StackRadar

CVE-2026-44705

High

Advisory

Published 27 May 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
178
of 17,781 indexed, latest versions
Container images
174
deployed by those charts
Fix available
1 of 1
affected package

tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape

Carried by container images the latest versions of 178 of 17,781 indexed charts deploy, on 174 images.

Affected packageAffected versionsFixed inImages
tmpnpm0.0.23, 0.0.28, 0.0.29, 0.0.30+6 more0.2.6174
OSV records
GHSA-ph9p-34f9-6g65

Charts affected

178 by stars
ChartLatestAffected imagesRadar Score
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
tmp@0.0.33
0.2.6

Open the chart page →

16,620
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
tmp@0.0.33
0.2.6

Open the chart page →

5,582
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
tmp@0.0.33
0.2.6

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
tmp@0.0.33
0.2.6

Open the chart page →

3,638
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
tmp@0.2.3
0.2.6

Open the chart page →

5,497
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
tmp@0.0.33
0.2.6

Open the chart page →

3,143
skoonerskooner0.2.21 of 1See more

skooner skooner 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
tmp@0.2.1
0.2.6

Open the chart page →

1,341
k8soketisoketi1.0.11 of 1See more

k8soketi soketi 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
tmp@0.2.1
0.2.6

Open the chart page →

2,267
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
tmp@0.0.33
0.2.6

Open the chart page →

2,121
alert-mappersomeblackmagic0.2.01 of 1See more

alert-mapper someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
someblackmagic/alert-mapper:v0.1.088351d85c04c
tmp@0.0.33
0.2.6

Open the chart page →

1,890
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
tmp@0.2.3
0.2.6

Open the chart page →

1,313
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
tmp@0.2.1
0.2.6

Open the chart page →

4,052
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
tmp@0.0.33
0.2.6

Open the chart page →

3,881
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
tmp@0.0.33
0.2.6

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
tmp@0.0.33
0.2.6

Open the chart page →

919
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
tmp@0.0.28
0.2.6

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
tmp@0.0.28
0.2.6

Open the chart page →

12,460
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
tmp@0.2.1
0.2.6

Open the chart page →

3,576
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-44705.

Open the chart page →

17,323
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
tmp@0.0.33
0.2.6

Open the chart page →

3,746
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
tmp@0.2.1
0.2.6

Open the chart page →

3,129
skoonervhdirkVerified publisher0.1.41 of 1See more

skooner vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
tmp@0.2.1
0.2.6

Open the chart page →

1,341
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
tmp@0.0.33
0.2.6

Open the chart page →

5,984
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
tmp@0.2.3
0.2.6

Open the chart page →

5,484
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
tmp@0.2.5
0.2.6

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
tmp@0.0.33
0.2.6

Open the chart page →

6,285
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
tmp@0.2.1
0.2.6

Open the chart page →

1,752
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
tmp@0.2.1
0.2.6

Open the chart page →

9,381

Container images carrying it

174 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/data-fair/notify:3c739b74dabb0
tmp@0.0.33
0.2.6
1
ghcr.io/data-fair/portals:18b621866ceb2
tmp@0.0.33
0.2.6
1
ghcr.io/data-fair/processings:15a9216989707
tmp@0.0.33
0.2.6
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
tmp@0.0.33
0.2.6
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
tmp@0.2.5
0.2.6
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
tmp@0.2.5
0.2.6
1
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
tmp@0.2.3
0.2.6
1
ghcr.io/lerentis/bitwarden-crd-operator:0.17.00a608c6ead85
tmp@0.0.33
0.2.6
1
ghcr.io/linkwarden/linkwarden:v2.16.30664c28a039b
tmp@0.0.33
0.2.6
1
ghcr.io/middleware-labs/odigos-ui:middleware-test-0.0.787120a4561a9
tmp@0.2.1
0.2.6
1
ghcr.io/middleware-labs/vision-ui:middleware-test-0.0.853772b7b42c7
tmp@0.2.1
0.2.6
1
ghcr.io/open-telemetry/demo:1.12.0-frontend8b348f00ca4c
tmp@0.2.3
0.2.6
1
ghcr.io/rodg/nodecg-base:latest31be4bf87070
tmp@0.0.33
0.2.6
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
tmp@0.0.33
0.2.6
1
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
tmp@0.2.5
0.2.6
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
tmp@0.2.3
0.2.6
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
tmp@0.0.33
0.2.6
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
tmp@0.2.1
0.2.6
1
quay.io/helmpack/monocular-ui:v1.10.086b71e90319f
tmp@0.0.28
0.2.6
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
tmp@0.0.33
0.2.6
1
quay.io/mongodb/farm-intro-frontend:0.199ccdfd543e1
tmp@0.0.33
0.2.6
1
quay.io/netwarps/blockscoutbecd3e39360a
tmp@0.0.33
0.2.6
1
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
tmp@0.2.1
0.2.6
1
quay.io/wekan/wekan:v5.65cb17600883a3
tmp@0.0.33
0.2.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.