StackRadar

CVE-2026-44705

High

Advisory

Published 27 May 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
178
of 17,781 indexed, latest versions
Container images
174
deployed by those charts
Fix available
1 of 1
affected package

tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape

Carried by container images the latest versions of 178 of 17,781 indexed charts deploy, on 174 images.

Affected packageAffected versionsFixed inImages
tmpnpm0.0.23, 0.0.28, 0.0.29, 0.0.30+6 more0.2.6174
OSV records
GHSA-ph9p-34f9-6g65

Charts affected

178 by stars
ChartLatestAffected imagesRadar Score
dltkvassist-iot-data-integrity-verification0.2.01 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

1 of the 9 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
tmp@0.2.1
0.2.6

Open the chart page →

77,706
dltflassist-iot-dlt-based-fl0.2.01 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

1 of the 9 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.1.0c8a170683be7
tmp@0.2.1
0.2.6

Open the chart page →

77,706
fl-orchestrator-guiassist-iot-fl-orchestrator0.1.01 of 3See more

fl-orchestrator-gui assist-iot-fl-orchestrator 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
assistiot/fl_orchestrator:api-latest7473d77448e1
tmp@0.0.33
0.2.6

Open the chart page →

9,369
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
assistiot/open_api_frontend:1.0.1f11d82defc70
tmp@0.0.33
0.2.6
pantsel/konga:latestc8172b75607d
tmp@0.0.28
0.2.6

Open the chart page →

18,277
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
tmp@0.2.1
0.2.6
assistiot/smart-orchestrator_enabler:latest89f37e88c871
tmp@0.2.1
0.2.6
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
tmp@0.2.1
0.2.6

Open the chart page →

45,363
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ltdstudio/terraforming-mars:latest0e76c6f4eac0
tmp@0.0.33
0.2.6

Open the chart page →

7,152
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
tmp@0.0.33
0.2.6

Open the chart page →

4,455
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
tmp@0.0.33
0.2.6
sysnet4admin/colosseum-prm:log5802bfcd7fed
tmp@0.0.33
0.2.6

Open the chart page →

26,996
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
tmp@0.0.23
0.2.6

Open the chart page →

4,069
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
tmp@0.2.1
0.2.6

Open the chart page →

7,405
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
tmp@0.0.33
0.2.6

Open the chart page →

4,083
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
tmp@0.2.3
0.2.6

Open the chart page →

2,759
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
tmp@0.0.33
0.2.6

Open the chart page →

29,901
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
tmp@0.0.33
0.2.6

Open the chart page →

2,580
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
tmp@0.0.33
0.2.6

Open the chart page →

77,758
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
tmp@0.0.33
0.2.6

Open the chart page →

25,456
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad2 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

2 of the 6 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
tmp@0.2.5
0.2.6
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
tmp@0.2.5
0.2.6

Open the chart page →

18,293
coderstudio-strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

coderstudio-strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
tmp@0.0.33
0.2.6

Open the chart page →

5,141
docker-composecoderstudio-strapi-devVerified publisher0.0.11 of 3See more

docker-compose coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
tmp@0.0.33
0.2.6

Open the chart page →

5,141
strapi-devcoderstudio-strapi-devVerified publisher0.0.11 of 3See more

strapi-dev coderstudio-strapi-dev 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
rcdelacruz/my-strapi-app:js-amd6438007f358355
tmp@0.0.33
0.2.6

Open the chart page →

5,141
containers-security-chartscontainers-security0.1.01 of 7See more

containers-security-charts containers-security 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
coldatom/containers-security-api:latesteae9e82da080
tmp@0.2.1
0.2.6

Open the chart page →

9,146
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
tmp@0.2.3
0.2.6

Open the chart page →

14,559
quickchartcowboysysopVerified publisher5.0.01 of 1See more

quickchart cowboysysop 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ianw/quickchart:v1.7.1dc49dd460c37
tmp@0.0.33
0.2.6

Open the chart page →

5,488
kongacreate-databases0.1.01 of 1See more

konga create-databases 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
tmp@0.0.28
0.2.6

Open the chart page →

5,209
wazuhcsic-charts0.1.01 of 4See more

wazuh csic-charts 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.4.11787550d2358
tmp@0.2.1
0.2.6

Open the chart page →

13,852
db-operatordb-operatorVerified publisher0.1.01 of 1See more

db-operator db-operator 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
plumdog/db-operator:latest0c2fa2db0357
tmp@0.2.1
0.2.6

Open the chart page →

3,042
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
tmp@0.0.33
0.2.6

Open the chart page →

4,551
documensodocumensoVerified publisher0.0.61 of 2See more

documenso documenso 0.0.6

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
documenso/documenso:v1.8.17f16a9449f18
tmp@0.2.1
0.2.6

Open the chart page →

2,862
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
tmp@0.0.33
0.2.6

Open the chart page →

11,174
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
tmp@0.2.1
0.2.6

Open the chart page →

27,096
blockscoutethereum-helm-chartsVerified publisher0.2.31 of 2See more

blockscout ethereum-helm-charts 0.2.3

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
blockscout/blockscout:5.1.5c365a8f2dc12
tmp@0.0.33
0.2.6

Open the chart page →

1,928
lodestarethereum-helm-chartsVerified publisher1.2.21 of 2See more

lodestar ethereum-helm-charts 1.2.2

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
chainsafe/lodestar:latest5593f6e97912
tmp@0.0.33
0.2.6

Open the chart page →

2,522
bee-localchainethersphereVerified publisher0.2.01 of 1See more

bee-localchain ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
tmp@0.0.33
0.2.6

