StackRadar

CVE-2026-44705

High

Advisory

Published 27 May 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
178
of 17,781 indexed, latest versions
Container images
174
deployed by those charts
Fix available
1 of 1
affected package

tmp has Path Traversal via unsanitized prefix/postfix that enables directory escape

Carried by container images the latest versions of 178 of 17,781 indexed charts deploy, on 174 images.

Affected packageAffected versionsFixed inImages
tmpnpm0.0.23, 0.0.28, 0.0.29, 0.0.30+6 more0.2.6174
OSV records
GHSA-ph9p-34f9-6g65

Charts affected

178 by stars
ChartLatestAffected imagesRadar Score
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
gjeanmart/safe-ganache-node:latest926264c8f2d1
tmp@0.0.33
0.2.6

Open the chart page →

16,620
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
tmp@0.0.33
0.2.6

Open the chart page →

5,582
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
tmp@0.0.33
0.2.6

Open the chart page →

4,431
wekanschmitzis1.1.11 of 1See more

wekan schmitzis 1.1.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
quay.io/wekan/wekan:v5.65cb17600883a3
tmp@0.0.33
0.2.6

Open the chart page →

3,638
secret-managersecret-managerVerified publisher1.0.01 of 4See more

secret-manager secret-manager 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
leonardomulticloud/svc-vault-frontend:v1.0.0e42a341e0299
tmp@0.2.3
0.2.6

Open the chart page →

5,497
dashysergiotocaliniVerified publisher1.0.01 of 1See more

dashy sergiotocalini 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
tmp@0.0.33
0.2.6

Open the chart page →

3,143
skoonerskooner0.2.21 of 1See more

skooner skooner 0.2.2

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
tmp@0.2.1
0.2.6

Open the chart page →

1,341
k8soketisoketi1.0.11 of 1See more

k8soketi soketi 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
quay.io/soketi/k8soketi:0.1-18-debian4cd9ea9434c4
tmp@0.2.1
0.2.6

Open the chart page →

2,267
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
tmp@0.0.33
0.2.6

Open the chart page →

2,121
alert-mappersomeblackmagic0.2.01 of 1See more

alert-mapper someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
someblackmagic/alert-mapper:v0.1.088351d85c04c
tmp@0.0.33
0.2.6

Open the chart page →

1,890
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
tmp@0.2.3
0.2.6

Open the chart page →

1,313
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
tmp@0.2.1
0.2.6

Open the chart page →

4,052
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
tmp@0.0.33
0.2.6

Open the chart page →

3,881
fdi-dotstatsuite-sfs-solrstatcan1.0.21 of 4See more

fdi-dotstatsuite-sfs-solr statcan 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
tmp@0.0.33
0.2.6

Open the chart page →

6,065
fdi-dotstatsuite-sfs-solr-statefulstatcan1.0.21 of 2See more

fdi-dotstatsuite-sfs-solr-stateful statcan 1.0.2

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
tmp@0.0.33
0.2.6

Open the chart page →

919
kurento_webrtc_demostunner0.1.01 of 2See more

kurento_webrtc_demo stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
tmp@0.0.28
0.2.6

Open the chart page →

12,460
stunner-kurento-one2one-callstunner0.1.01 of 2See more

stunner-kurento-one2one-call stunner 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
tmp@0.0.28
0.2.6

Open the chart page →

12,460
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
tmp@0.2.1
0.2.6

Open the chart page →

3,576
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-44705.

Open the chart page →

17,323
evolution-apivcnngrVerified publisher1.0.01 of 5See more

evolution-api vcnngr 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
evoapicloud/evolution-api:latest966625532d90
tmp@0.0.33
0.2.6

Open the chart page →

3,746
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
tmp@0.2.1
0.2.6

Open the chart page →

3,129
skoonervhdirkVerified publisher0.1.41 of 1See more

skooner vhdirk 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
tmp@0.2.1
0.2.6

Open the chart page →

1,341
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
tmp@0.0.33
0.2.6

Open the chart page →

5,984
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
wazuh/wazuh-dashboard:4.14.491c8d793746f
tmp@0.2.3
0.2.6

Open the chart page →

5,484
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
tmp@0.2.5
0.2.6

Open the chart page →

5,459
kibanawiremindVerified publisher8.5.231 of 2See more

kibana wiremind 8.5.23

1 of the 2 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
library/kibana:8.18.004c0fc150f3a
tmp@0.0.33
0.2.6

Open the chart page →

6,285
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
tmp@0.2.1
0.2.6

Open the chart page →

1,752
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-44705.

