StackRadar

CVE-2026-53655

Medium

Advisory

Published 15 Jun 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.002
5th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
889
of 17,781 indexed, latest versions
Container images
920
deployed by those charts
Fix available
2 of 3
affected packages

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

Carried by container images the latest versions of 889 of 17,781 indexed charts deploy, on 920 images.

Affected packageAffected versionsFixed inImages
tarnpm1.0.3, 2.2.1, 2.2.2, 4.0.2+31 more7.5.16920
npmapk11.17.0-r011.17.0-r21
node-tardeb1.0.3-2, 2.2.1-1, 4.4.10+ds1-2ubuntu1, 6.1.13+~cs7.0.5-3no fix listed6
OSV records
CGA-85f3-cvh5-pcppGHSA-vmf3-w455-68vhUBUNTU-CVE-2026-53655
Also known as
CGA-r3rf-vp7c-364p

Charts affected

889 by stars
ChartLatestAffected imagesRadar Score
multilink-clientassist-iot-multi-link-client-app1.0.01 of 2See more

multilink-client assist-iot-multi-link-client-app 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
assistiot/multi-link_client:latestcf048365d042
tar@6.2.0
7.5.16

Open the chart page →

1,446
multilink-serverassist-iot-multi-link-server-app1.0.01 of 2See more

multilink-server assist-iot-multi-link-server-app 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
assistiot/multi-link_server:latestf38c76a4c960
tar@6.1.15
7.5.16

Open the chart page →

973
openapiassist-iot-open-api-management0.2.22 of 6See more

openapi assist-iot-open-api-management 0.2.2

2 of the 6 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
assistiot/open_api_frontend:1.0.1f11d82defc70
tar@4.4.19
7.5.16
pantsel/konga:latestc8172b75607d
tar@4.4.13
7.5.16

Open the chart page →

18,277
smartorchestratorassist-iot-smart-orchestrator4.0.03 of 14See more

smartorchestrator assist-iot-smart-orchestrator 4.0.0

3 of the 14 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
assistiot/smart-orchestrator_cluster:latest4f41e1defe99
tar@4.4.19
7.5.16
assistiot/smart-orchestrator_enabler:latest89f37e88c871
tar@6.1.11
7.5.16
assistiot/smart-orchestrator_repository:latesta8b8dbed04a4
tar@6.1.11
7.5.16

Open the chart page →

45,363
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
tar@6.2.1
7.5.16

Open the chart page →

32,501
asya-playgroundasya1.1.31 of 1See more

asya-playground asya 1.1.3

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
localstack/localstack:3.19d278167f2b7
tar@6.2.0
7.5.16

Open the chart page →

9,412
shynetatrox0.1.11 of 1See more

shynet atrox 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
milesmcc/shynet:v0.12.0e821e31140f7
tar@6.1.0
7.5.16

Open the chart page →

5,507
nas-appsawesomeVerified publisher2.0.02 of 8See more

nas-apps awesome 2.0.0

2 of the 8 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ltdstudio/terraforming-mars:latest0e76c6f4eac0
tar@2.2.2
7.5.16
wettyoss/wetty:latest7423b3d40ba2
tar@7.5.11
7.5.16

Open the chart page →

7,152
awesomeblessingappawesomeblessingapp1.1.01 of 1See more

awesomeblessingapp awesomeblessingapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
bnwokoye/nodejswebapp:latest74de7dc7ebfb
tar@6.1.13
7.5.16

Open the chart page →

1,267
bookinfobasictechno0.1.01 of 6See more

bookinfo basictechno 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.17.0b6a6b88d3578
tar@4.4.13
7.5.16

Open the chart page →

20,671
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
tar@6.2.1
7.5.16

Open the chart page →

1,722
pangolinbdcode0.14.11 of 1See more

pangolin bdcode 0.14.1

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
fosrl/pangolin:latest83a55f933b4d
tar@7.5.15
7.5.16

Open the chart page →

1,901
bluesky-pdsbear0.4.2081 of 1See more

bluesky-pds bear 0.4.208

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/bluesky-social/pds:0.4.208637083d9369d
tar@6.2.1
7.5.16

Open the chart page →

2,136
opendistro-esbeeinventor1.15.11 of 3See more

opendistro-es beeinventor 1.15.1

1 of the 3 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.13.2c740d7a89475
tar@6.0.2
7.5.16