Open the chart page →

2,266
bzz-token-serviceethersphereVerified publisher0.2.01 of 1See more

bzz-token-service ethersphere 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ethersphere/bzz-token-service:latest7624f11a72ad
tmp@0.0.33
0.2.6

Open the chart page →

3,260
geth-swapethersphereVerified publisher0.6.31 of 2See more

geth-swap ethersphere 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ethersphere/bee-localchain:latest0558799ca992
tmp@0.0.33
0.2.6

Open the chart page →

4,756
smeejasfanzynoodle0.0.11 of 1See more

smeejas fanzynoodle 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
fanzynoodle/smeejas:0.0.15f9916c1a287
tmp@0.2.1
0.2.6

Open the chart page →

4,127
flamegabe565Verified publisher0.6.01 of 1See more

flame gabe565 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
pawelmalak/flame:multiarch2.3.19f88b17692a0
tmp@0.2.1
0.2.6

Open the chart page →

2,172
wekan-oldgabisonfire0.1.21 of 1See more

wekan-old gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
wekanteam/wekan:v4.2268a51f0327df
tmp@0.0.33
0.2.6

Open the chart page →

5,941
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
tmp@0.0.33
0.2.6

Open the chart page →

9,019
qryn-helmgigapipeVerified publisher0.1.91 of 1See more

qryn-helm gigapipe 0.1.9

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
qxip/qryn:3.2.3977acc9c7a9fd
tmp@0.0.33
0.2.6

Open the chart page →

2,973
Governify-Bluejaygovernify0.1.04 of 12See more

Governify-Bluejay governify 0.1.0

4 of the 12 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
tmp@0.0.33
0.2.6
governify/registry:v3.4.0d3f37f4f8168
tmp@0.2.1
0.2.6
governify/render:v2.2.0daeca1ce28e6
tmp@0.0.33
0.2.6
governify/reporter:v2.2.038595913458f
tmp@0.0.33
0.2.6

Open the chart page →

22,512
Governify-Falcongovernify0.1.05 of 10See more

Governify-Falcon governify 0.1.0

5 of the 10 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
tmp@0.0.33
0.2.6
governify/collector-dynamic:v1.3.06d3d1a5b46a9
tmp@0.2.1
0.2.6
governify/registry:v3.4.0d3f37f4f8168
tmp@0.2.1
0.2.6
governify/render:v2.2.0daeca1ce28e6
tmp@0.0.33
0.2.6
governify/reporter:v2.2.038595913458f
tmp@0.0.33
0.2.6

Open the chart page →

24,319
opentelemetry-demogpg-dev0.33.81 of 27See more

opentelemetry-demo gpg-dev 0.33.8

1 of the 27 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
tmp@0.2.3
0.2.6

Open the chart page →

49,025
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
tmp@0.2.1
0.2.6

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
tmp@0.2.1
0.2.6

Open the chart page →

2,682
irslackdhalkeye0.1.01 of 1See more

irslackd halkeye 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
halkeye/irslackd:latest7638bfba70b0
tmp@0.0.33
0.2.6

Open the chart page →

2,064
streamsheetshelm-chartsVerified publisher0.2.34 of 8See more

streamsheets helm-charts 0.2.3

4 of the 8 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
tmp@0.1.0
0.2.6
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
tmp@0.0.33
0.2.6
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
tmp@0.1.0
0.2.6
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
tmp@0.1.0
0.2.6

Open the chart page →

89,959
backstagehelm-charts-nr0.1.151 of 2See more

backstage helm-charts-nr 0.1.15

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
tmp@0.2.1
0.2.6

Open the chart page →

8,213
openbashelm-openbasVerified publisher1.8.141 of 7See more

openbas helm-openbas 1.8.14

1 of the 7 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
openbas/caldera-server:5.1.0a277796d9724
tmp@0.0.33
0.2.6

Open the chart page →

25,017
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
tmp@0.0.33
0.2.6

Open the chart page →

32,915

Container images carrying it

174 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/data-fair/notify:3c739b74dabb0
tmp@0.0.33
0.2.6
1
ghcr.io/data-fair/portals:18b621866ceb2
tmp@0.0.33
0.2.6
1
ghcr.io/data-fair/processings:15a9216989707
tmp@0.0.33
0.2.6
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
tmp@0.0.33
0.2.6
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
tmp@0.2.5
0.2.6
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
tmp@0.2.5
0.2.6
1
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
tmp@0.2.3
0.2.6
1
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
tmp@0.0.33
0.2.6
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
tmp@0.0.33
0.2.6
1
ghcr.io/middleware-labs/odigos-ui:middleware-test-0.0.787120a4561a9
tmp@0.2.1
0.2.6
1
ghcr.io/middleware-labs/vision-ui:middleware-test-0.0.853772b7b42c7
tmp@0.2.1
0.2.6
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
tmp@0.2.3
0.2.6
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
tmp@0.0.33
0.2.6
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
tmp@0.0.33
0.2.6
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
tmp@0.2.5
0.2.6
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
tmp@0.2.3
0.2.6
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
tmp@0.0.33
0.2.6
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
tmp@0.2.1
0.2.6
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
tmp@0.0.28
0.2.6
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
tmp@0.0.33
0.2.6
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
tmp@0.0.33
0.2.6
1
quay.io/netwarps/blockscoutbecd3e39360a
tmp@0.0.33
0.2.6
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
tmp@0.2.1
0.2.6
1
quay.io/wekan/wekan:v5.65cb17600883a3
tmp@0.0.33
0.2.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.