Container imageDigestPackageFixed in
opensearchproject/opensearch-dashboards:2.18.00ecd8444add2
tmp@0.2.1
0.2.6

Open the chart page →

9,381

Container images carrying it

174 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
tmp@0.2.1
0.2.6
5
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
tmp@0.2.1
0.2.6
4
assistiot/dlt_api:2.0.0e36a8922fa0c
tmp@0.2.1
0.2.6
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
tmp@0.2.1
0.2.6
3
pantsel/konga:latestc8172b75607d
tmp@0.0.28
0.2.6
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
tmp@0.0.33
0.2.6
3
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
tmp@0.2.1
0.2.6
3
ethersphere/bee-localchain:latest0558799ca992
tmp@0.0.33
0.2.6
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
tmp@0.0.33
0.2.6
2
governify/assets-manager:v1.4.12987672448c7
tmp@0.0.33
0.2.6
2
governify/registry:v3.4.0d3f37f4f8168
tmp@0.2.1
0.2.6
2
governify/render:v2.2.0daeca1ce28e6
tmp@0.0.33
0.2.6
2
governify/reporter:v2.2.038595913458f
tmp@0.0.33
0.2.6
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
tmp@0.0.28
0.2.6
2
library/arangodb:3.11.81e75d74954a4
tmp@0.0.33
0.2.6
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
tmp@0.2.1
0.2.6
2
mesosphere/kommander:6.100.13917e82333a9
tmp@0.2.1
0.2.6
2
migmartri/prerender:latest486aacfd5aa9
tmp@0.0.28
0.2.6
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
tmp@0.2.1
0.2.6
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
tmp@0.2.1
0.2.6
2
mojaloop/reporting:v12.1.0d480a62103d6
tmp@0.2.3
0.2.6
2
mojaloop/reporting-hub-bop-api-svc:v4.1.2b45a2d6f0f2a
tmp@0.0.33
0.2.6
2
outlinewiki/outline:0.69.1d060dcd8f9aa
tmp@0.0.33
0.2.6
2
requarks/wiki:2:latest68f0d1848261
tmp@0.2.5
0.2.6
2
siscc/dotstatsuite-sdmx-faceted-search:master12c5048f7402
tmp@0.0.33
0.2.6
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
tmp@0.0.33
0.2.6
2
adeptiainc/adeptia-automate-mcp-server:1.0.0283001e83739
tmp@0.2.5
0.2.6
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
tmp@0.2.3
0.2.6
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
tmp@0.0.33
0.2.6
1
arturisimo/server-urjc:v1.0d8dc4430531e
tmp@0.2.1
0.2.6
1
assistiot/dlt_api:2.1.0c8a170683be7
tmp@0.2.1
0.2.6
1
assistiot/fl_orchestrator:api-latest7473d77448e1
tmp@0.0.33
0.2.6
1
assistiot/open_api_frontend:1.0.1f11d82defc70
tmp@0.0.33
0.2.6
1
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
tmp@0.2.1
0.2.6
1
assistiot/smart-orchestrator_enabler:latest89f37e88c871
tmp@0.2.1
0.2.6
1
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
tmp@0.2.1
0.2.6
1
baserow/baserow:1.30.1df0c42eb67e8
tmp@0.0.33
0.2.6
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
tmp@0.0.33
0.2.6
1
blockscout/blockscout:5.1.5c365a8f2dc12
tmp@0.0.33
0.2.6
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
tmp@0.2.1
0.2.6
1
catalysm/csmm:latestf003b35f54d9
tmp@0.2.1
0.2.6
1
chainsafe/lodestar:latest5593f6e97912
tmp@0.0.33
0.2.6
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
tmp@0.2.1
0.2.6
1
coldatom/containers-security-api:latesteae9e82da080
tmp@0.2.1
0.2.6
1
daskdev/dask-notebook:1.1.0052630f5ca04
tmp@0.0.33
0.2.6
1
decayofmind/hubot:3.3.21e18e92fe694
tmp@0.0.33
0.2.6
1
directus/directus:11.1.0e3c8bb975350
tmp@0.0.33
0.2.6
1
documenso/documenso:v1.8.17f16a9449f18
tmp@0.2.1
0.2.6
1
ducktors/turborepo-remote-cache:latest31ec9e83c844
tmp@0.2.5
0.2.6
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
tmp@0.0.33
0.2.6
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.