Open the chart page →

5,806
myhelmappbelihelmapp1.1.01 of 1See more

myhelmapp belihelmapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
belirta/beli-docker:v1.0.0f65ad0e23b4d
tar@6.1.14
7.5.16

Open the chart page →

1,187
http-debugbicarus-labs0.1.01 of 1See more

http-debug bicarus-labs 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
bicarus/http-https-echo:2785dd6a7e805e
tar@6.1.11
7.5.16

Open the chart page →

867
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
tar@6.1.11
7.5.16

Open the chart page →

4,455
huebigdata-chartsVerified publisher1.0.41 of 2See more

hue bigdata-charts 1.0.4

1 of the 2 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
gethue/hue:4.10.05702b2c37ff9
tar@4.4.13
7.5.16

Open the chart page →

22,891
bluerange-mosquittobluerangeOfficialVerified publisher1.0.41 of 1See more

bluerange-mosquitto bluerange 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
bluerange/bluerange-mosquitto:25f1bfbba84832
tar@7.5.1
7.5.16

Open the chart page →

1,168
istio-bookinfobookinfo1.2.21 of 6See more

istio-bookinfo bookinfo 1.2.2

1 of the 6 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.15.009b9d6958a13
tar@2.2.1
7.5.16

Open the chart page →

18,980
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
tar@6.2.1
7.5.16
sysnet4admin/colosseum-prm:log5802bfcd7fed
tar@6.2.1
7.5.16

Open the chart page →

26,996
overseerrbrandan-schmitz-helm-chartsVerified publisher1.4.01 of 1See more

overseerr brandan-schmitz-helm-charts 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
linuxserver/overseerr:1.35.06108ed066d4a
tar@6.1.13
7.5.16

Open the chart page →

3,071
rtorrent-floodbryanalves0.5.01 of 1See more

rtorrent-flood bryanalves 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
jesec/flood:4.7.03d1d0bec117a
tar@6.1.11
7.5.16

Open the chart page →

1,477
node-appbryopsida0.5.11 of 2See more

node-app bryopsida 0.5.1

1 of the 2 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/k8s-dev-pod:main82d0b161161d
tar@6.2.1
7.5.16

Open the chart page →

14,352
openmctbryopsida0.1.11 of 1See more

openmct bryopsida 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/openmct:main38b6a50a62b2
tar@6.2.1
7.5.16

Open the chart page →

951
syslog-portalbryopsida0.3.11 of 1See more

syslog-portal bryopsida 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/bryopsida/syslog-portal:main3947bfd04f49
tar@7.4.3
7.5.16

Open the chart page →

1,306
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
tar@6.2.1
7.5.16

Open the chart page →

1,338
qbittorrentcfi20176.13.31 of 1See more

qbittorrent cfi2017 6.13.3

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
tar@6.2.1
7.5.16

Open the chart page →

1,338
dv-podcharonOfficialVerified publisher0.19.11 of 5See more

dv-pod charon 0.19.1

1 of the 5 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
obolnetwork/charon-dkg-sidecar:maine263be0a7440
tar@7.4.3
7.5.16

Open the chart page →

7,405
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
tar@7.4.3
7.5.16

Open the chart page →

4,083
audiobookshelfcharts-derwitt-devVerified publisher1.1.01 of 1See more

audiobookshelf charts-derwitt-dev 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
tar@6.2.1
7.5.16

Open the chart page →

1,722
ddb-proxycharts-derwitt-devVerified publisher1.3.01 of 1See more

ddb-proxy charts-derwitt-dev 1.3.0

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/mrprimate/ddb-proxy:0.0.258dc2d7fb460f
tar@6.1.11
7.5.16

Open the chart page →

812
otbrcharts-derwitt-devVerified publisher0.2.01 of 1See more

otbr charts-derwitt-dev 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
openthread/otbr:latestf307f59f6432
tar@2.2.1
node-tar@2.2.1-1
7.5.16
no fix listed

Open the chart page →

12,779
servicechart-serviceVerified publisher0.0.41 of 1See more

service chart-service 0.0.4

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
punkerside/noroot:v0.0.7be20c81d6ca1
tar@6.1.11
7.5.16

