@0.2.1
0.2.6
1
zooz/predator:1.6f491d1f7a865
tmp@0.0.28
0.2.6
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
tmp@0.0.33
0.2.6
1
ghcr.io/adnoctem/lhci:1.0.119553e4b4033
tmp@0.0.33
0.2.6
1
ghcr.io/antoniolago/vaultwarden-kubernetes-secrets:0.0.0-main13e267ad7d94
tmp@0.0.33
0.2.6
1
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
tmp@0.2.3
0.2.6
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
tmp@0.2.3
0.2.6
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
tmp@0.1.0
0.2.6
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
tmp@0.0.33
0.2.6
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
tmp@0.1.0
0.2.6
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
tmp@0.1.0
0.2.6
1
ghcr.io/curium-rocks/kube-admission-controller-starter:maine9716966f30b
tmp@0.2.1
0.2.6
1
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
tmp@0.2.1
0.2.6
1
ghcr.io/data-fair/data-fair:3cc9498b64b5b
tmp@0.1.0
0.2.6
1
ghcr.io/data-fair/metrics:0a8d40779eeae
tmp@0.0.33
0.2.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.