Open the chart page →

930
chatgpt-next-webchatgpt-next-web0.1.11 of 1See more

chatgpt-next-web chatgpt-next-web 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
yidadaa/chatgpt-next-web:latesteaaa469ddeeb
tar@6.2.1
7.5.16

Open the chart page →

1,977
audiobookshelfchristianhuthVerified publisher2.4.01 of 1See more

audiobookshelf christianhuth 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
tar@6.2.1
7.5.16

Open the chart page →

1,722
countlychristianhuthVerified publisher5.2.12 of 3See more

countly christianhuth 5.2.1

2 of the 3 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
countly/api:25.05.4f4cc7447c4f5
tar@6.2.1
7.5.16
countly/frontend:25.05.42acbc11499b6
tar@6.2.1
7.5.16

Open the chart page →

7,295
mcp-for-argocdchristianhuthVerified publisher2.0.01 of 1See more

mcp-for-argocd christianhuth 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/argoproj-labs/mcp-for-argocd:v0.9.0dffc6c719d86
tar@6.2.1
7.5.16

Open the chart page →

1,947
kamaji-consoleclastixVerified publisher0.1.31 of 1See more

kamaji-console clastix 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ghcr.io/clastix/kamaji-console:v0.2.129ecf8d4fa65
tar@6.1.15
7.5.16

Open the chart page →

2,759
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
tar@2.2.1
7.5.16

Open the chart page →

29,901
ethereumcloudnativeapp1.0.01 of 3See more

ethereum cloudnativeapp 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
ethereumex/eth-stats-dashboard:v0.0.1a7603aa8df4c
tar@2.2.1
node-tar@1.0.3-2
7.5.16
no fix listed

Open the chart page →

27,417
hlf-couchdbcloudnativeapp1.0.61 of 1See more

hlf-couchdb cloudnativeapp 1.0.6

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
hyperledger/fabric-couchdb:0.4.10c65891b6c237
tar@2.2.1
7.5.16

Open the chart page →

33,963
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
tar@2.2.1
7.5.16

Open the chart page →

2,580
kube-slackcloudnativeapp1.0.01 of 1See more

kube-slack cloudnativeapp 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
willwill/kube-slack:v4.1.1d443017aae98
tar@2.2.1
7.5.16

Open the chart page →

1,937
node-redcloudnativeapp1.2.21 of 1See more

node-red cloudnativeapp 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
nodered/node-red-docker:0.19.6-v8070643219ea2
tar@2.2.1
7.5.16

Open the chart page →

4,790
webpagetest-agentcloudnativeapp0.2.01 of 1See more

webpagetest-agent cloudnativeapp 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
timothyclarke/wptagent:2018-01-2322c41e5ca7e2
tar@2.2.1
7.5.16

Open the chart page →

77,758
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
tar@2.2.2
7.5.16

Open the chart page →

25,456
robot-shopcloud-native-toolkit1.1.13 of 12See more

robot-shop cloud-native-toolkit 1.1.1

3 of the 12 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
robotshop/rs-cart:latest388349d5cb3c
tar@4.4.15
7.5.16
robotshop/rs-catalogue:latestd545747c1b97
tar@4.4.15
7.5.16
robotshop/rs-user:latestea509182c180
tar@4.4.15
7.5.16

Open the chart page →

29,555
setup-jobcloud-native-toolkit0.3.01 of 2See more

setup-job cloud-native-toolkit 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
tar@4.4.13
7.5.16

Open the chart page →

2,792
slack-notificationscloud-native-toolkit0.1.71 of 1See more

slack-notifications cloud-native-toolkit 0.1.7

1 of the 1 container images this version deploys carry CVE-2026-53655.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/slack-notifications:latest041df93e2bac
tar@4.4.13
7.5.16

Open the chart page →

1,545

Container images carrying it

920 by charts deploying them

A fixed version is listed for 2 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
bicarus/http-https-echo:2785dd6a7e805e
tar@6.1.11
7.5.16
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
tar@6.1.11
7.5.16
1
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
tar@4.4.1
7.5.16
1
blockscout/blockscout:5.1.5c365a8f2dc12
tar@6.1.11
7.5.16
1
bluerange/bluerange-mosquitto:25f1bfbba84832
tar@7.5.1
7.5.16
1
bnjbvr/kresus:0.22.137e216b182c8
tar@7.4.3
7.5.16
1
bnwokoye/nodejswebapp:latest74de7dc7ebfb
tar@6.1.13
7.5.16
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
tar@6.1.0
7.5.16
1
budibase/apps:3.41.344fe6feab985
tar@7.5.11
7.5.16
1
budibase/database:2.1.0d90f656261c9
tar@7.5.11
7.5.16
1
budibase/worker:3.41.3de5e2e560ce8
tar@7.5.11
7.5.16
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
tar@4.4.19
7.5.16
1
carlosmz87/test_helm_backend:latest8ffa63aa995d
tar@7.4.3
7.5.16
1
catalysm/csmm:latestf003b35f54d9
tar@6.1.11
7.5.16
1
cccs/assemblyline-ui-frontend:4.7.4.stable174c8e4b6c0483
tar@7.5.11
7.5.16
1
ccjacobs14/amazon:59a9b14a6f09e
tar@6.2.0
7.5.16
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
tar@6.2.1
7.5.16
1
chandanteekinavar/findery-market-user-service:1.049e164a9a439
tar@6.1.11
7.5.16
1
chatwoot/chatwoot:v4.15.167ebc751c171
tar@2.2.2
7.5.16
1
chibisafe/chibisafe:latest836467a50792
tar@6.2.1
7.5.16
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
tar@6.2.1
7.5.16
1
chocobozzz/peertube:v8.1.5052712130691
tar@7.5.13
7.5.16
1
christianhuth/node-hostname:1.0.1c07f414a3e4b
tar@7.4.3
7.5.16
1
cnieg/maildev:v1.1.998ee05668915
tar@4.4.13
7.5.16
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
tar@6.1.11
7.5.16
1
codercom/code-server:4.11.0-debian1e2cc688008e
tar@6.1.11
7.5.16
1
codetogether/codetogether:latest4348c8a38752
tar@6.2.1
7.5.16
1
coldatom/containers-security-api:latesteae9e82da080
tar@6.1.13
7.5.16
1
coldatom/containers-security-front:latest7c2fbbb41bcf
tar@6.1.11
7.5.16
1
conduction/conduction-ui-app:devd591f5e6f2a9
tar@6.1.0
7.5.16
1
contane/foreman:0.5.2efb98bdcc4e9
tar@7.4.3
7.5.16
1
cortezaproject/corteza-server-corredor:2024.9.44ea78dfe5364
tar@6.2.1
7.5.16
1
countly/api:25.05.4f4cc7447c4f5
tar@6.2.1
7.5.16
1
countly/countly-server:25.05.4e3c238248f99
tar@6.2.1
7.5.16
1
countly/frontend:25.05.42acbc11499b6
tar@6.2.1
7.5.16
1
cryptexlabs/authf:0.12.11189c07411d7c
tar@6.2.0
7.5.16
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
tar@6.2.0
7.5.16
1
cspconsole/report-processor:1.0.279a2d8840bfdf
tar@7.5.11
7.5.16
1
cyfershepard/jellystat:1.1.11c4e2dfa8bddf
tar@7.5.15
7.5.16
1
dacinfomotion/h2p:latest68fa393b472c
tar@6.1.15
7.5.16
1
danny1dockerhub/nodejswebapp:lateste434683fcc89
tar@6.1.13
7.5.16
1
daskdev/dask-notebook:1.1.0052630f5ca04
tar@2.2.1
7.5.16
1
datarhei/restreamer:0.6.4655e12f9eeed
tar@4.4.13
7.5.16
1
davdiv/musicociel:deva85f99be882c
tar@6.2.0
7.5.16
1
davidvmar/urjc-davidvmar-external-service:1.0.02a68e9ac7f09
tar@4.4.13
7.5.16
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
tar@4.4.13
7.5.16
1
dbgate/dbgate:7.2.0-alpine287077002446
tar@6.2.1
7.5.16
1
dbgate/dbgate:7.2.3f2dc7423ea88
tar@7.5.11
7.5.16
1
decayofmind/hubot:3.3.21e18e92fe694
tar@1.0.3
7.5.16
1
decisionrules/business-intelligence:latest1135a6d4f09b
tar@7.5.11
7.5.16
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.